A method, device, storage medium and electronic device for generating a proxy certificate
By regularly storing and detecting certificate information during the process of generating proxy certificates, the problem of regenerating certificates after abnormal interruption of proxy system is solved, and the efficiency of generating proxy certificates and the stability of traffic transmission is improved.
Patent Information
- Application Number
- CN202211542430.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-02
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-12-02
AI Technical Summary
In the prior art, the process of generating server-side proxy certificates is less efficient, which leads to the impact of traffic transmission, especially when the proxy system needs to re-generate the certificate from scratch after abnormal interruption.
During the process of generating the proxy certificate, the certificate information of the proxy certificate constructed in memory is regularly detected whether the certificate information of the proxy certificate is stored in the target file. If it has been stored, the constructed certificate information is read from the target file after the proxy system is abnormally restored to continue to construct the proxy certificate.
It improves the efficiency of generating proxy certificates, reduces the time to reconstruct certificates after abnormal recovery, and ensures normal traffic transmission and service continuity.
Smart Images

Figure CN116015666B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology. Specifically, it relates to a method, device, storage medium, and electronic device for generating proxy certificates. Background Art
[0002] With the continuous change of the network environment, the security of data traffic transmission is particularly important.
[0003] Due to the increasing complexity of traffic encryption algorithms, bypass decryption can no longer meet the requirements. Therefore, the currently widely used is the proxy decryption system. When the client and the server perform traffic transmission, they need to pass through the proxy decryption system. The proxy decryption system needs to negotiate with the client and the server and check the validity of the server's certificate. After the proxy decryption system checks the server's certificate, it needs to generate a server proxy certificate so that the proxy system can decrypt the client's traffic. Currently, in the process of generating the server proxy certificate, when the proxy system has an abnormal interruption, the process of generating the proxy certificate is also terminated. When the abnormality is restored, it is necessary to regenerate the proxy certificate from the beginning again, resulting in a low efficiency of generating the proxy certificate and affecting the traffic transmission.
[0004] Therefore, how to provide a technical solution for an efficient method of generating proxy certificates has become a technical problem that urgently needs to be solved. Summary of the Invention
[0005] Some embodiments of the present application aim to provide a method, device, storage medium, and electronic device for generating proxy certificates. Through the technical solutions of the embodiments of the present application, the efficiency of generating proxy certificates can be improved, so that traffic can be effectively transmitted and the normal operation of services can be guaranteed.
[0006] In a first aspect, some embodiments of the present application provide a method for generating a proxy certificate, including: during the process of generating a proxy certificate corresponding to a server-side certificate, regularly detecting whether the certificate information for constructing the proxy certificate in the memory is stored in a target file, and obtaining a detection result, where the certificate information includes: server address, server domain name, construction certificate generation time, and construction certificate content; according to the detection result, determining whether to add the certificate information to the target file, so that after the construction abnormality is restored during the process of constructing the proxy certificate, the certificate information constructed before the abnormality can be read from the target file to obtain the proxy certificate.
[0007] In some embodiments of the present application, during the process of generating a proxy certificate, the certificate information is stored in a target file. After an exception occurs and is recovered, the constructed certificate information can be read from the target file without having to reconstruct it repeatedly, improving the efficiency of generating the proxy certificate, enabling effective transmission of traffic, and ensuring the normal operation of the service.
[0008] In some embodiments, the method of periodically detecting whether the certificate information for constructing the proxy certificate is stored in the target file and obtaining the detection result includes: if the certificate information of the proxy certificate is not stored in the target file, then confirming that the detection result is not stored; and determining whether to add the certificate information to the target file according to the detection result includes: adding the certificate information to the target file.
[0009] In some embodiments of the present application, by detecting that the certificate information is not stored and storing it in the target file, effective storage of the certificate information can be achieved, providing effective information for subsequent use.
[0010] In some embodiments, before periodically detecting whether the certificate information for constructing the proxy certificate is stored in the target file, the method further includes: creating the target file, where the target file is stored in a target path or a target device.
[0011] In some embodiments of the present application, by creating a target file, the certificate information can be stored in an orderly manner, facilitating searching.
[0012] In some embodiments, the method further includes: performing an operation on the certificate information to obtain an information identification value, and storing the information identification value in the target file.
