Resource access control method, and platform
Patent Information
- Application Number
- HK42026123738
- Authority / Receiving Office
- HK · HK
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-21
- Filing Date
- 2026-05-20
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2044-06-18
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
(19) State Intellectual Property Office (12) Invention Patent Application (10) Application Publication Number (43) Application Publication Date (21) Application Number 202410796626.1 (22) Application Date 2024.06.19 (66) Domestic Priority Data 202410634307.0 2024.05.21 CN (71) Applicant Huawei Cloud Computing Technology Co., Ltd. Address 550025, Guizhou Province, Guiyang City, Gui'an New District, Qianzhong Avenue, Xinggong Road, Huawei Cloud Data Center (72) Inventors Huang Yinyun, Lin Weibao, Li Jun (74) Patent Agency Beijing Yiteng Intellectual Property Agency (General Partnership) 11309 Patent Attorney Liu Chenlei, Chen Ji (51) Int.Cl. H04L 9 / 40 (2022.01) H04L 67 / 60 (2022.01) (54) Invention Title: A Resource Access Control Method and Platform (57) Abstract: This application provides a resource access control method and platform. The method includes: a management platform recording a first access control policy configured by the administrator of a target organization for a target access endpoint, wherein the target access endpoint is at least one of multiple access endpoints; the management platform acquiring a target access request for a target resource, wherein the target resource is a resource corresponding to the target access endpoint among multiple resources; and the management platform, based on the first access control policy, allowing or prohibiting the target access endpoint from forwarding the target access request to the target resource. This method enables the administrator of an organization to control resource access requests, avoiding resource loss, unreasonable use, etc. Claims 3 pages, Description 16 pages, Drawings 9 pages, CN 121000403 A 2025.11.21 CN 1 21 00 04 03 A 1. A resource access control method, characterized in that the method is applied to a management platform, the management platform being used to manage multiple access endpoints and multiple resources of a target organization, wherein the multiple resources are provided by multiple servers in an infrastructure, the multiple servers being located in the same data center or multiple data centers in the infrastructure, each of the multiple access endpoints corresponding to at least one of the multiple resources, the access endpoint being used to forward an access request for the resource corresponding to the access endpoint; the method comprising: the management platform recording a first access control policy configured by the administrator of the target organization for a target access endpoint, the target access endpoint being at least one of the multiple access endpoints; the management platform obtaining a target access request for a target resource, the target resource being the resource corresponding to the target access endpoint among the multiple resources; the management platform, based on the first access control policy, allowing or prohibiting the target access endpoint from forwarding the target access request to the target resource.2. The method according to claim 1, wherein the target access endpoint is created by a first user within the target organization, and the management platform further records a second access control policy configured by the first user for the target access endpoint; the management platform, based on the first access control policy, allows or prohibits the target access endpoint from forwarding the target access request to the target resource, comprising: the management platform, based on the first access control policy and the second access control policy, allowing or prohibiting the target access endpoint from forwarding the target access request to the target resource. 3. The method according to claim 1 or 2, characterized in that: the management platform records the first access control policy configured by the administrator of the target organization for the target access endpoint, including: the management platform associating the first access control policy with the organization node of the target organization, the organization node being an organizational unit (OU) or a first user within the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; the management platform, based on the first access control policy, allows or prohibits the target access endpoint from forwarding the target access request to the target resource, including: when the management platform confirms that the target access endpoint belongs to the organization node, based on the first access control policy, allowing or prohibiting the target access endpoint from forwarding the target access request to the target resource. 4. The method according to claim 3, characterized in that: the method further includes: recording the association relationship between the identifier of the target access endpoint and the identifier of the first user; confirming that the target access endpoint belongs to the organization node includes: obtaining the identifier of the target access endpoint from the target access request; confirming that the target access endpoint belongs to the organization node based on the identifier of the target access endpoint and the association relationship. 5. The method according to any one of claims 1-4, characterized in that, the first access control policy indicates the permission of a user within the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a first user or a second user within the target organization; wherein, the target access endpoint is created by the first user, and the second user is a user within the target organization other than the first user; or, according to claims 1 / 3 page 2 CN 121000403 A, the first access control policy indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a user outside the target organization. 6. The method according to any one of claims 1-5, characterized in that, the target access endpoint is a Virtual Private Cloud Terminal Node (VPCEP).7. A management platform, characterized in that the management platform is used to manage multiple access endpoints and multiple resources of a target organization, wherein the multiple resources are provided by multiple servers in an infrastructure, the multiple servers are located in the same data center or multiple data centers in the infrastructure, each of the multiple access endpoints corresponds to at least one of the multiple resources, and the access endpoint is used to forward access requests for the resource corresponding to the access endpoint; the management platform includes: a recording module, used to record a first access control policy configured by the administrator of the target organization for a target access endpoint, the target access endpoint being at least one of the multiple access endpoints; an acquisition module, used to acquire a target access request for a target resource, the target resource being the resource corresponding to the target access endpoint among the multiple resources; and a control module, used to allow or prohibit the target access endpoint from forwarding the target access request to the target resource based on the first access control policy. 8. The management platform according to claim 7, wherein the target access endpoint is created by a first user within the target organization, and the management platform further records a second access control policy configured by the first user for the target access endpoint; the control module is configured to: allow or prohibit the target access endpoint from forwarding the target access request to the target resource based on the first access control policy and the second access control policy. 9. The management platform according to claim 7 or 8, wherein the recording module is configured to: associate the first access control policy with an organizational node of the target organization, the organizational node being an organizational unit (OU) or a first user within the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; the control module is configured to: upon confirming that the target access endpoint belongs to the organizational node, allow or prohibit the target access endpoint from forwarding the target access request to the target resource based on the first access control policy. 10. The management platform according to claim 9, wherein the recording module is further configured to: record the association between the identifier of the target access endpoint and the identifier of the first user; the control module is configured to: obtain the identifier of the target access endpoint from the target access request; and confirm that the target access endpoint belongs to the organization node based on the identifier of the target access endpoint and the association. 11. The management platform according to any one of claims 7-10, wherein the first access control policy indicates the permission of a user within the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a first user or a second user within the target organization;Wherein, the target access endpoint is created by the first user, and the second user is a user within the target organization other than the first user; Claims 2 / 3, page 3, CN 121000403 A Alternatively, the first access control policy indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a user outside the target organization. 12. The management platform according to any one of claims 7-11, wherein the target access endpoint is a Virtual Private Cloud Terminal Node (VPCEP). 13. A computing device cluster, comprising at least one computing device, each computing device comprising a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the computing device cluster to perform the method according to any one of claims 1-6. 14. A computer-readable storage medium, comprising computer program instructions, wherein when the computer program instructions are executed by the computing device cluster, the computing device cluster performs the method according to any one of claims 1-6. 15. A computer program product comprising instructions, wherein when the instructions are run by the computer device cluster, the computer device cluster performs the method according to any one of claims 1-6. Claims 3 / 3 Page 4 CN 121000403 A A Resource Access Control Method and Platform
[0001] This application claims priority to Chinese Patent Application No. 202410634307.0, filed on May 21, 2024, entitled "An Access Control Method and Apparatus", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of computer technology, and more particularly to a resource access control method and platform. Background Art
[0003] With the development of technologies such as cloud computing, enterprises and other organizations can purchase or rent resources provided by remote infrastructure, such as computing resources and storage resources. In this way, organizations do not need to build infrastructure locally, reducing the organization's operating costs.
