A communication method, apparatus, electronic device, and computer storage medium

By exchanging keys and authentication information between the cloud management platform and virtual service nodes, the problem of the cloud management platform being unable to modify the image file configuration is solved, and secure and efficient communication is achieved.

CN115580460BActive Publication Date: 2026-03-31SANGFOR TECH INC
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-28
Publication Date
2026-03-31

AI Technical Summary

Technical Problem

The cloud management platform cannot modify the image file configuration when creating a virtual firewall service, which requires communication to be achieved by hardcoding a default key, increasing workload and posing security risks.

Method used

The cloud management platform sends the first key and identification information to the virtual service node. The virtual service node generates and encrypts the second key and authentication information. After decryption, the cloud management platform obtains and deletes the key exchange interface to achieve secure communication.

Benefits of technology

It reduces the workload of the cloud management platform, improves communication security, and avoids the risks associated with hard-coded default keys.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115580460B_ABST
    Figure CN115580460B_ABST
Patent Text Reader

Abstract

This invention provides a communication method, apparatus, electronic device, and computer storage medium. The method is applied to a cloud management platform, which manages virtual service nodes within the cloud platform. The method includes: sending a first key and first identification information of the first key to the virtual service node; receiving encrypted first exchange information sent by the virtual service node, the first exchange information including at least: a second key generated by the virtual service node and authentication information; the encrypted first exchange information is information obtained by the virtual service node encrypting the first exchange information according to the first key; decrypting the encrypted first exchange information according to the first key to obtain the second key and authentication information; and communicating with the virtual service node according to the second key and authentication information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to a communication method, and more particularly to a communication method, apparatus, electronic device, and computer storage medium. Background Technology

[0002] Cloud computing platforms, also known as cloud services, refer to services based on hardware and software resources. Users can access or use virtual services within the cloud platform simply by using a cloud management platform, greatly improving development efficiency. For example, a user can create a virtual firewall service for their business through a cloud management platform and access or manage it directly without a key. However, it's important to note that while cloud platforms typically provide a generic image file for creating virtual firewall services, they cannot modify the image file configuration during creation and therefore cannot obtain the key to access the virtual firewall service. This means that subsequent management of the virtual firewall service through the cloud management platform requires hard-coding default keys, increasing the workload and reducing efficiency. Furthermore, using hard-coded default keys poses significant security risks, potentially leading to attacks on the cloud service. Therefore, effectively ensuring secure communication between the cloud management platform and other virtual services is a crucial technical challenge that needs to be addressed. Summary of the Invention

[0003] This invention provides a communication method, apparatus, electronic device, and computer storage medium.

[0004] This invention provides a communication method applied to a cloud management platform, wherein the cloud management platform is used to manage virtual service nodes in the cloud platform; the method includes:

[0005] Send the first key and the first identification information of the first key to the virtual service node;

[0006] The system receives encrypted first exchange information sent by the virtual service node, the first exchange information including at least: a second key generated by the virtual service node and authentication information; the encrypted first exchange information is information obtained by the virtual service node encrypting the first exchange information according to the first key;

[0007] The encrypted first exchange information is decrypted using the first key to obtain the second key and the authentication information.

[0008] Communicate with the virtual service node based on the second key and the authentication information.

[0009] In the above scheme, sending the first key and the first identifier information of the first key to the virtual service node includes:

[0010] The first key and its first identifier information are sent to the virtual service node through a key exchange interface; the key exchange interface is an interface created by the virtual service node.

[0011] The receiving of the encrypted first exchange information sent by the virtual service node includes:

[0012] Receive the encrypted first exchange information sent by the virtual service node through the key exchange interface;

[0013] Before communicating with the virtual service node based on the second key and the authentication information, the method further includes:

[0014] Send an instruction to the virtual service node to delete the key exchange interface.

[0015] In the above scheme, the first exchange information further includes the first identification information; the step of decrypting the encrypted first exchange information according to the first key to obtain the second key and the authentication information includes:

[0016] The encrypted first exchange information is decrypted using the first key to obtain the decrypted information.

[0017] If the decrypted information includes the first identification information, the second key and authentication information are obtained based on the decrypted information.

[0018] In the above scheme, the first exchange information further includes a sending time, which is the time when the virtual service node sends the encrypted first exchange information to the cloud management platform; the step of decrypting the encrypted first exchange information according to the first key to obtain the second key and the authentication information includes:

[0019] The encrypted first exchange information is decrypted using the first key to obtain the sending time;

[0020] Based on the sending time, the sending duration is determined, where the sending duration is the time from the sending time to the current time;

[0021] If the sending time is less than the preset expiration time, the second key and authentication information are obtained based on the decrypted information.

[0022] This invention also provides another communication method applied to virtual service nodes; the method includes:

[0023] The system receives a first key and its first identifier information from a cloud management platform; the cloud management platform is used to manage virtual service nodes in the cloud platform.

[0024] Generate a second key and authentication information;

[0025] The first exchange information is encrypted using the first key to obtain encrypted first exchange information; the first exchange information includes at least the second key and the authentication information.

[0026] The cloud management platform sends encrypted first exchange information to the cloud management platform, which then decrypts the encrypted first exchange information using the first key to obtain the second key and the authentication information. The cloud management platform then communicates with the virtual service node using the second key and the authentication information.

[0027] In the above scheme, before receiving the first key and the first identifier information of the first key sent by the cloud management platform, the method further includes:

[0028] Create a key exchange interface;

[0029] The first key and the first identifier information of the first key sent by the cloud management platform include:

[0030] The key exchange interface receives the first key and the first identification information of the first key sent by the cloud management platform.

[0031] The step of sending the encrypted first exchange information to the cloud management platform includes:

[0032] The encrypted first exchange information is sent to the cloud management platform through the key exchange interface;

[0033] After sending the encrypted first exchange information to the cloud management platform, the method further includes:

[0034] Receive the instruction from the cloud management platform to delete the key exchange interface;

[0035] The key exchange interface is deleted according to the deletion instruction.

