A cloud resource access control method based on cloud computing technology and a cloud management platform

CN122802180APending Publication Date: 2026-09-22HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610636614.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-08-15
Filing Date
2023-02-07
Publication Date
2026-09-22

AI Technical Summary

Technical Problem

[0007]但是现有的组织管理服务提供的组织合规控制策略往往仅能对账号内的身份进行约束,无法对账号内的资源进行约束

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122802180A_ABST
    Figure CN122802180A_ABST
Patent Text Reader

Abstract

The application provides a cloud resource access control method based on cloud computing technology, applied to a cloud management platform, and the method comprises the following steps: the cloud management platform acquires and records a first resource control strategy configured by an administrator of a target organization for a target cloud resource in the target organization, wherein the first resource control strategy is used for indicating the access permission of a user outside the target organization to the target cloud resource; the cloud management platform acquires a first resource access request triggered by the user outside the target organization for the target cloud resource in the target organization; and the cloud management platform allows or rejects the first resource access request to access the target cloud resource according to the first resource control strategy recorded by itself. The cloud resource access control method based on cloud computing technology provided by the application can restrict the access of the user outside an organization to the cloud resource in the organization.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to Chinese Patent Application No. 202210972620.6, filed on August 15, 2022, entitled "An Access Control Method and Apparatus Based on Organizational Resources", the entire contents of which are incorporated herein by reference.

[0002] This application is a divisional application. The original application has the application number 202310076418.X and the original application date is February 7, 2023. The entire contents of the original application are incorporated herein by reference. Technical Field

[0003] This application relates to the field of computer technology, and in particular to a cloud resource access control method and cloud management platform based on cloud computing technology. Background Technology

[0004] To meet enterprise clients' needs for unified management of identity and resources, IT systems need to provide organizational management services. These services primarily offer three capabilities to clients: A Separation of Duty Unit (SoD Unit) is the smallest unit used to configure different operational permissions and host different cloud resources, in order to meet the principle of separating responsibilities and permissions among different business departments and operational personnel within an enterprise. Different cloud vendors use different names for SoD Units; for example, SoD Units may be called Account, Subscription, and Project.

[0005] Hierarchical management is a common practice in enterprises, where companies typically have a top-down tree-like organizational structure. The ability of hierarchical management is to organize SoD units in a tree-like structure, making it easier for operators in various departments of the enterprise to manage them.

[0006] Organizational compliance control strategies require enterprises to have unified compliance control capabilities over operational personnel and resources applied for in the cloud, such as controlling access boundaries for cloud data storage. Organizational compliance control strategies are a type of mandatory access control (MAC) policy imposed on the entire organization or certain organizational units. It's important to note that, unlike discretionary access control (DAC), mandatory access control is not an authorization but a constraint; objects affected by mandatory access control policies will not have permissions exceeding the scope defined by the policy.

[0007] However, existing organizational management services often only restrict the identity within an account, and cannot restrict the resources within the account. Summary of the Invention

[0008] The embodiments of this application provide a cloud resource access control method based on cloud computing technology. The resource control strategy directly acts on resources within the organization, constrains access to resources within the organization, and enables the restriction of access to cloud resources within the organization by users outside the organization.

[0009] Firstly, this application provides a cloud resource access control method based on cloud computing technology. This method is applied to a cloud management platform for managing infrastructure providing multiple cloud resources. The infrastructure includes at least one cloud data center, each cloud data center having multiple servers. One or any combination of the multiple cloud resources is deployed on at least one server in the infrastructure, and the multiple cloud resources are located within at least one organization. The method includes: the cloud management platform acquiring and recording a first resource control policy configured by the administrator of the target organization for target cloud resources within the target organization, wherein the first resource control policy is used to instruct users outside the target organization on access rights to the target cloud resources; the cloud management platform acquiring a first resource access request triggered by a user outside the target organization for target cloud resources within the target organization; and the cloud management platform allowing or denying the first resource access request to access the target cloud resources according to its recorded first resource control policy.

[0010] The cloud resource access control method based on cloud computing technology provided in this application directly applies the resource control policy to cloud resources within an organization, constrains access to cloud resources within the organization, enables organizational administrators to perform unified access control management of cloud resources within the organization, and enables the restriction of access to cloud resources within the organization by users outside the organization. For example, it can overcome the problem of resources being frequently shared across accounts in an organization with multiple accounts, and control resources within the organization to prevent unauthorized access by users outside the organization.

[0011] For example, the first resource control strategy includes a first constraint condition, which is used to restrict the accessing user to belong to the target organization. When the resource access request is triggered by a user outside the target organization, that is, when the accessing user does not meet the first constraint condition, the first resource access request to access the target resource is rejected.

[0012] In one possible implementation, the cloud resource access control method based on cloud computing technology provided in this application further includes: a cloud management platform acquiring and recording a second resource control policy configured by the administrator of the target organization for the target cloud resources within the target organization, wherein the second resource control policy is used to instruct users within the target organization on access rights to the target cloud resources; the cloud management platform acquiring second resource access requests for the target cloud resources within the target organization triggered by users within the target organization; and the cloud management platform allowing or denying the second resource access requests to access the target cloud resources according to its recorded second resource control policy.

[0013] In this possible implementation, a second resource control strategy is used to control users' access to cloud resources within the organization. For example, users in different departments can be restricted to accessing cloud resources under their respective departments, thus achieving more granular resource management.

[0014] For example, the second resource control strategy includes a second constraint condition, which is used to restrict the accessing user to belong to the target organization node. When the access request is triggered by a user within the target organization, but the user is not a node of the target organization, the accessing user does not meet the second constraint condition, and the first resource access request is rejected from accessing the target resource.

[0015] In another possible implementation, before the cloud management platform obtains and records the first resource control policy configured by the administrator of the target organization for the target cloud resources within the target organization, the cloud resource access control method based on cloud computing technology provided in this application further includes: the cloud management platform obtaining multiple registration requests carrying different user accounts; the cloud management platform registering and recording multiple user accounts according to the multiple registration requests, wherein the multiple user accounts include the administrator's account; the cloud management platform assigning the multiple user accounts to the target organization, and setting the administrator's account as the administrator account of the target organization.

[0016] In other words, you need to register on the cloud management platform before using cloud services. You can register multiple accounts and manage them in an organizational structure. Each account corresponds to a specific cloud resource. For example, if the organization is a corporate organization, different accounts can be registered for each member of the organization. Members with different levels or belonging to different departments can use different cloud resources under the corporate organization.

[0017] In another possible implementation, the first resource access request carries a user account registered on the cloud management platform by a user outside the target organization. The cloud management platform obtains the resource access request for the target cloud resource within the target organization triggered by the user outside the target organization, including: if the cloud management platform determines that the user account carried in the first resource access request does not belong to the multiple user accounts corresponding to the target organization, it determines that the first resource access request was triggered by a user outside the target organization.

[0018] In other words, if an access request comes from another user on the cloud who is registered on the cloud but not within the target organization, the cloud management platform will determine that the access request is triggered by a user outside the target organization.

[0019] In another possible implementation, the first resource access request does not carry a user account registered in the cloud management platform. The cloud management platform obtains a resource access request for a target cloud resource within the target organization triggered by a user outside the target organization. This includes: if the cloud management platform determines that the first resource access request does not carry a user account registered in the cloud management platform, it determines that the first resource access request was triggered by a user outside the target organization.

[0020] In this possible implementation, the access request comes from other users off-premises who are not registered on the cloud (i.e., do not have an account). The cloud management platform will identify access requests from such users as being triggered by users outside the target organization.

[0021] For example, the target cloud resource corresponding to the access request is a virtual machine. A webpage is provided on the cloud for public network use. Terminals on the cloud (such as mobile phones or personal computers) can access the public IP (target public IP) of this webpage through their own source public IP.

[0022] In one possible implementation, the cloud resource access control method based on cloud computing technology provided in this application further includes: a cloud management platform obtaining a third resource control policy and obtaining context information of a third resource access request, the context information including IP network segment information, the IP network segment information indicating the IP network segment where the sender of the resource access request is located; the third resource control policy also includes a third constraint condition, the third constraint condition being used to constrain the source public network IP network segment corresponding to the resource access request to belong to a preset IP network segment; when the source public network IP network segment belongs to the preset IP network segment, the user is allowed to access the target cloud resource, that is, the cloud resource access control method based on cloud computing technology provided in this application can prohibit or allow users (including cloud users or on-premises users) of a specific source public network segment to access the target cloud resource.

