Access control method based on cloud management platform, and cloud management platform
By implementing a credential-based access control method on the cloud management platform, allowing tenants to customize access relationships between multiple cloud instances, the problem that tenants cannot actively control access relationships in the existing technology is solved, improving the tenant experience and ensuring data security.
Patent Information
- Application Number
- PCT/CN2024/140852
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-04-26
- Filing Date
- 2024-12-20
- Publication Date
- 2025-06-26
AI Technical Summary
In existing cloud technology, tenants cannot actively control the access relationship between multiple cloud instances, resulting in poor tenant experience and possible data security issues.
By implementing a credential-based access control method on the cloud management platform, tenants are allowed to customize access relationships between multiple cloud instances by providing access control policies. The specific steps include: the first cloud instance sends a credential acquisition request to the cloud management platform, the cloud management platform parses the access control policy and detects whether the first cloud instance is in the cloud instance specified in the policy, and if so, sends the tenant's credentials to the first cloud instance.
It realizes the active control of the access relationship between multiple cloud instances by tenants, improves the tenant experience, and enhances the flexibility of data processing while ensuring data security.
Smart Images

Figure CN2024140852_26062025_PF_FP_ABST
Abstract
Description
An access control method based on cloud management platform and cloud management platform
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 22, 2023, with application number 202311785301.5 and application name “A cross-service forwarding method based on cloud management platform and cloud management platform”, and claims priority to the Chinese patent application filed with the State Intellectual Property Office on April 26, 2024, with application number 202410516416.2 and application name “A access control method based on cloud management platform and cloud management platform”, all contents of which are incorporated by reference into this application. Technical Field
[0002] The embodiments of the present application relate to the field of cloud technology, and in particular to an access control method based on a cloud management platform and a cloud management platform. Background Art
[0003] With the rapid development of cloud technology, more and more tenants are choosing to deploy cloud services to handle their business. Generally, when tenants need to call multiple cloud services to handle their business, communication occurs between the multiple cloud instances used to deploy multiple cloud services, forming a communication chain.
[0004] In related technologies, a cloud service system includes a cloud management platform and multiple cloud instances that provide cloud services to tenants. The cloud management platform can, based on the tenant's access control requirements, limit the access relationships between multiple cloud instances. For example, the cloud management platform can limit the first cloud instance among multiple cloud instances to access the second cloud instance among multiple cloud instances, while the first cloud instance cannot access the third cloud instance among multiple cloud instances. When a tenant has data processing requirements, since data processing also requires the first cloud instance and the second cloud instance to complete it together, after the tenant accesses the first cloud instance, the first cloud instance will query the cloud management platform whether it can access the second cloud instance. The cloud management platform can allow the first cloud instance to access the second cloud instance to meet the tenant's data processing requirements.
[0005] In the above process, since the access relationship is established by the cloud management platform, it is a black box for tenants. Tenants cannot actively control the access relationship between multiple cloud instances, resulting in a poor tenant experience. Summary of the Invention
[0006] The embodiments of the present application provide an access control method and a cloud management platform based on a cloud management platform, which enable tenants to manage mutual access between multiple cloud instances, thereby improving the tenant experience.
[0007] A first aspect of an embodiment of the present application provides an access control method based on a cloud management platform. The cloud management platform used to implement the method can manage multiple cloud instances that provide cloud services to tenants. The multiple cloud instances can communicate with each other based on the tenant's credentials. The method includes:
[0008] Among multiple cloud instances serving tenants, when a first cloud instance needs to access a second cloud instance, the first cloud instance may send a credential acquisition request to the cloud management platform, wherein the credential acquisition request is used to indicate the tenant's access control policy for multiple cloud instances, and the access control policy is provided by the tenant to the first cloud instance, and the access control policy is used to indicate at least one cloud instance among the multiple cloud instances from which the credential can be obtained.
[0009] After receiving the credential acquisition request from the first cloud instance, the cloud management platform can parse the credential acquisition request to obtain the access control policy. The cloud management platform can then detect whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy. If the first cloud instance is located in the at least one cloud instance, the cloud management platform sends the tenant's credentials to the first cloud instance, allowing the first cloud instance to access the second cloud instance based on the tenant's credentials.
[0010] It can be seen from the above method that: among the multiple cloud instances serving the tenant, at least one cloud instance that can be granted the tenant's credentials is specified by the tenant. The at least one authorized cloud instance can obtain the tenant's credentials from the cloud management platform to access the remaining cloud instances. In other words, the access relationship between these multiple cloud instances is customized by the tenant. Therefore, for the first cloud instance among these multiple cloud instances, whether it can access the second cloud instance is set in advance by the tenant. Therefore, it is set entirely in accordance with the tenant's access control intention. The tenant can achieve active control over the first cloud instance, which is beneficial for the tenant to manage mutual access between these multiple cloud instances, thereby improving the tenant's experience and ensuring the security of the tenant's data on the cloud instance.
[0011] In one possible implementation, an access control policy is used to indicate a cloud instance whitelist set by a tenant, the cloud instance whitelist comprising at least one cloud instance from a plurality of cloud instances. The cloud management platform, based on a credential acquisition request, detecting whether a first cloud instance is located in the at least one cloud instance indicated by the access control policy includes: the cloud management platform, based on the credential acquisition request, detecting whether the first cloud instance is located in the cloud instance whitelist indicated by the access control policy. In the aforementioned implementation, after receiving the credential acquisition request sent by the first cloud instance, the cloud management platform may parse the request to determine the access control policy established by the tenant for the plurality of cloud instances. When the access control policy includes the cloud instance whitelist set by the tenant, since the cloud instance whitelist includes at least one cloud instance selected by the tenant from the plurality of cloud instances, the cloud management platform detects whether the first cloud instance is located in the cloud instance whitelist. If the first cloud instance is located in the cloud instance whitelist, the cloud management platform may provide the tenant's credentials to the first cloud instance, so that the first cloud instance can use the tenant's credentials to access the second cloud instance.
[0012] In one possible implementation, each cloud instance includes at least one interface, the credential acquisition request is also used to indicate the interface of the first cloud instance called by the tenant, the access control policy is used to indicate the interface whitelist set by the tenant, the interface whitelist is composed of the interface of at least one cloud instance among multiple cloud instances, and the cloud management platform detects whether the first cloud instance is located in at least one cloud instance indicated by the access control policy based on the credential acquisition request, including: the cloud management platform detects whether the interface of the first cloud instance called by the tenant is located in the interface whitelist indicated by the access control policy based on the credential acquisition request. In the aforementioned implementation, after receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse out the interface of the first cloud instance called by the tenant and the access control policy established by the tenant for multiple cloud instances from the request. When the access control policy includes an interface whitelist set by the tenant, since the interface whitelist includes the interface of at least one cloud instance selected by the tenant from the interfaces of these multiple cloud instances, the cloud management platform can detect whether the interface of the first cloud instance called by the tenant is in the interface whitelist. If the interface of the first cloud instance called by the tenant is in the interface whitelist, the cloud management platform can provide the tenant's credentials to the first cloud instance, so the first cloud instance can use the tenant's credentials to access the second cloud instance.
[0013] In one possible implementation, an access control policy is used to indicate a tenant's identity. A cloud management platform has a pre-set identity whitelist for a first cloud instance, the identity whitelist consisting of multiple pre-set identities. The cloud management platform, based on a credential acquisition request, detecting whether the first cloud instance is located in at least one cloud instance indicated by the access control policy includes: the cloud management platform, based on the credential acquisition request, detecting whether the identity indicated by the access control policy is located in the identity whitelist. In the aforementioned implementation, after receiving the credential acquisition request from the first cloud instance, the cloud management platform may parse the request to determine the access control policy established by the tenant for the multiple cloud instances. When the access control policy includes the identity used by the tenant to access the first cloud instance, since the cloud management platform has a pre-set identity whitelist for the first cloud instance, the cloud management platform may detect whether the identity used by the tenant to access the first cloud instance is located in the identity whitelist for the first cloud instance. If the identity used by the tenant to access the first cloud instance is located in the identity whitelist for the first cloud instance, the cloud management platform may provide the tenant's credentials to the first cloud instance, so that the first cloud instance can use the tenant's credentials to access the second cloud instance.
