Resource access control method, and platform
By using a management platform in a cloud computing environment to record the access control policies configured by administrators, the problems of loss and unreasonable use caused by uncontrolled resources are solved, and secure control and efficient management of resource access are achieved.
Patent Information
- Application Number
- PCT/CN2025/080179
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-06-19
- Filing Date
- 2025-03-03
- Publication Date
- 2025-11-27
AI Technical Summary
In a cloud computing environment, an organization's resources may be lost or misused due to uncontrolled management permissions, and users may share resources with external users or use them improperly.
A resource access control method and platform are provided. The management platform records the access control policies configured by the administrator and allows or denies access requests based on the policies, ensuring that the access endpoints comply with the policy requirements when forwarding access requests to resources.
Effectively control resource access, prevent resource loss and unreasonable use, ensure resource security, and improve the efficiency and accuracy of access control.
Smart Images

Figure CN2025080179_27112025_PF_FP_ABST
Abstract
Description
A resource access control method and platform
[0001] The present application claims priority to the Chinese Patent Application No. 202410634307.0, filed on May 21, 2024, entitled "A method and device for access control", and the Chinese Patent Application No. 202410796626.1, filed on June 19, 2024, entitled "A resource access control method and platform", both of which are incorporated herein by reference in their entirety. TECHNICAL FIELD
[0002] The present application relates to the technical field of computer, and in particular, to a resource access control method and platform. BACKGROUND
[0003] With the development of cloud computing and other technologies, an organization such as an enterprise can purchase or rent resources provided by a remote infrastructure, such as computing resources, storage resources, and the like. In this way, the organization does not need to build infrastructure locally, thereby reducing the operating cost of the organization.
[0004] A user in the organization can apply for and use resources by virtue of his / her identity in the organization. Generally, the user has management authority over the resources applied for by the user, and if the management authority is not controlled, it can lead to loss of resources of the organization. For example, the user can share the resources applied for by the user with users outside the organization, and the user can use the resources applied for by the user unreasonably, and the like. SUMMARY
[0005] The present application provides a resource access control method and platform, which can enable an administrator of an organization to control access requests for resources, and avoid loss of resources and unreasonable use of resources.
[0006] In a first aspect, a resource access control method is provided. The method is applied to a management platform, and the management platform is used to manage a plurality of access endpoints and a plurality of resources of a target organization. The plurality of resources are provided by a plurality of servers in an infrastructure, and the plurality of servers are arranged in a same data center or a plurality of data centers in the infrastructure. Each of the plurality of access endpoints corresponds to at least one of the plurality of resources, and the access endpoint is used to forward an access request for the resource corresponding to the access endpoint to the resource. The method comprises: recording, by the management platform, a first access control policy configured by an administrator of the target organization for a target access endpoint, the target access endpoint being at least one of the plurality of access endpoints; obtaining, by the management platform, a target access request for a target resource, the target resource being a resource corresponding to the target access endpoint in the plurality of resources; and allowing or prohibiting, by the management platform, the target access endpoint to forward the target access request to the target resource based on the first access control policy.
[0007] In the method, the administrator of the organization can configure the access control policy and apply the access control policy to the access endpoint used to forward the access request to the resource. In this way, when there is an access request to be forwarded by the access endpoint, it can be determined based on the access control policy whether the access request is allowed by the administrator of the organization. If the access request is allowed by the administrator of the organization, the access endpoint is allowed to forward the access request to the resource, so that the access request can access the resource. If the access request is not allowed by the administrator of the organization, the access endpoint is prohibited from forwarding the access request to the resource, so as to avoid the access request from accessing the resource. In this way, the administrator of the organization can control the access request of the resource of the organization, so as to protect the security of the resource and avoid unreasonable use, loss, etc. of the resource.
[0008] In a possible implementation, the target access endpoint is created by a first user in the target organization, and the management platform further records a second access control policy configured by the first user for the target access endpoint; and the management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy, including: the management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy and the second access control policy.
[0009] In the implementation, the user who creates the access endpoint can also configure the access control policy, and when there is an access request to be forwarded by the access endpoint, it is determined based on the access control policy whether the access request is allowed by the user in addition to determining whether the access request is allowed by the administrator of the organization. When the access request is allowed by both the administrator and the user, the access endpoint is allowed to forward the access request to the resource, otherwise the access endpoint is prohibited from forwarding the access request to the resource, so as to further protect the security of the resource.
[0010] In a possible implementation, the management platform records the first access control policy configured by the administrator of the target organization for the target access endpoint, including: the management platform associates the first access control policy with an organization node of the target organization, the organization node being an organization unit OU in the target organization or a first user, and the target access endpoint being created by the first user; and the management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy, including: the management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy when it is confirmed that the target access endpoint belongs to the organization node.
[0011] In this embodiment, the management platform can make the access control policy effective on the access endpoints in the organization node by associating the access control policy with the organization node, so that the operation of making the access control policy effective on each access endpoint is saved. Moreover, whenever there is a new access endpoint in the organization node, the access control policy is automatically made effective on the new access endpoint, so that the control on the new access endpoint can be timely implemented, and the security of the resource is efficiently ensured. When there is an access request that needs to be forwarded by the access endpoint, the access control policy of the access endpoint can be quickly queried by confirming the organization node to which the access endpoint belongs, and the efficiency of the access control is improved.
[0012] In a possible implementation, the method further includes: recording an association relationship between the identifier of the target access endpoint and the identifier of the first user; and confirming that the target access endpoint belongs to the organization node includes: obtaining the identifier of the target access endpoint from the target access request; and confirming that the target access endpoint belongs to the organization node based on the identifier of the target access endpoint and the association relationship.
[0013] The access request usually carries the identifier of the access endpoint that is called, and in this implementation, the user to which the access endpoint belongs can be identified by confirming the identifier of the access endpoint carried by the access request. Then, the organization node to which the access endpoint belongs can be identified by the user to which the access endpoint belongs.
[0014] In a possible implementation, the first access control policy indicates the permission of a user in the target organization to access the target resource through the target access endpoint, and the target access request is initiated by the first user or the second user in the target organization; the target access endpoint is created by the first user, and the second user is a user in the target organization other than the first user.
[0015] In this way, the administrator can prevent the users in the organization from using the resources of the organization unreasonably by using the access control policy.
[0016] In a possible implementation, the first access control policy indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by the user outside the target organization.
[0017] In this way, the administrator can prevent the users outside the organization from using the resources of the organization illegally by using the access control policy, and the security of the resource is ensured.
[0018] In a possible implementation, the target access endpoint is a virtual private cloud endpoint node (VPCEP).
[0019] The method can be used for the management of the VPCEP by the cloud management platform, so that the administrator can control the access to the cloud resource.
