Cloud resource access control method based on cloud computing technology and cloud management platform

By applying resource control policies directly to cloud resources, the method ensures secure access control within organizations, preventing unauthorized access from outside users and enhancing resource management.

JP2025526884APending Publication Date: 2025-08-15HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2025508801
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-02-07
Filing Date
2023-06-30
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

Existing organizational management services cannot effectively constrain access to cloud resources within an organization, allowing unauthorized access by users outside the organization, particularly in multi-account environments.

Method used

Applying resource control policies directly to cloud resources within an organization to manage and restrict access, using a cloud management platform to enforce access permissions and deny unauthorized access requests from outside users.

Benefits of technology

Enables unified access control management for cloud resources within an organization, preventing unauthorized access from outside users and enhancing resource security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025526884000001_ABST
    Figure 2025526884000001_ABST
Patent Text Reader

Abstract

A cloud resource access control method based on cloud computing technology is applied to a cloud management platform. The method includes: the cloud management platform acquires and records a first resource control policy for a target cloud resource within the target organization configured by an administrator of the target organization, the first resource control policy indicating an access permission for a user outside the target organization to the target cloud resource; the cloud management platform acquires a first resource access request for the target cloud resource within the target organization triggered by the user outside the target organization; and the cloud management platform grants or denies the first resource access request for access to the target cloud resource based on the first resource control policy recorded by the cloud management platform. According to the cloud resource access control method based on cloud computing technology provided in the present application, a user outside the organization can be restricted from accessing cloud resources within the organization.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This application claims priority to Chinese Patent Application No. 202210972620.6, filed on August 15, 2022, entitled "Method and Apparatus for Access Control Based on Organizational Resources," and Chinese Patent Application No. 202310076418.X, filed on February 7, 2023, entitled "Cloud Resource Access Control Method Based on Cloud Computing Technology and Cloud Management Platform," both of which are incorporated herein by reference in their entireties.

[0002] The present application relates to the field of computer technology, and in particular to a cloud resource access control method and cloud management platform based on cloud computing technology. [Background technology]

[0003] To meet enterprise customers' requirements for integrated management and control of identities and resources, IT systems need to provide organizational management services, which provide customers with three main capabilities:

[0004] Separation of Duty Unit (SoD unit): A separation of duty unit is the smallest unit configured to configure different operation permissions and carry different cloud resources to meet the principle of separation of responsibilities and permissions between various business divisions and business operators of an enterprise. For different cloud vendors, the SoD unit has different names. For example, an SoD unit may be called an account, a subscription, or a project.

[0005] Hierarchical Management: Enterprises generally have a top-down tree organizational structure, and the capability of hierarchical management is to organize SoD units in a tree structure to facilitate management by operators in various departments of the enterprise.

[0006] Organizational Compliance Control Policy: Enterprises need to have a unified compliance control capability for operators and resources applied on the cloud, for example, controlling the access boundary of cloud data. An organizational compliance control policy is a type of mandatory access control (MAC) policy that applies to the entire organization or some organizational units. Note that unlike discretionary access control (DAC), mandatory access control is a constraint, not an authorization. An object to which a mandatory access control policy is applied does not have permissions beyond the scope of the policy.

[0007] However, the organizational compliance control policies provided by existing organizational management services can only constrain identities within an account, but cannot constrain resources within the account. Summary of the Invention [Means for solving the problem]

[0008] The embodiments of the present application provide a cloud resource access control method based on cloud computing technology, in which resource control policies are directly applied to resources within an organization to restrict access to resources within the organization, so that users outside the organization can be restricted from accessing cloud resources within the organization.

[0009] According to a first aspect, the present application provides a cloud resource access control method based on cloud computing technology. The method is applied to a cloud management platform, the cloud management platform is configured to manage an infrastructure providing a plurality of cloud resources, the infrastructure includes at least one cloud data center, a plurality of servers are arranged in each cloud data center, one or any combination of the plurality of cloud resources is deployed on the at least one server of the infrastructure, and the plurality of cloud resources are configured for at least one organization. The method includes: the cloud management platform acquires and records a first resource control policy for a target cloud resource in the target organization configured by an administrator of the target organization, the first resource control policy indicating access permissions of users outside the target organization for the target cloud resource; the cloud management platform acquires a first resource access request for the target cloud resource in the target organization triggered by the user outside the target organization; and the cloud management platform grants or denies the first resource access request to access the target cloud resource based on the first resource control policy recorded by the cloud management platform.

[0010] According to the cloud resource access control method based on cloud computing technology provided in the present application, resource control policies are directly applied to cloud resources within an organization to restrict access to the cloud resources within the organization, so that an administrator of the organization can perform unified access control management for the cloud resources within the organization and restrict users outside the organization from accessing the cloud resources within the organization. For example, in an organization's multi-account environment, when resources are frequently shared between accounts, resources within the organization are controlled to prevent unauthorized access by users outside the organization.

[0011] For example, the first resource control policy includes a first constraint, and the first constraint is used to restrict the case where the access user belongs to the target organization. When the first resource access request is triggered by a user outside the target organization, that is, when the access user does not satisfy the first constraint, the first resource access request to access the target cloud resource is denied.

[0012] In a possible implementation, the cloud resource access control method based on cloud computing technology provided in the present application further includes: a cloud management platform acquiring and recording a second resource control policy for a target cloud resource in the target organization configured by an administrator of the target organization, the second resource control policy indicating an access permission of a user in the target organization for the target cloud resource; the cloud management platform acquiring a second resource access request for the target cloud resource in the target organization triggered by a user in the target organization; and the cloud management platform allowing or denying the second resource access request to access the target cloud resource based on the second resource control policy recorded by the cloud management platform.

[0013] In this possible implementation, the access of users within the organization to cloud resources within the organization is controlled through a second resource control policy, for example, to achieve more advanced resource management, restricting the case where users from different departments can only access cloud resources of the department to which they belong.

[0014] For example, the second resource control policy includes a second constraint condition, which is used to restrict the case where the access user belongs to the target organization node. If the second resource access request is triggered by a user in the target organization but the user does not belong to the target organization node, that is, if the access user does not satisfy the second constraint condition, the second resource access request to access the target resource is denied.

[0015] In another possible implementation, before the cloud management platform obtains and records a first resource control policy for a target cloud resource in the target organization configured by an administrator of the target organization, the cloud resource access control method based on cloud computing technology provided in the present application further includes: the cloud management platform obtains a plurality of registration requests carrying different user accounts; the cloud management platform respectively registers and records a plurality of user accounts based on the plurality of registration requests, the plurality of user accounts including an administrator's account; the cloud management platform classifies the plurality of user accounts into the target organization, and sets the administrator's account to an administrator account of the target organization.

[0016] That is, before using a cloud service, registration needs to be performed on the cloud management platform, and multiple accounts can be registered. Accounts are managed in organizational form, and each account corresponds to a corresponding cloud resource. For example, the organization is an enterprise organization, and members within the enterprise register different accounts, and members at different levels or departments can use different cloud resources within the enterprise organization.

[0017] In another possible implementation, the first resource access request carries a user account registered in the cloud management platform by a user outside the target organization, and the cloud management platform obtaining the resource access request for the target cloud resource in the target organization triggered by the user outside the target organization includes the cloud management platform determining that the first resource access request was triggered by a user outside the target organization if it determines that the user account carried in the first resource access request does not belong to a plurality of user accounts corresponding to the target organization.

[0018] In other words, the access request is from another user on the cloud, who has registered on the cloud but is not at the target organization, and the cloud management platform determines that the access request sent by the user was triggered by a user outside the target organization.

[0019] In another possible implementation, the first resource access request does not carry a user account registered with the cloud management platform, and the cloud management platform obtaining a resource access request for a target cloud resource in the target organization triggered by a user outside the target organization includes, if the cloud management platform determines that the first resource access request does not carry a user account registered with the cloud management platform, determining that the first resource access request was triggered by a user outside the target organization.

[0020] In this possible implementation, the access request is from another user away from the cloud, and the user does not register on the cloud (i.e., the user does not have an account). The cloud management platform determines that the access request sent by the user was triggered by a user outside the target organization.

[0021] For example, the target cloud resource corresponding to the access request is a virtual machine. A web page used by a public network is provided on the cloud, and a terminal (e.g., a mobile phone or a personal computer) remote from the cloud can access the public network IP (target public network IP) of the web page by using the source public network IP of the terminal.

[0022] In a possible implementation form, the cloud resource access control method based on the cloud computing technology provided in the present application includes: The cloud management platform obtains a third resource control policy and obtains context information of the third resource access request, the context information including IP network segment information, and the IP network segment information indicates an IP network segment where a sending end of the resource access request is located; The third resource control policy further includes a third constraint, and the third constraint is used to restrict a case where the source public network IP network segment corresponding to the resource access request belongs to a preset IP network segment; The present invention further includes the following: when the source public network IP network segment belongs to the predetermined IP network segment, the user is allowed to access the target cloud resource. In other words, according to the cloud resource access control method based on the cloud computing technology provided in the present application, users of a specific source public network segment (including users on the cloud or users away from the cloud) may be prohibited from accessing the target cloud resource or may be allowed to access the target cloud resource.

