Cross-domain access control method based on cloud management platform, and cloud management platform

Through the access control interface of the cloud management platform, tenants can formulate access control policies at one time. The cloud management platform automatically manages cross-domain communication authorization, solving the problem of tenants' frequent policy modifications and improving operational convenience and experience.

WO2025140271A1PCT designated stage expired Publication Date: 2025-07-03HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/142189
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-29
Filing Date
2024-12-25
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

In public cloud systems, tenants need to frequently modify access control policies to achieve cross-domain communication, resulting in inconvenient operation and poor experience.

Method used

Through the cloud management platform, tenants can formulate access control policies at once, and the cloud management platform automatically determines and manages cross-domain communication authorizations to reduce tenants' operations.

Benefits of technology

It realizes convenient management of cross-domain communication, reduces the number of operations that tenants have in formulating access control policies, and improves the tenant experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024142189_03072025_PF_FP_ABST
    Figure CN2024142189_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The present application discloses a cross-domain access control method based on a cloud management platform, and a cloud management platform, which can reduce the operations of tenants when formulating access control policies, provide convenience for tenants, and thus improve tenant experience. The method of the present application comprises: for a plurality of domains comprised in an organization of a tenant, when the tenant needs to perform access control for a first cloud service comprised in a first domain among the plurality of domains, the tenant may input an access control policy formulated by the tenant for the first cloud service of the first domain to an access control interface provided by the cloud management platform, so that the cloud management platform can receive the access control policy by means of the access control interface. If the access control policy is used for indicating that the access authorization scope of the first cloud service comprised in the first domain is a second cloud service comprised in the organization of the tenant, the cloud management platform allows the second cloud service comprised in any domain in the organization of the tenant to access the first cloud service comprised in the first domain.
Need to check novelty before this filing date? Find Prior Art

Description

A cross-domain access control method based on cloud management platform and cloud management platform

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 26, 2023, with application number 202311824996.3, and with the invention name “A cloud service management method and cloud management platform based on cloud management platform”, and claims priority to the Chinese patent application filed with the State Intellectual Property Office on March 29, 2024, with application number 202410381646.2, and with the invention name “A cross-domain access control method and cloud management platform based on cloud management platform”, the entire contents of which are incorporated by reference into this application. Technical Field

[0002] The embodiments of the present application relate to the field of cloud technology, and in particular to a cross-domain access control method based on a cloud management platform and a cloud management platform. Background Art

[0003] In a public cloud system, each tenant can have at least one domain (realm). Therefore, the system can have multiple domains belonging to different tenants or the same tenant. Each domain can host one or more cloud services of the tenant, providing remote services to the tenant. Because domains are isolated from each other, cross-domain communication between cloud services in different domains requires tenant authorization.

[0004] In related technologies, when other domains need to access a tenant's domain, the tenant can set an access control policy for that domain. This access control policy typically specifies which domains within that domain can access a cloud service within that domain. Based on the access control policy, the cloud services within those domains are then authorized by the tenant to access the cloud service within that domain, thus achieving cross-domain communication.

[0005] However, if another cloud service in the new domain also needs to access this cloud service in the domain, the tenant needs to modify the access control policy for the domain so that the other cloud service in the new domain is also authorized. However, this will increase the tenant's operations on the access control policy, causing great inconvenience to the tenant and resulting in a poor tenant experience. Summary of the Invention

[0006] The embodiments of the present application provide a cross-domain access control method and a cloud management platform based on a cloud management platform, which can reduce the operations of tenants when formulating access control policies, provide convenience for tenants, and thus improve the tenant experience.

[0007] A first aspect of an embodiment of the present application provides a cross-domain access control method based on a cloud management platform. The cloud management platform used to implement the method can manage infrastructure that provides cloud services. The infrastructure includes a tenant organization. The tenant organization can include multiple domains of the tenant. Hereinafter, one of the multiple domains is referred to as a first domain. The first domain can include a first cloud service. The method includes:

[0008] For multiple domains included in a tenant's organization, when the tenant needs to perform access control for a first cloud service included in a first domain, the cloud management platform can provide the tenant with an access control interface. The tenant inputs the access control policy formulated by the tenant for the first cloud service included in the first domain into the access control interface. The cloud management platform can then receive the access control policy for the first cloud service included in the first domain through the access control interface. The access control policy can be used to indicate the access authorization scope set by the tenant for the first cloud service included in the first domain.

[0009] After obtaining the access control policy, the cloud management platform can determine the access authorization scope of the first cloud service contained in the first domain based on the access control policy. When the access authorization scope is the second cloud service contained in the tenant's organization, the cloud management platform can allow the second cloud service contained in any domain in the tenant's organization to access the first cloud service contained in the first domain, thereby realizing cross-domain communication. When the access authorization scope is the second cloud service contained in the second domain (another domain in the tenant's organization), the cloud management platform can allow the second cloud service contained in the second domain to access the first cloud service contained in the first domain, thereby realizing cross-domain communication.

[0010] The above method demonstrates that, among multiple domains within a tenant's organization, a tenant can formulate an access control policy for a first cloud service contained in a first domain and send the policy to the cloud management platform. The cloud management platform can then determine that the first cloud service contained in the first domain has access authorization scoped to a second cloud service contained in any domain within the tenant's organization. This means that the second cloud service contained in any domain within the tenant's organization is authorized by the tenant. The cloud management platform then allows the second cloud service contained in any domain within the tenant's organization to access the first cloud service contained in the first domain. Because the access control policy specifies that the first cloud service contained in the first domain has access authorization scoped to the tenant's entire organization, once the tenant's organization joins a new domain, the second microservice contained in the new domain automatically obtains the tenant's authorization. Therefore, the cloud management platform allows the second microservice contained in the new domain to access the first cloud service contained in the first domain. Similarly, once a domain leaves the tenant's organization, the second microservice contained in that domain no longer obtains the tenant's authorization. Therefore, the cloud management platform no longer allows the second microservice contained in that domain to access the first cloud service contained in the first domain. In this way, the tenant only needs to formulate an access control policy once for the first cloud service contained in the first domain. There is no need to re-formulate a new access control policy due to changes in domains in the organization. This can reduce the tenant's operations, provide convenience for the tenant, and thus improve the tenant experience.

