Access permission suggestion method and apparatus based on cloud computing technology

WO2026201134A1PCT designated stage Publication Date: 2026-10-01HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2026/086521
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2025-03-28
Filing Date
2026-03-27
Publication Date
2026-10-01

Smart Images

  • Figure CN2026086521_01102026_PF_FP_ABST
    Figure CN2026086521_01102026_PF_FP_ABST
Patent Text Reader

Abstract

Disclosed in the embodiments of the present application are an access permission suggestion method and apparatus based on cloud computing technology, which method and apparatus are used for improving the accuracy of an access permission analysis system in analyzing over-authorized content. The method in the embodiments of the present application comprises: a cloud management platform determining an access control policy of a tenant account on the basis of an input of a tenant; the cloud management platform acquiring a cloud service access record of the tenant account, wherein the cloud service access record comprises context attributes of one or more analysis objects associated with the tenant account; the cloud management platform analyzing the context attributes in the cloud service access record on the basis of a permission restriction policy, so as to determine a target attribute, wherein the permission restriction policy is used for indicating one or more restriction rules for the context attributes; and the cloud management platform generating a permission analysis result on the basis of the target attribute, and providing the permission analysis result to the tenant, wherein the permission analysis result is used for indicating over-authorized content of the access control policy and a permission restriction suggestion generated on the basis of the over-authorized content.
Need to check novelty before this filing date? Find Prior Art

Description

A method and apparatus for granting access permissions based on cloud computing technology

[0001] This application claims priority to Chinese patent application filed on March 28, 2025, with application number 202510397798.6 and entitled "A Method and Apparatus for Proposing Access Permissions Based on Cloud Computing Technology", the entire contents of which are incorporated herein by reference. Technical Field

[0002] This application relates to the field of computers, and more particularly to an access permission suggestion method and apparatus based on cloud computing technology. Background Technology

[0003] With the rapid development of cloud computing technology, mainstream cloud service providers have proposed attribute-based access control (ABAC) schemes for access management. In this scheme, the system can control access permissions based on different attributes, making access management more flexible. However, in real-world user scenarios, due to personnel changes, failure to promptly revoke granted temporary permissions, and other reasons, over-authorization often occurs over time. Over-authorization may lead to security risks and compliance challenges.

[0004] To mitigate the risk of over-authorization in access control, many cloud service providers offer access permission analysis services. These services analyze and optimize access control policies, identifying and removing unused permissions. Current access permission analysis solutions can perform unused analysis on identities and their associated permissions within Identity and Access Management (IAM) services, guiding users to clean up unused identities and permissions.

[0005] However, current access control analysis services can only effectively identify completely unused authorization items and judge them as over-authorized. For authorization items with usage records, the access control analysis system cannot further determine whether the access permissions are over-authorized, resulting in low accuracy of the access control analysis system in analyzing over-authorization. Summary of the Invention

[0006] This application provides an access permission suggestion method based on cloud computing technology to improve the accuracy and granularity of over-authorization analysis of access control policies. This application also provides a cloud-based access permission suggestion device, computing device, computing device cluster, computer-readable storage medium, and computer program product corresponding to this cloud-based access permission suggestion method.

[0007] In a first aspect, embodiments of this application provide an access permission suggestion method based on cloud computing technology. This method is applied to a cloud management platform, which manages infrastructure providing various cloud services, including multiple data centers. The method includes: the cloud management platform determining an access control policy for a tenant account based on tenant input, where the tenant account is an account registered with the cloud management platform, and the tenant accesses at least one cloud service of the infrastructure through the tenant account under the restrictions of the access control policy. The cloud management platform obtains cloud service access records for the tenant account. These records include contextual attributes associated with one or more analysis objects related to the tenant account. The contextual attributes include one or more of the following: subject attributes, object attributes, and environment attributes. The subject attributes include the tenant account, the object attributes include cloud services accessed by the tenant account, and the environment attributes include IP address ranges involved in the cloud services. The cloud management platform analyzes the contextual attributes in the cloud service access records based on the access restriction policy to determine target attributes. The target attributes include contextual attributes in the access records that conform to the access restriction policy. The access restriction policy indicates one or more restriction rules for the contextual attributes. The cloud management platform generates permission analysis results based on target attributes and provides these results to tenants. The permission analysis results are used to indicate over-authorized content in access control policies and to generate permission restriction suggestions based on over-authorized content.

[0008] In this embodiment, the cloud management platform can perform permission analysis and provide permission restriction suggestions based on the context attributes in the cloud service access records of tenant accounts. This allows it to identify authorized items among already used permissions that can be subject to additional restrictions, thereby minimizing the scope of permissions. Compared to existing permission analysis systems that only analyze unused permissions under access control policies, the access permission suggestion method based on cloud computing technology provided in this embodiment can more precisely identify over-authorized content for some already used permissions and provide permission restriction suggestions based on the context attributes in the access records. This improves the accuracy and precision of the analysis of over-authorization in access control policies.

[0009] In one possible implementation, the subject attributes include, for example, the user's identity identifier, the organization identifier of the department to which the user belongs, the user's job title identifier, and the user's age identifier. The object attributes include, for example, the cloud service identifier and the resource identifier bound to the cloud service. The environmental attributes include, for example, the source IP range of the access request, the timestamp of the access request, and the geographical location of the access request.

[0010] In this embodiment, the cloud management platform can analyze various types of contextual attributes in the access records, thereby enabling it to discover over-authorization content in access control policies from different attribute dimensions and improving the granularity of over-authorization analysis.

[0011] In one possible implementation, during the analysis of contextual attributes in cloud service access records based on permission restriction policies, the cloud management platform checks the cloud service access records based on one or more permission restriction rules in the permission restriction policy. When the analysis object associated with the tenant account in the cloud service access record conforms to the permission restriction rule, the cloud management platform determines the target attribute based on the contextual attributes corresponding to the permission restriction rule. Here, the one or more permission restriction rules in the permission restriction policy are permission restriction rules summarized from historical practical experience. "The analysis object associated with the tenant account in the cloud service access record conforming to the permission restriction rule" means that all records in the cloud service access record conform to a certain permission restriction rule in the permission restriction policy.

[0012] In this embodiment, the cloud management platform can match the contextual attributes in the access records based on preset permission restriction rules. If the cloud service access record meets the permission restriction rules, the cloud management platform can determine the target attribute based on the content of the permission restriction rules and impose permission restrictions based on the target attribute, thereby improving the feasibility of the cloud management platform in this embodiment to discover the target attribute.

[0013] In one possible implementation, the permission restriction rules include restricting unused permissions from the same organization based on the sub-organization identifier. When the cloud management platform determines the target attribute based on the context attribute corresponding to the permission restriction rule, if multiple tenant accounts in the access record come from the same sub-organization of the same organization, that is, the access record conforms to the permission restriction rule, then the sub-organization identifier to which the multiple tenant accounts belong is determined as the target attribute.

[0014] In this embodiment, the cloud management platform can analyze the contextual attributes in the access records based on the permission restriction rules related to the sub-organization identifier, thereby determining the target attribute that needs to be restricted as the user's organization, which improves the feasibility of the cloud management platform in generating permission analysis results.

