Authentication methods, related equipment, storage media, and computer program products

By using the first domain as a client to request service authorization from the KDC in the computing power network, the problem of low authentication efficiency of Kerberos technology in the computing power network is solved, achieving efficient and unified authorization for all service nodes and reducing authentication overhead.

CN118802131BActive Publication Date: 2026-01-30CHINA MOBILE COMM LTD RES INST +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410330629.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-03-21
Publication Date
2026-01-30
Estimated Expiration
2044-03-21

AI Technical Summary

Technical Problem

In computing networks, the authentication efficiency is low and the authentication overhead is high when using Kerberos technology to authenticate clients that initiate service authorization requests.

Method used

By using the first domain as a client to request service authorization from the KDC for all service nodes, the KDC only needs to authenticate the identity of the first domain, instead of authenticating the identity of each service node, thus improving authentication efficiency and reducing overhead.

Benefits of technology

It enables unified service authorization for all service nodes in the computing power network, improving authentication efficiency and reducing authentication overhead.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118802131B_ABST
    Figure CN118802131B_ABST
Patent Text Reader

Abstract

This application discloses an authentication method, apparatus, first node, key distribution center (KDC), second node, first server, second server, storage medium, and computer program product. The method includes: the first node sending first information to the KDC, the first information requesting service authorization for N service nodes in a first domain; receiving second information sent by the KDC, the second information indicating authorization completion, the second information including a first key and third information, the first key including a session key between the first domain as a first client and a first server, the third information representing authorized access credentials associated with the client and the first server; and sending the first key and the third information to the other N service nodes besides the first node, the third information being used at least for service authentication between the service nodes and the first server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of information security, and in particular to an authentication method, apparatus, related equipment, storage medium, and computer program product. Background Technology

[0002] The Kerberos system employs a client-server architecture and the Data Encryption Standard (DES) encryption technology. Before requesting services from the server, a client in a Kerberos system must request service authorization from a Key Distribution Center (KDC). Upon receiving the authorization request, the KDC authenticates the client's identity. Once authentication is successful, the KDC authorizes the client to access services. After authorization, the client can request services from the server and perform service authentication with the server; both the client and server can authenticate each other's identities. The Kerberos system can be used to prevent eavesdropping, prevent replay attacks, and protect data integrity. It is a system that uses a symmetric key system for key management.

[0003] When the Kerberos system is applied in computing power networks, if Kerberos technology is used to authenticate and authorize clients that initiate service authorization requests, the authentication overhead is large and the authentication efficiency is low. Summary of the Invention

[0004] To address the related technical issues, embodiments of this application provide an authentication method, apparatus, first node, KDC, second node, first server, second server, storage medium, and computer program product.

[0005] The technical solution of this application embodiment is implemented as follows:

[0006] This application provides an authentication method applied to a first node, which belongs to a first domain. The first domain contains N service nodes, where N is an integer greater than or equal to 1, including:

[0007] Send a first message to the KDC, the first message being used to request service authorization for N service nodes in the first domain;

[0008] The system receives a second message sent by the KDC, the second message indicating that authorization is complete, the second message containing a first key and a third message, the first key containing the first domain as a session key between the first client and the first server, and the third message representing the authorized access credentials associated with the first client and the first server.

[0009] The first key and third information are sent to the other service nodes among the N service nodes, excluding the first node. The third information is used at least for service authentication with the first server.

[0010] In the above scheme, the first information includes the identifier of the first domain and / or the fourth information, wherein the fourth information represents the services that each of the N service nodes can apply for.

[0011] In the above scheme, the fourth information includes the fifth information of each of the N service nodes, and the fifth information represents the service identifier that the service node can apply for by signing with the private key of the service node.

[0012] In the above scheme, sending the first key to the other service nodes among the N service nodes besides the first node includes:

[0013] For one of the N service nodes other than the first node, encrypt the first key using the key of the service node;

[0014] Send the encrypted first key to the service node.

