Resource access control method and platform
By recording access control policies for administrators and users through the management platform, and controlling the forwarding of access endpoints, the problems of resource loss and unreasonable use in the cloud computing environment are solved, and the secure management and efficient control of resources are achieved.
Patent Information
- Application Number
- CN202410796626.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2024-05-21
- Filing Date
- 2024-06-19
- Publication Date
- 2025-11-21
AI Technical Summary
In a cloud computing environment, an organization's resources may be lost or misused due to uncontrolled management permissions, and users may share resources with external users or use them improperly.
The management platform records the access control policies configured by the administrator and allows or denies access requests based on these policies, controlling the forwarding of access endpoints to resources. Combined with user-defined access control policies, it ensures that access requests comply with the permissions of the administrator and the user.
Effective control of resource access prevents resource loss and misuse, thereby improving resource security and management efficiency.
Smart Images

Figure CN121000403A_ABST
Abstract
Description
[0001] This application claims priority to Chinese Patent Application No. 202410634307.0, filed on May 21, 2024, entitled “An Access Control Method and Apparatus”, the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of computer technology, and in particular to a resource access control method and platform. Background Technology
[0003] With the development of technologies such as cloud computing, enterprises and organizations can purchase or rent resources provided by remote infrastructure, such as computing and storage resources. This eliminates the need for organizations to build their own infrastructure locally, reducing their operating costs.
[0004] Users within an organization can apply for and use resources based on their organizational status. Generally, users have administrative privileges over the resources they request. Failure to control these privileges can lead to resource loss for the organization. For example, users might share their requested resources with users outside the organization, or they might misuse the resources they request. Summary of the Invention
[0005] This application provides a resource access control method and platform that enables an organization's administrators to control resource access requests and avoid losses and unreasonable use of resources.
[0006] Firstly, a resource access control method is provided. This method is applied to a management platform that manages multiple access endpoints and multiple resources of a target organization. The multiple resources are provided by multiple servers in an infrastructure, and these servers are located in the same or multiple data centers within the infrastructure. Each access endpoint corresponds to at least one of the multiple resources, and each access endpoint is used to forward access requests for that resource to the resource corresponding to it. The method includes: the management platform recording a first access control policy configured by the target organization's administrator for a target access endpoint, where the target access endpoint is at least one of the multiple access endpoints; the management platform obtaining a target access request for a target resource, where the target resource is the resource corresponding to the target access endpoint among the multiple resources; and the management platform, based on the first access control policy, allowing or prohibiting the target access endpoint from forwarding the target access request to the target resource.
[0007] In this method, an organization's administrator can configure access control policies and apply them to access endpoints used to forward access requests to resources. Thus, whenever an access request needs to be forwarded by an access endpoint, the administrator can determine, based on the access control policy, whether the request is permitted by the administrator. If permitted, the access endpoint is allowed to forward the request to the resource, allowing the request to access the resource. If not permitted, the access endpoint is prohibited from forwarding the request to the resource, preventing access. Therefore, the administrator can control access requests to the organization's resources, ensuring resource security and preventing unreasonable use or loss of resources.
[0008] In one possible implementation, the target access endpoint is created by a first user within the target organization, and the management platform also records a second access control policy configured by the first user for the target access endpoint; the management platform allows or prohibits the target access endpoint from forwarding target access requests to the target resource based on the first access control policy, including: the management platform allows or prohibits the target access endpoint from forwarding target access requests to the target resource based on the first access control policy and the second access control policy.
[0009] In this implementation, the user who creates the access endpoint can also configure access control policies. Whenever an access request needs to be forwarded by the access endpoint, in addition to determining whether the access request is permitted by the organization's administrator, the system also determines whether the access request is permitted by the user based on the access control policy. The access endpoint is only allowed to forward the access request to the resource if it is permitted by both the administrator and the user; otherwise, the access endpoint is prohibited from forwarding the access request to the resource, thereby further ensuring the security of the resource.
[0010] In one possible implementation, the management platform records the first access control policy configured by the administrator of the target organization for the target access endpoint, including: the management platform associating the first access control policy with the organization node of the target organization, the organization node being an organizational unit (OU) or a first user within the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; the management platform, based on the first access control policy, allows or prohibits the target access endpoint from forwarding target access requests to the target resource, including: when the management platform confirms that the target access endpoint belongs to an organization node, it allows or prohibits the target access endpoint from forwarding target access requests to the target resource based on the first access control policy.
[0011] In this implementation, the management platform can associate access control policies with organizational nodes, making the access control policies effective for access endpoints within that organizational node. This eliminates the need to apply access control policies to each individual access endpoint, saving operational time. Furthermore, whenever a new access endpoint is added to an organizational node, the access control policy automatically applies to it, enabling timely control over new endpoints and efficiently ensuring resource security. Additionally, when an access request needs to be forwarded to an access endpoint, the access control policy for that endpoint can be quickly retrieved by identifying the organizational node to which it belongs, further improving access control efficiency.
[0012] In one possible implementation, the method further includes: recording the association between the identifier of the target access endpoint and the identifier of the first user; confirming that the target access endpoint belongs to the organization node includes: obtaining the identifier of the target access endpoint from the target access request; and confirming that the target access endpoint belongs to the organization node based on the identifier of the target access endpoint and the association.
[0013] Access requests typically carry an identifier for the endpoint being accessed. In this implementation, by verifying the identifier of the access endpoint carried in the access request, the user to whom the access endpoint belongs can be identified. Furthermore, by identifying the user to whom the access endpoint belongs, the organizational node to which the access endpoint belongs can be identified.
[0014] In one possible implementation, the first access control policy indicates the permission of users within the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a first user or a second user within the target organization; wherein the target access endpoint is created by the first user, and the second user is a user within the target organization other than the first user.
[0015] In this way, administrators can use access control policies to prevent users within the organization from misusing the organization's resources.
[0016] In one possible implementation, the first access control policy indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by the user outside the target organization.
[0017] In this way, administrators can use access control policies to prevent unauthorized users from accessing the organization's resources, thus ensuring resource security.
[0018] In one possible implementation, the target access endpoint is a Virtual Private Cloud Endpoint Node (VPCEP).
[0019] This method can be used by cloud management platforms to manage VPCEP, enabling administrators to control access to cloud resources.