[0015] In one possible implementation, during the process of generating permission analysis results based on target attributes, the cloud management platform generates permission analysis results based on sub-organization identifiers. The permission analysis results indicate that the access control policy should be modified from restricting access by organization identifier to restricting access by sub-organization identifiers under the organization path, that is, only allowing user accounts of the specified sub-organization to access.

[0016] In this embodiment, the cloud management platform can modify the access control policy that restricts access based on the organization identifier to restrict access based on the sub-organization identifier under the organization path, thereby reducing the over-authorization of the organization to which the user account belongs in the access control policy.

[0017] In one possible implementation, the permission restriction rule also includes restricting access to other cloud services based on resource identifiers. When the cloud management platform determines the target attribute based on the context attribute corresponding to the permission restriction rule, if multiple access targets in the access record are cloud services with the same resource identifier, that is, the access record conforms to the permission restriction rule, the cloud management platform determines the resource identifiers corresponding to the multiple access targets as the target attribute.

[0018] In this embodiment, the cloud management platform can analyze the contextual attributes in the access records based on the permission restriction rules related to the resource identifier, thereby determining the target attribute that needs to be restricted as the resource identifier of the access target, which improves the feasibility of the cloud management platform in generating permission analysis results.

[0019] In one possible implementation, during the process of generating permission analysis results based on target attributes, the cloud management platform generates permission analysis results based on resource identifiers. The permission analysis results indicate that access control policies should restrict access to cloud services that match the resource identifiers, that is, allow users to access cloud services with specified resource identifiers only.

[0020] In this embodiment, the cloud management platform can add a restriction to the access control policy based on the resource identifier of the target cloud service, limiting access to cloud services that only match the resource identifier, thereby reducing the over-authorization of access to the target cloud service in the access policy.

[0021] In one possible implementation, the permission restriction rules also include restricting the access permissions of other users based on network protocol IP address ranges. When the cloud management platform determines the target attribute based on the context attribute corresponding to the permission restriction rule, if multiple users in the access record come from the same IP address range, that is, the access record conforms to the permission restriction rule, then the cloud management platform determines the IP address range corresponding to the multiple users as the target attribute.

[0022] In this embodiment, the cloud management platform can analyze the contextual attributes in the access records based on the permission restriction rules related to the user's IP segment, thereby determining that the target attribute for permission restriction is the user's IP address, which improves the feasibility of the cloud management platform in generating permission analysis results.

[0023] In one possible implementation, during the process of generating permission analysis results based on target attributes, the cloud management platform generates permission analysis results based on IP address ranges. The permission analysis results indicate that access control policies should restrict access to only users from specified IP address ranges, and allow access only from users from specified IP address ranges.

[0024] In this embodiment, the cloud management platform can add a restriction to the access control policy that only allows users of a specified IP address range to access the target cloud service based on the IP address range to which the target user belongs, thereby reducing the over-authorization of access to the target cloud service in the access policy.

[0025] In one possible implementation, after the cloud management platform generates permission analysis results for the target attributes, the cloud management platform modifies the access control policy based on the permission analysis results. Specifically, the cloud management platform can perform one or more of the following operations on the access control policy based on the permission analysis results: adding or modifying authorization field, adding or modifying condition field, and adding or modifying resource field.

[0026] In this embodiment, the cloud management platform can modify the access control policy based on the permission analysis results, thereby optimizing the permission scope in the access control policy and reducing the over-authorization content in the access control policy.

[0027] Secondly, embodiments of this application provide an access permission suggestion device based on cloud computing technology. This device includes an acquisition unit and a processing unit. The acquisition unit determines the access control policy for a tenant account based on tenant input. The tenant account is an account registered by the tenant on a cloud management platform. The tenant accesses at least one cloud service of the infrastructure through the tenant account under the restrictions of the access control policy. The acquisition unit also acquires cloud service access records for the tenant account. These access records include context attributes associated with one or more analysis objects associated with the tenant account. The context attributes include one or more of the following: subject attributes, object attributes, and environment attributes. The subject attributes include the tenant account; the object attributes include cloud services accessed by the tenant account; and the environment attributes include IP address ranges involved in the cloud services. The processing unit analyzes the context attributes in the cloud service access records based on the access restriction policy to determine target attributes. The target attributes include context attributes in the access records that conform to the access restriction policy. The access restriction policy indicates one or more restriction rules for the context attributes. The processing unit also generates access control analysis results based on the target attributes and provides these results to the tenant. The access control analysis results indicate over-authorization content of the access control policy and access restriction suggestions generated based on the over-authorization content.

[0028] In one possible implementation, the processing unit is specifically used to check the cloud service access record based on one or more permission restriction rules in the permission restriction policy. When the analysis object associated with the tenant account in the cloud service access record meets the permission restriction rule, the target attribute is determined based on the context attribute corresponding to the permission restriction rule.

[0029] In one possible implementation, the permission restriction rules include restricting unused permissions from the same organization based on the sub-organization identifier. Specifically, when multiple tenant accounts in the access records come from the same sub-organization of the same organization, the processing unit determines the sub-organization identifier to which the multiple tenant accounts belong as the target attribute.

[0030] In one possible implementation, the processing unit is specifically used to generate permission analysis results based on the sub-organization identifier. The permission analysis results indicate that the access control policy should be modified from restricting access by organization identifier to restricting access by sub-organization identifier under the organization path.

[0031] In one possible implementation, the permission restriction rule also includes restricting access to other cloud services based on resource identifiers. Specifically, when multiple access targets in the access record are cloud services with the same resource identifier, the processing unit determines the resource identifiers corresponding to the multiple access targets as target attributes.

[0032] In one possible implementation, the processing unit is specifically used to generate permission analysis results based on resource identifiers, and the permission analysis results indicate that access to cloud services that match the resource identifiers should be restricted in the access control policy.

[0033] In one possible implementation, the permission restriction rules also include restricting the access permissions of other users based on network protocol IP address ranges. Specifically, when multiple users in the access records come from the same IP address range, the processing unit determines the IP address ranges corresponding to the multiple users as the target attribute.

[0034] In one possible implementation, the processing unit is specifically used to generate permission analysis results based on IP address ranges, and the permission analysis results indicate that access control policies should restrict access to only users within specified IP address ranges.

[0035] In one possible implementation, the processing unit is further configured to perform one or more of the following operations on the access control policy based on the permission analysis results: adding or modifying the authorization field, adding or modifying the condition field, and adding or modifying the resource field.

[0036] Thirdly, embodiments of this application provide a computing device including a processor coupled to a memory. The processor stores instructions, which, when executed by the processor, cause the computing device to perform the method described in the first aspect or any possible implementation thereof.

[0037] Fourthly, embodiments of this application provide a computing device cluster, which includes one or more computing devices. Each computing device includes a processor coupled to a memory. The processor is used to store instructions, which, when executed by the processor, cause the computing device cluster to perform the method described in the first aspect or any possible implementation thereof.

[0038] Fifthly, embodiments of this application provide a computer-readable storage medium having instructions stored thereon, which, when executed, cause a computer to perform the method described in the first aspect or any possible implementation thereof.