[0023] In this possible implementation, the resource control policy includes multiple constraints, and authentication for the resource access request is successful only if the resource access request information satisfies all of the constraints. This provides more sophisticated resource access control. For example, context information of the resource access request information is obtained, and the context information includes a public network IP network segment corresponding to the resource access request, and the multiple constraints in the resource control policy include the IP network segment where the sending end of the resource access request is located belonging to a preset network segment (e.g., a public network segment where a target organization is located). Only access requests sent from the preset network segment are successfully authenticated and allowed to access the target resource.

[0024] In another possible implementation, the resource access request information further includes operation information, where the operation information indicates an operation to be performed on the target resource, the resource control policy further includes a fourth constraint condition, where the fourth constraint condition is used to constrain cases in which the operation indicated by the operation information belongs to preset operations, and the authentication result of the resource access request is further related to the operation information and the third constraint condition.

[0025] The resource access request information further carries operation information, and the constraints in the resource control policy include that the operation indicated by the operation information belongs to a preset operation, for example, the preset operation is a read operation, that is, only a read operation is allowed to be performed on the target resource.

[0026] In another possible implementation, the target resource information includes a resource identifier, the resource identifier uniquely identifying the target resource, and determining a resource control policy corresponding to the target resource information includes querying a pre-configured index table based on the resource identifier to obtain a resource control policy corresponding to the target resource information, where a plurality of index terms in the index table are determined based on the plurality of resource identifiers, and the plurality of resource identifiers are a plurality of resource identifiers corresponding to a plurality of resources in the target organization or an organization node to which the target resource belongs.

[0027] In this possible implementation, the resource identifier is used as an index to the resource control policy, so that the authentication system can quickly perform indexing, obtain the freedom control policy that applies to the target resource, and perform policy calculation.

[0028] In another possible implementation, the step of determining a resource control policy corresponding to the target resource information includes the steps of: determining an organizational member to which the target resource belongs based on the target resource information; querying a mapping table to obtain a resource control policy associated with an organizational node where the target organization and / or organizational member is located, wherein the mapping table records a mapping relationship between each organizational node and / or organization and each resource control policy; and determining a resource control policy corresponding to the target resource information based on the resource control policy associated with the organizational node where the target organization and / or organizational member is located.

[0029] In other words, another method is provided for quickly finding a resource control policy corresponding to target resource information. The organizational member to which the target resource belongs is determined, the organizational node and / or the organization in which the organizational member is located is determined, and then the resource control policy to be applied to the organization and / or the organizational node is determined. The resource control policy is a resource control policy corresponding to the target resource.

[0030] In another possible implementation, the resource access request is used to call an application programming interface API to access a target resource in a target cloud service, and if the authentication result is successful, the resource access request is responded to, and the result of accessing the target resource based on the access request is returned to the accessing user. For example, if the resource access request is to perform a read operation on the target resource, the result of the access is the read target resource data.

[0031] In another possible implementation, the first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field, where the cloud resource identifier field identifies a target cloud resource, the effect field identifies that access to the target cloud resource is denied or allowed, the request type field identifies a request type of the first resource access request, and the condition field indicates a user outside the target organization.

[0032] Optionally, the types of cloud resources include virtual machines and containers for computing services, buckets for object storage services, EVS disks, and cloud databases.

[0033] According to a second aspect, the present application provides a cloud management platform. The cloud management platform is configured to manage an infrastructure providing a plurality of cloud resources, the infrastructure including at least one cloud data center, a plurality of servers disposed in each cloud data center, one or any combination of the plurality of cloud resources being deployed on the at least one server of the infrastructure, and the plurality of cloud resources being configured for at least one organization. The cloud management platform includes an organization management module, a service module, and an authentication module. The organization management module is configured to acquire and record a first resource control policy for a target cloud resource within the target organization configured by an administrator of the target organization, the first resource control policy indicating access permissions for users outside the target organization for the target cloud resource; the service module is configured to acquire a first resource access request for the target cloud resource within the target organization triggered by a user outside the target organization; the authentication module is configured to determine a first authentication result based on the first resource control policy recorded by the organization management module, the first authentication result being to allow or deny the first resource access request for access to the target cloud resource; and the service module is further configured to acquire the first authentication result from the authentication module and to allow or deny the first resource access request for access to the target cloud resource based on the first authentication result.

[0034] In a possible implementation, the organization management module is further configured to obtain and record a second resource control policy for a target cloud resource in the target organization configured by an administrator of the target organization, the second resource control policy indicating access permissions of users in the target organization for the target cloud resource; the service module is further configured to obtain a second resource access request for the target cloud resource in the target organization triggered by a user in the target organization; the authentication module is configured to determine a second authentication result based on the second resource control policy recorded by the organization management module, the second authentication result being to allow or deny the second resource access request to access the target cloud resource; and the service module is further configured to obtain the second authentication result from the authentication module and to allow or deny the second resource access request to access the target cloud resource based on the second authentication result.

[0035] In another possible implementation, the cloud management platform further includes a registration module configured to receive a plurality of registration requests carrying different user accounts and respectively register and record the plurality of user accounts based on the plurality of registration requests, the plurality of user accounts including an administrator account, and an organization management module configured to categorize the plurality of user accounts into a target organization and set the administrator account as an administrator account of the target organization.

[0036] In another possible implementation, the first resource access request carries a user account registered by a user outside a target organization of the cloud management platform, and the service module is configured to determine that the first resource access request was triggered by a user outside the target organization if the service module determines that the user account carried in the first resource access request does not belong to the multiple user accounts corresponding to the target organization recorded by the registration module.

[0037] In another possible implementation, the first resource access request does not carry a user account registered with the cloud management platform, and the service module is configured to determine that the first resource access request was triggered by a user outside the target organization if it determines that the first resource access request does not carry a user account registered with the cloud management platform.

[0038] In another possible implementation, the first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field, where the cloud resource identifier field identifies a target cloud resource, the effect field identifies that access to the target cloud resource is denied or allowed, the request type field identifies a request type of the first resource access request, and the condition field indicates a user outside the target organization.

[0039] In another possible implementation, the types of cloud resources include virtual machines and containers for computing services, buckets for object storage services, EVS disks, and cloud databases.

[0040] According to a third aspect, the present application provides a server including a storage and a processor, wherein the storage stores executable code and the processor executes the executable code to implement the method provided in the first aspect of the present application.

[0041] According to a fourth aspect, the present application provides a computing device including a storage and a processor, the storage storing executable code and the processor executing the executable code to implement the method provided in the first aspect of the present application.

[0042] According to a fifth aspect, the present application provides a computer-readable storage medium storing a computer program which, when run on a computer, enables the computer to perform the method provided in the first aspect of the present application.

[0043] According to a sixth aspect, the present application provides a computer program or computer program product, comprising instructions that, when executed, implement the method provided in the first aspect of the present application.

[0044] According to a seventh aspect, an embodiment of the present application further provides a chip including at least one processor and a communication interface, wherein the processor is configured to perform the method according to the first aspect of the present application. [Brief explanation of the drawings]

[0045] [Figure 1] FIG. 1 is a diagram of an organization management service model in the related art. [Figure 2] FIG. 1 is a diagram of an organization management service model in the related art. [Figure 3] FIG. 1 is a diagram of an organization management service model in the related art. [Figure 4] Diagram of an SCP denying access to the s3:GetObject API. [Figure 5] The diagram after the SCP has been bound to the root node of the organization. [Figure 6] This is a scenario diagram after account sharing is performed after the SCP is bound to the root node of the organization. [Figure 7] 1 is a diagram of the architecture of a system to which a cloud resource access control method based on cloud computing technology according to an embodiment of the present application can be applied; [Figure 8] 1 is a schematic flowchart of a cloud resource access control method based on cloud computing technology according to an embodiment of the present application; [Figure 9] This is a diagram showing how the RCP is directly applied to cloud resources within a target organization after being bound to the root node of the target organization. [Figure 10] 4 is a schematic flowchart of another cloud resource access control method based on cloud computing technology according to an embodiment of the present application; [Figure 11] FIG. 2 is a diagram of an implementation process of a resource access control method in a specific application scenario according to an embodiment of the present application. [Figure 12] FIG. 1 is a diagram of the structure of a cloud control platform according to an embodiment of the present application. [Figure 13] FIG. 1 is a diagram of the structure of a computing device according to an embodiment of the present application. [Figure 14] FIG. 1 is a diagram of a computing device cluster according to an embodiment of the present application. [Figure 15] FIG. 15 is a diagram of an application scenario of the computing device cluster provided in FIG. 14. DETAILED DESCRIPTION OF THE INVENTION

[0046] Hereinafter, the technical solutions in the embodiments of the present application will be clearly described with reference to the accompanying drawings. It is clear that the described embodiments are only some embodiments of the present application, and not all embodiments. Any other embodiments obtained by those skilled in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0047] The term "embodiment" as used herein means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the present application. Phrases appearing in various places in this specification do not necessarily refer to the same embodiment, nor are they mutually exclusive independent or alternative embodiments. It is explicitly and implicitly understood by those skilled in the art that an embodiment described herein may be combined with another embodiment.

