An identity authentication method, system and device
By introducing an authentication proxy server on the business side of the cloud computing platform, it is determined whether the derived key needs to be pulled from the authentication server for authentication, which solves the single point, performance and hot customer problems of the cloud computing platform when facing the rapidly growing number of tenants and requesting traffic, and achieves the effect of reducing the pressure and cost of the authentication server.
Patent Information
- Application Number
- CN202211287940.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-20
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2042-10-20
AI Technical Summary
When facing the rapidly growing number of tenants and requested traffic, cloud computing platforms have single-point problems, performance problems and hot customer problems. The existing technology is solved by horizontal scaling authentication servers, but it cannot handle network unavailability problems and increases costs.
Introduce an authentication proxy server on the business side. By obtaining the identity authentication request of the business server, it determines whether it is necessary to pull the derived key from the authentication server for authentication. If not, it is authenticated through local cache.
Reduces the computing pressure of the authentication server, avoids authentication failure caused by network unavailability, reduces costs and improves system reliability.
Smart Images

Figure CN115694938B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, further relates to the field of cloud computing technology, and particularly relates to an identity authentication method, system and device. Background Art
[0002] When a user requests services from a business server, signature authentication is required, and relevant services can be obtained only after the signature authentication passes. For cloud services, with the rapid growth of the number of tenants on the cloud, the cloud resources purchased by tenants are also increasing, resulting in a rapid growth of cloud request traffic. The single-point problem, performance problem, and hot customer problem are becoming increasingly prominent. To address the above problems, the authentication server can be horizontally scaled; however, this method cannot handle the unavailable impact caused by network problems between the requestor and the authentication server; secondly, the horizontal scaling of the authentication server will also increase costs. Summary of the Invention
[0003] The present disclosure provides a method, system and device for identity authentication.
[0004] According to one aspect of the present disclosure, there is provided an identity authentication method, which is applied to an authentication proxy server at the service end, and the service end further includes a business server. The method includes:
[0005] Obtain an identity authentication request corresponding to the business server; the identity authentication request contains an authentication string;
[0006] According to the authentication string, determine whether it is necessary to pull the derived key of the identity authentication request from the authentication server;
[0007] If so, pull the derived key of the identity authentication request from the authentication server, and perform authentication on the identity authentication request according to the derived key;
[0008] If not, perform authentication on the identity authentication request through local cache.
[0009] According to another aspect of the present disclosure, there is provided an identity authentication system, including: an authentication proxy server at the service end, a business server at the service end, and an authentication server at the authentication end;
[0010] The authentication proxy server is configured to obtain an identity authentication request corresponding to the business server; the identity authentication request contains an authentication string; according to the authentication string, determine whether it is necessary to pull the derived key of the identity authentication request from the authentication server; if so, pull the derived key of the identity authentication request from the authentication server, and perform authentication on the identity authentication request according to the derived key; if not, perform authentication on the identity authentication request through local cache;
[0011] The service server is configured to respond to the access request corresponding to the identity authentication request when the authentication of the identity authentication request passes.
[0012] The authentication server of the authentication end is configured to generate a derived key of the identity authentication request.
[0013] According to another aspect of the present disclosure, an identity authentication device is provided. The device includes:
[0014] A preprocessing module, configured to obtain an identity authentication request corresponding to the service server; the identity authentication request includes an authentication string.
[0015] A judgment module, configured to judge whether to pull a derived key of the identity authentication request from an authentication server according to the authentication string.
[0016] A pulling module, configured to, if it is necessary to pull a derived key of the identity authentication request from an authentication server, pull the derived key of the identity authentication request from the authentication server, and perform authentication on the identity authentication request according to the derived key.
[0017] A local processing module, configured to, if it is not necessary to pull a derived key of the identity authentication request from an authentication server, perform authentication on the identity authentication request through local cache.
[0018] According to another aspect of the present disclosure, an electronic device is provided, including:
[0019] At least one processor; and
[0020] A memory communicatively connected to the at least one processor; wherein,
[0021] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute any of the above identity authentication methods.
[0022] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause the computer to execute any of the above identity authentication methods.
[0023] According to another aspect of the present disclosure, a computer program product is provided, including a computer program, and the computer program implements any of the above identity authentication methods when executed by a processor.
[0024] The identity authentication method provided by this disclosure is applied to an authentication proxy server on the service side. The service side also includes a service server. The method includes: obtaining an identity authentication request corresponding to the service server; the identity authentication request contains an authentication string; according to the authentication string, determining whether it is necessary to pull the derived key of the identity authentication request from the authentication server; if so, pulling the derived key of the identity authentication request from the authentication server and performing authentication on the identity authentication request according to the derived key; if not, performing authentication on the identity authentication request through the local cache. This can reduce the computing pressure on the authentication server.