[0023] In this possible implementation, the resource control policy includes multiple constraints. Only when the resource access request information meets all the constraints will the resource access request pass authentication, providing more granular resource access control. For example, by obtaining the context information of the resource access request information, including the public IP network segment corresponding to the resource access request, the multiple constraints in the resource control policy include that the IP network segment of the resource access request sender belongs to a preset network segment (such as the public network segment where the target organization is located). Only access requests originating from this preset network segment will pass authentication and be allowed to access the target resource.

[0024] In another possible implementation, the resource access request information also includes operation information, which indicates the operation to be performed on the target resource; the resource control policy also includes a fourth constraint, which is used to constrain the operation indicated by the operation information to be a preset operation; the authentication result of the resource access request is also related to the operation information and the third constraint.

[0025] The resource access request information also carries operation information. Multiple constraints in the resource control policy include constraints that indicate that the operation is a preset operation. For example, the preset operation is a read operation. In other words, the access is used to only allow read operations to be performed on the target resource.

[0026] In another possible implementation, the target resource information includes a resource identifier, which is used to uniquely identify the target resource; determining the resource control strategy corresponding to the target resource information includes: querying a preset index table based on the resource identifier to obtain the resource control strategy corresponding to the target resource information, wherein multiple index entries in the index table are determined based on multiple resource identifiers, and the multiple resource identifiers are multiple resource identifiers corresponding to multiple resources within the target organization or the organization node to which the target resource belongs.

[0027] In this possible implementation, the resource identifier is used as an index for the resource control policy, enabling the authentication system to quickly index and obtain the free control policy applied to the target resource for policy calculation.

[0028] In another possible implementation, determining the resource control policy corresponding to the target resource information includes: determining the organizational member to which the target resource belongs based on the target resource information; querying a mapping table to obtain the resource control policies associated with the organizational nodes of the target organization and / or organizational members, wherein the mapping table records the mapping relationship between each organizational node and / or organization and each resource control policy; and determining the resource control policy corresponding to the target resource based on the resource control policies associated with the organizational nodes of the target organization and / or organizational members.

[0029] This provides another way to quickly find the resource control strategy corresponding to the target resource. By determining the organizational member to which the target resource belongs, and then determining the organizational node and / or organization where the organizational member is located, the resource control strategy that applies to the organization and / or organizational node is determined. These resource control strategies are the resource control strategies corresponding to the target resource.

[0030] In another possible implementation, a resource access request is used to invoke the application programming interface (API) to access a target resource in the target cloud service. If the authentication result is successful, the resource access request is responded to, and the access result of the target resource according to the access request is returned to the accessing user. For example, if the resource access request is to perform a read operation on the target resource, the access result is the data of the target resource that has been read.

[0031] In another possible implementation, the first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field. The cloud resource identifier field is used to identify the target cloud resource, the effect field is used to indicate whether access to the target cloud resource is denied or allowed, the request type field is used to identify the request type of the first resource access request, and the condition field is used to indicate users outside the target organization.

[0032] Optionally, cloud resource types include virtual machines and containers for computing services, buckets for object storage services, cloud disks, and cloud databases.

[0033] Secondly, this application provides a cloud management platform for managing infrastructure providing multiple cloud resources. The infrastructure includes at least one cloud data center, each cloud data center has multiple servers, and one or any combination of the multiple cloud resources is deployed on at least one server of the infrastructure. The multiple cloud resources are located in at least one organization. The cloud management platform includes an organization management module, a service module, and an authentication module. The organization management module is used to obtain and record a first resource control policy configured by the administrator of the target organization for the target cloud resources within the target organization. The first resource control policy is used to instruct users outside the target organization on access rights to the target cloud resources. The service module is used to obtain a first resource access request triggered by a user outside the target organization for the target cloud resources within the target organization. The authentication module is used to determine a first authentication result based on the first resource control policy recorded by the organization management module. The first authentication result is to allow or deny the first resource access request to access the target cloud resources. The service module is also used to obtain the first authentication result from the authentication module and allow or deny the first resource access request to access the target cloud resources based on the first authentication result.

[0034] In one possible implementation, the organization management module is further configured to acquire and record a second resource control policy configured by the administrator of the target organization for the target cloud resources within the target organization, wherein the second resource control policy is used to instruct users within the target organization on access rights to the target cloud resources; the service module is further configured to acquire second resource access requests for the target cloud resources within the target organization triggered by users within the target organization; the authentication module is configured to determine a second authentication result based on the second resource control policy recorded by the organization management module, wherein the second authentication result is to allow or deny the second resource access request to access the target cloud resources; the service module is further configured to acquire the second authentication result from the authentication module, and allow or deny the second resource access request to access the target cloud resources based on the second authentication result.

[0035] In another possible implementation, the cloud management platform also includes a registration module, which is used to obtain multiple registration requests carrying different user accounts, register and record multiple user accounts according to the multiple registration requests, including the administrator's account; the organization management module is used to assign the multiple user accounts to the target organization and set the administrator's account as the administrator account of the target organization.

[0036] In another possible implementation, the first resource access request carries a user account registered on the cloud management platform by a user outside the target organization; the service module determines that the first resource access request is triggered by a user outside the target organization if the user account carried in the first resource access request does not belong to one of the multiple user accounts corresponding to the target organization recorded by the registration module.

[0037] In another possible implementation, the first resource access request does not carry a user account registered in the cloud management platform; the service module is used to determine that the first resource access request was triggered by a user outside the target organization if the first resource access request does not carry a user account registered in the cloud management platform.

[0038] In another possible implementation, the first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field. The cloud resource identifier field is used to identify the target cloud resource, the effect field is used to indicate whether access to the target cloud resource is denied or allowed, the request type field is used to identify the request type of the first resource access request, and the condition field is used to indicate users outside the target organization.

[0039] In another possible implementation, cloud resources include virtual machines and containers for computing services, buckets for object storage services, cloud disks, and cloud databases.

[0040] Thirdly, this application provides a server, including a memory and a processor, wherein the memory stores executable code, and the processor executes the executable code to implement the method provided in the first aspect of this application.

[0041] Fourthly, this application provides a computing device, including a memory and a processor, wherein the memory stores executable code, and the processor executes the executable code to implement the method provided in the first aspect of this application.

[0042] Fifthly, this application provides a computer-readable storage medium having a computer program stored thereon, which, when executed in a computer, causes the computer to perform the method provided in the first aspect of this application.

[0043] In a sixth aspect, this application provides a computer program or computer program product, the computer program or computer program product including instructions that, when executed, implement the method provided in the first aspect of this application.

[0044] In a seventh aspect, embodiments of this application also provide a chip, including at least one processor and a communication interface, wherein the processor is used to execute the method described in the first aspect of this application. Attached Figure Description

[0045] Figures 1 to 3 These are schematic diagrams of organizational management service models in related technologies.

[0046] Figure 4 This is a schematic diagram of an SCP that denies access to the s3:GetObject API.

[0047] Figure 5 This is a diagram illustrating how an SCP is bound to the root node of an organization.

[0048] Figure 6 This is a schematic diagram of a scenario where an SCP is bound to the organization's root node and then shared via account sharing.

[0049] Figure 7 A schematic diagram of the architecture of a system that can apply the cloud resource access control method based on cloud computing technology provided in the embodiments of this application is shown.

[0050] Figure 8 This is a flowchart illustrating a cloud resource access control method based on cloud computing technology, provided as an embodiment of this application.

[0051] Figure 9 This diagram illustrates how RCP, after being bound to the root node of a target organization, directly applies to cloud resources within that organization.

[0052] Figure 10 This is a flowchart illustrating another cloud resource access control method based on cloud computing technology provided in an embodiment of this application.

[0053] Figure 11 This illustration shows the implementation process of the resource access control method provided in this application embodiment in a specific application scenario.

[0054] Figure 12 This is a schematic diagram of the structure of a cloud control platform provided in an embodiment of this application.

[0055] Figure 13 This is a schematic diagram of the structure of a computing device provided in an embodiment of this application.

[0056] Figure 14This is a schematic diagram of a computing device cluster provided in an embodiment of this application.

