A Security Mechanism Design Method for Rights Domain Control of the Horizon System Based on Openstack

By introducing a hash encryption mechanism into OpenStack's Horizon system, the security problem of the domain control API is solved, the data prevention capabilities are enhanced, the security and stability of the permission data are ensured, and the security and stability of the permission data are adapted to different security needs.

CN115688135BActive Publication Date: 2025-07-22CHINA TELECOM DIGITAL INTELLIGENCE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211349970.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-31
Publication Date
2025-07-22
Estimated Expiration
2042-10-31

AI Technical Summary

Technical Problem

In the existing OpenStack Horizon system, the API security problem under domain control has not been effectively solved, which has led to hackers who may obtain high permissions by cracking the role_simpledate interface, causing security risks.

Method used

A security mechanism for domain control of the Horizon system based on Openstack was designed, and the API of the domain function was encrypted using hash encryption method. The API of the middleware was used to hash encryption when data was read, refreshed and updated, and the data was planned through time-controlled encryption to ensure the security of the data.

Benefits of technology

It improves the security of the domain control function, prevents rainbow table attacks, ensures data stability and the security of permission data, and flexibly adjusts encryption functions to meet different security needs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115688135B_ABST
    Figure CN115688135B_ABST
Patent Text Reader

Abstract

The present invention discloses a security mechanism design method for right domain control of the Horizon system based on Openstack, which relates to the technical field of computer information security and includes: 1. Overall design of right domain functions; 2. API design of right domain functions; 3. API design of middleware; 4. Design of the Hash algorithm logic unit of middleware, adopting a time control method to plan the encryption method according to the instant encryption method of time; 5. Interaction and cooperation between the middleware and the API of right domain functions, where the API of the middleware calls the API of right domain functions. When the API of the middleware reads, refreshes, and updates data, hash encryption is performed, and during use, decoding is performed through the corresponding encrypted key data, and the data after decoding is restored to variables. The hash encryption method designed for the security mechanism of right domain control in the present invention solves the security problem of APIs and enhances the security of right domain control functions.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer information security, and in particular to a security mechanism design method for domain control of the Horizon system based on Openstack. Background Art

[0002] OpenStack is an open-source cloud computing management platform project, which is a combination of a series of software open-source projects. OpenStack provides scalable and elastic cloud computing services for private and public clouds. The project goal is to provide a cloud computing management platform that is simple to implement, highly scalable, rich, and standardized. Although OpenStack has become increasingly mature since its inception and can basically meet most of the needs of cloud computing users, with the development of cloud computing technology, OpenStack also needs to be continuously improved. OpenStack has gradually become a mainstream cloud computing platform solution in the market.

[0003] Security issues have always been a problem in the entire cloud computing industry. Although there are security measures such as user identity information verification in Open Stack, and even domains that can represent security trust levels individually or in combination are defined, with the change and development of user needs, security issues cannot be underestimated.

[0004] Horizon is a Web control panel used to manage and control OpenStack services. Users can view and manage the OpenStack status through this interface. The main role of Horizon is to provide an administrator operation platform for Openstack. When using Horizon to manage users, different users have different permissions after logging in. This is the domain control function on Horizon. With this as the basis, it is convenient to empower customers at different levels. However, once a hacker cracks the interface role_simpledate that returns the coarse-grained data of domain control, the hacker can modify role_simpledate to make a low-privilege user obtain high user privileges, that is, the user obtains permissions that he should not have obtained, which will cause a large amount of losses in the actual production environment. Summary of the Invention

[0005] In view of the above-mentioned defects of the prior art, the technical problem to be solved by the present invention is: to provide a security mechanism design method for domain control of the Horizon system based on Openstack, design a hash encryption method for its security, effectively solve the security problem of the API, and at the same time enable data to prevent rainbow table attacks and enhance the security of the entire domain control function.

