KR102936977B1 - Method for verifying service and user in a cloud environment and system therefor - Google Patents
Method for verifying service and user in a cloud environment and system thereforInfo
- Publication number
- KR102936977B1 KR102936977B1 KR1020250024337A KR20250024337A KR102936977B1 KR 102936977 B1 KR102936977 B1 KR 102936977B1 KR 1020250024337 A KR1020250024337 A KR 1020250024337A KR 20250024337 A KR20250024337 A KR 20250024337A KR 102936977 B1 KR102936977 B1 KR 102936977B1
- Authority
- KR
- South Korea
- Prior art keywords
- cloud service
- user
- cloud
- certificate
- authentication
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Active
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0884—Network architectures or network communication protocols for network security for authentication of entities by delegation of authentication, e.g. a proxy authenticates an entity to be authenticated on behalf of this entity vis-à-vis an authentication entity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0442—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/105—Multiple levels of security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/12—Applying verification of the received information
- H04L63/126—Applying verification of the received information the source of the received data
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Abstract
클라우드 환경에서 서비스 및 사용자 인증 방법 및 그 시스템이 제공된다. 본 개시의 일 실시예에 따른 서비스 제공 방법은, 컴퓨팅 시스템에 의해 수행되는 방법에 있어서, 제1 클라우드 서비스를 사용하는 사용자의 단말로부터 제2 클라우드 서비스에 대한 액세스 요청을 수신하는 단계, 상기 액세스 요청을 수신하는 것에 응답하여, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증되었는지 여부를 판정하는 단계, 상기 판정의 결과, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증된 경우, 상기 제1 클라우드 서비스에 상기 사용자의 검증 요청을 송신하는 단계, 상기 검증 요청에 응답하여, 상기 제2 클라우드 서비스에, 상기 사용자가 상기 제2 클라우드 서비스에 대한 액세스 권한이 있는지 여부에 관한 사용자 검증 결과를 송신하는 단계 및 상기 사용자 검증 결과를 이용하여, 상기 사용자에 대하여, 상기 제2 클라우드 서비스에 대한 액세스 권한을 설정하는 단계를 포함하되, 상기 제1 클라우드 서비스 및 상기 제2 클라우드 서비스는 동일한 클라우드 플랫폼 상에서 제공되는 서비스일 수 있다.A method for authenticating services and users in a cloud environment and a system thereof are provided. A service providing method according to one embodiment of the present disclosure is a method performed by a computing system, comprising: receiving an access request for a second cloud service from a terminal of a user using a first cloud service; determining, in response to receiving the access request, whether the first cloud service is authenticated in the second cloud service; transmitting a user verification request to the first cloud service if the first cloud service is authenticated in the second cloud service as a result of the determination; transmitting, in response to the verification request, a user verification result regarding whether the user has access to the second cloud service; and using the user verification result, setting access rights to the second cloud service for the user, wherein the first cloud service and the second cloud service may be services provided on the same cloud platform.
Description
본 개시는 클라우드 환경에서 서비스 및 사용자 인증 방법 및 시스템에 관한 것이다. 보다 자세하게는, 기존에 제공되는 클라우드 서비스에서 새로운 클라우드 서비스를 제공하는 방법 및 그 시스템에 관한 것이다.The present disclosure relates to a method and system for service and user authentication in a cloud environment. More specifically, it relates to a method and system for providing a new cloud service within an existing cloud service.
클라우드 환경에서 서비스 제공 방법은 인터넷을 통해 컴퓨팅 자원과 소프트웨어를 온디맨드(On-Demand) 방식으로 제공하는 방식을 의미한다. 일반적으로 IaaS(Infrastructure as a Service), PaaS(Platform as a Service), SaaS(Software as a Service)로 나뉘며, 사용자는 필요에 따라 서버, 스토리지, 네트워크, 애플리케이션 등을 클라우드에서 실행할 수 있다. In a cloud environment, service delivery refers to the on-demand provision of computing resources and software via the Internet. These are typically categorized as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Users can run servers, storage, networks, applications, and more in the cloud as needed.
서비스 제공자는 가상화 기술과 분산 컴퓨팅을 활용하여 자동 확장(Scalability), 고가용성(High Availability), 보안(Security)을 보장하며, REST API 및 인증 프로토콜(OAuth, SAML 등)을 통해 다양한 서비스와의 연동성을 제공한다.Service providers leverage virtualization technology and distributed computing to ensure automatic scalability, high availability, and security, and provide interoperability with various services through REST APIs and authentication protocols (OAuth, SAML, etc.).
이를 통해 기업과 개인은 물리적 인프라를 직접 운영할 필요 없이, 클라우드 기반으로 효율적이고 확장 가능한 IT 서비스를 구축 및 운영할 수 있다.This allows businesses and individuals to build and operate efficient and scalable IT services on a cloud basis without having to directly operate physical infrastructure.
이 논문은 2022년도 정부(과학기술정보통신부)의 재원으로 정보통신기획평가원의 지원을 받아 수행된 연구임(No.2022-0-01019, eSIM 생태계 조성을 위한 엣지 디바이스 전용 eSIM 보안 플랫폼 기술 개발).This study was supported by the National IT Industry Promotion Agency (NIPA) through funding from the Ministry of Science and ICT (Ministry of Science and ICT) in 2022 (No. 2022-0-01019, Development of eSIM security platform technology for edge devices to foster an eSIM ecosystem).
This work was supported by Institute of Information & communications Technology Planning & Evaluation (IITP) grant funded by the Korea government(MSIT)(No.2022-0-01019, Development of eSIM security platform technology for edge devices to expand the eSIM ecosystem).This work was supported by Institute of Information & communications Technology Planning & Evaluation (IITP) grant funded by the Korea government (MSIT)(No.2022-0-01019, Development of eSIM security platform technology for edge devices to expand the eSIM ecosystem).
본 개시의 몇몇 실시예들에서 해결하고자 하는 기술적 과제는, 클라우드 플랫폼에서 제공되는 다양한 서비스를 사용자가 별도의 로그인 없이 이용할 수 있는 클라우드 환경에서 서비스 제공 방법 및 그 시스템을 제공하는 것이다.A technical problem to be solved in some embodiments of the present disclosure is to provide a method and system for providing services in a cloud environment, in which a user can use various services provided on a cloud platform without a separate log-in.
본 개시의 몇몇 실시예들에서 해결하고자 하는 다른 기술적 과제는, 클라우드 환경에서 서비스 구축 시 인증이 필요한 서비스에 인증을 요청하는 방법 및 그 시스템을 제공하는 것이다.Another technical problem to be solved in some embodiments of the present disclosure is to provide a method and system for requesting authentication for a service requiring authentication when building a service in a cloud environment.
본 개시의 기술적 과제들은 이상에서 언급한 기술적 과제들로 제한되지 않으며, 언급되지 않은 또 다른 기술적 과제들은 아래의 기재로부터 본 개시의 기술분야에서의 통상의 기술자에게 명확하게 이해될 수 있을 것이다.The technical problems of the present disclosure are not limited to the technical problems mentioned above, and other technical problems not mentioned will be clearly understood by those skilled in the art of the present disclosure from the description below.
상기 기술적 과제를 해결하기 위한 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 방법은, 컴퓨팅 시스템에 의해 수행되는 방법에 있어서, 제1 클라우드 서비스를 사용하는 사용자의 단말로부터 제2 클라우드 서비스에 대한 액세스 요청을 수신하는 단계; 상기 액세스 요청을 수신하는 것에 응답하여, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증되었는지 여부를 판정하는 단계; 상기 판정의 결과, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증된 경우, 상기 제1 클라우드 서비스에 상기 사용자의 검증 요청을 송신하는 단계; 상기 검증 요청에 응답하여, 상기 제2 클라우드 서비스에, 상기 사용자가 상기 제2 클라우드 서비스에 대한 액세스 권한이 있는지 여부에 관한 사용자 검증 결과를 송신하는 단계; 및 상기 사용자 검증 결과를 이용하여, 상기 사용자에 대하여, 상기 제2 클라우드 서비스에 대한 액세스 권한을 설정하는 단계를 포함하되, 상기 제1 클라우드 서비스 및 상기 제2 클라우드 서비스는 동일한 클라우드 플랫폼 상에서 제공되는 서비스일 수 있다.According to some embodiments of the present disclosure for solving the above technical problem, a method for providing a service in a cloud environment is provided, the method comprising: receiving an access request for a second cloud service from a terminal of a user using a first cloud service; determining, in response to receiving the access request, whether the first cloud service is authenticated in the second cloud service; transmitting a user verification request to the first cloud service if the first cloud service is authenticated in the second cloud service as a result of the determination; transmitting, in response to the verification request, a user verification result regarding whether the user has access to the second cloud service; and using the user verification result, setting access rights for the user to the second cloud service, wherein the first cloud service and the second cloud service may be services provided on the same cloud platform.
몇몇 실시예들에서, 상기 판정하는 단계는, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증되지 않은 경우, 상기 제2 클라우드 서비스로부터 상기 제1 클라우드 서비스에 대한 인증 요청을 수신하는 단계; 상기 인증 요청에 응답하여, 상기 제2 클라우드 서비스의 인증서 및 공인 IP 정보를 이용하여 상기 제1 클라우드 서비스에 대한 인증 요청 데이터를 생성하는 단계; 상기 인증 요청 데이터를 상기 제1 클라우드 서비스의 인증서에 포함된 공개키로 암호화하는 단계; 상기 제1 클라우드 서비스의 공인 IP로 상기 암호화된 인증 요청 데이터를 송신하는 단계; 상기 제1 클라우드 서비스의 비밀키를 이용하여, 상기 암호화된 인증 요청 데이터를 복호화하는 단계; 상기 인증 요청 데이터에 포함된 상기 제2 클라우드 서비스 인증서의 인증 기관(Certificate Authority)과 상기 클라우드 플랫폼에 저장된 제2 클라우드 서비스의 인증서의 인증 기관이 일치하는지 여부를 검증하는 단계; 및 상기 검증의 결과, 상기 인증 요청 데이터에 포함된 상기 제2 클라우드 서비스의 인증서의 인증 기관과 상기 클라우드 플랫폼에 저장된 제2 클라우드 서비스의 인증서의 인증 기관이 일치하는 경우, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 제공될 수 있도록 상기 제1 클라우드 서비스의 인증 대상에 상기 제2 클라우드 서비스를 추가하는 단계를 포함할 수 있다.In some embodiments, the determining step comprises: receiving an authentication request for the first cloud service from the second cloud service when the first cloud service is not authenticated by the second cloud service; generating authentication request data for the first cloud service using a certificate and public IP information of the second cloud service in response to the authentication request; encrypting the authentication request data with a public key included in the certificate of the first cloud service; transmitting the encrypted authentication request data to the public IP of the first cloud service; decrypting the encrypted authentication request data using a private key of the first cloud service; verifying whether a Certificate Authority of the second cloud service certificate included in the authentication request data matches a Certificate Authority of a certificate of the second cloud service stored in the cloud platform; And as a result of the verification, if the certification authority of the certificate of the second cloud service included in the authentication request data matches the certification authority of the certificate of the second cloud service stored in the cloud platform, the step of adding the second cloud service to the authentication target of the first cloud service so that the first cloud service can be provided in the second cloud service may be included.
몇몇 실시예들에서, 상기 제1 클라우드 서비스의 인증 대상에 상기 제2 클라우드 서비스를 추가하는 단계는, 상기 제1 클라우드 서비스의 저장 공간에 상기 제2 클라우드 서비스의 인증서 및 공인 IP 정보를 저장하는 단계를 포함할 수 있다.In some embodiments, the step of adding the second cloud service to the authentication target of the first cloud service may include the step of storing a certificate and public IP information of the second cloud service in a storage space of the first cloud service.
몇몇 실시예들에서, 상기 판정하는 단계는, 상기 제2 클라우드 서비스의 인증서 또는 공인 IP 정보가 변경된 경우, 상기 제2 클라우드 서비스로부터 상기 제1 클라우드 서비스에 대한 인증 정보 갱신 요청을 수신하는 단계; 상기 인증 정보 갱신 요청에 응답하여, 상기 제2 클라우드 서비스의 변경된 인증서 또는 공인 IP 정보를 이용하여, 상기 제1 클라우드 서비스에 대한 인증 갱신 요청 데이터를 생성하는 단계; 상기 제2 클라우드 서비스의 변경 전 인증서의 비밀키를 이용하여, 상기 인증 갱신 요청 데이터에 서명을 수행하고, 서명 인증 갱신 요청 데이터를 생성하는 단계; 상기 서명 인증 갱신 요청 데이터를 상기 제1 클라우드 서비스의 인증서에 포함된 공개키로 암호화하는 단계; 상기 제1 클라우드 서비스의 공인 IP로 상기 암호화된 서명 인증 갱신 요청 데이터를 송신하는 단계; 상기 제1 클라우드 서비스의 비밀키를 이용하여, 상기 서명 인증 갱신 요청 데이터를 복호화하는 단계; 상기 제2 클라우드 서비스의 변경 전 인증서의 공개키를 이용하여, 상기 서명 인증 갱신 요청 데이터를 검증하는 단계; 상기 서명 인증 갱신 요청 데이터에 포함된 상기 제2 클라우드 서비스의 인증서의 인증 기관(Certificate Authority)과 상기 클라우드 플랫폼에 저장된 제2 클라우드 서비스 인증서의 인증 기관이 일치하는지 여부를 검증하는 단계; 및 상기 서명 인증 갱신 요청 데이터에 포함된 상기 제2 클라우드 서비스의 인증서의 인증 기관과 상기 클라우드 플랫폼에 저장된 제2 클라우드 서비스의 인증서의 인증 기관이 일치하는 경우, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 제공될 수 있도록 상기 제1 클라우드 서비스의 인증 대상에 상기 제2 클라우드 서비스를 추가하는 단계를 포함할 수 있다.In some embodiments, the determining step comprises: receiving, from the second cloud service, a request for renewal of authentication information for the first cloud service, if the certificate or public IP information of the second cloud service has changed; generating, in response to the authentication information renewal request, authentication renewal request data for the first cloud service using the changed certificate or public IP information of the second cloud service; signing the authentication renewal request data using a private key of a certificate of the second cloud service before the change, and generating signature authentication renewal request data; encrypting the signature authentication renewal request data using a public key included in a certificate of the first cloud service; transmitting the encrypted signature authentication renewal request data to the public IP of the first cloud service; decrypting the signature authentication renewal request data using the private key of the first cloud service; verifying the signature authentication renewal request data using the public key of the certificate of the second cloud service before the change; verifying whether a certificate authority of a certificate of the second cloud service included in the signature authentication renewal request data matches a certificate authority of a second cloud service certificate stored in the cloud platform; And, if the certification authority of the certificate of the second cloud service included in the signature authentication renewal request data matches the certification authority of the certificate of the second cloud service stored in the cloud platform, the step of adding the second cloud service to the authentication target of the first cloud service so that the first cloud service can be provided in the second cloud service may be included.