[0036] In the above scheme, generating the second key and authentication information includes:

[0037] A second key and authentication information are randomly generated.

[0038] This invention also provides a communication device applied to a cloud management platform, the cloud management platform being used to manage virtual service nodes in the cloud platform; the device includes at least:

[0039] The first sending module is used to send a first key and first identification information of the first key to the virtual service node;

[0040] A first receiving module is configured to receive encrypted first exchange information sent by the virtual service node, wherein the first exchange information includes at least: a second key generated by the virtual service node and authentication information; the encrypted first exchange information is information obtained by the virtual service node encrypting the first exchange information according to the first key.

[0041] The decryption module is used to decrypt the encrypted first exchange information according to the first key to obtain the second key and the authentication information;

[0042] The communication module is used to communicate with the virtual service node based on the second key and the authentication information.

[0043] In one implementation, the sending module is configured to send a first key and first identification information of the first key to the virtual service node, including:

[0044] The first key and its first identifier information are sent to the virtual service node through a key exchange interface; the key exchange interface is an interface created by the virtual service node.

[0045] The receiving module is used to receive the encrypted first exchange information sent by the virtual service node, including:

[0046] Receive the encrypted first exchange information sent by the virtual service node through the key exchange interface;

[0047] The communication module, used to communicate with the virtual service node based on the second key and the authentication information, further includes:

[0048] Send an instruction to the virtual service node to delete the key exchange interface.

[0049] In one implementation, the first exchange information further includes the first identification information; the obtaining module is configured to decrypt the encrypted first exchange information according to the first key to obtain the second key and the authentication information, including:

[0050] The encrypted first exchange information is decrypted using the first key to obtain the decrypted information.

[0051] If the decrypted information includes the first identification information, the second key and authentication information are obtained based on the decrypted information.

[0052] In one implementation, the first exchange information further includes a sending time, which is the time when the virtual service node sends the encrypted first exchange information to the cloud management platform; the obtaining module is used to decrypt the encrypted first exchange information according to the first key to obtain the second key and the authentication information, including:

[0053] The encrypted first exchange information is decrypted using the first key to obtain the sending time;

[0054] Based on the sending time, the sending duration is determined, where the sending duration is the time from the sending time to the current time;

[0055] If the sending time is less than the preset expiration time, the second key and authentication information are obtained based on the decrypted information.

[0056] This invention also provides another communication device for use in virtual service nodes; the device includes at least:

[0057] The second receiving module is used to receive a first key and a first identification information of the first key sent by the cloud management platform; the cloud management platform is used to manage virtual service nodes in the cloud platform.

[0058] The generation module is used to generate a second key and authentication information;

[0059] An encryption module is used to encrypt the first exchange information according to the first key to obtain encrypted first exchange information; the first exchange information includes at least: the second key and the authentication information;

[0060] The second sending module is used to send encrypted first exchange information to the cloud management platform, so that the cloud management platform can decrypt the encrypted first exchange information according to the first key to obtain the second key and the authentication information, and enable the cloud management platform to communicate with the virtual service node according to the second key and the authentication information.

[0061] In one implementation, the receiving module is configured to receive a first key and first identification information of the first key sent by the cloud management platform, including:

[0062] Before receiving the first key and the first identifier information of the first key sent by the cloud management platform, a key exchange interface is created;

[0063] The key exchange interface receives the first key and the first identification information of the first key sent by the cloud management platform.

[0064] The sending module is used to send encrypted first exchange information to the cloud management platform, including:

[0065] The encrypted first exchange information is sent to the cloud management platform through the key exchange interface;

[0066] After sending the encrypted first exchange information to the cloud management platform, the system receives an instruction from the cloud management platform to delete the key exchange interface.

[0067] The key exchange interface is deleted according to the deletion instruction.

[0068] In one implementation, the generation module is used to generate a second key and authentication information, including:

[0069] A second key and authentication information are randomly generated.

[0070] This invention also provides an electronic device, including a first memory, a first processor, and a computer program stored in the first memory and executable on the first processor. When the first processor executes the program, it implements any of the above-described communication methods applied to the cloud management platform.

[0071] This invention also provides another electronic device, including a second memory, a second processor, and a computer program stored in the second memory and executable on the second processor. When the second processor executes the program, it implements any of the above-described communication methods applied to the virtual service node.

[0072] This invention also provides a computer storage medium storing a computer program that, when executed by a processor, implements any of the above-described communication methods.

[0073] This invention provides a communication method, apparatus, electronic device, and computer storage medium. The method involves sending a first key and first identification information of the first key to a virtual service node; receiving encrypted first exchange information sent by the virtual service node, wherein the first exchange information includes at least a second key generated by the virtual service node and authentication information; the encrypted first exchange information is obtained by the virtual service node encrypting the first exchange information using the first key; decrypting the encrypted first exchange information using the first key to obtain the second key and the authentication information; and communicating with the virtual service node using the second key and the authentication information.

[0074] As can be seen, in this embodiment of the invention, the cloud management platform sends a first key and a first identifier of the first key to the virtual service node, enabling the virtual service node to encrypt the first exchange information according to the first key and send the encrypted first exchange information to the cloud management platform. Here, the first exchange information includes at least a second key generated by the virtual service node and authentication information. The cloud management platform can decrypt the encrypted first exchange information according to the first key to obtain the second key and authentication information, thereby enabling the management of the virtual service node and communication with it. It can be seen that in this embodiment of the invention, the cloud management platform and the virtual service node exchange key information, enabling the cloud management platform to communicate with the virtual service node based on the virtual service node's key information. This avoids communication through hard-coded default keys, reduces the workload of the cloud management platform, and improves the communication security between the cloud management platform and other virtual service nodes.