[0004] Users in an organization can apply for and use resources based on their identity in the organization. Generally speaking, users have management rights over the resources they apply for. If these management rights are not controlled, it may lead to the loss of the organization's resources. For example, a user might share the resources they have applied for with users outside the organization, or a user might misuse the resources they have applied for.
[0005] This application provides a resource access control method and platform, enabling organizational administrators to control resource access.
[0006] In a first aspect, a resource access control method is provided. This method is applied to a management platform, which manages multiple access endpoints and multiple resources of a target organization. The multiple resources are provided by multiple servers in an infrastructure, and the multiple servers are located in the same data center or multiple data centers within the infrastructure. Each access endpoint corresponds to at least one resource among the multiple resources, and the access endpoint is used to forward access requests for that resource to the resource corresponding to the access endpoint. The method includes: the management platform recording a first access control policy configured by the target organization's administrator for a target access endpoint, where the target access endpoint is at least one of the multiple access endpoints; the management platform obtaining a target access request for a target resource, where the target resource is the resource corresponding to the target access endpoint among the multiple resources; and the management platform, based on the first access control policy, allowing or prohibiting the target access endpoint from forwarding the target access request to the target resource.
[0007] In this method, the organization's administrator can configure access control policies and apply these policies to access endpoints used to forward access requests to resources. Thus, whenever an access request needs to be forwarded by an access endpoint, the access control policy can be used to determine whether the access request is permitted by the organization's administrator. If the access request is permitted by the organization's administrator, the access endpoint is allowed to forward the access request to the resource, enabling the access request to access the resource. If the access request is not permitted by the organization's administrator, the access endpoint is prohibited from forwarding the access request to the resource, preventing the access request from accessing the resource. Thus, the organization's administrator can control access requests to the organization's resources, ensuring resource security and preventing unreasonable use or loss of resources.
[0008] In one possible implementation, the target access endpoint is created by a first user within the target organization. The management platform also records a second access control policy configured by the first user for the target access endpoint. Based on the first access control policy, the management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource, including: the management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy and the second access control policy.
[0009] In this implementation, the user who creates the access endpoint can also configure access control policies. Whenever an access request needs to be forwarded by the access endpoint, in addition to determining whether the access request is permitted by the organization's administrator, the access control policy is also used to determine whether the access request is permitted by the user. The access endpoint is only allowed to forward the access request to the resource if it is permitted by both the administrator and the user; otherwise, the access endpoint is prohibited from forwarding the access request to the resource, thereby further ensuring resource security.
[0010] In one possible implementation, the management platform records the first access control policy configured by the administrator of the target organization for the target access endpoint, including: the management platform associating the first access control policy with the organization node of the target organization, the organization node being an organizational unit (OU) or a first user within the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint was created by the first user; the management platform, based on the first access control policy, allows or prohibits the target access endpoint from forwarding target access requests to the target resource, including: when the management platform confirms that the target access endpoint belongs to the organization node, it allows or prohibits the target access endpoint from forwarding target access requests to the target resource based on the first access control policy.
[0011] In this embodiment, the management platform can make the access control policy effective for the access endpoints within the organization node by associating the access control policy with the organization node, thereby eliminating the need to perform the activation operation for each access endpoint, saving operations. Furthermore, whenever a new access endpoint is added within the organization node, the access control policy automatically takes effect on the new access endpoint, thereby enabling timely control of the new access endpoint and efficiently ensuring resource security. And when an access request needs to be forwarded to an access endpoint, the access control policy of the access endpoint can be quickly queried by confirming the organization node to which the access endpoint belongs, thus improving the efficiency of access control.
[0012] In one possible implementation, the method further includes: recording the association between the identifier of the target access endpoint and the identifier of the first user; confirming that the target access endpoint belongs to the organization node includes: obtaining the identifier of the target access endpoint from the target access request; and confirming that the target access endpoint belongs to the organization node based on the identifier of the target access endpoint and the association.
[0013] The access request usually carries the identifier of the access endpoint to be called. In this implementation, the user to which the access endpoint belongs can be identified by confirming the identifier of the access endpoint carried in the access request. Then, the organization node to which the access endpoint belongs can be identified by the user to which the access endpoint belongs.
[0014] In one possible implementation, the first access control policy indicates the permission of users in the target organization to access the target resource through the target access endpoint. The target access request is initiated by the first user or the second user in the target organization; wherein the target access endpoint is created by the first user, and the second user is a user in the target organization other than the first user.
[0015] Thus, administrators can use access control policies to prevent users within the organization from improperly using the organization's resources.
[0016] In one possible implementation, the first access control policy instructs users outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by the user outside the target organization.
[0017] Thus, administrators can use access control policies to prevent users outside the organization from illegally using the organization's resources, ensuring...Resource security is ensured.
[0018] In one possible implementation, the target access endpoint is a Virtual Private Cloud Terminal Node (VPCEP). Specification 2 / 16 page 6 CN 121000403 A
[0019] This method can be used by a cloud management platform to manage VPCEP, enabling administrators to control access to cloud resources.
[0020] In a second aspect, a management platform is provided, which is used to manage multiple access endpoints and multiple resources of a target organization, wherein the multiple resources are provided by multiple servers in the infrastructure, the multiple servers are set in the same data center or multiple data centers in the infrastructure, each of the multiple access endpoints corresponds to at least one of the multiple resources, and the access endpoint is used to forward access requests for the resource corresponding to the access endpoint; the management platform includes: a recording module, used to record a first access control policy configured by the administrator of the target organization for the target access endpoint, the target access endpoint being at least one of the multiple access endpoints; an acquisition module, used to acquire a target access request for a target resource, the target resource being the resource corresponding to the target access endpoint among the multiple resources; and a control module, used to allow or prohibit the target access endpoint from forwarding the target access request to the target resource based on the first access control policy.
[0021] In one possible implementation, the target access endpoint is created by a first user within the target organization, and the management platform also records a second access control policy configured by the first user for the target access endpoint; the control module is used to: allow or prohibit the target access endpoint from forwarding target access requests to the target resource based on the first access control policy and the second access control policy.
[0022] In one possible implementation, the recording module is used to: associate the first access control policy with the organization node of the target organization, where the organization node is an organizational unit (OU) or the first user within the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; the control module is used to: allow or prohibit the target access endpoint from forwarding target access requests to the target resource based on the first access control policy when it is confirmed that the target access endpoint belongs to the organization node.
[0023] In one possible implementation, the recording module is also used to: record the association between the identifier of the target access endpoint and the identifier of the first user; the control module is used to: obtain the identifier of the target access endpoint from the target access request; and confirm that the target access endpoint belongs to the organization node based on the identifier of the target access endpoint and the association.
[0024] In one possible implementation, the first access control policy indicates the permission of users within the target organization to access target resources through a target access endpoint, and the target access request is initiated by a first user or a second user within the target organization; wherein the target access endpoint is created by the first user, and the second user is a user within the target organization other than the first user.Alternatively, the first access control policy indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by the user outside the target organization.
[0025] In one possible implementation, the target access endpoint is a Virtual Private Cloud Terminal Node (VPCEP).
[0026] In a third aspect, a computing device cluster is provided, including at least one computing device, each computing device including a processor and a memory; the processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device to cause the computing device cluster to perform the method provided in the first aspect.
[0027] In a fourth aspect, a computer-readable storage medium is provided, including computer program instructions, which, when executed by the computing device cluster, cause the computing device cluster to perform the method provided in the first aspect.
[0028] In a fifth aspect, a computer program product containing instructions is provided, which, when run by the computer device cluster, cause the computer device cluster to perform the method provided in the first aspect.