몇몇 실시예들에서, 상기 제1 클라우드 서비스의 인증 대상에 상기 제2 클라우드 서비스를 추가하는 단계는, 상기 제1 클라우드 서비스의 저장 공간에 상기 제2 클라우드 서비스의 변경된 인증서 및 공인 IP 정보를 저장하는 단계를 포함할 수 있다.In some embodiments, the step of adding the second cloud service to the authentication target of the first cloud service may include the step of storing the changed certificate and public IP information of the second cloud service in the storage space of the first cloud service.
몇몇 실시예들에서, 상기 사용자의 검증 요청은, 상기 제1 클라우드 서비스의 인증서에 포함된 공개키로 암호화된, 상기 제1 클라우드 서비스의 고유 식별 정보 및 상기 제1 클라우드 서비스에 대한 상기 사용자의 제1 사용자 인증 토큰(Authentication Token)에 관한 사용자 검증 요청 데이터를 포함할 수 있다.In some embodiments, the user's verification request may include user verification request data regarding the user's first user authentication token for the first cloud service and unique identification information of the first cloud service, encrypted with a public key included in a certificate of the first cloud service.
몇몇 실시예들에서, 상기 사용자 검증 결과를 송신하는 단계는, 상기 제1 클라우드 서비스의 인증서에 포함된 비밀키를 이용하여, 상기 사용자 검증 요청 데이터를 복호화하는 단계; 상기 제1 사용자 인증 토큰을 이용하여, 상기 사용자의 정보를 획득하는 단계; 상기 사용자의 정보를 이용하여, 상기 제2 클라우드 서비스에 대한 상기 사용자의 액세스 권한 정보를 획득하는 단계; 및 상기 액세스 권한 정보를 상기 제2 클라우드 서비스의 인증서에 포함된 공개키로 암호화하는 단계를 포함할 수 있다.In some embodiments, the step of transmitting the user verification result may include: decrypting the user verification request data using a private key included in a certificate of the first cloud service; obtaining information about the user using the first user authentication token; obtaining access authority information about the user for the second cloud service using the information about the user; and encrypting the access authority information using a public key included in a certificate of the second cloud service.
몇몇 실시예들에서, 상기 액세스 권한을 설정하는 단계는, 상기 사용자가 상기 제2 클라우드 서비스에 대한 액세스 권한이 있는 경우, 상기 제2 클라우드 서비스에 대한 상기 사용자의 제2 사용자 인증 토큰의 생성 요청을 송신하는 단계; 및 상기 생성 요청을 수신하는 것에 응답하여, 상기 액세스 권한 정보를 이용하여, 상기 제2 클라우드 서비스에 대한 상기 사용자의 액세스 권한 및 토큰 만료 시간에 관한 정보를 포함하는 제2 사용자 인증 토큰을 생성하는 단계를 포함할 수 있다. In some embodiments, the step of setting the access rights may include: if the user has access rights to the second cloud service, transmitting a request for generating a second user authentication token of the user to the second cloud service; and in response to receiving the generation request, using the access rights information, generating a second user authentication token including information regarding the user's access rights to the second cloud service and a token expiration time.
상기 기술적 과제를 해결하기 위한 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 시스템은, 통신 인터페이스; 컴퓨터 프로그램이 로드되는 메모리; 및 상기 컴퓨터 프로그램이 실행되는 하나 이상의 프로세서를 포함하되, 상기 컴퓨터 프로그램은, 제1 클라우드 서비스를 사용하는 사용자의 단말로부터 제2 클라우드 서비스에 대한 액세스 요청을 수신하는 동작; 상기 액세스 요청을 수신하는 것에 응답하여, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증되었는지 여부를 판정하는 동작; 상기 판정의 결과, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증된 경우, 상기 제1 클라우드 서비스에 상기 사용자의 검증 요청을 송신하는 동작; 상기 검증 요청에 응답하여, 상기 제2 클라우드 서비스에, 상기 사용자가 상기 제2 클라우드 서비스에 대한 액세스 권한이 있는지 여부에 관한 사용자 검증 결과를 송신하는 동작; 및 상기 사용자 검증 결과를 이용하여, 상기 사용자에 대하여, 상기 제2 클라우드 서비스에 대한 액세스 권한을 설정하는 동작을 실행시키는 인스트럭션들(instructions)을 포함하되, 상기 제1 클라우드 서비스 및 상기 제2 클라우드 서비스는 동일한 클라우드 플랫폼 상에서 제공되는 서비스일 수 있다.According to some embodiments of the present disclosure for solving the above technical problem, a system for providing a service in a cloud environment includes: a communication interface; a memory in which a computer program is loaded; and one or more processors in which the computer program is executed, wherein the computer program includes instructions for performing the following operations: receiving an access request for a second cloud service from a terminal of a user using a first cloud service; determining, in response to receiving the access request, whether the first cloud service is authenticated in the second cloud service; transmitting a user verification request to the first cloud service if the first cloud service is authenticated in the second cloud service as a result of the determination; transmitting, in response to the verification request, a user verification result regarding whether the user has access to the second cloud service to the second cloud service; and using the user verification result, setting access rights for the user to the second cloud service, wherein the first cloud service and the second cloud service may be services provided on the same cloud platform.
상기 기술적 과제를 해결하기 위한 본 개시의 몇몇 실시예들에 따른 컴퓨터로 판독가능한 기록매체에 저장된 컴퓨터 프로그램은, 컴퓨팅 장치와 결합되어, 제1 클라우드 서비스를 사용하는 사용자의 단말로부터 제2 클라우드 서비스에 대한 액세스 요청을 수신하는 단계; 상기 액세스 요청을 수신하는 것에 응답하여, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증되었는지 여부를 판정하는 단계; 상기 판정의 결과, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증된 경우, 상기 제1 클라우드 서비스에 상기 사용자의 검증 요청을 송신하는 단계; 상기 검증 요청에 응답하여, 상기 제2 클라우드 서비스에, 상기 사용자가 상기 제2 클라우드 서비스에 대한 액세스 권한이 있는지 여부에 관한 사용자 검증 결과를 송신하는 단계; 및 상기 사용자 검증 결과를 이용하여, 상기 사용자에 대하여, 상기 제2 클라우드 서비스에 대한 액세스 권한을 설정하는 단계를 실행시키되, 상기 제1 클라우드 서비스 및 상기 제2 클라우드 서비스는 동일한 클라우드 플랫폼 상에서 제공되는 서비스일 수 있다.According to some embodiments of the present disclosure for solving the above technical problem, a computer program stored on a computer-readable recording medium is coupled to a computing device and executes the steps of: receiving an access request for a second cloud service from a terminal of a user using a first cloud service; determining, in response to receiving the access request, whether the first cloud service is authenticated in the second cloud service; transmitting a user verification request to the first cloud service if the first cloud service is authenticated in the second cloud service as a result of the determination; transmitting, in response to the verification request, a user verification result regarding whether the user has access to the second cloud service; and setting access rights to the second cloud service for the user using the user verification result, wherein the first cloud service and the second cloud service may be services provided on the same cloud platform.
도 1은 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 시스템의 구성 및 동작을 설명하기 위한 시스템 구성도이다.
도 2는 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 방법의 동작을 설명하기 위한 신호 흐름도이다.
도 3은 도 2를 참조하여 설명한, 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 방법의 세부 동작을 설명하기 위한 상세 순서도이다.
도 4는 도 2를 참조하여 설명한, 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 방법의 세부 동작을 설명하기 위한 상세 순서도이다.
도 5는 도 2를 참조하여 설명한, 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 방법의 세부 동작을 설명하기 위한 상세 순서도이다.
도 6은 도 2를 참조하여 설명한, 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 방법의 세부 동작을 설명하기 위한 상세 순서도이다.
도 7은 본 개시의 몇몇 실시예들에서 설명된 컴퓨팅 장치의 하드웨어 구성도이다.FIG. 1 is a system configuration diagram for explaining the configuration and operation of a service provision system in a cloud environment according to some embodiments of the present disclosure.
FIG. 2 is a signal flow diagram illustrating the operation of a service providing method in a cloud environment according to some embodiments of the present disclosure.
FIG. 3 is a detailed flowchart for explaining detailed operations of a service provision method in a cloud environment according to some embodiments of the present disclosure, described with reference to FIG. 2.
FIG. 4 is a detailed flowchart for explaining detailed operations of a service provision method in a cloud environment according to some embodiments of the present disclosure, described with reference to FIG. 2.
FIG. 5 is a detailed flowchart for explaining the detailed operation of a service provision method in a cloud environment according to some embodiments of the present disclosure, described with reference to FIG. 2.
FIG. 6 is a detailed flowchart for explaining the detailed operation of a service provision method in a cloud environment according to some embodiments of the present disclosure, described with reference to FIG. 2.
FIG. 7 is a hardware configuration diagram of a computing device described in some embodiments of the present disclosure.
이하, 첨부된 도면을 참조하여 본 개시의 바람직한 실시예들을 상세히 설명한다. 본 발명의 이점 및 특징, 그리고 그것들을 달성하는 방법은 첨부되는 도면과 함께 상세하게 후술되어 있는 실시예들을 참조하면 명확해질 것이다. 그러나 본 발명의 기술적 사상은 이하의 실시예들에 한정되는 것이 아니라 서로 다른 다양한 형태로 구현될 수 있으며, 단지 이하의 실시예들은 본 발명의 기술적 사상을 완전하도록 하고, 본 발명이 속하는 기술분야에서 통상의 지식을 가진 자에게 본 발명의 범주를 완전하게 알려주기 위해 제공되는 것이며, 본 발명의 기술적 사상은 청구항의 범주에 의해 정의될 뿐이다. Hereinafter, preferred embodiments of the present disclosure will be described in detail with reference to the attached drawings. The advantages and features of the present invention, and methods for achieving them, will become clearer with reference to the embodiments described in detail below together with the attached drawings. However, the technical spirit of the present invention is not limited to the following embodiments and may be implemented in various different forms. The following embodiments are provided only to complete the technical spirit of the present invention and to fully inform those skilled in the art of the present invention of the scope of the present invention, and the technical spirit of the present invention is defined only by the scope of the claims.
본 개시를 설명함에 있어, 관련된 공지 구성 또는 기능에 대한 구체적인 설명이 본 발명의 요지를 흐릴 수 있다고 판단되는 경우에는 그 상세한 설명은 생략한다. In describing the present disclosure, if it is determined that a detailed description of a related known configuration or function may obscure the gist of the present invention, the detailed description will be omitted.
다른 정의가 없다면, 이하의 실시예들에서 사용되는 용어(기술 및 과학적 용어를 포함)는 본 개시가 속한 기술분야에서 통상의 지식을 가진 자에게 공통적으로 이해될 수 있는 의미로 사용될 수 있으나, 이는 관련 분야에 종사하는 기술자의 의도 또는 판례, 새로운 기술의 출현 등에 따라 달라질 수도 있다. 본 개시에서 사용된 용어는 실시예들을 설명하기 위한 것이며 본 개시의 범주를 제한하고자 하는 것은 아니다.Unless otherwise defined, the terms (including technical and scientific terms) used in the following examples may be used with meanings commonly understood by those of ordinary skill in the art to which this disclosure pertains; however, this may vary depending on the intentions of engineers working in the relevant field, precedents, the emergence of new technologies, etc. The terminology used in this disclosure is for the purpose of describing the embodiments and is not intended to limit the scope of this disclosure.
이하의 실시예들에서 사용되는 단수의 표현은 문맥상 명백하게 단수인 것으로 특정되지 않는 한, 복수의 개념을 포함한다. 또한, 복수의 표현은 문맥상 명백하게 복수인 것으로 특정되지 않는 한, 단수의 개념을 포함한다.In the following examples, singular expressions include plural concepts unless the context clearly specifies that they are singular. Furthermore, plural expressions include singular concepts unless the context clearly specifies that they are plural.
또한, 이하의 실시예들에서 사용되는 제1, 제2, A, B, (a), (b) 등의 용어는 어떤 구성요소를 다른 구성요소와 구별하기 위해 사용되는 것일 뿐, 그 용어에 의해 해당 구성요소의 본질이나 차례 또는 순서 등이 한정되지는 않는다.In addition, terms such as first, second, A, B, (a), (b), etc. used in the following embodiments are only used to distinguish certain components from other components, and the nature, order, or sequence of the components are not limited by the terms.
이하 첨부된 도면들을 참조하여 본 개시의 다양한 실시예들에 대하여 설명한다.Various embodiments of the present disclosure will be described below with reference to the attached drawings.