[0011] In one possible implementation, the access control policy includes an authorized identifier, an organization identifier, and an identifier of the second cloud service. In the aforementioned implementation, the access control policy may include an authorized identifier, an identifier of the tenant's organization (e.g., an identity document (ID) of the tenant's organization), and an identifier of the second cloud service (e.g., an ID of the second cloud service). In this way, based on the access control policy, the cloud management platform may determine whether access to the first cloud service included in the first domain is authorized to access the second cloud service included in any domain of the tenant's organization.

[0012] In one possible implementation, the access control policy includes the authorized identifier, the identifier of the second domain, and the identifier of the second cloud service. In the aforementioned implementation, the access control policy may include the authorized identifier, the identifier of the second domain (e.g., the ID of the second domain, etc.), and the identifier of the second cloud service (e.g., the ID of the second cloud service, etc.). In this way, based on the access control policy, the cloud management platform can determine whether access to the first cloud service included in the first domain is authorized to access the second cloud service included in the second domain.

[0013] In one possible implementation, the access control policy also includes the processing that can be executed by the first cloud service, and the cloud management platform allows the second cloud service contained in any domain in the organization to access the first cloud service, including: the cloud management platform receives an access request sent by the second cloud service contained in the third domain, and sends the access request to the first cloud service, the access request is used to instruct the first cloud service to perform processing on the target data, the third domain is any domain in the organization; the cloud management platform receives the processing result of the target data sent by the first cloud service, and sends the processing result to the second cloud service contained in the third domain. In the aforementioned implementation, the access control policy may also include the processing that the tenant allows the first cloud service to perform. Assuming that any domain in the tenant's organization is the third domain, when the second cloud service contained in the third domain needs to access the first cloud service contained in the first domain, the second cloud service contained in the third domain can send an access request to the cloud management platform, and the access request is used to request the first cloud service contained in the first domain to perform some processing on the target data. The cloud management platform can then detect whether the second microservice contained in the third domain is within the access authorization scope set by the tenant for the first cloud service contained in the first domain. If so, the cloud management platform can further detect whether the processing indicated by the access request is a processing that the tenant allows the first cloud instance contained in the first domain to execute. If so, the cloud management platform can forward the access request to the first cloud service contained in the first domain. After receiving the access request, the first cloud service contained in the first domain can perform the processing indicated by the access request on the target data, thereby obtaining the processing result of the target data, and return the processing result of the target data to the cloud management platform. After obtaining the processing result of the target data, the cloud management platform can forward the processing result of the target data to the second cloud service contained in the third domain to complete cross-domain communication.

[0014] In one possible implementation, the access control policy also includes processing that can be executed by the first cloud service, and the cloud management platform allows the second cloud service included in the second domain to access the first cloud service, including: the cloud management platform receives an access request sent by the second cloud service included in the second domain, and sends the access request to the first cloud service, where the access request is used to instruct the first cloud service to perform processing on the target data; the cloud management platform receives the processing result of the target data sent by the first cloud service, and sends the processing result to the second cloud service included in the second domain. In the aforementioned implementation, the access control policy may also include processing that can be executed by the first cloud service allowed by the tenant. When the second cloud service included in the second domain needs to access the first cloud service included in the first domain, the second cloud service included in the second domain may send an access request to the cloud management platform, where the access request is used to request the first cloud service included in the first domain to perform certain processing on the target data. The cloud management platform can then detect whether the second microservice contained in the second domain is within the access authorization scope set by the tenant for the first cloud service contained in the first domain. If so, the cloud management platform can further detect whether the processing indicated by the access request is a processing that the tenant allows the first cloud instance contained in the first domain to execute. If so, the cloud management platform can forward the access request to the first cloud service contained in the first domain. After receiving the access request, the first cloud service contained in the first domain can perform the processing indicated by the access request on the target data, thereby obtaining the processing result of the target data, and return the processing result of the target data to the cloud management platform. After obtaining the processing result of the target data, the cloud management platform can forward the processing result of the target data to the second cloud service contained in the second domain to complete cross-domain communication.

[0015] In one possible implementation, the first cloud service is deployed in a cloud instance included in the first domain, where the cloud instance includes any one of the following: a physical server, a virtual machine, a container, a micro virtual machine, and a bare metal server.

[0016] In one possible implementation, multiple domains are located in the same site or different sites. A site includes any of the following: region, availability zone, data center, computer room, and cabinet.

[0017] A second aspect of an embodiment of the present application provides a cloud management platform, which is used to manage an infrastructure that provides cloud services. The infrastructure includes a tenant's organization, the organization includes multiple domains, and the first domain of the multiple domains includes a first cloud service. The cloud management platform includes: a receiving module, which is used to receive an access control policy for the first cloud service sent by the tenant through an access control interface; an access control module, which is used to: if the access control policy is used to indicate that the access authorization scope of the first cloud service is the second cloud service included in the organization, allow the second cloud service included in any domain in the organization to access the first cloud service; or, if the access control policy is used to indicate that the access authorization scope is the second cloud service included in the second domain, allow the second cloud service included in the second domain to access the first cloud service, where the second domain is one of the multiple domains.

[0018] In one possible implementation, the access control policy includes an identifier of the authorized party, an identifier of the organization, and an identifier of the second cloud service.

[0019] In one possible implementation, the access control policy includes an identifier of the authorization, an identifier of the second domain, and an identifier of the second cloud service.

[0020] In one possible implementation, the access control policy also includes processing executable by the first cloud service, and the access control module is used to: receive an access request sent by the second cloud service included in the third domain, and send the access request to the first cloud service, the access request is used to instruct the first cloud service to perform processing on the target data, and the third domain is any domain in the organization; receive the processing result of the target data sent by the first cloud service, and send the processing result to the second cloud service included in the third domain.