[0057] Figure 15 yes Figure 14 This diagram illustrates an application scenario for a computing device cluster. Detailed Implementation

[0058] The technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.

[0059] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0060] Cloud technology refers to a managed service that unifies a series of resources such as hardware, software, and networks within a wide area network or local area network to enable data computing, storage, processing, and sharing.

[0061] Public cloud refers to a cloud service provided by a third-party provider to users. Public clouds are generally accessible via the internet and may be free or inexpensive. These clouds have numerous instances and provide service across an open public network.

[0062] A private cloud is a cloud infrastructure and hardware / software resources built behind a firewall, allowing various departments within an organization or enterprise to share resources within a data center. A private cloud is a cloud infrastructure that operates entirely for a specific organization; the administrator may be the organization itself or a third party; its location may be internal or external to the organization.

[0063] Hybrid cloud refers to a cloud computing environment composed of private cloud resources and public cloud resources.

[0064] Service control policy (SCP) refers to a mandatory access control policy in organizational services that applies to identities within the organization.

[0065] Resource control policy (RCP) refers to a mandatory access control policy that applies to resources within an organization.

[0066] Cloud Management Platform and Infrastructure: The cloud management platform is used to manage the infrastructure of cloud vendors. The infrastructure consists of multiple cloud data centers located in different regions, with at least one cloud data center in each region. The cloud management platform can provide interfaces related to cloud computing services, such as configuration pages or application program interfaces (APIs), for tenants to access cloud services. Tenants can log in to the cloud management platform with a pre-registered account and password, and after successful login, select and purchase cloud services provided by the cloud data centers in the designated region. Cloud services include object storage services, virtual machine services, container services, or other known cloud services.

[0067] Tenant: The top-level object used to manage cloud services and / or cloud resources. Tenants register tenant accounts and set tenant passwords on the cloud management platform through local clients (such as browsers). Local clients remotely log in to the cloud management platform through the tenant account and set tenant password. The cloud management platform provides a configuration interface or API for tenants to configure and use cloud services, where cloud services are specifically provided by the infrastructure managed by the cloud management platform as described above.

[0068] This application provides a resource access control method that can be applied to any IT system (such as public cloud systems, private cloud systems, and hybrid cloud systems) that requires organized resource management and unified access control. It uses internal resources as the target of organizational control policies to control internal resources and prevent access from external identities, thereby ensuring the security of internal resources.

[0069] The following section uses a public cloud system as an example to describe in detail the specific implementation of the resource access control method provided in this application embodiment. Other IT systems are similar, and for the sake of brevity, they will not be described in detail.

[0070] It is understood that when the resource access control method provided in the embodiments of this application is applied to a public cloud system, it can also be called a cloud resource access control method based on cloud computing technology.

[0071] Most mainstream public cloud vendors provide organizational management services. Figures 1 to 3 The document illustrates the organization management service models provided by different public cloud vendors. It can be seen that different public cloud vendors use different names for the SoD unit. Figure 1 In Model 1 shown, the SoD unit represents an account. Figure 2 In Model 2 shown, the SoD unit is a subscription; Figure 3In Model 3 shown, the SoD unit represents the project.

[0072] Most of the organizational management service models in related technologies operate on identities within SoD, but cannot directly constrain cloud resources within SoD, which can cause some problems.

[0073] Taking Model 1 as an example, in terms of organizational compliance control capabilities, Model 1 provides an SCP model. SCP is a MAC model that includes a domain-specific language (DSL) to describe an access control policy. For example, Figure 4 This describes a strategy for denying access to the s3:GetObject API.

[0074] Clients can create SCP policies and bind them to a specific tree node in the organization management service. Once bound, the identities within all accounts managed by that tree node will be subject to the control of that SCP policy. Figure 5 As shown, when putting Figure 4 Once the SCP policy shown is bound to the organization's root node, all accounts within the organization will be denied access to the s3:GetObject API.

[0075] In the organizational management service solutions of various public cloud vendors, the SoD unit contains two types of objects: identities and resources. In this scenario, it's worth noting that organizational compliance control policies (such as SCP) operate on identities within the organization. For example, in... Figure 5 In the example, none of the identities (IAM users and IAM roles) within account 3 (Acct-3) can call the s3:GetObject API. This model has the following drawbacks: In organization management services, accounts, as SoD units, also serve as resource containers. SCP can only constrain identities within an account, but cannot constrain resources within the account. In a multi-account environment within an organization, resources are often shared across accounts. Controlling resources within an organization from being accessed illegally by identities outside the organization is a common customer requirement, and the above-mentioned organization management service models cannot achieve this function.

[0076] For example, Figure 6 In the example shown, an organization's administrator wants to use SCP to restrict access to S3 bucket data within the organization from being accessed by identities outside the organization. However, account 3 (Acct-3) can bypass this restriction by sharing a bucket with an account outside the organization (Acct-4). In this case, account 4 (Acct-4) still has permission to access the bucket data within account 3 (Acct-3) because SCP cannot restrict access to resources within the organization by identities outside the organization.

[0077] Another typical scenario is that an organization's administrator wants to restrict access to resources within the organization to a specific IP address range, such as the public network segment where the company is located. This constraint still cannot be achieved using the SCP strategy described above.

[0078] To address the aforementioned issues, this application provides a cloud resource access control method based on cloud computing technology, enabling an organization's administrator to perform unified access control over resources within the organization. For example, it can prohibit cloud resources within a target organization from being accessed by users outside the target organization, or prohibit cloud resources within a target organization's nodes from being accessed by users outside the target organization's nodes.

[0079] The following detailed description, in conjunction with the accompanying drawings, outlines the specific implementation of the cloud resource access control method and cloud management platform device based on cloud computing technology provided in the embodiments of this application.

[0080] Figure 7 A schematic diagram of the system architecture for which the cloud resource access control method based on cloud computing technology provided in the embodiments of this application can be applied is shown. Figure 7 As shown, the system includes a cloud management platform 20 and infrastructure 1. Tenant A can log in to the cloud management platform 20 via client 40 through the Internet 30 using an account and password pre-registered on the cloud management platform 20, and manage cloud resources in infrastructure 1 through the cloud management platform 20. Tenant A can deploy organizational management services for its cloud resources on the cloud management platform 20. Infrastructure 1 contains multiple computing devices. For example, infrastructure 1 includes computing devices 11, 12, ..., 13. For example, computing device 11 includes a hardware layer and a software layer. The hardware layer includes memory 116, processor 117, network card 118, and hard disk 119. The software layer includes cloud resources 111, 112, 113, 114, ... and the operating system 115 of computing device 11. The operating system 115 includes a cloud resource manager 1151 and a cloud management platform client 1152. The cloud resource manager 1151 is used to manage multiple cloud resources and communicates with the cloud management platform 20 through the cloud management platform client 1152. It is worth noting that, in the embodiments of this application, the number of computing devices in the infrastructure can be one or more, and the number of cloud resources in the computing devices can be one or more; the embodiments of this application do not limit this.

[0081] For example, infrastructure 1 includes at least one cloud data center, such as Figure 7Cloud data centers 100 and 200 are configured in the infrastructure 1. Each cloud data center has multiple computing devices. For example, cloud data center 100 has computing devices 11 and 12, cloud data center 200 has computing device 13, and so on. One or any combination of multiple cloud resources is deployed in at least one computing device of infrastructure 1. For example, cloud resources 111, 112, 113, and 114 are deployed in computing device 11, and cloud resources 121, 122, 123, and 124 are deployed in computing device 12. Multiple cloud resources of the same tenant can be configured within one organization.

[0082] Computing devices 11, 12 and 13 can be servers. A server can be an independent physical server or a server cluster or distributed system composed of multiple physical servers. The server provides various cloud services, such as cloud databases, cloud computing, cloud storage and other basic cloud computing services.

[0083] The server involved in this solution can be a hardware server or embedded in a virtualization environment. For example, the server involved in this solution can be a virtual machine running on a hardware server that includes one or more other virtual machines.

[0084] Figure 8 This is a flowchart illustrating a cloud resource access control method based on cloud computing technology, provided as an embodiment of this application. This cloud computing-based resource access control method can be applied to... Figure 7 The cloud management platform 20 shown enables access control over cloud resources within the organization. For example... Figure 8 As shown, the cloud resource access control method based on cloud computing technology includes at least steps S801 to S803.