[0025] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of this disclosure, nor is it used to limit the scope of this disclosure. Other features of this disclosure will become easily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] The drawings are used to better understand this solution and do not constitute a limitation to this disclosure. Among them:
[0027] Figure 1 is the first process schematic diagram of the identity authentication method according to this disclosure;
[0028] Figure 2 is the second process schematic diagram of the identity authentication method according to this disclosure;
[0029] Figure 3 is the third process schematic diagram of the identity authentication method according to this disclosure;
[0030] Figure 4a is the schematic diagram of the system deployment architecture for completing authentication and authorization in the related art;
[0031] Figure 4b is the schematic diagram of the system deployment architecture for completing authentication and authorization of this disclosure;
[0032] Figure 5 is the overall architecture schematic diagram of the authentication proxy server according to this disclosure;
[0033] Figure 6 is the fourth process schematic diagram of the identity authentication method according to this disclosure;
[0034] Figure 7 is the process schematic diagram of preparing the interceptor according to this disclosure;
[0035] Figure 8 is the process schematic diagram of the statistical interceptor according to this disclosure;
[0036] Figure 9 is the class diagram of the identifier and the identification context according to this disclosure;
[0037] Figure 10 It is a schematic diagram of the processing flow of the authentication interceptor according to the present disclosure;
[0038] Figure 11 It is an interaction schematic diagram of an identity authentication system according to the present disclosure;
[0039] Figure 12 It is a first structural schematic diagram of an identity authentication device according to the present disclosure;
[0040] Figure 13 It is a second structural schematic diagram of an identity authentication device according to the present disclosure;
[0041] Figure 14 It is a third structural schematic diagram of an identity authentication device according to the present disclosure;
[0042] Figure 15 It is a block diagram of an electronic device for implementing the identity authentication method of the embodiments of the present disclosure. Detailed implementation manners
[0043] The following describes exemplary embodiments of the present disclosure with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to assist understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.
[0044] When a user requests services from a business server, signature authentication is required, and relevant services can only be obtained after successful signature authentication. For cloud services, the API (Application Programming Interface) authentication of cloud services uniformly uses a signature verification mechanism. The current signature algorithm brings a secure and reliable identity verification mechanism for cloud services, intercepting a large number of illegal requests and malicious attacks. However, with the rapid growth of the number of cloud tenants, the cloud resources purchased by tenants are also increasing, resulting in a rapid growth of cloud request traffic. The single-point problem, performance problem, and hot customer problem are becoming increasingly prominent. First, there is the single-point problem. After receiving a user request, all services must submit an authentication string to the authentication server for verification. Once the authentication server is attacked or experiences a performance bottleneck and cannot respond to signature verification requests in a timely manner, all services on the cloud will be affected. Second, there is the performance problem. The authentication server manages the AccessKey secret key information of customers and is not suitable for large-scale co-location with business operations. If the service instances of the authentication server are only deployed on a limited proportion of machines, no matter how optimized its performance is, it will ultimately not be able to meet the QPS (Queries-per-second) requirements of business instances on hundreds of thousands of machines in the cloud platform. Finally, there is the hot customer problem. Each cloud product has its own hot customers and VIP customers. The authentication and authorization of these customers are processed simultaneously with those of ordinary users, and there may be a situation of priority inversion.
[0045] To address the above problems, in the related art, the solution is to horizontally expand the authentication server; however, this method cannot handle the unavailable impact caused by network problems between the requestor and the authentication server; secondly, the horizontal expansion of the authentication server will also increase costs.
[0046] To solve at least one of the single-point problem, performance problem, and hot customer problem, the embodiments of the present disclosure provide an identity authentication method, which is applied to an authentication proxy server at the business end. The business end also includes a business server, and the business end is a system end that provides cloud service operations. For example, for a cloud service that provides computing resources, the business end is the system end where the computing server is located. For example, for a cloud service that provides storage resources, the business end is the system end where the storage server is located.
[0047] In one example, the authentication proxy server runs the IAM front-end service in Sidecar mode. Here, the Sidecar mode refers to a mode in which additional functions are added to the existing service, and these additional functions do not affect the existing service logic. IAM (identity access management) is identity recognition and access management. The IAM front-end service means that the IAM function is implemented through the front-end service, that is, a front-end service is added to the authentication proxy server at the service end to implement the IAM function. In one example, the IAM function can be a process running in the authentication proxy server through the front-end service, and the identity authentication method in the embodiments of the present application can be implemented through the IAM front-end service.
[0048] See Figure 1 , the identity authentication method of the embodiments of the present application includes:
[0049] S101. Obtain the identity authentication request corresponding to the service server; the identity authentication request contains an authentication string;
[0050] When a user requests a service from a service server, signature authentication is required, and relevant services can be obtained only after the signature authentication passes. Specifically, when the user sends an http request to the service server, the authentication proxy server needs to perform signature authentication on the http request first. Before performing signature authentication on the http request, the authentication proxy server will also set an ID for the received http request to facilitate sorting of the request, and then perform data structuring processing on the http request to convert the http request format into a data format used internally by the authentication proxy server, obtaining an identity authentication request.
[0051] The process of the authentication proxy server performing signature authentication on the http request is the process of reproducing and generating the authentication string. By comparing the generated authentication string with the authentication string carried in the identity authentication request, the signature authentication result can be determined.
[0052] S102. According to the authentication string, determine whether it is necessary to pull the derived key of the identity authentication request from the authentication server;
[0053] The authentication string contains three parts: a prefix string (authStringPrefix), a signed header field (signedHeaders), and a signature digest (signature). Among them, the prefix string is composed of three parts: {access key ID (accessKeyId)} / {timestamp (timestamp)} / {validity period (expirationPeriodInSeconds)}.
[0054] The authentication proxy server can determine whether to pull the derived key of the identity authentication request from the authentication server according to the authentication string. The authentication server is the IAM center cluster for identity authentication. In one example, the authentication server is at the authentication end, that is, the system end different from the service end.
[0055] In one example, before determining whether to pull the derived key of the identity authentication request from the authentication server according to the authentication string, it further includes:
[0056] Determine whether the identity authentication request has been cached in the local cache. If it exists, obtain the authentication result of the identity authentication request from the local cache; if not, trigger the execution of S102. When the identity authentication request is included in the local cache, the authentication result of the identity authentication request can be directly obtained from the cache. At this time, there is no need to generate an authentication string to be authenticated for the identity authentication request, saving the computing resources of the authentication proxy server.
