A method, apparatus, electronic device, and storage medium for managing sensitive credentials.

By managing, generating, and encrypting/decrypting sensitive credentials for the middleware through the DSM system and key management system, the problem of high risk of middleware credential leakage is solved, and secure credential management and efficient connection without human intervention are achieved.

CN116319001BActive Publication Date: 2026-03-13BEIJING QIYI CENTURY SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-03-20
Publication Date
2026-03-13

AI Technical Summary

Technical Problem

In existing technologies, sensitive credentials in middleware are managed through hard-coding or plaintext configuration, which leads to a high risk of sensitive information leakage and fails to effectively protect sensitive information.

Method used

By receiving middleware information through the DSM system, completing configuration information registration, and generating sensitive credentials, the business server does not need to manage them manually. The DSM system and key management system are used to encrypt and decrypt sensitive credentials and manage policies, reducing the risk of leakage.

Benefits of technology

It enables the management of sensitive credentials without human intervention, reduces the risk of sensitive information leakage, and improves the security and management efficiency of middleware credentials.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116319001B_ABST
    Figure CN116319001B_ABST
Patent Text Reader

Abstract

This application relates to a sensitive credential management method, apparatus, electronic device, and storage medium. The method, applied to a DSM system, includes: receiving middleware information of middleware to be hosted from a business server; registering the middleware's configuration information based on the middleware information; establishing a connection with the middleware based on the middleware's configuration information; generating sensitive credentials for the middleware based on the middleware's configuration information in response to an application request from the business server; and sending a successful application identifier to the business server so that the business server knows that sensitive credentials for the middleware have been generated based on the identifier; and sending the sensitive credentials for the middleware in response to a retrieval request from the business server so that the business server can connect to the middleware based on the sensitive credentials. This application manages sensitive credentials through the DSM system, preventing anyone from obtaining the plaintext of sensitive credentials and reducing the risk of sensitive credential leakage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security, and in particular to a method, apparatus, electronic device and storage medium for managing sensitive credentials. Background Technology

[0002] With the rapid development and widespread adoption of the internet and mobile internet, internet applications have become the primary means for individuals and businesses to obtain and disseminate information. While the information sharing provided by internet applications brings convenience to people's lives, it also increases the risk of sensitive information leakage.

[0003] In recent years, incidents of massive sensitive information leaks have continued to occur, causing losses to many individuals and businesses. Sensitive credentials for databases, APIs, and other middleware are among the most critical sensitive information. Currently, sensitive credentials are generally managed by business service providers using hard-coding or plaintext configuration. These methods directly expose sensitive credentials in the code, and since business service providers have extensive access permissions, the risk of sensitive information leakage is very high. Summary of the Invention

[0004] In order to solve the above-mentioned technical problems, or at least partially solve the above-mentioned technical problems, this application provides a sensitive credential management method, apparatus, electronic device and storage medium.

[0005] Firstly, this application provides a sensitive credential management method applied to a DSM system, including:

[0006] Receive middleware information of middleware to be hosted sent by the business server, complete the registration of the middleware configuration information based on the middleware information, and establish a connection with the middleware based on the middleware configuration information;

[0007] In response to the application request sent by the business server, a sensitive credential for the middleware is generated based on the configuration information of the middleware, and an application success identifier is sent to the business server so that the business server knows that the sensitive credential for the middleware has been generated based on the identifier.

[0008] In response to an acquisition request sent by the business server, the sensitive credentials of the middleware are sent so that the business server can connect to the middleware based on the sensitive credentials of the middleware.

[0009] Secondly, this application provides a sensitive credential management method applied to a business server, including:

[0010] The middleware information of the middleware to be hosted is sent to the DSM system, so that the DSM system can complete the registration of the middleware's configuration information based on the middleware information of the middleware to be hosted, and establish a connection with the middleware based on the middleware's configuration information.

[0011] Send an application request to the DSM system so that the DSM system generates the middleware's sensitive credentials based on the middleware's configuration information and sends an application success identifier to the business server;

[0012] Receive a successful application identifier sent by the DSM system, and based on the identifier, know that the DSM system has generated the sensitive credentials for the middleware;

[0013] Send an acquisition request to the DSM system, receive the sensitive credentials of the middleware sent by the DSM system, and connect to the middleware based on the sensitive credentials of the middleware.

[0014] Thirdly, a sensitive credential management device is provided for use in a DSM system, comprising: a registration module, a sensitive credential generation module, an identifier sending module, and a sensitive credential sending module, wherein...

[0015] The registration module is used to receive middleware information of middleware hosted by the business server, complete the registration of the middleware's configuration information based on the middleware information, and establish a connection with the middleware based on the middleware's configuration information.

[0016] The sensitive credential generation module is used to generate sensitive credentials for the middleware based on the configuration information of the middleware in response to an application request sent by the business server.

[0017] The identifier sending module is used to send an identifier indicating successful application to the business server, so that the business server can know the information that the sensitive credentials of the middleware have been generated based on the identifier;

[0018] The sensitive credential sending module is used to send the sensitive credential of the middleware in response to the acquisition request sent by the business server, so that the business server can connect to the middleware based on the sensitive credential of the middleware.

[0019] Fourthly, a sensitive credential management device is provided, applied to a business server, comprising: an information sending module, an application sending module, an identifier receiving module, and a sensitive credential acquisition module, wherein...

[0020] The information sending module is used to send the middleware information of the middleware to be hosted to the DSM system, so that the DSM system can complete the registration of the middleware's configuration information based on the middleware information of the middleware to be hosted, and establish a connection with the middleware based on the middleware's configuration information.