이하에서는, 도 1을 참조하여 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 시스템의 구성 및 동작을 설명한다. 도 1은 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 시스템의 구성 및 동작을 설명하기 위한 시스템 구성도이다.Hereinafter, the configuration and operation of a service provision system in a cloud environment according to some embodiments of the present disclosure will be described with reference to FIG. 1. FIG. 1 is a system configuration diagram for explaining the configuration and operation of a service provision system in a cloud environment according to some embodiments of the present disclosure.
도 1을 참조하면, 서비스 제공 시스템은 클라우드 플랫폼(10) 및 사용자 단말(20)을 포함하여 구성될 수 있다. 클라우드 플랫폼(10)은 서비스 서버(11), 제1 클라우드 서비스(12) 및 제2 클라우드 서비스(13)를 포함하여 구성될 수 있다. 다만, 본 개시의 범위가 이에 한정되는 것은 아니다. 경우에 따라서는, 서비스 제공 시스템이 도 1에 도시되지 않은 모듈/장치/시스템을 더 포함하는 형태로 구성될 수도 있다. 또는, 도 1에 도시된 구성요소들(10 내지 13 및 20) 중 적어도 일부가 제외된 형태로 서비스 제공 시스템이 구성될 수도 있다.Referring to FIG. 1, a service provision system may be configured to include a cloud platform (10) and a user terminal (20). The cloud platform (10) may include a service server (11), a first cloud service (12), and a second cloud service (13). However, the scope of the present disclosure is not limited thereto. In some cases, the service provision system may be configured to further include modules/devices/systems not illustrated in FIG. 1. Alternatively, the service provision system may be configured to exclude at least some of the components (10 to 13 and 20) illustrated in FIG. 1.
사용자 단말(20)은 클라우드 플랫폼(10)에서 제공되는 제1 클라우드 서비스(12)를 사용하는 사용자의 단말일 수 있다. 사용자는 사용자 단말(20)을 통해 제1 클라우드 서비스(12)에 접속할 수 있다. 이 경우, 사용자는 제1 클라우드 서비스(12) 상에서 동일한 클라우드 플랫폼(10) 상에서 제공되는 서비스인 제2 클라우드 서비스(13)를 사용하고자 하는 경우가 있을 수 있다.The user terminal (20) may be a user terminal using the first cloud service (12) provided on the cloud platform (10). The user may access the first cloud service (12) through the user terminal (20). In this case, the user may wish to use the second cloud service (13), which is a service provided on the same cloud platform (10) as the first cloud service (12).
서비스 서버(11)는 클라우드 플랫폼(10)에서 제공되는 클라우드 서비스(12 및 13)를 유지 및 관리할 수 있다. 이하에서는, 제1 클라우드 서비스(12) 및 제2 클라우드 서비스(13) 상호 간에 발생하는 트랜잭션은 서비스 서버(11)가 최초로 수신하고, 서비스 서버(11)가 해당 트랜잭션을 상호(12, 13)에게 전달하는 것으로 전제한다. 다만, 설명의 편의를 위해, 서비스 서버(11)에 대한 언급 없이 제1 클라우드 서비스(12)와 제2 클라우드 서비스(13) 상호 간에 직접적인 트랜잭션이 있는 것으로 설명될 수 있다.The service server (11) can maintain and manage cloud services (12 and 13) provided on the cloud platform (10). In the following, it is assumed that transactions occurring between the first cloud service (12) and the second cloud service (13) are initially received by the service server (11), and the service server (11) transmits the transaction to the other (12, 13). However, for convenience of explanation, it may be described as a direct transaction between the first cloud service (12) and the second cloud service (13) without any mention of the service server (11).
또한, 제1 클라우드 서비스(12)는 클라우드 플랫폼(10) 상에서 기존에 제공되는 서비스이고, 제2 클라우드 서비스(13)는 클라우드 플랫폼(10) 상에 새롭게 추가되어 서비스 인증 및 사용자의 액세스 권한에 대한 검증이 필요한 서비스임을 전제로 설명을 이어 나가기로 한다.In addition, the explanation will continue on the premise that the first cloud service (12) is a service that is already provided on the cloud platform (10), and the second cloud service (13) is a service that is newly added on the cloud platform (10) and requires service authentication and verification of user access rights.
서비스 서버(11)는 제1 클라우드 서비스(12)를 사용하는 사용자의 단말(20)로부터 제2 클라우드 서비스에 대한 액세스 요청을 수신할 수 있다.The service server (11) can receive an access request to the second cloud service from a terminal (20) of a user using the first cloud service (12).
서비스 서버(11)는 상기 액세스 요청을 수신하는 것에 응답하여, 제2 클라우드 서비스(13)에서 제1 클라우드 서비스(12)가 인증되었는지 여부를 판정할 수 있다. 제2 클라우드 서비스(13)의 사용자가 제1 클라우드 서비스(12)의 UI 및 REST API 호출이 가능하게 하려면, 제1 클라우드 서비스(12)와 제2 클라우드 서비스(13) 상호 간에 서비스 인증이 필요하다. 이에 대하여는, 도 3 및 도 4를 참조하여 자세하게 설명한다.In response to receiving the access request, the service server (11) can determine whether the first cloud service (12) is authenticated by the second cloud service (13). In order for the user of the second cloud service (13) to be able to call the UI and REST API of the first cloud service (12), service authentication is required between the first cloud service (12) and the second cloud service (13). This will be described in detail with reference to FIGS. 3 and 4.
제2 클라우드 서비스(13)에서 제1 클라우드 서비스(12)가 인증된 경우, 서비스 서버(11)는 제1 클라우드 서비스(12)에 사용자의 검증 요청을 송신할 수 있다. 제1 클라우드 서비스(12)의 사용자가 제1 클라우드 서비스(12) 상에서 제2 클라우드 서비스(13)를 사용하기 위해서는, 서비스 서버(11)가 제1 클라우드 서비스(12) 상에 저장된 사용자의 액세스 정보 등을 조회하고, 조회 결과 제2 클라우드 서비스(13)를 액세스할 수 있는 권한이 있어야 한다.When the first cloud service (12) is authenticated in the second cloud service (13), the service server (11) can transmit a user verification request to the first cloud service (12). In order for the user of the first cloud service (12) to use the second cloud service (13) on the first cloud service (12), the service server (11) must search for the user's access information stored on the first cloud service (12), and, as a result of the search, must have the authority to access the second cloud service (13).
제1 클라우드 서비스(12)는 상기 검증 요청에 응답하여, 서비스 서버(11)를 통해 제2 클라우드 서비스(13)에, 사용자가 제2 클라우드 서비스(13)에 대한 액세스 권한이 있는지 여부에 관한 사용자 검증 결과를 송신할 수 있다. 이에 대하여는, 도 5를 참조하여 자세하게 설명한다.In response to the verification request, the first cloud service (12) can transmit a user verification result regarding whether the user has access rights to the second cloud service (13) to the second cloud service (13) via the service server (11). This will be described in detail with reference to FIG. 5.
제2 클라우드 서비스(12)는 상기 사용자 검증 결과를 이용하여, 상기 사용자에 대하여, 제2 클라우드 서비스(12)에 대한 액세스 권한을 설정할 수 있다. 이에 대하여는, 도 6을 참조하여 자세하게 설명한다.The second cloud service (12) can use the user verification results to set access rights for the user to the second cloud service (12). This will be described in detail with reference to FIG. 6.
한편, 몇몇 실시예들에서, 서비스 제공 시스템의 구성요소들(10 내지 20)은 네트워크를 통해 통신할 수 있다. 여기서, 네트워크는 근거리 통신망(Local Area Network; LAN), 광역 통신망(Wide Area Network; WAN), 이동 통신망(mobile radio communication network), Wibro(Wireless Broadband Internet) 등과 같은 모든 종류의 유/무선 네트워크로 구현될 수 있다.Meanwhile, in some embodiments, components (10 to 20) of the service provision system may communicate via a network. Here, the network may be implemented as any type of wired/wireless network, such as a Local Area Network (LAN), a Wide Area Network (WAN), a mobile radio communication network, or Wibro (Wireless Broadband Internet).
상술한 클라우드 플랫폼(10)의 구성요소들 각각은 적어도 하나의 컴퓨팅 장치로 구현될 수 있다. 예를 들어, 클라우드 플랫폼(10)의 모든 기능이 하나의 컴퓨팅 장치에서 구현될 수도 있고, 클라우드 플랫폼(10)의 제1 기능은 제1 컴퓨팅 장치에서 구현되고 제2 기능은 제2 컴퓨팅 장치에서 구현될 수도 있다. 또는, 클라우드 플랫폼(10)의 특정 기능이 복수의 컴퓨팅 장치에서 구현될 수도 있다.Each of the components of the cloud platform (10) described above may be implemented on at least one computing device. For example, all functions of the cloud platform (10) may be implemented on a single computing device, or a first function of the cloud platform (10) may be implemented on a first computing device and a second function may be implemented on a second computing device. Alternatively, specific functions of the cloud platform (10) may be implemented on multiple computing devices.
이하에서는, 이해의 편의를 제공하기 위해, 후술될 방법들의 모든 단계/동작이 상술한 서비스 서버(11)에서 수행되는 것을 가정하여 설명을 이어가도록 한다. 따라서, 특정 단계/동작의 주체가 생략된 경우, 서비스 서버(11)에서 수행되는 것으로 이해될 수 있다. 다만, 실제 환경에서는 후술될 방법의 일부 단계/동작이 다른 컴퓨팅 장치에서 수행될 수도 있다.For ease of understanding, the following description assumes that all steps/operations of the methods described below are performed on the aforementioned service server (11). Therefore, if the subject of a specific step/operation is omitted, it can be understood that it is performed on the service server (11). However, in an actual environment, some steps/operations of the methods described below may be performed on other computing devices.
본 실시예에 따르면, 클라우드 플랫폼(10) 상에서 제공되는 서비스가 추가된 경우, 사용자가 기존에 제공되는 서비스인 제1 클라우드 서비스(12)에서 새롭게 제공되는 서비스인 제2 클라우드 서비스(13)에 별도의 가입이나 로그인 없이 쉽게 실행할 수 있다는 장점이 있다. 따라서, 본 실시예에 따르면, 클라우드 플랫폼(10)에서 제공되는 다양한 클라우드 서비스들에 대한 확장성 및 사용자 편의성이 증대될 수 있다는 장점이 있다.According to this embodiment, when a service provided on a cloud platform (10) is added, there is an advantage in that a user can easily execute a newly provided second cloud service (13) from an existing first cloud service (12) without separate registration or log-in. Therefore, according to this embodiment, there is an advantage in that the scalability and user convenience of various cloud services provided on the cloud platform (10) can be increased.
이하에서는, 도 2를 참조하여, 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 방법의 동작을 설명한다. 도 2는 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 방법의 동작을 설명하기 위한 신호 흐름도이다. Hereinafter, with reference to FIG. 2, the operation of a service provision method in a cloud environment according to some embodiments of the present disclosure will be described. FIG. 2 is a signal flow diagram illustrating the operation of a service provision method in a cloud environment according to some embodiments of the present disclosure.
도 2를 참조하면, 제1 클라우드 서비스(12)를 사용하는 사용자의 사용자 단말(20)은 서비스 서버(11)에 제2 클라우드 서비스(13)에 대한 액세스 요청을 송신할 수 있다(S100). 사용자는 사용자 단말(20)에 표시되는 제1 클라우드 서비스(12)의 UI 또는 REST API를 통해 제2 클라우드 서비스(13)에 대한 액세스 요청을 송신할 수 있다. REST API(Representational State Transfer API)는 웹에서 사용자 단말(20)가 서비스 서버(11) 간에 데이터를 주고받을 수 있도록 HTTP 프로토콜을 기반으로 설계된 응용 프로그램 인터페이스이다. 본 개시가 속하는 기술 분야의 통상의 기술자는 이미 숙지하였을 사항인 바, 자세한 설명은 생략한다.Referring to FIG. 2, a user terminal (20) of a user using a first cloud service (12) can transmit an access request for a second cloud service (13) to a service server (11) (S100). The user can transmit an access request for the second cloud service (13) through the UI of the first cloud service (12) displayed on the user terminal (20) or through a REST API. The REST API (Representational State Transfer API) is an application program interface designed based on the HTTP protocol to enable a user terminal (20) to exchange data between a service server (11) on the web. Since this is something that a person skilled in the art to which the present disclosure pertains is already familiar with, a detailed description thereof will be omitted.
이후, 서비스 서버(11)는 상기 액세스 요청을 수신하는 것에 응답하여, 제2 클라우드 서비스(13)에서 제1 클라우드 서비스(12)가 인증되었는지 여부를 판정할 수 있다(S200). 제2 클라우드 서비스(13)의 사용자가 제1 클라우드 서비스(12)의 UI 및 REST API 호출이 가능하게 하려면, 제1 클라우드 서비스(12)와 제2 클라우드 서비스(13) 상호 간에 서비스 인증이 필요하다. 따라서, 서비스 서버(11)는 제2 클라우드 서비스(13)에서 제1 클라우드 서비스(12)가 인증되었는지 여부를 판정하고, 만약 제2 클라우드 서비스(13)에서 제1 클라우드 서비스(12)가 인증되지 않은 경우, 소정의 절차를 거쳐 인증을 수행할 수 있다. 이에 대하여는, 도 3 및 도 4를 참조하여 자세하게 설명한다.Thereafter, in response to receiving the access request, the service server (11) can determine whether the first cloud service (12) is authenticated in the second cloud service (13) (S200). In order for the user of the second cloud service (13) to be able to call the UI and REST API of the first cloud service (12), service authentication is required between the first cloud service (12) and the second cloud service (13). Accordingly, the service server (11) determines whether the first cloud service (12) is authenticated in the second cloud service (13), and if the first cloud service (12) is not authenticated in the second cloud service (13), authentication can be performed through a predetermined procedure. This will be described in detail with reference to FIGS. 3 and 4.