[0057] S103. If so, pull the derived key of the identity authentication request from the authentication server, and authenticate the identity authentication request according to the derived key;
[0058] If it is necessary to pull the derived key of the identity authentication request from the authentication server, pull the derived key of the identity authentication request from the authentication server, generate an authentication string to be authenticated for the identity authentication request according to the derived key, and complete the authentication of the identity authentication request by comparing the authentication string to be authenticated with the authentication string carried in the identity authentication request.
[0059] S104. If not, authenticate the identity authentication request through the local cache.
[0060] If it is not necessary to pull the derived key of the identity authentication request from the authentication server, authenticate the identity authentication request according to the local cache.
[0061] The identity authentication method provided by the embodiments of the present disclosure obtains the identity authentication request corresponding to the service server through the authentication proxy server at the service end; the identity authentication request contains an authentication string; according to the authentication string, it is determined whether to pull the derived key of the identity authentication request from the authentication server; if so, pull the derived key of the identity authentication request from the authentication server, and authenticate the identity authentication request according to the derived key; if not, authenticate the identity authentication request through the local cache. It can be seen that the embodiments of the present disclosure intercept traffic through the authentication proxy server and implement signature authentication locally, which can effectively avoid the failure problem of the centralized IAM cluster and reduce the pressure on the centralized IAM cluster at the same time.
[0062] In one example, the above step S102 can be refined into the following steps. Refer to Figure 2 , and the method includes:
[0063] S201. When the authentication string indicates that the identity authentication request belongs to a preset version, update the identity authentication request count corresponding to the preset version;
[0064] When a user requests services from different business servers, the generated authentication strings can be of different versions. For example, when the user requests intelligent cloud services, the type of the generated authentication string can be the intelligent cloud v1 version. The authentication proxy server will only count the identity authentication request count after determining that the authentication string is of the intelligent cloud v1 version.
[0065] S202. Determine whether the identity authentication request count corresponding to the preset version is greater than a preset threshold;
[0066] The preset threshold can be a value set according to experience, such as 1000, 3000. When the statistical count of the current preset version is greater than the preset threshold, it indicates that the authentication proxy server has received a lot of requests.
[0067] S203. If it is greater, then based on whether the access key identity ID in the authentication string is cached in the local cache, determine whether it is necessary to pull a derived key from the authentication server for the identity authentication request.
[0068] When the number of identity authentication requests of the preset version is greater than the preset threshold, it is also necessary to further determine whether it is necessary to pull a derived key from the authentication server for the identity authentication request. There are two reasons for this:
[0069] First, if the user sends an identity authentication request and then sends another identity authentication request without receiving the authentication result, then two identical identity authentication requests will be generated except for the different timestamps. For these two identity authentication requests, the same derived key will be pulled; second, frequently generating derived keys will reduce the performance of the authentication server. Combining these two reasons, when it is determined that the number of identity authentication requests of the preset version is greater than the preset threshold, it is also necessary to determine whether it is necessary to pull a derived key from the authentication server for the identity authentication request based on whether the access key ID in the authentication string is cached.
[0070] We hope that the authentication proxy server can perform concurrent control during the process of pulling the derived key, ensuring that the derived key is pulled from the authentication server only when needed. Considering the control of the concurrency granularity, the best granularity is to allow concurrency when the authentication strings are different except for the timestamps. However, in the authentication string, in fact, except for the access key ID, the only other thing that may change is the validity period of the authentication string, and its change frequency is not high. Therefore, the granularity can be controlled at the access key ID, that is, when there are identical access key IDs being pulled, the authentication request will not be pulled.
[0071] It can be seen that the embodiments of the present disclosure perform concurrent control during the process of pulling the derived key, which can improve the working efficiency of the authentication server.
[0072] In one example, when the authentication string indicates that the authentication request belongs to a preset version, the authentication requests belonging to privileged customers can be filtered according to the list of privileged customers, and further, based on whether the access key ID in the authentication string is cached, it is determined whether it is necessary to pull the derived key from the authentication server for the authentication request. Among them, the list of privileged customers can be sent by the authentication server to the authentication proxy server and saved locally on the authentication proxy server. The authentication proxy server can give priority to processing the authentication requests of privileged customers.
[0073] It can be seen that the embodiments of the present disclosure filter the authentication requests belonging to privileged customers and give priority to processing the authentication requests of privileged customers, which can guarantee the rights and interests of privileged customers.
[0074] There may be a situation where the pull of the derived key fails. In one example, referring to Figure 3 , the method further includes:
[0075] S301. Determine the start time for pulling the derived key from the authentication server;
[0076] The derived key is a parameter related to time. In one example, the derived key generated by the authentication server is at the second level. That is to say, the derived keys generated at 12:00:00 and 12:00:01 are different. It is very likely that the user uses the current time for signing. In order to authenticate the user, the authentication proxy server needs to pull the derived keys within a few seconds from the server.
[0077] When pulling the derived key of the authentication request from the authentication server, record the time at this moment.
[0078] S302. When the duration from the start time reaches the preset duration and the derived key has not been obtained, pull the derived key of the authentication request from the authentication server again;
[0079] Since the time to start pulling the derived key has been obtained previously, when the time elapsed from the start time is greater than a preset duration, it indicates that the pull may have failed. In this case, a re-pull will be selected. The preset duration can be a value set based on experience, such as 1s or 2s.
[0080] S303. When the duration from the moment of restarting the pull is greater than the preset duration and the derived key has not been obtained, generate a pull failure record corresponding to the access key ID.
[0081] If the corresponding derived key is still not obtained within the preset duration after re-pulling the derived key, it means that the re-pull of the derived key has also failed. To avoid hindering subsequent requests with the same access key ID, a pull failure record corresponding to the current access key ID can be generated.
[0082] The pull result record can be used for concurrent control of pulling the derived key.