[0021] In one possible implementation, the access control policy also includes processing executable by the first cloud service, and the access control module is used to: receive an access request sent by the second cloud service included in the second domain, and send the access request to the first cloud service, where the access request is used to instruct the first cloud service to perform processing on the target data; receive the processing result of the target data sent by the first cloud service, and send the processing result to the second cloud service included in the second domain.

[0022] In one possible implementation, the first cloud service is deployed in a cloud instance included in the first domain, where the cloud instance includes any one of the following: a physical server, a virtual machine, a container, a micro virtual machine, and a bare metal server.

[0023] In one possible implementation, multiple domains are located in the same site or different sites. A site includes any of the following: region, availability zone, data center, computer room, and cabinet.

[0024] A third aspect of an embodiment of the present application provides a computing device cluster, which includes at least one computing device, each computing device including a processor and a memory: the memory is used to store instructions; the processor is used to enable the computing device cluster to execute the method described in the first aspect or any possible implementation method of the first aspect according to the instructions.

[0025] A fourth aspect of an embodiment of the present application provides a computer storage medium storing one or more instructions, which, when executed by one or more computers, enables the one or more computers to implement the method described in the first aspect or any possible implementation method of the first aspect.

[0026] A fifth aspect of the embodiments of the present application provides a computer program product, which stores instructions. When the instructions are executed by a computer, the computer implements the method described in the first aspect or any possible implementation method of the first aspect.

[0027] In an embodiment of the present application, for multiple domains included in a tenant's organization, when the tenant needs to perform access control for a first cloud service included in a first domain among the multiple domains, the tenant can input the access control policy formulated by the tenant for the first cloud service of the first domain into the access control interface provided by the cloud management platform, so that the cloud management platform can receive the access control policy through the access control interface. If the access control policy is used to indicate that the access authorization scope of the first cloud service included in the first domain is the second cloud service included in the tenant's organization, the cloud management platform allows the second cloud service included in any domain in the tenant's organization to access the first cloud service included in the first domain. In the above process, among the multiple domains included in the tenant's organization, for the first cloud service included in the first domain, the tenant can formulate an access control policy for it and send the access control policy to the cloud management platform. Therefore, the cloud management platform can determine that the access authorization scope of the first cloud service included in the first domain is the second cloud service included in any domain in the tenant's organization, which is equivalent to the second cloud service included in any domain in the tenant's organization being authorized by the tenant, and the cloud management platform allows the second cloud service included in any domain in the tenant's organization to access the first cloud service included in the first domain. Because the access control policy specifies that the access authorization scope of the first cloud service contained in the first domain is the tenant's entire organization, once the tenant's organization joins a new domain, the second microservice contained in the new domain automatically obtains the tenant's authorization. Therefore, the cloud management platform can allow the second microservice contained in the new domain to access the first cloud service contained in the first domain. Correspondingly, once a domain leaves the tenant's organization, the second microservice contained in that domain no longer obtains the tenant's authorization. Therefore, the cloud management platform no longer allows the second microservice contained in that domain to access the first cloud service contained in the first domain. In this way, the tenant only needs to formulate an access control policy once for the first cloud service contained in the first domain, and there is no need to re-formulate a new access control policy due to changes in domains in the organization. This can reduce the tenant's operations, provide convenience for tenants, and thus improve the tenant experience. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] FIG1 is a schematic diagram of the structure of a cloud service system provided in an embodiment of the present application;

[0029] FIG2 is another schematic diagram of the organization of tenants provided in an embodiment of the present application;

[0030] FIG3 is a flow chart of a cross-domain access control method based on a cloud management platform provided in an embodiment of the present application;

[0031] FIG4 is a schematic diagram of a tenant interface provided in an embodiment of the present application;

[0032] FIG5 is another schematic diagram of a tenant interface provided in an embodiment of the present application;

[0033] FIG6 is another schematic diagram of the cloud service system provided in an embodiment of the present application;

[0034] FIG7 is another schematic diagram of the cloud service system provided in an embodiment of the present application;

[0035] FIG8 is a schematic diagram of the structure of a cloud management platform provided in an embodiment of the present application;

[0036] FIG9 is a schematic diagram of a structure of a computing device provided in an embodiment of the present application;

[0037] FIG10 is a schematic diagram of a structure of a computing device cluster provided in an embodiment of the present application;

[0038] FIG11 is a schematic diagram of computer devices in a computer cluster provided by an embodiment of the present application being connected via a network. DETAILED DESCRIPTION

[0039] The embodiments of the present application provide a cross-domain access control method and a cloud management platform based on a cloud management platform, which can reduce the operations of tenants when formulating access control policies, provide convenience for tenants, and thus improve the tenant experience.

[0040] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, and this is merely a way of distinguishing the objects of the same attributes when describing them in the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment.

[0041] In a public cloud system, each tenant can own at least one domain. Therefore, multiple domains can be deployed in the system, belonging to different tenants or the same tenant. Each domain can host one or more cloud services belonging to the tenant, providing remote services. Because domains are isolated from each other, cross-domain communication between cloud services in different domains requires tenant authorization.

[0042] In related art, when other domains need to access a tenant's domain, the tenant can set an access control policy for that domain. The access control policy set by the tenant typically indicates which domains within that domain can access a cloud service contained in that cloud service. Based on the access control policy, the cloud services contained in these domains are then authorized by the tenant to access the cloud service contained in that domain, thereby achieving cross-domain communication. For example, suppose a public cloud system includes domains A, B, C, and D. Domain A contains an object storage service, and domains B and C contain an audit service. In certain scenarios, the audit services contained in domains B and C need to write data to the object storage service contained in domain A. Therefore, the tenant to which domain A belongs can set an access control policy for domain A that allows the audit services contained in domains B and C to access the object storage service contained in domain A. Consequently, the audit services contained in domains B and C can subsequently access the object storage service contained in domain A to write data.

[0043] However, if another cloud service in the new domain also needs to access this cloud service in the domain, the tenant will need to modify the access control policy for the domain to authorize the other cloud service in the new domain. However, this will increase the tenant's access control policy operations, causing significant inconvenience to the tenant and resulting in a poor user experience. As in the example above, if a new domain E is added to the public cloud system and domain E also includes an audit service, when the audit service in domain E also needs to access the object storage service in domain A, the tenant will need to re-edit the new access control policy, which will cause operational inconvenience to the tenant.