[0021] The application sending module is used to send an application request to the DSM system, so that the DSM system generates the sensitive credentials of the middleware based on the middleware's configuration information, and sends an application success identifier to the business server;

[0022] The identifier receiving module is used to receive an identifier indicating successful application sent by the DSM system, and to know from the identifier that the DSM system has generated the sensitive credentials of the middleware;

[0023] The sensitive credential acquisition module is used to send an acquisition request to the DSM system, receive the sensitive credential of the middleware, and connect to the middleware based on the sensitive credential of the middleware.

[0024] Fifthly, an electronic device is provided, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory communicate with each other through the communication bus;

[0025] Memory, used to store computer programs;

[0026] When a processor executes a program stored in memory, it implements the steps of the sensitive credential management method described in any embodiment of the first aspect or the steps of the sensitive credential management method described in the second aspect.

[0027] In a sixth aspect, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps of the sensitive credential management method as described in any embodiment of the first aspect or the steps of the sensitive credential management method as described in the second aspect.

[0028] The technical solutions provided in this application have the following advantages compared with the prior art:

[0029] In this embodiment, the DSM system receives middleware information from a business server regarding middleware to be hosted. Based on this information, it registers the middleware's configuration information and establishes a connection with the middleware. In response to an application request from the business server, it generates sensitive credentials for the middleware based on the configuration information and sends a successful application identifier to the business server, allowing the business server to recognize the generated sensitive credentials. In response to a request from the business server, it sends the sensitive credentials to the middleware, enabling the business server to connect to the middleware based on these credentials. The business service provider no longer needs to manually manage sensitive credentials; it only needs to host the middleware to be proxied on the DSM system to obtain the sensitive credentials and connect to the middleware. This method manages the sensitive credentials of the middleware through the DSM system, without human intervention, reducing the risk of sensitive credential leakage. Attached Figure Description

[0030] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0031] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, for those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0032] Figure 1 This is a diagram illustrating the existing management of sensitive credentials.

[0033] Figure 2 This is a schematic diagram illustrating the management of sensitive credentials as provided in an embodiment of this application.

[0034] Figure 3 A flowchart illustrating a sensitive credential management method provided in this application embodiment;

[0035] Figure 4 This is a schematic diagram illustrating another method for managing sensitive credentials, provided as an embodiment of this application.

[0036] Figure 5 A flowchart illustrating another sensitive credential management method provided in this application embodiment;

[0037] Figure 6 A flowchart illustrating another sensitive credential management method provided in this application embodiment;

[0038] Figure 7A schematic diagram of a sensitive credential management device provided in an embodiment of this application;

[0039] Figure 8 A schematic diagram of a sensitive credential management device provided in an embodiment of this application;

[0040] Figure 9 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0041] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0042] First, some nouns or terms that appear in the description of the embodiments of this application shall be interpreted as follows:

[0043] SDK (Software Development Kit): A software development kit is a collection of development tools used by software engineers when building application software for specific software packages, software frameworks, hardware systems, operating systems, etc.

[0044] With the rapid development and widespread adoption of the internet and mobile internet, internet applications have become the primary means for individuals and businesses to obtain and disseminate information. While the information sharing provided by internet applications brings convenience to people's lives, it also increases the risk of sensitive information leakage.

[0045] Massive leaks of sensitive information continue to occur, causing losses to many individuals and businesses. Sensitive credentials for databases, APIs, and other middleware are among the most critical types of sensitive information. It's important to note that middleware is a type of software that sits between application systems and system software. It uses the basic services provided by system software to connect various parts of application systems or different applications on the network, achieving resource and function sharing. Understandably, the leakage of sensitive credentials in middleware will lead to the leakage of information stored within the middleware, causing significant losses to individuals and businesses.

[0046] Figure 1 This illustrates an existing method for managing sensitive credentials. For example... Figure 1As shown, the sensitive credentials of various middlewares are generally managed by the business server using hard-coded or plaintext configuration. The business server connects to the middleware through the sensitive credentials of various middlewares, obtains access permissions to the middleware, and then processes the information stored in the middleware.

[0047] However, hard-coding or plaintext configuration exposes the middleware's sensitive credentials directly in the code. Since many people have access to the business server, the risk of leakage of the middleware's sensitive credentials is very high.

[0048] In view of the above problems, one embodiment of this application provides a sensitive credential management method. Figure 2 This diagram illustrates the management of sensitive credentials according to an embodiment of this application. Figure 2 As shown in the embodiment of this application, the business server sends the middleware information of the middleware to be hosted to the DSM dynamic sensitive credential management system, so that the DSM system can complete the registration of the middleware configuration information based on the middleware information, establish a connection with the middleware, and then obtain the information stored in the middleware.

[0049] The business server initiates a business service that establishes a connection with the middleware and sends an application request to the DSM system. The DSM system receives the application request and generates sensitive credentials for the middleware based on the middleware's configuration information. After generating the sensitive credentials, the DSM system sends a successful application notification to the business server, enabling the business server to be aware that the sensitive credentials for the middleware have been generated.

[0050] Upon receiving the successful application notification, the business server can choose to immediately retrieve the middleware's sensitive credentials, or retrieve them according to its own needs. The business server sends a retrieval request to the DSM system, which receives the request and sends the middleware's sensitive credentials to the business server. The business server then establishes a connection with the middleware based on the middleware's sensitive credentials.