[0013] In some embodiments of the present application, by obtaining the information identification value of the certificate information through an operation, the certificate information can be effectively prevented from being tampered with.
[0014] In some embodiments, the method further includes: when the certificate information for constructing the proxy certificate in the memory is deleted, the certificate information in the target file is also deleted simultaneously.
[0015] In some embodiments of the present application, by synchronously deleting invalid certificate information, memory can be released.
[0016] In some embodiments, the step of reading the certificate information constructed before the exception from the target file to obtain the proxy certificate includes: reading the certificate information to be verified and the information identification value from the target file in chronological order; if it is confirmed that the certificate information to be verified is valid information, then using the certificate information to be verified as the certificate information, and constructing the proxy certificate based on the certificate information.
[0017] Some embodiments of the present application can achieve the accuracy and efficiency of proxy certificate construction by reading the certificate information to be verified and the information identification value in the target file, and then constructing a proxy certificate after verifying the validity of both.
[0018] In some embodiments, confirming that the certificate information to be verified is valid information includes: performing an operation on the certificate information to be verified to obtain a to-be-verified identification value; when it is confirmed that the to-be-verified identification value is the same as the information identification value, the certificate information to be verified is valid information.
[0019] Some embodiments of the present application compare the to-be-verified identification value of the certificate information to be verified with the information identification value to ensure that the certificate information has not been tampered with and guarantee the accuracy of the certificate information.
[0020] In some embodiments, before confirming that the certificate information to be verified is valid information, the method further includes: confirming that the memory size of the certificate information to be verified does not exceed a set memory threshold, and / or confirming that the reading time of the certificate information to be verified is within a preset time threshold.
[0021] Some embodiments of the present application confirm that the certificate information to be verified is valid information by the memory and / or the length of the reading time of the certificate information to be verified, so as to obtain accurate information of the certificate information to prevent tampering and obtaining invalid certificate information.
[0022] In a second aspect, some embodiments of the present application provide an apparatus for generating a proxy certificate, including: a detection module configured to periodically detect during the process of generating a proxy certificate corresponding to a server-side certificate whether the certificate information for constructing the proxy certificate in the memory is stored in a target file and obtain a detection result, where the certificate information includes: a server address, a server domain name, a construction certificate generation time, and a construction certificate content; a confirmation module configured to determine whether to add the certificate information to the target file according to the detection result, so that after a construction anomaly recovery occurs during the process of constructing the proxy certificate, the certificate information constructed before the anomaly can be read from the target file to obtain the proxy certificate.
[0023] In a third aspect, some embodiments of the present application provide a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method described in any embodiment of the first aspect can be implemented.
[0024] In a fourth aspect, some embodiments of the present application provide an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor, where when the processor executes the program, the method described in any embodiment of the first aspect can be implemented.
[0025] In a fifth aspect, some embodiments of the present application provide a computer program product, which includes a computer program. When the computer program is executed by a processor, the method described in any one of the embodiments of the first aspect can be implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] In order to more clearly illustrate the technical solutions of some embodiments of the present application, the accompanying drawings required for some embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show some embodiments of the present application and should not be regarded as limiting the scope. For those of ordinary skill in the art, other related drawings can be obtained based on these drawings without creative efforts.
[0027] Figure 1 System diagram for generating proxy certificates provided by some embodiments of the present application;
[0028] Figure 2 One of the method flowcharts for generating proxy certificates provided by some embodiments of the present application;
[0029] Figure 3 Another method flowchart for generating proxy certificates provided by some embodiments of the present application;
[0030] Figure 4 Block diagram of the device for generating proxy certificates provided by some embodiments of the present application;
[0031] Figure 5 Block diagram of the device for generating proxy certificates provided by some embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0032] The technical solutions in some embodiments of the present application will be described below with reference to the accompanying drawings in some embodiments of the present application.
[0033] It should be noted that similar reference numerals and letters denote similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of the present application, terms such as "first" and "second" are only used for descriptive distinction and cannot be understood as indicating or implying relative importance.