[0014] In one possible implementation, an access control policy indicates a communication duration set by a tenant and a time when the tenant accesses a first cloud instance. The cloud management platform, based on a credential acquisition request, detecting whether the first cloud instance is located in at least one cloud instance indicated by the access control policy includes: the cloud management platform detecting, based on the credential acquisition request, whether a difference between the time indicated by the access control policy and the current time is less than the communication duration indicated by the access control policy. In the aforementioned implementation, after receiving the credential acquisition request from the first cloud instance, the cloud management platform may parse the request to determine the access control policy established by the tenant for multiple cloud instances. When the access control policy includes the time when the tenant accesses the first cloud instance and the communication duration of the entire communication chain set by the tenant, the cloud management platform may calculate the difference between the time when the tenant accesses the first cloud instance and the current time, and detect whether the difference is less than the communication duration of the entire communication chain set by the tenant. If the difference is less than the communication duration, the cloud management platform may provide the tenant's credentials to the first cloud instance, so that the first cloud instance can use the tenant's credentials to access the second cloud instance.
[0015] In one possible implementation, an access control policy is used to indicate a feasible communication path set by a tenant between a tenant and a first cloud instance. The cloud management platform detects, based on a credential acquisition request, whether the first cloud instance is located in at least one cloud instance indicated by the access control policy, including: the cloud management platform detects, based on the credential acquisition request, whether the current communication path between the tenant and the first cloud instance matches the feasible communication path indicated by the access control policy. In the aforementioned implementation, after receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse the request to obtain the access control policy established by the tenant for multiple cloud instances. When the access control policy includes a feasible communication path between the tenant and the first cloud instance, the cloud management platform can detect whether the current communication path between the tenant and the first cloud instance matches the feasible communication path between the tenant and the first cloud instance. If the two match, the cloud management platform can provide the tenant's credentials to the first cloud instance, so that the first cloud instance can use the tenant's credentials to access the second cloud instance.
[0016] In one possible implementation, the access control policy is also used to indicate the signature of the access control policy, and the signature is obtained by the tenant performing a signature operation on the access control policy. The cloud management platform detects whether the first cloud instance is located in at least one cloud instance indicated by the access control policy based on the credential acquisition request, including: the cloud management platform performs a signature verification operation on the signature indicated by the access control policy based on the credential acquisition request; if the signature verification operation is successful, the cloud management platform detects whether the first cloud instance is located in at least one cloud instance indicated by the access control policy. In the aforementioned implementation, after receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse the access control policy formulated by the tenant for multiple cloud instances from the request. The access control policy may include the signature of the access control policy, which is obtained by the tenant performing a signature operation on the remaining fields contained in the access control policy. Then, the cloud management platform can first perform a signature verification operation on the signature. If the signature verification operation is successful, the cloud management platform detects whether the tenant's credentials can be provided to the first cloud instance.
[0017] In one possible implementation, the multiple cloud instances are any of the following: physical servers, virtual machines, containers, micro virtual machines, and bare metal servers.
[0018] A second aspect of an embodiment of the present application provides a cloud management platform, which is used to manage multiple cloud instances that provide cloud services to tenants. The multiple cloud instances can communicate with each other based on the tenant's credentials. The cloud management platform includes: a receiving module, which is used to receive a credential acquisition request sent by a first cloud instance among multiple cloud instances, and the credential acquisition request is used to indicate an access control policy for multiple cloud instances. The access control policy is provided by the tenant to the first cloud instance, and the access control policy is used to indicate at least one cloud instance among the multiple cloud instances from which the credential can be obtained; a detection module, which is used to detect, based on the credential acquisition request, whether the first cloud instance is located in at least one cloud instance indicated by the access control policy. If so, the cloud management platform sends the credential to the first cloud instance, and the credential is used for the first cloud instance to access a second cloud instance among the multiple cloud instances.
[0019] In one possible implementation, an access control policy is used to indicate a cloud instance whitelist set by a tenant, where the cloud instance whitelist consists of at least one cloud instance from a plurality of cloud instances. A detection module is used to detect, based on a credential acquisition request, whether the first cloud instance is in the cloud instance whitelist indicated by the access control policy.
[0020] In one possible implementation, each cloud instance includes at least one interface, the credential acquisition request is also used to indicate the interface of the first cloud instance called by the tenant, the access control policy is used to indicate the interface whitelist set by the tenant, and the interface whitelist is composed of the interface of at least one cloud instance among multiple cloud instances. The detection module is used to detect whether the interface of the first cloud instance called by the tenant is in the interface whitelist indicated by the access control policy based on the credential acquisition request.
[0021] In one possible implementation, the access control policy is used to indicate the identity of the tenant. An identity whitelist for the first cloud instance is preset in the cloud management platform. The identity whitelist consists of multiple preset identities. The detection module is used to detect whether the identity indicated by the access control policy is in the identity whitelist based on the credential acquisition request.
[0022] In one possible implementation, the access control policy is used to indicate the communication duration set by the tenant and the time when the tenant accesses the first cloud instance, and the detection module is used to detect, based on the credential acquisition request, whether the difference between the time indicated by the access control policy and the current time is less than the communication duration indicated by the access control policy.
[0023] In one possible implementation, the access control policy is used to indicate a feasible communication path between the tenant and the first cloud instance set by the tenant, and the detection module is used to detect whether the current communication path between the tenant and the first cloud instance matches the feasible communication path indicated by the access control policy based on a credential acquisition request.
[0024] In one possible implementation, the access control policy is also used to indicate the signature of the access control policy, and the signature is obtained by the tenant performing a signature operation on the access control policy. The detection module is used to: perform a signature verification operation on the signature indicated by the access control policy based on the credential acquisition request; if the signature verification operation is successful, detect whether the first cloud instance is located in at least one cloud instance indicated by the access control policy.
[0025] In one possible implementation, the multiple cloud instances are any of the following: physical servers, virtual machines, containers, micro virtual machines, and bare metal servers.
[0026] A third aspect of an embodiment of the present application provides a computing device cluster, which includes at least one computing device, each computing device including a processor and a memory: the memory is used to store instructions; the processor is used to enable the computing device cluster to execute the method described in the first aspect or any possible implementation method of the first aspect according to the instructions.
[0027] A fourth aspect of an embodiment of the present application provides a computer storage medium storing one or more instructions, which, when executed by one or more computers, enables the one or more computers to implement the method described in the first aspect or any possible implementation method of the first aspect.
[0028] A fifth aspect of the embodiments of the present application provides a computer program product, which stores instructions. When the instructions are executed by a computer, the computer implements the method described in the first aspect or any possible implementation method of the first aspect.