[0051] It is understood that the embodiments of this application manage the sensitive credentials of the middleware through the DSM system. Compared with the existing method of managing the sensitive credentials of the middleware through the business server, this management method does not allow natural persons to access the sensitive credentials of the middleware, thus reducing the risk of sensitive credentials being leaked.

[0052] Figure 3 A flowchart illustrating a sensitive credential management method according to an embodiment of this application is shown below. Figure 3 This application provides a detailed description of a sensitive credential management method based on embodiments.

[0053] A sensitive credential management method, such as Figure 3 As shown, it is applied to the DSM system and includes:

[0054] S301. Receive middleware information of the middleware to be managed sent by the business server, complete the registration of the middleware configuration information based on the middleware information, and establish a connection with the middleware based on the middleware configuration information.

[0055] The middleware information can be a unique identifier for the middleware; for example, the middleware information can be the name of the middleware.

[0056] The DSM system receives a unique identifier for the middleware to be hosted from the business server, identifies the middleware, and registers its configuration information. It's important to note that the middleware's configuration information serves as the bridge between the DSM system and the middleware. For example, when the middleware is a database, its configuration information includes the database name, table names, etc. The DSM system establishes a connection with the middleware based on this configuration information. Once the connection is established, the DSM system gains access to the middleware and can retrieve information stored within it.

[0057] S302. In response to the application request sent by the business server, generate the sensitive credentials of the middleware based on the configuration information of the middleware, and send an application success identifier to the business server so that the business server knows that the sensitive credentials of the middleware have been generated based on the identifier.

[0058] When a business service starts, the business server can send a request to the DSM system via the SDK to request sensitive credentials for the middleware. This means the business service can involve the business server establishing a connection with the middleware and retrieving information stored within it.

[0059] It should be noted that the business server can dynamically send sensitive credentials for middleware requesting read / write separation to the DSM system via the SDK as needed. For example, the business server can send sensitive credentials for middleware requesting read permissions to the DSM system via the SDK, or send sensitive credentials for middleware requesting write permissions to the DSM system via the SDK, or send sensitive credentials for two middleware requesting separate read and write permissions to the DSM system via the SDK.

[0060] Sensitive credentials typically include the account and password for accessing the middleware.

[0061] The DSM system generates sensitive credentials for the middleware based on its configuration information. After generating these credentials, the DSM system returns a successful request notification to the business server SDK. For example, the business server displays a pop-up window stating "Sensitive credentials generated." From this notification, the business server knows that the DSM system has generated the sensitive credentials, and therefore, the business server SDK can retrieve them.

[0062] S303. In response to the acquisition request sent by the business server, send the sensitive credentials of the middleware so that the business server can connect to the middleware based on the sensitive credentials of the middleware.

[0063] It should be noted that after the business server receives the successful application notification, it can choose to obtain the middleware's sensitive credentials immediately, or it can choose to obtain the middleware's sensitive credentials at a time according to its own needs.

[0064] The DSM system receives a request from the business server SDK and sends the middleware's sensitive credentials to the business server SDK, enabling the business server SDK to generate a connection pool based on the middleware's sensitive credentials, connect to the middleware, and thus complete the business service.

[0065] Preferably, the DSM system securely transmits data to the business server SDK via an HTTPS transmission channel, avoiding man-in-the-middle attacks caused by network communication and further reducing the risk of leakage of sensitive credentials of the middleware.

[0066] In one specific embodiment, the DSM system can receive and execute sensitive credential policies set by the business server. For example, the sensitive credential policy may include: renewing sensitive credentials, discarding sensitive credentials, and rotating sensitive credentials.

[0067] It is understandable that the sensitive credentials received by the business server have a limited usage time. If the business server wants to continue using the sensitive credentials before the usage time limit is reached, it can send a sensitive credential renewal policy to the DSM system. The DSM receives the policy and executes it to extend the usage time of the sensitive credentials.

[0068] Of course, the business server can also stop using the sensitive credential before the usage time limit is reached. The business server can send a policy to the DSM system to discard the sensitive credential. The DSM receives the policy and executes it to discard the sensitive credential.

[0069] The business server can also send a round-robin sensitive credential policy to the DSM system. The DSM system receives the round-robin sensitive credential policy, regenerates the sensitive credentials for the middleware periodically, and responds to the business server's request to obtain them by periodically sending new sensitive credentials to the business server.

[0070] In this embodiment, the DSM system receives middleware information from a business server regarding middleware to be hosted. Based on this middleware information, the system registers the middleware's configuration information and establishes a connection with the middleware based on the configuration information. In response to an application request from the business server, the system generates sensitive credentials for the middleware based on the middleware's configuration information and sends a successful application identifier to the business server, enabling the business server to recognize the generated sensitive credentials. In response to an acquisition request from the business server, the system sends the sensitive credentials for the middleware, allowing the business server to connect to the middleware based on these credentials. The business service provider no longer needs to manually manage sensitive credentials; it only needs to host the middleware to be proxied on the DSM system to obtain the middleware's sensitive credentials through DSM and then connect to the middleware using these credentials. This method manages the middleware's sensitive credentials through the DSM system, without human intervention, reducing the risk of sensitive credentials leakage.

[0071] Another embodiment of this application provides a method for managing sensitive credentials. Figure 4 This diagram illustrates the management of sensitive credentials according to an embodiment of this application. For example... Figure 4 As shown in this embodiment, the DSM system sends a join request to the key management system. Upon receiving the join request, the key management system sends identification credentials to the DSM system. The DSM system can then join the key management system based on these identification credentials.