[0020] In a second aspect, a management platform is provided for managing a plurality of access endpoints and a plurality of resources of a target organization, wherein the plurality of resources are provided by a plurality of servers in an infrastructure, the plurality of servers are disposed in a same data center or a plurality of data centers in the infrastructure, each of the plurality of access endpoints corresponds to at least one of the plurality of resources, and the access endpoint is configured to forward an access request for the resource corresponding to the access endpoint to the resource; the management platform comprises: a recording module configured to record a first access control policy configured by an administrator of the target organization for a target access endpoint, the target access endpoint being at least one of the plurality of access endpoints; an obtaining module configured to obtain a target access request for a target resource, the target resource being the resource corresponding to the target access endpoint in the plurality of resources; and a control module configured to allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy.
[0021] In a possible implementation, the target access endpoint is created by a first user in the target organization, and the management platform further records a second access control policy configured by the first user for the target access endpoint; and the control module is configured to allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy and the second access control policy.
[0022] In a possible implementation, the recording module is configured to associate the first access control policy with an organization node of the target organization, the organization node being an organization unit (OU) in the target organization or the first user, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; and the control module is configured to allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy, if it is confirmed that the target access endpoint belongs to the organization node.
[0023] In a possible implementation, the recording module is further configured to record an association relationship between an identifier of the target access endpoint and an identifier of the first user; and the control module is configured to obtain the identifier of the target access endpoint from the target access request, and confirm that the target access endpoint belongs to the organization node based on the identifier of the target access endpoint and the association relationship.
[0024] In a possible implementation, the first access control policy indicates a permission of a user in the target organization to access the target resource through the target access endpoint, and the target access request is initiated by the first user or a second user in the target organization; wherein the target access endpoint is created by the first user, and the second user is a user in the target organization other than the first user; or the first access control policy indicates a permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a user outside the target organization.
[0025] In a possible implementation, the target access endpoint is a virtual private cloud endpoint node (VPCEP).
[0026] In a third aspect, a computing device cluster is provided, including at least one computing device, each computing device including a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method provided in the first aspect.
[0027] In a fourth aspect, a computer-readable storage medium is provided, including computer program instructions, when the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method provided in the first aspect.
[0028] In a fifth aspect, a computer program product including instructions is provided, when the instructions are executed by a computing device cluster, the computing device cluster executes the method provided in the first aspect.
[0029] The beneficial effects of the second aspect to the fifth aspect can refer to the beneficial effects of the first aspect described above, and will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0030] FIG. 1 is a schematic diagram of a system architecture provided by an embodiment of the present application;
[0031] FIG. 2 is a schematic diagram of a system architecture provided by an embodiment of the present application;
[0032] FIG. 3 is a schematic diagram of a system architecture provided by an embodiment of the present application;
[0033] FIG. 4 is a flowchart of a resource access control method provided by an embodiment of the present application;
[0034] FIG. 5 is a schematic diagram of an access control policy provided by an embodiment of the present application;
[0035] FIG. 6 is a schematic diagram of an access control policy provided by an embodiment of the present application;
[0036] FIG. 7 is a flowchart of a resource access control method provided by an embodiment of the present application;
[0037] FIG. 8 is a flowchart of a resource access control method provided by an embodiment of the present application;
[0038] FIG. 9 is a structural schematic diagram of a management platform provided by an embodiment of the present application;
[0039] FIG. 10 is a structural schematic diagram of a computing device provided by an embodiment of the present application;
[0040] FIG. 11 is a structural schematic diagram of a computing device cluster provided by an embodiment of the present application;
[0041] FIG. 12 is a structural diagram of a computing device cluster provided by an embodiment of the present application. DETAILED DESCRIPTION
[0042] The scheme provided by the embodiments of the present application will be described below with reference to the drawings. In the embodiments of the present application, "multiple" refers to two or more, and "multiple types" refers to two or more types. "First", "second", and the like are only used to distinguish similar objects, and do not necessarily indicate a specific order or number of objects.
[0043] To facilitate understanding of the scheme provided by the embodiments of the present application, the technical terms that may be involved in the embodiments of the present application will be introduced first.
[0044] Cloud technology refers to a kind of hosting service that unifies a series of resources such as hardware, software, and network in a wide area network or a local area network to realize data calculation, storage, processing, and sharing.
[0045] Infrastructure refers to a facility that provides computing resources, storage resources, and / or network resources for computing services. A resource pool can include at least one data center, and each data center includes multiple servers. The servers can be used as hosts to deploy instances. In cloud technology, infrastructure is also referred to as cloud infrastructure, which is used to provide computing resources, storage resources, and / or network resources for cloud computing services.
[0046] Management platform refers to a platform provided by a computing service provider for interacting with users. Users can register an account on the management platform and rent computing services with the account, thereby becoming users of the computing services. Users can manage resource pools and instances in the resource pools through the management platform. In the case of cloud computing services, the management platform can be referred to as a cloud management platform.
[0047] User refers to a user who rents resources. Users can register an account on the management platform operated by the computing service provider through a browser or other client. The computing service provider will record different user accounts to isolate the resources of different users according to the accounts. Generally, users have complete access to the resources they rent.
[0048] Resource: refers to an instance deployed in the infrastructure for running, which is used to provide computing, network, or storage resources, and the instance includes but is not limited to a computing instance, an elastic cloud server (ECS), a bare metal server (BMS), an object storage service (OBS) bucket, an elastic load balancer (ELB), a network address translation gateway (NAT Gateway), a cloud cache, and the like. In cloud technology, the resource can be referred to as a cloud resource.
[0049] Infrastructure: a facility supporting a computing service, including at least one data center, each data center including a plurality of servers, which can provide one or more resources, for example, the servers can run computing instances such as virtual machines (VMs) or containers. For example, in the case of multiple data centers, the multiple data centers can be distributed in different geographic regions, and the data centers can be remotely connected through a backbone network.
[0050] Organization (ORG): an entity created by the management platform for unified management of multiple users in a hierarchical tree structure. An organization has multiple members. Each member of the multiple members is a user registered to the management platform. Typically, the multiple members or users in an organization belong to the same group, for example, the same enterprise.
[0051] Organization node: a node in the tree structure of the organization. The organization node can be an organizational unit (OU) in the organization, or a user in the organization.
[0052] Organizational unit (OU): also referred to as an organizational department, a node in the tree structure of the organization. The organizational unit is created by an organization administrator, and the organizational department can be nested. Each organizational unit is used to manage one or more users.
[0053] Root organizational unit (ROU): also referred to as root OU, a root node in the tree structure of the organization. The OUs other than the root OU in the organization are leaf nodes of the tree structure of the organization, or leaf nodes of the root OU. The leaf node can also be referred to as a child node.
[0054] Member account (Acct): also known as user account, is the object of organization management. A member account represents a user. After the organization is created, the organization administrator invites the existing account to join the organization, or creates a new account through the organization, and the newly created account automatically joins the organization.