[0048] Cloud technology: Cloud technology is a hosting service that integrates a set of resources, such as hardware, software, and networks, into a wide-area network or a local-area network to implement data computation, storage, processing, and sharing.

[0049] Public cloud: A public cloud is a cloud that is provided to users by a third-party provider and can be used by users. Public clouds may be generally available over a network and may be free or low-cost. There may be many instances of this type of cloud and it may provide services over an open public network.

[0050] Private cloud: Cloud infrastructure, as well as software and hardware resources, are created within a firewall so that departments of an organization or company share resources within a data center. A private cloud is a cloud infrastructure that operates on behalf of a specific organization. The administrator can be the organization or a third party. The administrator can be located within the organization or outside the organization.

[0051] Hybrid cloud: A hybrid cloud is a cloud computing environment that includes private and public cloud resources.

[0052] Service Control Policy (SCP): A service control policy is a mandatory access control policy that applies to identities within an organization on organizational services.

[0053] Resource control policy (RCP): A resource control policy is a mandatory access control policy that is applied to resources within an organization in the organization service.

[0054] Cloud Management Platform and Infrastructure: The cloud management platform is configured to manage a cloud vendor's infrastructure. The infrastructure is multiple cloud data centers located in different regions, with at least one cloud data center located in each region. The cloud management platform may provide an interface related to cloud computing services, such as a configuration page or an application programming interface (API) for tenants to access cloud services. Tenants may log in to the cloud management platform using a pre-registered account and password. After successful login, they select and purchase cloud services provided by cloud data centers in a specific region. The cloud service may be, for example, an object storage service, a virtual machine service, a container service, or another known cloud service.

[0055] Tenant: A tenant is the highest-level object used to manage cloud services and / or cloud resources. A tenant registers a tenant account and sets a tenant password in the cloud management platform via a local client (e.g., a browser). A tenant remotely logs in to the cloud management platform via a local client using the tenant account and the set tenant password. The cloud management platform provides a configuration page or API for the tenant to configure and use cloud services. Cloud services are specifically provided by infrastructure managed by the cloud management platform.

[0056] An embodiment of the present application provides a resource access control method that can be applied to any IT system (e.g., a public cloud system, a private cloud system, a hybrid cloud system) that needs to perform organizational management on resources and unify control on permissions. Resources within an organization are used as targets to which organizational management and control policies are applied. In this way, resources within the organization are controlled to deny access to identities outside the organization, and the security of resources within the organization is guaranteed.

[0057] In the following, a public cloud system is used as an example to describe in detail the specific implementation of the resource access control method provided in the embodiments of the present application. Other IT systems are similar to the public cloud system. For the sake of brevity, details are not described.

[0058] It should be understood that when the resource access control method provided in the embodiments of the present application is applied to a public cloud system, the resource access control method may also be referred to as a cloud resource access control method based on cloud computing technology.

[0059] Most mainstream public cloud vendors provide organization management services. Figures 1 to 3 respectively show organization management service models provided by different public cloud vendors. It can be seen that for different public cloud vendors, the SoD units have different names. The SoD unit of Model 1 shown in Figure 1 is an account. The SoD unit of Model 2 shown in Figure 2 is a subscription. The SoD unit of Model 3 shown in Figure 3 is a project.

[0060] Most of the related technologies' organizational management service models apply to the identity of the SoD unit, but they cannot directly constrain the cloud resources of the SoD, which causes some problems.

[0061] Model 1 is used as an example. For organizational compliance control capabilities, Model 1 provides the SCP model. The SCP model is a MAC model and includes a domain specific language (DSL) used to describe access control policies. For example, Figure 4 describes a policy that denies access to the s3:GetObject API.

[0062] Customers may create an SCP policy and bind it to a tree node in the organization management service. After the binding is complete, the identities of all accounts managed by the tree node are managed and controlled by the SCP policy. As shown in Figure 5, after the SCP policy shown in Figure 4 is bound to the root node of the organization, the identities of all accounts in the organization are denied access to the s3:GetObject API.

[0063] In each public cloud vendor's organization-managed service solution, an SoD unit contains two types of objects: identities and resources. Note that in this scenario, the objects to which organizational compliance control policies (e.g., SCPs) apply are identities within the organization. For example, in the example shown in Figure 5, all identities (IAM users and IAM roles) within Account 3 (Acct-3) cannot call the s3:GetObject API. This model has the following drawbacks:

[0064] In organization management services, as an SoD unit, an account is also responsible for a resource container. An SCP can only constrain identities within an account, but not resources within an account. In an organization's multi-account environment, resources are frequently shared among accounts. It is a common customer requirement that resources within an organization be controlled to prevent unauthorized access by identities outside the organization. The organization management service model described above cannot implement this functionality.

[0065] For example, in the example shown in Figure 6, an organization administrator wants to restrict identities outside the organization from accessing S3 bucket data within the organization via an SCP, but Account 3 (Acct-3) can bypass the restriction by sharing the bucket with an account outside the organization (Acct-4). In this case, Account 4 (Acct-4) still has permission to access bucket data within Account 3 (Acct-3) because an SCP cannot restrict identities outside the organization from accessing resources within the organization.

[0066] Another typical scenario is that an organization's administrator wants to restrict the resources within the organization to be accessible only through a fixed IP network segment, such as the public network segment where the company is located. This restriction cannot be implemented by an SCP policy.

[0067] To address the above-mentioned problems, an embodiment of the present application provides a cloud resource access control method based on cloud computing technology, so that an organization administrator can implement unified access control for resources within the organization, such as prohibiting users outside the organization from accessing cloud resources within a target organization, or prohibiting users outside the target organization node from accessing cloud resources within a target organization node.

[0068] A specific implementation form of the cloud resource access control method based on the cloud computing technology and cloud management platform provided in the embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0069] FIG. 7 is a diagram of a system architecture to which a cloud resource access control method based on cloud computing technology according to an embodiment of the present application can be applied. As shown in FIG. 7 , the system includes a cloud management platform 20 and an infrastructure 1. Tenant A may log in to the cloud management platform 20 via a client 40 via the Internet 30 using an account and password previously registered with the cloud management platform 20 and manage cloud resources in the infrastructure 1 through the cloud management platform 20. Tenant A may also deploy an organization management service for cloud resources in the infrastructure 1 on the cloud management platform 20. The infrastructure 1 includes multiple computing devices. For example, the infrastructure 1 includes computing device 11, computing device 12, and computing device 13. For example, the computing device 11 includes a hardware layer and a software layer. The hardware layer includes memory 116, a processor 117, a network adapter 118, and a hard disk 119. The software layer includes cloud resources 111, 112, 113, 114, etc., and an operating system 115 of the computing device 11. The operating system 115 includes a cloud resource manager 1151 and a cloud management platform client 1152, where the cloud resource manager 1151 is configured to manage multiple cloud resources and communicate with the cloud management platform 20 via the cloud management platform client 1152. It should be noted that in this embodiment of the present application, there may be one or more computing devices in the infrastructure, and there may be one or more cloud resources in the computing devices. This is not limited in this embodiment of the present application.

[0070] For example, infrastructure 1 includes at least one cloud data center, such as cloud data center 100 and cloud data center 200 in FIG. 7. A plurality of computing devices are disposed in each cloud data center. For example, computing device 11 and computing device 12 are disposed in cloud data center 100, and computing device 13 is disposed in cloud data center 200. One or any combination of a plurality of cloud resources is deployed in at least one computing device of infrastructure 1. For example, cloud resource 111, cloud resource 112, cloud resource 113, and cloud resource 114 are deployed in computing device 11, and cloud resource 121, cloud resource 122, cloud resource 123, and cloud resource 124 are deployed in computing device 12. A plurality of cloud resources of tenants may be set up within an organization.

[0071] Computing device 11, computing device 12, and computing device 13 may be servers. The servers may be independent physical servers or may be server clusters or distributed systems including multiple physical servers. The servers provide various cloud services, for example, basic cloud computing services such as cloud databases, cloud computing, and cloud storage.

[0072] The servers involved in this solution may be hardware servers or may be incorporated into a virtualized environment, for example, a server involved in this solution may be a virtual machine running on a hardware server that contains one or more other virtual machines.