[0072] As mentioned above, the business server sends the middleware information of the middleware to be hosted to the DSM dynamic sensitive credential management system, enabling the DSM system to register the middleware configuration information based on the middleware information, establish a connection with the middleware, and then obtain the information stored in the middleware.

[0073] The business server initiates a business service that establishes a connection with the middleware and sends a request to the DSM system. The DSM system receives the request and generates sensitive credentials for the middleware based on its configuration information. The DSM system then calls the key management system to encrypt the generated sensitive credentials, obtaining the encrypted sensitive credentials for the middleware. The DSM system stores the encrypted sensitive credentials for the middleware on disk for repeated access by the business server.

[0074] The DSM sends a successful request notification to the business server, informing the server that sensitive credentials for the middleware have been generated. Upon receiving the notification, the business server can choose to immediately retrieve the sensitive credentials for the middleware, or retrieve them according to its own needs.

[0075] The business server sends a request to the DSM system. Upon receiving the request, the DSM system calls the key management system to decrypt the encrypted sensitive credentials of the middleware stored on disk, thus obtaining the middleware's sensitive credentials. The DSM system then sends the middleware's sensitive credentials to the business server, which connects to the middleware based on these credentials.

[0076] It is understood that, based on the aforementioned management of sensitive credentials of the middleware through the DSM system, this application embodiment calls the key management system to perform encryption and decryption operations on the sensitive credentials of the middleware, thereby realizing the encryption and persistence of the sensitive credentials of the middleware, eliminating the risk of leakage of plaintext to disk, and further reducing the risk of leakage of sensitive credentials of the middleware.

[0077] Figure 5 A flowchart illustrating a sensitive credential management method according to an embodiment of this application is shown below. Figure 5 This application provides a detailed description of a sensitive data management method based on an embodiment.

[0078] A sensitive credential management method, such as Figure 5 As shown, it is applied to the DSM system and includes:

[0079] S501, Send a join request to the key management system.

[0080] To further reduce the risk of sensitive credentials being leaked, encryption and decryption of sensitive credentials in the middleware can be implemented. It is understood that encryption and decryption of sensitive credentials can be performed through a key management system. The DSM system initiates a request to join the key management system.

[0081] It should be noted that, relying on the hardware-level cloud encryption of the KMS key management system, DSM can encrypt and persist the metadata such as sensitive credentials of all middleware hosted, eliminating the risk of leakage due to plaintext storage.

[0082] S502: Receive the identity verification credential sent by the key management system in response to the join request, and join the key management system based on the identity verification credential.

[0083] The key management system receives a join request from the DSM system and sends identification credentials to the DSM system. For example, the identification credentials may include: AK, SK, and CMK. AK, or Access.Key.Id, is the access key, which the DSM system uses to access the key management system; SK, or Secret.Access.Id, is the signature key, which the DSM system sends to the key management system for signature verification, establishing a connection between the two systems; CMK is the root key, from which data keys can be derived. It should be noted that the DSM system receives the root key's KId and stores it in a configuration file. When it needs to generate data keys online using the key management platform, it sends the KId to the key management system. The key management system receives the KId, and the CMK derives the data key, which is used for encryption and decryption of sensitive credentials in the middleware.

[0084] S503: Receive middleware information of the middleware to be managed sent by the business server, complete the registration of the middleware configuration information based on the middleware information, and establish a connection with the middleware based on the middleware configuration information.

[0085] It can be understood that the description of step S503 is the same as the description of step S301 above, and will not be repeated here.

[0086] S504. In response to the application request sent by the business server, generate sensitive credentials for the middleware based on the middleware configuration information.

[0087] It can be understood that the description of step S504 is the same as the description of the same part of step S302 above, and will not be repeated here.

[0088] S505. Use the key management system to encrypt the sensitive credentials of the middleware to obtain the encrypted sensitive credentials of the middleware.

[0089] After the DSM system generates the sensitive credentials for the middleware, the DSM system will also call the key management system to encrypt the sensitive credentials for the middleware, thereby obtaining the encrypted sensitive credentials for the middleware.

[0090] It is understandable that this implementation method further improves the security of the middleware's sensitive credentials by calling the key management system to encrypt them, and greatly reduces the risk of leakage of the middleware's sensitive credentials.

[0091] S506. Store the middleware's encrypted credentials on the disk.

[0092] After obtaining the encrypted sensitive credentials of the middleware, the DSM system stores them on the disk so that the business server can request the middleware's sensitive credentials multiple times.

[0093] S507. Send a successful application identifier to the business server so that the business server can know that middleware sensitive credentials have been generated based on the identifier.

[0094] It can be understood that the description of step S507 is the same as the description of the same part of step S302 above, and will not be repeated here.

[0095] S508. In response to the acquisition request sent by the business server, the key management system is used to decrypt the encrypted sensitive credentials of the middleware and obtain the sensitive credentials of the middleware.

[0096] After receiving the retrieval request from the business server, the DSM system retrieves the encrypted sensitive credentials of the middleware stored on the disk and decrypts them through the key management system to obtain the sensitive credentials of the middleware.

[0097] Understandably, by encrypting and decrypting the sensitive credentials of the middleware, the security of the sensitive credentials of the middleware is further guaranteed.

[0098] S509. Send the middleware's sensitive credentials so that the business server can connect to the middleware based on the middleware's sensitive credentials.

[0099] It can be understood that the description of step S509 is the same as the description of the same part of step S303 above, and will not be repeated here.