[0075] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this application. Attached Figure Description

[0076] Figure 1 A flowchart illustrating a communication method provided in an embodiment of the present invention;

[0077] Figure 2 A flowchart illustrating another communication method provided in an embodiment of the present invention;

[0078] Figure 3 A flowchart illustrating a specific implementation of a communication method provided in an embodiment of the present invention;

[0079] Figure 4 A schematic diagram of a communication device provided in an embodiment of the present invention;

[0080] Figure 5 A schematic diagram of another communication device provided in an embodiment of the present invention;

[0081] Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention;

[0082] Figure 7 This is a schematic diagram of another electronic device provided in an embodiment of the present invention. Detailed Implementation

[0083] In related technologies, cloud management platforms need to communicate with virtual services provided within the cloud platform. For example, a user can create their own virtual firewall service through the cloud management platform. Based on the virtual firewall service's key information, the user can communicate with the virtual firewall service through the cloud management platform. However, the cloud management platform cannot modify the image file configuration when creating the virtual firewall service, meaning it cannot obtain the key information to access the virtual firewall service. This necessitates the use of hard-coded default keys to manage the virtual firewall service through the cloud management platform, increasing the workload of the cloud platform and posing certain security risks. Therefore, how to efficiently ensure the secure communication between the cloud management platform and other virtual services is a pressing technical problem that needs to be solved.

[0084] To address the aforementioned technical problems, this disclosure proposes technical solutions based on embodiments. The embodiments of the present invention will be further described in detail below with reference to the accompanying drawings and examples. It should be understood that the embodiments provided herein are merely illustrative of the invention and are not intended to limit the invention. Furthermore, the embodiments provided below are partial embodiments for implementing the present invention, not all embodiments for implementing the present invention. Unless otherwise specified, the technical solutions described in the embodiments of the present invention can be implemented in any combination.

[0085] It should be noted that, in the embodiments of the present invention, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a method or apparatus that includes a list of elements includes not only the elements expressly stated, but also other elements not expressly listed, or elements inherent to implementing the method or apparatus. Without further limitations, an element defined by the phrase "comprising a..." does not exclude the presence of other related elements (e.g., steps in the method or units in the apparatus, such as portions of circuitry, processors, programs, or software, etc.) in the method or apparatus that includes that element.

[0086] In this document, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. Furthermore, the term "at least one" in this document means any combination of at least two of any one or more elements. For example, including at least one of A, B, and C can mean including any one or more elements selected from the set consisting of A, B, and C.

[0087] For example, a communication method provided in an embodiment of the present invention includes a series of steps, but the communication method provided in an embodiment of the present invention is not limited to the steps described. Similarly, a communication device provided in an embodiment of the present invention includes a series of modules, but the communication device provided in an embodiment of the present invention is not limited to the modules explicitly described, but may also include modules that need to be set up for obtaining relevant information or processing based on information.

[0088] Embodiments of the present invention can be implemented based on terminals and / or servers. Here, the terminal can be a thin client, a thick client, a handheld or laptop device, a microprocessor-based system, a set-top box, a programmable consumer electronics product, a network personal computer, a minicomputer system, etc. The server can be a minicomputer system, a mainframe computer system, and a distributed cloud computing environment that includes any of the above systems, etc.

[0089] Servers and other electronic devices may include program modules that execute computer instructions. Typically, program modules may include routines, programs, object programs, components, logic, data structures, etc., which perform specific tasks. Computer systems / servers can be implemented in distributed cloud computing environments, where tasks are performed by remote processing devices linked via communication networks. In distributed cloud computing environments, program modules can reside on local or remote computing system storage media, including storage devices.

[0090] Figure 1 This is a flowchart illustrating a communication method provided in an embodiment of the present invention. The method is applied to a cloud management platform, which manages virtual service nodes within the cloud platform, such as... Figure 1 As shown, the process may include:

[0091] Step 101: Send the first key and the first identifier information of the first key to the virtual service node;

[0092] In this embodiment of the invention, a cloud platform refers to a service based on hardware and software resources, which has the ability to provide computing, networking and storage; a virtual service refers to a dynamically scalable and virtualized resource provided by the cloud platform, and a virtual service node is used to send, receive or forward information through a communication channel.

[0093] In this embodiment of the invention, the first secret key and its first identifier information are generated and stored by the cloud management platform. The secret key (SK) is used to encrypt and / or decrypt information to be transmitted, and the identifier information is the key's sequence number (SEQ). The corresponding secret key can be determined based on the identifier information.

[0094] For example, the information stored in the cloud management platform includes: a first key of ABC, and a first identifier of the first key of 123. When the cloud management platform receives information encrypted with the key and the first identifier of 123, it can determine that the encryption key is ABC based on the first identifier, thereby decrypting the encrypted information.

[0095] Step 102: Receive the encrypted first exchange information sent by the virtual service node. The first exchange information includes at least: a second key generated by the virtual service node and authentication information; the encrypted first exchange information is the information obtained by the virtual service node encrypting the first exchange information according to the first key.

[0096] In this embodiment of the invention, both the second key and the authentication information are generated by the virtual service node. The cloud management platform can manage the virtual service node or communicate with it based on the second key and the authentication information. It should be noted that the authentication information (Access Key, AK) is used to identify the identity information of the accessing user.

[0097] In this embodiment of the invention, the first exchange information represents information sent by the virtual service node to the cloud management platform, and the first exchange information includes at least a second key and authentication information. The virtual service node encrypts the first exchange information according to the first key sent by the cloud management platform, and then sends the encrypted first exchange information to the cloud management platform.