이후, 서비스 서버(11)는 제2 클라우드 서비스(13)에 S200 단계의 판정 결과를 송신할 수 있다(S201). Thereafter, the service server (11) can transmit the judgment result of step S200 to the second cloud service (13) (S201).
이에, 제2 클라우드 서비스(13)는 서비스 서버(11)에 사용자의 검증 요청을 송신할 수 있다(S300). 사용자의 검증 요청은 제1 클라우드 서비스(12)에 발급된 인증서에 포함된 공개키로 암호화된, 제1 클라우드 서비스(12)의 고유 식별 정보 및 제1 클라우드 서비스(12)에 대한 사용자의 제1 사용자 인증 토큰(Authentication Token)에 관한 사용자 검증 요청 데이터를 포함할 수 있다. 제1 클라우드 서비스(12)의 고유 식별 정보는 제1 클라우드 서비스(12)를 식별하기 위해 필요한 정보일 수 있다. 제1 사용자 인증 토큰은 제1 클라우드 서비스(12) 상에서의 사용자의 고유 식별 정보(ID) 및 사용자의 서비스에 대한 액세스 권한 등에 관한 정보를 획득하기 위해 필요한 정보일 수 있다.Accordingly, the second cloud service (13) may transmit a user verification request to the service server (11) (S300). The user verification request may include user verification request data regarding the unique identification information of the first cloud service (12) and the user's first user authentication token for the first cloud service (12), encrypted with a public key included in a certificate issued to the first cloud service (12). The unique identification information of the first cloud service (12) may be information necessary to identify the first cloud service (12). The first user authentication token may be information necessary to obtain information regarding the user's unique identification information (ID) and the user's access rights to the service on the first cloud service (12).
서비스 서버(11)는 제1 클라우드 서비스(12)에 상기 사용자의 검증 요청을 송신할 수 있다(S301).The service server (11) can transmit the user's verification request to the first cloud service (12) (S301).
제1 클라우드 서비스(12)는 상기 사용자의 검증 요청에 응답하여, 서비스 서버(11)에 사용자가 제2 클라우드 서비스(13)에 대한 액세스 권한이 있는지 여부에 관한 사용자 검증 결과를 송신할 수 있다(S400). 이에 대하여는, 도 5를 참조하여 자세하게 설명한다.In response to the user's verification request, the first cloud service (12) can transmit the user verification result regarding whether the user has access rights to the second cloud service (13) to the service server (11) (S400). This will be described in detail with reference to FIG. 5.
서비스 서버(11)는 제2 클라우드 서비스(13)에 상기 사용자 검증 결과를 송신할 수 있다(S401).The service server (11) can transmit the user verification result to the second cloud service (13) (S401).
제2 클라우드 서비스(13)는 상기 사용자 검증 결과를 이용하여, 사용자에 대하여, 제2 클라우드 서비스(13)에 대한 액세스 권한을 설정할 수 있다(S500). 이에 대하여는, 도 6을 참조하여 자세하게 설명한다.The second cloud service (13) can use the user verification results to set access rights for the user to the second cloud service (13) (S500). This will be described in detail with reference to FIG. 6.
이후, 제2 클라우드 서비스(13)는 서비스 서버(11)에 상기 액세스 권한에 관한 정보를 송신할 수 있다(S501).Thereafter, the second cloud service (13) can transmit information regarding the access rights to the service server (11) (S501).
이후, 서비스 서버(11)는 사용자 단말(20)의 제2 클라우드 서비스(13)에 대한 액세스 요청에 대한 응답으로서, 상기 액세스 권한에 따라 제2 클라우드 서비스(13)에 대한 액세스 허용 여부를 결정할 수 있다(S600). 즉, 제1 사용자가 제1 클라우드 서비스(12)에서 제2 클라우드 서비스(13)에 액세스할 권한이 있는 경우, 서비스 서버(11)는 제1 사용자의 사용자 단말에 대하여 제2 클라우드 서비스(13)로의 액세스를 허용할 수 있다. 반면, 제2 사용자가 제1 클라우드 서비스(12)에서 제2 클라우드 서비스(13)에 액세스할 권한이 없는 경우, 서비스 서버(11)는 제1 사용자의 사용자 단말에 대하여 제2 클라우드 서비스(13)로의 액세스를 거부하고, 제2 클라우드 서비스(13)로의 접속을 불허할 수 있다.Thereafter, the service server (11) may determine whether to allow access to the second cloud service (13) based on the access right in response to the user terminal (20)'s request for access to the second cloud service (13) (S600). That is, if the first user has the right to access the second cloud service (13) from the first cloud service (12), the service server (11) may allow the user terminal of the first user to access the second cloud service (13). On the other hand, if the second user does not have the right to access the second cloud service (13) from the first cloud service (12), the service server (11) may deny the user terminal of the first user access to the second cloud service (13) and disallow access to the second cloud service (13).
본 실시예에 따르면, 클라우드 플랫폼(10) 상에서 제공되는 서비스가 추가된 경우, 사용자가 기존에 제공되는 서비스인 제1 클라우드 서비스(12)에서 새롭게 제공되는 서비스인 제2 클라우드 서비스(13)에 별도의 가입이나 로그인 없이 쉽게 실행할 수 있다는 장점이 있다. 따라서, 본 실시예에 따르면, 클라우드 플랫폼(10)에서 제공되는 다양한 클라우드 서비스들에 대한 확장성 및 사용자 편의성이 증대될 수 있다는 장점이 있다.According to this embodiment, when a service provided on a cloud platform (10) is added, there is an advantage in that a user can easily execute a newly provided second cloud service (13) from an existing first cloud service (12) without separate registration or log-in. Therefore, according to this embodiment, there is an advantage in that the scalability and user convenience of various cloud services provided on the cloud platform (10) can be increased.
또한, 본 실시예에 따르면, 제1 클라우드 서비스(12)와 제2 클라우드 서비스(13)의 연동을 위한 서비스 인증 과정을 사람의 개입 없이 M2M(Machine To Machine) 방식으로 수행할 수 있으며, 원격으로 서비스 인증에 필요한 정보를 설정할 수 있다는 장점이 있다.In addition, according to this embodiment, the service authentication process for linking the first cloud service (12) and the second cloud service (13) can be performed in an M2M (Machine To Machine) manner without human intervention, and there is an advantage in that information required for service authentication can be set remotely.
이하에서는, 제1 클라우드 서비스(12) 및 제2 클라우드 서비스(13) 상호 간에 발생하는 트랜잭션은 서비스 서버(11)가 최초로 수신하고, 서비스 서버(11)가 해당 트랜잭션을 상호(12, 13)에게 전달하는 것으로 전제한다. 다만, 설명의 편의를 위해, 서비스 서버(11)에 대한 언급 없이 제1 클라우드 서비스(12)와 제2 클라우드 서비스(13) 상호 간에 직접적인 트랜잭션이 있는 것으로 설명될 수 있다.Hereinafter, it is assumed that a transaction occurring between a first cloud service (12) and a second cloud service (13) is initially received by the service server (11), and the service server (11) transmits the transaction to each other (12, 13). However, for convenience of explanation, it may be explained that there is a direct transaction between the first cloud service (12) and the second cloud service (13) without any mention of the service server (11).
또한, 제1 클라우드 서비스(12)는 클라우드 플랫폼(10) 상에서 기존에 제공되는 서비스이고, 제2 클라우드 서비스(13)는 클라우드 플랫폼(10) 상에 새롭게 추가되어 서비스 인증 및 사용자의 액세스 권한에 대한 검증이 필요한 서비스임을 전제로 설명을 이어 나가기로 한다.In addition, the explanation will continue on the premise that the first cloud service (12) is a service that is already provided on the cloud platform (10), and the second cloud service (13) is a service that is newly added on the cloud platform (10) and requires service authentication and verification of user access rights.
이하에서는, 도 3을 참조하여, 본 개시의 몇몇 실시예들에 따른 클라우드 서비스 상호 간 서비스 인증 방법을 설명한다. 도 3은 도 2를 참조하여 설명한, 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 방법의 세부 동작을 설명하기 위한 상세 순서도이다.Hereinafter, with reference to FIG. 3, a method for mutually authenticating cloud services according to some embodiments of the present disclosure will be described. FIG. 3 is a detailed flowchart illustrating the detailed operations of a method for providing services in a cloud environment according to some embodiments of the present disclosure, as described with reference to FIG. 2.
도 3을 참조하면, 제2 클라우드 서비스(13)에서 제1 클라우드 서비스(12)가 인증되지 않은 경우, 서비스 서버(11)는 제2 클라우드 서비스(13)로부터 제1 클라우드 서비스(12)에 대한 인증 요청을 수신할 수 있다(S210).Referring to FIG. 3, if the first cloud service (12) is not authenticated in the second cloud service (13), the service server (11) can receive an authentication request for the first cloud service (12) from the second cloud service (13) (S210).
서비스 서버(11)는 상기 인증 요청에 응답하여, 제2 클라우드 서비스(13)에 발급된 인증서 및 공인 IP 정보를 이용하여, 제1 클라우드 서비스(12)에 대한 인증 요청 데이터를 생성할 수 있다. 상기 인증 요청 데이터는 제1 클라우드 서비스(12)로 송신되는 것으로서, 제2 클라우드 서비스(13)의 인증서 및 공인 IP 정보를 포함할 수 있다. 제2 클라우드 서비스(13)의 인증서는 제2 클라우드 서비스(13)에 발급된 인증서의 진위 여부를 판정하는데 이용될 수 있다. 제2 클라우드 서비스(13)의 공인 IP 정보는 제2 클라우드 서비스(13)가 액세스하는 IP 정보를 식별하기 위해 이용될 수 있다. 상기 공인 IP 정보는 제2 클라우드 서비스(13)에 한 번 할당되면, 변경되지 않는 IP일 수 있다.The service server (11) may, in response to the authentication request, generate authentication request data for the first cloud service (12) using the certificate and public IP information issued to the second cloud service (13). The authentication request data is transmitted to the first cloud service (12) and may include the certificate and public IP information of the second cloud service (13). The certificate of the second cloud service (13) may be used to determine the authenticity of the certificate issued to the second cloud service (13). The public IP information of the second cloud service (13) may be used to identify IP information accessed by the second cloud service (13). The public IP information may be an IP that does not change once assigned to the second cloud service (13).
이후, 서비스 서버(11)는 상기 인증 요청 데이터를 제1 클라우드 서비스(12)의 인증서에 포함된 공개키로 암호화할 수 있다. 이후, 서비스 서버(11)는 제1 클라우드 서비스(12)의 공인 IP로 상기 암호화된 인증 요청 데이터를 송신할 수 있다(S212). 상기 인증 요청 데이터가 제1 클라우드 서비스(12)의 인증서에 포함된 공개키로 암호화됨으로써, 제1 클라우드 서비스(12)에게 상기 인증 요청 데이터가 전달될 수 있다. 만약 제1 클라우드 서비스(12) 외 다른 주체가 상기 인증 요청 데이터를 전달받은 경우, 다른 주체는 제1 클라우드 서비스(12)의 비밀키를 취득할 수 없으므로, 상기 인증 요청이 해킹 등의 사이버 공격으로 인해 다른 주체에게 전달된 경우라도, 다른 주체가 상기 인증 요청 데이터를 확인할 수 없다. 따라서, 클라우드 플랫폼(10)의 보안성이 향상될 수 있다.Thereafter, the service server (11) can encrypt the authentication request data with the public key included in the certificate of the first cloud service (12). Thereafter, the service server (11) can transmit the encrypted authentication request data to the public IP of the first cloud service (12) (S212). Since the authentication request data is encrypted with the public key included in the certificate of the first cloud service (12), the authentication request data can be transmitted to the first cloud service (12). If an entity other than the first cloud service (12) receives the authentication request data, the other entity cannot obtain the secret key of the first cloud service (12), and therefore, even if the authentication request is transmitted to another entity due to a cyber attack such as hacking, the other entity cannot confirm the authentication request data. Therefore, the security of the cloud platform (10) can be improved.
이후, 제1 클라우드 서비스(12)는 제1 클라우드 서비스의 비밀키를 이용하여, 상기 암호화된 인증 요청 데이터를 복호화할 수 있다. 이후, 제1 클라우드 서비스(12)는 상기 인증 요청 데이터에 포함된 제2 클라우드 서비스(13)의 인증서의 인증 기관(Certificate Authority)과 클라우드 플랫폼(10)에 저장된 제2 클라우드 서비스 인증서의 인증 기관이 일치하는지 여부를 검증할 수 있다(S213). S213 단계와 같이 인증 기관의 일치 여부가 검증됨으로써, 상기 인증 요청 데이터에 포함된 제2 클라우드 서비스(13)의 인증서의 진위 여부가 판정될 수 있다. 즉, S213 단계의 인증 기관의 일치 여부는 상기 인증 요청 데이터에 포함된 제2 클라우드 서비스(13)의 인증서의 진위 여부를 판정하는 인증 요소일 수 있다.Thereafter, the first cloud service (12) can decrypt the encrypted authentication request data using the secret key of the first cloud service. Thereafter, the first cloud service (12) can verify whether the certificate authority of the certificate of the second cloud service (13) included in the authentication request data matches the certificate authority of the second cloud service certificate stored in the cloud platform (10) (S213). By verifying whether the certificate authorities match as in step S213, the authenticity of the certificate of the second cloud service (13) included in the authentication request data can be determined. That is, whether the certificate authorities match in step S213 can be an authentication factor for determining the authenticity of the certificate of the second cloud service (13) included in the authentication request data.