[0039] Sixthly, embodiments of this application provide a computer program product including instructions that, when executed, cause a computer to implement the method described in the first aspect or any possible implementation thereof.

[0040] It is understood that the beneficial effects achieved by any of the above-mentioned cloud computing-based access permission suggestion devices, computing devices, computing device clusters, computer-readable media, or computer program products can be referred to the beneficial effects in the corresponding methods, and will not be repeated here. Attached Figure Description

[0041] Figure 1 is a schematic diagram of the system architecture of an access control analysis system provided in an embodiment of this application;

[0042] Figure 2 is a flowchart illustrating an access permission suggestion method based on cloud computing technology provided in an embodiment of this application;

[0043] Figure 3 is a schematic diagram of an access permission analysis process provided in an embodiment of this application;

[0044] Figure 4 is a schematic diagram of an access control policy optimization based on subject attributes provided in an embodiment of this application;

[0045] Figure 5 is a schematic diagram of an access control policy optimization based on object attributes provided in an embodiment of this application;

[0046] Figure 6 is a schematic diagram of an access control policy optimization based on environmental attributes provided in an embodiment of this application;

[0047] Figure 7 is a schematic diagram of an access permission suggestion device based on cloud computing technology provided in an embodiment of this application;

[0048] Figure 8 is a schematic diagram of the structure of a computing device provided in an embodiment of this application;

[0049] Figure 9 is a schematic diagram of the structure of a computing device cluster provided in an embodiment of this application;

[0050] Figure 10 is a schematic diagram of another computing device cluster provided in an embodiment of this application. Detailed Implementation

[0051] This application provides an access permission suggestion method and apparatus based on cloud computing technology, which improves the accuracy and granularity of over-authorization analysis of the current access control policy.

[0052] The terms “first,” “second,” “third,” “fourth,” etc. (if present) in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments described herein can be implemented in a sequence other than that illustrated or described herein. Furthermore, the terms “comprising” and “having,” and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0053] In the embodiments of this application, the terms "exemplary" or "for example" are used to indicate that something is an example, illustration, or description. Any embodiment or design that is described as "exemplary" or "for example" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design. Specifically, the use of the terms "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0054] First, some of the terms used in the embodiments of this application are introduced to facilitate understanding of the technical solutions by those skilled in the art.

[0055] Attribute-based access control (ABAC) is a dynamic access control mechanism. An ABAC system can control user access to resources based on multiple attributes, including user attributes, resource attributes, and environment attributes. For example, when a user attempts to access a resource, the ABAC system checks the relevant attributes and policies; if the attributes meet the policy conditions, access is granted.

[0056] Identity and access management (IAM) service is a centralized identity and access management service used to manage security operations such as user authentication, authorization, and auditing within the system. IAM service can support one or more access control mechanisms.

[0057] Key Management Service (KMS) is a cloud service for securely creating, storing, managing, and rotating encryption keys. KMS provides fundamental support for core data encryption scenarios, ensuring key security while simplifying the complexity of encryption operations.

[0058] Unused permission analysis refers to the system's identification and analysis of whether there are authorized permissions that are not being used. Unused permission analysis can be used to solve the problem of over-authorization in access control policies, ensuring that access management adheres to the principle of least privilege as much as possible.

[0059] An Identity and Access Control Analyzer (IAA) is a tool used to analyze resource access permissions in a cloud environment. It helps identify potential risks associated with access control policies such as over-authorization and external exposure, ensuring adherence to the principle of least privilege and reducing security vulnerabilities caused by excessive permission granting or misconfiguration. The IAM analyzer can also be used for analyzing unused permissions.

[0060] To make the technical solution of this application clearer and easier to understand, the system architecture of this application will be described below with reference to the accompanying drawings.

[0061] Please refer to Figure 1, which is a schematic diagram of the system architecture of an access control analysis system provided in an embodiment of this application. In the example shown in Figure 1, the access control analysis system 10 includes a user device 101, a cloud management platform 102, and a cloud service infrastructure 103. The specific functions of each part of the access control analysis system 10 are described below. The user device 101 is a terminal device directly operated by the user, also known as a tenant. Terminal devices include mobile phones, personal computers, IoT devices, and enterprise servers. The user device 101 can access cloud services in the cloud service infrastructure 103, such as virtual machine services, elastic cloud computing services, and cloud storage services.

[0062] Applications can run on user device 101. Users can manage access control policies in cloud management platform 102 through these applications and initiate permission restriction analyses and recommendations for the current access control policies. User device 101 can send permission analysis requests to cloud management platform 102. Cloud management platform 102 generates corresponding permission analysis results based on these requests. The permission analysis results include over-authorization content of the current access control policy and permission restriction recommendations generated based on the over-authorization content.

[0063] The cloud management platform 102 is a control center connecting the user device 101 and the cloud service infrastructure 103. It is used to uniformly manage various cloud services within the cloud service infrastructure 103. The management functions of the cloud management platform 102 include cloud service aggregation, access control policy enforcement, automated operation and maintenance, and cloud service monitoring and analysis. In this embodiment, the cloud management platform 102 also provides access permission analysis services. These services include analyzing potential over-authorization in the current access control policy and providing suggestions for modifying the current access control policy. Specifically, the cloud management platform 102 can provide permission restriction suggestions for the current access control policy based on the contextual attributes of the analyzed object. These permission restriction suggestions can limit some over-authorized permissions in the current access control policy.

[0064] The cloud management platform 102 can store permission restriction policies, which include one or more preset permission restriction rules. These permission restriction rules can be based on the historical practice of permission restriction. Different permission restriction rules will involve different context attributes. The cloud management platform 102 can analyze the access records of objects according to different permission restriction rules and select appropriate permission restriction rules to generate permission analysis results.

[0065] The cloud management platform 102 can also analyze the access records and current prevention and control policies of the analyzed objects to obtain permission analysis results. Specifically, the cloud management platform 102 can match corresponding permission restriction rules and generate restriction suggestions for the current access control policy based on the matched permission restriction rules. For example, if the cloud management platform 102 determines that the context attributes of the analyzed objects in the access records all conform to a certain permission restriction rule in the permission restriction policy, then the cloud management platform 102 determines the target attribute based on the attribute corresponding to that permission restriction rule and generates permission restriction suggestions as the permission analysis result based on the target attribute.

[0066] Cloud service infrastructure 103 provides the hardware and virtualization capabilities for cloud services. Cloud service infrastructure 103 includes multiple data centers, which constitute a cloud resource pool upon which various cloud services depend. The cloud resources in the cloud resource pool include computing resources, storage resources, and network resources. Multiple cloud services can be deployed in data centers in different regions or on different cloud servers within the same data center. A single cloud service can be deployed in data centers in different regions or on different cloud servers within the same data center; the specific deployment method is not limited.

[0067] It should be noted that the access permission analysis service in the above embodiments is a function provided by the cloud management platform 102. However, in some other possible embodiments of this application, the access permission analysis service may also be a native cloud service in the cloud service infrastructure 103, and there is no specific limitation. When the access permission analysis service is a native cloud service in the cloud service infrastructure 103, the cloud service management platform 102 may also provide the access permission analysis service based on the native cloud service.