[0034] In the related art, in today's network environment, the application scenarios of the HTTP protocol (Hyper Text Transfer Protocol) are becoming increasingly widespread. With the increasing requirements for the confidentiality of traffic transmission in the network environment, the vast majority of HTTP-based applications have switched to the HTTPS protocol (Hypertext Transfer Protocol Secure). For security devices, encrypted HTTPS traffic cannot be directly detected and needs to be decrypted first. As the encryption and decryption algorithms used in network traffic become more and more complex, side-channel decryption can no longer meet the requirements. Currently, the most commonly used is the proxy SSL decryption system. Among them, SSL stands for Secure Sockets Layer, which is a security protocol that provides security and data integrity for network communication and uses public key technology.
[0035] The working mode of the proxy SSL decryption system (referred to as the proxy system for short) belongs to the man-in-the-middle mode. After the client interacts with the proxy system through SSL, the proxy system negotiates with the server through SSL. After obtaining the certificate information of the server, a new certificate is reconstructed with the private key of the proxy system itself and then subsequent SSL negotiation is carried out with the client, so that the decrypted plaintext traffic can be obtained. The process of the proxy system constructing the proxy certificate usually takes some time in the live network environment for server certificate acquisition, certificate content inspection, validity period and validity check. In this processing stage, the request content of the client cannot be normally decrypted, and the request response speed of the client will be slowed down.
[0036] In the prior art, after the proxy system receives the encrypted traffic request from the client, the following steps are required to complete the certificate construction: 1) Construct a new encrypted traffic request and send it to the real server. 2) After obtaining the certificate from the server, check that the CN, validity period, validity, and some extension fields of the certificate meet the requirements. 3) Extract the server certificate information to construct the decryption certificate and cache it in the memory table entry. 4) If an exception occurs in the proxy system, the proxy system is restarted / reset, all the constructed certificate table entries are cleared, and the above process needs to be repeated to regenerate the certificate table entries.
[0037] As can be seen from the above related art, during the process of certificate construction, the encrypted communication traffic between the client and the server is in an undecryptable state or in a waiting-for-forwarding state. When the proxy system is restarted abnormally, it is necessary to reconstruct the proxy certificate from scratch, with low efficiency, which will have an adverse impact on traffic decryption and transmission.
[0038] In view of this, some embodiments of the present application provide a method for generating a proxy certificate. During the process of generating the proxy certificate, the method periodically detects whether the certificate information of the proxy certificate constructed in memory is stored in the target file, so as to ensure that after the proxy system is restarted or reset abnormally, the certificate information constructed before the abnormality can be read from the target file, and then the proxy certificate can be continued to be constructed on this basis. Some embodiments of the present application can improve the efficiency of generating the proxy certificate, enable the traffic to be effectively transmitted, and ensure the normal operation of the service.
[0039] The following will Figure 1 exemplarily elaborate on the system composition structure of the proxy certificate generation provided by some embodiments of the present application.
[0040] As Figure 1 shown, some embodiments of the present application provide a system for generating a proxy certificate. The system for generating a proxy certificate includes: a client 100, a proxy system 200, and a server side 300. Among them, the client 100 sends an encrypted traffic request to the proxy system 200, and the proxy system 200 sends a negotiation traffic request to the server side 300, and then obtains the server side certificate from the server side 300. The proxy system 200 checks the server side certificate. After the check passes, the content information in the server certificate is extracted, and a certificate entry (as a specific example of the certificate information) is constructed and stored in memory, and the certificate entry is stored in the target file during the construction process. During the process of the proxy system 200 constructing the certificate entry, due to network reasons, the proxy system cannot construct normally. After the proxy system is restarted, the certificate entry constructed before the restart can be read from the target file, and the construction can be continued on this basis to obtain the proxy certificate.
[0041] In some embodiments of the present application, when the proxy system has an abnormality, after the proxy system is restarted or reset and restored, there is no need to reconstruct the certificate information before the abnormality, and it can be directly read from the target file, which greatly improves the efficiency of constructing the proxy certificate, ensures the normal forwarding and decryption processing of the traffic, guarantees the normal operation of the service, and has high practicability.
[0042] The following will Figure 2 exemplarily elaborate on the implementation process of generating a proxy certificate executed by the proxy system 200 provided by some embodiments of the present application.
[0043] Please refer to the Figure 2 , Figure 2 which is a flowchart of a method for generating a proxy certificate provided by some embodiments of the present application. The method for generating a proxy certificate includes:
[0044] S210. During the process of generating a proxy certificate corresponding to the server - side certificate, periodically detect whether the certificate information for constructing the proxy certificate in the memory has been stored in the target file, and obtain the detection result. Among them, the certificate information includes: server address, server domain name, construction certificate generation time, and construction certificate content.