S213 단계의 검증 결과, 상기 인증 요청 데이터에 포함된 제2 클라우드 서비스(13)의 인증서의 인증 기관과 클라우드 플랫폼(10)에 저장된 제2 클라우드 서비스 인증서의 인증 기관이 일치하는 경우, 제1 클라우드 서비스(12)는 제2 클라우드 서비스(13)에서 제1 클라우드 서비스(12)가 제공될 수 있도록 제1 클라우드 서비스(12)의 인증 대상에 제2 클라우드 서비스(13)를 추가할 수 있다(S214). 즉, 이 경우, 제1 클라우드 서비스(12)는 제2 클라우드 서비스(13) 상에서 제2 클라우드 서비스(12)가 실행될 수 있도록 제2 클라우드 서비스(13)에 대한 서비스 상호(12, 13) 간 서비스 인증 작업을 수행할 수 있다.As a result of the verification in step S213, if the certification authority of the certificate of the second cloud service (13) included in the authentication request data matches the certification authority of the second cloud service certificate stored in the cloud platform (10), the first cloud service (12) can add the second cloud service (13) to the authentication target of the first cloud service (12) so that the first cloud service (12) can be provided on the second cloud service (13) (S214). That is, in this case, the first cloud service (12) can perform a service authentication operation between services (12, 13) for the second cloud service (13) so that the second cloud service (12) can be executed on the second cloud service (13).
일 실시예에서, 서비스 서버(11)는 제1 클라우드 서비스의 저장 공간(미도시)에 상기 인증 요청 데이터에 포함된 제2 클라우드 서비스의 인증서 및 공인 IP 정보를 저장할 수 있다.In one embodiment, the service server (11) may store the certificate and public IP information of the second cloud service included in the authentication request data in the storage space (not shown) of the first cloud service.
본 실시예에 따르면, 제1 클라우드 서비스(12)와 제2 클라우드 서비스(13)의 연동을 위한 서비스 인증 과정을 사람의 개입 없이 M2M(Machine To Machine) 방식으로 수행할 수 있으며, 원격으로 서비스 인증에 필요한 정보를 설정할 수 있다는 장점이 있다.According to this embodiment, the service authentication process for linking the first cloud service (12) and the second cloud service (13) can be performed in an M2M (Machine To Machine) manner without human intervention, and there is an advantage in that information required for service authentication can be set remotely.
또한, 본 실시예에 따르면, 클라우드 플랫폼(10)에서 제공되는 서비스 간의 인증 과정에서 동일한 인증 기관에 의해 서명된 인증서 기반의 안전한 서비스 인증 과정을 수행할 수 있다. 따라서, 본 실시예에 따르면, 인증서의 진위 여부를 용이하게 판정할 수 있음과 동시에 인증서의 진위 여부 또한 담보할 수 있다는 장점이 있다.Furthermore, according to this embodiment, a secure service authentication process based on a certificate signed by the same certification authority can be performed during the authentication process between services provided on the cloud platform (10). Therefore, according to this embodiment, the authenticity of a certificate can be easily determined, while also ensuring its authenticity.
제2 클라우드 서비스(13)에서 제1 클라우드 서비스(12)가 인증된 이후에 제2 클라우드 서비스(13)의 인증서 또는 공인 IP 등 인증 정보가 변경되는 경우가 있을 수 있다. 이 경우, 제2 클라우드 서비스(13)의 인증 정보가 제1 클라우드 서비스(12)에서 갱신되어야만, 제1 클라우드 서비스(12)에서 제2 클라우드 서비스(13)가 제공될 수 있고, 반대의 경우도 마찬가지이다.After the first cloud service (12) is authenticated by the second cloud service (13), there may be cases where the authentication information, such as the certificate or public IP of the second cloud service (13), is changed. In this case, the authentication information of the second cloud service (13) must be updated in the first cloud service (12) so that the second cloud service (13) can be provided by the first cloud service (12), and vice versa.
이하에서는, 도 4를 참조하여, 본 개시의 몇몇 실시예들에 따른 클라우드 서비스의 인증 정보가 변경된 경우, 클라우드 서비스 간의 인증 정보를 갱신하는 방법에 관하여 설명한다. 도 4는 도 2를 참조하여 설명한, 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 방법의 세부 동작을 설명하기 위한 상세 순서도이다.Hereinafter, with reference to FIG. 4, a method for updating authentication information between cloud services when authentication information of a cloud service has changed according to some embodiments of the present disclosure will be described. FIG. 4 is a detailed flowchart illustrating the detailed operations of a service provision method in a cloud environment according to some embodiments of the present disclosure, as described with reference to FIG. 2.
도 4를 참조하면, 제2 클라우드 서비스(13)의 인증서 또는 공인 IP 정보가 변경된 경우, 서비스 서버(11)는 제2 클라우드 서비스(13)로부터 제1 클라우드 서비스(12)에 대한 인증 정보 갱신 요청을 수신할 수 있다(S220).Referring to FIG. 4, when the certificate or public IP information of the second cloud service (13) is changed, the service server (11) can receive a request for renewal of authentication information for the first cloud service (12) from the second cloud service (13) (S220).
서비스 서버(11)는 상기 인증 정보 갱신 요청에 응답하여, 제2 클라우드 서비스(13)의 변경된 인증서 또는 공인 IP 정보를 이용하여, 제1 클라우드 서비스(12)에 대한 인증 갱신 요청 데이터를 생성할 수 있다(S221). 상기 인증 갱신 요청 데이터는 제1 클라우드 서비스(12)로 송신되는 것으로서, 제2 클라우드 서비스(13)의 변경된 인증서 및 공인 IP 정보를 포함할 수 있다. 제2 클라우드 서비스(13)의 변경된 인증서는 제2 클라우드 서비스(13)에 발급된 인증서의 진위 여부를 판정하는데 이용될 수 있다. 제2 클라우드 서비스(13)의 변경된 공인 IP 정보는 제2 클라우드 서비스(13)가 액세스하는 IP 정보를 식별하기 위해 이용될 수 있다. 상기 공인 IP 정보는 제2 클라우드 서비스(13)에 한 번 할당되면, 변경되지 않는 IP이지만, 외부 사정에 의해 변경되는 경우에 변경된 공인 IP 정보에 대한 인증이 필요하다.In response to the authentication information renewal request, the service server (11) may generate authentication renewal request data for the first cloud service (12) using the changed certificate or public IP information of the second cloud service (13) (S221). The authentication renewal request data is transmitted to the first cloud service (12) and may include the changed certificate and public IP information of the second cloud service (13). The changed certificate of the second cloud service (13) may be used to determine the authenticity of the certificate issued to the second cloud service (13). The changed public IP information of the second cloud service (13) may be used to identify the IP information accessed by the second cloud service (13). The public IP information is an IP that does not change once assigned to the second cloud service (13), but if it changes due to external circumstances, authentication of the changed public IP information is required.
이후, 제2 클라우드 서비스(13)는 제2 클라우드 서비스의 변경 전 인증서의 비밀키를 이용하여, 상기 인증 갱신 요청 데이터에 서명을 수행하고, 서명 인증 갱신 요청 데이터를 생성할 수 있다(S222). 제2 클라우드 서비스(13)는 서비스 서버(11)에 상기 서명 인증 갱신 요청 데이터를 송신할 수 있다.Thereafter, the second cloud service (13) may use the private key of the certificate of the second cloud service before the change to sign the authentication renewal request data and generate signature authentication renewal request data (S222). The second cloud service (13) may transmit the signature authentication renewal request data to the service server (11).
이후, 서비스 서버(11)는 상기 서명 인증 갱신 요청 데이터를 제1 클라우드 서비스(12)의 인증서에 포함된 공개키로 암호화할 수 있다. 서비스 서버(11)는 제1 클라우드 서비스(12)의 공인 IP로 상기 암호화된 서명 인증 갱신 요청 데이터를 송신할 수 있다(S223).Thereafter, the service server (11) can encrypt the signature authentication renewal request data with a public key included in the certificate of the first cloud service (12). The service server (11) can transmit the encrypted signature authentication renewal request data to the public IP of the first cloud service (12) (S223).
제1 클라우드 서비스(12)는 제1 클라우드 서비스(12)의 비밀키를 이용하여, 상기 서명 인증 갱신 요청 데이터를 복호화할 수 있다. 제1 클라우드 서비스(12)는 제2 클라우드 서비스(13)의 변경 전 인증서의 공개키를 이용하여, 성가 서명 인증 갱신 요청 데이터를 검증할 수 있다. 즉, 제1 클라우드 서비스(12)는 제2 클라우드 서비스(13)가 인증 갱신 요청 데이터에 제2 클라우드 서비스(13)의 변경 전의 인증서의 비밀키로 서명한 서명 인증 갱신 요청 데이터인지 여부를 확인하기 위해, 제2 클라우드 서비스(13)의 변경 전 인증서의 공개키를 이용하여, 성가 서명 인증 갱신 요청 데이터를 검증할 수 있다.The first cloud service (12) can decrypt the signature authentication renewal request data using the secret key of the first cloud service (12). The first cloud service (12) can verify the signature authentication renewal request data using the public key of the certificate before the change of the second cloud service (13). That is, the first cloud service (12) can verify the signature authentication renewal request data using the public key of the certificate before the change of the second cloud service (13) to confirm whether the signature authentication renewal request data is signed by the second cloud service (13) using the secret key of the certificate before the change of the second cloud service (13).
이후, 제1 클라우드 서비스(12)는 상기 서명 인증 갱신 요청 데이터에 포함된 제2 클라우드 서비스(13)의 인증서의 인증 기관과 클라우드 플랫폼(10)에 저장된 제2 클라우드 서비스(13)의 인증서의 인증 기관이 일치하는지 여부를 검증할 수 있다(S224). S224 단계와 같이 인증 기관의 일치 여부가 검증됨으로써, 상기 인증 갱신 요청 데이터에 포함된 제2 클라우드 서비스(13)의 인증서의 진위 여부가 판정될 수 있다. 즉, S224 단계의 인증 기관의 일치 여부는 상기 인증 갱신 요청 데이터에 포함된 제2 클라우드 서비스(13)의 인증서의 진위 여부를 판정하는 인증 요소일 수 있다.Thereafter, the first cloud service (12) can verify whether the certification authority of the certificate of the second cloud service (13) included in the signature authentication renewal request data matches the certification authority of the certificate of the second cloud service (13) stored in the cloud platform (10) (S224). By verifying whether the certification authorities match as in step S224, the authenticity of the certificate of the second cloud service (13) included in the authentication renewal request data can be determined. That is, whether the certification authorities match in step S224 can be an authentication factor for determining the authenticity of the certificate of the second cloud service (13) included in the authentication renewal request data.
S224 단계의 검증 결과, 상기 인증 갱신 요청 데이터에 포함된 제2 클라우드 서비스(13)의 인증서의 인증 기관과 클라우드 플랫폼(10)에 저장된 제2 클라우드 서비스 인증서의 인증 기관이 일치하는 경우, 제1 클라우드 서비스(12)는 제2 클라우드 서비스(13)에서 제1 클라우드 서비스(12)가 제공될 수 있도록 제1 클라우드 서비스(12)의 인증 대상에 제2 클라우드 서비스(13)를 추가할 수 있다(S214). 즉, 이 경우, 제1 클라우드 서비스(12)는 제2 클라우드 서비스(13) 상에서 제2 클라우드 서비스(12)가 실행될 수 있도록 제2 클라우드 서비스(13)에 대한 서비스 상호(12, 13) 간 서비스 인증 작업을 수행할 수 있다.As a result of the verification in step S224, if the certification authority of the certificate of the second cloud service (13) included in the authentication renewal request data matches the certification authority of the second cloud service certificate stored in the cloud platform (10), the first cloud service (12) can add the second cloud service (13) to the authentication target of the first cloud service (12) so that the first cloud service (12) can be provided on the second cloud service (13) (S214). That is, in this case, the first cloud service (12) can perform a service authentication operation between services (12, 13) for the second cloud service (13) so that the second cloud service (12) can be executed on the second cloud service (13).
일 실시예에서, 서비스 서버(11)는 제1 클라우드 서비스의 저장 공간(미도시)에 상기 인증 갱신 요청 데이터에 포함된 제2 클라우드 서비스의 변경된 인증서 및 공인 IP 정보를 저장할 수 있다.In one embodiment, the service server (11) may store the changed certificate and public IP information of the second cloud service included in the authentication renewal request data in the storage space (not shown) of the first cloud service.
본 실시예에 따르면, 제1 클라우드 서비스(12)와 제2 클라우드 서비스(13)의 연동을 위한 서비스 인증 과정을 사람의 개입 없이 M2M(Machine To Machine) 방식으로 수행할 수 있으며, 원격으로 서비스 인증에 필요한 정보를 설정할 수 있다는 장점이 있다.According to this embodiment, the service authentication process for linking the first cloud service (12) and the second cloud service (13) can be performed in an M2M (Machine To Machine) manner without human intervention, and there is an advantage in that information required for service authentication can be set remotely.
또한, 본 실시예에 따르면, 클라우드 플랫폼(10)에서 제공되는 서비스 간의 인증 과정에서 동일한 인증 기관에 의해 서명된 인증서 기반의 안전한 서비스 인증 과정을 수행할 수 있다. 따라서, 본 실시예에 따르면, 인증서의 진위 여부를 용이하게 판정할 수 있음과 동시에 인증서의 진위 여부 또한 담보할 수 있다는 장점이 있다.Furthermore, according to this embodiment, a secure service authentication process based on a certificate signed by the same certification authority can be performed during the authentication process between services provided on the cloud platform (10). Therefore, according to this embodiment, the authenticity of a certificate can be easily determined, while also ensuring its authenticity.