[0098] Step 103: Decrypt the encrypted first exchange information using the first key to obtain the second key and authentication information;

[0099] In this embodiment of the invention, the key can encrypt and / or decrypt the transmitted information. Since the first exchange information is encrypted according to the first key, the cloud management platform can decrypt the encrypted first exchange information according to the first key to obtain the first exchange information, that is, it can obtain the second key and authentication information of the virtual service node.

[0100] For example, the information stored in the cloud management platform includes: a first key of ABC, a first identifier of the first key of 123, and first exchange information encrypted according to the first key sent by a virtual service node. The first exchange information includes: a second key generated by the virtual service node of ABCD, and authentication information of abcd. The cloud management platform decrypts the first exchange information according to the first key to obtain the second key of ABCD and the authentication information of abcd.

[0101] Step 104: Communicate with the virtual service node based on the second key and authentication information.

[0102] In this embodiment of the invention, the cloud management platform can verify the identity information with the virtual service node to prove that the cloud management platform has the authority to communicate with the virtual service node; when the cloud management platform sends information to the virtual service node, it can encrypt the sent information according to the second key to ensure the security of information transmission and prevent the information from being tampered with or stolen during transmission.

[0103] For example, when the cloud management platform communicates with the virtual service node, it sends information encrypted with a second key and authentication information to the virtual service node. After receiving the encrypted information and authentication information, the virtual service node verifies that the cloud management platform has the authority to communicate with the virtual service node based on the authentication information. Then, it finds the corresponding second key based on the authentication information and decrypts the encrypted information using the second key to obtain the decrypted information, thereby completing the authentication and data transmission.

[0104] In practical applications, steps 101 to 104 are implemented using a processor based on an electronic device. The processor can be at least one of the following: Application Specific Integrated Circuit (ASIC), Digital Signal Processor (DSP), Digital Signal Processing Device (DSPD), Programmable Logic Device (PLD), Field Programmable Gate Array (FPGA), Central Processing Unit (CPU), controller, microcontroller, and microprocessor.

[0105] As can be seen, in this embodiment of the invention, firstly, the cloud management platform sends a first key and its first identifier information to the virtual service node. Then, the virtual service node generates a second key and authentication information to form first exchange information, encrypts the first exchange information according to the first key, and sends the encrypted first exchange information to the cloud management platform. Finally, the cloud management platform decrypts the encrypted first exchange information according to the first key, thereby obtaining the virtual service node's second key and authentication information, and can communicate with the virtual service node based on the second key and authentication information. It can be seen that in this embodiment of the invention, the cloud management platform and the virtual service node exchange key information, enabling the cloud management platform to obtain the virtual service node's second key and authentication information, thus achieving communication with the virtual service node. This avoids communication through hard-coded default keys, reduces the workload of the cloud management platform, and effectively improves the communication security between the cloud management platform and other virtual service nodes.

[0106] In some implementations, sending a first key and first identification information of the first key to the virtual service node includes:

[0107] The first key and its first identifier information are sent to the virtual service node through the key exchange interface; the key exchange interface is an interface created by the virtual service node.

[0108] Receive the encrypted first exchange information sent by the virtual service node, including:

[0109] Receive the encrypted first exchange information sent by the virtual service node through the key exchange interface;

[0110] Before communicating with the virtual service node based on the second key and authentication information, the method further includes:

[0111] Send a command to the virtual service node to delete the key exchange interface.

[0112] In some embodiments, the key exchange interface is an interface created by the virtual service node for the virtual service node and the cloud management platform to exchange key information. For example, when a user requests access to a virtual service on the cloud management platform, the platform creates a virtual machine using the corresponding image file of the virtual service and assigns a temporary Internet Protocol (IP) address to the virtual machine. The cloud management platform confirms the temporary IP address of the newly created virtual machine using Dynamic Host Configuration Protocol (DHCP). It should be noted that DHCP is typically used in large local area network environments, primarily for centralized management and allocation of IP addresses, enabling hosts in the network environment to dynamically obtain IP addresses. After the cloud management platform obtains the temporary IP address of the newly created virtual machine, the server defaults to creating only one interface per virtual service node: the key exchange interface.

[0113] In some embodiments, the cloud management platform can access the key exchange interface of the temporary IP address to send the cloud management platform's key information to the virtual service node, and the virtual service node can also send its key information and authentication information to the cloud management platform through the key exchange interface.

[0114] In some embodiments, since the key exchange interface is unprotected on the first access, meaning that no key is required to access the key exchange interface, there is a possibility of race condition attacks. Therefore, after the cloud management platform obtains the key information and authentication information of the virtual service node, the cloud management platform will send an instruction to the virtual service node to delete the key exchange interface, requiring the virtual service node to delete the key exchange interface and configure the application programming interface (API) of the virtual service node to realize communication between the cloud management platform and the virtual service node.

[0115] As can be seen, the key exchange interface is a one-time interface, meaning that it is closed after the cloud management platform and the virtual service node exchange key information once. This prevents the key exchange interface from being reused, prevents other virtual service nodes from attacking the key exchange interface, and prevents key information from being stolen or tampered with, thereby improving the communication security between the cloud management platform and the virtual service node.

[0116] In some implementations, the first exchange information further includes the first identification information; the step of decrypting the encrypted first exchange information according to the first key to obtain the second key and the authentication information includes:

[0117] The encrypted first exchange information is decrypted using the first key to obtain the decrypted information.

[0118] If the decrypted information includes the first identification information, the second key and authentication information are obtained based on the decrypted information.

[0119] In some embodiments, the first exchange information sent by the virtual service node to the cloud management platform also includes first identification information. The information stored in the cloud management platform also includes a first key and the first identification information of the first key. Therefore, the cloud management platform decrypts the encrypted first exchange information according to the first key and compares the decrypted information with the first identification information. If the decrypted information includes the first identification information, it indicates that the comparison is successful, that is, the information sent by the virtual service node has not been tampered with. Then, the cloud management platform stores the second key and authentication information obtained after decryption in the cloud management platform as credentials for subsequent communication with the virtual service node.