[0045] For example, in some embodiments of the present application, the proxy system 200 works properly, processes traffic, generates the constructed proxy certificate and caches it in the memory for invocation. The proxy system 200 checks the constructed certificate entries in the memory at a certain time interval (such as: once per hour or once per half - hour by default, which can be specifically set according to the actual situation) to confirm whether they have been stored in the target file.
[0046] In some embodiments of the present application, before executing S210, the method for generating a proxy certificate further includes: creating the target file, where the target file is stored in the target path or target device.
[0047] For example, in some embodiments of the present application, a storage directory file (as a specific example of the target file) can be established by natural day. For example, a storage directory file for the current day is established at 00:00:00 every day, and the newly generated constructed certificate information of the current day is stored in the storage directory file of the current day. By setting the storage directory file regularly, it can ensure the system time synchronization between the proxy system 200 and the storage system (as a specific example of the target path or target device). For example, when the system time on the storage system reaches 2022 / 11 / 23 00:00:00, a storage directory for the current day is established, and then the storage directory is named "20221123", and all the files of the newly generated constructed certificate entries of the current day are stored in the corresponding storage directory file under this storage directory.
[0048] Among them, the storage system can be selected based on the user's needs to store in a specific path of the local hard disk of the proxy system 200 (as a specific example of the target path). Or, considering security or redundancy, an independent external storage system, such as a mobile device (as a specific example of the target device), can be selected for storage.
[0049] In order to prevent the certificate information from being tampered with, in some embodiments of the present application, the method for generating a proxy certificate further includes: performing an operation on the certificate information to obtain an information identification value, and storing the information identification value in the target file.
[0050] For example, in some embodiments of the present application, hash calculations are performed on four items of data in the certificate information, namely the server address, server domain name, constructed certificate generation time, and constructed certificate content, to obtain a hash value (as a specific example of the information identification value). The hash value is then stored as the fifth item of data in the storage directory file.
[0051] In some embodiments of the present application, the method for generating a proxy certificate further includes: when the certificate information for constructing the proxy certificate in the memory is deleted, the certificate information in the target file is also deleted simultaneously.
[0052] For example, in some embodiments of the present application, when the constructed certificate entry in the memory of the proxy system 200 is deleted, the proxy system 200 deletes the corresponding file of the constructed certificate entry from the storage system. The reasons for deleting the certificate entry in the memory of the proxy system 200 include, but are not limited to: manual deletion or cancellation by the administrator, or cache timeout caused by the constructed certificate entry not being called for a long time, and automatic deletion such as when the current system time of the proxy system 200 has exceeded the validity period of the constructed certificate entry.
[0053] For example, if the target file is stored in a specific path local to the proxy system 200, a deletion operation command can be directly issued to delete the relevant certificate entry file. If it is an independent external storage system, a deletion instruction is sent through the selected protocol to delete the specified relevant certificate entry file.
[0054] In addition, in some other embodiments of the present application, the storage system can limit the number of files (i.e., storage directory files) of the constructed certificate entries stored, the occupied space size, or the number of created storage directories according to its own resource conditions. For example, the number of files does not exceed 1 million constructed certificate files; the occupied space size is no more than 10 GB of storage space; the number of created storage directories can be no more than 3000 directories, etc. It can be specifically set according to the actual situation, and the present application does not make specific limitations here.
[0055] For example, the storage system can provide a manual method to allow users to delete files of certificate entries constructed on a specified date (for example, files of certificate entries constructed on a historical date that has expired), or file directories of constructed certificate entries that exceed the number of days of the validity period. In addition, the proxy system 200 can also delete 20% (adjustable) of the stored constructed certificate entry files that are farthest from the current system time in chronological order.
[0056] For another example, the storage system can automatically and regularly check its own storage situation. When the number of files, occupied space size, or number of created directories of the constructed certificate entries exceeds the set threshold conditions, some or all of the files of the constructed certificate entries are automatically deleted, or the directories corresponding to the certificate entries are deleted.
[0057] In some other embodiments of the present application, in the case of selecting an independent external storage system, the proxy system 200 may select different transmission methods (such as HTTP, FTP, FTPS, or HTTPS, etc.) according to conditions such as transmission efficiency requirements or secure transmission requirements, and send the constructed certificate entry file (i.e., certificate information) to the independent external storage system and store it in the corresponding storage directory file.