[0055] Access endpoint: is the portal or interface of the corresponding resource. Usually, an access endpoint corresponds to a resource, and the access endpoint serves as the portal or interface of the corresponding resource, and is used to forward access requests for the resource to the resource to realize access to the resource. Common access endpoints include virtual private cloud endpoint (VPCEP) and the like. A user can create a VPCEP, and correspond the created VPCEP to the resource of the user.
[0056] Virtual private cloud endpoint (VPCEP): composed of two resource instances of "terminal node service" and "terminal node". Among them, the terminal node service refers to configuring a cloud service or a user private service as a service supported by the terminal node, which can be connected and accessed by the terminal node. The terminal node is used to establish a convenient, secure and private connection channel between the virtual private cloud (VPC) and the terminal node service.
[0057] Object storage service (OBS): an object-based mass storage service, which provides users with mass, secure, high-reliable and low-cost data storage capabilities.
[0058] Service control policy (SCP): a mandatory access control (MAC) policy in organization management service, which is an object of organization management. The service control policy describes a set of permissions. The service control policy is a constraint, not an authorization. The behavior of the user to which the service control policy is applied cannot exceed the set of permissions described in the service control policy.
[0059] Network control policy (NCP): A policy created by an administrator of an organization, used to restrict the connection permission and / or resource access permission of an access endpoint. When an administrator of an organization creates an NCP and binds the NCP to a node (e.g., a root organization unit, an organization unit, or a user) of the organization, the connection permission and / or access resource permission of all virtual private cloud terminal nodes inside all accounts under the jurisdiction of the node are controlled by the policy. The NCP is a mandatory access control (MAC) policy, which does not provide permission by itself, but only serves as a constraint.
[0060] VPCEP policy: A policy created by a user who creates a VPCEP, which is used by the VPCEP to limit the users who access a corresponding resource through the VPCEP and the access operations on the resource.
[0061] In one scheme, the access control policy (e.g., VPCEP policy) created by a user restricts the users who access the resource of the user through an access endpoint (e.g., VPCEP) and restricts the access operations on the resource of the user through the access endpoint. That is, the access permission of the resource of any user in an organization is controlled by the user, which may result in the resource of the organization being illegally used or abused.
[0062] To address the above issue, embodiments of the present disclosure provide a resource access control method. In the method, a management platform can record an access control policy configured by an administrator of an organization for an access endpoint, and restrict or control an access request that needs to be forwarded by the access endpoint based on the access control policy, thereby avoiding illegal use or abuse of a resource through the access endpoint.
[0063] Next, the resource access control method provided by embodiments of the present disclosure is described in detail.
[0064] FIG. 1 shows a system architecture that can be used to implement the method. The system architecture can include a management platform 100 and an infrastructure 200.
[0065] The infrastructure 200 can include one or more data centers, each of which can include a plurality of servers. The servers in the infrastructure 200 can provide resources, e.g., for a target organization. Among others, a user within the target organization can apply for resources in the infrastructure 200 through the management platform 100 by virtue of his / her identity as a member of the target organization. In response to the application, one or more servers in the infrastructure 200 can provide the user with resources. The resources applied for by the user can be referred to as the user's resources. Also, the user's resources belong to the target organization. The user within the target organization can create an access endpoint through the management platform 100. By way of example, the access endpoint can be created in the infrastructure 200 to run the access endpoint with the resources in the infrastructure 200.
[0066] The user can map the access endpoint created by him / her to one or more resources applied for by him / her to send access requests to the resources through the access endpoint to access the resources.
[0067] In an embodiment of the present application, the management platform 100 can be used by an administrator of a target organization to manage the target organization, e.g., to create the target organization, to add or delete users in the target organization, etc. The management platform 100 can also be used by the administrator of the target organization to manage resources of the target organization, e.g., to manage access permissions to the resources of the target organization. Specifically, the administrator of the target organization can configure an access control policy for an access endpoint to manage access permissions to resources corresponding to the access endpoint. The management platform 100 can receive and record the access control policy configured by the administrator, e.g., access control policy Al. The access control policy Al can act on the access endpoint and be used to indicate permissions of users within or outside the target organization to access the corresponding resources through the access endpoint. The management platform 100 can associate the access control policy Al to one or more organization nodes in the target organization at the instruction of the administrator of the target organization, so that the access control policy Al acts on access endpoints within the one or more organization nodes. Among others, the access endpoints within an organization node are access endpoints created or owned by users within the organization node.
[0068] In some embodiments, the management platform 100 can receive and record an access control policy configured by a user, e.g., access control policy A2. The access control policy A2 acts on the access endpoint created by the user and is used to indicate permissions of users within or outside the target organization to access the corresponding resources through the access endpoint.
[0069] When the management platform 100 receives an access request for a certain resource, the management platform 100 can control the access request based on an access control policy that acts on an access endpoint corresponding to the resource. For example, the management platform 100 can allow the access endpoint to send the access request to the resource, so that the access request accesses the resource, or the management platform 100 can prohibit the access endpoint from sending the access request to the resource, so that the access request does not access the resource.
[0070] Associating the access control policy Al to one or more organizational nodes can cause the access control policy Al to act on access endpoints within the one or more organizational nodes. In this way, the management platform 100 can control access to resources within the one or more organizational nodes based on the access control policy Al. The resources within an organizational node refer to resources of users within the organizational node.
[0071] In some embodiments, the management platform 100 can provide an organizational management service. Through the organizational management service, an administrator of a target organization can create the target organization in the management platform 100. The target organization created through the organizational management service includes the administrator and a plurality of users. The administrator has user management permissions. The user management permissions refer to permissions to manage users within the organization. The administrator can invite existing users on the management platform to join the organization to which the administrator belongs, or register new users on the management platform, and the newly registered users automatically join the organization to which the administrator belongs.
[0072] As shown in FIG. 2, the target organization created through the organizational management service can include a plurality of organizational units (OUs), such as OU 310, OU 320, OU 330, and the like. The OU 310 is a root organizational unit (ROU). The root organizational unit can also be referred to as a root OU, is a root node in a tree structure of the organization, and is created by default when the organization is created. The root OU corresponds to the administrator, and the administrator can manage all users in the organization.
[0073] The OUs 320, 330, and the like are leaf nodes of the OU 310 and are created by the administrator represented by the OU 310. The administrator can divide a plurality of users within the organization into different leaf nodes, so as to facilitate management of the plurality of users. For example, as shown in FIG. 2, the user 321 and the user 322 within the target organization belong to the OU 320, and the user 331 within the target organization belongs to the OU 330.
[0074] In some embodiments, the user in the target organization can also be referred to as a segregation of duty (SOD) unit, which is the smallest unit in the management platform that has specific operation permissions and specific resources, and meets the principle of separation of responsibilities and permissions of business departments and business personnel of the enterprise. The management platform can assign a user identifier to each user. The user identifiers of different users are different, and different users can be distinguished by the user identifiers. In addition, the user identifier has a mapping relationship with the organization and the OU to which the user belongs. In this way, the organization and the OU to which the user belongs can be obtained through the user identifier of the user.