[0068] In addition, since the user device 101, cloud management platform 102 and cloud service infrastructure 103 in the access permission analysis system 10 can all be deployed on computing devices or computing device clusters, the various modules in the access permission analysis system 10 can also be referred to as computing devices or computing device clusters in this embodiment.

[0069] Based on the access permission analysis system 10 shown in Figure 1, this application also provides an access permission suggestion method based on cloud computing technology. The following describes the access permission suggestion method based on cloud computing technology provided by the embodiments of this application.

[0070] Please refer to Figure 2, which is a flowchart illustrating an access permission suggestion method based on cloud computing technology provided in an embodiment of this application.

[0071] In the example shown in Figure 2, the method includes the following steps:

[0072] 201. The cloud management platform determines the access control policy for the tenant account based on the tenant's input, where the tenant account is the account registered by the tenant on the cloud management platform.

[0073] The cloud management platform 102 determines the access control policy for the tenant account based on the tenant's input. The tenant account is the account registered with the cloud management platform. The tenant accesses at least one cloud service of the infrastructure through this tenant account, subject to the restrictions of the access control policy. This access control policy is the current access control policy used by the cloud management platform 102 to control the tenant's access. The access control policy determined by the cloud management platform 102 is the access control policy for which the cloud management platform 102 needs to perform access permission analysis. The cloud management platform 102 can analyze the access permissions contained in this access control policy to identify over-authorization content within the access control policy.

[0074] For example, cloud management platform 102 determines an access control policy for a tenant account based on tenant input, which allows only tenant accounts in organization 1 to access cloud service 1. Under this access control policy, all users in organization 1 can access cloud service 1. However, this access control policy may contain over-authorization. Users can use the access permission analysis service provided by cloud management platform 102 to analyze the over-authorization content in this access control policy, so that the access control policy achieves minimal authorization.

[0075] 202. The cloud management platform obtains the cloud service access records of the tenant account. The cloud service access records include one or more context attributes of the analysis object associated with the tenant account.

[0076] In this embodiment, the cloud management platform 102 can provide access permission analysis services. These services can identify and analyze potentially over-authorized content in the current access control policy, restricting unused permissions within the policy. Furthermore, in the access permission suggestion method based on cloud computing technology provided in this embodiment, the cloud management platform 102 can also utilize contextual attributes in cloud service access records to analyze used permissions in the current access control policy from multiple dimensions. This analysis can uncover potential over-authorized content from the used permissions, providing more refined identification and analysis results for over-authorization. The details are as follows:

[0077] Before performing permission analysis, the cloud management platform 102 must first determine the object of analysis. The object is the tenant account to be analyzed and its corresponding cloud service permissions. The object is bound to a corresponding access control policy, which is the current access control policy and indicates the scope of access permissions for that user identity. It is understandable that the cloud management platform 102 can obtain the access control policy bound to the object of analysis through identity authentication and access control (IAM) services.

[0078] After determining the object of analysis, the cloud management platform 102 obtains the cloud service access records of the object of analysis. The access records include the permission records used by one or more objects of analysis when accessing the cloud services. The access records also include the context attributes of one or more objects of analysis. These context attributes can indicate the access characteristics of the objects of analysis. For example, the cloud management platform 102 can analyze the organizational characteristics of the access subject based on the organizational identifier of multiple tenant accounts in the access records, that is, analyze whether multiple tenant accounts come from the same organization.

[0079] In other words, the contextual attributes in the access records in this application embodiment can serve as an analytical perspective for the cloud management platform 102 to analyze whether there is over-authorization in the current access control policy. Contextual attributes can also be called contextual information or access-related attributes. For example, the contextual attributes in the access records include the user's identity identifier, the organization identifier of the department to which the user's identity belongs, and the timestamp of the access request.

[0080] In one possible implementation, the context attributes include one or more of the following: subject attributes, object attributes, and environment attributes. Subject attributes include attributes related to the tenant account, which can indicate the user's identity. Examples of subject attributes include the user's identity identifier, the organization identifier of the department to which the user's identity belongs, the user's job title identifier, and the user's age identifier. Object attributes include attributes related to the cloud services accessed by the tenant account. Examples of object attributes include the cloud service identifier and the resource identifier bound to the cloud service. Environment attributes are used to include attributes related to the access environment, such as the IP address range involved in the cloud service. Examples of environment attributes include the IP address range to which the access request belongs, the timestamp of the access request, and the geographical location of the access request.

[0081] It should be noted that, in this embodiment of the application, the access records obtained by the cloud management platform 102 can be access records within a specified tracking period. For example, the cloud management platform 102 obtains access records of the analysis object from the most recent 3 months, the most recent 6 months, or the most recent 12 months.

[0082] Please refer to Figure 3, which is a schematic diagram of an access permission analysis process provided in an embodiment of this application. In the example shown in Figure 3, the cloud management platform 102 obtains the access records of the analysis object within the tracking period. The analysis object is, for example, user identity 1 to user identity n. The access record contains the permission usage of user identity 1 to user identity n during the access process and the context attributes during the access process. The permission usage during the access process includes, for example, the permissions used by user identity 1 and the corresponding access control policy. The context attributes during the access process include information such as the subject attributes, object attributes, and environmental attributes related to the access of the analysis object.

[0083] In the example shown in Figure 3, the cloud management platform 102 can also obtain the access control policy bound to the analysis object from the IAM service, i.e. the current access control policy. The cloud management platform 102 can analyze these current access control policies in combination with the context attributes in the access records, and increase the restriction of unused permissions in the access control policy from different perspectives based on different context attributes, thereby reducing the problem of over-authorization.

[0084] 203. The cloud management platform analyzes the context attributes in the cloud service access records based on the permission restriction policy to determine the target attributes. The target attributes include the context attributes in the access records that conform to the permission restriction policy. The permission restriction policy is used to indicate one or more restriction rules on the context attributes.

[0085] After the cloud management platform 102 obtains the access records of the object to be analyzed, it analyzes the contextual attributes in the access records based on the permission restriction policy to determine the target attributes. The target attributes include the contextual attributes in the access records that conform to the permission restriction policy. That is, the target attributes can indicate the analysis angle for over-authorization analysis. The cloud management platform 102 can select specific permission restriction policies according to the target attributes. The permission restriction policy is used to indicate one or more restriction rules on the context attributes.

[0086] The permission restriction policy in this embodiment is a preset permission restriction policy based on historical practice of over-authorization analysis. One or more permission restriction rules in the permission restriction policy are permission restriction rules summarized based on historical practice experience. That is, in the historical practice of solving the problem of over-authorization of access control policies, users can summarize some permission restriction rules based on context attributes and store these permission restriction rules in the cloud management platform 102. The cloud management platform 102 can analyze access records based on these permission restriction rules and select the permission restriction rules that can be applied.

[0087] For example, one access control rule in a policy might restrict unused permissions from users within the same organization based on the sub-organization identifier to which the user belongs, meaning only users from the specified sub-organization are allowed access. This rule can restrict access control policies that are intended for users within the organization to users within a specific sub-organization. This access control rule is an example of a sub-organization identifier-based access control rule, and it can be an access control rule determined based on historical practices.