[0029] In an embodiment of the present application, when a first cloud instance needs to access a second cloud instance among multiple cloud instances serving a tenant, the first cloud instance may send a credential acquisition request to the cloud management platform. The credential acquisition request carries an access control policy for multiple cloud instances, which is provided by the tenant to the first cloud instance and is used to indicate at least one cloud instance among the multiple cloud instances serving the tenant from which the credential can be obtained. The cloud management platform can then parse the credential acquisition request to obtain the access control policy. The cloud management platform can then detect whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy. If so, the cloud management platform will send the tenant's credentials to the first cloud instance, allowing the first cloud instance to access the second cloud instance based on the tenant's credentials. In the above process, among the multiple cloud instances serving the tenant, at least one cloud instance that can be granted the tenant's credentials is specified by the tenant. The at least one authorized cloud instance can obtain the tenant's credentials from the cloud management platform to access the remaining cloud instances. In other words, the access relationship between these multiple cloud instances is customized by the tenant. Therefore, for the first cloud instance among these multiple cloud instances, whether it can access the second cloud instance is set in advance by the tenant. Therefore, it is set entirely in accordance with the tenant's access control intention. The tenant can actively control the first cloud instance, which is conducive to the tenant's management of mutual access between these multiple cloud instances, thereby improving the tenant's experience and ensuring the security of the tenant's data on the cloud instance. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] FIG1 is a schematic diagram of the structure of a cloud service system provided in an embodiment of the present application;
[0031] FIG2 is a flow chart of an access control method based on a cloud management platform provided in an embodiment of the present application;
[0032] FIG3 is a schematic diagram of a payload provided in an embodiment of the present application;
[0033] FIG4 is another schematic diagram of the structure of the cloud service system provided in an embodiment of the present application;
[0034] FIG5 is another structural diagram of the cloud service system provided in an embodiment of the present application;
[0035] FIG6 is another schematic diagram of the structure of the cloud service system provided in an embodiment of the present application;
[0036] FIG7 is another schematic diagram of the structure of the cloud service system provided in an embodiment of the present application;
[0037] FIG8 is another structural diagram of the cloud service system provided in an embodiment of the present application;
[0038] FIG9 is a schematic diagram of the structure of a cloud management platform provided in an embodiment of the present application;
[0039] FIG10 is a schematic diagram of a structure of a computing device provided in an embodiment of the present application;
[0040] FIG11 is a schematic diagram of the structure of a computing device cluster provided in an embodiment of the present application;
[0041] FIG12 is a schematic diagram of computer devices in a computer cluster provided by an embodiment of the present application being connected via a network. DETAILED DESCRIPTION
[0042] The embodiments of the present application provide an access control method and a cloud management platform based on a cloud management platform, which enable tenants to manage mutual access between multiple cloud instances, thereby improving the tenant experience.
[0043] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, and this is merely a way of distinguishing the objects of the same attributes when describing them in the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment.
[0044] With the rapid development of cloud technology, more and more tenants are choosing to deploy cloud services to handle their business. Generally, when tenants need to call multiple cloud services to handle their business, communication occurs between the multiple cloud instances used to deploy multiple cloud services, forming a communication chain.
[0045] In related technologies, a cloud service system includes a cloud management platform and multiple cloud instances that provide cloud services to tenants. The cloud management platform can independently define access relationships among multiple cloud instances based on the tenant's access control requirements. For example, the cloud management platform can limit access to a first cloud instance among multiple cloud instances, while preventing access to a third cloud instance. When a tenant has data processing needs, since data processing requires the collaboration of both the first and second cloud instances, after the tenant accesses the first cloud instance, the first cloud instance will query the cloud management platform whether it can access the second cloud instance. The cloud management platform can then allow the first cloud instance to access the second cloud instance to fulfill the tenant's data processing needs. For example, suppose cloud instance 1 is deployed with a data storage service and cloud instance 2 is deployed with a data encryption service. After the tenant's data is stored in cloud instance 1, since the cloud management platform stipulates that cloud instance 1 can call cloud instance 2 for data encryption, cloud instance 1 can call cloud instance 2 to encrypt the tenant's data, thereby obtaining the encrypted data. Therefore, the tenant's data is stored in cloud instance 1 in encrypted form.
[0046] In the above process, since the access relationship is established by the cloud management platform, it is a black box for tenants. Tenants cannot actively control the access relationship between multiple cloud instances, resulting in a poor tenant experience and may also cause certain security issues for tenants' data on cloud instances.
[0047] To address the above issues, the present application provides an access control method based on a cloud management platform. This method can be implemented through a cloud service system (e.g., a public cloud system, etc.). FIG1 is a schematic diagram of the structure of the cloud service system provided by the present application. As shown in FIG1 , the cloud service system includes an infrastructure that can provide cloud services and a cloud management platform that manages the infrastructure. The cloud management platform and the infrastructure are introduced separately below:
[0048] The cloud management platform can coordinate the management of the infrastructure in the entire cloud service system (for example, in the infrastructure, multiple cloud instances are created for tenants to serve tenants according to the instructions of tenants. These cloud instances can be used to run the cloud services specified by tenants (for example, data storage services, data encryption and decryption services, etc.) to provide remote data processing for tenants, etc.). It can also be open to tenants outside the cloud service system and respond to their requests. For example, the cloud management platform can provide various interfaces such as login interfaces and cloud instance purchase interfaces for access by tenants' clients (for example, terminal devices used by tenants or browsers on terminal devices, etc.). Among them, the cloud management platform can authenticate the tenant's client through the login interface, and after successful authentication, the tenant's client can be allowed to log in to the cloud management platform. For example, the cloud management platform can also allow the tenant's client to send a purchase request for multiple cloud instances to the cloud management platform through the cloud instance purchase interface. The purchase request is usually used to indicate these multiple cloud instances and the cloud services that need to be deployed on each cloud instance. Therefore, the cloud management platform can create multiple exclusive cloud instances for the tenant based on the purchase request, and deploy corresponding cloud services on each cloud instance, so that these multiple cloud instances can meet the tenant's data processing needs.
[0049] The infrastructure includes multiple cloud instances serving tenants, each running a cloud service. Because tenants' data processing needs may require the assistance of different cloud services, communication occurs between different cloud services, which is equivalent to communication between different cloud instances. This will not be discussed further. It is worth noting that communication between these multiple cloud instances serving tenants is based on the tenant's (identity) credentials, which are typically pre-configured in the cloud management platform. When a tenant has a data processing need, it can send a data processing request to a cloud instance. This data processing request contains not only the data to be processed but also the access control policy customized by the tenant for these multiple cloud instances. This access control policy can be used to indicate which cloud instances among these multiple cloud instances the tenant has selected to be granted the tenant's credentials by the cloud management platform. Upon receiving the data processing request, the cloud instance can parse it, generate a credential acquisition request containing the access control policy, and then send this credential acquisition request to the cloud management platform. The cloud management platform can then parse the credential acquisition request to obtain the access control policy. Subsequently, the cloud management platform can determine whether the cloud instance is located in the part of cloud instances indicated by the access control policy. If so, the cloud management platform can provide the tenant's credentials to the cloud instance so that the cloud instance can access the remaining cloud instances based on the tenant's credentials, thereby meeting the tenant's data processing needs.
[0050] Furthermore, the tenant's credentials can be understood as an account and password pair generated by the cloud management platform based on the tenant's identity information. It can be understood that for any cloud instance, the cloud management platform can generate an account and password pair that is unique to the cloud instance, so that the cloud instance can access other cloud instances as the tenant.
[0051] Furthermore, the access control policy formulated by the tenant can be presented as a special data structure (payload), which can contain multiple fields, some of which can be used to describe access control conditions, and other fields can be used to describe access control information. The access control conditions and access control information can be combined and used by the cloud management platform to perform authorization detection on any cloud instance (that is, whether the cloud instance can grant the tenant's credentials), or they can be used separately by the cloud management platform to perform authorization detection on any cloud instance. This will not be expanded here.
[0052] Furthermore, the access control policy formulated by the tenant also contains another field that is the signature of the entire access control policy. This signature is obtained by performing a signature operation on the above two fields. After obtaining the access control policy, the cloud management platform can first verify the signature. If the signature verification is successful, it indicates that both fields are authentic (or, in other words, that both fields are complete, etc.), and the cloud management platform can use these two fields to perform authorization checks on the cloud instance.
[0053] Furthermore, among the multiple cloud instances serving tenants, the cloud services run by any cloud instance can be applications, microservices, plug-ins, etc. developed by the tenant, or applications, microservices, plug-ins, etc. provided to the tenant by the cloud vendor (developer of the cloud service system), and there is no restriction here.