[0075] In some embodiments, the user identifier can be an account. In some embodiments, the user identifier can be a subscription. In some embodiments, the user identifier can be a project.
[0076] In some embodiments, in the tree structure shown in FIG. 2, the hierarchical management of the target organization can be implemented by using the organization compliance control policy. The users in the target organization can be managed by the organization compliance control policy, for example, the resources of the users or the behaviors of the users are managed. In this way, the access control policy A1 can be configured as an organization compliance control policy to manage the users in the target organization.
[0077] As shown in FIG. 2, each user has resources. For example, the user 321 has the resource 2101 and the resource 2102, the user 322 has the resource 220, and the user 331 has the resource 230. The resources of the user are resources that the user applies from the infrastructure 200 through the management platform 100. The user can use the resources to perform related businesses. The resources of the user belong to the organization to which the user belongs, and are resources of the organization to which the user belongs.
[0078] The user can create an access endpoint and correspond the access endpoint to the resource of the user. For example, the user 321 can create the access endpoint 2111 and the access endpoint 2112, and correspond the access endpoint 2111 to the resource 2101 and the access endpoint 2112 to the resource 2102. The user 322 can create the access endpoint 221 and correspond the access endpoint 221 to the resource 220. The user 331 can create the access endpoint 231 and correspond the access endpoint 231 to the resource 230.
[0079] In some embodiments, the administrator of the target organization can associate the access control policy A1 to any one or more OUs in the target organization. For example, as shown in FIG. 2, if the access control policy A1 is associated to the OU 320, then the access control policy A1 can act on the access endpoints 2111, 2112, 221, etc. within the OU 320. In this way, the management platform 100 can control the access requests to the resources within the OU 320 based on the access control policy A1.
[0080] In some embodiments, as shown in FIG. 3, the administrator of the target organization can associate the access control policy A1 to one or more users in the target organization, such as the user 321. Then the access control policy A1 can act on the access endpoints 2111, 2112. In this way, the management platform 100 can control the access requests to the resources of the user 321 based on the access control policy A1.
[0081] The above examples introduce the system architecture provided by the embodiments of the present application. Next, the resource access control method provided by the embodiments of the present application is introduced in combination with the system architecture.
[0082] The method can be performed by the management platform 100. The management platform 100 can include a recording module 110, an obtaining module 120, and a control module 130. Through these modules, the management platform 100 can implement the resource access control method provided by the embodiments of the present application. As shown in FIG. 4, the method includes the following steps.
[0083] In step 401, the administrator of the target organization can configure the access control policy A1 and indicate the access endpoints to which the access control policy A1 acts. That is, the administrator of the target organization can configure the access control policy A1 for one or more access endpoints in the target organization.
[0084] In some embodiments, the access control policy A1 can be referred to as a network control policy (NCP), which is used to restrict the connection authority and / or the resource access authority of the access endpoint, so as to control the access requests to the resources corresponding to the access endpoint.
[0085] In some embodiments, the access control policy A1 can contain a domain specific language (DSL) for describing a set of authorities. When the access control policy A1 is associated to an organization node (such as the OU 310), the access control policy A1 can act on all access endpoints within the organization node.
[0086] In some embodiments, as shown in FIG. 5, the policy structure of the access control policy A1 can include a policy version number and a policy permission statement. The policy permission statement can include, for example, an effect, an action, a condition, a resource type, and the like.
[0087] As shown in FIG. 6, the policy version number refers to the version of the policy, for example, 1.1.
[0088] The effect is used to define whether the operation in the action is allowed to be performed. The effect can be divided into allow and deny. When the effect of the same action has both allow and deny, the principle of deny priority is followed.
[0089] The action refers to the operation permission. The format of the action can be "service name: resource type: operation". For example, an action can be represented as "obs: bucket: listallmybuckets", obs is the service name, bucket is the resource type, and listallmybuckets is the operation.
[0090] The condition means that it is the effective condition of the access control policy, including a condition key and an operator. The format of the condition can be "operator: {condition key: [condition key1, condition key2]}". If multiple conditions are set, the access control policy takes effect when the multiple conditions are met at the same time. For example, "stringendwithifexists": {"g:username": ["specialcharacter"]} means that the access control policy takes effect when the username input by the user ends with "specialcharacter".
[0091] The resource type means the resource on which the access control policy acts. The format of the resource type can be "service name: region: domain id: resource type: resource path". The resource type supports wildcard match *. In an example, "obs: *: *: bucket: *" means all obs buckets. The resource on which the access control policy acts is specifically the resource corresponding to the access endpoint on which the access control policy acts or to which the access control policy is directed.
[0092] At step 402, the recording module 110 can record the access control policy Al in response to an indication of an administrator of the target organization, and record the access endpoint to which the access control policy Al is directed, i.e., record which access endpoints (e.g., the access endpoint Cl) the access control policy Al is configured for by the administrator. The access control policy is configured to act on the access endpoint to which the access control policy is directed, to control an access request to a resource corresponding to the access endpoint. The access endpoint to which the access control policy Al is directed is an access endpoint of a user in the target organization.
[0093] In some embodiments, the recording module 110 can associate the access control policy Al with one or more organization nodes in the target organization, and record the association. The access endpoint of a user in the organization node associated with the access control policy Al is the access endpoint to which the access control policy Al is directed. In this way, by recording the association between the access control policy Al and the organization node, the access endpoint to which the access control policy Al is directed is recorded. In one example, the organization node associated with the access control policy Al can be an OU or a user. The OU includes a plurality of users, and the user can be represented by an identifier of the user. In one example, the identifier of the user can be a user account.
[0094] In some embodiments, the recording module 110 can associate the access control policy Al with one or more access endpoints in the target organization, and record the association. The access endpoint associated with the access control policy Al is the access endpoint to which the access control policy Al is directed.
[0095] In some embodiments, the recording module 110 can record the access control policy Al and the access endpoint to which the access control policy Al is directed, into a database.
[0096] At step 403, the obtaining module 120 can obtain an access request Bl issued by a user. The user issuing the access request Bl can be a user outside the target organization, or a user inside the target organization. The access request is used to access a resource in the target organization. For ease of description, the resource to be accessed by the access request can be referred to as the target resource of the access request.
[0097] At step 404, the obtaining module 120 can identify that the access request Bl requests to invoke the access endpoint Cl.
[0098] As described above, the access request needs to be forwarded through the access endpoint corresponding to the target resource of the access request, to reach the target resource and achieve access to the target resource. The access endpoint Cl requested to be invoked by the access request Bl is the access endpoint corresponding to the target resource of the access request Bl, and the access request Bl needs to be forwarded through the access endpoint Cl to reach the target resource.