[0073] 8 is a schematic flowchart of a cloud resource access control method based on cloud computing technology according to an embodiment of the present application. The cloud resource access control method based on cloud computing technology may be applied to the cloud management platform 20 shown in FIG. 7 to implement access control to cloud resources within an organization. As shown in FIG. 8, the cloud resource access control method based on cloud computing technology includes at least steps S801 to S803.

[0074] Step S801: The cloud management platform obtains and records a first resource control policy for a target cloud resource in the target organization configured by an administrator of the target organization, where the first resource control policy indicates the access permission of a user outside the target organization for the target cloud resource.

[0075] The target organization may be any organizational structure where resource access control needs to be enforced, such as a company, a government agency, or a school. Members of the target organization may include leaders and employees of the target organization, external visitors, etc.

[0076] The target cloud resource may be any resource within the target organization. Before a resource access request is received at the target organization, the resource within the target organization may be divided. Specifically, the resource within the target organization may be divided into atomic, indivisible resource units. In this case, the target resource may be one resource unit or a set including multiple resource units within the target organization.

[0077] In the organization management service, hierarchical management is usually performed on resources corresponding to organizations. For example, an enterprise generally has a top-down tree organizational structure. The ability of hierarchical management is to organize SoD units in a tree structure to facilitate management by operators in various departments of the enterprise.

[0078] Optionally, the organizational structure of the target organization may be established based on department setting information of the target organization, and then organizational structure information of the target organization is determined based on members in the target organization, information about the departments to which the members belong, and the established organizational structure. The organizational structure may include multiple organizational nodes, where one organizational node represents one department, and one department may include at least one member.

[0079] In one example, after the establishment of the target organization is completed, a registration step is further included before step S801. For example, the cloud management platform receives multiple registration requests carrying different user accounts, the cloud management platform respectively registers and records the multiple user accounts based on the multiple registration requests, the multiple user accounts include an administrator account, the cloud management platform classifies the multiple user accounts into the target organization, and sets the administrator account as an administrator account of the target organization.

[0080] The cloud resources of the target organization are divided and managed based on the organizational structure information of the target organization. For example, the financial resources (e.g., financial reports) of the company are classified into nodes corresponding to the financial department, the sales resources (e.g., sales reports) of the company are classified into nodes corresponding to the sales department, and the production resources (e.g., production reports) of the company are classified into nodes corresponding to the production department.

[0081] The administrator of a target organization can create one or more RCPs and bind one or more RCPs to the entire organization (i.e., to the root node of the organization). The resources of all accounts in the organization are managed and controlled by the RCP.

[0082] The RCP bound to the entire target organization is the RCP corresponding to the target cloud resource. For example, if only one RCP 1 is bound to the root node of the target organization, the RCP corresponding to the target cloud resource is RCP 1. If RCP 1, RCP 2, and RCP 3 are bound to the root node of the target organization, the RCPs corresponding to the target cloud resource are RCP 1, RCP 2, and RCP 3.

[0083] There are several ways to determine the RCP corresponding to the target cloud resource information. For example, an index table is established using the resource identifier as an index of the RCP, and the RCP corresponding to the target cloud resource is quickly found using the resource identifier and the index table. A plurality of index terms in the index table are determined based on a plurality of resource identifiers, and the plurality of resource identifiers are a plurality of resource identifiers corresponding to a plurality of cloud resources in the target organization.

[0084] Alternatively, a mapping table is established to record the mapping relationship between organizations and RCPs, and the organizational member to which the target cloud resource belongs is determined based on the target cloud resource information, and then the target organization to which the organizational member belongs is discovered, and the mapping table is queried based on the target organization to obtain the RCP associated with the target organization, and the discovered RCP is the RCP corresponding to the target cloud resource.

[0085] Note that RCP is also a MAC policy, it does not provide permissions, it is used only as a constraint.

[0086] The cloud management platform acquires and records a first RCP among the RCPs bound to the target organization, the first RCP being a first RCP corresponding to the target cloud resource, and the first RCP indicating access permissions of users outside the target organization for the target cloud resource.

[0087] For example, the first RCP includes at least a first constraint, and the first constraint is used to restrict the case where the access user belongs to the target organization. When the resource access request is triggered by a user outside the target organization, that is, when the access user does not satisfy the first constraint, the first resource access request to access the target resource is denied.

[0088] Step S802: The cloud management platform obtains a first resource access request for a target cloud resource in the target organization, triggered by a user outside the target organization.

[0089] A user triggers a first resource access request for a target cloud resource in a target organization through a client (e.g., client 40 in FIG. 7 ), and the first resource access request is sent to the cloud management platform 20 via a network (e.g., Internet 30 in FIG. 7 ). In this way, the cloud management platform 20 obtains the first resource access request for a target cloud resource in the target organization triggered by the user.

[0090] The first resource access request carries target cloud resource information, and the cloud management platform may find a specific cloud resource, for example, a target cloud resource in a target organization, based on the target cloud resource information.

[0091] The target cloud resource information includes resource identification information, which may include any information capable of identifying a resource, such as a resource identifier, information about the product to which the resource belongs, and information about the region in which the resource is located. The resource identifier may identify a specific cloud resource. The information about the product to which the cloud resource belongs may include information about the service indicating the cloud product to which the cloud resource belongs. The information about the region in which the cloud resource is located may include the name or address of the region in which the cloud resource is located, etc.

[0092] It will be appreciated that the target cloud resource may be any type of cloud resource, for example, virtual machines and containers for computing services, buckets for object storage services, EVS disks, and cloud databases.

[0093] The user is a user outside the target organization. That is, there are two cases where the user does not belong to the target organization. In one case, the user registers a cloud account in the cloud, but the account does not belong to the target organization. For example, the first resource access request carries a user account registered by a user outside the target organization of the cloud management platform. After receiving the first resource access request, the cloud management platform obtains the user account carried in the first resource access request through analysis. If the user account does not belong to multiple user accounts corresponding to the target organization, the cloud management platform determines that the first resource access request is triggered by a user outside the target organization.

[0094] In other words, the access request is from another user on the cloud, and the user has registered on the cloud but is not within the target organization, and the cloud management platform determines that the access request sent by the user is triggered by a user outside the target organization.

[0095] It should be noted that the user account may be, for example, any one or combination of a username, real name, mobile phone number, ID card number, employee number, etc., as long as it can uniquely identify the user, and this is not limited to this embodiment of the present application.

[0096] It will be appreciated that for different public cloud vendors, a user account may have different names, for example, a user subscription and a user project.

[0097] In the other case, the user does not register an account with the cloud management platform, and the first resource access request does not carry a user account registered with the cloud management platform. If the analysis determines that the first resource access request does not carry a user account registered with the cloud management platform, the cloud management platform determines that the first resource access request is triggered by a user outside the target organization.

[0098] In other words, the access request is from another user outside the cloud, and the user is not registered with the cloud (i.e., the user does not have an account). The cloud management platform determines that the access request sent by the user is triggered by a user outside the target organization.

[0099] For example, the target cloud resource corresponding to the access request is a virtual machine. A web page used by a public network is provided on the cloud, and a terminal (e.g., a mobile phone or a personal computer) remote from the cloud can access the public network IP (target public network IP) of the web page by using the source public network IP of the terminal.

[0100] Step S803: The cloud management platform allows or denies the first resource access request to access the target cloud resource based on the first resource control policy recorded by the cloud management platform.

[0101] A first RCP of a target cloud resource in a target organization and a first resource access request of the target cloud resource in the target organization are obtained in steps S801 and S802. Then, authentication is performed on the first resource access request based on the first RCP. If the authentication is successful, the first resource access request to access the target cloud resource is permitted. If the authentication is unsuccessful, the first resource access request to access the target cloud resource is denied.

[0102] Specifically, a policy calculation is performed on the first resource access request based on the first RCP to obtain a policy calculation result, where the policy calculation result indicates whether authentication on the resource access request is successful.

[0103] For example, the first RCP includes a first constraint, and the first constraint is used to constrain the case where the access user belongs to the target organization. When a resource access request is triggered by a user outside the target organization, the policy calculation result is that the resource access request does not satisfy the first constraint, i.e., if the access user does not satisfy the first constraint, the authentication fails and the first resource access request to access the target resource is denied.

[0104] The policy calculation process determines whether the access request information satisfies the constraints of the RCP. For example, the RCP includes a constraint used to constrain the access user to belong to a target organization. In this case, the access user must belong to the target organization to satisfy the constraint. In other words, authentication for the access request can be successful, and the access request to access cloud resources within the target organization is permitted only if the access user belongs to the target organization. In this way, identities outside the organization are denied access to cloud resources within the organization, preventing cases in which an account within the organization shares cloud resources with members outside the organization for access and use in a multi-account scenario.