[0006] To achieve the above object, the present invention provides a security mechanism design method for domain control of the Horizon system based on Openstack, including the following steps:

[0007] Step S1, overall design of the domain function. Bind permission data through role, and add different roles for users to achieve different permission effects;

[0008] Step S2, API design of the domain function. Design the API of the domain function. The API interaction of the domain function adopts asynchronous call to trigger the option of selecting role to trigger the API of the domain function. The API of the domain function sends data to other APIs or databases to complete the implementation of the function;

[0009] Step S3, API design of the middleware. The API of the middleware uses the API provided by the nova component of openstack and adopts a timing refresh mechanism to provide data reading and data update functions;

[0010] Step S4, design of the Hash algorithm logic unit of the middleware. Adopt a time control method to plan the encryption method according to the instant encryption method of time;

[0011] Step S5, interaction and cooperation between the middleware and the API of the domain function. Introduce a Hash encryption mechanism on the basis of asynchronously calling the API of the domain function. The API of the middleware calls the API of the domain function. When the API of the middleware reads, refreshes and updates data, it performs hash encryption, and then decodes it with the corresponding encrypted key data during use. After decoding, the data is restored to a variable, and the permission value is directly used through asynchronous call to complete the verification of the function, and it is displayed on the horizon page after verification.

[0012] Preferably, in step S2, the API design of the domain function includes roles API design and role-realdata API design, and the API of the middleware collects the data of the API of the domain function for hash encryption.

[0013] Preferably, the roles API design uses the middleware for hash encryption, provides the functions of adding, deleting and modifying role data, corresponding to the post, delete, put methods, and provides the access method of keystone to implement database read and write operations. The data control module is in the form of a data template.

[0014] Preferably, when the role-realdata API design performs data update, it adds a read operation to the database to complete one database access. The middleware serves as an encryption kernel, designs the encryption logic based on the situation of the role-realdata API, adds a logical call at this position, and then performs hash encryption.

[0015] Preferably, in step 3, the API of the middleware includes Nova-Hash-API. The Nova-Hash-API provides data reading and data update functions by the GET method. When the data uses the Nova-Hash-API, it undergoes conversion processing to encrypt the data, and the output value of the data is directly assigned to the corresponding position of the asynchronous call in the form of a variable.

[0016] Preferably, in step S3, the API of the middleware adopts a timing refresh mechanism, and the content in the cache is refreshed every preset time. The preset time is encapsulated in the configuration file of nova and can be pre-configured according to security requirements.

[0017] Preferably, the preset time is 10 seconds, corresponding to 6 Nova-Hash-API hash encryption functions. The 6 Nova-Hash-API hash encryption functions are planned according to the instantaneous encryption method of time and are freely switched in chronological order.

[0018] Preferably, the expressions of the 6 Nova-Hash-API hash encryption functions are as follows:

[0019] The hash encryption function corresponding to Nova-Hash-API-Model-1 is called R = H1(S)

[0020] hash[i] = hash[i - 1] * base + str[i] - 'a' + 1;

[0021] The hash encryption function corresponding to Nova-Hash-API-Model-2 is called R = H2(S)

[0022] hash[i] = hash[i - 1] * base + str[i] - 'a' + 80;

[0023] The hash encryption function corresponding to Nova-Hash-API-Model-3 is called R = H3(S)

[0024] hash[i] = hash[i - 1] * base + str[i] - 'a' + 300;

[0025] The hash encryption function corresponding to Nova-Hash-API-Model-4 is called R = H4(S).

[0026] hash[i] = hash[i - 1] * base + str[i] - 'a' + 524;

[0027] The hash encryption function corresponding to Nova-Hash-API-Model-5 is called R = H5(S).

[0028] hash[i] = hash[i - 1] * base + str[i] - 'a' + 1000;

[0029] The hash encryption function corresponding to Nova-Hash-API-Model-6 is called R = H6(S).

[0030] hash[i] = hash[i - 1] * base + str[i] - 'a' + 1250;

[0031] Among them, i is an int-type value, and base is a predefined value.

