Intelligent password service platform

By combining cryptographic devices from different manufacturers and of different types into a resource cloud through an intelligent cryptographic service platform, and using AI models for load balancing and dynamic scheduling, the problem of poor scalability of existing systems has been solved, and flexible networking and efficient operation and maintenance have been achieved.

CN115567360BActive Publication Date: 2025-12-05CHONGQING AEROSPACE INFORMATION CO LTD

Patent Information

Application Number
CN202211153180.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-21
Publication Date
2025-12-05
Estimated Expiration
2042-09-21

AI Technical Summary

Technical Problem

Existing cryptographic service systems use equipment from different manufacturers, of different types and models, which requires the development and deployment of multiple systems, resulting in weak service capabilities, poor scalability, and an inability to meet the needs of business development.

Method used

An intelligent cryptographic service platform is adopted, including a service gateway, synchronization module, general server, reverse proxy server and several cryptographic devices. Through virtualization technology, cryptographic devices of different manufacturers and types are combined into a resource cloud, providing a unified interface service, and using AI models for load balancing and dynamic scheduling.

Benefits of technology

It enables flexible networking of cryptographic devices from different manufacturers and of different types, improves system scalability and operating efficiency, reduces operation and maintenance complexity, extends equipment life, and reduces operation and maintenance time and energy consumption.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115567360B_ABST
    Figure CN115567360B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of information system security, and particularly discloses an intelligent password service platform, which comprises a service gateway, a synchronization module, a general server, a reverse proxy server and a plurality of password devices; the synchronization module is used for synchronizing key resources of password devices of the same type after the password devices access a network; the general server is provided with a virtual module and a load balancing module; the load balancing module is used for connecting the password devices after the key resources are synchronized; the virtual module is used for virtually changing physical resources of secret devices into resource clouds of different types through a virtualization technology; the service gateway is used for obtaining a calling application of a third-party application service interface; the service gateway is also used for analyzing the calling application and determining service requests facing different resource clouds according to the analyzed results. The technical scheme of the application has high expansibility, can be flexibly networked, is convenient for reusing and does not waste existing resources.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the field of information system security technology, in particular to an intelligent password service platform. BACKGROUND

[0002] In the face of complex network security environment, password technology has been widely used in network security identity authentication, digital signature, data information encryption and other business links. Password service system as an important part of security application system has become more and more important and complex. At present, the password service system is mainly composed of the same manufacturer, the same type and the same model of equipment. However, due to the non-uniform construction period of various password service systems, different manufacturers, different types and different models of equipment are used, which leads to the need to develop and deploy multiple password service systems, weak service capacity, poor scalability, and cannot meet the continuous expansion of business development scale.

[0003] Therefore, an intelligent password service platform with high scalability and flexible networking is needed. SUMMARY

[0004] The present application provides an intelligent password service platform, which can improve the scalability, realize flexible networking, and support different manufacturer password devices.

[0005] In order to solve the above technical problems, the present application provides the following technical solutions:

[0006] The intelligent password service platform comprises a service gateway, a synchronization module, a general server, a reverse proxy server and a plurality of password devices.

[0007] The synchronization module is used to synchronize the key resources of the same type of password devices after the password devices are connected to the network.

[0008] The general server is provided with a virtual module and a load balancing module. The load balancing module is used to connect the password devices after the key resource synchronization, and the virtual module is used to virtualize the physical resources of the password devices into different types of resource clouds through virtualization technology.

[0009] The service gateway is used to obtain the calling application of the third-party application service interface, and is also used to analyze the calling application and determine the service request facing different resource clouds according to the analysis result.

[0010] The load balancing module is also used to receive the service request and determine the sending password device after load balancing judgment.

[0011] The reverse proxy server is used to receive the service request and forward it to the corresponding password device.

[0012] The cryptographic device is configured to respond to the service request after receiving the service request, and send the response result to the resource cloud through the reverse proxy server; the load balancing module is further configured to send the response result to the service gateway; and the service gateway is further configured to send the response result to the corresponding third-party application through the service interface.