[0015] This application also provides an authentication method applied to a KDC, including:

[0016] Receive first information sent by the first node, the first node belongs to the first domain, the first domain contains N service nodes, the first information is used to request service authorization for the N service nodes of the first domain, where N is an integer greater than or equal to 1;

[0017] Authentication is performed on N service nodes of the first domain by interacting with the first node;

[0018] After successful authentication, a second message is sent to the first node. The second message indicates that authorization is complete. The second message includes a first key and a third message. The first key includes the first domain as a session key between the first client and the first server. The third message represents the credentials for authorized access associated with the first client and the first server.

[0019] In the above scheme, the first information includes the identifier of the first domain and / or the fourth information, wherein the fourth information represents the services that each of the N service nodes can apply for.

[0020] In the above scheme, the fourth information includes the fifth information of each of the N service nodes, and the fifth information represents the service identifier that the service node can apply for by signing with the private key of the service node.

[0021] This application embodiment also provides an authentication method applied to a second node, the second node comprising one of N service nodes contained in a first domain, where N is an integer greater than or equal to 1, comprising:

[0022] The system receives a first key and third information sent by a first node, the first node belonging to the first domain, the first key containing the first domain as a session key between the first client and the first server, the third information representing a credential for authorized access associated with the first client and the first server, and the third information being used at least for service authentication between the service node and the first server.

[0023] Send a fifth message to the first server. The fifth message is used to request the first server to perform service authentication for the second node. The fifth message includes authentication information encrypted with the first key and a third message.

[0024] The system receives a sixth message sent by the first server, the sixth message containing the service authentication result.

[0025] In the above scheme, when sending the fifth information to the first server, the method further includes:

[0026] A seventh message is sent to a second server, which is used at least to perform data security processing authentication when the security levels of the first domain and the second domain to which the first server belongs are different. The seventh message contains relevant information about the first domain.

[0027] Receive the eighth message sent by the second server, the eighth message being used to instruct the second node and / or the first server to perform security processing on the data;

[0028] Authentication related to security processing is performed with the second server and the first server.

[0029] In the above scheme, when the eighth information is used at least to indicate that the second node needs to perform security processing on the data, the authentication related to the security processing performed on the second server and the first server includes:

[0030] Receive the first token sent by the second server;

[0031] The first token is used to invoke the security gateway for security processing and authentication.

[0032] If the security processing authentication is successful, the first security processing authentication credential is sent to the second server;

[0033] Receive a second credential associated with security processing authentication sent by the second server, the second credential being generated based on the first credential;

[0034] Service authentication is performed with the first server based on the second credential.

[0035] In the above scheme, where the eighth information is at least used to indicate to the first server that data security processing is required, the method further includes:

[0036] Service authentication is performed between the second server and the first server based on a third credential; wherein the third credential is generated by the second server for the first server based on a fourth credential, and the fourth credential is sent by the security gateway after the first server has passed security processing authentication.

[0037] This application embodiment also provides an authentication method applied to a first server, including:

[0038] The system receives a fifth message sent by a second node, where the second node includes one of N service nodes contained in the first domain, where N is an integer greater than or equal to 1. The fifth message is used to request the first server to authenticate the second node. The fifth message includes authentication information encrypted with a first key and third information. The first key includes the first domain as a session key between the first client and the first server. The third information represents the credentials for authorized access associated with the first client and the first server. The third information is used at least for service authentication with the second node.

[0039] Perform service authentication on the second node to obtain the service authentication result;

[0040] Send a sixth message to the second node, the sixth message containing the service authentication result.

[0041] In the above scheme, when receiving the fifth message sent by the second node, the method further includes:

[0042] Send a ninth message to a second server, the ninth message containing relevant information about the second domain to which the first server belongs, the second server being used at least to perform data security processing authentication when the security levels of the first domain and the second domain are different;

[0043] Receive the eighth message sent by the second server, the eighth message being used to instruct the second node and / or the second server to perform security processing on the data;

[0044] Service authentication related to security processing is performed with the second server and the second node.