[0032] Preferably, the step S4 includes the following steps:

[0033] The API of the middleware reads the server time;

[0034] Read the event, set the encryption function according to the preset time encapsulated in the nova configuration file, and plan the encryption method according to the instant encryption method of time. The encryption method is switched freely in chronological order;

[0035] Receive the virtual machine creation data input passed back by the API of the rights domain function, perform Hash data conversion to obtain different encryption functions R = E(S, Ke), and save the encryption key;

[0036] Receive the virtual machine deletion data passed back by the API of the rights domain function, perform Hash data conversion, and decode it using the decoding function E(S, Ke) to obtain the original data.

[0037] Preferably, the server clock synchronization is completed before the Nova-Hash-API reads the server time.

[0038] The beneficial effects of the present invention are:

[0039] 1. The technical solution of the present invention optimizes the hash algorithm, increases the data conversion efficiency while reducing the complexity, and solves the data leakage problem of coarse-grained permission data in the entire rights domain function;

[0040] 2. In the present invention, the role_realdata API combines the three functions of updating the database, storing the database, and reading the database, and executes the above functions in sequence. Whenever the role_realdata API is called, the data is automatically refreshed, stored, and read again, ensuring that the permission data stored in the database is already Hash-encrypted data, and the data in the database and the cookie cache are both secure permission-encrypted data, improving data stability.

[0041] 3. The present invention determines the encryption method based on the second of the server refresh time. In the later stage, only the configuration file or the API source code needs to be modified, and the order structure of the encryption function can be freely adjusted, or the corresponding encryption function can be added or reduced to improve security. The flexible hash algorithm of automated customization can well solve the page security problem of horizon.

[0042] The concept, specific structure and technical effects of the present invention will be further described below in conjunction with the drawings to fully understand the purpose, features and effects of the present invention. Description of the Drawings

[0043] Figure 1 It is a flowchart of the security mechanism design method for the right domain control of the Horizon system based on Openstack in the prior art;

[0044] Figure 2 It is a flowchart of the security mechanism design method for the right domain control of the Horizon system based on Openstack in a preferred embodiment of the present invention. Detailed Embodiments

[0045] The following introduces multiple preferred embodiments of the present invention with reference to the drawings of the specification to make its technical content clearer and easier to understand. The present invention can be embodied in many different forms of embodiments, and the protection scope of the present invention is not limited to the embodiments mentioned in the text.

[0046] As Figure 1 shown, it is a flowchart of the security mechanism design method for the right domain control of the Horizon system based on Openstack in the prior art. As Figure 2 shown, it is a flowchart of the security mechanism design method for the right domain control of the Horizon system based on Openstack in an embodiment of the present invention, including: overall design of the right domain function; API design of the right domain function; API design of the middleware; Hash algorithm logic unit design of the middleware; interaction and cooperation between the middleware and the API.

[0047] The domain control mainly adds different roles to users to achieve different permission effects. Since each role is bound to different permission data, users can achieve domain control by the administrator assigning roles to other non - administrator account users.

[0048] The functional interaction of the domain function mainly depends on the asynchronous - call API interaction. When the option of selecting a role is triggered at a certain time, the corresponding API will be triggered. The API sends data to other APIs or databases to complete the implementation of the function. This is the background control mode of the domain function. However, directly using the API to transmit data will cause data leakage, and the data involved in the domain control needs to be encrypted and decrypted.

[0049] The API design of the domain function includes:

[0050] a. roles: The roles API interface provides the functions of adding, deleting, and modifying role data, corresponding to the post, delete, and put methods respectively. And the roles API also provides the way of Keystone access to implement database read - write operations. The data control module is in the form of a data template. Keystone is one of the components of OpenStack, which is used to provide unified authentication services for other component members in the OpenStack family, including identity authentication, token issuance and verification, service list, user permission definition, etc.

[0051] b. role - realdata: The role - realdata API combines the three functions of updating the database, storing the database, and reading the database, and executes the above - mentioned functions in sequence.