[0100] In one specific embodiment, step S505 includes:

[0101] S5051, Receive the data key generated by the key management system.

[0102] The DSM system generates sensitive credentials for the middleware and calls the key management system. The key management system generates a data key based on the sensitive credentials from the middleware and sends it to the DSM system.

[0103] S5052. Use data keys to encrypt sensitive credentials of the middleware.

[0104] DSM receives the data key and uses it to encrypt the middleware's sensitive credentials, thus obtaining the middleware's encrypted sensitive credentials.

[0105] In one specific embodiment, step S508 includes:

[0106] S5081. Use the data key to decrypt the encrypted sensitive credentials of the middleware.

[0107] The DSM system receives a retrieval request from the business server SDK and retrieves the middleware's encrypted sensitive credentials from the disk. It then decrypts the encrypted sensitive credentials using the previously received data key to obtain the middleware's sensitive credentials.

[0108] In one specific embodiment, the DSM system can receive and execute sensitive credential policies set by the business server. For example, the sensitive credential policy may include: renewing sensitive credentials, discarding sensitive credentials, and rotating sensitive credentials.

[0109] It is understandable that the sensitive credentials received by the business server have a limited usage time. If the business server wants to continue using the sensitive credentials before the usage time limit is reached, it can send a sensitive credential renewal policy to the DSM system. The DSM receives the policy and executes it to extend the usage time of the sensitive credentials.

[0110] Of course, the business server can also stop using the sensitive credential before the usage time limit is reached. The business server can send a policy to the DSM system to discard the sensitive credential. The DSM receives the policy and executes it to discard the sensitive credential.

[0111] The business server can also send a round-robin sensitive credential policy to the DSM system. The DSM system receives the round-robin sensitive credential policy, regenerates the sensitive credentials for the middleware periodically, and responds to the business server's request to obtain them by periodically sending new sensitive credentials to the business server.

[0112] It should be noted that in the embodiments of this application, steps S501-S502 can be executed after steps S503-S504; step S506 can be executed after step S507, and no specific restrictions are made here.

[0113] It should be noted that the sensitive credential management method provided in this application embodiment is applicable to common middleware on the market, as well as custom and uncommon middleware, such as custom business platforms.

[0114] Another embodiment of this application provides a method for managing sensitive credentials. Figure 6 A flowchart illustrating a sensitive credential management method according to an embodiment of this application is shown below. Figure 6 This application provides a detailed description of a sensitive credential management method based on embodiments.

[0115] A sensitive credential management method, such as Figure 6 As shown, it is applied to the DSM system and includes:

[0116] Steps S601-S602. The descriptions of steps S601-S602 are the same as those of steps S501-S502, and will not be repeated here.

[0117] S603: Receive middleware information of the middleware to be managed from the business server.

[0118] The middleware information can be a unique identifier for the middleware; for example, the middleware information can be the name of the middleware.

[0119] The DSM system receives a unique identifier for the middleware to be managed from the business server and identifies the middleware to be managed.

[0120] S604. Determine if the middleware exists in the preset middleware list.

[0121] The preset middleware list consists of middleware whose configuration information has been registered on the DSM system. This application embodiment employs different sensitive credential management methods for middleware registered on the DSM system and middleware not registered on the DSM system.

[0122] The DSM system receives middleware information from the business server and identifies the middleware to be managed. It first needs to determine if the middleware exists in the preset middleware list, i.e., whether the middleware has been registered.

[0123] If the middleware exists in the preset middleware list, that is, the middleware has been registered, proceed to step S605.

[0124] If the middleware does not exist in the preset middleware list, that is, the middleware has not been registered, proceed to step S606.

[0125] S605. Locate the SDK corresponding to the middleware and run the SDK to perform the following steps:

[0126] A connection is established with the middleware based on the middleware's configuration information;

[0127] In response to the application request sent by the business server, a sensitive credential for the middleware is generated based on the configuration information of the middleware, and an application success identifier is sent to the business server so that the business server knows that the sensitive credential for the middleware has been generated based on the identifier.

[0128] In response to an acquisition request sent by the business server, the sensitive credentials of the middleware are sent so that the business server can connect to the middleware based on the sensitive credentials of the middleware.

[0129] It is understandable that if the middleware to be managed exists in the preset middleware list, it means that the middleware to be managed has been registered before. Therefore, the above steps can be performed by running the SDK that was configured beforehand to complete the management of the middleware's sensitive credentials.

[0130] It should be noted that the SDK contains the code to complete the above steps. Directly calling the SDK can manage the sensitive credentials of the middleware, saving time.

[0131] Of course, the middleware to be managed exists in the preset middleware list, or the above steps S501-S509 can be performed through another pre-configured SDK.

[0132] S606. Register the middleware configuration information based on the middleware information, and establish a connection with the middleware based on the middleware configuration information.

[0133] Understandably, the middleware to be managed is not previously in the preset middleware list, meaning it has not been registered on the DSM system. Therefore, the middleware to be managed needs to register its configuration information, and after registration, a connection will be established with the middleware based on that configuration information.

[0134] The DSM system receives a unique identifier for the middleware to be hosted from the business server, identifies the middleware, and registers its configuration information. It's important to note that the middleware's configuration information serves as the bridge between the DSM system and the middleware. For example, when the middleware is a database, its configuration information includes the database name, table names, etc. The DSM system establishes a connection with the middleware based on this configuration information. Once the connection is established, the DSM system gains access to the middleware and can retrieve information stored within it.