[0083] In one example, when the access key ID is different from any access key ID in the cache, or when there is a pull failure record corresponding to the access key ID, it is determined that a derived key needs to be pulled from the authentication server for the identity authentication request.
[0084] We hope that the authentication proxy server can perform concurrent control during the process of pulling the derived key to ensure that the derived key is only pulled from the authentication server when necessary. Considering the control of the concurrent granularity, the best granularity is to allow concurrency when the authentication strings are different except for the timestamp. However, in fact, except for the access key ID in the authentication string, the only other possible variable in the authentication string is the validity period of the authentication string, and its change frequency is not high. Therefore, the granularity can be controlled at the access key ID, that is, when there is an identical access key ID being pulled, the identity authentication request is not pulled.
[0085] At the same time, it is also considered that when pulling the derived key for the identity authentication request, a pull failure may occur. If the derived key cannot be successfully pulled for the identity authentication request 1, a pull failure record will be generated for the access key 1. When the identity authentication request carrying the access key 1 requests to pull the derived key again, although the derived key has been pulled for the access key 1, but there is a pull failure record corresponding to the access key 1. At this time, the derived key still needs to be pulled for the identity authentication request carrying the access key 1.
[0086] It can be seen that the embodiments of the present disclosure comprehensively determine whether to pull the derived key for the identity authentication request based on the two conditions of whether the access key ID is cached and whether there is a pull failure record corresponding to the access key ID, avoiding hindering subsequent requests with the same access key.
[0087] S304. In the case of re-pulling the derived key, cache the re-pulled derived key in the local cache.
[0088] If the corresponding derived key is obtained after re-pulling the derived key, a successful pull record can be generated for the current access key ID, and the successfully re-pulled derived key can be cached in the local cache.
[0089] Caching the derived key in the local cache can avoid the leakage of the private access key. The private access key and the access key ID are jointly used for signature authentication. However, if the authentication proxy server is attacked and the derived key is obtained, the signature generated with the derived key will still be valid for a period of time, usually within the caching time. The cache is generally only 15 seconds, and the overall impact is not significant.
[0090] It can be seen that in the embodiments of the present disclosure, by setting the pull failure record / pull success record, the process of pulling the derived key can be concurrently controlled to avoid hindering subsequent requests with the same access key ID.
[0091] In one example, the above step S104 may include the following steps:
[0092] Authenticate the identity authentication request according to the derived key in the local cache;
[0093] After the authentication proxy server pulls the derived key from the server, it will cache the pulled derived key in the local cache. When receiving an identity authentication request, first determine whether there is a derived key for verifying the identity authentication request cached in the local cache. If it exists, sign the identity authentication request according to the derived key to generate a string to be authenticated, and determine the result of the signature authentication by comparing the string to be authenticated with the authentication string carried in the identity authentication request.
[0094] Alternatively, determine whether the identity authentication request has been cached in the local cache. If it exists, obtain the authentication result of the identity authentication request from the local cache.
[0095] The local cache of the authentication proxy server can also cache the authentication results of the identity authentication requests that have been authenticated. By comparing the received identity authentication request with the identity authentication requests with existing results, the authentication of the identity authentication request can be completed.
[0096] It can be seen that the identity authentication method provided by the embodiments of the present disclosure completes the authentication of the identity authentication request by pre-pulling the derived key and caching the authentication result, greatly reducing the pressure on the IAM center cluster.
[0097] In one example, if neither the derived key for signing the authentication request nor the authentication result of the authentication request exists in the local cache, the authentication request will be sent to the authentication server for signature authentication at this time. The authentication proxy server will also receive the authentication result of the authentication server for this authentication request and store it in the local cache.
[0098] If the authentication server returns 2xx, it indicates that the authentication request has passed the authentication, and a successful cache will be set in the authentication proxy server accordingly; if the authentication server returns 4xx, it indicates that the authentication request has not passed the authentication, and a failed cache will be set in the authentication proxy server accordingly.
[0099] In one example, the authentication proxy server is deployed as a sidecar on the machines of the business line. When the business line sends an authentication and authorization request, it can intercept the request and complete local authentication and authorization. The schematic diagram is as Figure 4a and Figure 4b shown:
[0100] In the related art, the authentication of the authentication request is carried out in the manner as Figure 4a shown. The authentication requests of the object storage service and the cloud server service need to be signed and authenticated by the authentication server. In this case, the query rate of the authentication server per second is very high. When the customer makes a request to access, an obvious network interaction delay will be felt.
[0101] In the embodiments of the present application, the authentication of the authentication request is carried out in the manner as Figure 4b shown. The authentication of the service side has changed from accessing the authentication server to accessing the local authentication proxy server. The authentication requests corresponding to the object storage server and the cloud server have become signed and authenticated through the local authentication proxy server. Since the derived key is a parameter related to time, in one example, the derived key generated by the authentication server is at the second level. That is to say, the derived keys generated at 12:00:00 and 12:00:01 are different. It is very likely that the user uses the current time for signing. In order to authenticate the user's identity, when necessary, the authentication proxy server needs to pull the derived keys within a few seconds from the server. The authentication proxy server completes the local request by pre-pulling the derived keys and caching the authentication results.
[0102] Although caching the derived key can avoid the leakage of the sk (Secret Access Key), if the service is breached and the derived key is obtained, using it to generate a signature will still be valid for a period of time, but it is only controlled within the cached time, usually only 15 seconds when caching, and the overall impact is not significant.
[0103] In one example, the overall architecture diagram of the authentication proxy server is as Figure 5As shown, it includes a preparation interceptor, a statistics interceptor, an authentication interceptor, and a caching interceptor.