[0052] The main role of the middleware is to collect the data of the roles API and the role - realdata API. When the role_realdata API executes the data update function, it will increase the read operation to the database and complete a database access. At this time, taking the middleware as the encryption kernel and designing the encryption logic according to the situation of the API, a logical call will be added at this position, and then hash encryption will be performed.

[0053] Both the roles API and the role - realdata API use the middleware for hash encryption. When data is transmitted, the call process of the middleware is added in the API business process.

[0054] The middleware uses a separate API provided by the nova component of OpenStack. Nova is the most core component in the entire OpenStack. All kinds of actions required for the life cycle of an OpenStack cloud instance will be processed and supported by Nova. It is responsible for managing the computing resources, network, authorization, and measurement of the entire cloud. The API of the middleware is: nova-hash-api. The API of the middleware mainly but not limited to provides data reading and data update functions by the GET method. The main middleware is developed in Python. Any data using the API of the middleware can effectively encrypt the data. That is to say, the data needs to be converted. The output value of the data is directly assigned to the corresponding position of the asynchronous call in the form of a variable. Because the asynchronous call may use the cache mechanism, that is to say, the encryption method may be added to the cache. An embodiment of the present invention adopts a timing refresh mechanism. The content in the cache will become invalid every set time, such as 10 seconds. The set time is encapsulated in the configuration file of nova and can be shortened accordingly according to the actual usage scenario. Under this mechanism, even if the cache is forcibly obtained and the cookie cache is obtained and used to crack the encryption, but because of the expiration, the cache has expired. Therefore, the hash-encrypted data under the protection of timeliness is very stable data.

[0055] The permission data mainly includes the following content. Taking the creation of a virtual machine as an example: nova:instance:create, taking the deletion of a virtual machine as an example: nova:instance:delete, taking the editing of a virtual machine as an example: nova:instance:update. The above data is the data that the role-realdata API can return, and it is relatively simple. Once these data are leaked, the return value of the permissions of a certain user can be modified by controlling the role-realdata API, and then the permissions under that role can be modified. The permissions of users can be affected through the role.

[0056] The method adopted by the API of the middleware of the present invention is a time control method. First, nova-hash-api will read the server time. In order for the system to run stably, the step of clock synchronization is completed when deploying OpenStack, so as to solve the chain bugs between servers caused by different server times. For example, for the middleware involved in the present invention, if the server times are different, the encryption methods of the API within the same time period will also be different. This problem will have a great impact on multi-node OpenStack.

[0057] After reading the event, taking 10 seconds as a unit, the minutes of a certain time remain unchanged. There are 60 seconds in a minute, corresponding to 6 kinds of Nova-Hash-API-Model-1 (0-10s), Nova-Hash-API-Model-2 (10-20s), Nova-Hash-API-Model-3 (20-30s), Nova-Hash-API-Model-4 (30-40s), Nova-Hash-API-Model-5 (40-50s), Nova-Hash-API-Model-6 (50-60s). These 6 modes are planned according to the instant encryption method of time. These six encryption methods will switch freely in chronological order.

[0058] The Hash algorithm is a many-to-one mapping relationship. R = H(S) is a many-to-one mapping. Multiple different S can obtain the same R through the hash algorithm H. So there is no inverse mapping such that a single R can obtain a unique S. The hash encryption method designed according to security.

[0059] The hash encryption function corresponding to Nova-Hash-API-Model-1 is called R = H1(S)

[0060] The hash encryption function corresponding to Nova-Hash-API-Model-2 is called R = H2(S)

[0061] The hash encryption function corresponding to Nova-Hash-API-Model-3 is called R = H3(S)

[0062] The hash encryption function corresponding to Nova-Hash-API-Model-4 is called R = H4(S)

[0063] The hash encryption function corresponding to Nova-Hash-API-Model-5 is called R = H5(S)

[0064] The hash encryption function corresponding to Nova-Hash-API-Model-6 is called R = H6(S)

[0065] The specific encryption process is to input each character of the nova:instance:create data. Taking H1(S) as an example, each character of the above data is put into H1(S) in the form of S for data conversion.