[0045] In the above scheme, where the eighth information is at least used to indicate to the first server that data security processing is required, the method further includes:

[0046] Receive the second token sent by the second server;

[0047] The second token is used to invoke the security gateway for security authentication.

[0048] If the security processing authentication is successful, a fourth security processing authentication credential is sent to the second server;

[0049] Receive a third credential associated with security processing authentication sent by the second server, the third credential being generated based on the fourth credential;

[0050] Service authentication is performed with the second node based on the third credential.

[0051] In the above scheme, where the eighth information is at least used to indicate that the second node needs to perform security processing on the data, the method further includes:

[0052] Service authentication is performed between the second server and the second node based on the second credential; wherein the second credential is generated by the second server for the first server based on the first credential, and the first credential is sent by the security gateway after the second node has passed security processing authentication.

[0053] This application embodiment also provides an authentication method applied to a second server, including:

[0054] The system receives a seventh message sent by a second node, which belongs to a first domain. The first domain contains N service nodes, where N is an integer greater than or equal to 1. The seventh message contains relevant information about the first domain.

[0055] Receive the ninth message sent by the first server, the ninth message containing relevant information about the second domain to which the first server belongs;

[0056] Using the seventh and ninth information, it is determined that the security levels of the first domain and the second domain are different. An eighth information is then sent to the second node and the first server. The eighth information is used to instruct the second node and / or the second server to perform security processing on the data and to perform data security processing authentication.

[0057] In the above scheme, where the eighth information is at least used to indicate that the second node needs to perform security processing on the data, the method further includes:

[0058] Send a first token to the second node so that the second node can use the first token to call the security gateway for security authentication.

[0059] Receive the first security processing authentication credential sent by the second node if the security processing authentication is successful;

[0060] A second credential is generated based on the first credential and associated with security processing authentication;

[0061] Send the second credential to the second node.

[0062] In the above scheme, where the eighth information is at least used to indicate to the first server that data security processing is required, the method further includes:

[0063] Send a second token to the first server so that the first server can use the second token to invoke the security gateway for security authentication.

[0064] Receive the fourth security authentication credential sent by the first server if the security authentication is successful.

[0065] A third credential is generated based on the fourth credential and associated with security processing authentication;

[0066] Send the third credential to the first server.

[0067] This application embodiment also provides a first node, including: a first processor and a first memory for storing a computer program capable of running on the processor.

[0068] Wherein, when the first processor is used to run the computer program, it executes the steps of any of the methods described above on the first node side.

[0069] This application also provides a KDC, including: a second processor and a second memory for storing computer programs capable of running on the processor.

[0070] Wherein, when the second processor is used to run the computer program, it executes the steps of any of the methods described above on the KDC side.

[0071] This application also provides a second node, including: a third processor and a third memory for storing computer programs capable of running on the processor.

[0072] The third processor is used to execute any of the steps of the second node-side method when running the computer program.

[0073] This application also provides a first server, including: a fourth processor and a fourth memory for storing computer programs capable of running on the processor.

[0074] The fourth processor is used to execute the steps of any of the first server-side methods described above when running the computer program.

[0075] This application also provides a second server, including: a fifth processor and a fifth memory for storing computer programs capable of running on the processor.

[0076] The fifth processor, when running the computer program, executes the steps of any of the methods described above on the second server side.

[0077] This application embodiment also provides a storage medium storing a computer program thereon. When the computer program is executed by a processor, it implements the steps of any of the methods described above on the first node side, or the steps of any of the methods described above on the KDC side, or the steps of any of the methods described above on the second node side, or the steps of any of the methods described above on the first server side, or the steps of any of the methods described above on the second server side.

[0078] This application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of any of the methods described above on the first node side, or the steps of any of the methods described above on the KDC side, or the steps of any of the methods described above on the second node side, or the steps of any of the methods described above on the first server side, or the steps of any of the methods described above on the second server side.