[0054] Furthermore, among the multiple cloud instances serving tenants, these cloud instances can be presented in various ways. For example, these cloud instances can be physical servers selected by the cloud management platform. In another example, these cloud instances can be bare metal servers selected by the cloud management platform. In another example, these cloud instances can be virtual machines (VMs) created by the cloud management platform on physical servers through virtualization technology. In another example, these cloud instances can also be containers (docker) created by the cloud management platform on physical servers through virtualization technology. In another example, these cloud instances can also be micro virtual machines (microVMs) created by the cloud management platform on physical servers through virtualization technology, and so on.
[0055] Furthermore, for multiple cloud instances serving tenants, these multiple cloud instances can be deployed in the same site or different sites. The site can be presented in various forms. For example, the site can be a region in the infrastructure, or an availability zone in the infrastructure, or a data center (DC) in the infrastructure, or a room in the infrastructure, or a cabinet in the infrastructure, etc.
[0056] Based on the above cloud service system, it can be known that after a cloud instance serving a tenant receives a data processing request from a tenant, the cloud instance can generate a credential acquisition request containing the access control policy based on the access control policy contained in the data processing request, and send the credential acquisition request to the cloud management platform. The cloud management platform can then parse the credential acquisition request to obtain the access control policy. Since the access control policy can be used to indicate a portion of the cloud instances selected by the tenant to which the tenant's credentials can be granted, the cloud management platform can determine whether the cloud instance is located in the portion of cloud instances indicated by the access control policy. If so, the cloud management platform can provide the tenant's credentials to the cloud instance, so that the cloud instance can access the remaining cloud instances based on the tenant's credentials, thereby meeting the tenant's data processing needs. It can be seen that among the multiple cloud instances serving tenants, which specific cloud instances can be granted the tenant's credentials is specified by the tenant. This part of the authorized cloud instances can obtain the tenant's credentials from the cloud management platform to access the remaining cloud instances. In other words, the access relationship between these multiple cloud instances is customized by the tenant. Therefore, for any cloud instance among these multiple cloud instances, whether it can access the other cloud instances is completely set according to the tenant's access control intention. The tenant can actively control the cloud instance, which is conducive to the tenant's management of mutual access between these multiple cloud instances, thereby improving the tenant's experience. In order to further understand the process, the process is further introduced in conjunction with Figure 2. Figure 2 is a flow chart of the access control method based on the cloud management platform provided in an embodiment of the present application. As shown in Figure 2, the method can be implemented through the cloud service system shown in Figure 1. The cloud management platform includes infrastructure that provides cloud services to tenants and a cloud management platform that manages these infrastructures. These infrastructures include multiple cloud instances serving tenants. These multiple cloud instances communicate based on the tenant's credentials. The method includes:
[0057] 201. A cloud management platform receives a credential acquisition request sent by a first cloud instance among multiple cloud instances. The credential acquisition request is used to indicate an access control policy for the multiple cloud instances. The access control policy is provided by the tenant to the first cloud instance. The access control policy is used to indicate at least one cloud instance among the multiple cloud instances from which the credential can be obtained.
[0058] In this embodiment, when a tenant has data processing needs among multiple cloud instances serving a tenant, the tenant can send a data processing request to the first of the multiple cloud instances. This data processing request carries the tenant's data to be processed and the access control policies customized by the tenant for the multiple cloud instances. The first cloud instance can then parse the data processing request, determine that the tenant has a data processing need, and obtain the access control policy from the data processing request. Because the tenant's data processing need requires the first cloud instance to collaborate with the second cloud instance to fulfill it, the first cloud instance can generate a credential acquisition request that carries the access control policy and send it to the cloud management platform.
[0059] It should be noted that the access control policy is used to indicate at least one cloud instance selected by the tenant from the multiple cloud instances, from which the tenant's credentials can be obtained.
[0060] Specifically, the access control policy is usually a special data structure (payload), which may contain at least one of the following fields, which are described below:
[0061] (1) Cloud instance (or cloud service) control policy field, which describes the cloud instance whitelist set by the tenant. The cloud instance whitelist contains at least one cloud instance selected by the tenant from these multiple cloud instances, indicating that this at least one cloud instance can directly grant the tenant's credentials, that is, this at least one cloud instance is a cloud instance directly authorized by the tenant.
[0062] For example, as shown in Figure 3 (Figure 3 is a schematic diagram of a payload provided in an embodiment of the present application), assume that the cloud instances serving the tenant are cloud instance 1, cloud instance 2, and cloud instance 3. Cloud service 1 runs on cloud instance 1, cloud service 2 runs on cloud instance 2, and cloud service 3 runs on cloud instance 3. For these three cloud instances, the tenant can define a payload that includes a service control policy field. This field is used to describe a cloud instance whitelist. The cloud instance whitelist includes cloud instance 1 and cloud instance 3, indicating that these two cloud instances are cloud instances directly authorized by the tenant.
[0063] (2) API permission field, which describes the interface whitelist set by the tenant. It should be noted that among the multiple cloud instances serving the tenant, each cloud instance provides at least one interface to the outside world (it can also be understood that each cloud instance provides at least one type of interface to the outside world). The interface whitelist contains the interface of at least one cloud instance selected by the tenant from the interfaces of these multiple cloud instances, indicating that once the interface of this at least one cloud instance is called, this at least one cloud instance can directly grant the tenant's credentials.
[0064] For example, as shown in Figure 3, the cloud instances serving tenants are cloud instance 1, cloud instance 2, and cloud instance 3. These three cloud instances can provide one or more interfaces of different types, such as upload interface, download interface, encryption interface, and decryption interface. The tenant can define a payload, which includes an API permission field. This field is used to describe an interface whitelist. The interface whitelist can include the upload interface and download interface of cloud instance 1, and the encryption interface and decryption interface of cloud instance 2.
[0065] (3) The session policy field describes the larger scope of the permission control policy set by the tenant. The permission control policy can be the communication duration of the entire communication chain set by the tenant, or the feasible communication path between the tenant and each cloud instance set by the tenant, etc. Among them, the communication duration of the entire communication chain refers to the total time from the tenant accessing the first cloud instance, then the first cloud instance accessing the second cloud instance, until the access to the last cloud instance, which cannot exceed the communication duration. The feasible communication path between the tenant and a cloud instance refers to which cloud instances the tenant can pass through when communicating with the cloud instance. It can be seen that both the communication duration and the feasible communication path can be used to determine whether a cloud instance can grant the tenant's credentials.
[0066] For example, as shown in Figure 3, suppose that the cloud instances serving the tenant are cloud instance 1, cloud instance 2 and cloud instance 3. For these three cloud instances, the tenant can define a payload, which contains a session policy field. This field is used to describe that the communication duration of the communication chain set by the tenant is 3 minutes, or this field is used to describe a feasible communication path between the tenant and cloud instance 1. The feasible communication path is that the tenant can directly access cloud instance 1, and the tenant cannot access cloud instance 1 through other cloud instances (for example, cloud instance 2 and / or cloud instance 3).
[0067] (4) Properties field, which can be used to describe information such as the identity used by the tenant to access a cloud instance or the time when the tenant accesses a cloud instance (that is, the initial time when the tenant sends a data processing request to the cloud instance). Among them, for the identity used by the tenant to access a cloud instance, if the identity used by the tenant to access the cloud instance is in the preset identity whitelist, the cloud instance can grant the tenant's credentials. For the time when the tenant accesses a cloud instance, if the difference between the time and the current time is less than the aforementioned communication duration, the cloud instance can grant the tenant's credentials.
[0068] For example, as shown in Figure 3, suppose that the cloud instances serving the tenant are cloud instance 1, cloud instance 2, and cloud instance 3. Assuming that the tenant directly accesses cloud instance 1, for cloud instance 1, the tenant can define a payload, which contains a properties field. This field is used to describe the identity used by the tenant when accessing cloud instance 1 as X, or this field is used to describe the time when the tenant directly accesses cloud instance 1 as 10:00.