[0066] #include<stdio.h>

[0067] #include<string.h>

[0068] char str[1000010];

[0069] #define base 131 / / Take base as 131;

[0070] typedef unsigned long long int ULL; / / It's too long, so this is more convenient;

[0071] ULL hash[1000010], p[1000010]; / / Define. The hash array is used to store the hash values of each prefix, and the p array is used to store the values of each power of base;

[0072] int get(int l, int r) / / Custom function to calculate the hash value of each part of the string;

[0073]

[0074]

[0075] After the above program data conversion, 6 different hash encryption functions are obtained. The standard expression of the encryption algorithm is: R = E(S, Ke) is a one-to-one mapping. Given an S and an encryption key Ke, only a unique ciphertext R can be obtained. Conversely, given an R and a decryption key Kd, only a unique S can be obtained. This involves the issue of saving the encryption key. The keystone-provided assignment interface is used for database reading and writing, and the database can be directly read when using the data.

[0076] After having the above key KS, the data nova:instance:delete will be Hash-converted and then decoded using the decoding function E(S, Ke) to obtain the original data: nova:instance:delete. This method is also the GET method of the middleware. Through this method, the corresponding permission value data can be represented as variables in the program during asynchronous calls and then directly called as variables. However, this process involves encryption and decryption. All the data saved in the database and the data in the cookie cache are encrypted data.

[0077] In specific situations, such as when the security is relatively poor, the security of the horizon permission data can be increased by adding Hash data conversion functions. This can be triggered in a structured thinking and API design method to enhance the security of the horizon permission domain function.

[0078] The technical solution of the present invention is to introduce a Hash encryption mechanism on the basis of asynchronous API calls. The APIs such as roles and role-realdata are called in the form of middleware APIs. During data reading, refreshing, and updating, etc., hash encryption will be performed. When in use, it is decoded through the corresponding encrypted key data, and the data is restored to variables after decoding. The permission value is directly used through asynchronous calls to complete the verification of certain functions, and after verification, it can be fully displayed on the horizon page.

[0079] The preferred specific embodiments of the present invention have been described in detail above. It should be understood that those of ordinary skill in the art can make many modifications and variations based on the concept of the present invention without creative labor. Therefore, all technical solutions that can be obtained by those skilled in the art in this technical field based on the concept of the present invention through logical analysis, reasoning, or limited experiments on the basis of the prior art should fall within the protection scope determined by the claims.

Claims

1. A security mechanism design method for privilege domain control of the Horizon system based on Openstack, characterized in that, It includes the following steps: Step S1, overall design of the rights domain function. Bind permission data through role, and add different roles for users to achieve different permission effects; Step S2, API design of the rights domain function. The API interaction of the rights domain function adopts asynchronous call. Trigger the option of selecting role to trigger the API of the rights domain function. The API of the rights domain function sends data to other APIs or databases to complete the implementation of the function; Step S3, API design of the middleware. The API of the middleware uses the API provided by the nova component of openstack and adopts a timing refresh mechanism to provide data reading and data update functions; Step S4, design of the Hash algorithm logic unit of the middleware. Adopt a time control method to plan the encryption method according to the instantaneous encryption method of time; Step S5, interaction and cooperation between the middleware and the API of the rights domain function. On the basis of asynchronously calling the API of the rights domain function, introduce a Hash encryption mechanism. The API of the middleware calls the API of the rights domain function. When the API of the middleware reads, refreshes, and updates data, it performs hash encryption. When using, it decodes through the corresponding encrypted key data, restores the decoded data to a variable, and directly uses its permission value through asynchronous call to complete the verification of the function. After verification, it is displayed on the horizon page.

2. The security mechanism design method for right domain control of the Horizon system based on Openstack according to claim 1, characterized in that, In step S2, the API design of the rights domain function includes roles API design and role-realdataAPI design. The API of the middleware collects the data of the API of the rights domain function for hash encryption.