[0013] The basic scheme principle and advantages are as follows:

[0014] In the scheme, the virtual module combines cryptographic device resources into a heterogeneous resource cloud based on virtualization technology, integrates different manufacturers and different types of cryptographic devices, provides a unified interface service to the outside, and provides resource clouds by type. Cryptographic devices can be flexibly networked, making it easy to use old equipment, saving existing resources, saving costs, while shielding the details of the cryptographic device resource composition, improving operational efficiency and reducing operational complexity.

[0015] Further, the learning database is further included, and the service gateway is further configured to send the service interface call data to the learning database for storage; and the learning database is further configured to obtain device state data of the cryptographic device and store the device state data.

[0016] By bypassing the bypass, the service interface call is directly saved to the learning database, avoiding the increase in system burden when obtaining data from the main road.

[0017] Further, the scheduling module is further included, the AI model is pre-stored in the scheduling module, the scheduling module is configured to train the AI model by using the service interface call data and the device state data, so that the AI model obtains the resource trend of the cryptographic device; and the scheduling module is further configured to predict the resource cloud load and the device resource load in a future period of time by using the AI model.

[0018] The load balancing module is further configured to obtain a preliminary result according to a preset load balancing algorithm of different types of cryptographic devices when performing load balancing judgment, and then compare and correct the preliminary result and a prediction result obtained by the AI model to obtain an optimal result and determine the cryptographic device to be sent.

[0019] By using the AI model to predict the resource cloud load and the device resource load in a future period of time, intelligent dynamic scheduling is performed, load balancing is realized, system reliability is improved, device life is prolonged, operation and maintenance time is reduced, and device energy consumption is reduced.

[0020] Further, the scheduling module is further configured to correct the AI model according to the difference between the actual result and the prediction result after the training data reaches a set number.

[0021] In order to improve the prediction accuracy of the AI model.

[0022] Furthermore, the virtual module is also used to create a cache for the resource cloud, the cryptographic device is also used to send the response results to the cache for the resource cloud through the reverse proxy server, and the load balancing module is also used to send the response results in the cache to the service gateway.

[0023] Setting up a cache can improve the system's request response speed and increase the TPS value.

[0024] Furthermore, the service gateway is also used to determine whether the call request exceeds the concurrency limit; if it does, it stops receiving call requests.

[0025] It can limit the system's TPS value to prevent system crashes caused by exceeding the system's concurrent response limit.

[0026] Furthermore, the resource cloud includes one or more of the following: encryption service cloud, signature verification cloud, and dynamic password cloud. Attached Figure Description

[0027] Figure 1 This is a logical block diagram of the intelligent cryptography service platform in Implementation Example 1. Detailed Implementation

[0028] The following detailed description illustrates the specific implementation method:

[0029] Example 1

[0030] like Figure 1 As shown, the intelligent cryptographic service platform of this embodiment includes a service gateway, a synchronization module, a general server, a reverse proxy server, a learning database, a scheduling module, and several cryptographic devices.

[0031] The synchronization module is used to synchronize critical resources of cryptographic devices of the same type after the devices have connected to the network. For example, encryption machines and cryptographic cards involve key synchronization; timestamps and signature verification involve certificate synchronization; and other cryptographic devices determine the critical resources that need to be synchronized based on the nature of the device.

[0032] The general-purpose server is deployed with a virtualization module and a load balancing module. The load balancing module connects to cryptographic devices after synchronization of critical resources. The virtualization module uses virtualization technology to pool the physical resources of the cryptographic devices into resource pools, and virtualizes these resource pools into different types of resource clouds to shield the underlying implementation. The virtualization module also creates a cache for the resource clouds. The resource clouds include one or more of the following: encryption service cloud, signature verification cloud, and dynamic password cloud; in this embodiment, all of the above are included. In this embodiment, the load balancing module runs on the general-purpose server. In other embodiments, a load balancing cluster can be built as needed for hot standby and performance scaling. The load balancing module employs pipelining technology in conjunction with a caching mechanism to improve the system's concurrency capabilities.