[0088] For example, another permission restriction rule in the permission restriction policy is to restrict access to other cloud services based on the cloud service identifier, or to restrict access to other cloud services based on the resource identifier bound to the cloud service. That is, under this permission restriction rule, only users are allowed to access cloud services with a specified cloud service identifier or a specified resource identifier. This permission restriction rule is a permission restriction rule based on cloud service identifier or resource identifier.

[0089] For example, another access restriction rule in a permission restriction policy might restrict other users' access rights based on the network protocol IP address of the access request, or based on the timestamp of the access request. That is, under this permission restriction rule, only users from a specified IP address range are allowed access, or only users from a specified time period are allowed access. This permission restriction rule is an IP address range or time period-based permission restriction rule.

[0090] In one possible implementation, during the process of cloud management platform 102 analyzing the contextual attributes in access records based on permission restriction policies, cloud management platform 102 checks access records based on one or more permission restriction rules in the permission restriction policies. When the analysis object in the access record meets the permission restriction rules, cloud management platform 102 determines the target attribute based on the contextual attributes corresponding to the permission restriction rules.

[0091] Among them, the analysis object in the access record conforms to the permission restriction rule, which means that all records in the access record conform to a certain permission restriction rule in the permission restriction policy. For example, if the user identities in the access record all belong to the same sub-organization under the same organization, then the access record conforms to the permission restriction rule based on the sub-organization identifier to which the user identity belongs. The cloud management platform 102 can determine the target attribute as the sub-organization identifier based on the context attribute corresponding to the permission restriction rule.

[0092] Please refer to Figure 3. In the example shown in Figure 3, after the cloud management platform 102 obtains the access records of the analysis object during the tracking period and the current access policy bound to the analysis object, the cloud management platform 102 analyzes the context attributes in the access records based on the preset permission restriction policy. That is, it checks whether the access records all meet one or more permission restriction rules in the permission restriction policy. If there are matching permission restriction rules, the cloud management platform 102 determines the target attribute based on the context attributes corresponding to the permission restriction rules.

[0093] 204. The cloud management platform generates permission analysis results based on target attributes and provides the permission analysis results to tenants. The permission analysis results are used to indicate over-authorized content in access control policies and to suggest permission restrictions based on over-authorized content.

[0094] After analyzing the context attributes in the access records to determine the target attributes, the cloud management platform 102 generates permission analysis results based on the target attributes. The permission analysis results are used to indicate the over-authorized content and permission restriction suggestions of the current access control policy. The over-authorized content refers to the unused permissions under specific permission restriction rules in the current access control policy, and the permission restriction suggestions are the modification suggestions for the current access control policy.

[0095] Specifically, during the process of generating permission analysis results based on target attributes, the cloud management platform 102 generates specific permission restriction rules based on the target attributes. These specific permission restriction rules are also called target permission restriction rules, which are the permission restriction suggestions for the current access control policy in the permission analysis results. For example, if the cloud management platform 102 analyzes the context attributes in the access record based on the permission restriction policy and determines that the target attribute is "sub-organization identifier ou-qqq", then the cloud management platform 102 generates a specific permission restriction rule based on "sub-organization identifier ou-qqq" as "only allowing users with sub-organization identifier 'ou-qqq' to access".

[0096] In one possible implementation, after the cloud management platform 102 generates the permission analysis results, the user can modify the current access control policy based on the permission analysis results. Specifically, the user can perform one or more of the following operations on the current access control policy based on the permission analysis results: adding or modifying the action field, adding or modifying the condition field, and adding or modifying the resource field.

[0097] Please refer to Figure 3. In the example shown in Figure 3, after the cloud management platform 102 analyzes the contextual attributes in the access records based on the preset permission restriction policy to determine the target attributes and target restriction rules, the cloud management platform 102 uses the target restriction rules as the permission analysis result. Users can modify the current access control policy based on this permission analysis result, thereby increasing access restrictions based on the target attributes.

[0098] The permission analysis process in this application embodiment is described below with specific examples:

[0099] In one possible implementation, during the analysis of user access records by the cloud management platform 102, if multiple user identities in the access records originate from the same sub-organization of the same organization, the permission restriction rule is assumed to be: restricting permissions from unused sub-organizations within the same organization based on the sub-organization identifier. The current access control policy for multiple user identities is: access control based on organization identifier. This current access control policy may lead to over-authorization of users within the organization.

[0100] Since multiple user identities in the aforementioned access records belong to the same sub-organization, meaning the access records conform to the permission restriction rule, the cloud management platform 102 identifies the sub-organization identifier to which the multiple user identities belong as the target attribute. The cloud management platform 102 can generate permission analysis results based on this sub-organization identifier and the permission restriction rule; that is, the permission analysis results can suggest modifying the current access control policy from restricting access by organization identifier to restricting access by sub-organization identifiers under the organization path.

[0101] Please refer to Figure 4, which is a schematic diagram of access control policy optimization based on subject attributes provided in an embodiment of this application. In the example shown in Figure 4, (a) is the schematic code of the access control policy before optimization, and (b) is the schematic code of the access control policy after optimization. As can be seen from the code shown in Figure (a), the current access control policy allows users under the organization ID "o-zzzzzzzz" to access the system, but only two users, "xxxx…x" and "yyyy…y", have actually accessed the system in the access records. At this time, combined with the context attributes in the access records, it can be found that both users "xxxx…x" and "yyyy…y" belong to the multi-level sub-organization "ou-qqq" under the organization "o-zzzzzzzz". Therefore, the multi-level sub-organization "ou-qqq" can be used as the target attribute, and the cloud management platform 102 generates permission analysis results based on the multi-level sub-organization "ou-qqq".

[0102] In the example shown in Figure 4, the cloud management platform 102 provides optimization suggestions for the current access control policy based on the permission analysis results. The user changes the restriction on the organization identifier ID in the "condition field" of the access control policy to a restriction on the organization path. Comparing the code shown in Figure (a) and Figure (b), the current access control policy allows all users under the organization "o-zzzzzzzz" to access the organization. The optimized access control policy based on the permission analysis results allows users under the organization path "o-zzzzzzzz / / r-yyy / ou-zzzz / ou-qqq / *" to access the organization. Compared with the example code shown in Figure (a), the optimized access control policy narrows the scope of permissions and avoids over-authorization.

[0103] In one possible implementation, when the cloud management platform 102 analyzes the user's access records, if multiple access targets in the access records are cloud services with the same resource identifier, and the current access control policy does not restrict access to only cloud services with the specified resource identifier, then the permission restriction rule is: restrict access to other cloud services based on the resource identifier.

[0104] Since all the access targets in the above access records are meta-services with the same resource identifier, meaning all access records conform to the permission restriction rule, the cloud management platform 102 can determine the resource identifier corresponding to the access target as the target attribute. Based on the resource identifier and the permission restriction rule, the cloud management platform 102 generates a permission analysis result. The permission analysis result restricts access to cloud services that match the resource identifier in the current access control policy.