[0069] (5) Cloud instance (or cloud service) record (service appenders) field. This field is used to record the intermediate nodes and terminal nodes that the current communication chain passes through. The communication chain usually starts with the tenant as the initial node. Once the tenant accesses a cloud instance, the cloud instance is recorded as an intermediate node in this field. It can be seen that this field can describe the current communication path between the tenant and the cloud instance accessed by the tenant (for example, the initial node of the current communication path is the tenant, the first intermediate node is the cloud instance directly accessed by the tenant, the second intermediate node is the cloud instance directly accessed by the first intermediate node, and so on). It should be noted that since the content of this field is updated, the entire data structure will also be updated, that is, the entire access control policy will also be updated.
[0070] For example, as shown in Figure 3, suppose the cloud instances serving tenants are Cloud Instance 1, Cloud Instance 2, and Cloud Instance 3. Assuming the tenant directly accesses Cloud Instance 1, the tenant can define a payload for Cloud Instance 1. This payload contains a service appenders field. Since the tenant needs to access Cloud Instance 1, this field can record the initial node, the tenant. Alternatively, this field can be left blank, assuming the initial node is the tenant. In other words, the current communication path between the tenant and Cloud Instance 1 described by this field can be understood as the tenant directly accessing Cloud Instance 1.
[0071] (6) Cryptographic message field, which is used to describe the signature of the entire data structure. The signature is obtained by the tenant performing a signature operation on the remaining fields of the data structure (for example, one or more of the five fields (1) to (5) mentioned above). The signature can be used to ensure that the remaining fields are credible, that is, to ensure that these fields have not been tampered with.
[0072] 202. Based on the credential acquisition request, the cloud management platform detects whether the first cloud instance is located in at least one cloud instance indicated by the access control policy. If so, the cloud management platform sends the credential to the first cloud instance, and the credential is used for the first cloud instance to access the second cloud instance among the multiple cloud instances.
[0073] After receiving the credential acquisition request from the first cloud instance, the cloud management platform can parse the credential acquisition request to obtain the access control policy established by the tenant for multiple cloud instances. Based on the access control policy, the cloud management platform can then determine at least one cloud instance among the multiple cloud instances that can grant the tenant's credentials. Therefore, the cloud management platform can detect whether the first cloud instance is located within the at least one cloud instance. If the first cloud instance is located within the at least one cloud instance, the cloud management platform provides the tenant's credentials to the first cloud instance. The first cloud instance then processes the tenant's data to be processed and obtains processed data. (The processing performed by the first cloud instance on the data to be processed is not related to the tenant's credentials; even if the first cloud instance does not obtain the tenant's credentials, it can still process the data to be processed.) Because the processed data requires further processing by the second cloud instance, a new data processing request can be generated. The new data processing request includes the processed data, the tenant's credentials, and the access control policy established by the tenant for multiple cloud instances. The new data processing request is then sent to the second cloud instance. Because the new data processing request carries the tenant's credentials, the second cloud instance parses the request to obtain the access control policy and the processed data. The second cloud instance can then determine whether a third cloud instance is needed to assist in completing the tenant's data processing needs. If not, the second cloud instance can directly process the processed data, obtaining the data processing results and returning them to the tenant via the first cloud instance. If necessary, the second cloud instance can perform the operations previously performed by the first cloud instance, which will not be further described here.
[0074] Specifically, the cloud management platform may detect whether the first cloud instance is located in at least one cloud instance indicated by the access control policy in the following ways:
[0075] (1) After receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse the access control policy established by the tenant for multiple cloud instances from the request. When the access control policy contains a cloud instance control policy field, since the field is used to describe the cloud instance whitelist set by the tenant, and the cloud instance whitelist contains at least one cloud instance selected by the tenant from the multiple cloud instances, the cloud management platform detects whether the first cloud instance is in the cloud instance whitelist. If the first cloud instance is in the cloud instance whitelist, the cloud management platform can provide the tenant's credentials to the first cloud instance, so the first cloud instance can use the tenant's credentials to access the second cloud instance. If the first cloud instance is not in the cloud instance whitelist, the cloud management platform refuses to provide the tenant's credentials to the first cloud instance, so the first cloud instance cannot access the second cloud instance.
[0076] Still taking the above example, as shown in Figure 4 (Figure 4 is another structural diagram of the cloud service system provided by an embodiment of the present application), when the tenant initiates a data processing request carrying a payload to cloud instance 1, cloud instance 1 can parse the data processing request to obtain the payload, and send a credential acquisition request carrying the payload to the cloud management platform. After the cloud management platform parses the credential acquisition request, it can obtain the payload. Since the payload contains the service control policy field, the cloud instance whitelist described by this field includes cloud instance 1 (cloud service 1) and cloud instance 3 (cloud service 3), so the cloud management platform can determine that cloud instance 1 is in the cloud instance whitelist. The cloud management platform can then provide the tenant's credentials to cloud instance 1 for cloud instance 1 to access cloud instance 2. In addition, if cloud instance 2 also needs to obtain the tenant's credentials, it will also send a credential acquisition request to the cloud management platform, but since cloud instance 2 is not in the cloud instance whitelist, the cloud management platform will not provide the tenant's credentials to cloud instance 2, so cloud instance 2 cannot access the remaining cloud instances.
[0077] (2) After receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse the request to obtain the interface of the first cloud instance called by the tenant and the access control policy established by the tenant for multiple cloud instances. When the access control policy contains an interface permission field, since the field describes the interface whitelist set by the tenant, and the interface whitelist contains the interface of at least one cloud instance selected by the tenant from the interfaces of these multiple cloud instances, the cloud management platform can detect whether the interface of the first cloud instance called by the tenant is in the interface whitelist. If the interface of the first cloud instance called by the tenant is in the interface whitelist, the cloud management platform can provide the tenant's credentials to the first cloud instance, so the first cloud instance can use the tenant's credentials to access the second cloud instance. If the interface of the first cloud instance called by the tenant is not in the interface whitelist, the cloud management platform refuses to provide the tenant's credentials to the first cloud instance, so the first cloud instance cannot access the second cloud instance.
[0078] Still taking the above example as shown in Figure 5 (Figure 5 is another structural diagram of the cloud service system provided by an embodiment of the present application), after the cloud management platform receives the credential acquisition request sent by cloud instance 1, it can parse the credential acquisition request to obtain the payload and determine that the tenant has called the upload interface of cloud instance 1 (the upload interface of cloud instance 1 can be presented as the identifier of the upload interface of cloud instance 1 in the request, so based on the identifier, it can be determined that the tenant has called the upload interface of cloud instance 1). Since the payload contains the API permission field, this field is used to describe an interface whitelist, which can include the upload interface and download interface of cloud instance 1, and the encryption interface and decryption interface of cloud instance 2. Since the tenant calls the upload interface of cloud instance 1, and the upload interface of cloud instance 1 is in the interface whitelist, the cloud management platform can provide the tenant's credentials to cloud instance 1 for cloud instance 1 to access cloud instance 2. In addition, if cloud instance 1 subsequently calls the upload interface of cloud instance 2, and cloud instance 2 also needs to obtain the tenant's credentials, it will also send a credential acquisition request to the cloud management platform. However, since the upload interface of cloud instance 2 is not in the interface whitelist, the cloud management platform will not provide the tenant's credentials to cloud instance 2, so cloud instance 2 cannot access other cloud instances.