[0135] The descriptions of steps S607-S612 are the same as those of steps S504-S509, and will not be repeated here.

[0136] In one specific embodiment, the DSM system can receive and execute sensitive credential policies set by the business server. For example, the sensitive credential policy may include: renewing sensitive credentials, discarding sensitive credentials, and rotating sensitive credentials.

[0137] It is understandable that the sensitive credentials received by the business server have a limited usage time. If the business server wants to continue using the sensitive credentials before the usage time limit is reached, it can send a sensitive credential renewal policy to the DSM system. The DSM receives the policy and executes it to extend the usage time of the sensitive credentials.

[0138] Of course, the business server can also stop using the sensitive credential before the usage time limit is reached. The business server can send a policy to the DSM system to discard the sensitive credential. The DSM receives the policy and executes it to discard the sensitive credential.

[0139] The business server can also send a round-robin sensitive credential policy to the DSM system. The DSM system receives the round-robin sensitive credential policy, regenerates the sensitive credentials for the middleware periodically, and responds to the business server's request to obtain them by periodically sending new sensitive credentials to the business server.

[0140] This application supports the management of sensitive credentials for all middleware. The management of sensitive credentials for middleware that has not been registered on the DSM system adopts the same method as the previous embodiments. For the management of sensitive credentials for middleware that has been registered on the DSM system, the corresponding configured SDK is directly called to run the program. This method saves time while ensuring that the risk of leakage of sensitive credentials of middleware is reduced.

[0141] Another embodiment of this application provides a sensitive credential management method, applied to a business server, including:

[0142] Send the middleware information of the middleware to be managed to the DSM system so that the DSM system can register the middleware's configuration information based on the middleware information of the middleware to be managed and establish a connection with the middleware based on the middleware's configuration information.

[0143] Send an application request to the DSM system so that the DSM system can generate sensitive credentials for the middleware based on the middleware configuration information and send a successful application notification to the business server;

[0144] Receive a successful application identifier sent by the DSM system, and based on the identifier, know that the DSM system has generated sensitive credentials for the middleware;

[0145] Send an acquisition request to the DSM system, receive the sensitive credentials of the middleware sent by the DSM system, and connect to the middleware based on the sensitive credentials of the middleware.

[0146] It is understood that this embodiment describes a sensitive credential management method from the perspective of the business server, and its description is similar to steps S301-S303, so it will not be repeated here.

[0147] According to another aspect of the embodiments of this application, a sensitive credential management device is also provided, such as... Figure 7 As shown, the system applied to the DSM system includes: a registration module 701, a sensitive credential generation module 702, an identifier sending module 703, and a sensitive credential sending module 704, wherein...

[0148] The registration module 701 is used to receive middleware information from the middleware hosted by the business server, register the middleware configuration information based on the middleware information, and establish a connection with the middleware based on the middleware configuration information.

[0149] The sensitive credential generation module 702 is used to generate sensitive credentials for the middleware based on the middleware configuration information in response to the application request sent by the business server.

[0150] The identifier sending module 703 is used to send an identifier indicating successful application to the business server, so that the business server can know the information of the sensitive credentials of the middleware that have been generated based on the identifier;

[0151] The sensitive credential sending module 704 is used to send the middleware's sensitive credentials in response to a request sent by the business server, so that the business server can connect to the middleware based on the middleware's sensitive credentials.

[0152] The modules described above can solve the technical problem of high risk of sensitive credential leakage in middleware in related technologies.

[0153] As an optional embodiment, the device may further include a joining request module, an identity verification credential receiving module, a sensitive credential encryption module, a sensitive credential storage module, and a sensitive credential decryption module, wherein,

[0154] The join request module is used to send join requests to the key management system.

[0155] The identity verification credential receiving module is used to receive the identity verification credential sent by the key management system in response to the join request, and to join the key management system based on the identity verification credential.

[0156] The sensitive credential encryption module is used to encrypt the sensitive credentials of the middleware using the key management system, thereby obtaining the encrypted sensitive credentials of the middleware.

[0157] The sensitive credential storage module is used to store the encrypted sensitive credentials of the middleware on a disk.

[0158] Optionally, the sensitive credential storage module is also used to store the sensitive credentials of the middleware on a disk.

[0159] The sensitive credential decryption module is used to decrypt the encrypted sensitive credentials of the middleware using the key management system, and obtain the sensitive credentials of the middleware.

[0160] As an optional embodiment, the sensitive credential encryption module includes: a data key receiving unit and a data key encryption unit, wherein,

[0161] The data key receiving unit is used to receive data keys generated by the key management system.

[0162] The data key encryption unit is used to encrypt sensitive credentials of the middleware using a data key.

[0163] As an optional embodiment, the sensitive credential decryption module includes: a data key decryption unit.

[0164] The data key decryption unit is used to decrypt the encrypted sensitive credentials of the middleware using the data key.

[0165] As an optional embodiment, the device further includes: a sensitive credential policy receiving module.

[0166] The sensitive credential policy receiving module is used to receive the sensitive credential policies set by the business server and execute the sensitive credential policies.

[0167] The sensitive credential strategies include: renewing sensitive credentials, discarding sensitive credentials, and rotating sensitive credentials.