[0105] Please refer to Figure 5, which is a schematic diagram of access control policy optimization based on object attributes provided in an embodiment of this application. In the example shown in Figure 5, (a) is the schematic code of the access control policy before optimization, and (b) is the schematic code of the access control policy after optimization. As can be seen from the code shown in Figure (a), the current access control policy allows access to a Virtual Private Cloud (VPC) bound to any resource identifier, while the access targets in the access records are all VPCs with the identifier "11111". At this time, combined with the context attributes in the access records and the permission restriction rule "restrict access to other cloud services based on cloud service identifier", the identifier "11111" can be used as the target attribute. The cloud management platform 102 generates a permission analysis result based on the identifier "11111". The permission analysis result suggests adding a permission restriction rule: only allow access to the VPC with the identifier "11111".

[0106] In the example shown in Figure 5, the cloud management platform 102 provides optimization suggestions for the current access control policy based on the permission analysis results. The user adds the restriction "only allow access to the VPC identified as 11111" to the access control policy. Comparing the code shown in Figures (a) and (b), the "resource field" in the current access control policy is "*", which means there is no restriction on access to the target VPC. In the optimized access control policy based on the permission analysis results, only the VPC identified as "vpc:111111" is allowed to be accessed. The optimized access control policy narrows the scope of permissions and avoids over-authorization.

[0107] In the example shown in Figure 5, in the code shown in Figure (b), the cloud management platform 102 can also combine the context attribute "resource identifier g:ResourceTag" in the access record and the permission restriction rule "restrict access to other cloud services based on the resource identifier bound to the cloud service". Using the identifier "g:ResourceTag:engineering" as the target attribute, the cloud management platform 102 generates permission analysis results based on the identifier "g:ResourceTag:engineering". That is, in the permission access control policy optimized based on the permission analysis results, the user is only allowed to access the VPC bound to the resource tag "engineering". Compared with the example code shown in Figure (a), the optimized permission access control policy narrows the scope of permissions and avoids over-authorization.

[0108] In one possible implementation, when the cloud management platform 102 analyzes the user's access records, if multiple access requests in the access records come from the same IP address range, and the current access control policy does not restrict the IP address range of the accessing user, it is assumed that the permission restriction rule is: restrict the access permissions of other users based on the network protocol IP address range.

[0109] Since the users in the aforementioned access records all come from the same IP address range, meaning the access records conform to the permission restriction rule, the cloud management platform 102 can determine the IP address range corresponding to multiple users as the target attribute. The cloud management platform 102 generates permission analysis results based on the IP address range, and the permission analysis results indicate that the current access control policy should restrict access to only users within the specified IP address range.

[0110] Please refer to Figure 6, which is a schematic diagram of access control policy optimization based on environmental attributes provided in an embodiment of this application. In the example shown in Figure 6, (a) is the schematic code of the access control policy before optimization, and (b) is the schematic code of the access control policy after optimization. As can be seen from the code shown in Figure (a), the current access control policy allows users from any IP address range to access the key management service (KMS), while the access records show that the users accessing the service all come from the same IP range "123.123.123.0 / 24". At this time, combined with the context attribute "123.123.123.0 / 24" in the access record and the permission restriction rule "restrict the access permissions of other users based on the user's source network protocol IP address", the IP address range "123.123.123.0 / 24" can be used as the target attribute, and the cloud management platform 102 generates permission analysis results based on the IP address range "123.123.123.0 / 24".

[0111] In the example shown in Figure 6, the cloud management platform 102 provides optimization suggestions for the current access control policy based on the permission analysis results. The user adds the restriction "only allow users with IP address range 123.123.123.0 / 24 to access" to the current access control policy. As can be seen from the code shown in Figure (b), the optimized access control policy based on the permission analysis results only allows users from the IP address range "123.123.123.0 / 24" to access. Compared with the example code shown in Figure (a), the optimized access control policy narrows the scope of permissions and avoids over-authorization.

[0112] As can be seen from the above embodiments, the access permission analysis system in this application can analyze the possible over-authorized content based on the contextual attributes in the access record, thereby mining some content that can be restricted by permissions based on rich contextual information. Therefore, the access permission suggestion method based on cloud computing technology provided in this application can identify over-authorized content for some permissions that have already been used in the current access control policy, thereby improving the accuracy and precision of over-authorization analysis.

[0113] Based on the above method embodiments, this application also provides an access permission suggestion device based on cloud computing technology. The access permission suggestion device based on cloud computing technology provided in this application is described in detail below.

[0114] Please refer to Figure 7, which is a schematic diagram of the structure of an access permission suggestion device based on cloud computing technology provided in an embodiment of this application. In the example shown in Figure 7, the access permission suggestion device 700 based on cloud computing technology is used to implement the various steps performed by the access permission analysis system in the above embodiments. The access permission suggestion device 700 based on cloud computing technology includes an acquisition unit 701 and a processing unit 702.

[0115] The acquisition unit 701 is used to determine the access control policy for a tenant account based on tenant input. The tenant account is the account registered by the tenant on the cloud management platform. The tenant accesses at least one cloud service of the infrastructure through the tenant account under the restrictions of the access control policy. The acquisition unit 701 is also used to acquire the cloud service access records of the tenant account. The access records include context attributes associated with one or more analysis objects associated with the tenant account. The context attributes include one or more of the following: subject attributes, object attributes, and environment attributes. The subject attributes include the tenant account, the object attributes include the cloud services accessed by the tenant account, and the environment attributes include the IP address ranges involved in the cloud services. The processing unit 702 is used to analyze the context attributes in the cloud service access records based on the permission restriction policy to determine the target attributes. The target attributes include the context attributes in the access records that conform to the permission restriction policy. The permission restriction policy is used to indicate one or more restriction rules for the context attributes. The processing unit 702 also generates permission analysis results based on the target attributes and provides the permission analysis results to the tenant. The permission analysis results are used to indicate the over-authorization content of the access control policy and the permission restriction suggestions generated based on the over-authorization content.

[0116] In one possible implementation, the processing unit 702 is specifically used to check the cloud service access record based on one or more permission restriction rules in the permission restriction policy. When the analysis object associated with the tenant account in the cloud service access record meets the permission restriction rule, the target attribute is determined based on the context attribute corresponding to the permission restriction rule.

[0117] In one possible implementation, the permission restriction rules include restricting unused permissions from the same organization based on the sub-organization identifier. Specifically, the processing unit 702 is used to determine the sub-organization identifier to which the multiple tenant accounts belong as the target attribute when multiple tenant accounts in the access record belong to the same sub-organization of the same organization.

[0118] In one possible implementation, the processing unit 702 is specifically used to generate permission analysis results based on the sub-organization identifier. The permission analysis results indicate that the access control policy should be modified from restricting access by organization identifier to restricting access by sub-organization identifier under the organization path.

[0119] In one possible implementation, the permission restriction rule also includes restricting access to other cloud services based on resource identifiers. Specifically, when multiple access targets in the access record are cloud services with the same resource identifier, the processing unit 702 determines the resource identifiers corresponding to the multiple access targets as target attributes.