또한, 본 실시예에 따르면, 클라우드 플랫폼(10) 내 하나의 클라우드 서비스의 인증서 또는 공인 IP 정보가 변경된 경우, 해당 클라우드 서비스의 인증 정보가 클라우드 플랫폼(10) 내 다른 클라우드 서비스에서 사람의 개입 없이 자동으로 갱신될 수 있다는 장점이 있다. 따라서, 본 실시예에 따르면, 클라우드 플랫폼(10) 내 서비스의 확장성이 향상될 수 있다.Additionally, according to this embodiment, if the certificate or public IP information of one cloud service within the cloud platform (10) is changed, the authentication information of that cloud service can be automatically updated in other cloud services within the cloud platform (10) without human intervention, which is advantageous. Therefore, according to this embodiment, the scalability of services within the cloud platform (10) can be improved.
한편, 도 2를 참조하여 설명한 바와 같이, 제2 클라우드 서비스(13)는 서비스 서버(11)에 사용자의 검증 요청을 송신할 수 있다(S300). 상기 사용자의 검증 요청은 제1 클라우드 서비스(12)의 인증서에 포함된 공개키로 암호화된, 제1 클라우드 서비스(12)의 고유 식별 정보 및 제1 클라우드 서비스(12)에 대한 사용자의 제1 사용자 인증 토큰에 관한 사용자 검증 요청 데이터를 포함할 수 있다. 제1 클라우드 서비스(12)의 고유 식별 정보는 제1 클라우드 서비스(12)를 식별하기 위해 필요한 정보일 수 있다. 제1 사용자 인증 토큰은 제1 클라우드 서비스(12) 상에서의 사용자의 고유 식별 정보(ID) 및 사용자의 서비스에 대한 액세스 권한 등에 관한 정보를 획득하기 위해 필요한 정보일 수 있다.Meanwhile, as described with reference to FIG. 2, the second cloud service (13) may transmit a user verification request to the service server (11) (S300). The user verification request may include user verification request data regarding the user's first user authentication token for the first cloud service (12) and unique identification information of the first cloud service (12) encrypted with a public key included in the certificate of the first cloud service (12). The unique identification information of the first cloud service (12) may be information necessary to identify the first cloud service (12). The first user authentication token may be information necessary to obtain information regarding the user's unique identification information (ID) on the first cloud service (12) and the user's access rights to the service.
이하에서는, 도 5를 참조하여, 본 개시의 몇몇 실시예들에 따른 사용자가 제2 클라우드 서비스에 대한 액세스 권한이 있는지 여부에 관한 사용자 검증 결과를 생성하는 방법에 관하여 설명한다. 도 5는 도 2를 참조하여 설명한, 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 방법의 세부 동작을 설명하기 위한 상세 순서도이다.Hereinafter, with reference to FIG. 5, a method for generating a user verification result regarding whether a user has access to a second cloud service according to some embodiments of the present disclosure is described. FIG. 5 is a detailed flowchart illustrating the detailed operations of a service provision method in a cloud environment according to some embodiments of the present disclosure, as described with reference to FIG. 2.
도 5를 참조하면, 제1 클라우드 서비스(12)는 제1 클라우드 서비스(12)의 인증서에 포함된 비밀키를 이용하여, 상기 사용자 검증 요청 데이터를 복호화할 수 있다(S410).Referring to FIG. 5, the first cloud service (12) can decrypt the user verification request data using the secret key included in the certificate of the first cloud service (12) (S410).
이후, 제1 클라우드 서비스(12)는 상기 사용자 검증 요청 데이터에 포함된 제1 사용자 인증 토큰을 이용하여, 사용자의 정보를 획득할 수 있다(S411).Thereafter, the first cloud service (12) can obtain the user's information by using the first user authentication token included in the user verification request data (S411).
제1 클라우드 서비스(12)는 상기 사용자의 정보를 이용하여, 제2 클라우드 서비스(13)에 대한 사용자의 액세스 권한 정보를 획득할 수 있다(S412). 상기 제1 사용자 인증 토큰은 제1 클라우드 서비스(12) 상에서의 사용자의 고유 식별 정보(ID) 및 사용자의 서비스에 대한 액세스 권한 등에 관한 정보를 획득하기 위해 필요한 정보를 포함할 수 있다. 따라서, 제1 클라우드 서비스(12)는 제1 클라우드 서비스(12) 상에서의 사용자의 고유 식별 정보(ID) 및 사용자의 제1 클라우드 서비스(12) 및 제2 클라우드 서비스(13)에 대한 액세스 권한 등에 관한 정보를 획득할 수 있다.The first cloud service (12) can obtain the user's access rights information for the second cloud service (13) using the user's information (S412). The first user authentication token may include information necessary to obtain information regarding the user's unique identification information (ID) and the user's access rights to the service on the first cloud service (12). Accordingly, the first cloud service (12) can obtain the user's unique identification information (ID) on the first cloud service (12) and information regarding the user's access rights to the first cloud service (12) and the second cloud service (13).
이후, 제1 클라우드 서비스(12)는 서비스 서버(10)에 상기 액세스 권한 정보를 송신할 수 있다. 서비스 서버(11)는 상기 수신한 액세스 권한 정보를 제2 클라우드 서비스(13)의 인증서에 포함된 공개키로 암호화할 수 있다(S413). S413 단계의 수행 결과, 상기 액세스 권한 정보는 오로지 제2 클라우드 서비스(13)의 비밀키에 의해서만 복호화될 수 있으므로, 클라우드 플랫폼(10) 상 제공되는 서비스의 보안성이 강화될 수 있다는 장점이 있다.Thereafter, the first cloud service (12) can transmit the access right information to the service server (10). The service server (11) can encrypt the received access right information with the public key included in the certificate of the second cloud service (13) (S413). As a result of performing step S413, the access right information can be decrypted only by the private key of the second cloud service (13), so there is an advantage in that the security of the service provided on the cloud platform (10) can be strengthened.
이후, 서비스 서버(11)는 제2 클라우드 서비스(13)의 인증서에 포함된 공개키로 암호화된 액세스 권한 정보를 제2 클라우드 서비스(13)에 송신할 수 있다. 상기 암호화된 액세스 권한 정보가 제2 클라우드 서비스(13)에 전달된 경우, 제2 클라우드 서비스(13)는 제2 클라우드 서비스(13)의 비밀키를 이용하여, 상기 암호화 된 액세스 권한 정보를 복호화할 수 있다.Thereafter, the service server (11) can transmit access right information encrypted with the public key included in the certificate of the second cloud service (13) to the second cloud service (13). When the encrypted access right information is transmitted to the second cloud service (13), the second cloud service (13) can decrypt the encrypted access right information using the private key of the second cloud service (13).
이하에서는, 도 6을 참조하여, 본 개시의 몇몇 실시예들에 따른 액세스 권한을 설정하는 방법에 관하여 설명한다. 도 6은 도 2를 참조하여 설명한, 본 개시의 몇몇 실시예들에 따른 클라우드 환경에서 서비스 제공 방법의 세부 동작을 설명하기 위한 상세 순서도이다.Hereinafter, with reference to FIG. 6, a method for setting access rights according to some embodiments of the present disclosure will be described. FIG. 6 is a detailed flowchart illustrating detailed operations of a service provision method in a cloud environment according to some embodiments of the present disclosure, as described with reference to FIG. 2.
도 6을 참조하면, 제2 클라우드 서비스(13)는 사용자가 제1 클라우드 서비스(12) 상에서 제2 클라우드 서비스(13)에 대한 액세스 권한이 있는지 여부를 판정할 수 있다(S501). 제2 클라우드 서비스(13)는, 제1 클라우드 서비스(12)에 의해 획득된 제2 클라우드 서비스(13)에 대한 사용자의 액세스 권한 정보를 통해 사용자가 제1 클라우드 서비스(12) 상에서 제2 클라우드 서비스(13)에 대한 액세스 권한이 있는지 여부를 판정할 수 있다.Referring to FIG. 6, the second cloud service (13) can determine whether the user has access rights to the second cloud service (13) on the first cloud service (12) (S501). The second cloud service (13) can determine whether the user has access rights to the second cloud service (13) on the first cloud service (12) based on the user's access rights information for the second cloud service (13) acquired by the first cloud service (12).
만약, 사용자가 제1 클라우드 서비스(12) 상에서 제2 클라우드 서비스(13)에 대한 액세스 권한이 없는 경우, 제2 클라우드 서비스(13)는 제1 클라우드 서비스(12) 상에서 사용자가 제2 클라우드 서비스(13)를 사용할 수 없도록 제2 클라우드 서비스에 대한 액세스를 거절할 수 있다(S502).If the user does not have access to the second cloud service (13) on the first cloud service (12), the second cloud service (13) may deny access to the second cloud service (13) so that the user cannot use the second cloud service (13) on the first cloud service (12) (S502).
반면, 사용자가 제1 클라우드 서비스(12) 상에서 제2 클라우드 서비스(13)에 대한 액세스 권한이 있는 경우, 제2 클라우드 서비스(13)는 서비스 서버(11)에 제2 클라우드 서비스(13)에 대한 사용자의 제2 사용자 인증 토큰의 생성 요청을 송신할 수 있다(S503).On the other hand, if the user has access to the second cloud service (13) on the first cloud service (12), the second cloud service (13) can send a request to the service server (11) to create a second user authentication token for the user for the second cloud service (13) (S503).
서비스 서버(11)는 상기 제2 사용자 인증 토큰의 생성 요청을 수신하는 것에 응답하여, 제2 클라우드 서비스(13)에 대한 사용자의 액세스 권한 정보를 이용하여, 제2 클라우드 서비스(13)에 대한 사용자의 액세스 권한 및 토큰 만료 시간에 관한 정보를 포함하는 제2 사용자 인증 토큰을 생성할 수 있다. 즉, 제1 클라우드 서비스(12)의 사용자인 제1 사용자에 대한 검증이 완료되면, 제2 클라우드 서비스(13)는 상기 제1 사용자에 대하여 제2 클라우드 서비스(13)에 대한 제2 사용자 인증 토큰을 발급할 수 있다. 이 경우, 제2 클라우드 서비스(13)는 사전에 제1 사용자에 대하여 정의된 권한 및 토큰 만료 시간 정책을 적용하여 제2 사용자 인증 토큰을 발급하고 저장할 수 있다.In response to receiving a request for generating the second user authentication token, the service server (11) may generate a second user authentication token including information about the user's access rights to the second cloud service (13) and the token expiration time, using the user's access rights information for the second cloud service (13). That is, when verification of the first user, who is a user of the first cloud service (12), is completed, the second cloud service (13) may issue a second user authentication token for the second cloud service (13) to the first user. In this case, the second cloud service (13) may issue and store the second user authentication token by applying rights and token expiration time policies defined in advance for the first user.
본 실시예에 따르면, 클라우드 플랫폼(10)에서 제공되는 제1 클라우드 서비스(12)의 사용자가 클라우드 플랫폼(10)에 새롭게 추가되는 제2 클라우드 서비스(13)를 사용하기 위해서 제2 클라우드 서비스(13)에 별도로 가입하거나 로그인을 수행하지 않아도 된다. 대신, 해당 사용자가 제2 클라우드 서비스(13)에 초기에 액세스하는 경우, 제2 클라우드 서비스(13)에 대한 사용자 인증 토큰을 한번 발급받으면, 이후에는 해당 사용자에 대하여 사전에 정의된 범위 안에서 제1 클라우드 서비스(12) 및 제2 클라우드 서비스(13)를 사용할 있다는 장점이 있다. 따라서, 본 실시예에 따르면, 클라우드 플랫폼(10) 내 서비스의 확장성이 향상될 수 있다.According to the present embodiment, a user of the first cloud service (12) provided on the cloud platform (10) does not need to separately sign up for or log in to the second cloud service (13) in order to use the second cloud service (13) newly added to the cloud platform (10). Instead, when the user initially accesses the second cloud service (13), once a user authentication token for the second cloud service (13) is issued, the user can then use the first cloud service (12) and the second cloud service (13) within a predefined range, which is advantageous. Therefore, according to the present embodiment, the scalability of services within the cloud platform (10) can be improved.
도 7은 본 개시의 몇몇 실시예들에 따른 컴퓨팅 장치의 하드웨어 구성도이다. 도 7의 컴퓨팅 장치(1000)는, 하나 이상의 프로세서(1100), 시스템 버스(1600), 통신 인터페이스(1200), 프로세서(1100)에 의하여 수행되는 컴퓨터 프로그램(1500)을 로드(load)하는 메모리(1400)와, 컴퓨터 프로그램(1500)을 저장하는 스토리지(1300)를 포함할 수 있다.FIG. 7 is a hardware configuration diagram of a computing device according to some embodiments of the present disclosure. The computing device (1000) of FIG. 7 may include one or more processors (1100), a system bus (1600), a communication interface (1200), a memory (1400) for loading a computer program (1500) executed by the processor (1100), and a storage (1300) for storing the computer program (1500).
도 7의 컴퓨팅 시스템(1000)은, 예를 들어 도 1을 참조하여 설명한 클라우드 플랫폼(10)을 구성하는 하나 이상의 컴퓨팅 시스템의 하드웨어 구조를 제시하는 것일 수 있다.The computing system (1000) of FIG. 7 may present a hardware structure of one or more computing systems constituting the cloud platform (10) described with reference to FIG. 1, for example.
프로세서(1100)는 컴퓨팅 시스템(1000)의 각 구성의 전반적인 동작을 제어한다. 프로세서(1100)는 본 개시의 다양한 실시예들에 따른 방법/동작을 실행하기 위한 적어도 하나의 애플리케이션 또는 프로그램에 대한 연산을 수행할 수 있다. 메모리(1400)는 각종 데이터, 명령 및/또는 정보를 저장한다. 메모리(1400)는 본 개시의 다양한 실시예들에 따른 방법/동작들을 실행하기 위하여 스토리지(1300)로부터 하나 이상의 컴퓨터 프로그램(1500)을 로드(load) 할 수 있다. 스토리지(1300)는 하나 이상의 컴퓨터 프로그램(1500)을 비임시적으로 저장할 수 있다.The processor (1100) controls the overall operation of each component of the computing system (1000). The processor (1100) can perform operations for at least one application or program for executing methods/operations according to various embodiments of the present disclosure. The memory (1400) stores various data, commands, and/or information. The memory (1400) can load one or more computer programs (1500) from the storage (1300) to execute methods/operations according to various embodiments of the present disclosure. The storage (1300) can non-temporarily store one or more computer programs (1500).