[0105] As can be seen from the above, according to the cloud resource access control method based on cloud computing technology provided in the present application, RCP is directly applied to resources within an organization to directly restrict access to resources within the organization, so that users outside the organization can be restricted from accessing cloud resources within the organization. For example, in an organization's multi-account environment, when resources are frequently shared among accounts, resources within the organization are controlled to prevent unauthorized access by users outside the organization.

[0106] FIG. 9 shows that an RCP is set in a target organization by using the cloud resource access control method based on cloud computing technology provided in this embodiment of the present application, so that identities outside the organization are prohibited from accessing target cloud resources (e.g., cloud resources S3 and EC2 in Acct-3 in FIG. 9 ) in the target organization (e.g., Org-1 in FIG. 9 ).

[0107] 10 illustrates another cloud resource access control method based on cloud computing technology according to an embodiment of the present application. This method can be applied to the cloud management platform 20 illustrated in FIG. 7 to control access of users within an organization to target cloud resources within the target organization. As shown in FIG. 10, this method includes at least steps S1001 to S1003.

[0108] Step S1001: The cloud management platform obtains and records a second resource control policy for a target cloud resource in the target organization configured by an administrator of the target organization, where the second resource control policy indicates the access permissions of users in the target organization for the target cloud resource.

[0109] The establishment of target organizations and registration management of user accounts is implemented in a similar manner as shown in Figure 8. For details, please refer to the previous description. For the sake of brevity, the details will not be repeated here.

[0110] An administrator of a target organization may create one or more RCPs and bind one or more RCPs to a target organization node. The resources of all accounts within the target organization node are managed and controlled by the RCP.

[0111] An RCP bound to a target organization node is an RCP corresponding to a target cloud resource in the target organization node. For example, if only one RCP 1 is bound to the target organization node, the RCP corresponding to the target cloud resource is RCP 1. If RCP 1, RCP 2, and RCP 3 are bound to the target organization node, the RCPs corresponding to the target cloud resource are RCP 1, RCP 2, and RCP 3.

[0112] There are several ways to determine the RCP corresponding to the target cloud resource information. For example, an index table is established using the resource identifier as an index of the RCP, and the RCP corresponding to the target cloud resource is quickly found using the resource identifier and the index table. A plurality of index terms in the index table are determined based on a plurality of resource identifiers, and the plurality of resource identifiers are a plurality of resource identifiers corresponding to a plurality of cloud resources in the target organization node.

[0113] Alternatively, a mapping table is established to record the mapping relationship between the organization node and the RCP, and the organization member to which the target cloud resource belongs is determined based on the target cloud resource information, and then the target organization node to which the organization member belongs is discovered, and the mapping table is queried based on the target organization node to obtain the RCP associated with the target organization node, and the discovered RCP is the RCP corresponding to the target cloud resource.

[0114] The cloud management platform acquires and records a second RCP among the RCPs bound to the target organization node, the second RCP being a second RCP corresponding to the target cloud resource, and the second RCP indicating the access permission of a user in the target organization for the target cloud resource.

[0115] Step S1002: The cloud management platform obtains a second resource access request for a target cloud resource in the target organization, triggered by a user in the target organization.

[0116] A user in the target organization triggers a second resource access request for a target cloud resource in the target organization through a client, and the second resource access request is sent to the cloud management platform 20 via a network (e.g., the Internet 30 in FIG. 7 ). In this way, the cloud management platform 20 obtains the second resource access request for the target cloud resource in the target organization triggered by the user.

[0117] The second resource access request carries target cloud resource information. The cloud management platform may find a specific cloud resource, for example, a target cloud resource in a target organization, based on the target cloud resource information.

[0118] The target cloud resource information includes resource identification information, which may include any information capable of identifying a resource, such as a resource identifier, information about the product to which the resource belongs, and information about the region in which the resource is located. The resource identifier may identify a specific cloud resource. The information about the product to which the cloud resource belongs may include information about the service indicating the cloud product to which the cloud resource belongs. The information about the region in which the cloud resource is located may include the name or address of the region in which the cloud resource is located, etc.

[0119] After receiving the second resource access request, the cloud management platform analyzes the user account carried in the second resource access request, and if the user account belongs to multiple user accounts corresponding to the target organization, the cloud management platform determines that the second resource access request is triggered by a user in the target organization.

[0120] Step S1003: The cloud management platform allows or denies the second resource access request to access the target cloud resource based on the second resource control policy recorded by the cloud management platform.

[0121] A second RCP of a target cloud resource in a target organization and a second resource access request of the target cloud resource in the target organization are obtained through steps S1001 and S1002. Then, authentication is performed on the second resource access request based on the second RCP. If the authentication is successful, the second resource access request to access the target cloud resource is permitted. If the authentication is unsuccessful, the second resource control policy to access the target cloud resource is denied.

[0122] Specifically, a policy calculation is performed on the second resource access request based on the second RCP to obtain a policy calculation result, and the policy calculation result indicates whether authentication for the resource access request is successful.

[0123] For example, the second RCP includes a second constraint, which is used to constrain the case where the access user belongs to the target organization node. If the resource access request is triggered by a user within the target organization but outside the target organization node, the policy calculation result is that the resource access request does not satisfy the first constraint, that is, if the access user does not satisfy the second constraint, authentication fails and the second resource access request to access the target resource is denied.

[0124] If an administrator does not want resources in a specific department to be accessed by organizational members in another department, for example, if colleagues in a non-finance department are to be restricted from accessing resources in the finance department, the administrator can configure a second RCP, which includes a constraint condition used to restrict cases in which an access user belongs to a target organization node (the target organization node is an organization node corresponding to the finance department), and the access user must belong to the target organization node to satisfy the constraint condition. In other words, only if the access user belongs to the target organization node, authentication for the access request may be successful, and access to resources within the target organization node is permitted. In this way, users with identities outside the organization are denied access to resources within the organization, and in a multi-account scenario, cases in which an account within an organization node shares resources with members outside the organization node for access and use are avoided. In other words, cases in which members of an unspecified department access cloud resources of a specific department node are avoided.

[0125] An RCP is a MAC model. An RCP is a set of constraints described using a DSL and may precisely describe the set of resources and actions to which access is permitted or denied, as well as the permitting or denying conditions. One or more RCPs may be bound to an organization or an organization node. An RCP includes a cloud resource identifier field (Resource), an effect field (Effect), a request type field (Action), and a condition field (Condition), where the cloud resource identifier field identifies the target cloud resource, the effect field identifies whether access to the target cloud resource is denied or permitted, the request type field identifies the request type of the first resource access request, and the condition field indicates a user outside the target organization.

[0126] See Figure 9. The fields may include Version, Statement, Effect, Action, Resource, Condition, etc., and each field corresponds to one policy element in the RCP. The fields of the RCP are described below.

[0127] Version: The version is an optional policy element (string), for example, "Version":"2012-10-17", which indicates the version of the RCP document. The cloud service provider's RCP document version may have only one value, 2012-10-17. If the RCP does not have a Version element, the default value of the RCP document version is 2012-10-17.

[0128] Statement: A statement is a required element (array), for example, "Statement":[{...},{...},{...}]. Statements are the main elements of a policy and are used to describe specific constraint rules. Each Statement element may contain multiple statements, and each statement is enclosed in {}.

[0129] Effect: Effect is a required element (string), for example, “Effect”:“Deny”. Effect is a component of the constraint rule of Statement, and each constraint rule must contain an element, which has only two values: Allow or Deny, representing “explicit allow” and “explicit deny”, respectively.

[0130] Action: Action is a required element (string), for example, "Action":"s3:GetObject". Action is a component of a constraint rule of Statement, and each constraint rule must include this element. The value contains two parts: service-name and action-name. service-name is the namespace of the cloud service (e.g., s3 in Figure 9), and action-name is the operation name of each product (e.g., GetObject in Figure 9). The values of service-name and action-name are case-insensitive, and the operation name may contain the wildcard character *.

[0131] Resource: Resource is a required element (string). * may be used to indicate all resource objects, or a specific restricted resource scope and project to which the resource belongs may be used, for example, “arn:aws:s3...secret_bucket / *” in Figure 9.

[0132] Condition: A condition is an optional element (string) that is a valid constraint.

[0133] Note that if an SCP has both Allow and Deny constraints, Deny takes precedence.

[0134] When a policy calculation is performed on a resource access request and the RCP corresponding to the resource access request, if the effect of the policy corresponding to the resource access request is Allow, the calculation result is true (i.e., access is permitted) and authentication is successful. If the effect of the policy is Deny, the calculation result is false (i.e., access is denied) and authentication fails.

[0135] The RCP shown in Figure 9 is used as an example to explain the policy calculation performed for a resource access request based on the RCP. The main elements of the Statement policy in the RCP are "Effect": "Deny"; "Action": "s3:GetObject"; and "Conditon": {"StringNotEquals": {"aws:PrincepalOrgID": "org-1"}. In other words, all buckets in organization org-1 (i.e., the target organization) are prohibited from being accessed by identities outside organization org-1 (i.e., the target organization). In other words, only if the accessing user belongs to the target organization will authentication for the access request be successful and access to bucket resources in the target organization be permitted.