[0033] The service gateway, as a service entrance, is configured to acquire a calling application of a third-party application service interface, and is further configured to analyze the calling application and determine an internal interface of the calling application according to a result of the analysis, i.e., a service request facing different resource clouds. Specifically, the service gateway determines whether the calling application is an authorized request according to the calling application, and if the calling application is not an authorized request, the service gateway rejects the calling application, thereby realizing calling permission control, i.e., allowing an authorized request to call and disallowing an unauthorized calling. The service gateway further performs concurrent limitation on the calling application, i.e., if the calling application exceeds the concurrent limitation, the service gateway stops receiving the calling application, thereby limiting the TPS value of the system and avoiding system crash caused by exceeding the number of concurrent responses of the system.

[0034] The service gateway is further configured to send service interface calling data to the learning database for storage, thereby realizing bypass diversion and avoiding increasing the burden of the system when the calling data is acquired from the data trunk.

[0035] The learning database is further configured to acquire device state data of the cryptographic device.

[0036] The scheduling module pre-stores an AI model, and is configured to train the AI model by using the service interface calling data and the device state data, so that the AI model obtains resource trend information of the cryptographic device, thereby being able to predict resource cloud load and device resource load in a future period of time, so as to optimize load balancing configuration. The scheduling module is further configured to correct the AI model according to a difference between an actual result and a predicted result after a preset number of training data is reached, so as to improve prediction accuracy of the AI model. In the embodiment, the preset number is 100,000.

[0037] The load balancing module is further configured to, after receiving a service request, perform load balancing judgment, i.e., obtaining a preliminary result according to a preset load balancing algorithm of different types of cryptographic devices, then comparing and correcting the preliminary result with a predicted result obtained by the AI model to obtain an optimal result, so as to determine a cryptographic device to be sent, and then performing service request distribution. The optimal result is the smallest resource consumption, meets the largest demand, and obtains the most satisfactory result, in other words, the maximum benefit.

[0038] In this embodiment, the load balancing algorithm obtains the monitoring result of the cryptographic device resource, and specifically uses the minimum pressure algorithm to obtain a preliminary result. Taking a certain server cryptographic machine as an example, on X month X day at 12 o'clock, the system receives a service request, at this time the load balancing module obtains that the A device has the minimum pressure at present through the minimum pressure algorithm, at this time the preliminary result is to plan to forward the request to the A device; but according to the prediction obtained by the AI model, the A device will be automatically closed and offline through the dynamic resource pool mechanism due to serious resource vacancy, therefore, after comparison, the request will be transferred to other devices; for example, although the A device has a small pressure at this time, the required request exceeds the capacity of the A device, and although the B device does not have the minimum pressure at this time, the B device can be released in the next moment according to the prediction, therefore, the system still forwards the request to the B device at this time.

[0039] The reverse proxy server is configured to receive the service request and forward the service request to the corresponding cryptographic device.

[0040] The cryptographic device is configured to respond to the service request after receiving the service request, and send the response result to the cache of the resource cloud through the reverse proxy server, and the load balancing module is further configured to send the response result in the cache to the service gateway; the service gateway sends the response result to the corresponding third-party application through the service interface. In this embodiment, the purpose of setting the cache is to improve the request response speed of the system and increase the TPS (transactions per second) value.

[0041] Specifically, the learning database is further configured to classify and store the device state data. In this embodiment, the classified device state data includes device load data and device fault data.

[0042] The AI model includes several types, including an interface call prediction model, a device state prediction model, a fault and problem handling model, and a load balancing configuration model. In this embodiment, the above models are constructed by combining a clustering analysis model and a time series model.

[0043] The scheduling module is configured to train the interface call prediction model by using the service interface call data in the learning database, so that the interface call prediction model obtains the call trend of the service interface according to the time distribution, thereby being able to predict the interface call trend in a future period of time.