[0085] In step S801, the cloud management platform obtains and records the first resource control policy configured by the administrator of the target organization for the target cloud resources within the target organization. The first resource control policy is used to instruct users outside the target organization on access rights to the target cloud resources.

[0086] The target organization can be any organizational structure that requires resource access control, such as enterprises, government departments, and schools. Personnel within the target organization include leaders, employees, and visitors.

[0087] The target cloud resource can be any resource within the target organization. Before receiving access requests for resources within the target organization, the resources within the target organization can be partitioned, specifically into indivisible atomic resource units. In this case, the target resource can be a single resource unit or a collection of multiple resource units within the target organization.

[0088] In organizational management services, the resources of an organization are often managed hierarchically. For example, enterprises generally have a top-down tree-like organizational structure, and the ability of hierarchical management is to organize SoD units in a tree-like structure, which makes it easier for operators in various departments of the enterprise to manage them.

[0089] Optionally, an organizational structure can be established based on the target organization's departmental settings. Then, based on the personnel in the target organization, the departments to which those personnel belong, and the established organizational structure, the target organization's organizational structure information can be determined. This organizational structure can include multiple organizational nodes, with each node representing a department, and each department can include at least one person.

[0090] In one example, after the target organization is built, a registration step is included before step S801. For example, the cloud management platform obtains multiple registration requests carrying different user accounts; the cloud management platform registers and records multiple user accounts according to the multiple registration requests, including the administrator's account; the cloud management platform assigns the multiple user accounts to the target organization and sets the administrator's account as the administrator account of the target organization.

[0091] Cloud resources within the target organization are divided and managed according to the organization's organizational structure. For example, the company's financial resources (such as financial statements) are assigned to the node corresponding to the finance department, the company's sales resources (such as sales reports) are assigned to the node corresponding to the sales department, and the company's production resources (such as production reports) are assigned to the node corresponding to the production department.

[0092] The administrator of the target organization can create one or more RCPs and bind them to the entire organization (that is, bind them to the root node of the organization). All resources within the accounts of the organization will be controlled by the RCP.

[0093] The RCP bound to the entire target organization is the RCP corresponding to the target cloud resource. For example, if only one RCP1 is bound to the root node of the target organization, then the RCP corresponding to the target cloud resource is RCP1; if RCP1, RCP2, and RCP3 are bound to the root node of the target organization, then the RCP corresponding to the target cloud resource is RCP1, RCP2, and RCP3.

[0094] There are several methods to determine the RCP corresponding to the target cloud resource information. For example, an index table can be built using resource identifiers as indexes for RCPs. The RCP corresponding to the target cloud resource can be quickly found by matching the resource identifier to the index table. Multiple index entries in the index table are determined based on multiple resource identifiers, which are multiple resource identifiers corresponding to multiple cloud resources within the target organization.

[0095] Alternatively, a mapping table can be established that records the mapping relationship between organizations and RCPs. Based on the target cloud resource information, the organization members to which the target cloud resource belongs can be determined, and then the target organization to which the organization members belong can be found. Based on the target organization, the mapping table can be queried to obtain the RCPs associated with the target organization. These found RCPs are the RCPs corresponding to the target cloud resource.

[0096] It should be noted that RCP is also a type of MAC policy; it does not provide permissions but only serves as a constraint.

[0097] The cloud management platform obtains and records the first RCP in the RCP bound to the target organization. This first RCP is the first RCP corresponding to the target cloud resource. This first RCP is used to indicate the access rights of users outside the target organization to the target cloud resource.

[0098] For example, the first RCP includes at least a first constraint condition, which is used to constrain the accessing user to belong to the target organization. When the resource access request is triggered by a user outside the target organization, that is, when the accessing user does not meet the first constraint condition, the first resource access request to access the target resource is rejected.

[0099] In step S802, the cloud management platform obtains a first resource access request for a target cloud resource within the target organization, triggered by a user outside the target organization.

[0100] Users access the client (e.g.) Figure 7 Client 40 in the target organization triggers a first resource access request for a target cloud resource within the target organization. This first resource access request is transmitted over a network (e.g., ...). Figure 7 The request is sent from the Internet 30 to the cloud management platform 20, thus the cloud management platform 20 obtains the first resource access request triggered by the user for the target cloud resource within the target organization.

[0101] The first resource access request carries the target cloud resource information. The cloud management platform can locate the specific cloud resource based on the target cloud resource information, such as the target cloud resource within the target organization.

[0102] The target cloud resource information includes resource identification information, which can include any information that can identify a resource, such as a resource identifier, information about the product to which the resource belongs, and information about the region where the resource is located. The resource identifier can identify a specific cloud resource, the information about the product to which the cloud resource belongs can include information indicating which cloud product the cloud resource belongs to, and the information about the region where the cloud resource is located can include the name or address of the region where the cloud resource is located.

[0103] It is understandable that the target cloud resource can be any type of cloud resource, such as virtual machines and containers for computing services, buckets for object storage services, cloud disks, and cloud databases.

[0104] The user is outside the target organization. This means there are two scenarios where the user doesn't belong to the target organization. One is that the user has registered a cloud account, but that account doesn't belong to the target organization. For example, if the first resource access request carries a user account registered on the cloud management platform by a user outside the target organization, and the cloud management platform receives the first resource access request, it parses the request to obtain the user account. If this user account doesn't belong to any of the multiple user accounts corresponding to the target organization, it determines that the first resource access request was triggered by a user outside the target organization.

[0105] In other words, if an access request comes from another user on the cloud who is registered on the cloud but not within the target organization, the cloud management platform will determine that the access request is triggered by a user outside the target organization.

[0106] It should be explained that the user account can be any combination of one or more of the following: username, real name, mobile phone number, ID card number, employee number, etc., as long as it can uniquely identify the user. This application embodiment does not impose any limitations on this.

[0107] Understandably, user accounts may have other names depending on the public cloud provider, such as user subscriptions and user projects.

[0108] In another scenario, the user has not registered an account on the cloud management platform, and the first resource access request does not carry the user account registered on the cloud management platform. If the cloud management platform determines through parsing that the first resource access request does not carry the user account registered on the cloud management platform, it determines that the first resource access request was triggered by a user outside the target organization.

[0109] In other words, if the access request comes from other users outside the cloud who are not registered on the cloud (i.e., do not have an account), the cloud management platform will also identify the access request issued by such users as being triggered by users outside the target organization.

[0110] For example, the target cloud resource corresponding to the access request is a virtual machine. A webpage is provided on the cloud for public network use. Terminals on the cloud (such as mobile phones or personal computers) can access the public IP (target public IP) of this webpage through their own source public IP.

[0111] In step S803, the cloud management platform allows or denies the first resource access request to access the target cloud resource according to the first resource control policy it has recorded.

[0112] Steps S801 and S802 yield a first RCP for the target cloud resource within the target organization and a first resource access request for the target cloud resource within the target organization. Then, the first resource access request is authenticated based on the first RCP. If the authentication is successful, the first resource access request is allowed to access the target cloud resource; if the authentication fails, the first resource control policy is denied access to the target cloud resource.

[0113] Specifically, a policy calculation is performed on the first resource access request based on the first RCP to obtain the policy calculation result, which indicates whether the resource access request has passed authentication.

[0114] For example, the first RCP includes a first constraint condition, which is used to constrain the accessing user to belong to the target organization. When the resource access request is triggered by a user outside the target organization, the policy calculation result is not satisfied, that is, the accessing user does not meet the first constraint condition, the authentication fails, and the first resource access request is rejected from accessing the target resource.

[0115] The policy calculation process determines whether the access request information meets the constraints of the Restricted Access Policy (RCP). For example, if the RCP includes a constraint that the accessing user belongs to the target organization, then the accessing user must belong to the target organization to meet this constraint. In other words, only when the accessing user belongs to the target organization will the access request potentially pass authentication and be allowed to access cloud resources within the target organization. This effectively prevents unauthorized access to cloud resources within the organization from occurring in multi-account scenarios, where accounts within the organization share cloud resources with members outside the organization.

[0116] As can be seen from the above, the cloud resource access control method based on cloud computing technology provided in this application directly applies RCP to resources within the organization, directly constraining access to resources within the organization, and enabling the restriction of access to cloud resources within the organization by users outside the organization. For example, it can overcome the problem of resources being shared across accounts in an organization with multiple accounts, and control resources within the organization from being illegally accessed by users outside the organization.