[0104] The preparation interceptor is used to receive an HTTP request, convert the received HTTP request into an internal data structure, and at the same time obtain a cache from the cache module to construct an authentication context, where the constructed authentication context refers to an identity authentication request.
[0105] The statistics interceptor is used to mark hot customers and decide whether to pull a derived key in advance for hot customers.
[0106] The authentication interceptor is used to perform local authentication and authorization on identity authentication requests that can be locally processed; for identity authentication requests that cannot be locally processed, it determines whether a derived key needs to be pulled. If so, it marks that the identity authentication request needs to pull a derived key. The authentication interceptor can schedule identity authentication requests.
[0107] The caching interceptor is used to receive the response result of the authentication server and cache it, and set the cache into the cache module.
[0108] The cache module can be a simple LRU (Least Recently Used) cache.
[0109] The general data structure includes an authentication context, which is an interface between interceptors.
[0110] The utility functions include some operations such as string operations and time operations.
[0111] In one example, the authentication proxy server completes the identity authentication process in the following way. See Figure 6 :
[0112] The authentication proxy server includes a preparation interceptor, a statistics interceptor, an authentication interceptor, and a caching interceptor.
[0113] The preparation interceptor can receive an HTTP access request initiated by a user, set the ID of the request, and at the same time convert the HTTP request into an identity authentication request. Then, it checks whether the identity authentication request hits the quick-fail cache through a quick-fail checker. If it exists, the identity authentication request is authenticated according to the quick-fail cache; if it does not exist, the identity authentication request is sent to the statistics interceptor. Among them, the way to process the identity authentication request through the quick-fail checker can be: judging whether the identity authentication request has been cached in the local cache. If it exists, the authentication result of the identity authentication request is obtained from the local cache.
[0114] After receiving an identity authentication request, the statistics interceptor determines whether the authentication string in the identity authentication request is the intelligent cloud v1 version. If so, it finds the corresponding identification context information based on the mapping table saved locally, and counts the number of identification context information that meets the intelligent cloud v1 version. The data structure of the identification context information consists of an integer ID, a boolean is_fetching (indicating whether it is currently fetching), a pull start time of type atmoic<time_t>, and an integer count value. When the quantity exceeds the minimum value marked as a hot customer, a "hot customer" mark is added to the current identity authentication request, and the access key ID in the identity authentication request is continued to be obtained. When the access key ID has not appeared before, or there is a pull failure record corresponding to the access key ID, a derived key is pulled for the identity authentication request from the authentication server. If the quantity of the identification context information fails to exceed the minimum value marked as a hot customer, the identity authentication request is sent to the authorization interceptor.
[0115] After receiving an identity authentication request, the authorization interceptor determines whether to perform local authorization on the identity authentication request based on the local cache. If it cannot perform local authorization on the identity authentication request, it determines whether to pull a derived key for the identity authentication request. If needed, after pulling the derived key, authorization processing is performed on the identity authentication request. If not needed, the identity authentication request is sent to the authentication server for authorization authentication.
[0116] The cache interceptor can parse the response to the request returned by the authentication server, that is, in the case where the identity authentication request is not locally processed, it receives the response result from the authentication server and caches it. If 2xx is returned, a successful cache is set in the cache interceptor; if 4xx is returned, a failed cache is set in the cache interceptor.
[0117] The overall processing flow of the above preparation interceptor is as Figure 7 shown:
[0118] The preparation interceptor first receives the http request from the business line, sets an ID for it to sort out the request, and at the same time performs data structuring on the http, converts the http request into an authorization request, and constructs an authorization context based on the cache information. The cache information includes cache context information, application programming interface information, identifier information, etc. The cache context information includes information such as derived keys, tokens, and verification results. If the authorization context cannot be generated, it ends.
[0119] After generating the authorization context, the fast failure checker checks whether the authorization context exists in the local cache. If it exists, the authorization result of the authorization context is directly obtained from the local cache, and it enters fast failure; if it does not exist, it enters the statistics interceptor. The authorization context is the identity authentication request.
[0120] The overall processing flow of the above statistical interceptor is as Figure 8 shown below:
[0121] During the process of pulling the derived key for the identity authentication request, concurrent control is performed. The statistical interceptor first receives the identity authentication request carrying the identifier, and can periodically clear the mapping table that stores the mapping relationship between the identity authentication request and the identity context information. A corresponding identity context is newly created according to the identifier, and the corresponding relationship between the identity authentication request corresponding to the identifier and the newly created identity context is stored in the mapping table.
[0122] Count the number of current identity contexts, and determine whether the counted number is greater than the preset threshold. If it is greater, mark the identity authentication request as the identity authentication request of a hot customer; it is also possible to screen the identity authentication requests belonging to privileged customers through the privileged customer list, and mark the identity authentication requests of privileged customers as the identity authentication requests of hot customers.
[0123] If the identifier is not of the ak (accessKeyId, access key ID) type and is not the preset version, do not pull the derived key for the identity authentication request to which the identifier belongs; if the identifier is of the ak type and is also the preset version, attempt to pull the derived key for the identity authentication request to which the identifier belongs. In the case of a failed pull, if the waiting time exceeds the preset duration and does not exceed the preset number of pulls, continue to pull the derived key; if the waiting time exceeds the preset duration and exceeds the preset number of pulls, do not pull the derived key.
[0124] See Figure 9 , where the identifier of each identity authentication request includes the identification id information of the int type, the type information of the enum type (the type information of the enum type includes the ak type, the token (token) id, and the user (user) id), the is_top information of the bool type (the is_top information is used to indicate whether the identifier corresponds to a hot customer), and the need_fetching information of the bool type (the need_fetching information is used to determine whether to pull the derived key).