[0044] The scheduling module is further configured to analyze the prediction result of the interface call prediction model to obtain the interface service call frequency in each time period of the day, the interface concurrency, the data flow, and the peak period warning. The scheduling module is further configured to alarm the IP or the third-party application whose call state abnormal number exceeds a set value.

[0045] The scheduling module is further configured to read the device state data from the learning database. Specifically, the device state prediction model is trained by the device load data, so that the device state prediction model obtains the resource trend of the cryptographic device, thereby being able to predict the device resource load in a future period of time.

[0046] The scheduling module is further configured to analyze the prediction result of the device state prediction model, to obtain the all-day operation of the cryptographic device, including the device resource load, the peak period, the idle period, the CPU utilization in each period, the memory occupancy in each period, and the TPS. Thus, the peak period can be prewarned.

[0047] The scheduling module is further configured to train the fault and problem handling model by the device fault data, so that the fault and problem handling model obtains the fault trend of the cryptographic device, thereby being able to predict the device fault probability in a future period of time.

[0048] The scheduling module is further configured to determine whether the device fault probability is higher than a threshold value according to the prediction result of the fault and problem handling model, i.e., the device fault probability in a future period of time. If the device fault probability is higher than the threshold value, an abnormal alarm is given before a system error occurs.

[0049] The scheduling module is further configured to train the load balancing configuration model by the service interface calling data and the device load data, so that the load balancing configuration model obtains the resource trend of the cryptographic device, thereby being able to predict the resource cloud load and the device resource load in a future period of time. The load balancing module is further configured to dynamically configure and adjust the load balancing scheme of the resource cloud according to the prediction result of the load balancing configuration model, so as to achieve the optimization of resource use. The future period of time can be set according to actual conditions, such as 3 hours, 6 hours, 12 hours, 24 hours, 48 hours, 72 hours, 168 hours, etc. Considering the data fluctuation caused by weekends and holidays, a correction factor can be added for correction.

[0050] The cryptographic service platform of the embodiment is used to process a response process as follows.

[0051] The unified service interface is used to receive the calling application of the third-party application; the calling application is parsed, the internal interface of the calling is determined according to the parsed result, and the service request of the third-party application is forwarded to the resource cloud of the corresponding internal interface;

[0052] After the service request is forwarded to the resource cloud, the service request is immediately disconnected, and the resource is released (the disconnection in the embodiment is based on the pipeline technology, and the connection in the pre-established connection pool will not be released, and the same applies below), which is used for other service requests.

[0053] Then the load balancing module obtains a preliminary result according to the load balancing algorithm preset by the different types of cryptographic devices, and then compares and corrects the preliminary result with the prediction result obtained by the load balancing configuration model to determine the corresponding cryptographic device, and then distributes the service request, after the service request distribution, disconnects the connection and releases the resources.

[0054] The reverse proxy server sends the service request to the corresponding cryptographic device;

[0055] After the cryptographic device receives the service request, it performs corresponding processing, on the one hand, the device state prediction model can be evaluated in this process to give a prediction result of the processing completion time, and the prediction result is sent to the load balancing module; on the other hand, after the cryptographic device completes the processing of the service request, the processing result is returned to the cache of the resource cloud through the reverse proxy server.

[0056] After the load balancing module receives the prediction result, it establishes a connection with the service gateway in advance, then reads the processing result from the cache and returns it to the upper layer service gateway, and then the service gateway sends it to the third-party application through the service interface.

[0057] The scheme of the embodiment integrates different manufacturers and different types of cryptographic devices, combines the cryptographic device resources into a heterogeneous resource cloud based on virtualization technology, provides a unified interface service and a resource cloud according to the type, and can flexibly network the cryptographic devices, facilitate the use of old devices, save existing resources, save costs, shield the details of the cryptographic device resource composition, improve the running efficiency, and reduce the operation and maintenance complexity.

[0058] Through the AI model, load balancing is realized to achieve the purpose of intelligent dynamic scheduling, improve system reliability, prolong device life, reduce operation and maintenance time, and reduce device energy consumption.