[0136] The RCP may be configured based on actual requirements. For example, the RCP may include a constraint condition used to restrict the case where the source public network IP of the resource access request belongs to a predetermined IP network segment. The cloud management platform analyzes the resource access request information to obtain context information of the resource access request, where the context information includes IP network segment information, specifically, the source public network IP of the resource access request. The RCP corresponding to the target cloud resource includes a constraint condition that the source public network IP of the resource access request belongs to the predetermined IP network segment. In this case, the constraint condition can be satisfied only when the source public network IP of the resource access request belongs to the predetermined IP network segment. In other words, only when the source public network IP of the resource access request belongs to the predetermined IP network segment can authentication for the resource access request be successful, and the resource access request to access the resource in the target organization is permitted. In this way, the resource in the target organization can be accessed only when the access request is sent from a specific network segment.

[0137] For example, an administrator creates an RCP and binds the RCP to the root node of a target organization, and the RCP includes a constraint used to restrict the case where the source public network IP of a resource access request belongs to the public network segment where the target organization is located. In this case, access to cloud resources within the organization can be granted only when the resource access request is sent from the public network segment where the target organization is located.

[0138] In another example, to manage resources within an organization in a more sophisticated manner, an administrator may alternatively create an RCP and bind the RCP to a target organization or a target node of the target organization, where the RCP includes constraints used to constrain cases in which an action on the target resource belongs to a preset action. The resource access request information carries action information, and the action information indicates an action to be performed on the target resource. In this case, authentication for the resource access request may be successful and the action is permitted to be performed on the resource in the target organization only if the action belongs to the preset action.

[0139] For example, an administrator creates an RCP and binds the RCP to a target organization node, where the RCP includes a constraint used to constrain the cases in which an operation belongs to a read operation, in which only resource access requests of a read operation to access resources within the organization can be allowed, i.e., only read operations are allowed to be performed on resources within the target organization node.

[0140] It should be understood that if there are multiple RCPs corresponding to a target resource, authentication is successful only if the resource access request satisfies all RCPs corresponding to the target resource. For example, resource access request information includes target resource information, access user information, target resource operation information, and IP network segment information. RCPs corresponding to the target resource include RCP 1, RCP 2, and RCP 3. The constraint included in RCP 1 is that the access user belongs to the target organization node, the constraint included in RCP 2 is that the operation is a read operation, and the constraint included in RCP 3 is that the IP network segment is the public network segment where the target organization is located. Policy calculations are performed for the resource access request, RCP 1, RCP 2, and RCP 3, respectively. Authentication is successful only if all policy calculation results are successful. In other words, authentication is successful only if a member of the target organization node sends a read operation request from the public network segment where the target organization is located via RCP 1, RCP 2, and RCP 3. In other words, only members within the target organization node are permitted to perform read operations on resources within the target organization node from the public network segment on which the target organization is located.

[0141] The following uses specific examples to describe a specific implementation of the cloud resource access control method based on cloud computing technology provided in the embodiments of the present application.

[0142] As shown in FIG. 11, the cloud management platform includes three systems: an organization management system, an authentication system, and a service system. The organization management system provides an interface for creating RCPs and binding RCPs for customers (e.g., organization administrators). The service system provides specific APIs to collect resource information (e.g., resource identifiers) included in user requests (e.g., resource access requests) and forward the resource information to the authentication system. Based on the received resource identifiers, the authentication system queries the organization where the account to which the resource belongs is located from the organization management system and obtains all RCPs that affect the account. The authentication system performs policy calculation based on the RCPs corresponding to the target account and the user request, determines whether the user request for access is authorized, and returns the result to the service system.

[0143] 11 illustrates an implementation process of a cloud resource access control method based on cloud computing technology in a specific application scenario according to an embodiment of the present application. As shown in FIG. 11, an organization administrator first creates an RCP in step S1, and then binds the RCP to an organization node in step S2 to implement access control for resources within the organization or organization node.

[0144] When a common user needs to access a resource in the organization, the common user sends a request to call an API to the service system in step S3, where the request to call the API carries a resource identifier. Then, the service system sends an authentication request to the authentication system in step S4, where the authentication request carries a resource identifier, and the resource identifier uniquely identifies the target resource. Optionally, the resource identifier includes information about the account to which the resource belongs.

[0145] In step S5, the authentication system sends a request to the organization management system to query the RCP corresponding to the target resource, and the organization management system queries the organization in which the account is located and the RCP that applies to the account based on the information about the account carried in the resource identifier.

[0146] In step S6, the organizational management system returns the discovered RCP set corresponding to the target resource to the authentication system.

[0147] In step S7, the authentication system performs policy calculation based on the RCP and the request context (specifically, the target resource information, access user information, operation information, and IP network segment information carried in the resource access request), and the policy calculation result indicates whether the authentication is successful.

[0148] In step S8, the authentication system returns the authentication result to the service system. In step S9, the service system responds to the user's request. If the authentication is successful, the service system feeds back the access result to the user, or if the authentication is unsuccessful, the service system returns a result of rejecting the request to the user.

[0149] It should be understood that the organization management system, authentication system, and service system may be distributed across different servers or implemented by different modules within a server, which is not limited in this embodiment of the present application. In a public cloud scenario, the organization management system is a corresponding cloud service. Different public cloud vendors have correspondingly different names, such as resource directory service and organization service. The authentication system corresponds to an access control service on the cloud. The service system corresponds to various cloud services, such as S3, EC2, and OBS.

[0150] To implement the cloud resource access control method based on the cloud computing technology provided in the embodiments of the present application, an embodiment of the present application further provides a cloud management platform, which is configured to manage an infrastructure providing multiple cloud resources, the infrastructure including at least one cloud data center, multiple servers arranged in each cloud data center, one or any combination of the multiple cloud resources being deployed on the at least one server of the infrastructure, and the multiple cloud resources being configured in at least one organization.

[0151] 12 is a diagram of the structure of a cloud management platform according to an embodiment of the present application. As shown in FIG. 12, the cloud management platform 20 includes: an organization management module 2001, a service module 2002, and an authentication module 2003. The organization management module 2001 is configured to acquire and record a first resource control policy for a target cloud resource in the target organization configured by an administrator of the target organization, the first resource control policy indicating an access permission of a user outside the target organization to the target cloud resource; the service module 2002 is configured to acquire a first resource access request for the target cloud resource in the target organization triggered by a user outside the target organization; the authentication module 2003 is configured to determine a first authentication result based on the first resource control policy recorded by the organization management module, the first authentication result allowing or denying the first resource access request to access the target cloud resource; and the service module is further configured to acquire the first authentication result from the authentication module and allow or deny the first resource access request to access the target cloud resource based on the first authentication result.

[0152] In a possible implementation, the organization management module 2001 is further configured to obtain and record a second resource control policy for a target cloud resource within the target organization configured by an administrator of the target organization, the second resource control policy indicating access permissions of users within the target organization for the target cloud resource; the service module 2002 is further configured to obtain a second resource access request for the target cloud resource within the target organization triggered by a user within the target organization; the authentication module 2003 is configured to determine a second authentication result based on the second resource control policy recorded by the organization management module, the second authentication result being to allow or deny the second resource access request to access the target cloud resource; and the service module is further configured to obtain the second authentication result from the authentication module and to allow or deny the second resource access request to access the target cloud resource based on the second authentication result.

[0153] In another possible implementation, the cloud management platform further includes a registration module 2004. The registration module 2004 is configured to obtain a plurality of registration requests carrying different user accounts, and to respectively register and record the plurality of user accounts based on the plurality of registration requests, where the plurality of user accounts includes an administrator account, and the organization management module 2001 is configured to classify the plurality of user accounts into a target organization and set the administrator account as an administrator account of the target organization.

[0154] In another possible implementation, the first resource access request carries a user account registered by a user outside a target organization of the cloud management platform, and the service module is configured to determine that the first resource access request was triggered by a user outside the target organization if the service module determines that the user account carried in the first resource access request does not belong to the multiple user accounts corresponding to the target organization recorded by the registration module.

[0155] In another possible implementation, the first resource access request does not carry a user account registered with the cloud management platform, and the service module is configured to determine that the first resource access request was triggered by a user outside the target organization if it determines that the first resource access request does not carry a user account registered with the cloud management platform.

[0156] In another possible implementation, the first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field, where the cloud resource identifier field identifies a target cloud resource, the effect field identifies that access to the target cloud resource is denied or allowed, the request type field identifies a request type of the first resource access request, and the condition field indicates a user outside the target organization.