[0099] In some embodiments, the access request B1 carries an identification of the access endpoint it requests to invoke. In step 404, the obtaining module 120 can obtain the identification of the access endpoint from the access request B1, and identify that the access request B1 requests to invoke the access endpoint C1 based on the identification of the access endpoint.
[0100] In some embodiments, the access request B1 carries an identification of the target resource, and the recording module 110 records an association between the identification of the resource and the identification of the access endpoint corresponding to the resource. In step 404, the obtaining module 120 can obtain the identification of the target resource from the access request B1, obtain the association between the identification of the resource and the identification of the access endpoint corresponding to the resource from the recording module 110, and then identify that the access request B1 requests to invoke the access endpoint C1 based on the identification of the target resource and the association.
[0101] After identifying that the access request B1 requests to invoke the access endpoint C1, the obtaining module 120 can send an authentication request to the control module 130 through step 405. The authentication request includes the identification of the access endpoint C1.
[0102] The control module 130 can authenticate the access request B1 in response to the authentication request. Specifically, the control module 130 can include the following steps.
[0103] In step 406, the control module 130 can obtain the identification of the access endpoint C1 from the authentication request, and send the identification of the access endpoint C1 to the recording module 110. In step 407, the recording module can query the access control policy for the access endpoint C1 based on the identification of the access endpoint C1.
[0104] In some embodiments, as described above, the access control policy is associated with the organization node. In step 407, the organization node to which the access endpoint C1 belongs can be queried. Then, the access control policy associated with the organization node to which the access endpoint C1 belongs is taken as the access control policy for the access endpoint C1.
[0105] For example, when a user in the organization node creates an access endpoint, the created access endpoint can be associated with the organization node, and the association is recorded. The association is specifically an association between the identification of the access endpoint and the identification of the organization node. In step 407, the organization node to which the access endpoint C1 belongs can be queried based on the identification of the access endpoint C1 and the association.
[0106] The recording module 110 also records the association relationship between the access endpoint C1 and the user to which the access endpoint C1 belongs, for example. The association relationship is specifically the association relationship between the identifier of the access endpoint and the identifier of the user. In step 407, the user to which the access endpoint C1 belongs can be queried based on the identifier of the access endpoint C1 and the association relationship. Then, the access control policy associated with the organization node to which the user to which the access endpoint C1 belongs belongs is taken as the organization node to which the access endpoint C1 belongs.
[0107] The access control policy for the access endpoint C1 can be queried through the above steps. The access control policy for the access endpoint C1 can be set as the access control policy A1.
[0108] In step 408, the recording module 110 can send the access control policy A1 to the control module 130. In step 409, the control module 130 can determine whether the access request B1 meets the access control policy A1. The access request B1 can be calculated based on the access control policy A1 to obtain a calculation result, which can indicate whether the access request B1 meets the access control policy A1.
[0109] The access control policy A1 indicates the access permission of the resource accessed through the access endpoint C1. In step 409, it is determined whether the access request B1 has the access permission. If the access request B1 does not have the access permission, it is determined that the access request B1 does not meet the access control policy A1. Otherwise, it is determined that the access request B1 meets the access control policy A1.
[0110] In some embodiments, the access permission indicated by the access control policy A1 is the allowed operation type. If the operation type of the operation to be performed on the resource by the access request B1 belongs to the allowed operation type, it is determined that the access request B1 has the access permission. Otherwise, it is determined that the access request B1 does not have the access permission.
[0111] In some embodiments, the access control policy A1 can indicate the prohibited operation type. If the operation type of the operation to be performed on the resource by the access request B1 does not belong to the prohibited operation type, it is determined that the access request B1 has the access permission. Otherwise, it is determined that the access request B1 does not have the access permission.
[0112] In some embodiments, the access control policy A1 indicates the allowed user. If the user who issues the access request B1 belongs to the allowed user, it is determined that the access request B1 has the access permission. Otherwise, it is determined that the access request B1 does not have the access permission.
[0113] In some embodiments, the access control policy A1 indicates users that are prohibited from accessing. If the user that issues the access request B1 does not belong to the users that are prohibited from accessing, then the access request B1 is confirmed to have the access right. Otherwise, the access request B1 is confirmed to not have the access right.
[0114] In some embodiments, the access control policy A1 indicates the access right of a user within the target organization to access the resource through the access endpoint C1, and the access request B1 is issued by the user within the target organization.
[0115] In one example of this embodiment, the user that issues the access request B1 can be the user that creates the access endpoint C1. The user that creates the access endpoint C1 is also the user that applies for and has the resource corresponding to the access endpoint C1. In this example, the administrator can control the use of the resource of the user by the access control policy, avoiding unreasonable use of the resource.
[0116] In one example of this embodiment, the user that issues the access request B1 can be another user within the target organization, where the another user refers to a user other than the user that creates the access endpoint C1. In this example, the administrator of the organization can control the sharing range of the resource of the organization within the organization by the access control policy, avoiding unreasonable use of the resource.
[0117] In some embodiments, the access control policy A1 indicates the access right of a user outside the target organization to access the resource through the access endpoint C1, and the access request B1 is issued by the user outside the target organization. In this way, the administrator can control the access of the resource of the organization by the user outside the organization by the access control policy, protecting the security of the resource of the organization.
[0118] At step 410, the control module 130 can send the authentication result to the obtaining module 120 based on the result of step 409. When the result of step 409 is that the access request B1 conforms to the access control policy A1, the control module 130 sends an authentication result indicating that the authentication is successful to the obtaining module 120. Otherwise, the control module 130 sends an authentication result indicating that the authentication fails to the obtaining module 120.
[0119] In some embodiments, the user who creates the access endpoint C1 can configure the access control policy A2 for the access endpoint C1, and the recording module 110 can record the access control policy A2. As shown in FIG. 7, before performing the step 409, a step 701 is performed to determine whether the access request B1 meets the access control policy A2. The specific determination manner can refer to the above description, and will not be repeated here. If the determination result of the step 701 is that the access request B1 meets the access control policy A2, the step 409 is performed. If the determination result of the step 701 is that the access request B1 does not meet the access control policy A2, the authentication result indicating the authentication failure is directly sent to the obtaining module 120, and the step 409 does not need to be performed again. That is, in the case that the access request B1 meets the access control policy A1 and the access control policy A2 at the same time, the authentication result indicating the authentication success is obtained.
[0120] With continued reference to FIG. 4, after obtaining the authentication result, the obtaining module 120 can allow or prohibit the access endpoint C1 to forward the access request B1 to the corresponding resource based on the authentication result in the step 411. The corresponding resource here refers to the target resource of the access request B1. When the authentication result indicates the authentication success, the obtaining module 120 allows the access endpoint C1 to forward the access request C1 to the target resource, so that the access request C1 can access the target resource. When the authentication result indicates the authentication failure, the obtaining module 120 prohibits the access endpoint C1 to forward the access request C1 to the target resource, so as to avoid the access request C1 to access the target resource.