[0059] Embodiment two

[0060] The difference between the embodiment and the embodiment one is that in the initial stage of platform construction and operation, the same type of cryptographic devices form a resource pool through a virtual module after synchronizing the key resources.

[0061] In the system operation process, the resource consumption of different cryptographic devices and the overall system resource usage are obtained through device load data; in the embodiment, the overall system resource usage refers to the aggregation of the resource consumption of the same type of cryptographic devices.

[0062] The scheduling module learns the load balancing configuration model in depth through such data, and predicts the device resource load of different cryptographic devices and the overall system resource usage in a future period of time through the load balancing configuration model.

[0063] If the difference between the predicted system total resources and the product of the current system total resources and the system security redundancy coefficient is greater than the resource capacity of a certain cryptographic device, the virtual module is further configured to set the cryptographic device as a redundant device, and the load balancing module is configured to transfer service requests on the cryptographic device to other cryptographic devices, so as to shut down the device and save energy and device wear; the system security redundancy coefficient is used to ensure that the resources will not reach 100% utilization, and is initially 1.2-1.3.

[0064] If the difference between the quotient of the current system total resources divided by the system security redundancy coefficient and the predicted system total resources used in the future is less than 0, the virtual module is further configured to issue a resource shortage warning, and automatically start the cryptographic device in the off state to increase system resources.

[0065] In summary, by using the prediction results of the load balancing configuration model, the cryptographic device can be automatically started and stopped, and the purpose of dynamically constructing a resource pool is achieved.

[0066] Embodiment Three

[0067] The difference between this embodiment and embodiment two is that in this embodiment, the scheduling module is further configured to determine whether the cryptographic device needs to be expanded according to the predicted system total resource usage in the future; for example, if the system total resource usage is always in a full load state, it is determined that the cryptographic device needs to be expanded. The scoring is performed after the expansion is predicted, which can make the score best reflect the current device state.

[0068] If the cryptographic device needs to be expanded, the order of the cryptographic devices for scoring is determined according to the predicted device resource load of different cryptographic devices in the future. In this embodiment, the devices are sorted from high to low according to the device resource load, and a single cryptographic device can be scored, or multiple cryptographic devices can be scored simultaneously. The scheduling module is further configured to mark the cryptographic devices in the score, and the load balancing module is further configured to, after receiving a service request, preferentially distribute the service request to the cryptographic devices in the score, and when the cryptographic devices in the score cannot handle the service request, the load balancing module determines the cryptographic device to be sent.

[0069] The scheduling module is further configured to score the cryptographic devices according to the device failure data of the cryptographic devices, generate a device suggestion table according to the scores of the cryptographic devices of the same type in descending order, and provide a reference for relevant personnel to select appropriate manufacturers and appropriate models of devices when expansion is performed. For example, a failure score X = -(a * λ1) - (b * λ2) - (c * λ3) + (d * λ4), where a is the total number of failures per unit working time, b is the total repair time per unit working time, c is the number of failures during peak hours per unit working time, and d is the accuracy of the device failure probability prediction of the failure and problem handling model; λ1, λ2, λ3, and λ4 are weight coefficients that can be individually set according to actual conditions; in this embodiment, the unit working time is 500 hours.

[0070] The above is only an embodiment of the present application, and the application is not limited to this embodiment. The application is not limited to the field to which this embodiment relates, and common knowledge about specific structures and characteristics in the scheme is not described in detail. Those skilled in the art know all the common technical knowledge in the field to which the application belongs before the filing date or the priority date, can know all the prior art in the field, and have the ability to apply conventional experimental means before that date. Those skilled in the art can improve and implement the scheme based on their own abilities under the guidance of this application, and some typical known structures or known methods should not be an obstacle to the implementation of the application by those skilled in the art. It should be noted that, for those skilled in the art, without departing from the structure of the present application, a number of modifications and improvements can be made, which should also be considered as the protection scope of the present application, and these will not affect the implementation effect and practicality of the patent. The protection scope of the present application should be subject to the content of its claims, and the specific implementation mode and the like in the specification can be used to explain the content of the claims.