[0120] In one possible implementation, the processing unit 702 is specifically used to generate permission analysis results based on resource identifiers, and the permission analysis results indicate that access to cloud services that match the resource identifiers should be restricted in the access control policy.

[0121] In one possible implementation, the permission restriction rule also includes restricting the access permissions of other users based on network protocol IP address ranges. Specifically, the processing unit 702 is used to determine the IP address ranges corresponding to multiple users as target attributes when multiple users in the access records come from the same IP address range.

[0122] In one possible implementation, the processing unit 702 is specifically used to generate permission analysis results based on IP address ranges, and the permission analysis results indicate that access control policies should restrict access to only users with specified IP address ranges.

[0123] In one possible implementation, the processing unit 702 is further configured to perform one or more of the following operations on the access control policy based on the permission analysis results: adding or modifying the authorization field, adding or modifying the condition field, and adding or modifying the resource field.

[0124] It is understandable that the acquisition unit 701 and processing unit 702 in the access permission suggestion device 700 based on cloud computing technology can be mapped as functional modules to each module in the access permission analysis system 10 in Figure 1, thereby realizing the functions of each module in the access permission analysis system 10.

[0125] It should be understood that the division of units in the above device is merely a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, all units in the device can be implemented entirely through software calls from processing elements; all units can be implemented entirely in hardware; or some units can be implemented through software calls from processing elements, and others in hardware. For example, each unit can be a separate processing element, or it can be integrated into a chip within the device. Alternatively, it can be stored as a program in memory, called and executed by a processing element of the device. Moreover, these units can be fully or partially integrated together, or implemented independently. The processing element mentioned here can also be called a processor, which can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above units can be implemented through integrated logic circuits in the processor element or through software calls from processing elements.

[0126] It is worth noting that, for the sake of simplicity, the above method embodiments are described as a series of actions. However, those skilled in the art should know that this application is not limited to the order of the described actions. Furthermore, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily required by this application.

[0127] Other reasonable combinations of steps that can be conceived by those skilled in the art based on the above description also fall within the scope of protection of this application. Furthermore, those skilled in the art should also be aware that the embodiments described in the specification are preferred embodiments, and the actions involved are not necessarily essential to this application.

[0128] Please refer to Figure 8, which is a schematic diagram of the structure of a computing device provided in an embodiment of this application. As shown in Figure 8, the computing device 800 includes: a processor 801, a memory 802, a communication interface 803, and a bus 804. The processor 801, the memory 802, and the communication interface 803 are coupled through the bus (not labeled in the figure). The memory 802 stores instructions. When the execution instructions in the memory 802 are executed, the computing device 800 executes the method performed by the access permission analysis system in the above method embodiment.

[0129] The computing device 800 may be one or more integrated circuits configured to implement the methods described above, such as: one or more application-specific integrated circuits (ASICs), or one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs), or a combination of at least two of these forms of integrated circuits. Furthermore, when the units in the device can be implemented in the form of a processing element scheduler, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor capable of calling programs. Alternatively, these units may be integrated together to implement a system-on-a-chip (SOC).

[0130] The processor 801 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. A general-purpose processor can be a microprocessor or any conventional processor.

[0131] The memory 802 can be volatile memory or non-volatile memory, or it can include both. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).

[0132] The memory 802 stores executable program code, and the processor 801 executes the executable program code to implement the functions of the aforementioned units or modules, thereby implementing the aforementioned access permission suggestion method based on cloud computing technology. That is, the memory 802 stores instructions for executing the aforementioned access permission suggestion method based on cloud computing technology.

[0133] The communication interface 803 uses transceiver modules, such as, but not limited to, network interface cards and transceivers, to enable communication between the computing device 800 and other devices or communication networks.

[0134] In addition to the data bus, the 804 bus can also include a power bus, a control bus, and a status signal bus. The bus can be a Peripheral Component Interconnect Express (PCIe) bus, an Extended Industry Standard Architecture (EISA) bus, a Unified Bus (Ubus or UB), a Compute Express Link (CXL) bus, a Cache Coherent Interconnect for Accelerators (CCIX) bus, etc. The bus can be divided into address bus, data bus, and control bus.

[0135] Please refer to Figure 9, which is a schematic diagram of a computing device cluster provided in an embodiment of this application. As shown in Figure 9, the computing device cluster 900 includes at least one computing device 800.

[0136] As shown in Figure 9, the computing device cluster 900 includes at least one computing device 800. The memory 802 of one or more computing devices 800 in the computing device cluster 900 may store the same instructions for executing the aforementioned access permission suggestion method based on cloud computing technology.

[0137] In some possible implementations, the memory 802 of one or more computing devices 800 in the computing device cluster 900 may also store partial instructions for executing the aforementioned access permission recommendation method based on cloud computing technology. In other words, a combination of one or more computing devices 800 can jointly execute the instructions for executing the aforementioned access permission recommendation method based on cloud computing technology.

[0138] It should be noted that the memories 802 in the different computing devices 800 within the computing device cluster 900 can store different instructions, each used to execute a portion of the functions of the aforementioned node load control device. That is, the instructions stored in the memories 802 of the different computing devices 800 can implement the functions of one or more modules in the acquisition unit and processing unit.

[0139] In some possible implementations, one or more computing devices 800 in the computing device cluster 900 can be connected via a network. This network can be a wide area network (WAN) or a local area network (LAN), etc.

[0140] Please refer to Figure 10, which is a schematic diagram of computer devices in a computer cluster connected via a network according to an embodiment of this application. As shown in Figure 10, in the computing device cluster 1000, two computing devices 800A and 800B are connected via a network. Specifically, they are connected to the network through the communication interfaces in each computing device.

[0141] In one possible implementation, the memory in computing device 800A stores instructions for performing the fetch unit function. Meanwhile, the memory in computing device 800B stores instructions for performing the processing unit function.

[0142] It should be understood that the functions of computing device 800A shown in Figure 10 can also be performed by multiple computing devices. Similarly, the functions of computing device 800B can also be performed by multiple computing devices.

[0143] In another embodiment of this application, a computer-readable storage medium is also provided, which stores computer-executable instructions. When the processor of the device executes the computer-executable instructions, the device executes the method performed by the access permission analysis system in the above method embodiment.

[0144] In another embodiment of this application, a computer program product is also provided, which includes computer-executable instructions stored in a computer-readable storage medium. When the processor of the device executes the computer-executable instructions, the device performs the method executed by the access permission analysis system in the above-described method embodiments.

[0145] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0146] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection between apparatuses or units through some interfaces, and may be electrical, mechanical, or other forms.

[0147] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.

[0148] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.