[0117] Figure 9 This demonstrates how the cloud resource access control method based on cloud computing technology provided in this application sets up an RCP on a target organization to achieve access control within the target organization (e.g., cloud resource access control). Figure 9 The target cloud resources (e.g., Org-1) in Org-1) Figure 9 Access to cloud resources (S3 and EC2) in Acct-3 is prohibited for identities outside the organization.

[0118] Figure 10 This application illustrates another cloud resource access control method based on cloud computing technology, which can be applied to... Figure 7The cloud management platform 20 shown is used to control access to target cloud resources within the organization by users within that organization. For example... Figure 10 As shown, the method includes at least steps S1001 to S1003.

[0119] In step S1001, the cloud management platform obtains and records the second resource control policy configured by the administrator of the target organization for the target cloud resources within the target organization. The second resource control policy is used to instruct users within the target organization on access rights to the target cloud resources.

[0120] The construction of the target organization and the registration and management of user accounts Figure 8 The method shown is similar and can be found in the description above. For the sake of brevity, it will not be repeated here.

[0121] The administrator of the target organization can create one or more RCPs and bind them to the target organization's node. All resources within the accounts on that target organization's node will be controlled by that RCP.

[0122] The RCP bound to the target organization node is the RCP corresponding to the target cloud resource within the target organization node. For example, if only one RCP1 is bound to the target organization node, then the RCP corresponding to the target cloud resource is RCP1; if RCP1, RCP2, and RCP3 are bound to the target organization node, then the RCPs corresponding to the target cloud resource are RCP1, RCP2, and RCP3.

[0123] There are several methods to determine the RCP corresponding to the target cloud resource information. For example, an index table can be built using resource identifiers as indexes for RCPs. The RCP corresponding to the target cloud resource can be quickly found by matching the resource identifier to the index table. Multiple index entries in the index table are determined based on multiple resource identifiers, which are multiple resource identifiers corresponding to multiple cloud resources within the target organization node.

[0124] Alternatively, a mapping table can be established that records the mapping relationship between organizational nodes and RCPs. Based on the target cloud resource information, the organizational members to which the target cloud resource belongs can be determined, and then the target organizational node to which the organizational member belongs can be found. Based on the target organizational node, the mapping table can be queried to obtain the RCPs associated with the target organizational node. These found RCPs are the RCPs corresponding to the target cloud resource.

[0125] The cloud management platform obtains and records the second RCP in the RCP bound on the target organization's node. This second RCP is the second RCP corresponding to the target cloud resource. This second RCP is used to indicate the access rights of users within the target organization to the target cloud resource.

[0126] In step S1002, the cloud management platform obtains a second resource access request for a target cloud resource within the target organization, triggered by a user within the target organization.

[0127] Users within the target organization trigger a second resource access request for target cloud resources within the target organization via a client. This second resource access request is transmitted over a network (e.g., Figure 7 The Internet 30 in the middle sends the request to the cloud management platform 20, so that the cloud management platform 20 obtains the second resource access request triggered by the user for the target cloud resources within the target organization.

[0128] The first resource access request carries the target cloud resource information. The cloud management platform can locate the specific cloud resource based on the target cloud resource information, such as the target cloud resource within the target organization.

[0129] The target cloud resource information includes resource identification information, which can include any information that can identify a resource, such as a resource identifier, information about the product to which the resource belongs, and information about the region where the resource is located. The resource identifier can identify a specific cloud resource, the information about the product to which the cloud resource belongs can include information indicating which cloud product the cloud resource belongs to, and the information about the region where the cloud resource is located can include the name or address of the region where the cloud resource is located.

[0130] After receiving the second resource access request, the cloud management platform parses the request to obtain the user account carried in the second resource access request. If the user account belongs to multiple user accounts corresponding to the target organization, it determines that the second resource access request was triggered by a user within the target organization.

[0131] In step S1003, the cloud management platform allows or denies the second resource access request to access the target cloud resource according to its own recorded second resource control policy.

[0132] Steps S1001 and S1002 yield a second RCP for the target cloud resource within the target organization and a second resource access request for the target cloud resource within the target organization. Then, the second resource access request is authenticated based on the second RCP. If the authentication is successful, the second resource access request is allowed to access the target cloud resource; if the authentication fails, the second resource control policy is denied access to the target cloud resource.

[0133] Specifically, a policy calculation is performed on the second resource access request based on the second RCP to obtain the policy calculation result, which indicates whether the resource access request has passed authentication.

[0134] For example, the second RCP includes a second constraint condition, which is used to constrain the accessing user to belong to the target organization node. When the resource access request is triggered by a user within the target organization but outside the target organization node, the policy calculation result is not satisfied, that is, the accessing user does not meet the second constraint condition, the authentication fails, and the second resource access request is rejected from accessing the target resource.

[0135] When an administrator does not want members of other departments to access resources within a specific department—for example, to control access to resources within the finance department by colleagues outside the finance department—the administrator can set a second RCP (Registered Access Protocol). This second RCP includes a constraint that the accessing user must belong to the target organizational node (which is the organizational node corresponding to the finance department). The accessing user must belong to the target organizational node to satisfy this constraint. In other words, only when the accessing user belongs to the target organizational node will the access request potentially pass authentication and be allowed to access resources within that node. This effectively prevents access to organizational resources from identities outside the organizational node, thus eliminating the possibility of accounts within the organizational node sharing resources with members outside the organizational node in a multi-account scenario. In other words, it prevents members outside a specific department from accessing cloud resources under a specific department's node.

[0136] RCP is a MAC model, a set of constraints described using a DSL (Specific Definition Language). It precisely describes the set of resources, operations, and allow / deny conditions that are permitted or denied access. An organization or organization node can bind to one or more RCPs. An RCP includes a Cloud Resource Identifier field (Resource), an Effect field (Effect), an Action field (Action), and a Condition field (Condition). The Cloud Resource Identifier field identifies the target cloud resource; the Effect field indicates whether access to the target cloud resource is permitted or denied; the Action field identifies the request type of the first resource access request; and the Condition field indicates the user outside the target organization.

[0137] See Figure 9 Multiple fields can include Version, Statement, Effect, Action, Resource, Condition, etc. Each field corresponds to a strategy element in RCP. The following is an explanation of each field in RCP.

[0138] Version, an optional policy element, in the form of "Version": "2012-10-17", is used to specify the version of the RCP document. The RCP document version of a cloud service provider can only have one value, 2012-10-17. If there is no Version element in the RCP, its default value is 2012-10-17.

[0139] Statement: Required element (array), in the form of "Statement": [{…}, {…}, {…}]. The main element of the strategy, used to describe the specific constraint rules. Each Statement element can contain multiple statements, each enclosed in {}.

[0140] Effect: Required element, in the form of "Effect": "Deny", is a component of the Statement's constraint rules. Every constraint rule must include this element, which has only two values: Allow or Deny, representing "explicitly grant" and "explicitly deny", respectively.

[0141] Action: Required element (String), in the form of "Action": "s3:GetObject". This is a component of the Statement's constraint rules; every constraint rule must include this element. Its value consists of two parts: service-name and action-name, where service-name is the namespace of the cloud service (e.g., ...). Figure 9 In the context of s3), action-name is the operation name for each product (e.g., ...). Figure 9 In the `GetObject` method, the values ​​of `service-name` and `action-name` are case-insensitive, and the operation name can contain wildcards. .

[0142] Resource: Required element (String), can be used This can be used to represent all resource objects, or it can be used to specifically limit the scope of resources and the items to which the resources belong. For example, Figure 9 The "arn:aws:s3…secret" _bucket / ".

[0143] Conditon; Optional element (String), a constraint condition, referring to the conditions under which the constraint condition takes effect.

[0144] It should be noted that when there are both Allow and Deny constraints in an SCP, the Deny constraint takes precedence.

[0145] When calculating the policy for a resource access request and its corresponding RCP, if the validity of the policy corresponding to the resource access request is Allow, the calculation result is true (i.e., access is allowed) and authentication is successful. If the policy contains a validity Deny, the calculation result is false (i.e., access is denied) and authentication fails.