[0079] (3) After receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse the access control policy established by the tenant for multiple cloud instances from the request. When the access control policy contains a characteristic field, since the field can describe the identity used by the tenant when accessing the first cloud instance, and the cloud management platform has a preset identity whitelist for the first cloud instance, the cloud management platform can detect whether the identity used by the tenant when accessing the first cloud instance is in the identity whitelist for the first cloud instance. If the identity used by the tenant when accessing the first cloud instance is in the identity whitelist for the first cloud instance, the cloud management platform can provide the tenant's credentials to the first cloud instance, so the first cloud instance can use the tenant's credentials to access the second cloud instance. If the identity used by the tenant when accessing the first cloud instance is not in the identity whitelist for the first cloud instance, the cloud management platform refuses to provide the tenant's credentials to the first cloud instance, so the first cloud instance cannot access the second cloud instance.
[0080] Still taking the above example, as shown in Figure 6 (Figure 6 is another structural diagram of the cloud service system provided by an embodiment of the present application), after the cloud management platform receives the credential acquisition request sent by cloud instance 1, it can parse the credential acquisition request to obtain the payload. Since the payload contains the properties field, which is used to describe the identity X used by the tenant to access cloud instance 1, the cloud management platform can obtain the identity whitelist for cloud instance 1. The identity whitelist contains identities such as X, Y, and Z, and determines that the identity used by the tenant to access cloud instance 1 is in the identity whitelist. Then, the cloud management platform can provide the tenant's credentials to cloud instance 1 for cloud instance 1 to access cloud instance 2.
[0081] (4) After receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse the access control policy established by the tenant for multiple cloud instances from the request. When the access control policy includes a session policy field and a feature field, since the session policy field can describe the communication duration of the entire communication chain set by the tenant, and the feature field can describe the moment when the tenant accesses the first cloud instance, the cloud management platform can calculate the difference between the moment when the tenant accesses the first cloud instance and the current moment, and detect whether the difference is less than the communication duration of the entire communication chain set by the tenant. If the difference is less than the communication duration, the cloud management platform can provide the tenant's credentials to the first cloud instance, so the first cloud instance can use the tenant's credentials to access the second cloud instance. If the difference is greater than or equal to the communication duration, the cloud management platform refuses to provide the tenant's credentials to the first cloud instance, so the first cloud instance cannot access the second cloud instance.
[0082] Still taking the above example, as shown in Figure 7 (Figure 7 is another structural diagram of the cloud service system provided by an embodiment of the present application), after the cloud management platform receives the credential acquisition request sent by cloud instance 1, it can parse the credential acquisition request to obtain the payload. Since the payload contains the session policy field and the properties field, the session policy field is used to describe the communication duration of the communication chain set by the tenant as 3 minutes, and the properties field is used to describe the time when the tenant directly accesses cloud instance 1 as 10:00. Since the current time is 10:01, the cloud management platform can calculate that the difference between the time when the tenant directly accesses cloud instance 1 and the current time is 1 minute, which is less than the communication duration of the communication chain set by the tenant. The cloud management platform can then provide the tenant's credentials to cloud instance 1 for cloud instance 1 to access cloud instance 2. In addition, if Cloud Instance 2 also needs to obtain the tenant's credentials, it will also send a credential acquisition request to the cloud management platform. At this time, the current time has been updated to 10:04, and the difference between the two is 4 minutes. This difference is greater than the communication duration of the communication chain set by the tenant. Therefore, the cloud management platform will not provide the tenant's credentials to Cloud Instance 2, so Cloud Instance 2 cannot access other cloud instances.
[0083] (5) After receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse the access control policy established by the tenant for multiple cloud instances from the request. When the access control policy includes a session policy field and a cloud instance record field, since the cloud instance record field can describe the current communication path between the tenant and the first cloud instance, and the session policy field can describe the feasible communication path between the tenant and the first cloud instance, the cloud management platform can detect whether the current communication path between the tenant and the first cloud instance matches the feasible communication path between the tenant and the first cloud instance (for example, whether the two are the same or similar). If the two match, the cloud management platform can provide the tenant's credentials to the first cloud instance, so the first cloud instance can use the tenant's credentials to access the second cloud instance. If the two do not match, the cloud management platform refuses to provide the tenant's credentials to the first cloud instance, so the first cloud instance cannot access the second cloud instance.
[0084] Still taking the above example, as shown in Figure 8 (Figure 8 is another structural diagram of the cloud service system provided by an embodiment of the present application), after the cloud management platform receives the credential acquisition request sent by cloud instance 1, it can parse the credential acquisition request to obtain a payload. Since the payload contains a session policy field and a service appenders field, the session policy field is used to describe the feasible communication path between the tenant and cloud instance 1 (cloud service 1), that is, the tenant can directly access cloud instance 1, and the service appenders field (as shown in Figure 8, this field is empty and the starting node is not recorded) is used to describe the current communication path between the tenant and cloud instance 1, that is, the tenant directly accesses cloud instance 1. The two are matched, so the cloud management platform can provide the tenant's credentials to cloud instance 1 for cloud instance 1 to access cloud instance 2.
[0085] It's worth noting that the cloud management platform can also update the content of the service appenders field to cloud instance 1. Therefore, the updated service appenders field records the intermediate node cloud instance 1. At this time, the payload is also updated to the new payload. The cloud management platform can provide the new payload and the tenant's credentials to cloud instance 1, so that cloud instance 1 can use the new payload and the tenant's credentials to access cloud instance 2. At this time, the updated service appenders field in the new payload is used to describe the current communication path between the tenant and cloud instance 2 as the tenant indirectly accessing cloud instance 2 through cloud instance 1. Similarly, if cloud instance 2 requests the tenant's credentials from the cloud management platform, since the session policy field also describes the feasible communication path between the tenant and cloud instance 2 as cloud instance 2 (cloud service 2) must pass through cloud instance 1 (cloud service 1) before access, the cloud management platform can provide the tenant's credentials to cloud instance 2.
[0086] More specifically, to ensure the credibility of the access control policy, you can also perform the following operations:
[0087] After receiving the credential acquisition request sent by the first cloud instance, the cloud management platform can parse the access control policy formulated by the tenant for multiple cloud instances from the request. When the access control policy contains an encrypted information field, the encrypted information field is usually the signature of the access control policy, which is obtained by the tenant performing a signature operation on the remaining fields contained in the access control policy. Then, the cloud management platform can first perform a signature verification operation on the signature. If the signature verification operation is successful, the cloud management platform will use the remaining fields (refer to the aforementioned (1) to (5), which will not be repeated here) to detect whether the first cloud instance can be authorized, that is, whether the tenant's credentials can be provided to the first cloud instance.
[0088] It should be understood that, in this embodiment, among the various fields in the access control policy, only the cloud instance record field can be modified by the cloud management platform, while the remaining fields are generally not modifiable by the cloud management platform.
[0089] It should also be understood that in this embodiment, only the five independent detection methods (1) to (5) mentioned above are schematically introduced. In actual applications, these five methods can also be used in combination. For example, in the case of (1) + (2), the cloud management platform will only provide the tenant's credentials to the first cloud instance after determining that the first cloud instance is in the cloud instance whitelist and the interface of the tenant calling the first cloud instance is in the interface whitelist, etc. This will not be expanded here.
[0090] In an embodiment of the present application, when a first cloud instance needs to access a second cloud instance among multiple cloud instances serving a tenant, the first cloud instance may send a credential acquisition request to the cloud management platform. The credential acquisition request carries an access control policy for multiple cloud instances, which is provided by the tenant to the first cloud instance and is used to indicate at least one cloud instance among the multiple cloud instances serving the tenant from which the credential can be obtained. The cloud management platform can then parse the credential acquisition request to obtain the access control policy. The cloud management platform can then detect whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy. If so, the cloud management platform will send the tenant's credentials to the first cloud instance, allowing the first cloud instance to access the second cloud instance based on the tenant's credentials. In the above process, among the multiple cloud instances serving the tenant, at least one cloud instance that can be granted the tenant's credentials is specified by the tenant. The at least one authorized cloud instance can obtain the tenant's credentials from the cloud management platform to access the remaining cloud instances. In other words, the access relationship between these multiple cloud instances is customized by the tenant. Therefore, for the first cloud instance among these multiple cloud instances, whether it can access the second cloud instance is set in advance by the tenant. Therefore, it is set entirely in accordance with the tenant's access control intention. The tenant can actively control the first cloud instance, which is conducive to the tenant's management of mutual access between these multiple cloud instances, thereby improving the tenant's experience and ensuring the security of the tenant's data on the cloud instance.