[0157] In another possible implementation, the types of cloud resources include virtual machines and containers for computing services, buckets for object storage services, EVS disks, and cloud databases.

[0158] It should be understood that the organization management module, service module, authentication module, and registration module in the cloud management platform may be distributed to different servers or implemented by different modules in a server. This is not limited to this embodiment of the present application. In a public cloud scenario, the organization management module is a corresponding organization management service. Different public cloud vendors have correspondingly different names, such as resource directory service and organization service. The service module corresponds to various cloud services, such as computing service, storage service, and network service. The authentication module corresponds to an authentication service on the cloud. The registration module corresponds to a registration service on the cloud.

[0159] The organization management module 2001, the service module 2002, the authentication module 2003, and the registration module 2004 may all be implemented using software or hardware. For example, in the following, the organization management module 2001 is used as an example to describe the implementation form of the organization management module 2001. Similarly, for the implementation forms of the service module 2002, the authentication module 2003, and the registration module 2004, please refer to the implementation form of the organization management module 2001.

[0160] A module is used as an example of a software functional unit, and the organization management module 2001 may include code running on a computing instance. A computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Furthermore, there may be one or more computing instances. For example, the organization management module 2001 may include code running on multiple hosts / virtual machines / containers. Note that multiple hosts / virtual machines / containers used to execute the code may be distributed in the same region or in different regions. Furthermore, multiple hosts / virtual machines / containers used to execute the code may be distributed in the same availability zone (AZ) or in different AZs. Each AZ includes one or more data centers that are geographically close to each other. Generally, one region may include multiple AZs.

[0161] Similarly, multiple hosts / virtual machines / containers used to run code may be distributed in the same virtual private cloud (VPC) or across multiple VPCs. Generally, one VPC is configured in one region. For communication between two VPCs in the same region or between VPCs in different regions, a communication gateway must be configured in each VPC. Interconnection between VPCs is implemented through a communication gateway.

[0162] A module is used as an example of a hardware functional unit. The organization management module 2001 may include at least one computing device, such as a server. Alternatively, the organization management module 2001 may be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be implemented using a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0163] The computing devices included in the organization management module 2001 may be distributed in the same region or in different regions. The computing devices included in the organization management module 2001 may be distributed in the same AZ or in different AZs. Similarly, the computing devices included in the organization management module 2001 may be distributed in the same VPC or in multiple VPCs. The computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0164] It should be noted that in another embodiment, the organization management module 2001 may be configured to perform any step of the cloud resource access control method based on cloud computing technology, the service module 2002 may be configured to perform any step of the cloud resource access control method based on cloud computing technology, and the authentication module 2003 may be configured to perform any step of the cloud resource access control method based on cloud computing technology. The steps whose implementation is in charge of the organization management module 2001, the service module 2002, the authentication module 2003, and the registration module 2004 may be specified as needed. The organization management module 2001, the service module 2002, the authentication module 2003, and the registration module 2004 are each configured to implement different steps of the cloud resource access control method based on cloud computing technology in order to implement all functions of the cloud management platform.

[0165] The present application further provides a computing device 1300. As shown in Figure 13, the computing device 1300 includes a bus 1302, a processor 1304, a storage 1306, and a communication interface 1308. The processor 1304, the storage 1306, and the communication interface 1308 communicate with each other via the bus 1302. The computing device 1300 may be a server or a terminal device. It should be understood that the number of processors and storages in the computing device 1300 is not limited in the present application.

[0166] The bus 1302 may be a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, or the like. The bus may be categorized into an address bus, a data bus, a control bus, and the like. For ease of illustration, the bus is shown in FIG. 13 using only one line. However, this does not imply that there is only one bus or only one type of bus. The bus 1302 may include a path for transmitting information between components of the computing device 1300 (e.g., the storage 1306, the processor 1304, and the communication interface 1308).

[0167] The processor 1304 may include any one or more of a processor such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0168] Storage 1306 may include volatile memory, such as random access memory (RAM), and may further include non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0169] The storage 1306 stores executable program code, and the processor 1304 executes the executable program code to separately implement the functions of the organization management module 2001, the service module 2002, the authentication module 2003, and the registration module 2004, and to implement a cloud resource access control method based on cloud computing technology. In other words, the storage 1306 stores instructions used to execute a cloud resource access control method based on cloud computing technology.

[0170] The communication interface 1308 implements communications between the computing device 1300 and another device or communication network through the use of a transceiver module, such as, for example, but not limited to, a network interface card or a transceiver.

[0171] An embodiment of the present application further provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device may be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device may alternatively be a terminal device, such as a desktop computer, a notebook computer, or a smartphone.

[0172] 14 , the computing device cluster includes at least one computing device 1300. Storage 1306 in one or more computing devices 1300 in the computing device cluster may store the same instructions used to execute the cloud resource access control method based on cloud computing technology.

[0173] In some possible implementations, the storage 1306 in one or more computing devices 1300 in the computing device cluster may alternatively separately store some instructions used to execute a cloud resource access control method based on cloud computing technology. In other words, a combination of one or more computing devices 1300 may together execute instructions used to execute a cloud resource access control method based on cloud computing technology.

[0174] It should be noted that the storages 1306 in different computing devices 1300 in the computing device cluster may store different instructions, each used to perform certain functions of the cloud management platform. In other words, the instructions stored in the storages 1306 in the different computing devices 1300 may implement the functions of one or more of the organization management module 2001, the service module 2002, the authentication module 2003, and the registration module 2004.

[0175] In some possible implementations, one or more computing devices in a computing device cluster may be connected via a network. The network may be a wide area network, a local area network, or the like. FIG. 15 illustrates a possible implementation. As shown in FIG. 15, two computing devices 1300A and 1300B are connected via a network. Specifically, each computing device is connected to the network via a communication interface of the computing device. In this type of possible implementation, the storage 1306 in the computing device 1300A stores instructions for performing the functions of the organization management module 2001 and the service module 2002. Furthermore, the storage 1306 in the computing device 1300B stores instructions for performing the functions of the authentication module 2003 and the registration module 2004.

[0176] 15 may alternatively be completed by multiple computing devices 1300. Similarly, the functions of computing device 1300B may alternatively be completed by multiple computing devices 1300.

[0177] An embodiment of the present application further provides a computer program product including instructions. The computer program product may be software or a program product including instructions and capable of being executed on a computing device or stored in any available medium. When the computer program product is executed on at least one computing device, the at least one computing device is enabled to execute a cloud resource access control method based on cloud computing technology.

[0178] An embodiment of the present application further provides a computer-readable storage medium. The computer-readable storage medium may be any available medium accessible by a computing device, or a data storage such as a data center including one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk drive, or a magnetic tape), an optical medium (e.g., a DVD), a semiconductor medium (e.g., a solid-state drive), etc. The computer-readable storage medium includes instructions for instructing a computing device to perform a cloud resource access control method based on cloud computing technology.

[0179] In the above embodiments, the description of each embodiment focuses on each, and for the parts not described in detail in one embodiment, please refer to the related descriptions of other embodiments.

[0180] The basic principles of the present application have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, effects, etc. mentioned in the present application are merely examples and not limitations, and these advantages, benefits, effects, etc. cannot be considered mandatory for the embodiments of the present disclosure. In addition, the specific details disclosed above are merely for the purpose of illustration and ease of understanding, and are not intended to be limiting. The above details do not limit the cases in which the present disclosure must be implemented using the above specific details.

[0181] Block diagrams of apparatus, devices, and systems in this disclosure are merely examples and are not intended to require or imply that the connections, arrangements, and configurations must be performed in the manner shown in the block diagrams. Those skilled in the art will recognize that components, apparatus, devices, and systems may be connected, arranged, and configured in any manner. Words such as "comprise," "contain," and "have" are open words and may refer to and be used interchangeably with "including but not limited to." As used herein, the terms "or" and "and" refer to the term "and / or" and may be used interchangeably unless the context clearly dictates otherwise. As used herein, the word "for example" refers to and may be used interchangeably with the phrase "for example, but not limited to."

[0182] It is further noted that in the apparatus, devices, and methods disclosed in this disclosure, components or steps may be disassembled and / or recombined, which should be considered equivalent solutions of the present disclosure.

[0183] The foregoing description has been provided for purposes of illustration and description. Furthermore, the description is not intended to limit the embodiments of the present disclosure to the form disclosed herein. While several exemplary aspects and embodiments have been described above, those skilled in the art will recognize several variations, modifications, variations, additions, and subcombinations thereof.

[0184] It will be understood that the various numbers in the embodiments of the present application are used merely for distinction purposes to facilitate description, and are not used to limit the scope of the embodiments of the present application.