[0121] In some embodiments, the obtaining module 120 can also feed back the access result to the user who sends the access request C1. When the access endpoint C1 is allowed to forward the access request C1 to the target resource, the access result indicating the access success can be fed back. When the access endpoint C1 is prohibited to forward the access request C1 to the target resource, the access result indicating the access failure can be fed back.
[0122] In summary, the administrator of the organization can configure the access control policy for the access endpoint, and the access control policy can realize the access control of the organization resource by controlling whether the access endpoint forwards the access request, so that the administrator can control the access to the organization resource, and the unreasonable use of the organization resource, the loss of the organization resource, and the like are avoided.
[0123] Based on the above description, the embodiments of the present application further provide a resource method control method. The method is applied to the management platform 100 described above. The management platform 100 is used to manage a plurality of access endpoints and a plurality of resources of a target organization, wherein the plurality of resources are provided by a plurality of servers in the infrastructure 200, the plurality of servers are arranged in the same data center or a plurality of data centers in the infrastructure, each of the plurality of access endpoints corresponds to at least one resource of the plurality of resources, and the access endpoint is used to forward an access request for the resource corresponding to the access endpoint to the resource. As shown in FIG. 8, the method comprises the following steps.
[0124] In step 801, the management platform 100 records an access control policy A1 configured by an administrator of a target organization for a target access endpoint, the target access endpoint being at least one access endpoint of a plurality of access endpoints of the target organization. Wherein, the target access endpoint can be the access endpoint C1 described above.
[0125] The administrator can configure the access control policy A1 for at least one access endpoint in the target organization, and indicate the access endpoint to which the access control policy A1 corresponds to the management platform 100. In this way, the management platform 100 can record the access control policy A1 and the access endpoint to which the access control policy A1 corresponds. For details, please refer to the above description of steps 401-402 in FIG. 4, which will not be repeated here.
[0126] In step 802, the management platform 100 obtains a target access request for a target resource, the target resource being a resource corresponding to the target access endpoint in the plurality of resources. Wherein, the target access request can be the access request B1 described above.
[0127] A user outside or inside the target organization can initiate an access request for accessing one or more resources of the target organization, which can be referred to as a target resource. The management platform 100 can identify that the access endpoint corresponding to the target resource is a target access endpoint. For details, please refer to the above description of steps 403-404 in FIG. 4, which will not be repeated here.
[0128] In step 803, the management platform 100 allows or prohibits the target access endpoint to forward the target access request to the target resource based on the access control policy A1.
[0129] The management platform 100 records the access control policy for the target access endpoint, i.e., the control policy A1. When the access endpoint corresponding to the target resource is identified as the target access endpoint, the target access request to the target access resource can be controlled based on the access control policy A1. When the target access request conforms to the access control policy A1, the target access endpoint is allowed to forward the target access request to the target resource. When the target access request does not conform to the access control policy A1, the target access endpoint is prohibited from forwarding the target access request to the target resource. For details, refer to the description of steps 405-410 in FIG. 4 above, which will not be repeated here.
[0130] In some embodiments, the target access endpoint is created by a first user in the target organization, and the management platform 100 further records an access control policy A2 configured by the first user for the target access endpoint. The management platform 100 allows or prohibits the target access endpoint to forward the target access request to the target resource based on the access control policy A1, including: the management platform 100 allows or prohibits the target access endpoint to forward the target access request to the target resource based on the access control policy A1 and the access control policy A2.
[0131] The user who creates the target access endpoint can also control access to the user's resources by configuring an access control policy. When the access request conforms to both the user-configured access control policy (i.e., the access control policy A2) and the administrator-configured access control policy (i.e., the access control policy A1), the target access endpoint is allowed to forward the target access request to the target resource. When the access request does not conform to the user-configured access control policy and / or the administrator-configured access control policy, the target access endpoint is prohibited from forwarding the target access request to the target resource. For details, refer to the description of the embodiment shown in FIG. 7 above, which will not be repeated here.
[0132] In some embodiments, the management platform 100 records the access control policy A1 configured by the administrator of the target organization for the target access endpoint, including: the management platform 100 associates the access control policy A1 with an organization node of the target organization, the organization node being an organization unit OU in the target organization or a first user, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user. The management platform 100 allows or prohibits the target access endpoint to forward the target access request to the target resource based on the access control policy A1, including: the management platform 100 confirms that the target access endpoint belongs to the organization node, and allows or prohibits the target access endpoint to forward the target access request to the target resource based on the access control policy A1.
[0133] By associating the access control policy A1 with the organization node, the access control policy A1 can be applied to the corresponding access endpoint simply and quickly without configuring the access control policy for each access endpoint. When performing access control on a resource, the access control policy of the target access endpoint can be quickly queried by confirming the organization node to which the target access endpoint belongs, thereby improving the efficiency of access control.
[0134] In one example of this embodiment, the method further includes recording an association relationship between the identifier of the target access endpoint and the identifier of the first user. The confirming that the target access endpoint belongs to the organization node includes: obtaining the identifier of the target access endpoint from the target access request; and confirming that the target access endpoint belongs to the organization node based on the identifier of the target access endpoint and the association relationship.
[0135] Generally, when an access endpoint is created, the management platform 100 can record the identifier of the access endpoint and the association relationship of the access endpoint. An access request generally includes the identifier of the access endpoint called by the access request. Thus, the identifier of the access endpoint carried by the access request and the association relationship can be used to confirm that the access endpoint is created by the first user, and it can be further confirmed that the access endpoint belongs to the organization node in which the first user is located.
[0136] In some embodiments, the access control policy A1 indicates the permission of a user in the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a first user or a second user in the target organization; the target access endpoint is created by the first user, and the second user is a user in the target organization other than the first user.
[0137] In this embodiment, the administrator of the organization can prevent the users in the organization from using the resources of the organization unreasonably through the access control policy.
[0138] In some embodiments, the access control policy A1 indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a user outside the target organization.
[0139] In this embodiment, the administrator of the organization can prevent the users outside the organization from using the resources of the organization illegally through the access control policy.
[0140] In some embodiments, the target access endpoint is a VPCEP.
[0141] By the method provided in the embodiments of the present application, the access control policy configured by the administrator can control whether the access endpoint forwards the access request, so that the administrator can realize access control of the organization resources through the access control policy, and avoid unreasonable use of the organization resources, loss of the organization resources, and the like.