[0044] To address the above issues, the present application provides a cross-domain access control method based on a cloud management platform. This method can be implemented through a cloud service system (e.g., a public cloud system, etc.). FIG1 is a schematic diagram of the structure of the cloud service system provided by the present application. As shown in FIG1 , the cloud service system includes an infrastructure that can provide cloud services and a cloud management platform that manages these infrastructures. The cloud management platform and infrastructure are introduced separately below:

[0045] The cloud management platform can coordinate the management of the infrastructure in the entire cloud service system (for example, in the infrastructure, according to the tenant's instructions, create an organization dedicated to the tenant. The tenant's organization can contain multiple domains, each domain can contain multiple cloud instances, and these cloud instances can be used to run the tenant's cloud services to provide remote services to the tenant, etc.). It can also be open to tenants outside the cloud service system and respond to their requests. For example, the cloud management platform can provide various interfaces such as login interfaces and access control interfaces for tenants' clients (for example, the terminal device used by the tenant or the browser on the terminal device, etc.). Among them, the cloud management platform can authenticate the tenant's client through the login interface, and after successful authentication, the tenant's client can be allowed to log in to the cloud management platform. For example, the cloud management platform can also allow the tenant's client to send the access control policy set by the tenant for the target cloud service contained in the target domain to the cloud management platform through the access control interface. The access control policy can be used to indicate the access authorization scope of the target cloud service. For example, the access authorization scope can be the remaining cloud services contained in any domain in the tenant's entire organization. For another example, the access authorization scope can also be the remaining cloud services contained in one or more domains in the tenant's organization. Then, based on the access authorization scope indicated by the access control policy, the cloud management platform can allow the remaining cloud services contained in all domains in the tenant's organization, or the remaining cloud services in some domains, to access the target cloud service in the target domain, thereby achieving cross-domain communication. In addition, the access control policy can also be used to indicate certain processing (operations) that the target cloud service can perform on data. When the remaining cloud services contained in all domains in the organization, or the remaining cloud services in some domains, send an access request to the target cloud service in the target domain, the target cloud service will perform this processing on the data indicated by the access request and return the corresponding processing results, thereby completing cross-domain communication.

[0046] The infrastructure includes a tenant's organization, which includes multiple domains, each domain includes multiple cloud instances, and each cloud instance runs multiple cloud services. It should be noted that the cloud services running on different cloud instances can be the same or different, and there is no restriction here. When a cloud service in a domain needs to access another cloud service in another domain, cross-domain communication is triggered (the two cloud services can be the same cloud service or different cloud services, and there is no restriction here). For example, as shown in Figure 2 (Figure 2 is another schematic diagram of the tenant's organization provided in an embodiment of the present application), for the tenant's organization, assume that the organization includes domain A, domain B and domain C. Among them, domain A includes multiple cloud instances, each cloud instance runs an object storage service (OBS). Domain B includes multiple cloud instances, some of which run audit services, and some of which run log services. Domain C includes multiple cloud instances, some of which run audit services, and some of which run log services. Then, when the audit services in domains B and C need to write data to the object storage service of domain A, cross-domain communication is triggered.

[0047] Furthermore, in a tenant's organization, multiple domains may be multiple accounts of the tenant, multiple projects of the tenant, or multiple subscriptions of the tenant.

[0048] Furthermore, in a tenant's organization, any cloud service contained in any domain can be an application, microservice, plug-in, etc. developed by the tenant, or an application, microservice, plug-in, etc. provided to the tenant by the cloud vendor (developer of the cloud service system), without any restriction here.

[0049] Furthermore, in the tenant's organization, any cloud instance contained in any domain can be presented in a variety of ways. For example, the cloud instance can be a physical server selected by the cloud management platform. In another example, the cloud instance can be a bare metal server selected by the cloud management platform. In another example, the cloud instance can be a virtual machine (VM) created by the cloud management platform on the physical server through virtualization technology. In another example, the cloud instance can also be a container (docker) created by the cloud management platform on the physical server through virtualization technology. In another example, the cloud instance can also be a micro virtual machine (microVM) created by the cloud management platform on the physical server through virtualization technology, and so on.

[0050] Furthermore, in a tenant's organization, multiple domains can be deployed in the same site or different sites. The site can be presented in various forms. For example, the site can be a region in the infrastructure, or an availability zone in the infrastructure, or a data center (DC) in the infrastructure, or a room in the infrastructure, or a cabinet in the infrastructure, etc.

[0051] Based on the above cloud service system, within a tenant's organization, the tenant can formulate an access control policy for the target cloud service contained in the target domain and send it to the cloud management platform. The cloud management platform can then determine that the scope of its access authorization is the remaining cloud services contained in any domain within the tenant's organization. This means that the remaining cloud services contained in any domain within the tenant's organization are authorized by the tenant. The cloud management platform then allows the remaining cloud services contained in any domain within the tenant's organization to access the target cloud service contained in the target domain. Because the access control policy specifies that the scope of access authorization for the target cloud service contained in the target domain is the tenant's entire organization, once the tenant's organization joins a new domain, the remaining microservices contained in the new domain automatically obtain the tenant's authorization. Therefore, the cloud management platform allows the remaining microservices contained in the new domain to access the target cloud service contained in the target domain. Correspondingly, once a domain leaves the tenant's organization, the remaining microservices contained in that domain no longer obtain the tenant's authorization. Therefore, the cloud management platform no longer allows the remaining microservices contained in that domain to access the target cloud service contained in the target domain. In this way, the tenant only needs to formulate an access control policy once for the target cloud service included in the target domain, and does not need to re-formulate a new access control policy due to changes in the domain in the organization. This can reduce the tenant's operations, provide convenience for the tenant, and thus improve the tenant experience. In order to further understand the process, the following is a further introduction to the process in conjunction with Figure 3. Figure 3 is a flow chart of a cross-domain access control method based on a cloud management platform provided in an embodiment of the present application. As shown in Figure 3, the method is implemented by a cloud service system as shown in Figure 1. The cloud service system includes an infrastructure that provides cloud services and a cloud management platform that manages these infrastructures. These infrastructures include the tenant's organization. The tenant's organization includes multiple domains. Hereinafter, one of the multiple domains will be referred to as the first domain (i.e., the aforementioned target domain). The first domain may include a first cloud service (i.e., the aforementioned target cloud service). The method includes:

[0052] 301. The cloud management platform receives an access control policy for a first cloud service sent by a tenant through an access control interface.