[0149] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

Claims

1. An access permission suggestion method based on cloud computing technology, characterized in that, The method is applied to a cloud management platform, which manages infrastructure providing various cloud services, including multiple data centers. The method includes: The cloud management platform determines the access control policy for the tenant account based on the tenant input, wherein the tenant account is the account registered by the tenant on the cloud management platform, and the tenant accesses at least one cloud service of the infrastructure through the tenant account under the restriction of the access control policy. The cloud management platform obtains the cloud service access records of the tenant account. The cloud service access records include contextual attributes of one or more analysis objects associated with the tenant account. The contextual attributes include one or more of the following: subject attributes, object attributes, and environment attributes. The subject attributes include the tenant account. The object attributes include the cloud services accessed by the tenant account. The environment attributes include the IP address ranges involved in the cloud services. The cloud management platform analyzes the context attributes in the cloud service access records based on the permission restriction policy to determine the target attributes. The target attributes include the context attributes in the access records that conform to the permission restriction policy. The permission restriction policy is used to indicate one or more restriction rules on the context attributes. The cloud management platform generates permission analysis results based on the target attributes and provides the permission analysis results to the tenant. The permission analysis results are used to indicate the over-authorized content of the access control policy and the permission restriction suggestions generated based on the over-authorized content.

2. The method according to claim 1, characterized in that, The cloud management platform analyzes the contextual attributes in the cloud service access records based on the permission restriction policy, including: The cloud management platform checks the cloud service access records based on one or more permission restriction rules in the permission restriction policy. When the analysis object associated with the tenant account in the cloud service access record meets the permission restriction rule, the cloud management platform determines the target attribute based on the context attribute corresponding to the permission restriction rule.

3. The method according to claim 2, characterized in that, The permission restriction rules include restricting unused permissions from the same organization based on the sub-organization identifier. The cloud management platform analyzes the contextual attributes in the cloud service access records based on the permission restriction policy to determine the target attributes, including: When multiple tenant accounts in the access records come from the same sub-organization of the same organization, the cloud management platform determines the sub-organization identifier to which the multiple tenant accounts belong as the target attribute.

4. The method according to claim 3, characterized in that, The cloud management platform generates permission analysis results based on the target attributes, including: The cloud management platform generates permission analysis results based on the sub-organization identifier, and the permission analysis results indicate that the access control policy should be modified from restricting access by organization identifier to restricting access by sub-organization identifier under the organization path.

5. The method according to claim 2, characterized in that, The permission restriction rules also include restricting access to other cloud services based on resource identifiers. The cloud management platform analyzes the contextual attributes in the cloud service access records based on the permission restriction policy to determine the target attributes, including: When multiple access targets in the access record are cloud services with the same resource identifier, the cloud management platform determines the resource identifier corresponding to the multiple access targets as the target attribute.

6. The method according to claim 5, characterized in that, The cloud management platform generates permission analysis results based on the target attributes, including: The cloud management platform generates permission analysis results based on the resource identifier, and the permission analysis results indicate that the access control policy restricts access to cloud services that match the resource identifier.

7. The method according to claim 2, characterized in that, The access restriction rules also include restricting access permissions for other users based on network protocol IP address ranges. The cloud management platform analyzes the contextual attributes in the cloud service access records based on the access restriction policies to determine the target attributes, including: When multiple users in the access records come from the same IP address range, the cloud management platform determines the IP address range corresponding to the multiple users as the target attribute.

8. The method according to claim 7, characterized in that, The cloud management platform generates permission analysis results based on the target attributes, including: The cloud management platform generates permission analysis results based on the IP address range, and the permission analysis results indicate that the access control policy should restrict access to only users within the specified IP address range.

9. The method according to any one of claims 1 to 8, characterized in that, The method further includes: Based on the permission analysis results, the cloud management platform performs one or more of the following operations on the access control policy: adding or modifying authorization field, adding or modifying condition field, and adding or modifying resource field.

10. An access permission suggestion device based on cloud computing technology, characterized in that, The device includes: The acquisition unit is used to determine the access control policy of the tenant account based on the tenant input, wherein the tenant account is the account registered by the tenant on the cloud management platform, and the tenant accesses at least one cloud service of the infrastructure through the tenant account under the restriction of the access control policy. The acquisition unit is further configured to acquire the cloud service access records of the tenant account. The cloud service access records include context attributes of one or more analysis objects associated with the tenant account. The context attributes include one or more of the following: subject attributes, object attributes, and environment attributes. The subject attributes include the tenant account. The object attributes include the cloud services accessed by the tenant account. The environment attributes include the IP address ranges involved in the cloud services. The processing unit is configured to analyze the context attributes in the cloud service access records based on the permission restriction policy, and determine the target attributes. The target attributes include the context attributes in the access records that conform to the permission restriction policy. The permission restriction policy is used to indicate one or more restriction rules on the context attributes. The processing unit also generates permission analysis results based on the target attribute and provides the permission analysis results to the tenant. The permission analysis results are used to indicate the over-authorization content of the access control policy and the permission restriction suggestions generated based on the over-authorization content.

11. The apparatus according to claim 10, characterized in that, The processing unit is specifically used for: The cloud service access records are checked based on one or more permission restriction rules in the permission restriction policy; If the analysis object associated with the tenant account in the cloud service access record meets the permission restriction rule, the target attribute is determined based on the context attribute corresponding to the permission restriction rule.

12. The apparatus according to claim 11, characterized in that, The permission restriction rules include restricting unused permissions from the same organization based on sub-organization identifiers, and the processing unit is specifically used for: When multiple tenant accounts in the access records come from the same sub-organization of the same organization, the sub-organization identifier to which the multiple tenant accounts belong is determined as the target attribute.

13. The apparatus according to claim 12, characterized in that, The processing unit is specifically used for: Based on the sub-organization identifier, a permission analysis result is generated, and the permission analysis result indicates that the access control policy should be modified from restricting access by organization identifier to restricting access by sub-organization identifier under the organization path.

14. The apparatus according to claim 11, characterized in that, The permission restriction rules also include restricting access to other cloud services based on resource identifiers, and the processing unit is specifically used for: When multiple access targets in the access record are cloud services with the same resource identifier, the resource identifier corresponding to the multiple access targets is determined as the target attribute.

15. The apparatus according to claim 14, characterized in that, The processing unit is specifically used for: Based on the resource identifier, a permission analysis result is generated, and the permission analysis result indicates that the access control policy restricts access to cloud services that match the resource identifier.

16. The apparatus according to claim 11, characterized in that, The access restriction rules also include restricting access permissions for other users based on network protocol IP address ranges, and the processing unit is specifically used for: When multiple users in the access records come from the same IP address range, the IP address range corresponding to the multiple users is determined as the target attribute.

17. The apparatus according to claim 16, characterized in that, The processing unit is specifically used for: Based on the IP address range, a permission analysis result is generated, and the permission analysis result indicates that the access control policy should restrict access to only users within the specified IP address range.

18. The apparatus according to any one of claims 10 to 17, characterized in that, The processing unit is also used for: Based on the permission analysis results, perform one or more of the following operations on the access control policy: add or modify authorization field, add or modify condition field, add or modify resource field.

19. A computing device cluster, characterized in that, The device includes at least one computing device, the computing device including a processor coupled to a memory, the processor being used to store instructions that, when executed by the processor, cause the cluster of computing devices to perform the method of any one of claims 1 to 9.

20. A computer-readable storage medium having instructions stored thereon, characterized in that, When the instructions are executed, they cause the computer to perform the method of any one of claims 1 to 9.

21. A computer program product, the computer program product comprising instructions, characterized in that, When the instructions are executed, they cause the computer to perform the method of any one of claims 1 to 9.