[0125] The identity context corresponding to each identity authentication request includes the fetching_start_time information of the atmoic<time_t> type (the fetching_start_time information is used to indicate the start time of pulling the derived key), and the count information of the int type (the count information is used to count the current identity context).
[0126] Accessor is the accessor, and modifiers are the editors.
[0127] In one example, the processing flow of the statistical interceptor may further include:
[0128] Receiving an identity authentication request carrying an identifier;
[0129] Judging whether the type of the identifier is ak and it is an authentication string of a preset version. If not, directly pass through;
[0130] Judging whether the mapping table of the identity authentication request and the identity context needs to be cleared. If so, clear it;
[0131] Finding the identity context corresponding to the access key id according to the mapping table; if not found, creating a new identity context according to the access key id;
[0132] Counting the number of current identity contexts;
[0133] Judging whether the counting result exceeds the minimum threshold marked as a hot customer;
[0134] If so, marking the current identity authentication request as an identity authentication request of a hot customer and setting the is_top information of the identifier to true;
[0135] Judging whether it is necessary to pull a derived key for the identity authentication request of a hot customer; in one example, it can be judged according to the fields being pulled simultaneously in the identity authentication request and the fields being pulled currently;
[0136] If so, judging the start time of pulling the derived key. If the time exceeds the preset duration, pulling the derived key from the authentication server again, resetting the pulling start time, and at this time setting the field of pulling simultaneously in the identity authentication request to false;
[0137] If the time does not exceed the preset duration, setting the field of pulling simultaneously in the identity authentication request to true;
[0138] If it is not necessary to pull a derived key for the identity authentication request of a hot customer, setting the field of pulling currently in the identity authentication request to true, setting the pulling start time, and setting the field of pulling simultaneously in the identity authentication request to false;
[0139] If the counting result does not exceed the minimum threshold marked as a hot customer, it means that the current identity authentication request is not an identity authentication request of a hot customer, and it can be directly returned;
[0140] When receiving the response of the authentication server for pulling the derived key, setting the field of pulling currently in the identity context to false and setting the pulling time.
[0141] The processing flow of the above authentication interceptor is as Figure 10As shown in:
[0142] The authentication interceptor receives the authentication context output by the statistics interceptor. Here, the authentication context refers to the identity authentication request. If the authentication result of the identity authentication request is in the local cache, the processing is completed locally. Otherwise, when it is determined that a derived key needs to be pulled for the identity authentication request, a flag indicating the need to pull the derived key is set for it, and the derived key is pulled from the authentication server to perform authentication processing on the identity authentication request; when it is not necessary to pull the derived key for the identity authentication request, it is sent to the authentication server for authentication processing.
[0143] On the other hand, an embodiment of the present disclosure also provides an identity authentication system. Refer to Figure 11 , including: an authentication proxy server 1101 at the service side, a service server 1103 at the service side, and an authentication server 1102 at the authentication side;
[0144] The authentication proxy server is used to obtain the identity authentication request corresponding to the service server; the identity authentication request contains an authentication string; according to the authentication string, it is determined whether it is necessary to pull the derived key of the identity authentication request from the authentication server at the authentication side; if so, the derived key of the identity authentication request is pulled from the authentication server at the authentication side, and the identity authentication request is authenticated according to the derived key; if not, the identity authentication request is authenticated through the local cache;
[0145] The service server is used to respond to the access request corresponding to the identity authentication request when the identity authentication request passes the authentication;
[0146] The authentication server at the authentication side is used to generate the derived key of the identity authentication request.
[0147] In one example, the authentication proxy server is further used to determine whether the identity authentication request has been cached in the local cache. If it exists, the authentication result of the identity authentication request is obtained from the local cache; if not, the step of determining whether it is necessary to pull the derived key of the identity authentication request from the authentication server according to the authentication string is triggered.
[0148] In one example, the authentication proxy server is specifically used to update the count of the identity authentication requests corresponding to the preset version when the authentication string indicates that the identity authentication request belongs to the preset version;
[0149] Determine whether the count of the identity authentication requests corresponding to the preset version is greater than a preset threshold;
[0150] If it is greater than, it is determined whether it is necessary to pull the derived key from the authentication server for the identity authentication request based on whether the access key identifier ID in the authentication string is cached in the local cache.
[0151] In one example, the authentication proxy server is further configured to determine the start time for pulling the derived key from the authentication server;
[0152] When the duration from the start time reaches the preset duration and the derived key is not obtained, the derived key of the identity authentication request is pulled again from the authentication server;
[0153] When the duration from the restart time of pulling is greater than the preset duration and the derived key is not obtained, a pull failure record corresponding to the access key ID is generated;
[0154] When the derived key is pulled again, the pulled again derived key is cached in the local cache.
[0155] In one example, the authentication proxy server is specifically configured to determine that it is necessary to pull the derived key of the identity authentication request from the authentication server when the access key ID is different from any access key ID in the cache, or when there is a pull failure record corresponding to the access key ID.
[0156] In one example, the authentication proxy server is specifically configured to authenticate the identity authentication request according to the derived key in the local cache; or, determine whether the identity authentication request has been cached in the local cache, and if so, obtain the authentication result of the identity authentication request from the local cache.
[0157] On the other hand, an embodiment of the present disclosure further provides an identity authentication device, see Figure 12 , the device includes:
[0158] A preprocessing module 1201, configured to obtain the identity authentication request corresponding to the service server; the identity authentication request includes an authentication string;
[0159] A judgment module 1202, configured to judge whether it is necessary to pull the derived key of the identity authentication request from the authentication server according to the authentication string;
[0160] A pulling module 1203, configured to pull the derived key of the identity authentication request from the authentication server if it is necessary to pull the derived key of the identity authentication request from the authentication server, and authenticate the identity authentication request according to the derived key;
[0161] The local processing module 1204 is configured to, if it is not necessary to pull the derived key of the identity authentication request from the authentication server, perform authentication of the identity authentication request through local caching.