[0142] Based on the introduction of the method embodiments above, the embodiments of the present application further provide a management platform 900. The management platform 900 is used for managing a plurality of access endpoints and a plurality of resources of a target organization, wherein the plurality of resources are provided by a plurality of servers in an infrastructure, the plurality of servers are arranged in a same data center or a plurality of data centers in the infrastructure, each of the plurality of access endpoints corresponds to at least one resource of the plurality of resources, and the access endpoint is used to forward an access request for the resource corresponding to the access endpoint to the resource. As shown in FIG. 9, the management platform 900 includes:
[0143] a recording module 910, configured to record a first access control policy configured by an administrator of the target organization for a target access endpoint, the target access endpoint being at least one access endpoint of the plurality of access endpoints;
[0144] an obtaining module 920, configured to obtain a target access request for a target resource, the target resource being a resource corresponding to the target access endpoint in the plurality of resources;
[0145] a control module 930, configured to allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy.
[0146] In some embodiments, the target access endpoint is created by a first user in the target organization, and the management platform further records a second access control policy configured by the first user for the target access endpoint; and the control module 930 is configured to allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy and the second access control policy.
[0147] In some embodiments, the recording module 910 is configured to associate, by the management platform, the first access control policy with an organization node of the target organization, the organization node being an organization unit OU in the target organization or the first user, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; and the control module 930 is configured to, in a case where it is confirmed that the target access endpoint belongs to the organization node, allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy.
[0148] In some embodiments, the recording module 910 is further configured to record an association between an identifier of the target access endpoint and an identifier of the first user; and the control module 930 is configured to: obtain the identifier of the target access endpoint from the target access request; and determine that the target access endpoint belongs to the organization node based on the identifier of the target access endpoint and the association.
[0149] In some embodiments, the first access control policy indicates a permission of a user in the target organization to access the target resource via the target access endpoint, and the target access request is initiated by a first user or a second user in the target organization; and the target access endpoint is created by the first user, and the second user is a user in the target organization other than the first user.
[0150] In some embodiments, the first access control policy indicates a permission of a user outside the target organization to access the target resource via the target access endpoint, and the target access request is initiated by a user outside the target organization.
[0151] In some embodiments, the target access endpoint is a virtual private cloud terminal node VPCEP.
[0152] The recording module 910, the obtaining module 920, and the control module 930 can be implemented by software or by hardware. For example, the recording module 910 is taken as an example to introduce the implementation of the recording module 910. Similarly, the implementation of the obtaining module 920 and the control module 930 can refer to the implementation of the recording module 910.
[0153] As an example of a software functional unit, the recording module 910 can include code running on a computing instance. The computing instance can include at least one of a physical host (computing device), a virtual machine, and a container. Further, the computing instance can be one or more. For example, the recording module 910 can include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code can be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code can be distributed in the same availability zone AZ or in different AZs, and each AZ includes one data center or multiple data centers with close geographical locations. Generally, one region can include multiple AZs.
[0154] Likewise, the plurality of hosts / virtual machines / containers used to run the code can be distributed in the same VPC or in multiple VPCs. Among them, usually one VPC is set in one region, and a communication gateway needs to be set in each VPC for cross-region communication between two VPCs in the same region and between VPCs in different regions, and the interconnection between VPCs is realized through the communication gateway.
[0155] As an example of a hardware functional unit, the recording module 910 can include at least one computing device, such as a server, etc. Alternatively, the recording module 910 can also be a device implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), etc. Among them, the above-mentioned PLD can be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0156] The plurality of computing devices included in the recording module 910 can be distributed in the same region or in different regions. The plurality of computing devices included in the recording module 910 can be distributed in the same AZ or in different AZs. Likewise, the plurality of computing devices included in the recording module 910 can be distributed in the same VPC or in multiple VPCs. Among them, the plurality of computing devices can be any combination of servers, ASICs, PLDs, CPLDs, FPGAs, and GALs, etc.
[0157] It should be noted that in other embodiments, the recording module 910 can be used to perform any step of the method shown in FIG. 8, the acquisition module 920 can be used to perform any step of the method shown in FIG. 8, and the control module 930 can be used to perform any step of the method shown in FIG. 8. The steps responsible for the recording module 910, the acquisition module 920, and the control module 930 can be specified as needed, and the entire function of the management platform 900 can be realized by the recording module 910, the acquisition module 920, and the control module 930 respectively implementing different steps of the method shown in FIG. 8.
[0158] The application further provides a computing device 1000. As shown in FIG. 10, the computing device 1000 includes a bus 1002, a processor 1004, a memory 1006, and a communication interface 1008. The processor 1004, the memory 1006, and the communication interface 1008 communicate through the bus 1002. The computing device 1000 can be a server or a terminal device. It should be understood that the number of processors and memories in the computing device 1000 is not limited.
[0159] The bus 1002 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one line is shown in FIG. 10, but it does not mean that there is only one bus or only one type of bus. The bus 1002 can include a path for transmitting information between various components (for example, the memory 1006, the processor 1004, the communication interface 1008) of the computing device 1000.
[0160] The processor 1004 can include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP), etc.
[0161] The memory 1006 can include a volatile memory (for example, a random access memory (RAM)). The memory 1006 can also include a non-volatile memory (for example, a read-only memory (ROM), a flash memory, a mechanical hard disk drive (HDD), or a solid state drive (SSD)).
[0162] The memory 1006 stores executable program code, and the processor 1004 executes the executable program code to respectively implement the functions of the aforementioned recording module 910, the acquisition module 920, and the control module 930, thereby implementing the method shown in FIG. 8. That is, the memory 1006 stores instructions for executing the method shown in FIG. 8.
[0163] The communication interface 1008 enables communication among the computing device 1000 and other devices or communication networks using transceiver modules, such as, but not limited to, network interface cards, transceivers, and the like.
[0164] Embodiments of the present application also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device, such as a desktop computer, a notebook computer, or a smart phone.
[0165] As shown in FIG. 11, the computing device cluster includes at least one computing device 1000. The memory 1006 in one or more computing devices 1000 in the computing device cluster can store the same instructions for performing the method shown in FIG. 8.
[0166] In some possible implementations, the memory 1006 in one or more computing devices 1000 in the computing device cluster can also respectively store partial instructions for performing the method shown in FIG. 8. In other words, the combination of one or more computing devices 1000 can collectively perform the instructions for performing the method shown in FIG. 8.
[0167] It should be noted that the memory 1006 in different computing devices 1000 in the computing device cluster can store different instructions for performing part of the functions of the management platform 900. That is, the instructions stored in the memory 1006 in different computing devices 1000 can implement the functions of one or more of the recording module 910, the obtaining module 920, and the control module 930.
[0168] In some possible implementations, one or more computing devices in the computing device cluster can be connected through a network. The network can be a wide area network, a local area network, or the like. FIG. 12 shows one possible implementation. As shown in FIG. 12, two computing devices 1000A and 1000B are connected through a network. Specifically, the communication interface in each computing device is connected to the network. In this type of possible implementation, the memory 1006 in the computing device 1000A stores instructions for performing the functions of the recording module 910. Meanwhile, the memory 1006 in the computing device 1000B stores instructions for performing the functions of the obtaining module 920 and the control module 930.