[0168] As an optional embodiment, the device further includes: a determination module, a first execution module, and a second execution module, wherein,

[0169] The judgment module is used to determine whether the middleware exists in the preset middleware list;

[0170] The first execution module is used to perform the step of registering the configuration information of the middleware based on the middleware information if the result of the judgment module is that the middleware does not exist in the preset middleware list;

[0171] The second execution module is used to find the SDK corresponding to the middleware if the determination module result indicates that the middleware exists in the preset middleware list, and then run the SDK to perform the following steps:

[0172] Establish a connection with the middleware based on the middleware's configuration information;

[0173] In response to the application request sent by the business server, the middleware sensitive credentials are generated based on the middleware configuration information, and an application success identifier is sent to the business server so that the business server can know that the middleware sensitive credentials have been generated based on the identifier.

[0174] In response to a request from the business server, the middleware's sensitive credentials are sent so that the business server can connect to the middleware based on the middleware's sensitive credentials.

[0175] According to another aspect of the embodiments of this application, a sensitive credential management device is also provided, such as... Figure 8 As shown, this is applied to a business server and includes: an information sending module 801, an application sending module 802, an identifier receiving module 803, and a sensitive credential acquisition module 804, wherein...

[0176] The information sending module 801 is used to send the middleware information of the middleware to be managed to the DSM system, so that the DSM system can complete the registration of the middleware configuration information based on the middleware information of the middleware to be managed, and establish a connection with the middleware based on the middleware configuration information.

[0177] The application sending module 802 is used to send an application request to the DSM system so that the DSM system can generate sensitive credentials for the middleware based on the middleware configuration information and send an application success identifier to the business server.

[0178] The identifier receiving module 803 is used to receive the successful application identifier sent by the DSM system, and to know that the DSM system has generated sensitive credentials for the middleware based on the identifier;

[0179] The sensitive credential acquisition module 804 is used to send an acquisition request to the DSM system, receive sensitive credentials from the middleware, and connect to the middleware based on the sensitive credentials of the middleware.

[0180] like Figure 9 As shown, according to another aspect of the embodiments of this application, an electronic device is also provided for implementing the above-described sensitive credential management method, including: as Figure 9 As shown, the electronic device may include: a processor 901, a communication interface 902, a memory 903, and a communication bus 904, wherein the processor 901, the communication interface 902, and the memory 903 communicate with each other through the communication bus 904.

[0181] Memory 903 is used to store computer programs;

[0182] When the processor 901 executes the program stored in the memory 903, it implements the steps of the above method embodiment.

[0183] The bus mentioned in the above electronic devices can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. This bus can be divided into address bus, data bus, control bus, etc. For ease of illustration, only one thick line is used to represent it in the diagram, but this does not mean that there is only one bus or one type of bus.

[0184] The communication interface is used for communication between the aforementioned electronic devices and other devices.

[0185] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0186] The processors mentioned above can be general-purpose processors, including central processing units (CPUs), network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.

[0187] Those skilled in the art will understand that Figure 9 The structure shown is for illustrative purposes only and does not limit the structure of the electronic device described above. For example, the electronic device may also include components that are more... Figure 9 The more or fewer components shown (such as network interfaces, display devices, etc.), or having the same Figure 9 The different configurations shown.

[0188] This application also provides a computer-readable storage medium, which includes a stored program, wherein the program executes the method steps of the above method embodiments when it runs.

[0189] Optionally, in this embodiment, the storage medium may include, but is not limited to, various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.

[0190] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0191] The above description is merely a specific embodiment of the present invention, enabling those skilled in the art to understand or implement the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the invention. Therefore, the present invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A sensitive credential management method applied to a DSM system, characterized in that, The method comprises: receiving middleware information of middleware to be managed sent by a service server, completing registration of configuration information of the middleware based on the middleware information, and establishing a connection with the middleware based on the configuration information of the middleware; in response to an application request sent by the service server, generating sensitive credentials of the middleware based on the configuration information of the middleware, and sending an application success identifier to the service server, so that the service server learns that the sensitive credentials of the middleware have been generated based on the identifier; in response to an acquisition request sent by the service server, sending the sensitive credentials of the middleware, so that the service server connects the middleware based on the sensitive credentials of the middleware; before the receiving of the middleware information of the middleware to be managed sent by the service server, the method further comprises: sending a joining request to a key management system; receiving an identity recognition credential sent by the key management system in response to the joining request, and joining the key management system based on the identity recognition credential; after the generating of the sensitive credentials of the middleware based on the configuration information of the middleware, the method further comprises: encrypting the sensitive credentials of the middleware by using the key management system to obtain encrypted sensitive credentials of the middleware; and storing the encrypted sensitive credentials of the middleware in a disk; before the sending of the sensitive credentials of the middleware, the method comprises: decrypting the encrypted sensitive credentials of the middleware by using the key management system to obtain the sensitive credentials of the middleware.

2. The method of claim 1, wherein, The encrypting of the sensitive credentials of the middleware by using the key management system comprises: receiving a data key generated by the key management system; encrypting the sensitive credentials of the middleware by using the data key.

3. The method of claim 2, wherein, The decrypting of the encrypted sensitive credentials of the middleware by using the key management system comprises: decrypting the encrypted sensitive credentials of the middleware by using the data key.

4. The method of claim 3, wherein, The method further comprises: receiving a sensitive credential policy set by the service server, and executing the sensitive credential policy; wherein the sensitive credential policy comprises: renewing sensitive credentials, discarding sensitive credentials, and rotating sensitive credentials.

5. The method of claim 3, wherein, Before the completing of the registration of the configuration information of the middleware based on the middleware information, the method further comprises: judging whether the middleware exists in a preset middleware list; in a case where the middleware does not exist in the preset middleware list, executing the step of completing the registration of the configuration information of the middleware based on the middleware information.