[0120] It can be seen that by comparing the decrypted information with the first identification information stored in the cloud management platform, and by determining whether the decrypted information includes the first identification information, the cloud management platform can determine whether the first exchanged information has been tampered with during transmission, which can effectively improve the security of information transmission between the cloud management platform and the virtual service node.

[0121] In some implementations, the first exchange information further includes a sending time, which is the time when the virtual service node sends the encrypted first exchange information to the cloud management platform; the step of decrypting the encrypted first exchange information according to the first key to obtain the second key and the authentication information includes:

[0122] The encrypted first exchange information is decrypted using the first key to obtain the sending time;

[0123] Based on the sending time, the sending duration is determined, where the sending duration is the time from the sending time to the current time;

[0124] If the sending time is less than the preset expiration time, the second key and authentication information are obtained based on the decrypted information.

[0125] In some embodiments, the preset expiration time can be pre-set based on existing experience. If the sending time is greater than or equal to the preset expiration time, it indicates that the virtual service node takes a long time to send the first exchange information, and the first exchange information may be tampered with or sent incorrectly. Therefore, the first exchange information is invalidated. If the sending time is less than the preset expiration time, it indicates that the virtual service node takes a short time to send the first exchange information, and the first exchange information is less likely to be tampered with. Therefore, the first exchange information is valid, and the cloud management platform stores the decrypted second key and authentication information in the cloud management platform as credentials for subsequent communication with the virtual service node.

[0126] It can be seen that the cloud management platform determines whether the first exchange information has expired based on the sending time of the first exchange information sent by the virtual service node. This can effectively prevent the cloud management platform from receiving expired exchange information, which would prevent the cloud management platform and the virtual service node from communicating. This can further improve the security of information transmission between the cloud management platform and the virtual service node.

[0127] Figure 2 This is a flowchart illustrating another communication method provided in an embodiment of the present invention. This method is applied to virtual service nodes, such as... Figure 2 As shown, the process may include:

[0128] Step 201: Receive the first key and the first identifier information of the first key sent by the cloud management platform. The cloud management platform is used to manage the virtual service nodes in the cloud platform.

[0129] In this embodiment of the invention, the first key and the first identifier information of the first key are generated by the cloud management platform, and the virtual service node can encrypt the data that needs to be sent to the cloud management platform according to the first key.

[0130] Step 202: Generate a second key and authentication information.

[0131] In this embodiment of the invention, the second key is used to encrypt and / or decrypt the information to be transmitted, and the authentication information is used to identify the identity information of the accessing user.

[0132] Step 203: Encrypt the first exchange information according to the first key to obtain the encrypted first exchange information; the first exchange information includes at least: the second key and authentication information.

[0133] In this embodiment of the invention, the first exchange information is information sent by the virtual service node to the cloud management platform. The first exchange information includes at least a second key randomly generated by the virtual service node and authentication information. The virtual service node encrypts the first exchange information according to the first key sent by the cloud management platform and sends it to the cloud management platform.

[0134] Step 204: Send the encrypted first exchange information to the cloud management platform, so that the cloud management platform can decrypt the encrypted first exchange information according to the first key to obtain the second key and authentication information, and enable the cloud management platform to communicate with the virtual service node according to the second key and authentication information.

[0135] In this embodiment of the invention, since the first exchange information is encrypted using a first key, the cloud management platform can decrypt the encrypted first exchange information using the first key to obtain the first exchange information, which in turn yields the second key and authentication information of the virtual service node. The cloud management platform stores the decrypted second key and authentication information in the cloud management platform as credentials for subsequent communication with the virtual service node.

[0136] As can be seen, in this embodiment of the invention, the virtual service node generates a second key and authentication information to form a first exchange information, and encrypts the first exchange information according to the first key sent by the cloud management platform before sending it to the cloud management platform. This allows the cloud management platform to decrypt the first exchange information according to the first key to obtain the second key and authentication information of the virtual service node, thereby enabling communication with the cloud management platform. This avoids communication through hard-coded default keys and effectively improves the communication security between the cloud management platform and other virtual service nodes.

[0137] In some implementations, before receiving the first key and the first identifier information of the first key sent by the cloud management platform, the method further includes:

[0138] Create a key exchange interface;

[0139] Receive the first key and the first identifier information of the first key sent by the cloud management platform, including:

[0140] Receive the first key and the first identifier information of the first key sent by the cloud management platform through the key exchange interface;

[0141] Send the encrypted first exchange information to the cloud management platform, including:

[0142] Send the encrypted first exchange information to the cloud management platform through the key exchange interface;

[0143] After sending the encrypted first exchange information to the cloud management platform, the method further includes:

[0144] Receive instructions from the cloud management platform to delete the key exchange interface;

[0145] The key exchange interface is deleted according to the deletion instruction.

[0146] In some embodiments, the virtual service is created by the cloud management platform based on the corresponding image file of the virtual service. First, the cloud management platform creates a virtual machine for the virtual service and assigns a temporary IP address to the virtual machine. After the cloud management platform obtains the temporary IP address of the newly created virtual machine by starting DHCP, the virtual service node only creates one interface, namely the key exchange interface. The key exchange interface is used for the virtual service node and the cloud management platform to transmit key information to each other.

[0147] In some embodiments, since the key exchange interface can be accessed without a key the first time, it is vulnerable to race-state attacks by other nodes. Therefore, after obtaining the key information and authentication information of the virtual service node, the cloud management platform will send an instruction to the virtual service node to delete the key exchange interface to prevent the key exchange interface from being reused, thereby preventing the virtual service node from being maliciously attacked and causing the second key and authentication information of the virtual service node to be stolen or tampered with.