[0020] Secondly, a management platform is provided for managing multiple access endpoints and multiple resources of a target organization. The multiple resources are provided by multiple servers in an infrastructure, which are located in the same or multiple data centers within the infrastructure. Each access endpoint corresponds to at least one of the multiple resources, and the access endpoint is used to forward access requests for that resource to the resource corresponding to it. The management platform includes: a recording module for recording a first access control policy configured by the target organization's administrator for a target access endpoint, where the target access endpoint is at least one of the multiple access endpoints; an acquisition module for acquiring target access requests for a target resource, where the target resource is the resource corresponding to the target access endpoint among the multiple resources; and a control module for allowing or prohibiting the target access endpoint from forwarding target access requests to the target resource based on the first access control policy.
[0021] In one possible implementation, the target access endpoint is created by the first user within the target organization, and the management platform also records the second access control policy configured by the first user for the target access endpoint; the control module is used by the management platform to allow or prohibit the target access endpoint from forwarding target access requests to the target resource based on the first access control policy and the second access control policy.
[0022] In one possible implementation, the recording module is used to: associate the first access control policy with the organization node of the target organization, wherein the organization node is an organizational unit (OU) or a first user within the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; the control module is used to: upon confirming that the target access endpoint belongs to the organization node, allow or prohibit the target access endpoint from forwarding the target access request to the target resource based on the first access control policy.
[0023] In one possible implementation, the recording module is further configured to: record the association between the identifier of the target access endpoint and the identifier of the first user; the control module is configured to: obtain the identifier of the target access endpoint from the target access request; and, based on the identifier of the target access endpoint and the association, confirm that the target access endpoint belongs to the organization node.
[0024] In one possible implementation, the first access control policy instructs a user within the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a first user or a second user within the target organization; wherein the target access endpoint is created by the first user, and the second user is a user within the target organization other than the first user; or, the first access control policy instructs a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a user outside the target organization.
[0025] In one possible implementation, the target access endpoint is a Virtual Private Cloud Endpoint Node (VPCEP).
[0026] Thirdly, a computing device cluster is provided, including at least one computing device, each computing device including a processor and a memory; the processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster performs the method provided in the first aspect.
[0027] Fourthly, a computer-readable storage medium is provided, including computer program instructions that, when executed by a cluster of computing devices, execute the method provided in the first aspect.
[0028] Fifthly, a computer program product containing instructions is provided, which, when executed by a cluster of computer devices, causes the cluster of computer devices to perform the method provided in the first aspect.
[0029] The beneficial effects of the second to fifth aspects can be referred to the introduction of the beneficial effects of the first aspect above, and will not be repeated here. Attached Figure Description
[0030] Figure 1 A schematic diagram of a system architecture provided for an embodiment of this application;
[0031] Figure 2 A schematic diagram of a system architecture provided for an embodiment of this application;
[0032] Figure 3 A schematic diagram of a system architecture provided for an embodiment of this application;
[0033] Figure 4 A flowchart illustrating a resource access control method provided in an embodiment of this application;
[0034] Figure 5 A schematic diagram illustrating an access control policy provided in an embodiment of this application;
[0035] Figure 6 A schematic diagram illustrating an access control policy provided in an embodiment of this application;
[0036] Figure 7 A flowchart illustrating a resource access control method provided in an embodiment of this application;
[0037] Figure 8 A flowchart illustrating a resource access control method provided in an embodiment of this application;
[0038] Figure 9 A schematic diagram of the structure of a management platform provided in an embodiment of this application;
[0039] Figure 10 This is a schematic diagram of the structure of a computing device provided in an embodiment of this application;
[0040] Figure 11 This is a schematic diagram of the structure of a computing device cluster provided in an embodiment of this application;
[0041] Figure 12 This is a schematic diagram of the structure of a computing device cluster provided in an embodiment of this application. Detailed Implementation
[0042] The solutions provided in the embodiments of this application will now be described with reference to the accompanying drawings. In the embodiments of this application, "multiple" refers to two or more objects, and "various types" refers to two or more types. Terms such as "first," "second," etc., are only used to distinguish similar objects and are not necessarily used to describe a specific order or number of objects.
[0043] To facilitate understanding of the solutions provided in the embodiments of this application, the technical terms that may be involved in the embodiments of this application will be introduced first.
[0044] Cloud technology refers to a managed service that unifies a series of resources such as hardware, software, and networks within a wide area network or local area network to enable data computing, storage, processing, and sharing.
[0045] Infrastructure refers to the facilities that provide computing resources, storage resources, and / or network resources for computing services. A resource pool may include at least one data center, and each data center includes multiple servers. Servers act as hosts for deploying instances. In cloud technology, infrastructure is also called cloud infrastructure, used to provide computing resources, storage resources, and / or network resources for cloud computing services.
[0046] Management Platform: A platform provided by the computing service provider for interaction with users. Users can register accounts on the management platform and rent computing services using those accounts, thus becoming users of the computing services. Users can manage resource pools and instances within those resource pools through the management platform. In scenarios where the computing service is a cloud computing service, the management platform can be called a cloud management platform.
[0047] Users, also known as tenants, are those who rent resources. Users can register accounts on the management platform operated by the computing service provider through a browser or other client. The computing service provider records different user accounts and isolates resources for different users based on their accounts. Typically, users have full access to the resources they rent.
[0048] Resources refer to instances deployed within infrastructure used to run computing, networking, or storage resources. These instances include, but are not limited to, compute instances, Elastic Cloud Servers (ECS), Bare Metal Servers (BMS), Object Storage Service (OBS) buckets, Elastic Load Balancers (ELB), Network Address Translation Gateways (NAT Gateways), and cloud caching services. Typical compute instances include virtual machines (VMs) and containers. In cloud technology, resources can be referred to as cloud resources.
[0049] Infrastructure: The facilities that support computing services, including at least one data center, each data center comprising multiple servers. Servers can provide one or more resources, such as running virtual machines or containers. For example, in the case of infrastructure comprising multiple data centers, these data centers can be distributed across different geographical regions, and the data centers can be remotely connected via a backbone network.
[0050] Organizations (ORG): Hierarchical tree-structured entities created by the management platform for unified management of multiple users. An organization has multiple members. Each of these members is a user registered with the management platform. Multiple members or users within an organization typically belong to the same group, such as the same company.
[0051] Organizational nodes: These are the nodes in the tree structure of an organization. An organizational node can be an organizational unit (OU) within that organization, or it can be a user within that organization.
[0052] Organizational unit (OU): Also known as an organizational department, it is a node in the tree structure of an organization. Organizational units are created by the organization administrator, and organizational departments can be nested. Each organizational unit manages one or more users.