6. The method of claim 5, wherein, The method further comprises: in a case where the middleware exists in the preset middleware list, finding an SDK corresponding to the middleware, and running the SDK to execute the following steps: establishing a connection with the middleware based on the configuration information of the middleware; in response to an application request sent by the service server, generating sensitive credentials of the middleware based on the configuration information of the middleware, and sending an application success identifier to the service server, so that the service server learns that the sensitive credentials of the middleware have been generated based on the identifier; In response to the acquisition request sent by the service server, the sensitive credential of the middleware is sent, so that the service server connects the middleware based on the sensitive credential of the middleware.

7. A sensitive credential management method applied to a service server, characterized in that, Comprise: The middleware information of the middleware to be hosted is sent to the DSM system, so that the DSM system completes the registration of the configuration information of the middleware based on the middleware information of the middleware to be hosted, and establishes a connection with the middleware based on the configuration information of the middleware; An application request is sent to the DSM system, so that the DSM system generates a sensitive credential of the middleware based on the configuration information of the middleware, and sends an identification of application success to the service server; The identification of application success sent by the DSM system is received, and it is known that the DSM system has generated the sensitive credential of the middleware based on the identification; An acquisition request is sent to the DSM system, and the sensitive credential of the middleware sent by the DSM system is received, and the middleware is connected based on the sensitive credential of the middleware; Before the middleware information of the middleware to be hosted is sent to the DSM system, it further comprises: sending a join request to the key management system; receiving the identity identification credential sent by the key management system in response to the join request, and joining the key management system based on the identity identification credential; After the DSM system generates the sensitive credential of the middleware based on the configuration information of the middleware, it further comprises: encrypting the sensitive credential of the middleware by using the key management system to obtain the encrypted sensitive credential of the middleware; storing the encrypted sensitive credential of the middleware in the disk; Before the sensitive credential of the middleware sent by the DSM system is received, it comprises: decrypting the encrypted sensitive credential of the middleware by using the key management system to obtain the sensitive credential of the middleware.

8. A sensitive credential management apparatus applied to a DSM system, characterized in that, Comprise: The registration module, the sensitive credential generation module, the identification sending module and the sensitive credential sending module, wherein, The registration module is used for receiving the middleware information of the middleware hosted by the service server, completing the registration of the configuration information of the middleware based on the middleware information, and establishing a connection with the middleware based on the configuration information of the middleware; The sensitive credential generation module is used for generating the sensitive credential of the middleware based on the configuration information of the middleware in response to the application request sent by the service server; The identification sending module is used for sending an identification of application success to the service server, so that the service server knows that the sensitive credential of the middleware has been generated based on the identification; The sensitive credential sending module is used for sending the sensitive credential of the middleware in response to the acquisition request sent by the service server, so that the service server connects the middleware based on the sensitive credential of the middleware; The request joining module is used for sending a join request to the key management system; The identity identification credential receiving module is used for receiving the identity identification credential sent by the key management system in response to the join request, and joining the key management system based on the identity identification credential; A sensitive credential encryption module is configured to encrypt sensitive credentials of the middleware by using the key management system to obtain encrypted sensitive credentials of the middleware. A sensitive credential storage module is configured to store the encrypted sensitive credentials of the middleware in a disk. A sensitive credential decryption module is configured to decrypt the encrypted sensitive credentials of the middleware by using the key management system to obtain sensitive credentials of the middleware.

9. A sensitive credential management apparatus applied to a service server, characterized in that, Comprise: An information sending module, an application sending module, an identification receiving module, and a sensitive credential obtaining module, wherein The information sending module is configured to send middleware information of middleware to be managed to a DSM system, so that the DSM system completes registration of configuration information of the middleware based on the middleware information of the middleware to be managed, and establishes a connection with the middleware based on the configuration information of the middleware; The application sending module is configured to send an application request to the DSM system, so that the DSM system generates sensitive credentials of the middleware based on the configuration information of the middleware, and sends an identification of application success to the service server; The identification receiving module is configured to receive the identification of application success sent by the DSM system, and knows that the DSM system has generated the sensitive credentials of the middleware based on the identification; The sensitive credential obtaining module is configured to send an obtaining request to the DSM system, receive the sensitive credentials of the middleware, and connect the middleware based on the sensitive credentials of the middleware; A request joining module is configured to send a joining request to a key management system; An identity recognition credential receiving module is configured to receive an identity recognition credential sent by the key management system in response to the joining request, and join the key management system based on the identity recognition credential; A sensitive credential encryption module is configured to encrypt sensitive credentials of the middleware by using the key management system to obtain encrypted sensitive credentials of the middleware. A sensitive credential storage module is configured to store the encrypted sensitive credentials of the middleware in a disk. A sensitive credential decryption module is configured to decrypt the encrypted sensitive credentials of the middleware by using the key management system to obtain sensitive credentials of the middleware.

10. An electronic device, comprising: Comprise a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory complete mutual communication through the communication bus; The memory is configured to store a computer program. The processor is configured to execute the program stored on the memory to implement the sensitive credential management method of any one of claims 1-6 or the sensitive credential management method of claim 7.

11. A computer readable storage medium having stored thereon a computer program, characterized in that, The computer program is executed by the processor to implement the sensitive credential management method of any one of claims 1-6 or the steps of the sensitive credential management method of claim 7.

Citation Information

Patent Citations

  • Database access method, system and equipment

    CN110222531A

  • Database implementation method and device, electronic equipment and storage medium

    CN112835866A