[0029] The beneficial effects of the second to fifth aspects can be referred to the above description of the beneficial effects of the first aspect, and will not be repeated here. Specification 3 / 16 pages 7 CN 121000403 A Brief Description of the Drawings
[0030] Figure 1 is a schematic diagram of a system architecture provided in an embodiment of this application;
[0031] Figure 2 is a schematic diagram of a system architecture provided in an embodiment of this application;
[0032] Figure 3 is a schematic diagram of a system architecture provided in an embodiment of this application;
[0033] Figure 4 is a flowchart of a resource access control method provided in an embodiment of this application;
[0034] Figure 5 is a schematic diagram of an access control policy provided in an embodiment of this application;
[0035] Figure 6 is a schematic diagram of an access control policy provided in an embodiment of this application;
[0036] Figure 7 is a flowchart of a resource access control method provided in an embodiment of this application;
[0037] Figure 8 is a flowchart of a resource access control method provided in an embodiment of this application;
[0038] Figure 9 is a structural schematic diagram of a management platform provided in an embodiment of this application;
[0039] Figure 10 is a structural schematic diagram of a computing device provided in an embodiment of this application;
[0040] Figure 11 is a structural schematic diagram of a computing device cluster provided in an embodiment of this application;
[0041] Figure 12 is a schematic diagram of a computing device cluster provided in an embodiment of this application. Detailed Description
[0042] The solution provided in the embodiment of this application will be described below with reference to the accompanying drawings. In this embodiment, "multiple" refers to two or more, and "multiple types" refers to two or more. "First," "second," etc., are only used to distinguish similar objects and are not necessarily used to describe a specific order or number of objects.
[0043] To facilitate understanding of the solutions provided in the embodiments of this application, the technical terms that may be involved in the embodiments of this application will be introduced first.
[0044] Cloud technology refers to a hosting service that unifies a series of resources such as hardware, software, and networks within a wide area network or local area network to realize the computing, storage, processing, and sharing of data.
[0045] Infrastructure: is a facility that provides computing resources, storage resources, and / or network resources for computing services. A resource pool may include at least one data center, and each data center includes multiple servers. Among them, the server can act as a host for deploying instances. In cloud technology, infrastructure is also called cloud infrastructure, which is used to provide computing resources, storage resources, and / or network resources for cloud computing services.
[0046] Management platform: a platform provided by the computing service provider for interacting with users. Users can register an account on the management platform and rent computing services with the account, thereby becoming users of computing services. Users can manage resource pools and instances in resource pools through the management platform. In the scenario where the computing service is a cloud computing service, the management platform can be called a cloud management platform.
[0047] User: Also known as a tenant, this refers to a user who rents resources. Users can register accounts on the management platform operated by the computing service provider through a browser or other clients. The computing service provider will record the accounts of different users and isolate the resources of different users according to the accounts. Usually, users have full access to the resources they rent.
[0048] Resource: This refers to an instance deployed in the infrastructure to run, which is used to provide computing, network, or storage resources. Instances include, but are not limited to, computing instances, elastic cloud servers (ECS), bare metal servers (BMS), object storage service (OBS) buckets, elastic load balancers (ELB), network address translation gateways (NAT Gateways), cloud caching, and other services. Typical computing instances include virtual machines (VMs) and containers. In cloud technology, resources can be called cloud resources. Specification page 4 / 16 8 CN 121000403 A
[0049] Infrastructure: Facilities supporting computing services, including at least one data center, each data center including multiple servers, servers can provide one or more resources, such as servers can run computing instances such as virtual machines or containers. For example, in the case where the infrastructure includes multiple data centers, the multiple data centers can be distributed in different locations.In the same geographical area, data centers can be remotely connected through a backbone network.
[0050] Organizations (ORG): A hierarchical tree structure entity created by the management platform to uniformly manage multiple users. An organization has multiple members. Each of these multiple members is a user registered with the management platform. Among them, multiple members or users within an organization usually belong to the same group, for example, to the same enterprise.
[0051] Organization node: A node in the tree structure of an organization. An organization node can be an organizational unit (OU) in the organization, or a user in the organization.
[0052] Organizational unit (OU): Also known as an organizational department, it is a type of node in the tree structure of an organization. Organizational units are created by the organization administrator. Organizational departments can be nested. Each organizational unit is used to manage one or more users.
[0053] Root organizational unit (ROU): Also known as the root OU, it is the root node in the tree structure of an organization. Among them, all OUs in the organization except the root OU are leaf nodes of the tree structure of the organization, or leaf nodes of the root OU. Leaf nodes can also be simply referred to as child nodes.
[0054] Member account (Acct): also known as user account, is the object managed by the organization. One member account represents one user. After the organization is created, the organization administrator invites existing accounts to join the organization, or creates new accounts through the organization, and the newly created accounts are automatically added to the organization.
[0055] Access endpoint: is the portal or interface corresponding to the resource. Usually, an access endpoint corresponds to a resource. The access endpoint acts as the portal or interface of its corresponding resource and is used to forward access requests for the resource to achieve resource access. Common access endpoints include virtual private cloud endpoints (VPCEP). Users can create VPCEPs and map the created VPCEPs to the user's resources.
[0056] Virtual private cloud endpoint (VPCEP): consists of two types of resource instances: "endpoint service" and "endpoint". Among them, endpoint services refer to services that configure cloud services or user private services as services supported by endpoints, which can be connected to and accessed by endpoints. Endpoints are used to establish a convenient, secure, and private connection channel between the virtual private cloud (VPC) and endpoint services.
[0057] Object storage serviceOBS (Object-Based Storage Service) is an object-based massive storage service that provides users with massive, secure, highly reliable, and low-cost data storage capabilities.
[0058] Service Control Policy (SCP): A mandatory access control (MAC) policy in organizational management services that applies to users within the organization. A service control policy describes a set of permissions. It is a constraint, not an authorization. The behavior of a user subject to a service control policy cannot exceed the set of permissions described by that policy.
[0059] Network Control Policy (NCP): Created by the organization's administrator to constrain the connection permissions and / or resource access permissions of access endpoints. When an organization's administrator creates an NCP and binds it to a node within the organization (e.g., the root organizational unit, organizational unit, or user), the connection permissions and / or resource access permissions of all virtual private cloud terminal nodes within the accounts managed by that node will be controlled by this policy. An NCP is a mandatory access control (MAC) policy that does not provide permissions itself, but only serves as a constraint.
[0060] VPCEP policy: This is a policy created by the user who created the VPCEP when creating the VPCEP. This policy serves as the VPCEP and is used to restrict users who access corresponding resources through the VPCEP and the access operations performed on those resources.
[0061] In one solution, a user-created access control policy (e.g., a VPCEP policy) restricts users who access the user's resources through an access endpoint (e.g., a VPCEP) and restricts the access operations performed on the user's resources through that access endpoint. That is, the access permissions of any user's resources within the organization are controlled by that user, which may lead to the organization's resources being illegally used or abused.
[0062] In view of the above situation, this application provides a resource access control method. In this method, the management platform can record the access control policies configured by the organization's administrator for the access endpoint, and based on the access control policies, restrict or control the access requests that need to be forwarded by the access endpoint, thereby avoiding illegal use or abuse of resources through the access endpoint.
[0063] Next, the resource access control method provided in the embodiments of this application will be described in detail.
[0064] Figure 1 shows a system architecture that can be used to implement the method. The system architecture may include a management platform 100 and infrastructure 200.