[0053] In this embodiment, for multiple domains included in the tenant's organization, when the tenant needs to perform access control for the first cloud service included in the first domain, the cloud management platform can provide an access control interface (for example, an access control policy input field in the tenant interface, etc.) to the tenant's client, and the tenant inputs the access control policy formulated by the tenant for the first cloud service included in the first domain into the access control interface through its client, so the cloud management platform can receive the access control policy for the first cloud service included in the first domain through the access control interface. The access control policy can be used to indicate the access authorization scope set by the tenant for the first cloud service. For example, the access authorization can be for the second cloud service included in the tenant's organization. For another example, the access authorization can also be for another domain in the tenant's organization, that is, the second cloud service included in the second domain.

[0054] Specifically, the access control policy can be presented in the following ways:

[0055] (1) The access control policy may include an authorized identifier (the identifier is used to indicate that authorization is granted to a subject within a certain scope), an identifier of the tenant's organization (the identifier is used to indicate that the scope of authorization is the tenant's organization), and an identifier of the second cloud service (the identifier is used to indicate that the subject within the scope of authorization is the second cloud service included in the tenant's organization). In addition, the access control policy may also include processing that can be performed by the first cloud service (i.e., when the second cloud service included in any domain of the organization accesses the first cloud service included in the first domain, the first cloud service can perform processing on the second cloud service). In this way, based on the access control policy, the cloud management platform can determine that the first cloud service included in the first domain is authorized to access the second cloud service included in any domain of the tenant's organization.

[0056] For example, as shown in Figure 4 (Figure 4 is a schematic diagram of the tenant interface provided by an embodiment of the present application), assume that the tenant's organization 1 includes account 1 (i.e., domain 1), account 2 (i.e., domain 2), and account 3 (i.e., domain 3). Account 1 includes the object storage service, and accounts 2 and 3 include the audit service and the log service. When the tenant needs to perform access control for the object storage service included in account 1, the tenant can log in to the cloud management platform. The cloud management platform can provide the tenant with a tenant interface. The tenant interface includes an access control policy input field. Therefore, the tenant can enter the access control policy for the object storage service included in account 1 in the access control policy input field:

[0057] (2) The access control policy may include an authorized identifier (the identifier is used to indicate that authorization is granted to a subject within a certain scope), an identifier of the second domain (the identifier is used to indicate that the scope of authorization is one of the domains in the tenant's organization, i.e., the second domain), and an identifier of the second cloud service (the identifier is used to indicate that the subject within the scope of authorization is the second cloud service contained in the second domain). In addition, the access control policy may also include processing that can be performed by the first cloud service (i.e., when the second cloud service contained in the second domain accesses the first cloud service contained in the first domain, the first cloud service can perform processing on the second cloud service). In this way, based on the access control policy, the cloud management platform can determine that the access authorization for the first cloud service contained in the first domain is to access the second cloud service contained in the second domain.

[0058] For example, as shown in Figure 5 (Figure 5 is another schematic diagram of the tenant interface provided by an embodiment of the present application), assume that the tenant's organization 1 includes account 1 (i.e., domain 1), account 2 (i.e., domain 2), and account 3 (i.e., domain 3). Account 1 includes the object storage service, and accounts 2 and 3 include the audit service and the log service. When the tenant needs to perform access control for the object storage service included in account 1, the tenant can log in to the cloud management platform. The cloud management platform can provide the tenant with a tenant interface. The tenant interface includes an access control policy input field. Therefore, the tenant can enter the access control policy for the object storage service included in account 1 in the access control policy input field:

[0059] 302. If the access control policy is used to indicate that the access authorization scope of the first cloud service is the second cloud service included in the organization, the cloud management platform allows the second cloud service included in any domain in the organization to access the first cloud service.

[0060] After obtaining the access control policy, the cloud management platform can determine the access authorization scope of the first cloud service contained in the first domain based on the access control policy. When the access authorization scope is the second cloud service contained in the tenant's organization, the cloud management platform can allow the second cloud service contained in any domain in the tenant's organization to access the first cloud service contained in the first domain, thereby realizing cross-domain communication.

[0061] Specifically, the cloud management platform can achieve cross-domain communication through the following methods:

[0062] After obtaining the access control policy, the cloud management platform can determine the access authorization scope set by the tenant for the first cloud service contained in the first domain, the second cloud service contained in any domain in the tenant's organization based on the access control policy, and can also determine the processing that the tenant allows the first cloud service to perform.

[0063] Assuming any domain in a tenant's organization is the third domain, when a second cloud service in the third domain needs to access a first cloud service in the first domain, the second cloud service in the third domain can send an access request to the cloud management platform, requesting the first cloud service in the first domain to perform certain processing on the target data. The cloud management platform can then detect whether the second microservice in the third domain is within the access authorization scope set by the tenant for the first cloud service in the first domain. If so, the cloud management platform can further detect whether the processing indicated by the access request is a processing that the tenant allows to be executed by the first cloud instance in the first domain. If so, the cloud management platform can forward the access request to the first cloud service in the first domain.

[0064] After receiving the access request, the first cloud service in the first domain can perform the processing indicated by the access request on the target data, thereby obtaining the processing results of the target data and returning them to the cloud management platform. After receiving the processing results of the target data, the cloud management platform can forward the processing results of the target data to the second cloud service in the third domain. At this point, cross-domain communication between the first cloud service in the first domain and the second cloud service in the third domain has been successfully completed.