[0185] Those skilled in the art can further recognize that, in combination with the examples described in the embodiments disclosed herein, the units and algorithm steps can be implemented by electronic hardware, computer software, or a combination of the two. To clearly explain the compatibility between hardware and software, the configurations and steps of each example are generally described in the foregoing specification based on their functions. Whether these functions are performed by hardware or software depends on the specific application and the design constraints of the technical solution. Those skilled in the art can implement the described functions using various methods for each specific application, but such implementation should not be considered to go beyond the scope of this application.

[0186] The steps of a method or algorithm described in the embodiments disclosed herein may be implemented by hardware, a software module executed by a processor, or a combination of hardware and software. The software module may be inserted in a random access memory (RAM), a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a movable disk, a CD-ROM, or any other form of storage medium known in the art.

[0187] In the above specific implementations, the objectives, technical solutions and advantages of the present application are further described in detail. It should be understood that the above description is only a specific implementation of the present application and is not intended to limit the protection scope of the present application. Any modification, equivalent replacement or improvement made without departing from the principle of the present application shall fall within the protection scope of the present application. [Explanation of symbols]

[0188] 1. Infrastructure 11. Computing Devices 12 Computing Devices 13. Computing Devices 20 Cloud Management Platform 30 Internet 40 clients 100 Cloud Data Centers 111 Cloud Resources 112 cloud resources 113 Cloud Resources 114 cloud resources 115 Operating Systems 116 memory 117 processors 118 Network Adapter 119 Hard Disk 121 cloud resources 122 cloud resources 123 cloud resources 124 cloud resources 200 Cloud Data Centers 1151 Cloud Resource Manager 1152 Cloud Management Platform Client 1300 computing devices 1300A Computing Device 1300B Computing Device 1302 Bus 1304 processor 1306 Storage 1308 Communication Interface 2001 Organization Management Module 2002 Service Module 2003 Authentication Module 2004 Registration Module

Claims

1. A cloud resource access control method based on cloud computing technology, the method being applied to a cloud management platform, the cloud management platform being configured to manage an infrastructure providing a plurality of cloud resources, the infrastructure including at least one cloud data center, a plurality of servers being located in each cloud data center, one or any combination of the plurality of cloud resources being deployed on at least one server of the infrastructure, the plurality of cloud resources being configured for at least one organization, the method comprising: Obtaining and recording, by the cloud management platform, a first resource control policy for a target cloud resource in the target organization configured by an administrator of the target organization, wherein the first resource control policy indicates access permissions of users outside the target organization for the target cloud resource; Obtaining, by the cloud management platform, a first resource access request for the target cloud resource within the target organization, triggered by the user outside the target organization; allowing or denying, by the cloud management platform, the first resource access request for accessing the target cloud resource based on the first resource control policy recorded by the cloud management platform; Including, Cloud resource access control method.

2. Obtaining and recording, by the cloud management platform, a second resource control policy for the target cloud resource at the target organization configured by the administrator of the target organization, wherein the second resource control policy indicates access permissions of users at the target organization for the target cloud resource; obtaining, by the cloud management platform, a second resource access request for the target cloud resource in the target organization triggered by the user in the target organization; allowing or denying, by the cloud management platform, the second resource access request for accessing the target cloud resource based on the second resource control policy recorded by the cloud management platform; 3. The method of claim 2, further comprising:

3. Before the step of obtaining and recording, by the cloud management platform, a first resource control policy for a target cloud resource in the target organization, the first resource control policy being configured by an administrator of the target organization, The method comprises: Obtaining, by the cloud management platform, a plurality of registration requests carrying different user accounts; respectively registering and recording, by the cloud management platform, a plurality of user accounts based on the plurality of registration requests, wherein the plurality of user accounts includes an account of the administrator; classifying the plurality of user accounts into the target organization by the cloud management platform, and setting the administrator's account as an administrator account of the target organization; 3. The method of claim 1 or 2, further comprising:

4. the first resource access request carries a user account registered by the user outside the target organization on the cloud management platform; The step of obtaining, by the cloud management platform, a first resource access request for the target cloud resource within the target organization, triggered by the user outside the target organization, includes: determining, by the cloud management platform, when determining that the user account carried in the first resource access request does not belong to the plurality of user accounts corresponding to the target organization, that the first resource access request is triggered by the user outside the target organization; 4. The method of claim 3, comprising:

5. The step of acquiring, by the cloud management platform, a first resource access request for the target cloud resource within the target organization, the first resource access request not carrying a user account registered with the cloud management platform and triggered by the user outside the target organization, includes: determining, by the cloud management platform, that the first resource access request was triggered by the user outside the target organization if it is determined that the first resource access request does not carry the user account registered with the cloud management platform; 4. The method of claim 3, comprising:

6. the first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field; 6. The method of claim 1, wherein the cloud resource identifier field identifies the target cloud resource, the effect field identifies whether access to the target cloud resource is denied or allowed, the request type field identifies a request type of the first resource access request, and the condition field indicates a user outside the target organization.

7. The method of claim 1 , wherein the types of cloud resources include virtual machines, containers for computing services, buckets for object storage services, EVS disks, and cloud databases.

8. A cloud management platform configured to manage an infrastructure providing a plurality of cloud resources, the infrastructure including at least one cloud data center, a plurality of servers located in each cloud data center, one or any combination of the plurality of cloud resources being deployed on at least one server of the infrastructure, the plurality of cloud resources being configured for at least one organization; The cloud management platform: an organization management module configured by an administrator of a target organization to obtain and record a first resource control policy for a target cloud resource within the target organization, the first resource control policy indicating access permissions for users outside the target organization for the target cloud resource; a service module configured to obtain a first resource access request for the target cloud resource within the target organization triggered by the user outside the target organization; an authentication module configured to determine a first authentication result based on the first resource control policy recorded by the organization management module, wherein the first authentication result is to allow or deny the first resource access request to access the target cloud resource; Including, the service module is further configured to obtain the first authentication result from the authentication module; and permit or deny the first resource access request for accessing the target cloud resource based on the first authentication result. Cloud management platform.

9. The organization management module is further configured to obtain and record a second resource control policy for the target cloud resource in the target organization configured by the administrator of the target organization, the second resource control policy indicating access permissions of users in the target organization for the target cloud resource; the service module is further configured to obtain a second resource access request for the target cloud resource in the target organization triggered by the user in the target organization; The authentication module is configured to determine a second authentication result based on the second resource control policy recorded by the organization management module, and the second authentication result is to allow or deny the second resource access request to access the target cloud resource; the service module is further configured to obtain the second authentication result from the authentication module; and permit or deny the second resource access request for accessing the target cloud resource based on the second authentication result. The cloud management platform of claim 8.

10. The cloud management platform: a registration module configured to receive a plurality of registration requests carrying different user accounts, and to respectively register and record a plurality of user accounts based on the plurality of registration requests, wherein the plurality of user accounts includes an account of the administrator; the organization management module is configured to categorize the plurality of user accounts into the target organization and set the account of the administrator as an administrator account of the target organization; 10. The cloud management platform of claim 8 or 9.

11. the first resource access request carries a user account registered by the user outside the target organization on the cloud management platform; the service module is configured to determine that the first resource access request was triggered by the user outside the target organization if it determines that the user account carried in the first resource access request does not belong to the plurality of user accounts corresponding to the target organization and recorded by the registration module; The cloud management platform of claim 10.

12. the first resource access request does not carry a user account registered with the cloud management platform; the service module is configured to determine that the first resource access request was triggered by the user outside the target organization if it determines that the first resource access request does not carry the user account registered with the cloud management platform; The cloud management platform of claim 10.

13. 13. The cloud management platform of claim 8, wherein the first resource control policy includes a cloud resource identifier field, an effect field, a request type field, and a condition field, wherein the cloud resource identifier field identifies the target cloud resource, the effect field identifies that access to the target cloud resource is denied or allowed, the request type field identifies a request type of the first resource access request, and the condition field indicates a user outside the target organization.

14. 14. The cloud management platform of claim 8, wherein the types of cloud resources include virtual machines, containers for computing services, buckets for object storage services, EVS disks, and cloud databases.

15. a computing device cluster, the computing device cluster including at least one computing device, each computing device including a processor and storage; the storage is configured to store instructions; the processor is configured to, based on the instructions, enable the computing device cluster to perform the method of any one of claims 1 to 7. Computing device cluster.

16. A computer readable storage medium storing a computer program, which, when executed by a processor, implements the method of any one of claims 1 to 7.

17. 8. A computer program product comprising instructions, which when executed on a computing device, enable the computing device to perform the method of any one of claims 1 to 7.

Citation Information

Patent Citations

  • Selectively granting computer system access credentials to external users and non-users

    EP3945707A1

  • Device, program and method for managing file

    JP2011134037A

  • Account authentication method for cloud storage, and server

    US20200028838A1

  • User information management system, user information management method, management server program and recording medium with same recorded thereon, user terminal program and recording medium with same recorded thereon, and service server program and recording medium with same recorded thereon

    WO2016017324A1

  • Service-providing system

    WO2017090142A1