[0053] Root organizational unit (ROU): Also known as the root OU, it is the root node in the tree structure of an organization. All other OUs within the organization, excluding the root OU, are leaf nodes of that tree structure, or leaf nodes of the root OU. Leaf nodes can also be simply referred to as child nodes.
[0054] Member account (Acct): Also known as user account, it is the object of organization management. One member account represents one user. After the organization is created, the organization administrator invites existing accounts to join the organization, or creates new accounts through the organization, and the newly created accounts are automatically added to the organization.
[0055] Access endpoints are the portals or interfaces corresponding to resources. Typically, an access endpoint corresponds to a single resource. As the portal or interface for that resource, the access endpoint forwards access requests to that resource to enable access. Common access endpoints include Virtual Private Cloud Endpoints (VPCEPs). Users can create VPCEPs and map them to their own resources.
[0056] A Virtual Private Cloud Endpoint (VPCEP) consists of two resource instances: "Endpoint Service" and "Endpoint Node". The Endpoint Service refers to a cloud service or user-owned private service configured as a service supported by the endpoint, which can be connected to and accessed by the endpoint. The endpoint is used to establish a convenient, secure, and private connection channel between the Virtual Private Cloud (VPC) and the Endpoint Service.
[0057] Object Storage Service (OBS) is a massive object-based storage service that provides users with massive, secure, highly reliable, and low-cost data storage capabilities.
[0058] Service control policy (SCP): A mandatory access control (MAC) policy implemented in organizational management services for users within an organization. A SCP describes a set of permissions. It is a constraint, not an authorization. Users subject to a SCP cannot exceed the set of permissions defined by that policy.
[0059] Network control policy (NCP): This is a policy created by an organization's administrator to restrict connection permissions and / or resource access permissions for endpoints. When an organization's administrator creates an NCP and binds it to a node within the organization (such as the root organizational unit, organizational unit, or user), the connection permissions and / or resource access permissions of all virtual private cloud endpoints within the accounts managed by that node will be controlled by that policy. An NCP is a mandatory access control (MAC) policy; it does not provide permissions itself, but only serves as a constraint.
[0060] VPCEP policy: This is a policy created by the user who created the VPCEP when it was created. This policy, as the VPCEP, is used to restrict users who can access the corresponding resources through the VPCEP and the access operations that can be performed on those resources.
[0061] In one approach, user-created access control policies (such as VPCEP policies) restrict users who access a user's resources via an access endpoint (such as VPCEP), and also restrict the access operations performed on that user's resources through that access endpoint. In other words, access permissions to any user's resources within the organization are controlled by that user, which could potentially lead to the unauthorized use or abuse of the organization's resources.
[0062] To address the above issues, this application provides a resource access control method. In this method, a management platform can record access control policies configured by the organization's administrators for access endpoints, and based on these policies, constrain or control access requests that require forwarding by the access endpoint, thereby preventing unauthorized use or abuse of resources through the access endpoint.
[0063] Next, the resource access control method provided in the embodiments of this application will be described in detail.
[0064] Figure 1 A system architecture that can be used to implement this method is shown. This system architecture may include a management platform 100 and infrastructure 200.
[0065] Infrastructure 200 may include one or more data centers, and each data center may include multiple servers. The servers in Infrastructure 200 can provide resources, for example, to a target organization. Users within the target organization can request resources from Infrastructure 200 by virtue of their membership in the target organization through Management Platform 100. One or more servers in Infrastructure 200 can respond to the request and provide resources to the user. The resources requested by the user can be referred to as the user's resources, and these resources belong to the target organization. Users within the target organization can create access endpoints through Management Platform 100. For example, access endpoints can be created within Infrastructure 200 to utilize the resources within Infrastructure 200 to run the access endpoint.
[0066] Users can map their created access endpoints to one or more resources they have applied for, and send access requests to the resources through the access endpoints to achieve resource access.
[0067] In this embodiment, the management platform 100 can be used by the administrator of the target organization to manage the target organization, such as creating the target organization, adding or deleting users in the target organization, etc. The management platform 100 can also be used by the administrator of the target organization to manage the resources of the target organization, such as managing access permissions to the resources of the target organization. Specifically, the administrator of the target organization can configure access control policies for access endpoints to manage access permissions to the resources corresponding to those access endpoints. The management platform 100 can receive and record the access control policies configured by the administrator, such as access control policy A1. Access control policy A1 can be applied to the access endpoint and used to indicate the permissions of users inside or outside the target organization to access the corresponding resources through that access endpoint. Under the instruction of the administrator of the target organization, the management platform 100 can associate access control policy A1 with one or more organizational nodes in the target organization, so that access control policy A1 applies to the access endpoints within those one or more organizational nodes. The access endpoints within an organizational node are access endpoints created or owned by users within that organizational node.
[0068] In some embodiments, the management platform 100 may receive and record user-configured access control policies, such as access control policy A2. Access control policy A2 applies to the access endpoint created by the user and is used to indicate the permissions of users inside or outside the target organization to access corresponding resources through the access endpoint.
[0069] When the management platform 100 receives an access request for a resource, it can control the access request based on the access control policy applied to the access endpoint corresponding to the resource. For example, it can allow the access endpoint to send the access request to the resource so that the access request can access the resource, or it can prohibit the access endpoint from sending the access request to the resource so as to prevent the access request from accessing the resource.
[0070] Associating access control policy A1 with one or more organizational nodes allows access control policy A1 to apply to access endpoints within those organizational nodes. Therefore, management platform 100 can perform access control on resources within those one or more organizational nodes based on access control policy A1. Resources within an organizational node refer to the resources of users within that organizational node.
[0071] In some embodiments, the management platform 100 can provide organization management services. Through these services, the administrator of the target organization can create the target organization within the management platform 100. The target organization created through the organization management service includes an administrator and several users. The administrator has user management permissions. User management permissions refer to the permissions to manage users within the organization. The administrator can invite existing users on the management platform to join their organization, or register new users on the management platform, and these newly registered users will automatically join the administrator's organization.
[0072] like Figure 2 As shown, a target organization created through the organization management service can include multiple organizational units (OUs), such as OU310, OU320, and OU330. OU310 is the root organizational unit (ROU). The root organizational unit, also called the root OU, is the root node in the organization's tree structure and is created by default when the organization is created. The root OU corresponds to the administrator, who can manage all users within the organization.