[0058] It should be noted that FTP is short for File Transfer Protocol, and FTPS is an extended protocol that adds support for transport layer security and Secure Sockets Layer encryption protocol to the commonly used File Transfer Protocol (FTP).
[0059] S220, according to the detection result, determine whether to add the certificate information to the target file, so that after the construction anomaly is recovered during the process of constructing the proxy certificate, the certificate information constructed before the anomaly can be read from the target file to obtain the proxy certificate.
[0060] For example, in some embodiments of the present application, the proxy system 200 based on the detection result of the certificate entry in the memory, confirms whether to add it to the target file to achieve accurate backup storage of the certificate entry.
[0061] In some embodiments of the present application, S210 may include: if the certificate information of the proxy certificate is not stored in the target file, confirm that the detection result is not stored; S220 may include: adding the certificate information to the target file.
[0062] In some embodiments of the present application, the method for generating a proxy certificate further includes: S230 (not shown in the figure), after the construction anomaly is recovered during the process of constructing the proxy certificate, read the certificate information constructed before the anomaly from the target file to obtain the proxy certificate.
[0063] For example, in some embodiments of the present application, during the process of generating a proxy certificate by the proxy system 200, assuming that in the case of a software system failure or a hardware unexpected power-off of the proxy system 200, it will cause an anomaly in the process of constructing the proxy certificate. When the administrator solves the anomaly, when the proxy system 200 resumes normal operation, it can read the constructed certificate entry from the target file and store it in the memory for calling to generate the proxy certificate, without having to construct it from scratch again, saving time costs.
[0064] The implementation process of S230 is described below by way of example.
[0065] In some embodiments of the present application, S230 may include:
[0066] S231. Read the certificate information to be verified and the information identification value from the target file in chronological order.
[0067] For example, in some embodiments of the present application, when the proxy system 200 obtains the file for constructing the certificate entry from the storage system, it will preferentially obtain the file of the certificate entry to be verified in the directory closest to the current time of the proxy system and the previously calculated fifth data hash value, and then sequentially obtain all the files of the certificate entries to be verified in chronological order.
[0068] S232. If it is confirmed that the certificate information to be verified is valid information, then use the certificate information to be verified as the certificate information, and construct the proxy certificate based on the certificate information.
[0069] For example, in some embodiments of the present application, in order to ensure that the file for constructing the certificate entry obtained is an accurate and valid file, it is necessary to perform a valid verification on the obtained file of the certificate entry to be verified. After the verification passes, the file of the certificate entry to be verified is stored in the memory of the proxy system 200 as the file for constructing the certificate entry, and continue to construct other certificate representations of the proxy certificate until the proxy certificate is constructed.
[0070] In some embodiments of the present application, S232 may further include: performing an operation on the certificate information to be verified to obtain a verification identification value; when it is confirmed that the verification identification value is the same as the information identification value, then the certificate information to be verified is valid information.
[0071] For example, in some embodiments of the present application, view the content of the file of the certificate entry to be verified, perform a hash calculation on the four items of data: the server address, server domain name, construction certificate generation time, and construction certificate content of the content, to obtain a verification hash value (a specific example of the verification identification value). Compare the verification hash value with the fifth data hash value. If they are the same, it is confirmed as valid information, so as to ensure that there is no deviation or tampering in the content of the file of the certificate entry to be verified during storage and transmission.
[0072] In some embodiments of the present application, S232 may further include: confirming that the memory size of the certificate information to be verified does not exceed the set memory threshold, and / or confirming that the reading time of the certificate information to be verified is within the preset time threshold.
[0073] For example, in some embodiments of the present application, the proxy system 200 may confirm the number and / or time length of the files of the certificate entries to be verified. For example, during the process of reading the files of the certificate entries to be verified, if it is found that the set number limit of the certificate entries is not exceeded (that is, the memory size of the certificate information to be verified does not exceed the set memory threshold), it indicates that the read information is valid. Or, check the difference between the timestamp of the constructed certificate (as a specific example of the generation time of the constructed certificate) and the current system time of the proxy system 200. If it does not exceed the set time length (as a specific example of the preset time threshold), it indicates that the read information is valid. If the set time length is exceeded, that is, the file of the certificate entry to be verified was generated a long time ago, then the reading of this certificate entry is abandoned. In some other embodiments of the present application, the above-mentioned number limit and time length limit of the certificate entries may also be used together as the conditions for determining whether the file of the certificate entry to be verified is valid. The embodiments of the present application are not limited thereto.