[0162] In one example, refer to Figure 13 , the device further includes a fast authentication module 1301;
[0163] The fast authentication module 1301 is configured to determine whether the identity authentication request has been cached in the local cache. If it exists, obtain the authentication result of the identity authentication request from the local cache; if it does not exist, trigger the execution of the judgment module.
[0164] In one example, the judgment module is specifically configured to, when the authentication string indicates that the identity authentication request belongs to a preset version, update the identity authentication request count corresponding to the preset version; determine whether the identity authentication request count corresponding to the preset version is greater than a preset threshold; if it is greater, determine whether it is necessary to pull the derived key for the identity authentication request from the authentication server based on whether the access key ID in the authentication string is cached in the local cache.
[0165] In one example, refer to Figure 14 , the device further includes a pull result recording module 1401. The pull result recording module 1401 is configured to determine the start time of pulling the derived key from the authentication server; when the duration from the start time reaches a preset duration and the derived key has not been obtained, pull the derived key of the identity authentication request from the authentication server again; when the duration from the moment of restarting the pull is greater than the preset duration and the derived key has not been obtained, generate a pull failure record corresponding to the access key ID; when the derived key is pulled again, cache the pulled derived key in the local cache.
[0166] In one example, the judgment module is specifically configured to:
[0167] When the access key ID is different from any access key ID in the cache, or there is a pull failure record corresponding to the access key ID, it is determined that it is necessary to pull the derived key for the identity authentication request from the authentication server.
[0168] In one example, the local processing module is specifically configured to perform authentication of the identity authentication request according to the derived key in the local cache; or, determine whether the identity authentication request has been cached in the local cache. If it exists, obtain the authentication result of the identity authentication request from the local cache.
[0169] In the technical solution of the present disclosure, the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information and other processing comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0170] According to an embodiment of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0171] The electronic device is used to implement any one of the identity authentication methods in the present disclosure.
[0172] The readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements any one of the identity authentication methods in the present disclosure.
[0173] When the computer program product runs on a computer, the computer is caused to execute any one of the identity authentication methods in the present disclosure.
[0174] Figure 15 FIG. shows a schematic block diagram of an exemplary electronic device 1500 that can be used to implement the embodiments of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, for example, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, for example, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely exemplary and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0175] As Figure 15 shown, the device 1500 includes a computing unit 1501, which can execute various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 1502 or a computer program loaded from a storage unit 1508 into a random access memory (RAM) 1503. In the RAM 1503, various programs and data required for the operation of the device 1500 can also be stored. The computing unit 1501, the ROM 1502, and the RAM 1503 are connected to each other through a bus 1504. An input / output (I / O) interface 1505 is also connected to the bus 1504.
[0176] Multiple components in device 1500 are connected to I / O interface 1505, including: an input unit 1506, such as a keyboard, a mouse, etc.; an output unit 1507, such as various types of displays, speakers, etc.; a storage unit 1508, such as a magnetic disk, an optical disc, etc.; and a communication unit 1509, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 1509 allows device 1500 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.
[0177] The computing unit 1501 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 1501 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 1501 executes the various methods and processes described above, such as the authentication method. For example, in some embodiments, the authentication method can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 1508. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 1500 via the ROM 1502 and / or the communication unit 1509. When the computer program is loaded into the RAM 1503 and executed by the computing unit 1501, one or more steps of the authentication method described above can be executed. Alternatively, in other embodiments, the computing unit 1501 can be configured to execute the authentication method by any other suitable means (e.g., by means of firmware).
[0178] Various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGA), application-specific integrated circuits (ASIC), application-specific standard products (ASSP), system-on-chip systems (SOC), complex programmable logic devices (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a dedicated or general-purpose programmable processor, and can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0179] The program code for implementing the methods of the present disclosure may be written in any combination of one or more programming languages. These program codes may be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The program code may be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0180] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0181] In order to provide interaction with a user, the systems and techniques described herein may be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, speech input, or tactile input).
[0182] The systems and techniques described herein can be implemented in a computing system including backend components (e.g., as a data server), or a computing system including middleware components (e.g., an application server), or a computing system including frontend components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with an implementation of the systems and techniques described herein), or a computing system including any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), and the Internet.
[0183] A computer system can include a client and a server. The client and the server are generally remote from each other and typically interact through a communication network. The client - server relationship is created by computer programs running on respective computers and having a client - server relationship with each other. The server can be a cloud server, can also be a server of a distributed system, or a server incorporating blockchain.
[0184] It should be understood that various forms of the flow shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not limited herein.
[0185] The above - described specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub - combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.
Claims
1. An identity authentication method is applied to an authentication proxy server on the service side, and the service side further includes a service server. The method includes: Obtain the identity authentication request corresponding to the service server; The identity authentication request contains an authentication string; According to the authentication string, determine whether it is necessary to pull the derived key of the identity authentication request from the authentication server, including: when the authentication string indicates that the identity authentication request belongs to a preset version, update the identity authentication request count corresponding to the preset version; different versions indicate that the authentication string is generated when the user requests services from different service servers; determine whether the identity authentication request count corresponding to the preset version is greater than a preset threshold; if it is greater, then based on whether the access key identity ID in the authentication string is cached in the local cache, determine whether it is necessary to pull the derived key from the authentication server for the identity authentication request; If so, pull the derived key of the identity authentication request from the authentication server, and perform authentication on the identity authentication request according to the derived key; If not, perform authentication on the identity authentication request through the local cache; The method further includes: Determine the start time for pulling the derived key from the authentication server; When the duration from the start time reaches a preset duration and the derived key is not obtained, pull the derived key of the identity authentication request from the authentication server again; When the duration from the moment of restarting the pull is greater than the preset duration and the derived key is not obtained, generate a pull failure record corresponding to the access key ID; When the derived key is pulled again, cache the pulled derived key in the local cache.