[0065] Infrastructure 200 may include one or more data centers, and each data center may include multiple servers.Servers in infrastructure 200 can provide resources, for example, to a target organization. Users within the target organization can apply for resources in infrastructure 200 by virtue of their membership in the target organization through management platform 100. One or more servers in infrastructure 200 can respond to the application and provide resources to the user. The resources applied for by the user can be referred to as the user's resources. Furthermore, the resources applied for by the user belong to the target organization. Users within the target organization can create access endpoints through management platform 100. For example, access endpoints can be created in infrastructure 200 to utilize the resources in infrastructure 200 to run the access endpoint.
[0066] Users can map their created access endpoints to one or more resources they have applied for, and send access requests to the resources through the access endpoints to achieve resource access.
[0067] In this embodiment, management platform 100 can be used by the administrator of the target organization to manage the target organization, such as creating the target organization, adding or deleting users in the target organization, etc. Management platform 100 can also be used by the administrator of the target organization to manage the resources of the target organization, such as managing access permissions to the resources of the target organization. Specifically, the administrator of the target organization can configure access control policies for access endpoints to manage access permissions to the resources corresponding to those access endpoints. The management platform 100 can receive and record the access control policies configured by the administrator, such as access control policy A1. Access control policy A1 can be applied to the access endpoint and is used to indicate the permissions of users inside or outside the target organization to access the corresponding resources through the access endpoint. Under the instruction of the administrator of the target organization, the management platform 100 can associate access control policy A1 with one or more organizational nodes in the target organization, so that access control policy A1 applies to the access endpoints within the one or more organizational nodes. Here, the access endpoints within an organizational node are access endpoints created or owned by users within that organizational node.
[0068] In some embodiments, the management platform 100 can receive and record the access control policies configured by the user, such as access control policy A2. Access control policy A2 applies to the access endpoint created by the user and is used to indicate the permissions of users inside or outside the target organization to access the corresponding resources through the access endpoint.
[0069] When the management platform 100 receives an access request for a certain resource, it can control the access request based on the access control policy applied to the access endpoint corresponding to the resource. For example, it can allow the access endpoint to send the access request to the resource so that the access request can access the resource, or it can prohibit the access endpoint from sending the access request to the resource so as to prevent the access request from accessing the resource.
[0070] Associating access control policy A1 with one or more organizational nodes can make access control policy A1 apply to page 6 / 16 of this specification.121000403 A An access endpoint within one or more organizational nodes. Therefore, the management platform 100 can perform access control on resources within the one or more organizational nodes based on access control policy A1. Resources within an organizational node refer to the resources of users within that organizational node.
[0071] In some embodiments, the management platform 100 can provide an organizational management service. Through the organizational management service, the administrator of the target organization can create a target organization in the management platform 100. The target organization created through the organizational management service includes an administrator and several users. The administrator has user management permissions. User management permissions refer to the permissions to manage users within the organization. The administrator can invite existing users on the management platform to join the organization to which the administrator belongs, or register new users on the management platform, and the newly registered users will automatically join the organization to which the administrator belongs.
[0072] As shown in Figure 2, the target organization created through the organizational management service can include multiple organizational units (OUs), such as OU310, OU320, OU330, etc. OU310 is the root organizational unit (ROU). The root organizational unit, also known as the root OU, is the root node in the tree structure of an organization and is created by default when the organization is created. The root OU corresponds to the administrator, who can manage all users in the organization.
[0073] OU320, OU330, etc., are leaf nodes of OU310 and are created by the administrator represented by OU310. The administrator can divide multiple users in the organization into different leaf nodes to facilitate the management of multiple users. For example, as shown in Figure 2, users 321 and 322 in the target organization belong to OU320, and user 331 in the target organization belongs to OU330.
[0074] In some embodiments, users in the target organization can also be called segregation of duty (SOD) units, which are the smallest units in the management platform with specific operating permissions and specific resources, satisfying the principle of separation of responsibilities and permissions of business departments and business personnel of the enterprise. The management platform can assign a user identifier to each user. Different users have different user identifiers, which can be used to distinguish different users. Furthermore, there is a mapping relationship between the user identifier and the organization and OU to which the user belongs. Thus, the user's organization and OU can be obtained through the user identifier.
[0075] In some embodiments, the user identifier can be an account. In some embodiments, the user identifier can be a subscription. In some embodiments, the user identifier can be a project.
[0076] In some embodiments, in the tree structure shown in FIG2, hierarchical management of the target organization can be achieved using organizational compliance control policies. Specifically, organizational compliance control policies can be used to manage users within the target organization, such as managing user resources or user behavior. Thus, access control policy A1 can be configured as an organizational compliance control policy to manage users within the target organization.
[0077] As shown in FIG2, each user has resources. For example, user 321 has resources 2101 and 2102, user 322 has resource 220, and user 331 has resource 230. A user's resources are those requested by the user from infrastructure 200 through management platform 100.
[0078] Users can utilize their resources to perform related business. The user's resources belong to the organization to which the user belongs and are resources of that organization.
[0079] Users can create access endpoints and map these access endpoints to their resources. For example, user 321 can create access endpoint 2111 and access endpoint 2112, and map access endpoint 2111 to resource 2101, and access endpoint 2112 to resource 2102. User 322 can create access endpoint 221 and map access endpoint 221 to resource 220. User 331 can create access endpoint 231 and map access endpoint 231 to resource 230.
[0080] In some embodiments, the administrator of the target organization can associate access control policy A1 with any one or more OUs in the target organization. For example, as shown in FIG2, if access control policy A1 is associated with OU320, then access control policy A1 can be applied to access endpoints within OU320 such as access endpoint 2111, access endpoint 2112, and access endpoint 221. In this way, the management platform 100 can control access requests to resources within OU320 based on access control policy A1.
[0081] In some embodiments, as shown in FIG3, the administrator of the target organization can associate access control policy A1 with one or more users in the target organization, such as user 321. Then access control policy A1 can be applied to access endpoint 2111 and access endpoint 2112. In this way, the management platform 100 can control the access requests of user 321 to resources based on access control policy A1.
[0082] The above example describes the system architecture provided by the embodiments of this application. Next, the resource access control method provided by the embodiments of this application will be described in conjunction with the system architecture.
[0083] This method can be executed by the management platform 100. The management platform 100 may include a recording module 110, an acquisition module 120, and a control module 130. Through these modules, the management platform 100 can realize the resource access provided by the embodiments of this application.Control Method. As shown in Figure 4, the method includes the following steps.
[0084] In step 401, the administrator of the target organization can configure access control policy A1 and indicate the access endpoints on which access control policy A1 applies. That is, the administrator of the target organization can configure access control policy A1 for one or more access endpoints in the target organization.
[0085] In some embodiments, access control policy A1 may be called a network control policy (NCP), which is used to restrict the connection permissions and / or resource access permissions of access endpoints to control access requests for the resources corresponding to the access endpoint.
[0086] In some embodiments, access control policy A1 may contain a domain-specific language (DSL) to describe a set of permissions. Wherein, when access control policy A1 is associated with an organization node (e.g., OU310), the access control policy A1 can apply to all access endpoints within the organization node.
[0087] In some embodiments, as shown in Figure 5, the policy structure of access control policy A1 may include a policy version number and a policy permission statement. Among them, policy permission statements can include multiple ones, such as effect, action, condition, resource type, etc.
[0088] As shown in Figure 6, the policy version number refers to the policy version, for example, 1.1.
[0089] effect is used to define whether the operation in the authorization item is allowed to be executed. Among them, effect can be divided into allow and deny. When the effect of the same authorization item has both allow and deny, the principle of deny takes precedence.