[0091] The above is a detailed description of the access control method based on the cloud management platform provided in the embodiment of the present application. The cloud management platform provided in the embodiment of the present application will be introduced below. Figure 9 is a structural diagram of the cloud management platform provided in the embodiment of the present application. As shown in Figure 9, the cloud management platform is used to manage multiple cloud instances that provide cloud services to tenants. Multiple cloud instances can communicate with each other based on the tenant's credentials. The cloud management platform includes:
[0092] The receiving module 901 is used to receive a credential acquisition request sent by a first cloud instance among multiple cloud instances. The credential acquisition request is used to indicate an access control policy for multiple cloud instances. The access control policy is provided by the tenant to the first cloud instance. The access control policy is used to indicate at least one cloud instance among the multiple cloud instances from which the credential can be obtained. For example, the receiving module 901 can be used to implement step 201 in the embodiment shown in Figure 2.
[0093] Detection module 902 is configured to detect, based on the credential acquisition request, whether the first cloud instance is located in at least one cloud instance indicated by the access control policy. If so, the cloud management platform sends the credential to the first cloud instance, which is used to allow the first cloud instance to access a second cloud instance in the plurality of cloud instances. For example, detection module 902 may be used to implement step 202 in the embodiment shown in FIG. 2 .
[0094] In one possible implementation, the access control policy is used to indicate a cloud instance whitelist set by the tenant, where the cloud instance whitelist consists of at least one cloud instance from multiple cloud instances. The detection module 902 is used to detect whether the first cloud instance is in the cloud instance whitelist indicated by the access control policy based on a credential acquisition request.
[0095] In one possible implementation, each cloud instance includes at least one interface, the credential acquisition request is also used to indicate the interface of the first cloud instance called by the tenant, the access control policy is used to indicate the interface whitelist set by the tenant, and the interface whitelist is composed of the interface of at least one cloud instance among multiple cloud instances. The detection module 902 is used to detect whether the interface of the first cloud instance called by the tenant is in the interface whitelist indicated by the access control policy based on the credential acquisition request.
[0096] In one possible implementation, the access control policy is used to indicate the identity of the tenant. An identity whitelist for the first cloud instance is preset in the cloud management platform. The identity whitelist consists of multiple preset identities. The detection module 902 is used to detect whether the identity indicated by the access control policy is in the identity whitelist based on the credential acquisition request.
[0097] In one possible implementation, the access control policy is used to indicate the communication duration set by the tenant and the time when the tenant accesses the first cloud instance. The detection module 902 is used to detect, based on the credential acquisition request, whether the difference between the time indicated by the access control policy and the current time is less than the communication duration indicated by the access control policy.
[0098] In one possible implementation, the access control policy is used to indicate a feasible communication path between the tenant and the first cloud instance set by the tenant, and the detection module 902 is used to detect whether the current communication path between the tenant and the first cloud instance matches the feasible communication path indicated by the access control policy based on the credential acquisition request.
[0099] In one possible implementation, the access control policy is also used to indicate the signature of the access control policy, and the signature is obtained by the tenant performing a signature operation on the access control policy. The detection module 902 is used to: based on the credential acquisition request, perform a signature verification operation on the signature indicated by the access control policy; if the signature verification operation is successful, detect whether the first cloud instance is located in at least one cloud instance indicated by the access control policy.
[0100] In one possible implementation, the multiple cloud instances are any of the following: physical servers, virtual machines, containers, micro virtual machines, and bare metal servers.
[0101] It should be noted that the information interaction, implementation process, etc. between the modules / units of the above-mentioned device are based on the same concept as the method embodiment of the present application, and the technical effects they bring are the same as those of the method embodiment of the present application. For specific contents, please refer to the description in the method embodiment shown above in the embodiment of the present application, and no further details will be given here.
[0102] Please refer to Figure 10, which is a schematic diagram of the structure of a computing device provided in an embodiment of the present application. As shown in Figure 10, the computing device 1000 (which can be used to present the aforementioned cloud management platform) includes: a processor 1001, a memory 1002, a communication interface 1003, and a bus 1004. The processor 1001, the memory 1002, and the communication interface 1003 are coupled via a bus (not labeled in the figure). The memory 1002 stores instructions. When the execution instructions in the memory 1002 are executed, the computing device 1000 executes the method executed by the cloud management platform in the above method embodiment.
[0103] The computing device 1000 may be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASICs), one or more digital signal processors (DSPs), one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. For example, when a unit in the device can be implemented in the form of a processing element scheduler, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call a program. For example, these units can be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0104] The processor 1001 may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0105] The memory 1002 may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. The non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0106] Memory 1002 stores executable program code, and processor 1001 executes the executable program code to implement the functions of the aforementioned receiving module, detection module, and other modules, thereby implementing the aforementioned access control method based on the cloud management platform. In other words, memory 1002 stores instructions for executing the aforementioned access control method based on the cloud management platform.
[0107] The communication interface 1003 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 1000 and other devices or a communication network.
[0108] In addition to the data bus, bus 1004 may also include a power bus, a control bus, and a status signal bus. The bus may be a Peripheral Component Interconnect Express (PCIe) bus, an Extended Industry Standard Architecture (EISA) bus, a unified bus (Ubus or UB), a Compute Express Link (CXL), or a Cache Coherent Interconnect for Accelerators (CCIX). Buses can be categorized as address buses, data buses, and control buses.
[0109] Please refer to Figure 11, which is a schematic diagram of the structure of a computing device cluster provided in an embodiment of the present application. As shown in Figure 11, the computing device cluster 1100 includes at least one computing device 1000.
[0110] As shown in Figure 11, the computing device cluster 1100 includes at least one computing device 1000. The memory 1002 in one or more computing devices 1000 in the computing device cluster 1100 may store the same instructions for executing the above-mentioned access control method based on the cloud management platform.
[0111] In some possible implementations, the memory 1002 of one or more computing devices 1000 in the computing device cluster 1100 may also store partial instructions for executing the aforementioned cloud management platform-based access control method. In other words, the combination of one or more computing devices 1000 may jointly execute the aforementioned cloud management platform-based access control method.
[0112] It should be noted that the memory 1002 in different computing devices 1000 in the computing device cluster 1100 may store different instructions, each for executing a portion of the functions of the aforementioned cloud management platform. In other words, the instructions stored in the memory 1002 in different computing devices 1000 may implement the functions of one or more modules such as the receiving module and the detection module.
[0113] In some possible implementations, one or more computing devices 1000 in the computing device cluster 1100 may be connected via a network, which may be a wide area network or a local area network.
[0114] Please refer to Figure 12, which is a schematic diagram of computer devices in a computer cluster provided by an embodiment of the present application being connected via a network. As shown in Figure 12, two computing devices 1000A and 1000B are connected via a network. Specifically, each computing device is connected to the network via a communication interface.
[0115] In a possible implementation, the memory of the computing device 1000A stores instructions for executing functions of a receiving module and the like. Meanwhile, the memory of the computing device 1000B stores instructions for executing functions of a detecting module and the like.
[0116] It should be understood that the functions of the computing device 1000A shown in Figure 12 may also be completed by multiple computing devices. Similarly, the functions of the computing device 1000B may also be completed by multiple computing devices.
[0117] An embodiment of the present application also relates to a computer storage medium, in which a program for signal processing is stored. When the computer storage medium is run on a computer, the computer executes the steps executed by the cloud management platform in the embodiment shown in Figure 4.