[0146] by Figure 9 Taking the RCP example shown, this section introduces the policy calculation of RCP for resource access requests. The main elements of the Statement policy in this RCP are: "Effect": "Deny"; "Action": "s3:GetObject"; "Condition": {"StringNotEquals": {"aws:PrincepalOrgID": "org-1"}. This means that all buckets within the org-1 organization (i.e., the target organization) are restricted from access by identities outside the org-1 organization (i.e., non-target organization). In other words, access requests will only be authenticated and allowed to access bucket resources within the target organization if the accessing user belongs to the target organization.

[0147] RCPs can be configured according to actual needs. For example, an RCP might include a constraint that the source public IP address of a resource access request must belong to a preset IP network segment. The cloud management platform parses the resource access request information to obtain the context information, which includes IP network segment information, i.e., the source public IP address of the resource access request. If the RCP corresponding to the target cloud resource includes the constraint that the source public IP address of the resource access request must belong to a preset IP network segment, then this constraint can only be satisfied if the source public IP address of the resource access request belongs to the preset IP network segment. In other words, only when the source public IP address of the resource access request belongs to the preset IP network segment will the resource access request likely pass authentication and be allowed to access resources within the target organization. This ensures that access to resources within the target organization is restricted to requests originating from specific network segments.

[0148] For example, if an administrator creates an RCP bound to the root node of a target organization, and this RCP includes a constraint that the source public IP address of the resource access request belongs to the public network segment where the target organization is located, then only resource access requests originating from the public network segment where the target organization is located can be allowed to access cloud resources within the organization.

[0149] In another example, to manage resources within an organization more precisely, an administrator can create an RCP bound to the target organization or a target node within the target organization. This RCP includes constraints that operations on the target resource are preset operations; the resource access request information carries operation information indicating the operation to be performed on the target resource; thus, it is limited that only resource access requests whose operations are preset operations can pass authentication and be allowed to operate on resources within the target organization.

[0150] For example, if an administrator creates an RCP bound to a target organization node, and this RCP includes constraints that restrict the operation to read operations, then only read resource access requests are allowed to access resources within the organization, that is, only read operations are allowed on resources within the target organization node.

[0151] It is understandable that when there are multiple RCPs corresponding to a target resource, authentication will only pass if the resource access request satisfies all the RCPs corresponding to the target resource. For example, the resource access request information includes target resource information, accessing user information, operation information for the target resource, and IP network segment information; the RCPs corresponding to the target resource include RCP1, RCP2, and RCP3. Among them, RCP1 includes the constraint that the accessing user belongs to the target organization node, RCP2 includes the constraint that the operation is a read operation, and RCP3 includes the constraint that the IP network segment is the public network segment where the target organization is located. Policy calculations are performed on the resource access request and RCP1, RCP2, and RCP3 respectively. Authentication will only pass if all policy calculation results are satisfactory. In other words, the target resource, through RCP1, RCP2, and RCP3, constrains that only members within the target organization node can initiate read operation requests for the target resource from the public network segment where the target organization is located for authentication to pass. That is, the resources within the target organization node can only be read by members within the target organization node from the public network segment where the target organization is located.

[0152] The following example illustrates the specific implementation of the cloud resource access control method based on cloud computing technology provided in this application.

[0153] like Figure 11As shown, the cloud management platform comprises three systems: an organization management system, an authentication system, and a service system. The organization management system, for clients (e.g., organization administrators), provides interfaces for creating and binding RCPs. The service system provides specific APIs to collect resource information (e.g., resource identifiers) contained in user requests (e.g., resource access requests) and passes it to the authentication system. The authentication system, based on the received resource identifier, queries the organization management system to determine the organization to which the resource belongs and retrieves all RCPs that will affect that account. The authentication system performs policy calculations based on the RCP corresponding to the target account and the user request, determines whether the user request is allowed access, and returns the result to the service system.

[0154] Figure 11 This illustration shows the implementation process of the cloud resource access control method based on cloud computing technology provided in this application embodiment in a specific application scenario. For example... Figure 11 As shown, the organization administrator first creates an RCP through step S1, and then binds the RCP to a certain organization node through step S2 to achieve access control over resources within the organization or organization node.

[0155] When a regular user needs to access resources within the organization, a request to call the API is sent to the service system in step S3. This API call request carries a resource identifier. Then, in step S4, the service system sends an authentication request to the authentication system. This authentication request carries a resource identifier. The resource identifier is used to uniquely identify the target resource. Optionally, the resource identifier may include the account information where the resource is located.

[0156] In step S5, the authentication system sends a request to the organization management system to query the RCP corresponding to the target resource. The organization management system queries the organization to which the account belongs and the RCP acting on it based on the account information carried by the resource identifier.

[0157] In step S6, the organization management system returns the RCP set corresponding to the queried target resource to the authentication system.

[0158] Step S7: The authentication system performs policy calculation based on the RCP and request context (i.e., the target resource information, access user information, operation information and IP network segment information carried in the resource access request). The result of the policy calculation is used to indicate whether the authentication is successful.

[0159] In step S8, the authentication system returns the authentication result to the service system. In step S9, the service system responds to the user's request; if authentication is successful, it sends an access result to the user; if authentication fails, it sends a request rejection result to the user.

[0160] It is understood that the organization management system, authentication system, and service system can be distributed across different servers or implemented as different modules within a server; this application does not limit this. In a public cloud scenario, the organization management system is the corresponding cloud service, with different names used by different public cloud vendors, such as resource catalog service or organization service. The authentication system corresponds to the access control service on the cloud. The service system corresponds to various cloud services, such as S3, EC2, and OBS.

[0161] To implement the cloud resource access control method based on cloud computing technology provided in this application embodiment, this application embodiment also provides a cloud management platform. The cloud management platform is used to manage the infrastructure that provides multiple cloud resources. The infrastructure includes at least one cloud data center, each cloud data center is equipped with multiple servers, one or any combination of multiple cloud resources is deployed in at least one server of the infrastructure, and the multiple cloud resources are set up in at least one organization.

[0162] Figure 12 This is a schematic diagram of the structure of a cloud management platform provided in an embodiment of this application. Figure 12 As shown, the cloud management platform 20 includes an organization management module 2001, a service module 2002, and an authentication module 2003. The organization management module 2001 is used to acquire and record a first resource control policy configured by the administrator of the target organization for target cloud resources within the target organization. This first resource control policy instructs users outside the target organization on their access rights to the target cloud resources. The service module 2002 is used to acquire first resource access requests triggered by users outside the target organization for target cloud resources within the target organization. The authentication module 2003 is used to determine a first authentication result based on the first resource control policy recorded by the organization management module. This first authentication result either allows or denies the first resource access request to access the target cloud resources. The service module is also used to acquire the first authentication result from the authentication module and allow or deny the first resource access request to access the target cloud resources based on the first authentication result.

[0163] In one possible implementation, the organization management module 2001 is further configured to acquire and record a second resource control policy configured by the administrator of the target organization for the target cloud resources within the target organization, wherein the second resource control policy is used to instruct users within the target organization on access rights to the target cloud resources; the service module 2002 is further configured to acquire second resource access requests triggered by users within the target organization for the target cloud resources within the target organization; the authentication module 2003 is configured to determine a second authentication result based on the second resource control policy recorded by the organization management module, wherein the second authentication result is to allow or deny the second resource access request to access the target cloud resources; the service module is further configured to acquire the second authentication result from the authentication module, and allow or deny the second resource access request to access the target cloud resources based on the second authentication result.

[0164] In another possible implementation, the cloud management platform also includes a registration module 2004, which is used to obtain multiple registration requests carrying different user accounts, register and record multiple user accounts according to the multiple registration requests, wherein the multiple user accounts include the administrator's account; the organization management module 2001 is used to assign the multiple user accounts to the target organization and set the administrator's account as the administrator account of the target organization.

[0165] In another possible implementation, the first resource access request carries a user account registered on the cloud management platform by a user outside the target organization; the service module determines that the first resource access request is triggered by a user outside the target organization if the user account carried in the first resource access request does not belong to one of the multiple user accounts corresponding to the target organization recorded by the registration module.

[0166] In another possible implementation, the first resource access request does not carry a user account registered in the cloud management platform; the service module is used to determine that the first resource access request was triggered by a user outside the target organization if the first resource access request does not carry a user account registered in the cloud management platform.