[0073] OU320, OU330, etc., are leaf nodes of OU310, created by the administrator represented by OU310. The administrator can assign multiple users within the organization to different leaf nodes for easier management. For example... Figure 2 As shown, users 321 and 322 within the target organization belong to OU320, and user 331 within the target organization belongs to OU330.
[0074] In some embodiments, users within the target organization can also be referred to as Segregation of Duty (SOD) units. These are the smallest units in the management platform with specific operational permissions and resources, satisfying the principle of separation of responsibilities and permissions between business departments and personnel. The management platform can assign a user identifier to each user. Different users have different user identifiers, which can be used to distinguish between them. Furthermore, there is a mapping relationship between the user identifier, the user's organization, and the Organizational Unit (OU). Thus, the user's organization and OU can be obtained through their user identifier.
[0075] In some embodiments, the user identifier can be an account. In some embodiments, the user identifier can be a subscription. In some embodiments, the user identifier can be a project.
[0076] In some embodiments, Figure 2 The tree structure shown allows for hierarchical management of the target organization using organizational compliance control policies. These policies can be used to manage users within the target organization, such as managing user resources or user behavior. Thus, access control policy A1 can be configured as an organizational compliance control policy to manage users within the target organization.
[0077] like Figure 2 As shown, each user has resources. For example, user 321 has resources 2101 and 2102, user 322 has resource 220, and user 331 has resource 230. A user's resources are those resources that the user requests from infrastructure 200 through management platform 100.
[0078] Users can utilize their resources to perform related business. These resources belong to the user's organization and are considered the organization's resources.
[0079] Users can create access endpoints and map them to their resources. For example, user 321 can create access endpoints 2111 and 2112, mapping access endpoint 2111 to resource 2101 and access endpoint 2112 to resource 2102. User 322 can create access endpoint 221 and map it to resource 220. User 331 can create access endpoint 231 and map it to resource 230.
[0080] In some embodiments, the administrator of the target organization can associate access control policy A1 with any one or more OUs within the target organization. For example, Figure 2As shown, by associating access control policy A1 with OU320, access control policy A1 can be applied to access endpoints within OU320, such as access endpoint 2111, access endpoint 2112, and access endpoint 221. In this way, management platform 100 can control access requests to resources within OU320 based on access control policy A1.
[0081] In some embodiments, such as Figure 3 As shown, the administrator of the target organization can associate access control policy A1 with one or more users in the target organization, such as user 321. Then, access control policy A1 can be applied to access endpoint 2111 and access endpoint 2112. In this way, the management platform 100 can control user 321's access requests to resources based on access control policy A1.
[0082] The above example illustrates the system architecture provided in the embodiments of this application. Next, the resource access control method provided in the embodiments of this application will be described in conjunction with this system architecture.
[0083] This method can be executed by a management platform 100. The management platform 100 may include a recording module 110, an acquisition module 120, and a control module 130. Through these modules, the management platform 100 can implement the resource access control method provided in the embodiments of this application. Figure 4 As shown, the method includes the following steps.
[0084] In step 401, the administrator of the target organization can configure access control policy A1 and specify the access endpoints on which access control policy A1 applies. That is, the administrator of the target organization can configure access control policy A1 for one or more access endpoints in the target organization.
[0085] In some embodiments, access control policy A1 may be referred to as network control policy (NCP), which is used to restrict the connection permissions and / or resource access permissions of the access endpoint in order to control access requests for the resources corresponding to the access endpoint.
[0086] In some embodiments, access control policy A1 may include a domain-specific language (DSL) to describe a set of permissions. When access control policy A1 is associated with an organization node (e.g., OU310), it can apply to all access endpoints within that organization node.
[0087] In some embodiments, such as Figure 5As shown, the policy structure of access control policy A1 can include a policy version number and policy permission statements. The policy permission statements can include multiple statements, such as effect, action, condition, and resource type.
[0088] like Figure 6 As shown, the policy version number refers to the version of the policy, for example, 1.1.
[0089] The `effect` property defines whether an operation within an authorization item is allowed to be executed. `effect` can be categorized as either "allow" or "deny". When the same authorization item has both "allow" and "deny" effects, the "deny" effect takes precedence.
[0090] Authorization items refer to operation permissions. The format of authorization items can be "service name:resource type:operation". For example, an authorization item can be represented as "obs:bucket:listallmybuckets", where obs is the service name, bucket is the resource type, and listallmybuckets is the operation.
[0091] The meaning of "condition" is: it refers to the conditions under which an access control policy takes effect, including the condition key and the operator. The format of a condition can be "operator:
[0092] The access control policy is defined as `{condition key: [condition key 1, condition key 2]}`. If multiple conditions are set, the access control policy takes effect when all conditions are met simultaneously. For example, `"stringendwithifexists": {"g:username": ["specialcharacter"]}` means that the access control policy takes effect when the username entered by the user ends with "specialcharacter".
[0093] The resource type refers to the resource to which the access control policy applies. The format of a resource type can be "service name:region:domainld:resource type:resource path". Wildcard characters * are supported for resource types. In one example, "obs:*:*:bucket:*" represents all OBS buckets. Specifically, the resource to which the access control policy applies is the resource corresponding to the access endpoint targeted by the access control policy.
[0094] In step 402, the recording module 110 may, in response to an instruction from the administrator of the target organization, record access control policy A1 and the access endpoints targeted by access control policy A1, i.e., record which access endpoints (e.g., access endpoint C1) access control policy A1 is configured for by the administrator. The access control policy operates on the access endpoints it targets to control access requests to the resources corresponding to those endpoints. The access endpoints targeted by access control policy A1 are the access endpoints of users within the target organization.
[0095] In some embodiments, the recording module 110 can associate access control policy A1 with one or more organizational nodes in the target organization and record this association. The access endpoint of a user within the organizational node associated with access control policy A1 is the access endpoint targeted by access control policy A1. Thus, by recording the association between access control policy A1 and the organizational node, the access endpoint targeted by access control policy A1 is recorded. In one example, the organizational node associated with access control policy A1 can be an OU or a user. An OU includes multiple users, and users can be represented by user identifiers. In one example, a user identifier can specifically be a user account.
[0096] In some embodiments, the recording module 110 may associate access control policy A1 with one or more access endpoints in the target organization and record the association. The access endpoint associated with access control policy A1 is the access endpoint targeted by access control policy A1.
[0097] In some embodiments, the recording module 110 may record the access control policy A1 and the access endpoint targeted by the access control policy A1 into the database.