[0090] Authorization item refers to operation permission. The format of authorization item can be "service name: resource type: operation". For example, an authorization item can be represented as "obs: bucket: listallmybuckets", where obs is the service name, bucket is the resource type, and listallmybuckets is the operation.
[0091] The meaning of condition is: it is the effective condition of access control policy, including condition key and operator. The format of condition can be "operator:
[0092] {condition key: [condition key 1, condition key 2]}. If multiple conditions are set, the access control policy takes effect when all conditions are met simultaneously. For example, "string end withif exis ts": {"g:username": ["specialcharacter"]} means: access control is activated when the username entered by the user ends with "specialcharacter".The access control policy takes effect.
[0093] The meaning of resource type is: the resource on which the access control policy applies. The format of resource type can be "service name:region:domainld:resource type:resource path". Resource type supports wildcards *. In one example, "obs:*:*:bucket:*" means: all OBS buckets. Wherein, the resource on which the access control policy applies is specifically the resource corresponding to the access endpoint on which the access control policy applies or is targeted. Specification 8 / 16 pages 12 CN 121000403 A
[0094] In step 402, the recording module 110 can respond to the instructions of the administrator of the target organization, record access control policy A1, and record the access endpoint targeted by access control policy A1, that is, record which access endpoints (e.g., access endpoint C1) the administrator has configured access control policy A1 for. Wherein, the access control policy applies to the access endpoint targeted by the access control policy to control access requests to the resource corresponding to the access endpoint. The access endpoint targeted by access control policy A1 is the access endpoint of the user within the target organization.
[0095] In some embodiments, the recording module 110 may associate access control policy A1 with one or more organizational nodes in the target organization and record the association. The access endpoint of a user within the organizational node associated with access control policy A1 is the access endpoint targeted by access control policy A1. Thus, by recording the association between access control policy A1 and the organizational node, the access endpoint targeted by access control policy A1 is recorded. In one example, the organizational node associated with access control policy A1 may be an OU or a user. An OU includes multiple users, and users can be represented by user identifiers. In one example, the user identifier may specifically be a user account.
[0096] In some embodiments, the recording module 110 may associate access control policy A1 with one or more access endpoints in the target organization and record the association. The access endpoint associated with access control policy A1 is the access endpoint targeted by access control policy A1.
[0097] In some embodiments, the recording module 110 may record access control policy A1 and the access endpoint targeted by access control policy A1 in a database.
[0098] In step 403, the acquisition module 120 acquires the access request B1 issued by the user. The user issuing access request B1 can be a user outside the target organization or a user within the target organization. The access request is used to access resources within the target organization. For ease of description, the resource to be accessed by the access request can be referred to as the target resource of the access request.
[0099] In step 404, the acquisition module 120 can identify that access request B1 requests to call access endpoint C1.
[0100] As described above, an access request needs to be forwarded through the access endpoint corresponding to its target resource in order to reach the target resource and achieve access to the target resource. The access endpoint C1 requested by access request B1 is the access endpoint corresponding to the target resource of access request B1. Access request B1 needs to be forwarded through access endpoint C1 in order to reach the target resource.
[0101] In some embodiments, access request B1 carries the identifier of the access endpoint it requests to call. In step 404, the acquisition module 120 can obtain the identifier of the access endpoint from access request B1, and based on the identifier of the access endpoint, identify that access request B1 requests to call access endpoint C1.
[0102] In some embodiments, access request B1 carries the identifier of its target resource, and the recording module 110 records the association relationship between the identifier of the resource and the identifier of the access endpoint corresponding to the resource. In step 404, the acquisition module 120 can obtain the identifier of the target resource from the access request B1, obtain the association relationship between the resource identifier and the identifier of the access endpoint corresponding to the resource from the recording module 110, and then, based on the identifier of the target resource and the association relationship, identify that the access request B1 requests to call the access endpoint C1.
[0103] After identifying that the access request B1 requests to call the access endpoint C1, the acquisition module 120 can send an authentication request to the control module 130 through step 405. The authentication request includes the identifier of the access endpoint C1.
[0104] The control module 130 can respond to the authentication request and authenticate the access request B1. Specifically, it can include the following steps.
[0105] In step 406, the control module 130 can obtain the identifier of the access endpoint C1 from the authentication request and send the identifier of the access endpoint C1 to the recording module 110. In step 407, the recording module can query the access control policy for the access endpoint C1 based on the identifier of the access endpoint C1. Specification 9 / 16 Page 13 CN 121000403 A
[0106] In some embodiments, as described above, the access control policy is associated with the organization node. In step 407, the organization node to which the access endpoint C1 belongs can be queried. Then, the access control policy associated with the organization node to which the access endpoint C1 belongs is used as the access control policy for the access endpoint C1.
[0107] Exemplarily, the recording module 110 also records the association relationship between the access endpoint C1 and the organization node to which the access endpoint C1 belongs. For example, when a user creates an access endpoint within an organization node, the created access endpoint can be associated with the organization node, and the association relationship can be recorded. Specifically, the association relationship is the association relationship between the identifier of the access endpoint and the identifier of the organization node. In step 407, the organization node to which the access endpoint C1 belongs can be queried based on the identifier of the access endpoint C1 and the association relationship.
[0108] For example, the recording module 110 also records the association between access endpoint C1 and the user to which access endpoint C1 belongs. Specifically, this association is the association between the identifier of the access endpoint and the identifier of the user. In step 407, the user to which access endpoint C1 belongs can be queried based on the identifier of access endpoint C1 and this association. Then, the access control policy associated with the organization node to which the user to which access endpoint C1 belongs is used as the organization node to which access endpoint C1 belongs.
[0109] The access control policy for access endpoint C1 can be queried through the above steps. The access control policy for access endpoint C1 can be set as access control policy A1.
[0110] In step 408, the recording module 110 can send access control policy A1 to the control module 130. In step 409, the control module 130 can determine whether access request B1 conforms to access control policy A1. Specifically, based on access control policy A1, policy calculation can be performed on access request B1, and the calculation result can indicate whether access request B1 conforms to access control policy A1.
[0111] Wherein, access control policy A1 indicates the access permission to access resources through access endpoint C1. In step 409, it is determined whether access request B1 has the access permission. If it does not have the access permission, it is confirmed that access request B1 does not comply with access control policy A1. Otherwise, it is confirmed that access request B1 complies with access control policy A1.
[0112] In some embodiments, the access permission indicated by access control policy A1 is a permitted operation type. If the operation type of the operation that access request B1 wants to perform on the resource is a permitted operation type, it is confirmed that access request B1 has the access permission. Otherwise, it is confirmed that access request B1 does not have the access permission.
[0113] In some embodiments, access control policy A1 may indicate a prohibited operation type. If the operation type of the operation that access request B1 wants to perform on the resource is not a prohibited operation type, it is confirmed that access request B1 has the access permission. Otherwise, it is confirmed that access request B1 does not have the access permission.
[0114] In some embodiments, access control policy A1 indicates the user who is allowed to access. If the user who issued access request B1 is an allowed user, it is confirmed that access request B1 has the access permission. Otherwise, it is confirmed that access request B1 does not have the required access permission.
[0115] In some embodiments, access control policy A1 indicates users who are prohibited from accessing the resource. If the user issuing access request B1 is not a prohibited user, it is confirmed that access request B1 has the required access permission. Otherwise, it is confirmed that access request B1 does not have the required access permission.
[0116] In some embodiments, access control policy A1 indicates the access permission of users within the target organization to access resources through access endpoint C1, and access request B1 is issued by a user within the target organization.