[0118] An embodiment of the present application also relates to a computer program product, which stores instructions that, when executed by a computer, enable the computer to execute the steps performed by the cloud management platform in the embodiment shown in FIG4 .
[0119] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0120] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0121] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0122] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0123] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
Claims
1. An access control method based on a cloud management platform, characterized in that: The cloud management platform is used to manage multiple cloud instances that provide cloud services to tenants, and the multiple cloud instances can communicate with each other based on the credentials of the tenants. The method includes: The cloud management platform receives a credential acquisition request sent by a first cloud instance among the multiple cloud instances, where the credential acquisition request is used to indicate an access control policy for the multiple cloud instances, where the access control policy is provided by the tenant to the first cloud instance, and where the access control policy is used to indicate at least one cloud instance among the multiple cloud instances from which the credential can be acquired; Based on the credential acquisition request, the cloud management platform detects whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy. If so, the cloud management platform sends the credential to the first cloud instance, and the credential is used for the first cloud instance to access a second cloud instance among the multiple cloud instances.
2. The method according to claim 1, characterized in that The access control policy is used to indicate a cloud instance whitelist set by the tenant, the cloud instance whitelist is composed of at least one cloud instance among the multiple cloud instances, and the cloud management platform detects, based on the credential acquisition request, whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy, including: The cloud management platform detects, based on the credential acquisition request, whether the first cloud instance is in the cloud instance whitelist indicated by the access control policy.
3. The method according to claim 1, characterized in that Each cloud instance includes at least one interface, the credential acquisition request is further used to indicate the interface of the first cloud instance called by the tenant, the access control policy is used to indicate the interface whitelist set by the tenant, the interface whitelist is composed of the interface of at least one cloud instance among the multiple cloud instances, and the cloud management platform detects whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy based on the credential acquisition request, including: The cloud management platform detects, based on the credential acquisition request, whether the interface of the first cloud instance called by the tenant is in the interface whitelist indicated by the access control policy.
4. The method according to claim 1, characterized in that The access control policy is used to indicate the identity of the tenant, the cloud management platform is pre-set with an identity whitelist for the first cloud instance, the identity whitelist is composed of a plurality of pre-set identities, and the cloud management platform detects, based on the credential acquisition request, whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy, including: The cloud management platform detects, based on the credential acquisition request, whether the identity indicated by the access control policy is in the identity whitelist.
5. The method according to claim 1, characterized in that The access control policy is used to indicate the communication duration set by the tenant and the time when the tenant accesses the first cloud instance, and the cloud management platform detects whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy based on the credential acquisition request, including: The cloud management platform detects, based on the credential acquisition request, whether a difference between the time indicated by the access control policy and the current time is less than the communication duration indicated by the access control policy.
6. The method according to claim 1, characterized in that The access control policy is used to indicate a feasible communication path between the tenant and the first cloud instance set by the tenant, and the cloud management platform detects, based on the credential acquisition request, whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy, including: The cloud management platform detects, based on the credential acquisition request, whether a current communication path between the tenant and the first cloud instance matches the feasible communication path indicated by the access control policy.
7. The method according to any one of claims 1 to 6, characterized in that: The access control policy is further used to indicate a signature of the access control policy, where the signature is obtained by the tenant performing a signature operation on the access control policy. The cloud management platform detects, based on the credential acquisition request, whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy, including: The cloud management platform performs a signature verification operation on the signature indicated by the access control policy based on the credential acquisition request; If the signature verification operation is successful, the cloud management platform detects whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy.
8. The method according to any one of claims 1 to 7, characterized in that: The multiple cloud instances are any of the following: a physical server, a virtual machine, a container, a micro virtual machine, and a bare metal server.
9. A cloud management platform, characterized in that: The cloud management platform is used to manage multiple cloud instances that provide cloud services to tenants. The multiple cloud instances can communicate with each other based on the credentials of the tenants. The cloud management platform includes: a receiving module, configured to receive a credential acquisition request sent by a first cloud instance among the multiple cloud instances, wherein the credential acquisition request is used to indicate an access control policy for the multiple cloud instances, wherein the access control policy is provided by the tenant to the first cloud instance, and wherein the access control policy is used to indicate at least one cloud instance among the multiple cloud instances from which the credential can be acquired; A detection module is used to detect whether the first cloud instance is located in at least one of the cloud instances indicated by the access control policy based on the credential acquisition request. If so, the cloud management platform sends the credential to the first cloud instance, and the credential is used for the first cloud instance to access a second cloud instance among the multiple cloud instances.
10. The cloud management platform according to claim 9, characterized in that: The access control policy is used to indicate a cloud instance whitelist set by the tenant, and the cloud instance whitelist is composed of at least one cloud instance among the multiple cloud instances. The detection module is used to detect whether the first cloud instance is in the cloud instance whitelist indicated by the access control policy based on the credential acquisition request.
11. The cloud management platform according to claim 9, characterized in that: Each cloud instance includes at least one interface, the credential acquisition request is also used to indicate the interface of the first cloud instance called by the tenant, the access control policy is used to indicate the interface whitelist set by the tenant, and the interface whitelist is composed of the interface of at least one cloud instance among the multiple cloud instances. The detection module is used to detect whether the interface of the first cloud instance called by the tenant is in the interface whitelist indicated by the access control policy based on the credential acquisition request.
12. The cloud management platform according to claim 9, characterized in that: The access control policy is used to indicate the identity of the tenant. The cloud management platform is pre-set with an identity whitelist for the first cloud instance, and the identity whitelist is composed of multiple pre-set identities. The detection module is used to detect whether the identity indicated by the access control policy is in the identity whitelist based on the credential acquisition request.
13. The cloud management platform according to claim 9, characterized in that: The access control policy is used to indicate the communication duration set by the tenant and the time when the tenant accesses the first cloud instance. The detection module is used to detect, based on the credential acquisition request, whether the difference between the time indicated by the access control policy and the current time is less than the communication duration indicated by the access control policy.
14. The cloud management platform according to claim 9, characterized in that: The access control policy is used to indicate a feasible communication path between the tenant and the first cloud instance set by the tenant, and the detection module is used to detect, based on the credential acquisition request, whether the current communication path between the tenant and the first cloud instance matches the feasible communication path indicated by the access control policy.
15. The cloud management platform according to any one of claims 9 to 14, characterized in that: The access control policy is further used to indicate a signature of the access control policy, where the signature is obtained by the tenant performing a signature operation on the access control policy. The detection module is used to: Based on the credential acquisition request, performing a signature verification operation on the signature indicated by the access control policy; If the signature verification operation is successful, it is detected whether the first cloud instance is located in the at least one cloud instance indicated by the access control policy.
16. The cloud management platform according to any one of claims 9 to 15, characterized in that: The multiple cloud instances are any of the following: a physical server, a virtual machine, a container, a micro virtual machine, and a bare metal server.
17. A computing device cluster, characterized in that: The computing device cluster includes at least one computing device, each computing device including a processor and a memory: The memory is used to store instructions; The processor is configured to cause the computing device cluster to execute the method according to any one of claims 1 to 8 according to the instructions.
18. A computer storage medium, characterized in that: The computer storage medium stores one or more instructions, which, when executed by one or more computers, enable the one or more computers to implement the method of any one of claims 1 to 8.
19. A computer program product, characterized in that The computer program product stores instructions, which, when executed by a computer, enable the computer to implement the method according to any one of claims 1 to 8.
Citation Information
Patent Citations
Method and device for controlling permission of tenant to access container instance
CN111935110A
Cloud computing resource access method and device, service line service and gateway
CN112187725A
Resource access authority management method and device, electronic equipment and medium
CN114095200A
Techniques for selective container access to cloud services based on hosting node
US20220217139A1