Claims

1. An intelligent password service platform, characterized in that, The system comprises a service gateway, a synchronization module, a general server, a reverse proxy server and a plurality of cryptographic devices; The synchronization module is configured to synchronize key resources of the same type of cryptographic devices after the cryptographic devices access the network; The general server is provided with a virtual module and a load balancing module, the load balancing module is configured to connect the cryptographic devices after the key resource synchronization, and the virtual module is configured to virtualize the physical resources of the cryptographic devices into different types of resource clouds through a virtualization technology; The service gateway is configured to obtain a calling application of a third-party application service interface, and is further configured to analyze the calling application and determine a service request facing different resource clouds according to the analysis result; The load balancing module is further configured to determine the cryptographic device to be sent after receiving the service request and performing load balancing judgment; The reverse proxy server is configured to receive the service request and forward the service request to the corresponding cryptographic device; The cryptographic device is configured to respond to the service request after receiving the service request, and send the response result to the resource cloud through the reverse proxy server, and the load balancing module is further configured to send the response result to the service gateway; the service gateway is further configured to send the response result to the corresponding third-party application through the service interface; The system further comprises a learning database, and the service gateway is further configured to send the service interface calling data to the learning database for storage; the learning database is further configured to obtain device state data of the cryptographic device and store the device state data; The system further comprises a scheduling module, the scheduling module pre-stores an AI model, and the scheduling module is configured to train the AI model through the service interface calling data and the device state data, so that the AI model obtains resource trend information of the cryptographic device; the scheduling module is further configured to predict the resource cloud load and the device resource load in a future period of time through the AI model; The load balancing module is further configured to obtain a preliminary result according to a load balancing algorithm preset for different types of cryptographic devices when performing load balancing judgment, and then compare and correct the preliminary result and a prediction result obtained by the AI model to obtain an optimal result, and determine the cryptographic device to be sent; The scheduling module is further configured to correct the AI model according to the difference between the actual result and the prediction result after the training data reaches a set number; In the initial stage of platform construction and operation, the same type of cryptographic devices form a resource pool through the virtual module after key resource synchronization; In the system operation process, the resource consumption of different cryptographic devices and the overall system resource usage are obtained through device load data; The scheduling module performs deep learning on the load balancing configuration model through such data, and predicts the device resource load of different cryptographic devices and the overall system resource usage in a future period of time through the load balancing configuration model; If the difference between the predicted overall system resource and the product of the current overall system resource and a system safety redundancy coefficient is greater than the resource capacity of a cryptographic device, the virtual module is further configured to set the cryptographic device as a spare device, and the load balancing module is configured to transfer the service request on the cryptographic device to other cryptographic devices; The system safety redundancy coefficient is used to ensure that the resource usage rate is not 100%, and is initially set to 1.2-1.

3. If the difference between the quotient of the total resources of the current system divided by the system security redundancy coefficient and the predicted total resources of the system used in the future period of time is less than 0, the virtual module is further used to issue a resource shortage warning, and automatically start the cryptographic device in the off state. 2.The intelligent password service platform according to claim 1, characterized in that: The virtual module is further used to create a cache of the resource cloud, and the cryptographic device is further used to send the response result to the cache of the resource cloud through the reverse proxy server, and the load balancing module is further used to send the response result in the cache to the service gateway. 3.The intelligent password service platform of claim 1, wherein: The service gateway is further used to determine whether the calling application exceeds the concurrency limit, and if so, stop receiving the calling application.

4. The intelligent password service platform of claim 1, wherein: The resource cloud includes one or more of an encryption service cloud, a signature verification cloud, and a dynamic password cloud.

Citation Information

Patent Citations

  • System and method for providing cryptographic service through virtual cryptographic equipment cluster

    CN107040589A

Cited By

  • Load balancing password service platform based on digital certificate and task scheduling method thereof

    CN121770753A