[0148] In some embodiments, after receiving an instruction from the cloud management platform to delete the key exchange interface, the virtual service node deletes the key exchange interface according to the deletion instruction, configures the API of the virtual service node, and realizes communication between the cloud management platform and the virtual service node based on the API.

[0149] In some implementations, generating a second key and authentication information includes:

[0150] A second key and authentication information are randomly generated.

[0151] In some embodiments, the virtual service node randomly generates a second key and authentication information, making the second key and authentication information random. This effectively prevents the virtual service node from being maliciously attacked during communication between the virtual service node and the cloud management platform, further improving the communication security between the cloud management platform and other virtual service nodes.

[0152] Figure 3 The following is a flowchart illustrating a specific implementation of a communication method provided in an embodiment of the present invention, as shown below. Figure 3 As shown, the process may include:

[0153] Step 301: The user requests access to a virtual service.

[0154] Step 302: The cloud management platform creates a virtual machine and assigns it a temporary IP address.

[0155] In this embodiment of the invention, a user applies to access a virtual service on the cloud management platform. The cloud management platform will create a virtual machine using the image file corresponding to the virtual service and assign a temporary IP address to the virtual machine.

[0156] Step 303: The virtual service node obtains a temporary IP address and creates a key exchange interface.

[0157] In this embodiment of the invention, the virtual service node can obtain a temporary IP address when the virtual machine starts for the first time.

[0158] Step 304: The cloud management platform confirms that the virtual machine has obtained a temporary IP address.

[0159] In this embodiment of the invention, the cloud management platform can confirm whether the virtual machine has obtained a temporary IP address based on DHCP.

[0160] Step 305: The cloud management platform sends the first key and the first identifier information of the first key to the virtual service node.

[0161] In some embodiments, after the cloud management platform confirms that the virtual machine has obtained a temporary IP address via DHCP, the cloud management platform sends a first key and a first identifier of the first key to the virtual service node. For example, the content sent may be as follows: {“SecretKey”:“ABC”,“SEQ”:“123”}.

[0162] Step 306: The virtual service node receives the first key and the first identifier information of the first key, and randomly generates the second key and authentication information.

[0163] In some embodiments, after receiving the first key and the first identification information of the first key, the virtual service node temporarily saves the SecretKey as SK1 and randomly generates a second key (SecretKey2, SK2) and authentication information (Access key, AK2). For example, the content can be as follows: {"SK2":"ABCD","AK2":"1234"}.

[0164] Step 307: The virtual service node sends the first exchange information, encrypted with the first key, to the cloud management platform.

[0165] In this embodiment of the invention, the first exchange information includes at least: a second key, authentication information, a first identification information, and a sending time. Here, the sending time is the time when the virtual service node sends the encrypted first exchange information to the cloud management platform.

[0166] Step 308: The cloud management platform decrypts the encrypted first exchange information based on the first key.

[0167] In this embodiment of the invention, the cloud management platform decrypts the encrypted first exchange information according to the first key. By comparing whether the decrypted information includes the first identification information and determining the sending duration based on the sending time, the cloud management platform determines whether the first exchange information has expired. If the decrypted information includes the first identification information and the sending duration is less than the preset expiration duration, the cloud management platform stores the decrypted second key and authentication information in the cloud management platform as credentials for subsequent communication with virtual service nodes.

[0168] Step 309: The cloud management platform sends a command to the virtual service node to delete the key exchange interface, which is encrypted with the second key.

[0169] In this embodiment of the invention, after the cloud management platform and the virtual service node successfully exchange key information, the cloud management platform sends an instruction to the virtual service node to delete the key exchange interface.

[0170] Step 310: Delete the key exchange interface on the virtual service node.

[0171] In this embodiment of the invention, the virtual service node decrypts the encrypted instruction sent by the cloud management platform according to the second key to obtain the instruction to delete the key exchange interface, and deletes the key exchange interface according to the deletion instruction.

[0172] Step 311: Configure the API of the virtual service node in the cloud management platform.

[0173] In this embodiment of the invention, the cloud management platform configures the API of the virtual service node based on the second key and authentication information, and realizes communication between the cloud management platform and the virtual service node based on the API.

[0174] Based on the same technical concept as the foregoing embodiments, see Figure 4 This invention provides a communication device applied to a cloud management platform, the cloud management platform being used to manage virtual service nodes within the cloud platform; the device includes at least:

[0175] The first sending module 401 is used to send a first key and first identification information of the first key to the virtual service node;

[0176] The second receiving module 402 is configured to receive encrypted first exchange information sent by the virtual service node, wherein the first exchange information includes at least: a second key generated by the virtual service node and authentication information; the encrypted first exchange information is information obtained by the virtual service node encrypting the first exchange information according to the first key.

[0177] Decryption module 403 is used to decrypt the encrypted first exchange information according to the first key to obtain the second key and the authentication information;

[0178] The communication module 404 is used to communicate with the virtual service node based on the second key and the authentication information.

[0179] In one implementation, the first sending module 401 is configured to send a first key and first identification information of the first key to the virtual service node, including:

[0180] The first key and its first identifier information are sent to the virtual service node through a key exchange interface; the key exchange interface is an interface created by the virtual service node.

[0181] The first receiving module 402 is configured to receive encrypted first exchange information sent by the virtual service node, including:

[0182] Receive the encrypted first exchange information sent by the virtual service node through the key exchange interface;

[0183] The communication module 404 is used to communicate with the virtual service node based on the second key and the authentication information, and further includes:

[0184] Send an instruction to the virtual service node to delete the key exchange interface.

[0185] In one implementation, the first exchange information further includes the first identification information; the decryption module 403 is configured to decrypt the encrypted first exchange information according to the first key to obtain the second key and the authentication information, including:

[0186] The encrypted first exchange information is decrypted using the first key to obtain the decrypted information.