[0169] It should be understood that the functions of the computing device 1000A shown in FIG. 12 can also be completed by multiple computing devices 1000. Similarly, the functions of the computing device 1000B can also be completed by multiple computing devices 1000.
[0170] The embodiment of the present application further provides another computing device cluster. The connection relationship between the computing devices in the computing device cluster can be similar to the connection mode of the computing device cluster described with reference to FIG. 11 and FIG. 12. The difference is that the same instruction for executing the method shown in FIG. 8 can be stored in the memory 1006 of one or more computing devices 1000 in the computing device cluster.
[0171] In some possible implementation manners, part of the instruction for executing the method shown in FIG. 8 can also be stored in the memory 1006 of one or more computing devices 1000 in the computing device cluster respectively. In other words, the combination of one or more computing devices 1000 can collectively execute the instruction for executing the method shown in FIG. 8.
[0172] The embodiment of the present application further provides a computer program product containing instructions. The computer program product can be a software or program product containing instructions, which can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, the at least one computing device is caused to execute the method shown in FIG. 8.
[0173] The embodiment of the present application further provides a computer readable storage medium. The computer readable storage medium can be any available medium that a computing device can store or a host migration device such as a data center containing one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid state disk) and the like. The computer readable storage medium contains instructions, which instruct the computing device to execute the method shown in FIG. 8.
[0174] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present application, but not to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand: it can still modify the technical solutions recorded in the foregoing embodiments, or make equivalent replacement to part of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the protection scope of the technical solutions of the embodiments of the present application.
Claims
1. A resource access control method characterized by, The method is applied to a management platform for managing a plurality of access endpoints and a plurality of resources of a target organization, wherein the plurality of resources are provided by a plurality of servers in an infrastructure, the plurality of servers are arranged in the same data center or a plurality of data centers in the infrastructure, each of the plurality of access endpoints corresponds to at least one of the plurality of resources, and the access endpoint is used to forward an access request for the resource corresponding to the access endpoint to the resource; the method comprises: The management platform records a first access control policy configured by an administrator of the target organization for a target access endpoint, and the target access endpoint is at least one of the plurality of access endpoints; The management platform obtains a target access request for a target resource, and the target resource is a resource corresponding to the target access endpoint in the plurality of resources; The management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy.
2. The method of claim 1, wherein, The target access endpoint is created by a first user in the target organization, and the management platform also records a second access control policy configured by the first user for the target access endpoint; The management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy, comprising: the management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy and the second access control policy.
3. The method of claim 1 or 2, wherein The management platform records a first access control policy configured by an administrator of the target organization for a target access endpoint, comprising: the management platform associates the first access control policy with an organization node of the target organization, the organization node is an organization unit OU or a first user in the target organization, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; The management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy, comprising: the management platform allows or prohibits the target access endpoint from forwarding the target access request to the target resource based on the first access control policy under the condition that the target access endpoint belongs to the organization node.
4. The method of claim 3, wherein The method further comprises: recording an association relationship between an identifier of the target access endpoint and an identifier of the first user; The confirmation that the target access endpoint belongs to the organization node comprises: Obtaining the identifier of the target access endpoint from the target access request; Based on the identifier of the target access endpoint and the association relationship, it is confirmed that the target access endpoint belongs to the organization node.
5. The method of any one of claims 1-4, wherein The first access control policy indicates a permission of a user in the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a first user or a second user in the target organization; the target access endpoint is created by the first user, and the second user is a user in the target organization other than the first user; Or, The first access control policy indicates a permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a user outside the target organization.
6. The method according to any one of claims 1-5, characterized in that, The target access endpoint is a virtual private cloud terminal node VPCEP.
7. A management platform, characterized by The management platform is configured to manage a plurality of access endpoints and a plurality of resources of a target organization, wherein the plurality of resources are provided by a plurality of servers in an infrastructure, the plurality of servers are arranged in a same data center or a plurality of data centers in the infrastructure, each of the plurality of access endpoints corresponds to at least one of the plurality of resources, and the access endpoint is configured to forward an access request for the resource corresponding to the access endpoint to the resource; the management platform comprises: A recording module configured to record a first access control policy configured by an administrator of the target organization for a target access endpoint, the target access endpoint being at least one of the plurality of access endpoints; An obtaining module configured to obtain a target access request for a target resource, the target resource being a resource corresponding to the target access endpoint in the plurality of resources; A control module configured to allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy.
8. The management platform of claim 7, wherein, The target access endpoint is created by a first user in the target organization, and the management platform further records a second access control policy configured by the first user for the target access endpoint; The control module is configured to allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy and the second access control policy.
9. The management platform of claim 7 or 8, wherein: The recording module is configured to associate the first access control policy with an organization node of the target organization, the organization node being an organization unit OU in the target organization or a first user, wherein the OU includes at least one user including the first user, and the target access endpoint is created by the first user; The control module is configured to, based on a confirmation that the target access endpoint belongs to the organization node, allow or prohibit the target access endpoint to forward the target access request to the target resource based on the first access control policy.
10. The management platform of claim 9, wherein: The recording module is further configured to record an association relationship between an identifier of the target access endpoint and an identifier of the first user; The control module is configured to: Obtain the identifier of the target access endpoint from the target access request; Based on the identification of the target access endpoint and the association relationship, it is confirmed that the target access endpoint belongs to the organization node. 11.The management platform of any one of claims 7-10, characterized in that, the first access control policy indicates the permission of a user in the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a first user or a second user in the target organization; wherein the target access endpoint is created by the first user, and the second user is a user in the target organization other than the first user; or, the first access control policy indicates the permission of a user outside the target organization to access the target resource through the target access endpoint, and the target access request is initiated by a user outside the target organization.
12. The management platform of any one of claims 7-11, wherein, The target access endpoint is a virtual private cloud terminal node VPCEP.
13. A cluster of computing devices, characterized in that, comprise at least one computing device, each computing device comprising a processor and a memory; the processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the cluster of computing devices to perform the method of any one of claims 1-6.
14. A computer-readable storage medium, characterized in that, comprise computer program instructions which, when executed by a cluster of computing devices, cause the cluster of computing devices to perform the method of any one of claims 1-6.
15. A computer program product comprising instructions, characterized in that, when the instructions are executed by a cluster of computing devices, cause the cluster of computing devices to perform the method of any one of claims 1-6.
Citation Information
Patent Citations
Use of freeform metadata for access control
CN104995598A
API access control method, apparatus and device, and medium
CN112035858A
Trust area security protection method and device
CN112351022A
Access request processing method, container cloud platform, electronic equipment and storage medium
CN113672901A
Cloud resource access control method based on cloud computing technology and cloud management platform
CN117640125A