[0117] In one example of this embodiment, the user issuing access request B1 may be the user who created access endpoint C1. The user who created access endpoint C1 is also the user who applied for and has the resources corresponding to access endpoint C1. In this example, the administrator can control the user's use of the resources by the user through access control policies, avoiding unreasonable use of resources.
[0118] In one example of this embodiment, the user issuing access request B1 may be another user within the target organization, referring to users other than the user who created access endpoint C1. In this example, the organization's administrator can control the sharing scope of the organization's resources within the organization through access control policies, avoiding unreasonable use of resources.
[0119] In some embodiments, access control policy A1 indicates the access rights of users outside the target organization to access resources through access endpoint C1, and access request B1 is issued by a user outside the target organization. In this way, the administrator can control the access of users outside the organization to the organization's resources through access control policies, protecting the organization's resource security.
[0120] In step 410, the control module 130 may send an authentication result to the acquisition module 120 based on the judgment result of step 409. Specifically, if the judgment result of step 409 is that access request B1 conforms to access control policy A1, an authentication result indicating successful authentication is sent to the acquisition module 120. Otherwise, an authentication result indicating authentication failure is sent to the acquisition module 120.
[0121] In some embodiments, the user who creates access endpoint C1 can configure access control policy A2 for access endpoint C1, and the recording module 110 can record access control policy A2. As shown in FIG7, before executing step 409, step 701 is executed first to determine whether access request B1 conforms to access control policy A2. The specific judgment method can be referred to the above description and will not be repeated here. If the judgment result of step 701 is that access request B1 conforms to access control policy A2, then step 409 is executed. If the judgment result of step 701 is that access request B1 does not conform to access control policy A2, then an authentication result indicating authentication failure is directly sent to the acquisition module 120, without needing to execute step 409. That is, an authentication result indicating successful authentication is only obtained when access request B1 conforms to both access control policy A1 and access control policy A2.
[0122] Continuing to refer to Figure 4, after obtaining the authentication result, the acquisition module 120 can, in step 411, allow or prohibit access endpoint C1 from forwarding access request B1 to the corresponding resource based on the authentication result. Here, the corresponding resource refers to the target resource of access request B1. When the authentication result indicates successful authentication, the acquisition module 120 allows access endpoint C1 to forward access request B1 to the target resource.The access request C1 is requested, thereby enabling access request C1 to access the target resource. When the authentication result indicates that the authentication has failed, the acquisition module 120 prohibits the access endpoint C1 from forwarding access request C1 to the target resource, thereby preventing access request C1 from accessing the target resource.
[0123] In some embodiments, the acquisition module 120 can also provide feedback on the access result to the user who issued access request C1. Wherein, when the access endpoint C1 is allowed to forward access request C1 to the target resource, an access result indicating successful access can be provided. When the access endpoint C1 is prohibited from forwarding access request C1 to the target resource, an access result indicating failed access can be provided.
[0124] In summary, the administrator of the organization can configure access control policies for access endpoints. These access control policies can control whether the access endpoint forwards access requests, thereby enabling the administrator to control access to organizational resources and avoid unreasonable use of organizational resources, loss of organizational resources, etc.
[0125] Based on the above description, this application embodiment also provides a resource method control method. This method is applied to the above-mentioned management platform 100. The management platform 100 is used to manage multiple access endpoints and multiple resources of a target organization. The multiple resources are provided by multiple servers in the infrastructure 200, which are located in the same or multiple data centers within the infrastructure. Each access endpoint corresponds to at least one of the multiple resources, and the access endpoint is used to forward access requests for that resource to the resource corresponding to it. As shown in Figure 8, the method includes the following steps:
[0126] Step 801: The management platform 100 records the access control policy A1 configured by the administrator of the target organization for a target access endpoint. The target access endpoint is at least one of the multiple access endpoints of the target organization. The target access endpoint may be the access endpoint C1 described above.
[0127] The administrator can configure access control policy A1 for at least one access endpoint in the target organization and indicate the access endpoint targeted by access control policy A1 to the management platform 100. Thus, the management platform 100 can record access control policy A1 and the access endpoint targeted by access control policy A1. For details, please refer to the above description of steps 401-402 in Figure 4, which will not be repeated here. Specification 11 / 16 pages 15 CN 121000403 A
[0128] Step 802: The management platform 100 obtains a target access request for a target resource, where the target resource is the resource among the plurality of resources corresponding to the target access endpoint. The target access request may be the access request B1 described above.
[0129] Users outside or within the target organization can initiate access to one or more resources of the target organization.The access request, one or more of which can be called the target resource. The management platform 100 can identify the access endpoint corresponding to the target resource as the target access endpoint. For details, please refer to the above description of steps 403-404 in Figure 4, which will not be repeated here.
[0130] Step 803, the management platform 100 allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on access control policy A1.
[0131] The management platform 100 records the access control policy for the target access endpoint, namely control policy A1. When the access endpoint corresponding to the target resource is identified as the target access endpoint, the access to the target resource by the target access request can be controlled based on access control policy A1. Among them, when the target access request conforms to access control policy A1, the target access endpoint is allowed to forward the target access request to the target resource. When the target access request does not conform to access control policy A1, the target access endpoint is prohibited from forwarding the target access request to the target resource. For details, please refer to the above description of steps 405-410 in Figure 4, which will not be repeated here.
[0132] In some embodiments, the target access endpoint is created by a first user within the target organization, and the management platform 100 also records the access control policy A2 configured by the first user for the target access endpoint. The management platform 100, based on access control policy A1, allows or prohibits the target access endpoint from forwarding the target access request to the target resource, including: the management platform 100, based on access control policy A1 and access control policy A2, allows or prohibits the target access endpoint from forwarding the target access request to the target resource.
[0133] The user who created the target access endpoint can also control access to the user's resources by configuring access control policies. Specifically, when an access request simultaneously conforms to both the user-configured access control policy (i.e., access control policy A2) and the administrator-configured access control policy (i.e., access control policy A1), the target access endpoint is allowed to forward the target access request to the target resource. When an access request does not conform to the user-configured access control policy and / or the administrator-configured access control policy, the target access endpoint is prohibited from forwarding the target access request to the target resource. For details, please refer to the above description of the embodiment shown in Figure 7, which will not be repeated here.
[0134] In some embodiments, the management platform 100 records the access control policy A1 configured by the administrator of the target organization for the target access endpoint, including: the management platform 100 associating the access control policy A1 with the organization node of the target organization, wherein the organization node is an organizational unit (OU) or a first user within the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint was created by the first user. The management platform 100 is based onAccess control policy A1 allows or prohibits the target access endpoint from forwarding the target access request to the target resource, including: when the management platform 100 confirms that the target access endpoint belongs to the organization node, it allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on access control policy A1.
[0135] By associating access control policy A1 with the organization node, access control policy A1 can be applied to the corresponding access endpoint simply and quickly, without having to configure access control policies for each access endpoint individually. Furthermore, when performing resource access control, the access control policy of the target access endpoint can be quickly queried by confirming the organization node to which the target access endpoint belongs, thus improving the efficiency of access control.
[0136] In one example of this embodiment, the method further includes: recording the association between the identifier of the target access endpoint and the identifier of the first user. The confirmation that the target access endpoint belongs to the organization node includes: obtaining the identifier of the target access endpoint from the target access request described on page 12 / 16 of the specification, CN 121000403 A; and confirming that the target access endpoint belongs to the organization node based on the identifier of the target access endpoint and the association relationship.