컴퓨터 프로그램(1500)은 본 개시의 다양한 실시예들에 따른 방법/동작들이 구현된 하나 이상의 인스트럭션들(instructions)을 포함할 수 있다. 컴퓨터 프로그램(1500)이 메모리(1400)에 로드 되면, 프로세서(1100)는 상기 하나 이상의 인스트럭션들을 실행시킴으로써 본 개시의 다양한 실시예들에 따른 방법/동작들을 수행할 수 있다.The computer program (1500) may include one or more instructions implementing methods/operations according to various embodiments of the present disclosure. When the computer program (1500) is loaded into the memory (1400), the processor (1100) may execute the one or more instructions to perform the methods/operations according to various embodiments of the present disclosure.
일 실시예에서, 컴퓨터 프로그램(1500)은 제1 클라우드 서비스를 사용하는 사용자의 단말로부터 제2 클라우드 서비스에 대한 액세스 요청을 수신하는 동작, 상기 액세스 요청을 수신하는 것에 응답하여, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증되었는지 여부를 판정하는 동작, 상기 판정의 결과, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증된 경우, 상기 제1 클라우드 서비스에 상기 사용자의 검증 요청을 송신하는 동작, 상기 검증 요청에 응답하여, 상기 제2 클라우드 서비스에, 상기 사용자가 상기 제2 클라우드 서비스에 대한 액세스 권한이 있는지 여부에 관한 사용자 검증 결과를 송신하는 동작 및 상기 사용자 검증 결과를 이용하여, 상기 사용자에 대하여, 상기 제2 클라우드 서비스에 대한 액세스 권한을 설정하는 동작을 실행시키는 인스트럭션들(instructions)을 포함하되, 상기 제1 클라우드 서비스 및 상기 제2 클라우드 서비스는 동일한 클라우드 플랫폼 상에서 제공되는 서비스일 수 있다.In one embodiment, the computer program (1500) includes instructions for executing the following operations: receiving an access request for a second cloud service from a terminal of a user using a first cloud service; determining, in response to receiving the access request, whether the first cloud service is authenticated in the second cloud service; transmitting a user verification request to the first cloud service if the first cloud service is authenticated in the second cloud service as a result of the determination; transmitting, in response to the verification request, a user verification result regarding whether the user has access to the second cloud service to the second cloud service; and using the user verification result, setting access rights for the user to the second cloud service, wherein the first cloud service and the second cloud service may be services provided on the same cloud platform.
지금까지 도 1 내지 도 7을 참조하여 본 개시의 다양한 실시예들 및 그 실시예들에 따른 효과들을 언급하였다. 본 개시의 기술적 사상에 따른 효과들은 이상에서 언급한 효과들로 제한되지 않으며, 언급되지 않은 또 다른 효과들은 아래의 기재로부터 통상의 기술자에게 명확하게 이해될 수 있을 것이다.Various embodiments of the present disclosure and the effects thereof have been described with reference to FIGS. 1 through 7 so far. The effects of the technical concept of the present disclosure are not limited to the effects described above, and other effects not mentioned will be readily apparent to those skilled in the art from the description below.
또한, 이상의 실시예들에서 복수의 구성요소들이 하나로 결합되거나 결합되어 동작하는 것으로 설명되었다고 해서, 본 개시의 기술적 사상이 반드시 이러한 실시예에 한정되는 것은 아니다. 즉, 본 개시의 기술적 사상의 목적 범위 안에서라면, 그 모든 구성요소들이 하나 이상으로 선택적으로 결합하여 동작할 수도 있다.Furthermore, even though the above embodiments have described multiple components as being combined or operating in combination, the technical concept of the present disclosure is not necessarily limited to these embodiments. That is, within the scope of the technical concept of the present disclosure, all of the components may be selectively combined and operated one or more times.
지금까지 설명된 본 개시의 기술적 사상은 컴퓨터가 읽을 수 있는 매체 상에 컴퓨터가 읽을 수 있는 코드로 구현될 수 있다. 컴퓨터로 읽을 수 있는 기록 매체에 기록된 컴퓨터 프로그램은 인터넷 등의 네트워크를 통하여 다른 컴퓨팅 장치에 전송되어 상기 다른 컴퓨팅 장치에 설치될 수 있고, 이로써 상기 다른 컴퓨팅 장치에서 사용될 수 있다.The technical concepts of the present disclosure described so far can be implemented as computer-readable code on a computer-readable medium. A computer program recorded on a computer-readable recording medium can be transmitted to another computing device via a network such as the Internet, installed on said other computing device, and thus used on said other computing device.
Claims (10)
제1 클라우드 서비스를 사용하는 사용자의 단말로부터 제2 클라우드 서비스에 대한 액세스 요청을 수신하는 단계;
상기 액세스 요청을 수신하는 것에 응답하여, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증되었는지 여부를 판정하는 단계;
상기 판정의 결과, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증된 경우, 상기 제1 클라우드 서비스에 상기 사용자의 검증 요청을 송신하는 단계;
상기 검증 요청에 응답하여, 상기 제2 클라우드 서비스에, 상기 사용자가 상기 제2 클라우드 서비스에 대한 액세스 권한이 있는지 여부에 관한 사용자 검증 결과를 송신하는 단계; 및
상기 사용자 검증 결과를 이용하여, 상기 사용자에 대하여, 상기 제2 클라우드 서비스에 대한 액세스 권한을 설정하는 단계를 포함하되,
상기 제1 클라우드 서비스 및 상기 제2 클라우드 서비스는 동일한 클라우드 플랫폼 상에서 제공되는 서비스이고,
상기 판정하는 단계는,
상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증되지 않은 경우, 상기 제2 클라우드 서비스로부터 상기 제1 클라우드 서비스에 대한 인증 요청을 수신하는 단계;
상기 인증 요청에 응답하여, 상기 제2 클라우드 서비스의 인증서 및 공인 IP 정보를 이용하여 상기 제1 클라우드 서비스에 대한 인증 요청 데이터를 생성하는 단계;
상기 인증 요청 데이터를 상기 제1 클라우드 서비스의 인증서에 포함된 공개키로 암호화하는 단계;
상기 제1 클라우드 서비스의 공인 IP로 상기 암호화된 인증 요청 데이터를 송신하는 단계;
상기 제1 클라우드 서비스의 비밀키를 이용하여, 상기 암호화된 인증 요청 데이터를 복호화하는 단계;
상기 인증 요청 데이터에 포함된 상기 제2 클라우드 서비스 인증서의 인증 기관(Certificate Authority)과 상기 클라우드 플랫폼에 저장된 제2 클라우드 서비스의 인증서의 인증 기관이 일치하는지 여부를 검증하는 단계; 및
상기 검증의 결과, 상기 인증 요청 데이터에 포함된 상기 제2 클라우드 서비스의 인증서의 인증 기관과 상기 클라우드 플랫폼에 저장된 제2 클라우드 서비스의 인증서의 인증 기관이 일치하는 경우, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 제공될 수 있도록 상기 제1 클라우드 서비스의 인증 대상에 상기 제2 클라우드 서비스를 추가하는 단계를 포함하는,
클라우드 환경에서 서비스 제공 방법.In a method performed by a computing system,
A step of receiving an access request for a second cloud service from a terminal of a user using a first cloud service;
In response to receiving the access request, determining whether the first cloud service is authenticated in the second cloud service;
As a result of the above determination, if the first cloud service is authenticated in the second cloud service, a step of transmitting the user's verification request to the first cloud service;
In response to the verification request, transmitting to the second cloud service a user verification result regarding whether the user has access to the second cloud service; and
A step of setting access rights to the second cloud service for the user using the user verification result is included.
The above first cloud service and the above second cloud service are services provided on the same cloud platform,
The above judging step is,
A step of receiving an authentication request for the first cloud service from the second cloud service when the first cloud service is not authenticated in the second cloud service;
In response to the authentication request, a step of generating authentication request data for the first cloud service using the certificate and public IP information of the second cloud service;
A step of encrypting the above authentication request data with a public key included in the certificate of the first cloud service;
A step of transmitting the encrypted authentication request data to the public IP of the first cloud service;
A step of decrypting the encrypted authentication request data using the secret key of the first cloud service;
A step of verifying whether the certificate authority of the second cloud service certificate included in the above authentication request data matches the certificate authority of the second cloud service certificate stored in the cloud platform; and
As a result of the above verification, if the certification authority of the certificate of the second cloud service included in the authentication request data matches the certification authority of the certificate of the second cloud service stored in the cloud platform, a step of adding the second cloud service to the authentication target of the first cloud service so that the first cloud service can be provided in the second cloud service is included.
How to provide services in a cloud environment.
상기 제1 클라우드 서비스의 인증 대상에 상기 제2 클라우드 서비스를 추가하는 단계는,
상기 제1 클라우드 서비스의 저장 공간에 상기 제2 클라우드 서비스의 인증서 및 공인 IP 정보를 저장하는 단계를 포함하는,
클라우드 환경에서 서비스 제공 방법.In the first paragraph,
The step of adding the second cloud service to the authentication target of the first cloud service is as follows:
Comprising a step of storing the certificate and public IP information of the second cloud service in the storage space of the first cloud service,
How to provide services in a cloud environment.
제1 클라우드 서비스를 사용하는 사용자의 단말로부터 제2 클라우드 서비스에 대한 액세스 요청을 수신하는 단계;
상기 액세스 요청을 수신하는 것에 응답하여, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증되었는지 여부를 판정하는 단계;
상기 판정의 결과, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증된 경우, 상기 제1 클라우드 서비스에 상기 사용자의 검증 요청을 송신하는 단계;
상기 검증 요청에 응답하여, 상기 제2 클라우드 서비스에, 상기 사용자가 상기 제2 클라우드 서비스에 대한 액세스 권한이 있는지 여부에 관한 사용자 검증 결과를 송신하는 단계; 및
상기 사용자 검증 결과를 이용하여, 상기 사용자에 대하여, 상기 제2 클라우드 서비스에 대한 액세스 권한을 설정하는 단계를 포함하되,
상기 제1 클라우드 서비스 및 상기 제2 클라우드 서비스는 동일한 클라우드 플랫폼 상에서 제공되는 서비스이고,
상기 판정하는 단계는,
상기 제2 클라우드 서비스의 인증서 또는 공인 IP 정보가 변경된 경우, 상기 제2 클라우드 서비스로부터 상기 제1 클라우드 서비스에 대한 인증 정보 갱신 요청을 수신하는 단계;
상기 인증 정보 갱신 요청에 응답하여, 상기 제2 클라우드 서비스의 변경된 인증서 또는 공인 IP 정보를 이용하여, 상기 제1 클라우드 서비스에 대한 인증 갱신 요청 데이터를 생성하는 단계;
상기 제2 클라우드 서비스의 변경 전 인증서의 비밀키를 이용하여, 상기 인증 갱신 요청 데이터에 서명을 수행하고, 서명 인증 갱신 요청 데이터를 생성하는 단계;
상기 서명 인증 갱신 요청 데이터를 상기 제1 클라우드 서비스의 인증서에 포함된 공개키로 암호화하는 단계;
상기 제1 클라우드 서비스의 공인 IP로 상기 암호화된 서명 인증 갱신 요청 데이터를 송신하는 단계;
상기 제1 클라우드 서비스의 비밀키를 이용하여, 상기 서명 인증 갱신 요청 데이터를 복호화하는 단계;
상기 제2 클라우드 서비스의 변경 전 인증서의 공개키를 이용하여, 상기 서명 인증 갱신 요청 데이터를 검증하는 단계;
상기 서명 인증 갱신 요청 데이터에 포함된 상기 제2 클라우드 서비스의 인증서의 인증 기관(Certificate Authority)과 상기 클라우드 플랫폼에 저장된 제2 클라우드 서비스 인증서의 인증 기관이 일치하는지 여부를 검증하는 단계; 및
상기 서명 인증 갱신 요청 데이터에 포함된 상기 제2 클라우드 서비스의 인증서의 인증 기관과 상기 클라우드 플랫폼에 저장된 제2 클라우드 서비스의 인증서의 인증 기관이 일치하는 경우, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 제공될 수 있도록 상기 제1 클라우드 서비스의 인증 대상에 상기 제2 클라우드 서비스를 추가하는 단계를 포함하는,
클라우드 환경에서 서비스 제공 방법.In a method performed by a computing system,
A step of receiving an access request for a second cloud service from a terminal of a user using a first cloud service;
In response to receiving the access request, determining whether the first cloud service is authenticated in the second cloud service;
As a result of the above determination, if the first cloud service is authenticated in the second cloud service, a step of transmitting the user's verification request to the first cloud service;
In response to the verification request, transmitting to the second cloud service a user verification result regarding whether the user has access to the second cloud service; and
A step of setting access rights to the second cloud service for the user using the user verification result is included.