[0074] For example, as an example, the proxy system 200 sets a certificate entry number limit (e.g., 100,000) or a set time length (e.g., limited to not exceeding 24 hours from the current system time). During the reading process, if it is found that 100,000 constructed certificate entries have been restored, then when performing the file restoration process for the 100,001st certificate entry, the timestamp of this certificate file (that is, the generation time of the constructed certificate) will be viewed and the difference will be calculated with the current system time of the proxy system. If the calculation result is less than 86,400 seconds (that is, the file of this constructed certificate entry was generated within 24 hours), it should be retained. If the calculation result is greater than 86,400 seconds (that is, the file of this constructed certificate entry was generated more than 24 hours ago), then the content will be discarded.
[0075] In some other embodiments of the present application, the proxy system 200 may also view the constructed certificate content in the file of the certificate entry to be verified and confirm the expiration date of the constructed certificate content. Compare the expiration date of the constructed certificate content with the current system time of the proxy system. If the expiration date of the constructed certificate content is earlier than the current system time of the proxy system, it indicates that this constructed certificate has expired, and the restoration of this certificate entry will be abandoned. For example, the expiration date of the constructed certificate content is 2022.11.03.12:00, and the current system time is 2022.11.04.12:00, then the certificate content has expired and does not need to be read.
[0076] The following will Figure 3 exemplarily elaborate on the specific implementation process of generating proxy certificates provided by some embodiments of the present application.
[0077] Please refer to the appendix Figure 3 , Figure 3A flowchart of a method for generating a proxy certificate provided for some embodiments of the present application.
[0078] The above process will be described exemplarily below.
[0079] S310. Obtain the server certificate of the server 300.
[0080] For example, as a specific example of the present application, when the proxy system 200 is running normally, it processes the encrypted traffic requests sent by the client 100. The website URL of the server 300 accessed by the client 100 is https: / / eku - test.test.com. The proxy system 100 obtains the website certificate (as an example of the server certificate) of the website "eku - test.test.com" and the website address, such as: 1.1.1.1.
[0081] S320. Generate a proxy certificate corresponding to the server - side certificate.
[0082] S330. Regularly detect whether the certificate information for constructing the proxy certificate in the memory is stored in the target file. If so, execute S350; otherwise, execute S340.
[0083] For example, as a specific example of the present application, the proxy system 200 constructs a proxy certificate using the private key stored locally, generates a constructed certificate entry (as a specific example of the certificate information), and stores it in the memory. The proxy system 200 regularly detects whether the constructed certificate entry is stored in the target file of the storage system. The proxy system 200 checks the constructed certificate entry in the memory at a certain time interval, such as: one hour, and compares it with the file on the storage system to confirm whether the constructed certificate entry is stored in the target file of the storage system.
[0084] S340. Add the certificate information to the target file and perform an operation on the certificate information to obtain an information identification value.
[0085] For example, as a specific example of the present application, if the constructed certificate entry is not on the target file of the storage system, then write the constructed certificate entry. The written content includes: server address, server domain name, constructed certificate generation time (timestamp), and constructed certificate content. And calculate the hash value of these four pieces of information.
[0086] S350. Determine whether the proxy system 200 has an exception. If so, execute 360; otherwise, return to S320.
[0087] S360. When the proxy system 200 recovers from the abnormal state to the normal state, read the certificate information constructed before the exception from the target file to obtain the proxy certificate.
[0088] For example, as a specific example of the present application, the proxy system 200 is interrupted in the process of generating a proxy certificate due to an abnormal shutdown of the software system. When the proxy system 200 is restarted, it is necessary to read the constructed certificate table item before the abnormal shutdown from the target file of the storage system. After reading the target file, the constructed certificate table item and the hash value to be verified are obtained. The certificate table item to be verified is calculated to obtain the hash value to be verified. If the hash value to be verified is consistent with the hash value, the certificate table item to be verified is used as the constructed certificate table item, and other items of the constructed proxy certificate are stored in the memory for the proxy system 200 to call and generate the proxy certificate. It should be noted that the method for confirming the validity of the certificate table item to be verified can also be referred to. Figure 2 The number of certificate entries or the setting time length, etc. in the above method embodiment are not described here to avoid repetition.