[0065] Still taking the above example, as shown in Figure 6 (Figure 6 is another schematic diagram of the cloud service system provided by an embodiment of the present application, and Figure 6 is drawn based on Figure 4), when the audit service of account 3 needs to write certain data to the object storage service of account 1, the audit service of account 3 can send an access request to the cloud management platform. The cloud management platform determines that the audit service of account 3 is located in the authorized subject of the object storage service of account 1, and the processing indicated by the access request (i.e., writing the data) is the processing allowed by the tenant, and then sends the access request to the object storage service of account 1, so that the object storage service of account 1 can store the data, which is equivalent to writing the data to the object storage service of account 1. Then, the object storage service of account 1 can return the processing result of the data to the cloud management platform. Then, the cloud management platform can send the processing result of the data to the audit service of account 3, and the audit service of account 3 can determine that the data has been successfully written to the object storage service of account 1 based on the processing result of the data.

[0066] 303. If the access control policy is used to indicate that the access authorization scope is the second cloud service included in the second domain, the cloud management platform allows the second cloud service included in the second domain to access the first cloud service, and the second domain is one of the multiple domains.

[0067] After obtaining the access control policy, the cloud management platform can determine the access authorization scope of the first cloud service contained in the first domain based on the access control policy. When the access authorization scope is the second cloud service contained in the second domain (another domain in the tenant's organization), the cloud management platform can allow the second cloud service contained in the second domain to access the first cloud service contained in the first domain, thereby realizing cross-domain communication.

[0068] Specifically, the cloud management platform can achieve cross-domain communication through the following methods:

[0069] After obtaining the access control policy, the cloud management platform can determine the access authorization scope set by the tenant for the first cloud service contained in the first domain, the second cloud service contained in the second domain in the tenant's organization, and the processing allowed by the tenant to be performed by the first cloud service based on the access control policy.

[0070] When a second cloud service in a second domain needs to access a first cloud service in a first domain, the second cloud service in the second domain can send an access request to the cloud management platform, requesting the first cloud service in the first domain to perform certain processing on target data. The cloud management platform can then check whether the second microservice in the second domain is within the access authorization scope set by the tenant for the first cloud service in the first domain. If so, the cloud management platform can further check whether the processing indicated by the access request is a processing that the tenant allows the first cloud instance in the first domain to perform. If so, the cloud management platform can forward the access request to the first cloud service in the first domain.

[0071] After receiving the access request, the first cloud service in the first domain can perform the processing indicated by the access request on the target data, thereby obtaining the processing results of the target data and returning them to the cloud management platform. After receiving the processing results of the target data, the cloud management platform can forward the processing results of the target data to the second cloud service in the second domain. At this point, cross-domain communication between the first cloud service in the first domain and the second cloud service in the second domain has been successfully completed.

[0072] Still taking the above example, as shown in Figure 7 (Figure 7 is another schematic diagram of the cloud service system provided by an embodiment of the present application, and Figure 7 is drawn based on Figure 5), when the audit service of account 2 needs to write certain data to the object storage service of account 1, the audit service of account 2 can send an access request to the cloud management platform. The cloud management platform determines that the audit service of account 2 is located in the authorized subject of the object storage service of account 1, and the processing indicated by the access request (i.e., writing the data) is the processing allowed by the tenant, and then sends the access request to the object storage service of account 1, so that the object storage service of account 1 can store the data, which is equivalent to writing the data to the object storage service of account 1. Then, the object storage service of account 1 can return the processing result of the data to the cloud management platform. Then, the cloud management platform can send the processing result of the data to the audit service of account 2, and the audit service of account 2 can determine that the data has been successfully written to the object storage service of account 1 based on the processing result of the data.

[0073] In an embodiment of the present application, for multiple domains included in a tenant's organization, when the tenant needs to perform access control for a first cloud service included in a first domain among the multiple domains, the tenant can input the access control policy formulated by the tenant for the first cloud service of the first domain into the access control interface provided by the cloud management platform, so that the cloud management platform can receive the access control policy through the access control interface. If the access control policy is used to indicate that the access authorization scope of the first cloud service included in the first domain is the second cloud service included in the tenant's organization, the cloud management platform allows the second cloud service included in any domain in the tenant's organization to access the first cloud service included in the first domain. In the above process, among the multiple domains included in the tenant's organization, for the first cloud service included in the first domain, the tenant can formulate an access control policy for it and send the access control policy to the cloud management platform. Therefore, the cloud management platform can determine that the access authorization scope of the first cloud service included in the first domain is the second cloud service included in any domain in the tenant's organization, which is equivalent to the second cloud service included in any domain in the tenant's organization being authorized by the tenant, and the cloud management platform allows the second cloud service included in any domain in the tenant's organization to access the first cloud service included in the first domain. Because the access control policy specifies that the access authorization scope of the first cloud service contained in the first domain is the tenant's entire organization, once the tenant's organization joins a new domain, the second microservice contained in the new domain automatically obtains the tenant's authorization. Therefore, the cloud management platform can allow the second microservice contained in the new domain to access the first cloud service contained in the first domain. Correspondingly, once a domain leaves the tenant's organization, the second microservice contained in that domain no longer obtains the tenant's authorization. Therefore, the cloud management platform no longer allows the second microservice contained in that domain to access the first cloud service contained in the first domain. In this way, the tenant only needs to formulate an access control policy once for the first cloud service contained in the first domain, and there is no need to re-formulate a new access control policy due to changes in domains in the organization. This can reduce the tenant's operations, provide convenience for tenants, and thus improve the tenant experience.

[0074] Furthermore, in an embodiment of the present application, for the first cloud service included in the first domain, the second microservices of all domains in the organization or the second microservices of the second domain must obtain authorization from the tenant before accessing the first cloud service included in the first domain. This can prevent the domain of some attackers from arbitrarily accessing the first cloud service included in the first domain, which is conducive to ensuring the data security of the tenants.