The above first cloud service and the above second cloud service are services provided on the same cloud platform,
The above judging step is,
A step of receiving a request for renewing authentication information for the first cloud service from the second cloud service when the certificate or public IP information of the second cloud service has changed;
In response to the authentication information renewal request, a step of generating authentication renewal request data for the first cloud service using the changed certificate or public IP information of the second cloud service;
A step of signing the authentication renewal request data using the secret key of the certificate before the change of the second cloud service and generating signed authentication renewal request data;
A step of encrypting the above signature authentication renewal request data with a public key included in the certificate of the first cloud service;
A step of transmitting the encrypted signature authentication renewal request data to the public IP of the first cloud service;
A step of decrypting the signature authentication renewal request data using the secret key of the first cloud service;
A step of verifying the signature authentication renewal request data using the public key of the certificate before the change of the second cloud service;
A step of verifying whether the certificate authority of the second cloud service certificate included in the signature authentication renewal request data matches the certificate authority of the second cloud service certificate stored in the cloud platform; and
If the certification authority of the certificate of the second cloud service included in the signature authentication renewal request data matches the certification authority of the certificate of the second cloud service stored in the cloud platform, a step of adding the second cloud service to the authentication target of the first cloud service so that the first cloud service can be provided in the second cloud service is included.
How to provide services in a cloud environment.
상기 제1 클라우드 서비스의 인증 대상에 상기 제2 클라우드 서비스를 추가하는 단계는,
상기 제1 클라우드 서비스의 저장 공간에 상기 제2 클라우드 서비스의 변경된 인증서 및 공인 IP 정보를 저장하는 단계를 포함하는,
클라우드 환경에서 서비스 제공 방법.In paragraph 4,
The step of adding the second cloud service to the authentication target of the first cloud service is as follows:
Comprising a step of storing the changed certificate and public IP information of the second cloud service in the storage space of the first cloud service,
How to provide services in a cloud environment.
상기 사용자의 검증 요청은,
상기 제1 클라우드 서비스의 인증서에 포함된 공개키로 암호화된, 상기 제1 클라우드 서비스의 고유 식별 정보 및 상기 제1 클라우드 서비스에 대한 상기 사용자의 제1 사용자 인증 토큰(Authentication Token)에 관한 사용자 검증 요청 데이터를 포함하는,
클라우드 환경에서 서비스 제공 방법.In the first paragraph,
The above user's verification request is:
Including user verification request data regarding the user's first user authentication token for the first cloud service and unique identification information of the first cloud service encrypted with a public key included in the certificate of the first cloud service,
How to provide services in a cloud environment.
상기 사용자 검증 결과를 송신하는 단계는,
상기 제1 클라우드 서비스의 인증서에 포함된 비밀키를 이용하여, 상기 사용자 검증 요청 데이터를 복호화하는 단계;
상기 제1 사용자 인증 토큰을 이용하여, 상기 사용자의 정보를 획득하는 단계;
상기 사용자의 정보를 이용하여, 상기 제2 클라우드 서비스에 대한 상기 사용자의 액세스 권한 정보를 획득하는 단계; 및
상기 액세스 권한 정보를 상기 제2 클라우드 서비스의 인증서에 포함된 공개키로 암호화하는 단계를 포함하는,
클라우드 환경에서 서비스 제공 방법.In paragraph 6,
The step of transmitting the above user verification result is:
A step of decrypting the user verification request data using a secret key included in the certificate of the first cloud service;
A step of obtaining information about the user using the first user authentication token;
A step of obtaining the user's access authority information for the second cloud service by using the user's information; and
A step of encrypting the above access authority information with a public key included in the certificate of the second cloud service,
How to provide services in a cloud environment.
상기 액세스 권한을 설정하는 단계는,
상기 사용자가 상기 제2 클라우드 서비스에 대한 액세스 권한이 있는 경우, 상기 제2 클라우드 서비스에 대한 상기 사용자의 제2 사용자 인증 토큰의 생성 요청을 송신하는 단계; 및
상기 생성 요청을 수신하는 것에 응답하여, 상기 액세스 권한 정보를 이용하여, 상기 제2 클라우드 서비스에 대한 상기 사용자의 액세스 권한 및 토큰 만료 시간에 관한 정보를 포함하는 제2 사용자 인증 토큰을 생성하는 단계를 포함하는,
클라우드 환경에서 서비스 제공 방법.In paragraph 7,
The steps to set the above access rights are:
If the user has access to the second cloud service, a step of sending a request for generating a second user authentication token of the user to the second cloud service; and
In response to receiving the above generation request, a step of generating a second user authentication token including information about the user's access rights to the second cloud service and a token expiration time using the access rights information,
How to provide services in a cloud environment.
컴퓨터 프로그램이 로드되는 메모리; 및
상기 컴퓨터 프로그램이 실행되는 하나 이상의 프로세서를 포함하되,
상기 컴퓨터 프로그램은,
제1 클라우드 서비스를 사용하는 사용자의 단말로부터 제2 클라우드 서비스에 대한 액세스 요청을 수신하는 동작;
상기 액세스 요청을 수신하는 것에 응답하여, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증되었는지 여부를 판정하는 동작;
상기 판정의 결과, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증된 경우, 상기 제1 클라우드 서비스에 상기 사용자의 검증 요청을 송신하는 동작;
상기 검증 요청에 응답하여, 상기 제2 클라우드 서비스에, 상기 사용자가 상기 제2 클라우드 서비스에 대한 액세스 권한이 있는지 여부에 관한 사용자 검증 결과를 송신하는 동작; 및
상기 사용자 검증 결과를 이용하여, 상기 사용자에 대하여, 상기 제2 클라우드 서비스에 대한 액세스 권한을 설정하는 동작을 실행시키는 인스트럭션들(instructions)을 포함하되,
상기 제1 클라우드 서비스 및 상기 제2 클라우드 서비스는 동일한 클라우드 플랫폼 상에서 제공되는 서비스이고,
상기 판정하는 동작은,
상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 인증되지 않은 경우, 상기 제2 클라우드 서비스로부터 상기 제1 클라우드 서비스에 대한 인증 요청을 수신하는 동작;
상기 인증 요청에 응답하여, 상기 제2 클라우드 서비스의 인증서 및 공인 IP 정보를 이용하여 상기 제1 클라우드 서비스에 대한 인증 요청 데이터를 생성하는 동작;
상기 인증 요청 데이터를 상기 제1 클라우드 서비스의 인증서에 포함된 공개키로 암호화하는 동작;
상기 제1 클라우드 서비스의 공인 IP로 상기 암호화된 인증 요청 데이터를 송신하는 동작;
상기 제1 클라우드 서비스의 비밀키를 이용하여, 상기 암호화된 인증 요청 데이터를 복호화하는 동작;
상기 인증 요청 데이터에 포함된 상기 제2 클라우드 서비스 인증서의 인증 기관(Certificate Authority)과 상기 클라우드 플랫폼에 저장된 제2 클라우드 서비스의 인증서의 인증 기관이 일치하는지 여부를 검증하는 동작; 및
상기 검증의 결과, 상기 인증 요청 데이터에 포함된 상기 제2 클라우드 서비스의 인증서의 인증 기관과 상기 클라우드 플랫폼에 저장된 제2 클라우드 서비스의 인증서의 인증 기관이 일치하는 경우, 상기 제2 클라우드 서비스에서 상기 제1 클라우드 서비스가 제공될 수 있도록 상기 제1 클라우드 서비스의 인증 대상에 상기 제2 클라우드 서비스를 추가하는 동작을 포함하는,
클라우드 환경에서 서비스 제공 시스템.communication interface;
Memory into which computer programs are loaded; and
Including one or more processors on which the above computer program is executed,
The above computer program,
An action of receiving an access request for a second cloud service from a terminal of a user using a first cloud service;
In response to receiving the access request, an action of determining whether the first cloud service is authenticated in the second cloud service;
As a result of the above determination, if the first cloud service is authenticated in the second cloud service, an operation of transmitting the user's verification request to the first cloud service;
In response to the verification request, an operation of transmitting a user verification result regarding whether the user has access to the second cloud service to the second cloud service; and
Using the above user verification result, instructions are included to execute an operation for setting access rights to the second cloud service for the user.
The above first cloud service and the above second cloud service are services provided on the same cloud platform,
The above judgment action is,
An operation of receiving an authentication request for the first cloud service from the second cloud service when the first cloud service is not authenticated in the second cloud service;
In response to the authentication request, an action of generating authentication request data for the first cloud service using the certificate and public IP information of the second cloud service;
An action of encrypting the above authentication request data with a public key included in the certificate of the first cloud service;
An action of transmitting the encrypted authentication request data to the public IP of the first cloud service;
An operation of decrypting the encrypted authentication request data using the secret key of the first cloud service;
An operation of verifying whether the certificate authority of the second cloud service certificate included in the above authentication request data matches the certificate authority of the second cloud service certificate stored in the cloud platform; and
As a result of the above verification, if the certification authority of the certificate of the second cloud service included in the authentication request data matches the certification authority of the certificate of the second cloud service stored in the cloud platform, an operation of adding the second cloud service to the authentication target of the first cloud service so that the first cloud service can be provided in the second cloud service is included.
Service provision system in a cloud environment.
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020250024337A KR102936977B1 (en) | 2025-02-25 | 2025-02-25 | Method for verifying service and user in a cloud environment and system therefor |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR1020250024337A KR102936977B1 (en) | 2025-02-25 | 2025-02-25 | Method for verifying service and user in a cloud environment and system therefor |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| KR102936977B1 true KR102936977B1 (en) | 2026-03-12 |
Family
ID=99102293
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| KR1020250024337A Active KR102936977B1 (en) | 2025-02-25 | 2025-02-25 | Method for verifying service and user in a cloud environment and system therefor |
Country Status (1)
| Country | Link |
|---|---|
| KR (1) | KR102936977B1 (en) |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR101942763B1 (en) | 2016-09-08 | 2019-01-28 | 전북대학교산학협력단 | Encrypted index based range query processing method and range query processing system |
| KR102184928B1 (en) | 2019-07-29 | 2020-12-01 | 베스핀글로벌 주식회사 | Total Account management System based on Token and Method |
-
2025
- 2025-02-25 KR KR1020250024337A patent/KR102936977B1/en active Active
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| KR101942763B1 (en) | 2016-09-08 | 2019-01-28 | 전북대학교산학협력단 | Encrypted index based range query processing method and range query processing system |
| KR102184928B1 (en) | 2019-07-29 | 2020-12-01 | 베스핀글로벌 주식회사 | Total Account management System based on Token and Method |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP7457173B2 (en) | Internet of Things (IOT) device management | |
| CN105376216B (en) | A remote access method, proxy server and client | |
| EP3412001B1 (en) | A method of data transfer and cryptographic devices | |
| US8788811B2 (en) | Server-side key generation for non-token clients | |
| US9032496B2 (en) | Secure single sign-on | |
| CN113614720B (en) | An apparatus and method for dynamically configuring trusted application access control | |
| CN111639327B (en) | An open platform authentication method and device | |
| KR101530809B1 (en) | Dynamic platform reconfiguration by multi-tenant service providers | |
| US20110167263A1 (en) | Wireless connections to a wireless access point | |
| JP6572750B2 (en) | Authentication control program, authentication control device, and authentication control method | |
| EP3570517B1 (en) | Authentication technique making use of emergency credential | |
| US11240246B2 (en) | Secure confirmation exchange for offline industrial machine | |
| CN107634973B (en) | Service interface safe calling method | |
| JP6894160B1 (en) | Usage right information processing device based on smart contract, usage right information processing system, and usage right information processing method | |
| US11977620B2 (en) | Attestation of application identity for inter-app communications | |
| CN118159967A (en) | Controlling access to computing resources implemented in an isolated environment | |
| US12531844B2 (en) | Computing systems and methods for protecting application programming interfaces with two-factor authentication | |
| US20250330322A1 (en) | Computing systems and methods for protecting application programming interfaces with two-factor authentication | |
| KR102936977B1 (en) | Method for verifying service and user in a cloud environment and system therefor | |
| US20200119919A1 (en) | Electronic device authentication managing apparatus | |
| KR102780025B1 (en) | System and method for remote support, and web application server for executing the same | |
| CN116561820A (en) | Trusted data processing method and related device | |
| CN115150154A (en) | User login authentication method and related device | |
| CN119382888B (en) | User authentication method, intelligent service system, device, medium, and program | |
| US20220116217A1 (en) | Secure linking of device to cloud storage |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PA0109 | Patent application |
St.27 status event code: A-0-1-A10-A12-nap-PA0109 |
|
| PA0201 | Request for examination |
St.27 status event code: A-1-2-D10-D11-exm-PA0201 |
|
| PA0302 | Request for accelerated examination |
St.27 status event code: A-1-2-D10-D16-exm-PA0302 |
|
| D13-X000 | Search requested |
St.27 status event code: A-1-2-D10-D13-srh-X000 |
|
| PE0902 | Notice of grounds for rejection |
St.27 status event code: A-1-2-D10-D21-exm-PE0902 |
|
| E13-X000 | Pre-grant limitation requested |
St.27 status event code: A-2-3-E10-E13-lim-X000 |
|
| P11-X000 | Amendment of application requested |
St.27 status event code: A-2-2-P10-P11-nap-X000 |
|
| P13-X000 | Application amended |
St.27 status event code: A-2-2-P10-P13-nap-X000 |
|
| PE0902 | Notice of grounds for rejection |
St.27 status event code: A-1-2-D10-D21-exm-PE0902 |
|
| E13-X000 | Pre-grant limitation requested |
St.27 status event code: A-2-3-E10-E13-lim-X000 |
|
| P11-X000 | Amendment of application requested |
St.27 status event code: A-2-2-P10-P11-nap-X000 |
|
| D22 | Grant of ip right intended |
Free format text: ST27 STATUS EVENT CODE: A-1-2-D10-D22-EXM-PE0701 (AS PROVIDED BY THE NATIONAL OFFICE) |
|
| PE0701 | Decision of registration |
St.27 status event code: A-1-2-D10-D22-exm-PE0701 |
|
| PG1601 | Publication of registration |
St.27 status event code: A-4-4-Q10-Q13-nap-PG1601 |
|
| Q13 | Ip right document published |
Free format text: ST27 STATUS EVENT CODE: A-4-4-Q10-Q13-NAP-PG1601 (AS PROVIDED BY THE NATIONAL OFFICE) |