[0137] Typically, when creating an access endpoint, the management platform 100 can record the identifier of the access endpoint and the association relationship of the access endpoint. The access request usually also includes the identifier of the access endpoint requested by the access request. Thus, the identifier and association relationship of the access endpoint carried in the access request can be used to confirm that the access endpoint was created by the first user, and thus it can be confirmed that the access endpoint belongs to the organization node where the first user is located.
[0138] In some embodiments, access control policy A1 indicates the permission of users in the target organization to access the target resource through the target access endpoint, and the target access request is initiated by the first user or the second user in the target organization; wherein the target access endpoint is created by the first user, and the second user is a user in the target organization other than the first user.
[0139] In this embodiment, the organization's administrator can prevent users within the organization from unreasonably using the organization's resources through access control policies.
[0140] In some embodiments, access control policy A1 indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by the user outside the target organization.
[0141] In this embodiment, the organization's administrator can prevent users outside the organization from illegally using the organization's resources through access control policies.
[0142] In some embodiments, the target access endpoint is a VPCEP.
[0143] Through the method provided in this application embodiment, the access control policy configured by the administrator can control the access endpoint to be...Whether to forward access requests allows administrators to control access to organizational resources through access control policies, avoiding unreasonable use and loss of organizational resources.
[0144] Based on the above description of the method embodiments, this application also provides a management platform 900. The management platform 900 is used to manage multiple access endpoints and multiple resources of a target organization, wherein the multiple resources are provided by multiple servers in the infrastructure, the multiple servers are set in the same data center or multiple data centers in the infrastructure, each of the multiple access endpoints corresponds to at least one of the multiple resources, and the access endpoint is used to forward access requests for the resource corresponding to the access endpoint. As shown in Figure 9, the management platform 900 includes:
[0145] a recording module 910, configured to record a first access control policy configured by the administrator of the target organization for a target access endpoint, wherein the target access endpoint is at least one of the plurality of access endpoints;
[0146] an acquisition module 920, configured to acquire a target access request for a target resource, wherein the target resource is the resource corresponding to the target access endpoint among the plurality of resources;
[0147] a control module 930, configured to allow or prohibit the target access endpoint from forwarding the target access request to the target resource based on the first access control policy.
[0148] In some embodiments, the target access endpoint is created by a first user within the target organization, and the management platform also records a second access control policy configured by the first user for the target access endpoint; the control module 930 is configured to: allow or prohibit the target access endpoint from forwarding the target access request to the target resource based on the first access control policy and the second access control policy.
[0149] In some embodiments, the recording module 910 is configured to: associate the management platform with the first access control policy and the organization node of the target organization, wherein the organization node is an organization unit (OU) or a first user within the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; the control module 930 is configured to: upon confirming that the target access endpoint belongs to the organization node, allow or prohibit the target access endpoint from forwarding the target access request to the target resource based on the first access control policy.
[0150] In some embodiments, the recording module 910 is further configured to: record the association between the identifier of the target access endpoint and the identifier of the first user; the control module 930 is configured to: obtain the first user's identifier from the target access request.The identifier of the target access endpoint; based on the identifier of the target access endpoint and the association relationship, confirm that the target access endpoint belongs to the organization node.
[0151] In some embodiments, the first access control policy indicates the permission of a user within the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a first user or a second user within the target organization; wherein, the target access endpoint is created by the first user, and the second user is a user within the target organization other than the first user.
[0152] In some embodiments, the first access control policy indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a user outside the target organization.
[0153] In some embodiments, the target access endpoint is a Virtual Private Cloud Terminal Node (VPCEP).
[0154] The recording module 910, the acquisition module 920, and the control module 930 can all be implemented by software or by hardware. For example, the implementation of the recording module 910 will be described below using the recording module 910 as an example. Similarly, the implementation of the acquisition module 920 and the control module 930 can refer to the implementation of the recording module 910.
[0155] As an example of a software functional unit, the recording module 910 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the computing instance may be one or more. For example, the recording module 910 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same Availability Zone (AZ) or in different AZs, each AZ including one data center or multiple geographically proximate data centers. Typically, a region may include multiple AZs.
[0156] Similarly, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same VPC or in multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, and between VPCs in different regions, requires a communication gateway within each VPC to achieve interconnection between VPCs.
[0157] As an example of a hardware functional unit, the recording module 910 may include at least one computing device, such as a server. Alternatively, the recording module 910 may also utilize an application-specific integrated circuit (ASIC).Devices implemented using integrated circuits (ASICs) or programmable logic devices (PLDs). The PLD can be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0158] The multiple computing devices included in the recording module 910 can be distributed in the same region or in different regions. The multiple computing devices included in the recording module 910 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the recording module 910 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of servers, ASICs, PLDs, CPLDs, FPGAs, and GALs. (See page 14 / 16 of CN 121000403 A for specifications of computing devices.)
[0159] It should be noted that, in other embodiments, the recording module 910 can be used to execute any step in the method shown in FIG8, the acquisition module 920 can be used to execute any step in the method shown in FIG8, and the control module 930 can be used to execute any step in the method shown in FIG8. The steps implemented by the recording module 910, the acquisition module 920, and the control module 930 can be specified as needed. The management platform 900 can achieve all functions by implementing different steps in the method shown in FIG8 through the recording module 910, the acquisition module 920, and the control module 930 respectively.
[0160] This application also provides a computing device 1000. As shown in FIG10, the computing device 1000 includes: a bus 1002, a processor 1004, a memory 1006, and a communication interface 1008. The processor 1004, the memory 1006, and the communication interface 1008 communicate with each other through the bus 1002. The computing device 1000 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 1000.
[0161] Bus 1002 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. Buses can be divided into address buses, data buses, control buses, etc. For ease of representation, only one line is used in Figure 10, but this does not mean...This indicates that there is only one bus or one type of bus. Bus 1002 may include a path for transmitting information between various components of computing device 1000 (e.g., memory 1006, processor 1004, communication interface 1008).
[0162] Processor 1004 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0163] Memory 1006 may include volatile memory, such as random access memory (RAM). Memory 1006 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0165] The memory 1006 stores executable program code, and the processor 1004 executes the executable program code to implement the functions of the aforementioned recording module 910, acquisition module 920, and control module 930, thereby implementing the method shown in FIG8. That is, the memory 1006 stores instructions for executing the method shown in FIG8.
[0166] The communication interface 1008 uses a transceiver module, such as but not limited to a network interface card or transceiver, to realize communication between the computing device 1000 and other devices or communication networks.
[0167] This application embodiment also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device may be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device may also be a desktop computer, a laptop computer, or a smartphone or other terminal device.
[0168] As shown in FIG11, the computing device cluster includes at least one computing device 1000. The memory 1006 of one or more computing devices 1000 in the computing device cluster may store the same instructions for executing the method shown in FIG8.
[0169] In some possible implementations, the memory 1006 of one or more computing devices 1000 in the computing device cluster may also each store a portion of the instructions for executing the method shown in FIG8. In other words, a combination of one or more computing devices 1000 can jointly execute the instructions for executing the method shown in FIG8.
[0170] It should be noted that the memory 1006 in different computing devices 1000 in the computing device cluster can store different instructions (pages 15 / 16 of the specification, CN 121000403 A), which are used to execute some functions of the management platform 900. That is, the instructions stored in the memory 1006 in different computing devices 1000 can implement the functions of one or more modules of the recording module 910, the acquisition module 920, and the control module 930.