[0075] The above is a detailed description of the cross-domain access control method based on the cloud management platform provided in an embodiment of the present application. The cloud management platform provided in an embodiment of the present application will be introduced below. FIG8 is a structural diagram of the cloud management platform provided in an embodiment of the present application. As shown in FIG8, the cloud management platform is used to manage the infrastructure for providing cloud services. The infrastructure includes a tenant organization, and the organization includes multiple domains. The first domain of the multiple domains includes a first cloud service. The cloud management platform includes:

[0076] The receiving module 801 is configured to receive an access control policy for the first cloud service sent by the tenant through the access control interface; for example, the receiving module 801 may be used to implement step 301 in the embodiment shown in FIG. 3 .

[0077] Access control module 802 is configured to: if the access control policy indicates that the first cloud service's access authorization scope is a second cloud service within the organization, allow the second cloud service within any domain within the organization to access the first cloud service; or, if the access control policy indicates that the access authorization scope is a second cloud service within a second domain, allow the second cloud service within the second domain to access the first cloud service, where the second domain is one of the multiple domains. For example, access control module 802 may be configured to implement step 302 or step 303 in the embodiment shown in FIG. 3 .

[0078] In one possible implementation, the access control policy includes an identifier of the authorized party, an identifier of the organization, and an identifier of the second cloud service.

[0079] In one possible implementation, the access control policy includes an identifier of the authorization, an identifier of the second domain, and an identifier of the second cloud service.

[0080] In one possible implementation, the access control policy also includes processing executable by the first cloud service, and the access control module is used to: receive an access request sent by the second cloud service included in the third domain, and send the access request to the first cloud service, the access request is used to instruct the first cloud service to perform processing on the target data, and the third domain is any domain in the organization; receive the processing result of the target data sent by the first cloud service, and send the processing result to the second cloud service included in the third domain.

[0081] In one possible implementation, the access control policy also includes processing executable by the first cloud service, and the access control module is used to: receive an access request sent by the second cloud service included in the second domain, and send the access request to the first cloud service, where the access request is used to instruct the first cloud service to perform processing on the target data; receive the processing result of the target data sent by the first cloud service, and send the processing result to the second cloud service included in the second domain.

[0082] In one possible implementation, the first cloud service is deployed in a cloud instance included in the first domain, where the cloud instance includes any one of the following: a physical server, a virtual machine, a container, a micro virtual machine, and a bare metal server.

[0083] In one possible implementation, multiple domains are located in the same site or different sites. A site includes any of the following: region, availability zone, data center, computer room, and cabinet.

[0084] It should be noted that the information interaction, implementation process, etc. between the modules / units of the above-mentioned device are based on the same concept as the method embodiment of the present application, and the technical effects they bring are the same as those of the method embodiment of the present application. For specific contents, please refer to the description in the method embodiment shown above in the embodiment of the present application, and no further details will be given here.

[0085] Please refer to Figure 9, which is a schematic diagram of the structure of a computing device provided in an embodiment of the present application. As shown in Figure 9, the computing device 900 (which can be used to present the aforementioned cloud management platform) includes: a processor 901, a memory 902, a communication interface 903, and a bus 904. The processor 901, the memory 902, and the communication interface 903 are coupled via a bus (not labeled in the figure). The memory 902 stores instructions. When the execution instructions in the memory 902 are executed, the computing device 900 executes the method executed by the cloud management platform in the above method embodiment.

[0086] The computing device 900 may be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASICs), one or more digital signal processors (DSPs), one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. For example, when a unit in the apparatus can be implemented in the form of a processing element scheduler, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call a program. For example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0087] The processor 901 may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.

[0088] The memory 902 may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. The non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).

[0089] The memory 902 stores executable program code, and the processor 901 executes the executable program code to implement the functions of the aforementioned receiving module and access control module, thereby implementing the above-mentioned cross-domain access control method based on the cloud management platform. In other words, the memory 902 stores instructions for executing the above-mentioned cross-domain access control method based on the cloud management platform.

[0090] The communication interface 903 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 900 and other devices or a communication network.

[0091] In addition to the data bus, bus 904 may also include a power bus, a control bus, and a status signal bus. The bus may be a Peripheral Component Interconnect Express (PCIe) bus, an Extended Industry Standard Architecture (EISA) bus, a unified bus (Ubus or UB), a Compute Express Link (CXL), or a Cache Coherent Interconnect for Accelerators (CCIX). Buses can be categorized as address buses, data buses, and control buses.

[0092] Please refer to Figure 10 , which is a schematic diagram of the structure of a computing device cluster provided in an embodiment of the present application. As shown in Figure 10 , the computing device cluster 1000 includes at least one computing device 900 .

[0093] As shown in Figure 10, the computing device cluster 1000 includes at least one computing device 900. The memory 902 in one or more computing devices 900 in the computing device cluster 1000 may store the same instructions for executing the above-mentioned cross-domain access control method based on the cloud management platform.

[0094] In some possible implementations, the memory 902 of one or more computing devices 900 in the computing device cluster 1000 may also store partial instructions for executing the above-mentioned cross-domain access control method based on the cloud management platform. In other words, the combination of one or more computing devices 900 can jointly execute the above-mentioned cross-domain access control method based on the cloud management platform.

[0095] It should be noted that the memory 902 in different computing devices 900 in the computing device cluster 1000 may store different instructions, each for executing a portion of the functions of the aforementioned cloud management platform. In other words, the instructions stored in the memory 902 in different computing devices 900 may implement the functions of one or more modules such as the receiving module and the access control module.

[0096] In some possible implementations, one or more computing devices 900 in the computing device cluster 1000 may be connected via a network, which may be a wide area network or a local area network.

[0097] Please refer to Figure 11, which is a schematic diagram of computer devices in a computer cluster provided by an embodiment of the present application being connected via a network. As shown in Figure 11, two computing devices 900A and 900B are connected via a network. Specifically, each computing device is connected to the network via a communication interface.

[0098] In one possible implementation, the memory of the computing device 900A stores instructions for executing functions of a receiving module and the like. Meanwhile, the memory of the computing device 900B stores instructions for executing functions of an access control module and the like.

[0099] It should be understood that the functions of the computing device 900A shown in Figure 11 may also be completed by multiple computing devices. Similarly, the functions of the computing device 900B may also be completed by multiple computing devices.