[0098] In step 403, the acquisition module 120 acquires the access request B1 issued by the user. The user issuing access request B1 can be a user outside the target organization or a user within the target organization. The access request is used to access resources within the target organization. For ease of description, the resource to be accessed by the access request can be referred to as the target resource of the access request.
[0099] In step 404, the acquisition module 120 can identify that the access request B1 requests to access the access endpoint C1.
[0100] As mentioned above, an access request needs to be forwarded through the access endpoint corresponding to its target resource in order to reach the target resource and achieve access to the target resource. The access endpoint C1 invoked by access request B1 is the access endpoint corresponding to the target resource of access request B1, and access request B1 needs to be forwarded through access endpoint C1 to reach the target resource.
[0101] In some embodiments, access request B1 carries an identifier of the access endpoint it requests to invoke. In step 404, the acquisition module 120 can obtain the identifier of the access endpoint from access request B1, and based on the identifier of the access endpoint, identify that access request B1 requests to invoke access endpoint C1.
[0102] In some embodiments, access request B1 carries the identifier of its target resource, and the recording module 110 records the association between the resource identifier and the identifier of the access endpoint corresponding to the resource. In step 404, the acquisition module 120 can obtain the identifier of the target resource from access request B1, obtain the association between the resource identifier and the identifier of the access endpoint corresponding to the resource from the recording module 110, and then, based on the identifier of the target resource and the association, identify that access request B1 requests to call access endpoint C1.
[0103] After recognizing that access request B1 requests access to endpoint C1, the acquisition module 120 can send an authentication request to the control module 130 through step 405. The authentication request includes the identifier of the access endpoint C1.
[0104] The control module 130 can respond to the authentication request and authenticate the access request B1. Specifically, this may include the following steps.
[0105] In step 406, the control module 130 can obtain the identifier of access endpoint C1 from the authentication request and send the identifier of access endpoint C1 to the recording module 110. In step 407, the recording module can query the access control policy for access endpoint C1 based on the identifier of access endpoint C1.
[0106] In some embodiments, as described above, access control policies are associated with organization nodes. In step 407, the organization node to which access endpoint C1 belongs can be queried. Then, the access control policy associated with the organization node to which access endpoint C1 belongs is used as the access control policy for access endpoint C1.
[0107] For example, the recording module 110 also records the association between access endpoint C1 and the organizational node to which access endpoint C1 belongs. For instance, when a user creates an access endpoint within an organizational node, the created access endpoint can be associated with that organizational node, and the association relationship can be recorded. Specifically, this association relationship is the association between the identifier of the access endpoint and the identifier of the organizational node. In step 407, the organizational node to which access endpoint C1 belongs can be queried based on the identifier of access endpoint C1 and this association relationship.
[0108] For example, the recording module 110 also records the association between access endpoint C1 and the user to which access endpoint C1 belongs. Specifically, this association is the association between the identifier of the access endpoint and the identifier of the user. In step 407, the user to which access endpoint C1 belongs can be queried based on the identifier of access endpoint C1 and this association. Then, the access control policy associated with the organization node to which the user to which access endpoint C1 belongs is used as the organization node to which access endpoint C1 belongs.
[0109] The access control policy for endpoint C1 can be retrieved by following the steps above. The access control policy for endpoint C1 can be set to access control policy A1.
[0110] In step 408, the recording module 110 can send access control policy A1 to the control module 130. In step 409, the control module 130 can determine whether access request B1 conforms to access control policy A1. Specifically, based on access control policy A1, policy calculation can be performed on access request B1, and the calculation result can indicate whether access request B1 conforms to access control policy A1.
[0111] Access control policy A1 specifies the access permissions for accessing resources via access endpoint C1. In step 409, it is determined whether access request B1 has such access permissions. If it does not have such access permissions, access request B1 is confirmed to be inconsistent with access control policy A1. Otherwise, access request B1 is confirmed to be consistent with access control policy A1.
[0112] In some embodiments, the access permission indicated by access control policy A1 is a permitted operation type. If the operation type that access request B1 intends to perform on the resource is a permitted operation type, then access request B1 is confirmed to have that access permission. Otherwise, access request B1 is confirmed not to have that access permission.
[0113] In some embodiments, access control policy A1 may indicate prohibited operation types. If the operation type that access request B1 intends to perform on the resource is not a prohibited operation type, then access request B1 is confirmed to have the required access permission. Otherwise, access request B1 is confirmed to not have the required access permission.
[0114] In some embodiments, access control policy A1 indicates the users allowed to access the service. If the user issuing access request B1 is an allowed user, then access request B1 is confirmed to have that access permission. Otherwise, access request B1 is confirmed to not have that access permission.
[0115] In some embodiments, access control policy A1 indicates users who are prohibited from access. If the user issuing access request B1 is not a prohibited user, then access request B1 is confirmed to have the required access rights. Otherwise, access request B1 is confirmed to not have the required access rights.
[0116] In some embodiments, access control policy A1 indicates the access rights of a user within the target organization to access a resource through access endpoint C1, and access request B1 is issued by a user within the target organization.
[0117] In one example of this embodiment, the user issuing access request B1 could be the user who created access endpoint C1. The user who created access endpoint C1 is also the user who applied for and possesses the resources corresponding to access endpoint C1. In this example, the administrator can control the user's use of the user's resources through access control policies, thus preventing the unreasonable use of resources.
[0118] In one example of this embodiment, the user issuing access request B1 can be another user within the target organization; other users refer to users other than the user who created access endpoint C1. In this example, the organization's administrator can control the scope of resource sharing within the organization through access control policies, thus preventing the unreasonable use of resources.
[0119] In some embodiments, access control policy A1 instructs a user outside the target organization to access resources through access endpoint C1, and access request B1 is issued by the user outside the target organization. In this way, administrators can use access control policies to control access to organizational resources by users outside the organization, thereby protecting the organization's resource security.
[0120] In step 410, the control module 130 may send an authentication result to the acquisition module 120 based on the judgment result of step 409. Specifically, if the judgment result of step 409 is that access request B1 conforms to access control policy A1, an authentication result indicating successful authentication is sent to the acquisition module 120. Otherwise, an authentication result indicating authentication failure is sent to the acquisition module 120.
[0121] In some embodiments, the user who creates access endpoint C1 can configure access control policy A2 for access endpoint C1, and the recording module 110 can record access control policy A2. For example... Figure 7As shown, before executing step 409, step 701 is executed first to determine whether access request B1 conforms to access control policy A2. The specific determination method can be found above and will not be repeated here. If the determination result of step 701 is that access request B1 conforms to access control policy A2, then step 409 is executed. If the determination result of step 701 is that access request B1 does not conform to access control policy A2, then an authentication failure result is directly sent to the acquisition module 120, without needing to execute step 409. In other words, an authentication success result is only obtained if access request B1 conforms to both access control policy A1 and access control policy A2.