3. The security mechanism design method for the right domain control of the Horizon system based on Openstack according to claim 2, characterized in that, The roles API design uses the middleware for hash encryption, provides functions for adding, deleting, and modifying role data, corresponding to the post, delete, and put methods, and provides a way to access keystone to implement database read and write operations. The data control module is in the form of a data template.

4. The security mechanism design method for right domain control of the Openstack-based Horizon system according to claim 2, wherein The role-realdata API design adds reading to the database when performing data update, completes one database access. The middleware is used as the encryption kernel, designs the encryption logic according to the situation of the role-realdata API, adds a logical call at this position, and then performs hash encryption.

5. The security mechanism design method for the rights domain control of the Horizon system based on Openstack according to claim 1, characterized in that In step 3, the API of the middleware includes Nova-Hash-API. The Nova-Hash-API provides data reading and data update functions by the GET method. When using the Nova-Hash-API for data, conversion processing is performed, and the data is encrypted. The output value of the data is directly assigned to the corresponding position of the asynchronous call in the form of a variable.

6. The security mechanism design method for the rights domain control of the Openstack-based Horizon system according to claim 1, characterized in that, In step S3, the API of the middleware adopts a timing refresh mechanism. The content in the cache is refreshed every preset time. The preset time is encapsulated in the configuration file of nova and is pre-configured according to security requirements.

7. The security mechanism design method for the rights domain control of the Openstack-based Horizon system according to claim 6, characterized in that, The preset time is 10 seconds, corresponding to 6 Nova-Hash-API hash encryption functions. The 6 Nova-Hash-API hash encryption functions are planned according to the instant encryption method of time and can be freely switched in chronological order.

8. The security mechanism design method for the right domain control of the Openstack-based Horizon system according to claim 7, characterized in that, The expressions of the 6 Nova-Hash-API hash encryption functions are as follows: The hash encryption function corresponding to Nova-Hash-API-Model-1 is called H1(S) hash[i] = hash[i - 1] * base + str[i] - 'a' + 1; The hash encryption function corresponding to Nova-Hash-API-Model-2 is called H2(S) hash[i] = hash[i - 1] * base + str[i] - 'a' + 80; The hash encryption function corresponding to Nova-Hash-API-Model-3 is called H3(S) hash[i] = hash[i - 1] * base + str[i] - 'a' + 300; The hash encryption function corresponding to Nova-Hash-API-Model-4 is called H4(S) hash[i] = hash[i - 1] * base + str[i] - 'a' + 524; The hash encryption function corresponding to Nova-Hash-API-Model-5 is called H5(S) hash[i] = hash[i - 1] * base + str[i] - 'a' + 1000; The hash encryption function corresponding to Nova-Hash-API-Model-6 is called H6(S) hash[i] = hash[i - 1] * base + str[i] - 'a' + 1250; Among them, i is an int-type value, base is a predefined value, hash[] is a hash array, str[] is a character array, and 'a' is the character a.

9. The security mechanism design method for right domain control of the Horizon system based on Openstack according to claim 1, characterized in that, Step S4 includes the following steps: The API of the middleware reads the server time; Read the event, set the encryption function according to the preset time encapsulated in the nova configuration file, and plan the encryption method according to the instant encryption method of time. The encryption method can be freely switched in chronological order; Receive the input of virtual machine creation data returned by the API of the rights domain function, perform Hash data conversion to obtain different encryption functions E(S, Ke), and save the encryption key; Receive the virtual machine deletion data returned by the API of the rights domain function, perform Hash data conversion, and decode it using the decoding function E(S, Ke) to obtain the original data; Among them, S is a character and Ke is an encryption key.

10. The security mechanism design method for right domain control of the Horizon system based on Openstack as claimed in claim 7, wherein The server clock synchronization is completed before the Nova-Hash-API reads the server time.

Citation Information

Patent Citations

  • Public bank big data service platform based on openstack

    CN104767813A

  • Implementation method and device for decentralization and domain division functions of Skyline system based on Openstack

    CN115118480A