[0187] If the decrypted information includes the first identification information, the second key and authentication information are obtained based on the decrypted information.

[0188] In one implementation, the first exchange information further includes a sending time, which is the time when the virtual service node sends the encrypted first exchange information to the cloud management platform; the decryption module 403 is used to decrypt the encrypted first exchange information according to the first key to obtain the second key and the authentication information, including:

[0189] The encrypted first exchange information is decrypted using the first key to obtain the sending time;

[0190] Based on the sending time, the sending duration is determined, where the sending duration is the time from the sending time to the current time;

[0191] If the sending time is less than the preset expiration time, the second key and authentication information are obtained based on the decrypted information.

[0192] Based on the same technical concept as the foregoing embodiments, see Figure 5 The present invention also provides another communication device for use in virtual service nodes; the device includes at least:

[0193] The second receiving module 501 is used to receive a first key and a first identification information of the first key sent by the cloud management platform; the cloud management platform is used to manage virtual service nodes in the cloud platform.

[0194] Module 502 is used to generate a random second key and authentication information;

[0195] Encryption module 503 is used to encrypt the first exchange information according to the first key to obtain encrypted first exchange information; the first exchange information includes at least: the second key and the authentication information;

[0196] The second sending module 504 is used to send encrypted first exchange information to the cloud management platform, so that the cloud management platform can decrypt the encrypted first exchange information according to the first key to obtain the second key and the authentication information, and enable the cloud management platform to communicate with the virtual service node according to the second key and the authentication information.

[0197] In one implementation, the second receiving module 501 is configured to receive a first key and first identification information of the first key sent by the cloud management platform, including:

[0198] Before receiving the first key and the first identifier information of the first key sent by the cloud management platform, a key exchange interface is created;

[0199] The key exchange interface receives the first key and the first identification information of the first key sent by the cloud management platform.

[0200] The second sending module 504 is used to send encrypted first exchange information to the cloud management platform, including:

[0201] The encrypted first exchange information is sent to the cloud management platform through the key exchange interface;

[0202] After sending the encrypted first exchange information to the cloud management platform, the system receives an instruction from the cloud management platform to delete the key exchange interface.

[0203] The key exchange interface is deleted according to the deletion instruction.

[0204] The generation module 502 is used to generate a second key and authentication information, including:

[0205] A second key and authentication information are randomly generated.

[0206] It should be noted that the description of the above device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects. For technical details not disclosed in the device embodiments of this application, please refer to the description of the method embodiments of this application for understanding.

[0207] It should be noted that, in the embodiments of the present invention, if the above-described methods are implemented as software functional modules and sold or used as independent products, they can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiments of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a terminal, server, etc.) to execute all or part of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), magnetic disks, or optical disks. Thus, the embodiments of this application are not limited to any specific hardware and software combination.

[0208] Correspondingly, this embodiment of the invention further provides a computer program product, which includes computer-executable instructions for implementing any of the communication methods provided in this embodiment of the invention.

[0209] Accordingly, this embodiment of the invention further provides a computer storage medium storing computer-executable instructions, which are used to implement any of the communication methods provided in the above embodiments.

[0210] In some embodiments, the functions or modules of the apparatus provided in the present invention can be used to execute the methods described in the above method embodiments. The specific implementation can be referred to the description of the above method embodiments, and for the sake of brevity, it will not be repeated here.

[0211] Based on the same technical concept as the foregoing embodiments, see Figure 6 An embodiment of the present invention provides an electronic device, a first electronic device 600, which may include: a first memory 610 and a first processor 620. The electronic device 600 can run a computer program on the first processor 620. When the first processor 620 executes the program, it implements any of the communication methods described above applied to a cloud management platform; wherein,

[0212] The first memory 610 is used to store computer programs and data;

[0213] The first processor 620 is used to execute the computer program stored in the first memory 610 to implement any of the communication methods applied to the cloud management platform in the foregoing embodiments.

[0214] Based on the same technical concept as the foregoing embodiments, see Figure 7 This invention provides another electronic device, a second electronic device 700, which may include: a second memory 710 and a second processor 720. The electronic device 700 can run a computer program on the second processor 720. When the second processor 720 executes the program, it implements any of the communication methods described above applied to a virtual service node.

[0215] The second memory 710 is used to store computer programs and data;

[0216] The second processor 720 is used to execute the computer program stored in the second memory 710 to implement any of the communication methods applied to the virtual service node in the foregoing embodiments.

[0217] The description of the various embodiments above tends to emphasize the differences between the various embodiments. The similarities or similarities can be referred to each other. For the sake of brevity, they will not be repeated here.

[0218] The methods disclosed in the various method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.

[0219] The features disclosed in the various product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.

[0220] The features disclosed in the various method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method or device embodiments.

[0221] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are merely illustrative and exemplary. The division of units is only a logical functional division, and in actual implementation, there may be other division methods, such as: multiple units or components may be combined, or integrated into another system, or some features may be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the various components shown or discussed may be through some interfaces, and the indirect coupling or communication connection between devices or units may be electrical, mechanical, or other forms.

[0222] The units described above as separate components may or may not be physically separate. The components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple grid units. Depending on the actual situation, some or all of the units may be selected to achieve the purpose of this embodiment.

[0223] In addition, each functional unit in the various embodiments of this application can be integrated into one processing module, or each unit can be a separate unit, or two or more units can be integrated into one unit; the integrated unit can be implemented in hardware or in the form of hardware plus software functional units.

[0224] Those skilled in the art will understand that all or part of the steps of the above method embodiments can be implemented by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it performs the steps of the above method embodiments.