[0089] Through the above methods for generating proxy certificates provided by some embodiments of the present application, it can be known that the construction certificate information generated by the proxy system 200 is written into the target file of the storage system in a certain format, ensuring that the proxy system 200 can read the data in the target file of the storage system after recovering from the abnormal state, and quickly recover the construction certificate information. After the proxy system 200 recovers from the abnormal state, the construction certificate table items before the abnormal state can be quickly recovered, improving the efficiency of generating proxy certificates, thereby improving the efficiency and effect of traffic processing in the network.
[0090] Please refer to Figure 4 , Figure 4 The block diagram of the composition of the device for generating a proxy certificate provided by some embodiments of the present application is shown. It should be understood that the device for generating a proxy certificate corresponds to the above method embodiment and can perform each step involved in the above method embodiment. The specific functions of the device for generating a proxy certificate can be found in the description above. To avoid repetition, the detailed description is appropriately omitted here.
[0091] Figure 4 The device for generating a proxy certificate includes at least one software function module that can be stored in a memory in the form of software or firmware or solidified in the device for generating a proxy certificate. The device for generating a proxy certificate includes: a detection module 410, which is configured to periodically detect whether the certificate information for constructing the proxy certificate in the memory is stored in a target file during the process of generating a proxy certificate corresponding to the server-side certificate, and obtain a detection result, wherein the certificate information includes: a server address, a server domain name, a construction certificate generation time, and a construction certificate content; a confirmation module 420, which is configured to determine whether to add the certificate information to the target file based on the detection result, so that after recovery from a construction anomaly in the process of constructing the proxy certificate, the certificate information constructed before the anomaly is read from the target file to obtain the proxy certificate.
[0092] In some embodiments of the present application, the detection module 410 is configured to confirm that the detection result is not stored if the certificate information of the proxy certificate is not stored in the target file; the confirmation module 420 is configured to add the certificate information to the target file.
[0093] In some embodiments of the present application, before the detection module 410, the apparatus for generating a proxy certificate further includes a creation module (not shown in the figure), which is configured to: create the target file, where the target file is stored in a target path or a target device.
[0094] In some embodiments of the present application, the creation module is configured to perform an operation on the certificate information to obtain an information identification value, and store the information identification value in the target file.
[0095] In some embodiments of the present application, the apparatus for generating a proxy certificate further includes a deletion module (not shown in the figure), which is configured to delete the certificate information in the target file when the certificate information for constructing the proxy certificate in the memory is deleted.
[0096] In some embodiments of the present application, the apparatus for generating a proxy certificate further includes a reading module (not shown in the figure), which is configured to read the certificate information to be verified and the information identification value from the target file in chronological order; if it is confirmed that the certificate information to be verified is valid information, then use the certificate information to be verified as the certificate information, and construct the proxy certificate based on the certificate information.
[0097] In some embodiments of the present application, the reading module is configured to perform an operation on the certificate information to be verified to obtain a verification identification value; if it is confirmed that the verification identification value is the same as the information identification value, then the certificate information to be verified is valid information.
[0098] In some embodiments of the present application, the reading module is configured to confirm that the memory size of the certificate information to be verified does not exceed a set memory threshold, and / or confirm that the reading time of the certificate information to be verified is within a preset time threshold.
[0099] Some embodiments of the present application further provide a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the operations corresponding to any of the methods provided in the above embodiments can be implemented.
[0100] Some embodiments of the present application further provide a computer program product, the computer program product includes a computer program, wherein when the computer program is executed by a processor, the operations corresponding to any of the methods provided in the above embodiments can be implemented.
[0101] As Figure 5 shown in the figure, some embodiments of the present application provide an electronic device 500, which includes: a memory 510, a processor 520, and a computer program stored on the memory 510 and executable on the processor 520. When the processor 520 reads the program from the memory 510 through a bus 530 and executes the program, it can implement the method of any of the above embodiments.
[0102] The processor 520 can process digital signals and can include various computing architectures. For example, a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements a combination of multiple instruction sets. In some examples, the processor 520 can be a microprocessor.