[0122] Continue reading Figure 4 After obtaining the authentication result, the acquisition module 120 can, in step 411, allow or prohibit the access endpoint C1 from forwarding access request B1 to the corresponding resource based on the authentication result. Here, the corresponding resource refers to the target resource of access request B1. When the authentication result indicates successful authentication, the acquisition module 120 allows the access endpoint C1 to forward access request C1 to the target resource, thereby enabling access request C1 to access the target resource. When the authentication result indicates authentication failure, the acquisition module 120 prohibits the access endpoint C1 from forwarding access request C1 to the target resource, thereby preventing access request C1 from accessing the target resource.
[0123] In some embodiments, the acquisition module 120 can also provide feedback on the access result to the user who issued the access request C1. Specifically, when access endpoint C1 is allowed to forward access request C1 to the target resource, a successful access result can be provided. When access endpoint C1 is prohibited from forwarding access request C1 to the target resource, an access failure result can be provided.
[0124] In summary, an organization's administrators can configure access control policies for access endpoints. These policies can control whether access endpoints forward access requests, thereby controlling access to organizational resources and preventing unreasonable use or loss of organizational resources.
[0125] Based on the above description, this application also provides a resource control method. This method is applied to the aforementioned management platform 100. The management platform 100 manages multiple access endpoints and multiple resources of a target organization. The multiple resources are provided by multiple servers in infrastructure 200, and these servers are located in the same or multiple data centers within the infrastructure. Each access endpoint corresponds to at least one of the multiple resources, and each access endpoint is used to forward access requests for that resource to the resource corresponding to that access endpoint. Figure 8As shown, the method includes the following steps.
[0126] Step 801: The management platform 100 records the access control policy A1 configured by the administrator of the target organization for the target access endpoint, wherein the target access endpoint is at least one of multiple access endpoints of the target organization. The target access endpoint may be the access endpoint C1 described above.
[0127] The administrator can configure access control policy A1 for at least one access endpoint within the target organization and indicate the access endpoint targeted by access control policy A1 to the management platform 100. In this way, the management platform 100 can record access control policy A1 and the access endpoint targeted by access control policy A1. For details, please refer to the above text. Figure 4 The details of steps 401-402 will not be repeated here.
[0128] Step 802: The management platform 100 obtains a target access request for a target resource, wherein the target resource is the resource among the plurality of resources corresponding to the target access endpoint. The target access request may be access request B1 as described above.
[0129] Users outside or within the target organization can initiate access requests to one or more resources within the target organization; these resources can be referred to as target resources. The management platform 100 can identify the access endpoint corresponding to the target resource as the target access endpoint. For details, please refer to the above section. Figure 4 The details of steps 403-404 will not be repeated here.
[0130] Step 803: Based on access control policy A1, management platform 100 allows or prohibits the target access endpoint from forwarding the target access request to the target resource.
[0131] The management platform 100 records the access control policy for the target access endpoint, namely control policy A1. When the access endpoint corresponding to the target resource is identified as the target access endpoint, access to the target resource by the target access request can be controlled based on access control policy A1. Specifically, when the target access request conforms to access control policy A1, the target access endpoint is allowed to forward the target access request to the target resource. When the target access request does not conform to access control policy A1, the target access endpoint is prohibited from forwarding the target access request to the target resource. For details, please refer to the above text. Figure 4 The details of steps 405-410 will not be repeated here.
[0132] In some embodiments, the target access endpoint is created by a first user within the target organization, and the management platform 100 also records the access control policy A2 configured by the first user for the target access endpoint. The management platform 100, based on access control policy A1, allows or prohibits the target access endpoint from forwarding the target access request to the target resource, including: the management platform 100, based on access control policy A1 and access control policy A2, allows or prohibits the target access endpoint from forwarding the target access request to the target resource.
[0133] The user who creates the target access endpoint can also control access to resources by configuring access control policies. Specifically, if an access request conforms to both the user-configured access control policy (access control policy A2) and the administrator-configured access control policy (access control policy A1), the target access endpoint is allowed to forward the target access request to the target resource. If the access request does not conform to both the user-configured access control policy and / or the administrator-configured access control policy, the target access endpoint is prohibited from forwarding the target access request to the target resource. See the above for details. Figure 7 The description of the illustrated embodiments will not be repeated here.
[0134] In some embodiments, the management platform 100 records the access control policy A1 configured by the administrator of the target organization for the target access endpoint, including: the management platform 100 associating the access control policy A1 with the organization node of the target organization, wherein the organization node is an organizational unit (OU) or a first user within the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint was created by the first user. Based on the access control policy A1, the management platform 100 allows or prohibits the target access endpoint from forwarding the target access request to the target resource, including: when the management platform 100 confirms that the target access endpoint belongs to the organization node, it allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the access control policy A1.
[0135] By associating access control policy A1 with an organization node, access control policy A1 can be applied to the corresponding access endpoints simply and quickly, without needing to configure access control policies for each access endpoint individually. Furthermore, when performing resource access control, the access control policy for the target access endpoint can be quickly retrieved by identifying the organization node to which the target access endpoint belongs, thus improving access control efficiency.
[0136] In one example of this embodiment, the method further includes: recording the association between the identifier of the target access endpoint and the identifier of the first user. Confirming that the target access endpoint belongs to the organization node includes: obtaining the identifier of the target access endpoint from the target access request; and confirming that the target access endpoint belongs to the organization node based on the identifier of the target access endpoint and the association.
[0137] Typically, when an access endpoint is created, the management platform 100 can record the identifier of the access endpoint and its associated relationships. Access requests usually also include the identifier of the access endpoint that the access request requests to invoke. Thus, by using the identifier and associated relationships of the access endpoint carried in the access request, it can be confirmed that the access endpoint was created by the first user, and further, it can be confirmed that the access endpoint belongs to the organization node to which the first user belongs.
[0138] In some embodiments, access control policy A1 indicates the permission of a user within the target organization to access the target resource through the target access endpoint, wherein the target access request is initiated by a first user or a second user within the target organization; wherein the target access endpoint is created by the first user, and the second user is a user within the target organization other than the first user.
[0139] In this embodiment, the organization's administrator can use access control policies to prevent users within the organization from misusing the organization's resources.