[0225] The above description is merely a preferred embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A communication method characterized by comprising: The method is applied to a cloud management platform used for managing a virtual service node in a cloud platform, and comprises the following steps: creating a virtual machine corresponding to the virtual service node and allocating a temporary IP address to the virtual machine; after confirming that the virtual machine acquires the temporary IP address, sending a first key and first identification information of the first key to the virtual service node through a key exchange interface; the key exchange interface is an interface created after the virtual service node acquires the temporary IP address; receiving encrypted first exchange information sent by the virtual service node through the key exchange interface; the first exchange information at least comprises a second key generated by the virtual service node and identity authentication information; the encrypted first exchange information is information obtained by encrypting the first exchange information according to the first key by the virtual service node; decrypting the encrypted first exchange information according to the first key to obtain the second key and the identity authentication information; sending an instruction of deleting the key exchange interface to the virtual service node; configuring an application programming interface of the virtual service node according to the second key and the identity authentication information; communicating with the virtual service node based on the application programming interface.

2. The method of claim 1, wherein, The first exchange information further comprises the first identification information; the step of decrypting the encrypted first exchange information according to the first key to obtain the second key and the identity authentication information comprises the following steps: decrypting the encrypted first exchange information according to the first key to obtain decrypted information; in the case that the decrypted information comprises the first identification information, obtaining the second key and identity authentication information according to the decrypted information.

3. The method of claim 1, wherein, The first exchange information further comprises a sending time; the sending time is a time when the virtual service node sends the encrypted first exchange information to the cloud management platform; the step of decrypting the encrypted first exchange information according to the first key to obtain the second key and the identity authentication information comprises the following steps: decrypting the encrypted first exchange information according to the first key to obtain the sending time; determining a sending duration according to the sending time; the sending duration is a duration from the sending time to a current time; in the case that the sending duration is less than a preset expired duration, obtaining the second key and identity authentication information according to the decrypted information.

4. A communication method characterized by comprising: The method is applied to a virtual service node, and comprises the following steps: obtaining a temporary IP address; the temporary IP address is allocated after a cloud management platform creates a virtual machine corresponding to the virtual service node; the cloud management platform is used for managing a virtual service node in a cloud platform; after confirming that the temporary IP address is acquired, creating a key exchange interface; receiving a first key and first identification information of the first key sent by the cloud management platform through the key exchange interface; generating a second key and identity authentication information; According to the first secret key, the first exchange information is encrypted to obtain encrypted first exchange information; the first exchange information at least includes the second secret key and the identity authentication information; Through the secret key exchange interface, the encrypted first exchange information is sent to the cloud management platform, so that the cloud management platform decrypts the encrypted first exchange information according to the first secret key to obtain the second secret key and the identity authentication information; An instruction of deleting the secret key exchange interface is received from the cloud management platform; According to the deletion instruction, the secret key exchange interface is deleted; Based on the application programming interface of the virtual service node, the cloud management platform is communicated; the application programming interface is configured by the cloud management platform according to the second secret key and the identity authentication information.

5. The method of claim 4, wherein, The second secret key and the identity authentication information are generated, including: The second secret key and the identity authentication information are randomly generated.

6. A communication device, characterized by The cloud management platform is applied to, and the cloud management platform is used for managing virtual service nodes in a cloud platform; the device at least includes: A first sending module is configured to create a virtual machine corresponding to the virtual service node, and allocate a temporary IP address to the virtual machine; after confirming that the virtual machine acquires the temporary IP address, the first sending module is configured to send a first secret key and first identification information of the first secret key to the virtual service node through a secret key exchange interface; the secret key exchange interface is an interface created after the virtual service node acquires the temporary IP address; A first receiving module is configured to receive encrypted first exchange information sent by the virtual service node through the secret key exchange interface; the first exchange information at least includes a second secret key and identity authentication information generated by the virtual service node; the encrypted first exchange information is information obtained by encrypting the first exchange information according to the first secret key by the virtual service node; A decryption module is configured to decrypt the encrypted first exchange information according to the first secret key to obtain the second secret key and the identity authentication information; A communication module is configured to send an instruction of deleting the secret key exchange interface to the virtual service node; according to the second secret key and the identity authentication information, an application programming interface of the virtual service node is configured; based on the application programming interface, the virtual service node is communicated.

7. A communication device, characterized by The virtual service node is applied to; The device at least includes: A second receiving module is configured to acquire a temporary IP address; the temporary IP address is allocated after a virtual machine corresponding to the virtual service node is created by a cloud management platform; the cloud management platform is used for managing virtual service nodes in a cloud platform; after it is determined that the temporary IP address is acquired, the second receiving module is configured to create a secret key exchange interface; the first secret key and first identification information of the first secret key sent by the cloud management platform are received through the secret key exchange interface; A generation module is configured to generate a second secret key and identity authentication information; An encryption module is configured to encrypt first exchange information according to the first secret key to obtain encrypted first exchange information; the first exchange information at least includes the second secret key and the identity authentication information. The second sending module is configured to send the encrypted first exchange information to the cloud management platform through the key exchange interface, so that the cloud management platform decrypts the encrypted first exchange information according to the first key to obtain the second key and the identity authentication information; receive an instruction of deleting the key exchange interface sent by the cloud management platform; delete the key exchange interface according to the instruction; and communicate with the cloud management platform based on an application programming interface of the virtual service node, wherein the application programming interface is configured by the cloud management platform according to the second key and the identity authentication information.

8. An electronic device, comprising: The electronic device comprises a first memory, a first processor, and a computer program stored in the first memory and executable on the first processor, and the first processor implements the communication method of any one of claims 1-3 when executing the program.

9. An electronic device, comprising: The electronic device comprises a second memory, a second processor, and a computer program stored in the second memory and executable on the second processor, and the second processor implements the communication method of any one of claims 4-5 when executing the program.

10. A computer storage medium, the storage medium having stored thereon a computer program; characterized in that, The computer program is executed to implement the communication method of any one of claims 1-5.

Citation Information

Patent Citations

  • Secure session method and device

    CN113411345A