[0103] The memory 510 can be used to store instructions executed by the processor 520 or data related to the execution of the instructions. These instructions and / or data can include code for implementing some or all of the functions of one or more modules described in the embodiments of the present application. The processor 520 of the present disclosure embodiment can be used to execute the instructions in the memory 510 to implement the method shown above. The memory 510 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory, or other memories well known to those skilled in the art.
[0104] The above description is only for the embodiments of the present application and is not intended to limit the protection scope of the present application. For those skilled in the art, the present application can have various changes and modifications. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application shall be included in the protection scope of the present application. It should be noted that similar reference numerals and letters indicate similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings.
[0105] The above description is only for the specific implementation manners of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or replacements, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
[0106] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent in such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the said element.
Claims
1. A method for generating a proxy certificate, characterized in that, it includes: During the process of generating a proxy certificate corresponding to the server - side certificate, regularly detect whether the certificate information for constructing the proxy certificate in the memory is stored in a target file, and obtain the detection result, where the certificate information includes: server address, server domain name, construction certificate generation time, and construction certificate content; According to the detection result, determine whether to add the certificate information to the target file, so that when a construction exception occurs during the process of constructing the proxy certificate, after the exception is recovered, read the certificate information constructed before the exception from the target file to obtain the proxy certificate.
2. The method according to claim 1, characterized in that, The step of regularly detecting whether the certificate information for constructing the proxy certificate is stored in the target file and obtaining the detection result includes: If the certificate information for constructing the proxy certificate is not stored in the target file, confirm that the detection result is not stored; The step of determining whether to add the certificate information to the target file according to the detection result includes: Adding the certificate information to the target file.
3. The method according to claim 1 or 2, characterized in that, Before the step of regularly detecting whether the certificate information for constructing the proxy certificate is stored in the target file, the method further includes: Create the target file, where the target file is stored in a target path or a target device.
4. The method according to claim 1 or 2, characterized in that, The method further includes: Perform an operation on the certificate information to obtain an information identification value, and store the information identification value in the target file.
5. The method according to claim 2, characterized in that, The method further includes: When the certificate information for constructing the proxy certificate in the memory is deleted, simultaneously delete the certificate information in the target file.
6. The method according to claim 4, characterized in that, The step of reading the certificate information constructed before the exception from the target file to obtain the proxy certificate includes: Read the certificate information to be verified and the information identification value from the target file in chronological order; If it is confirmed that the certificate information to be verified is valid information, then use the certificate information to be verified as the certificate information, and construct the proxy certificate based on the certificate information.
7. The method according to claim 6, characterized in that, The step of confirming that the certificate information to be verified is valid information includes: Perform an operation on the certificate information to be verified to obtain a verification identification value; If it is confirmed that the verification identification value is the same as the information identification value, then the certificate information to be verified is valid information.
8. The method according to claim 7, characterized in that, Before the step of confirming that the certificate information to be verified is valid information, the method further includes: Confirm that the memory size of the certificate information to be verified does not exceed a set memory threshold, and / or confirm that the reading time of the certificate information to be verified is within a preset time threshold.
9. An apparatus for generating a proxy certificate, characterized in that, it includes: A detection module, configured to periodically detect during the process of generating a proxy certificate corresponding to a server-side certificate whether the certificate information for constructing the proxy certificate in memory is stored in a target file, and obtain a detection result, where the certificate information includes: a server address, a server domain name, a construction certificate generation time, and a construction certificate content; A confirmation module, configured to determine whether to add the certificate information to the target file according to the detection result, so that when a construction anomaly occurs during the process of constructing the proxy certificate, after the anomaly is recovered, the certificate information constructed before the anomaly is read from the target file to obtain the proxy certificate.
10. A computer-readable storage medium, characterized in that, a computer program is stored on the computer-readable storage medium, where the computer program, when run by a processor, executes the method according to any one of claims 1-8.
11. A computer program product, characterized in that, the computer program product includes a computer program, where the computer program, when run by a processor, executes the method according to any one of claims 1-8.
12. An electronic device, characterized in that, it includes a memory, a processor, and a computer program stored on the memory and running on the processor, where the computer program, when run by the processor, executes the method according to any one of claims 1-8.
Citation Information
Patent Citations
System for monitoring and updating service certificates
CN110225013A
Transparent secure socket layer
US20080263215A1