[0140] In some embodiments, access control policy A1 indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, wherein the target access request is initiated by the user outside the target organization.
[0141] In this embodiment, the organization's administrator can use access control policies to prevent unauthorized users from using the organization's resources.
[0142] In some embodiments, the target access endpoint is a VPCEP.
[0143] The method provided in this application embodiment allows the administrator to configure access control policies to control whether access endpoints forward access requests, thereby enabling the administrator to control access to organizational resources through access control policies and avoiding unreasonable use of organizational resources and loss of organizational resources.
[0144] Based on the above description of the method embodiments, this application also provides a management platform 900. The management platform 900 is used to manage multiple access endpoints and multiple resources of a target organization. The multiple resources are provided by multiple servers in an infrastructure, and the multiple servers are located in the same or multiple data centers within the infrastructure. Each of the multiple access endpoints corresponds to at least one of the multiple resources, and the access endpoint is used to forward access requests for that resource to the resource corresponding to that access endpoint. Figure 9 As shown, the management platform 900 includes:
[0145] The recording module 910 is used to record the first access control policy configured by the administrator of the target organization for the target access endpoint, wherein the target access endpoint is at least one of the plurality of access endpoints;
[0146] The acquisition module 920 is used to acquire a target access request for a target resource, wherein the target resource is the resource among the plurality of resources that corresponds to the target access endpoint;
[0147] The control module 930 is configured to allow or prohibit the target access endpoint from forwarding the target access request to the target resource based on the first access control policy.
[0148] In some embodiments, the target access endpoint is created by a first user within the target organization, and the management platform also records a second access control policy configured by the first user for the target access endpoint; the control module 930 is used to: allow or prohibit the target access endpoint from forwarding the target access request to the target resource based on the first access control policy and the second access control policy.
[0149] In some embodiments, the recording module 910 is configured to: associate a first access control policy with an organization node of the target organization, wherein the organization node is an organizational unit (OU) or a first user within the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; the control module 930 is configured to: upon confirming that the target access endpoint belongs to the organization node, allow or prohibit the target access endpoint from forwarding the target access request to the target resource based on the first access control policy.
[0150] In some embodiments, the recording module 910 is further configured to: record the association between the identifier of the target access endpoint and the identifier of the first user; the control module 930 is configured to: obtain the identifier of the target access endpoint from the target access request; and confirm that the target access endpoint belongs to the organization node based on the identifier of the target access endpoint and the association.
[0151] In some embodiments, the first access control policy indicates the permission of a user within the target organization to access the target resource through the target access endpoint, wherein the target access request is initiated by a first user or a second user within the target organization; wherein the target access endpoint is created by the first user, and the second user is a user within the target organization other than the first user.
[0152] In some embodiments, the first access control policy indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, wherein the target access request is initiated by the user outside the target organization.
[0153] In some embodiments, the target access endpoint is a Virtual Private Cloud Endpoint Node (VPCEP).
[0154] The recording module 910, acquisition module 920, and control module 930 can all be implemented in software or in hardware. For example, the implementation of the recording module 910 will be described below. Similarly, the implementation of the acquisition module 920 and control module 930 can refer to the implementation of the recording module 910.
[0155] As an example of a software functional unit, the recording module 910 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, or a container. Further, the aforementioned computing instance may be one or more. For example, the recording module 910 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same Availability Zone (AZ) or in different AZs, each AZ including one or more geographically proximate data centers. Typically, a region may include multiple AZs.
[0156] Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same VPC or across multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, as well as between VPCs in different regions, requires a communication gateway to be set up within each VPC to enable interconnection between VPCs.
[0157] As an example of a hardware functional unit, the recording module 910 may include at least one computing device, such as a server. Alternatively, the recording module 910 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be implemented using a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.
[0158] The multiple computing devices included in the recording module 910 can be distributed in the same region or in different regions. Similarly, the multiple computing devices included in the recording module 910 can be distributed in the same Availability Zone (AZ) or in different AZs. Likewise, the multiple computing devices included in the recording module 910 can be distributed in the same Virtual Private Cloud (VPC) or in multiple VPCs. These multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0159] It should be noted that, in other embodiments, the recording module 910 can be used to perform... Figure 8 In any step of the method shown, module 920 can be used to execute... Figure 8 The control module 930 can be used to execute any step in the method shown. Figure 8 Any step in the method shown. The steps implemented by the recording module 910, the acquisition module 920, and the control module 930 can be specified as needed, and implemented by the recording module 910, the acquisition module 920, and the control module 930 respectively. Figure 8 The different steps in the method shown are used to implement all the functions of the management platform 900.
[0160] This application also provides a computing device 1000. For example... Figure 10As shown, the computing device 1000 includes a bus 1002, a processor 1004, a memory 1006, and a communication interface 1008. The processor 1004, the memory 1006, and the communication interface 1008 communicate with each other via the bus 1002. The computing device 1000 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 1000.
[0161] Bus 1002 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 10 The bus 1002 may be represented by a single line, but this does not mean that there is only one bus or one type of bus. The bus 1002 may include a path for transmitting information between various components of the computing device 1000 (e.g., memory 1006, processor 1004, communication interface 1008).
[0162] Processor 1004 may include a central processing unit (CPU) and a graphics processing unit (GPU).
[0163] Processing unit (GPU), microprocessor (MP), or digital signal processor (DSP) are any one or more of the following: processing unit (GPU), microprocessor (MP), or digital signal processor (DSP).
[0164] The memory 1006 may include volatile memory, such as random access memory (RAM). The memory 1006 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0165] The memory 1006 stores executable program code, and the processor 1004 executes the executable program code to implement the functions of the aforementioned recording module 910, acquisition module 920, and control module 930, thereby achieving... Figure 8 The method shown. That is, the memory 1006 stores the method for execution. Figure 8The instructions for the method shown.
[0166] The communication interface 1008 uses transceiver modules such as, but not limited to, network interface cards and transceivers to enable communication between the computing device 1000 and other devices or communication networks.
[0167] This application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.
[0168] like Figure 11 As shown, the computing device cluster includes at least one computing device 1000. The memory 1006 of one or more computing devices 1000 in the computing device cluster may store the same memory for executing... Figure 8 The instructions for the method shown.
[0169] In some possible implementations, the memory 1006 of one or more computing devices 1000 in the computing device cluster may also store memory for execution. Figure 8 The instructions of the method shown are partial. In other words, a combination of one or more computing devices 1000 can jointly execute instructions for performing... Figure 8 The instructions for the method shown.