[0167] In another possible implementation, the first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field. The cloud resource identifier field is used to identify the target cloud resource, the effect field is used to indicate whether access to the target cloud resource is denied or allowed, the request type field is used to identify the request type of the first resource access request, and the condition field is used to indicate users outside the target organization.

[0168] In another possible implementation, cloud resources include virtual machines and containers for computing services, buckets for object storage services, cloud disks, and cloud databases.

[0169] It is understood that the organization management module, service module, authentication module, and registration module in the cloud management platform can be distributed across different servers or implemented as different modules within a server; this application embodiment does not limit this. In a public cloud scenario, the organization management module refers to the corresponding organization management service, which may have different names depending on the public cloud vendor, such as resource catalog service or organization service. The service module corresponds to various cloud services, such as computing services, storage services, and network services; the authentication module corresponds to the authentication service on the cloud; and the registration module corresponds to the registration service on the cloud.

[0170] The organization management module 2001, service module 2002, authentication module 2003, and registration module 2004 can all be implemented in software or hardware. For example, the implementation of the organization management module 2001 will be described below. Similarly, the implementation of the service module 2002, authentication module 2003, and registration module 2004 can refer to the implementation of the organization management module 2001.

[0171] As an example of a software functional unit, the organization management module 2001 may include code running on computing instances. These computing instances may include at least one of physical hosts (computing devices), virtual machines, and containers. Furthermore, the aforementioned computing instances may be one or more. For example, the organization management module 2001 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed within the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed within the same availability zone (AZ) or in different AZs, each AZ comprising one or more geographically proximate data centers. Typically, a region may include multiple AZs.

[0172] Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same Virtual Private Cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, as well as between VPCs in different regions, requires a communication gateway to be set up within each VPC to enable interconnection between VPCs.

[0173] As an example of a hardware functional unit, the organization management module 2001 may include at least one computing device, such as a server. Alternatively, the organization management module 2001 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The aforementioned PLD may be implemented using a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.

[0174] The organization management module 2001 includes multiple computing devices that can be distributed within the same region or in different regions. Similarly, the organization management module 2001 includes multiple computing devices that can be distributed within the same Availability Zone (AZ) or in different AZs. Likewise, the acquisition module 1001 includes multiple computing devices that can be distributed within the same Virtual Private Cloud (VPC) or in multiple VPCs. These multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0175] It should be noted that, in other embodiments, the organization management module 2001 can be used to execute any step in the cloud resource access control method based on cloud computing technology, the service module 2002 can be used to execute any step in the cloud resource access control method based on cloud computing technology, and the authentication module 2003 can be used to execute any step in the cloud resource access control method based on cloud computing technology. The steps implemented by the organization management module 2001, service module 2002, authentication module 2003, and registration module 2004 can be specified as needed. The organization management module 2001, service module 2002, authentication module 2003, and registration module 2004 respectively implement different steps in the cloud resource access control method based on cloud computing technology to realize all the functions of the cloud control platform.

[0176] This application also provides a computing device 1300. For example... Figure 13As shown, the computing device 1300 includes a bus 1302, a processor 1304, a memory 1306, and a communication interface 1308. The processor 1304, the memory 1306, and the communication interface 1308 communicate with each other via the bus 1302. The computing device 1300 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 1300.

[0177] Bus 1302 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 13 The bus 1302 may be represented by a single line, but this does not mean that there is only one bus or one type of bus. The bus 1302 may include a path for transmitting information between various components of the computing device 1300 (e.g., memory 1306, processor 1304, communication interface 1308).

[0178] The processor 1304 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0179] The memory 1306 may include volatile memory, such as random access memory (RAM). The processor 1304 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0180] The memory 1306 stores executable program code, and the processor 1304 executes this executable program code to implement the functions of the aforementioned organization management module 2001, service module 2002, authentication module 2003, and registration module 2004, thereby realizing a cloud resource access control method based on cloud computing technology. That is, the memory 1306 stores instructions for executing the cloud resource access control method based on cloud computing technology.

[0181] The communication interface 1308 uses transceiver modules such as, but not limited to, network interface cards and transceivers to enable communication between the computing device 1300 and other devices or communication networks.

[0182] This application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.

[0183] like Figure 14 As shown, the computing device cluster includes at least one computing device 1300. The memory 1306 of one or more computing devices 1300 in the computing device cluster may store the same instructions for executing cloud resource access control methods based on cloud computing technology.

[0184] In some possible implementations, the memory 1306 of one or more computing devices 1300 in the computing device cluster may also store partial instructions for executing cloud resource access control methods based on cloud computing technology. In other words, a combination of one or more computing devices 1300 can jointly execute instructions for executing cloud resource access control methods based on cloud computing technology.

[0185] It should be noted that the memory 1306 in different computing devices 1300 within the computing device cluster can store different instructions, which are used to execute certain functions of the cloud management platform. That is, the instructions stored in the memory 1306 of different computing devices 1300 can implement the functions of one or more modules among the organization management module 2001, service module 2002, authentication module 2003, and registration module 2004.

[0186] In some possible implementations, one or more computing devices in a computing device cluster can be connected via a network. This network can be a wide area network (WAN) or a local area network (LAN), etc. Figure 15 One possible implementation is shown. For example... Figure 15 As shown, two computing devices 1300A and 1300B are connected via a network. Specifically, they are connected to the network through communication interfaces in each computing device. In this possible implementation, the memory 1306 in computing device 1300A stores instructions for performing the functions of the organization management module 2001 and the service module 2002. Simultaneously, the memory 1306 in computing device 1300B stores instructions for performing the functions of the authentication module 2003 and the registration module 2004.

[0187] It should be understood that Figure 15 The functions of computing device 1300A shown can also be performed by multiple computing devices 1300. Similarly, the functions of computing device 1300B can also be performed by multiple computing devices 1300.

[0188] This application also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions, capable of running on a computing device or stored on any usable medium. When the computer program product runs on at least one computing device, it causes the at least one computing device to execute a cloud resource access control method based on cloud computing technology.

[0189] This application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store, or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute a cloud resource access control method based on cloud computing technology.

[0190] In the above embodiments, the descriptions of each embodiment have different focuses. For parts that are not described in detail or recorded in a certain embodiment, please refer to the relevant descriptions of other embodiments.

[0191] The basic principles of this application have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this application are merely examples and not limitations, and should not be considered as essential features of the various embodiments of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the specific details described above.

[0192] The block diagrams of the devices, apparatuses, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, apparatuses, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.

[0193] It should also be noted that in the apparatus, devices, and methods of this disclosure, the components or steps can be disassembled and / or recombined. These disassemblies and / or recombinations should be considered as equivalent solutions to this disclosure.

[0194] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.

[0195] It is understood that the various numerical designations used in the embodiments of this application are merely for descriptive convenience and are not intended to limit the scope of the embodiments of this application.

Claims

1. A cloud resource access control method based on cloud computing technology, characterized in that, The method is applied to a cloud management platform, which manages infrastructure providing multiple cloud resources. The infrastructure includes at least one cloud data center, each cloud data center having multiple servers. One or any combination of the multiple cloud resources is deployed in the at least one cloud data center. The method includes: The cloud management platform obtains a first resource control policy created by the administrator of the target organization, wherein the first resource control policy is bound to the target organization node of the target organization, and the first resource control policy applies to the cloud resources within the target organization node. The cloud management platform obtains a first resource access request triggered by a user for a target cloud resource within the target organization node, wherein the cloud resource within the target organization node includes the target cloud resource. The cloud management platform determines a first authentication result based on the first resource control policy, wherein the first authentication result is to allow or deny the resource access request to access the target cloud resource; Based on the first authentication result, the cloud management platform allows or denies the resource access request to access the target cloud resource.

2. The method according to claim 1, characterized in that, The first resource control policy includes a first constraint condition, which is used to restrict the accessing user to belong to the target organization node. The cloud management platform determines a first authentication result based on the first resource control policy, including: The cloud management platform determines the first authentication result based on the first constraint, wherein the user is a user outside the target organization node, and the first authentication result is to deny the resource access request to access the target cloud resource; The cloud management platform, based on the first authentication result, allows or denies the resource access request to access the target cloud resource, including: Based on the first authentication result, the cloud management platform rejects the resource access request from accessing the target cloud resource.