[0100] An embodiment of the present application also relates to a computer storage medium, in which a program for signal processing is stored. When the computer storage medium is run on a computer, the computer executes the steps executed by the cloud management platform in the embodiment shown in Figure 3.

[0101] An embodiment of the present application also relates to a computer program product, which stores instructions that, when executed by a computer, enable the computer to execute the steps performed by the cloud management platform in the embodiment shown in FIG3 .

[0102] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0103] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.

[0104] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0105] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.

[0106] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

Claims

1. A cross-domain access control method based on a cloud management platform, characterized in that The cloud management platform is used to manage the infrastructure that provides cloud services. The infrastructure includes the tenant's organization, and the organization includes multiple domains. The first domain among the multiple domains includes a first cloud service. The method includes: The cloud management platform receives, through an access control interface, an access control policy sent by the tenant for the first cloud service. If the access control policy is used to indicate that the access authorization scope of the first cloud service is a second cloud service included in the organization, the cloud management platform allows the second cloud service included in any domain of the organization to access the first cloud service; or, If the access control policy is used to indicate that the access authorization scope is a second cloud service included in a second domain, the cloud management platform allows the second cloud service included in the second domain to access the first cloud service, where the second domain is one of the domains in the organization.

2. The method according to claim 1, characterized in that, The access control policy includes an authorized identifier, an identifier of the organization, and an identifier of the second cloud service.

3. The method according to claim 1, wherein The access control policy includes an authorized identifier, an identifier of the second domain, and an identifier of the second cloud service.

4. The method according to claim 2, wherein The access control policy further includes a process executable by the first cloud service. The cloud management platform allowing the second cloud service included in any domain of the organization to access the first cloud service includes: The cloud management platform receives an access request sent by the second cloud service included in a third domain and sends the access request to the first cloud service. The access request is used to indicate that the first cloud service executes the process on target data, and the third domain is any domain in the organization; The cloud management platform receives the processing result of the target data sent by the first cloud service and sends the processing result to the second cloud service included in the third domain.

5. The method according to claim 3, wherein The access control policy further includes a process executable by the first cloud service. The cloud management platform allowing the second cloud service included in the second domain to access the first cloud service includes: The cloud management platform receives an access request sent by the second cloud service included in the second domain and sends the access request to the first cloud service. The access request is used to indicate that the first cloud service executes the process on target data; The cloud management platform receives the processing result of the target data sent by the first cloud service and sends the processing result to the second cloud service included in the second domain.

6. The method according to any one of claims 1 to 5, characterized in that, The first cloud service is deployed in a cloud instance included in the first domain, and the cloud instance includes any one of the following: physical server, virtual machine, container, micro virtual machine, and bare metal server.

7. The method according to any one of claims 1 to 6, characterized in that, The multiple domains are located in the same site or different sites, and the site includes any one of the following: region, availability zone, data center, computer room, and cabinet.

8. A cloud management platform, characterized in that, The cloud management platform is used to manage the infrastructure that provides cloud services. The infrastructure includes the tenant's organization, and the organization includes multiple domains. The first domain among the multiple domains includes a first cloud service. The cloud management platform includes: A receiving module, configured to receive, through an access control interface, an access control policy sent by the tenant for the first cloud service; An access control module, configured to: If the access control policy is used to indicate that the access authorization scope of the first cloud service is the second cloud service included in the organization, any second cloud service included in any domain of the organization is allowed to access the first cloud service; or, If the access control policy is used to indicate that the access authorization scope is the second cloud service included in the second domain, the second cloud service included in the second domain is allowed to access the first cloud service, and the second domain is one of the domains in the organization.

9. The cloud management platform according to claim 8, wherein The access control policy includes the authorized identifier, the identifier of the organization, and the identifier of the second cloud service.

10. The cloud management platform according to claim 8, characterized in that The access control policy includes the authorized identifier, the identifier of the second domain, and the identifier of the second cloud service.

11. The cloud management platform according to claim 9, wherein The access control policy further includes the processing executable by the first cloud service. The access control module is configured to: Receive an access request sent by a second cloud service included in a third domain, and send the access request to the first cloud service. The access request is used to indicate that the first cloud service performs the processing on target data. The third domain is any domain in the organization; Receive the processing result of the target data sent by the first cloud service, and send the processing result to the second cloud service included in the third domain.

12. The cloud management platform according to claim 10, wherein The access control policy further includes the processing executable by the first cloud service. The access control module is configured to: Receive an access request sent by a second cloud service included in the second domain, and send the access request to the first cloud service. The access request is used to indicate that the first cloud service performs the processing on target data; Receive the processing result of the target data sent by the first cloud service, and send the processing result to the second cloud service included in the second domain.

13. The cloud management platform according to any one of claims 8 to 12, characterized in that The first cloud service is deployed in a cloud instance included in the first domain. The cloud instance includes any one of the following: a physical server, a virtual machine, a container, a micro virtual machine, and a bare metal server.

14. The cloud management platform according to any one of claims 8 to 13, characterized in that The multiple domains are located in the same site or different sites. The site includes any one of the following: a region, an availability zone, a data center, a computer room, and a cabinet.

15. A cluster of computing devices, characterized in that, The computing device cluster includes at least one computing device. Each computing device includes a processor and a memory: The memory is used to store instructions; The processor is configured to, according to the instructions, cause the computing device cluster to execute the method according to any one of claims 1 to 7.

16. A computer storage medium, characterized in that, The computer storage medium stores one or more instructions. When the instructions are executed by one or more computers, the one or more computers are caused to implement the method according to any one of claims 1 to 7.

17. A computer program product, characterized in that, The computer program product stores instructions. When the instructions are executed by a computer, the computer is caused to implement the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Cross-domain access control method based on cloud management platform and cloud management platform

    CN120223342A

  • Multi-tenant-oriented cross-tenant access method, system and device and medium

    CN114884653A

  • Cloud service access permission setting method for enclave instances and cloud management platform

    CN116707849A

  • Secure client-side communication between multiple domains

    US20110246772A1

  • Network security management method and computer device

    US20230300141A1