[0171] In some possible implementations, one or more computing devices in the computing device cluster can be connected through a network. The network can be a wide area network or a local area network, etc. Figure 12 shows one possible implementation. As shown in Figure 12, two computing devices 1000A and 1000B are connected through a network. Specifically, they are connected to the network through the communication interface in each computing device. In this type of possible implementation, the memory 1006 in computing device 1000A stores instructions for executing the functions of the recording module 910. Meanwhile, the memory 1006 in computing device 1000B stores instructions for executing the functions of acquisition module 920 and control module 930.
[0172] It should be understood that the functions of computing device 1000A shown in FIG12 can also be performed by multiple computing devices 1000. Similarly, the functions of computing device 1000B can also be performed by multiple computing devices 1000.
[0173] This application embodiment also provides another computing device cluster. The connection relationship between the computing devices in this computing device cluster can be similarly referred to the connection method of the computing device cluster described in FIG11 and FIG12. The difference is that the memory 1006 in one or more computing devices 1000 in this computing device cluster can store the same instructions for executing the method shown in FIG8.
[0174] In some possible implementations, the memory 1006 of one or more computing devices 1000 in this computing device cluster can also store some instructions for executing the method shown in FIG8. In other words, a combination of one or more computing devices 1000 can jointly execute the instructions for executing the method shown in FIG8.
[0175] This application embodiment also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions, capable of running on a computing device or stored in any usable medium. When the computer program product is run on at least one computing device, it causes the at least one computing device to perform the method shown in FIG8.
[0176] This application embodiment also provides a computer-readable storage medium. The computer-readable storage medium may be any usable medium that a computing device can store, or a host such as a data center containing one or more usable media.Migration device. The available medium may be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc. The computer-readable storage medium includes instructions that instruct the computing device to perform the method shown in FIG8.
[0177] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and not to limit it; although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of this application. Instruction Manual 16 / 16 Page 20 CN 121000403 A Figure 1 Instruction Manual Figure 1 / 9 Page 21 CN 121000403 A Figure 2 Instruction Manual Figure 2 / 9 Page 22 CN 121000403 A Figure 3 Instruction Manual Figure 3 / 9 Page 23 CN 121000403 A Figure 4 Instruction Manual Figure 4 / 9 Page 24 CN 121000403 A Figure 5 Figure 6 Instruction Manual Figure 5 / 9 Page 25 CN 121000403 A Figure 7 Figure 8 Instruction Manual Figure 6 / 9 Page 26 CN 121000403 A Figure 9 Figure 10 Instruction Manual Figure 7 / 9 Page 27 CN 121000403 A Figure 11 Instruction Manual Figure 8 / 9 Page 28 CN 121000403 A Figure 12 Instruction Manual Figure 9 / 9 Page 29 CN 121000403 A Abstract The present application provides a resource access control method, and a platform. The method includes: a management platform records a first access control policy configured by an administrator of a target organization for a target access endpoint, where the target access endpoint is at least one access endpoint among a plurality of accessendpoints; the management platform obtains a target access request for a target resource, where the target resource is a resource, which corresponds to the target access endpoint, among a plurality of resources; and on the basis of the first access control policy, the management platform allows or forbids the target access endpoint to forward the target access request to the target resource. The method can enable an administrator of an organization to control resource access requests, thereby avoiding the loss of resources, unreasonable use of resources, etc.
Claims
1. A resource access control method characterized by, The method is applied to a management platform for managing a plurality of access endpoints and a plurality of resources of a target organization, wherein the plurality of resources are provided by a plurality of servers in an infrastructure, the plurality of servers are arranged in the same data center or a plurality of data centers in the infrastructure, each of the plurality of access endpoints corresponds to at least one of the plurality of resources, and the access endpoint is used to forward an access request for the resource corresponding to the access endpoint to the resource; the method comprises: The management platform records a first access control policy configured by an administrator of the target organization for a target access endpoint, and the target access endpoint is at least one of the plurality of access endpoints; The management platform obtains a target access request for a target resource, and the target resource is a resource corresponding to the target access endpoint in the plurality of resources; The management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy.
2. The method of claim 1, wherein, The target access endpoint is created by a first user in the target organization, and the management platform also records a second access control policy configured by the first user for the target access endpoint; The management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy, comprising: the management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy and the second access control policy.
3. The method of claim 1 or 2, wherein The management platform records a first access control policy configured by an administrator of the target organization for a target access endpoint, comprising: the management platform associates the first access control policy with an organization node of the target organization, the organization node is an organization unit OU or a first user in the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; The management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy, comprising: the management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy under the condition that the target access endpoint belongs to the organization node.
4. The method of claim 3, wherein The method further comprises: recording an association relationship between an identifier of the target access endpoint and an identifier of the first user; The confirmation that the target access endpoint belongs to the organization node comprises: Obtaining the identifier of the target access endpoint from the target access request; Based on the identifier of the target access endpoint and the association relationship, it is confirmed that the target access endpoint belongs to the organization node.
5. The method of any one of claims 1-4, wherein The first access control policy indicates a permission of a user in the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a first user or a second user in the target organization; the target access endpoint is created by the first user, and the second user is a user in the target organization other than the first user; Or, The first access control policy indicates a permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a user outside the target organization.
6. The method according to any one of claims 1-5, characterized in that, The target access endpoint is a virtual private cloud terminal node VPCEP.
7. A management platform, characterized by The management platform is configured to manage a plurality of access endpoints and a plurality of resources of a target organization, wherein the plurality of resources are provided by a plurality of servers in an infrastructure, the plurality of servers are arranged in a same data center or a plurality of data centers in the infrastructure, each of the plurality of access endpoints corresponds to at least one of the plurality of resources, and the access endpoint is configured to forward an access request for the resource corresponding to the access endpoint to the resource; the management platform comprises: A recording module configured to record a first access control policy configured by an administrator of the target organization for a target access endpoint, the target access endpoint being at least one of the plurality of access endpoints; An obtaining module configured to obtain a target access request for a target resource, the target resource being a resource corresponding to the target access endpoint in the plurality of resources; A control module configured to allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy.
8. The management platform of claim 7, wherein, The target access endpoint is created by a first user in the target organization, and the management platform further records a second access control policy configured by the first user for the target access endpoint; The control module is configured to allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy and the second access control policy.
9. The management platform of claim 7 or 8, wherein The recording module is configured to associate the first access control policy with an organization node of the target organization, the organization node being an organization unit OU in the target organization or a first user, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; The control module is configured to, based on a confirmation that the target access endpoint belongs to the organization node, allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy.
10. The management platform of claim 9, wherein The recording module is further configured to record an association relationship between an identifier of the target access endpoint and an identifier of the first user; The control module is configured to: Obtain the identifier of the target access endpoint from the target access request; Based on the identification of the target access endpoint and the association relationship, it is confirmed that the target access endpoint belongs to the organization node. 11.The management platform of any one of claims 7-10, characterized in that, the first access control policy indicates the permission of a user in the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a first user or a second user in the target organization; wherein the target access endpoint is created by the first user, and the second user is a user in the target organization other than the first user; or, the first access control policy indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a user outside the target organization.
12. The management platform of any one of claims 7-11, wherein, The target access endpoint is a virtual private cloud terminal node VPCEP.
13. A cluster of computing devices, characterized in that, comprise at least one computing device, each computing device comprising a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the cluster of computing devices to perform the method of any one of claims 1-6.
14. A computer-readable storage medium, characterized in that, comprise computer program instructions which, when executed by a cluster of computing devices, cause the cluster of computing devices to perform the method of any one of claims 1-6.
15. A computer program product comprising instructions, characterized in that, when the instructions are executed by a cluster of computing devices, cause the cluster of computing devices to perform the method of any one of claims 1-6.