[0170] It should be noted that the memory 1006 in different computing devices 1000 within the computing device cluster can store different instructions, which are used to execute certain functions of the management platform 900. That is, the instructions stored in the memory 1006 of different computing devices 1000 can implement the functions of one or more modules among the recording module 910, the acquisition module 920, and the control module 930.
[0171] In some possible implementations, one or more computing devices in a computing device cluster can be connected via a network. This network can be a wide area network (WAN) or a local area network (LAN), etc. Figure 12 One possible implementation is shown. For example... Figure 12 As shown, two computing devices 1000A and 1000B are connected via a network. Specifically, they are connected to the network through communication interfaces in each computing device. In this possible implementation, the memory 1006 in computing device 1000A stores instructions for executing the functions of the recording module 910. Simultaneously, the memory 1006 in computing device 1000B stores instructions for executing the functions of the acquisition module 920 and the control module 930.
[0172] It should be understood that Figure 12The functions of computing device 1000A shown can also be performed by multiple computing devices 1000. Similarly, the functions of computing device 1000B can also be performed by multiple computing devices 1000.
[0173] This application also provides another computing device cluster. The connection relationships between the computing devices in this computing device cluster can be similarly referred to... Figure 11 and Figure 12 The connection method of the computing device cluster. The difference is that the memory 1006 of one or more computing devices 1000 in this computing device cluster can store the same data for execution. Figure 8 The instructions for the method shown.
[0174] In some possible implementations, the memory 1006 of one or more computing devices 1000 in the computing device cluster may also store memory for execution. Figure 8 The instructions of the method shown are partial. In other words, a combination of one or more computing devices 1000 can jointly execute instructions for performing... Figure 8 The instructions for the method shown.
[0175] This application also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions, capable of running on a computing device or stored on any usable medium. When the computer program product is run on at least one computing device, it causes the at least one computing device to perform... Figure 8 The method shown.
[0176] This application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store, or a host migration device such as a data center that includes one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute... Figure 8 The method shown.
[0177] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of this application.
Claims
1. A resource access control method characterized by, The method is applied to a management platform for managing a plurality of access endpoints and a plurality of resources of a target organization, wherein the plurality of resources are provided by a plurality of servers in an infrastructure, the plurality of servers are arranged in the same data center or a plurality of data centers in the infrastructure, each of the plurality of access endpoints corresponds to at least one of the plurality of resources, and the access endpoint is used to forward an access request for the resource corresponding to the access endpoint to the resource; the method comprises: The management platform records a first access control policy configured by an administrator of the target organization for a target access endpoint, and the target access endpoint is at least one of the plurality of access endpoints; The management platform obtains a target access request for a target resource, and the target resource is a resource corresponding to the target access endpoint in the plurality of resources; The management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy.
2. The method of claim 1, wherein, The target access endpoint is created by a first user in the target organization, and the management platform also records a second access control policy configured by the first user for the target access endpoint; The management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy, comprising: the management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy and the second access control policy.
3. The method of claim 1 or 2, wherein The management platform records a first access control policy configured by an administrator of the target organization for a target access endpoint, comprising: the management platform associates the first access control policy with an organization node of the target organization, the organization node is an organization unit OU or a first user in the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; The management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy, comprising: the management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy under the condition that the target access endpoint belongs to the organization node.
4. The method of claim 3, wherein The method further comprises: recording an association relationship between an identifier of the target access endpoint and an identifier of the first user; The confirmation that the target access endpoint belongs to the organization node comprises: Obtaining the identifier of the target access endpoint from the target access request; Based on the identifier of the target access endpoint and the association relationship, it is confirmed that the target access endpoint belongs to the organization node.
5. The method of any one of claims 1-4, wherein The first access control policy indicates a permission of a user in the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a first user or a second user in the target organization; the target access endpoint is created by the first user, and the second user is a user in the target organization other than the first user; Or, The first access control policy indicates a permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a user outside the target organization.
6. The method according to any one of claims 1-5, characterized in that, The target access endpoint is a virtual private cloud terminal node VPCEP.
7. A management platform, characterized by The management platform is configured to manage a plurality of access endpoints and a plurality of resources of a target organization, wherein the plurality of resources are provided by a plurality of servers in an infrastructure, the plurality of servers are arranged in a same data center or a plurality of data centers in the infrastructure, each of the plurality of access endpoints corresponds to at least one of the plurality of resources, and the access endpoint is configured to forward an access request for the resource corresponding to the access endpoint to the resource; the management platform comprises: A recording module configured to record a first access control policy configured by an administrator of the target organization for a target access endpoint, the target access endpoint being at least one of the plurality of access endpoints; An obtaining module configured to obtain a target access request for a target resource, the target resource being a resource corresponding to the target access endpoint in the plurality of resources; A control module configured to allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy.
8. The management platform of claim 7, wherein, The target access endpoint is created by a first user in the target organization, and the management platform further records a second access control policy configured by the first user for the target access endpoint; The control module is configured to allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy and the second access control policy.
9. The management platform of claim 7 or 8, wherein The recording module is configured to associate the first access control policy with an organization node of the target organization, the organization node being an organization unit OU in the target organization or a first user, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; The control module is configured to, based on a confirmation that the target access endpoint belongs to the organization node, allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy.
10. The management platform of claim 9, wherein The recording module is further configured to record an association relationship between an identifier of the target access endpoint and an identifier of the first user; The control module is configured to: Obtain the identifier of the target access endpoint from the target access request; Based on the identification of the target access endpoint and the association relationship, it is confirmed that the target access endpoint belongs to the organization node. 11.The management platform of any one of claims 7-10, characterized in that, the first access control policy indicates the permission of a user in the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a first user or a second user in the target organization; wherein the target access endpoint is created by the first user, and the second user is a user in the target organization other than the first user; or, the first access control policy indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a user outside the target organization.
12. The management platform of any one of claims 7-11, wherein, The target access endpoint is a virtual private cloud terminal node VPCEP.
13. A cluster of computing devices, characterized in that, comprise at least one computing device, each computing device comprising a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the cluster of computing devices to perform the method of any one of claims 1-6.
14. A computer-readable storage medium, characterized in that, comprise computer program instructions which, when executed by a cluster of computing devices, cause the cluster of computing devices to perform the method of any one of claims 1-6.
15. A computer program product comprising instructions, characterized in that, when the instructions are executed by a cluster of computing devices, cause the cluster of computing devices to perform the method of any one of claims 1-6.