2. The method according to claim 1, wherein, Before determining whether it is necessary to pull the derived key of the identity authentication request from the authentication server according to the authentication string, the method further includes: Determine whether the identity authentication request has been cached in the local cache. If it exists, obtain the authentication result of the identity authentication request from the local cache; If not, trigger the step of determining whether it is necessary to pull the derived key of the identity authentication request from the authentication server according to the authentication string.
3. The method according to claim 1, determining whether it is necessary to pull the derived key from the authentication server for the identity authentication request based on whether the access key identity ID in the authentication string is cached in the local cache, includes: When the access key ID is different from any access key ID in the cache, or there is a pull failure record corresponding to the access key ID, it is determined that it is necessary to pull the derived key from the authentication server for the identity authentication request.
4. The method according to claim 1, performing authentication on the identity authentication request through the local cache, includes: Perform authentication on the identity authentication request according to the derived key in the local cache; or Determine whether the identity authentication request has been cached in the local cache. If it exists, obtain the authentication result of the identity authentication request from the local cache.
5. The method according to claim 1, wherein, the authentication proxy server runs the sidecar mode identity recognition and access management front-end machine service.
6. An identity authentication device, the device comprises: a preprocessing module, configured to obtain an identity authentication request corresponding to a service server; the identity authentication request contains an authentication string; a judgment module, configured to judge whether it is necessary to pull a derived key of the identity authentication request from an authentication server according to the authentication string, including: when the authentication string indicates that the identity authentication request belongs to a preset version, updating the identity authentication request count corresponding to the preset version; different versions indicate that the authentication string is generated when the user requests services from different service servers; judging whether the identity authentication request count corresponding to the preset version is greater than a preset threshold; if it is greater, judge whether it is necessary to pull a derived key for the identity authentication request from the authentication server based on whether the access key identity ID in the authentication string is cached in the local cache; a pulling module, configured to, if it is necessary to pull a derived key of the identity authentication request from the authentication server, pull the derived key of the identity authentication request from the authentication server, and perform authentication on the identity authentication request according to the derived key; a local processing module, configured to, if it is not necessary to pull a derived key of the identity authentication request from the authentication server, perform authentication on the identity authentication request through the local cache; the device further comprises a pulling result recording module, configured to determine the start time of pulling the derived key from the authentication server; when the duration from the start time reaches a preset duration and the derived key is not obtained, pull the derived key of the identity authentication request from the authentication server again; when the duration from the re-start pulling moment is greater than the preset duration and the derived key is not obtained, generate a pulling failure record corresponding to the access key ID; when the derived key is pulled again, cache the re-pulled derived key in the local cache.
7. The device according to claim 6, the device further comprises a quick authentication module; the quick authentication module is configured to judge whether the identity authentication request has been cached in the local cache. If it exists, obtain the authentication result of the identity authentication request from the local cache; if it does not exist, trigger the execution of the judgment module.
8. The device according to claim 6, the judgment module is specifically configured to: when the access key ID is different from any access key ID in the cache, or there is a pulling failure record corresponding to the access key ID, determine that it is necessary to pull a derived key for the identity authentication request from the authentication server.
9. The apparatus according to claim 6, wherein the local processing module is specifically configured to authenticate the authentication request according to the derived key in the local cache; or, determine whether the authentication request has been cached in the local cache, and if so, obtain the authentication result of the authentication request from the local cache.
10. An identity authentication system comprising: an authentication proxy server at the service side, a service server at the service side, and an authentication server at the authentication side; the authentication proxy server is configured to obtain the identity authentication request corresponding to the service server; the authentication string is included in the identity authentication request; judging whether it is necessary to pull the derived key of the identity authentication request from the authentication server according to the authentication string, including: when the authentication string indicates that the identity authentication request belongs to a preset version, updating the identity authentication request count corresponding to the preset version; different versions indicate that the authentication string is generated when the user requests services from different service servers; judging whether the identity authentication request count corresponding to the preset version is greater than a preset threshold; if it is greater, judging whether it is necessary to pull the derived key for the identity authentication request from the authentication server based on whether the access key identity ID in the authentication string is cached in the local cache; if so, pulling the derived key of the identity authentication request from the authentication server, and authenticating the identity authentication request according to the derived key; if not, authenticating the identity authentication request through the local cache; determining the start time for pulling the derived key from the authentication server; when the duration from the start time reaches a preset duration and the derived key has not been obtained, pulling the derived key of the identity authentication request from the authentication server again; when the duration from the re-start pulling moment is greater than the preset duration and the derived key has not been obtained, generating a pull failure record corresponding to the access key ID; when the derived key is pulled again, caching the re-pulled derived key in the local cache; the service server is configured to respond to the access request corresponding to the identity authentication request when the authentication of the identity authentication request is passed; the authentication server at the authentication side is configured to generate the derived key of the identity authentication request.
11. An electronic device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and when the instructions are executed by the at least one processor, the at least one processor is enabled to execute the method according to any one of claims 1-5.
12. A non-transitory computer-readable storage medium storing computer instructions wherein, the computer instructions are used to cause the computer to execute the method according to any one of claims 1-5.
13. A computer program product comprising a computer program, where the computer program, when executed by a processor, implements the method according to any one of claims 1-5.
Citation Information
Patent Citations
Authentication method and device, computer equipment and storage medium
CN111949974A
Authentication information synchronization method and device
CN112788048A