3. The method according to claim 1 or 2, characterized in that, Before the cloud management platform obtains the first resource control policy created by the administrator of the target organization, the method further includes: The cloud management platform receives multiple registration requests carrying different user accounts; The cloud management platform registers and records multiple user accounts based on the multiple registration requests, wherein the multiple user accounts include the administrator's account; The cloud management platform assigns the multiple user accounts to the target organization and sets the administrator's account as the administrator account of the target organization.

4. The method according to claim 3, characterized in that, The resource access request carries a user account registered on the cloud management platform by a user outside the target organization node. The cloud management platform obtains the resource access request triggered by the user for the target cloud resource within the target organization node, including: The cloud management platform determines that the resource access request was triggered by a user outside the target organization if the user account carried in the resource access request is not within the target organization node.

5. The method according to any one of claims 1 to 4, characterized in that, The target organization node is also bound to a second resource control policy, which includes a second constraint condition. The second constraint condition is used to restrict the source public IP address in the resource access request to a preset IP network segment. Before the cloud management platform allows or denies the resource access request to access the target cloud resource based on the first authentication result, the method further includes: The cloud management platform determines a second authentication result based on the second resource control policy, wherein the source public IP of the resource access request belongs to the preset IP network segment, and the second authentication result is that the resource access request is allowed to access the target cloud resource; The cloud management platform, based on the first authentication result, allows or denies the resource access request to access the target cloud resource, including: The cloud management platform rejects the resource access request to access the target cloud resource based on the first authentication result and the second authentication result.

6. The method according to any one of claims 1 to 4, characterized in that, The target organization node is also bound to a second resource control policy and a third resource control policy. The second resource control policy includes a second constraint condition, which is used to restrict the source public IP address in the resource access request to a preset IP network segment. The third resource control policy includes a third constraint condition, which is used to restrict the operation on the target cloud resource to a preset operation. Before the cloud management platform allows or denies the resource access request to access the target cloud resource based on the first authentication result, the method further includes: The cloud management platform determines a second authentication result based on the second resource control policy, wherein the source public IP of the resource access request belongs to the preset IP network segment, and the second authentication result is that the resource access request is allowed to access the target cloud resource; The cloud management platform determines a third authentication result based on the third resource control policy, wherein the resource access request carries operation information, the operation information indicates that the operation to be performed on the target cloud resource is the preset operation, and the third authentication result is to allow the resource access request to access the target cloud resource; The cloud management platform, based on the first authentication result, allows or denies the resource access request to access the target cloud resource, including: The cloud management platform rejects the resource access request to access the target cloud resource based on the first authentication result, the second authentication result, and the third authentication result.

7. The method according to any one of claims 1 to 6, characterized in that, The first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field, wherein the cloud resource identifier field is used to identify the target cloud resource, the effect field is used to identify whether to deny or allow access to the target cloud resource, the request type field is used to identify the request type of the resource access request, and the condition field is used to indicate the restriction conditions under which the constraint conditions take effect.

8. The method according to any one of claims 1 to 7, characterized in that, The types of cloud resources include virtual machines and containers for computing services, buckets for object storage services, cloud disks, and cloud databases.

9. The method according to any one of claims 1 to 8, characterized in that, The resource access request includes target cloud resource information, which includes a resource identifier and product information to which the resource belongs. The product information to which the resource belongs is used to indicate the business information of the cloud product to which the target cloud resource belongs.

10. The method according to any one of claims 1 to 9, characterized in that, The cloud management platform records service control policies created by the administrator of the target organization for target identities within the target organization. These service control policies are used to instruct the target identities within the target organization not to access the target cloud resources.

11. A cloud management platform, characterized in that, The cloud management platform is used to manage the infrastructure that provides multiple cloud resources. The infrastructure includes at least one cloud data center, each cloud data center having multiple servers. One or any combination of the multiple cloud resources is deployed in the at least one cloud data center. The cloud management platform includes: The organization management module is used to obtain the first resource control policy created by the administrator of the target organization. The first resource control policy is bound to the target organization node of the target organization, and the target of the first resource control policy is the cloud resources within the target organization node. The service module is used to obtain a first resource access request triggered by a user for a target cloud resource within the target organization node, wherein the cloud resource within the target organization node includes the target cloud resource. The authentication module is used to determine a first authentication result based on the first resource control policy, wherein the first authentication result is to allow or deny the resource access request to access the target cloud resource; The service module is also configured to allow or deny the resource access request to access the target cloud resource based on the first authentication result.

12. The cloud management platform according to claim 11, characterized in that, The first resource control policy includes a first constraint condition, which is used to restrict the accessing user to belong to the target organization node. The cloud management platform determines a first authentication result based on the first resource control policy. The authentication module is specifically used to determine the first authentication result based on the first constraint condition, wherein the user is a user outside the target organization node, and the first authentication result is to deny the resource access request to access the target cloud resource; The service module is specifically used to reject the resource access request for accessing the target cloud resource based on the first authentication result.

13. The cloud management platform according to claim 11 or 12, characterized in that, The cloud management platform also includes: The registration module is used to obtain multiple registration requests carrying different user accounts, register and record multiple user accounts according to the multiple registration requests, wherein the multiple user accounts include the administrator's account; The organization management module is used to assign the multiple user accounts to the target organization and set the administrator's account as the administrator account of the target organization.

14. The cloud management platform according to claim 13, characterized in that, The resource access request carries a user account registered on the cloud management platform by a user outside the target organization. The service module is configured to determine that the resource access request was triggered by a user outside the target organization if the user account carried in the resource access request is not within the target organization.

15. The cloud management platform according to any one of claims 11 to 14, characterized in that, The target organization node is also bound to a second resource control policy, which includes a second constraint condition. This constraint condition is used to restrict the source public IP address in the resource access request to a preset IP address segment. The authentication module is further configured to determine a second authentication result based on the second resource control policy, wherein the source public IP of the resource access request belongs to the preset IP network segment, and the second authentication result is to allow the resource access request to access the target cloud resource; The service module is specifically used to reject the resource access request for accessing the target cloud resource based on the first authentication result and the second authentication result.

16. The cloud management platform according to any one of claims 11 to 14, characterized in that, The target organization node is also bound to a second resource control policy and a third resource control policy. The second resource control policy includes a second constraint condition, which is used to restrict the source public IP address in the resource access request to a preset IP address segment. The third resource control policy includes a third constraint condition, which is used to restrict the operation targeting the target cloud resource to a preset operation. The authentication module is further configured to determine a second authentication result based on the second resource control policy, wherein the source public IP of the resource access request belongs to the preset IP network segment, and the second authentication result is to allow the resource access request to access the target cloud resource; The authentication module is further configured to determine a third authentication result based on the third resource control strategy, wherein the resource access request carries operation information, the operation information indicates that the operation performed on the target cloud resource is the preset operation, and the third authentication result is to allow the resource access request to access the target cloud resource; The service module is specifically used to reject the resource access request for accessing the target cloud resource based on the first authentication result, the second authentication result, and the third authentication result.

17. The cloud management platform according to any one of claims 11 to 16, characterized in that, The first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field, wherein the cloud resource identifier field is used to identify the target cloud resource, the effect field is used to identify whether to deny or allow access to the target cloud resource, the request type field is used to identify the request type of the resource access request, and the condition field is used to indicate the restriction conditions under which the constraint conditions take effect.

18. The cloud management platform according to any one of claims 11 to 17, characterized in that, The types of cloud resources include virtual machines and containers for computing services, buckets for object storage services, cloud disks, and cloud databases.

19. The cloud management platform according to any one of claims 11 to 18, characterized in that, The resource access request includes target cloud resource information, which includes a resource identifier and product information to which the resource belongs. The product information to which the resource belongs is used to indicate the business information of the cloud product to which the target cloud resource belongs.

20. The cloud management platform according to any one of claims 11 to 19, characterized in that, The organization management module records service control policies created by the administrator of the target organization for target identities within the target organization. These service control policies are used to instruct the target identities within the target organization not to access the target cloud resources.

21. A computing device cluster, characterized in that, The computing device cluster includes at least one computing device, each computing device including a processor and memory: The memory is used to store instructions; The processor is configured to, according to the instructions, cause the computing device cluster to perform the method of any one of claims 1 to 10.

22. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it causes the method as described in any one of claims 1 to 10 to be implemented.

23. A computer program product comprising instructions that, when run on a computing device, cause the computing device to perform the method as described in any one of claims 1 to 10.