[0079] The authentication method, apparatus, first node, KDC, second node, first server, second server, storage medium, and computer program product provided in this application embodiment are as follows: The first node sends first information to the KDC, the first information being used to request service authorization for N service nodes in the first domain. The first node belongs to the first domain, and the first domain contains N service nodes, where N is an integer greater than or equal to 1. After receiving the first information sent by the first node, the KDC authenticates the N service nodes in the first domain by interacting with the first node. After successful authentication, the KDC sends second information to the first node, the second information indicating that authorization is complete. The second information includes a first key and third information. The first key contains the first domain as a session key between the first client and the first server, and the third information represents the authorized access credentials associated with the first client and the first server. After receiving the second information sent by the KDC, the first node sends the first key and the third information to the other service nodes among the N service nodes besides the first node. The third information is used at least for service authentication with the first server. The solution provided in this application embodiment allows the first node in the first domain to request service authorization from the KDC for all service nodes within the first domain. In this way, the KDC only needs to authenticate the identity of the first domain as the first client to authorize services for all service nodes, without needing to authenticate the identity of each service node in the first domain, thus improving authentication efficiency and reducing authentication overhead. Attached Figure Description

[0080] Figure 1 This is a flowchart illustrating the first authentication method according to an embodiment of this application;

[0081] Figure 2 This is a flowchart illustrating the second authentication method according to an embodiment of this application;

[0082] Figure 3 This is a flowchart illustrating the third authentication method according to an embodiment of this application;

[0083] Figure 4 This is a flowchart illustrating the fourth authentication method according to an embodiment of this application;

[0084] Figure 5 This is a flowchart illustrating the fifth authentication method according to an embodiment of this application;

[0085] Figure 6 This is a flowchart illustrating the sixth authentication method according to an embodiment of this application;

[0086] Figure 7 This is a schematic diagram of the computing power network system structure used in this application.

[0087] Figure 8This is a schematic diagram illustrating the process of inter-domain authentication and authorization for the application example in this application;

[0088] Figure 9 A flowchart illustrating the application example service request for this application;

[0089] Figure 10 This is a schematic diagram of the structure of the first authentication device according to an embodiment of this application;

[0090] Figure 11 This is a schematic diagram of the structure of the second authentication device according to an embodiment of this application;

[0091] Figure 12 This is a schematic diagram of the third type of authentication device according to an embodiment of this application;

[0092] Figure 13 This is a schematic diagram of the fourth type of authentication device according to an embodiment of this application;

[0093] Figure 14 This is a schematic diagram of the fifth type of authentication device in this application.

[0094] Figure 15 This is a schematic diagram of the first node structure in an embodiment of this application;

[0095] Figure 16 This is a schematic diagram of the KDC structure in an embodiment of this application;

[0096] Figure 17 This is a schematic diagram of the second node structure in an embodiment of this application;

[0097] Figure 18 This is a schematic diagram of the first server structure according to an embodiment of this application;

[0098] Figure 19 This is a schematic diagram of the second server structure according to an embodiment of this application;

[0099] Figure 20 This is a schematic diagram of the authentication system structure in an embodiment of this application. Detailed Implementation

[0100] The present application will now be described in further detail with reference to the accompanying drawings and embodiments.

[0101] In the context of computing power networks, these networks typically provide computing services by accessing various computing resources. These resources may use different architectures and be provided by different providers (specifically, cloud platforms, edge clouds, etc.). Therefore, when the amount of data requiring computation or storage is large, or when the types of computation differ, the provision of services by computing power networks usually involves interaction between multiple nodes (also understood as service nodes, network entities, or computing nodes). Each node may correspond to a different provider, using the computing resources required to provide the computing services. Since the security environments and trust levels of different providers may vary, the security levels of different nodes may also differ; that is, different nodes may reside in different trust domains (also understood as security domains). When nodes in different trust domains interact (also understood as collaborate), if even one node is impersonated by an attacker, the interaction between nodes may lead to data leakage.

[0102] To prevent the leakage of sensitive information, each node in the computing power network can undergo identity authentication (or verification) before its first data transmission (or service participation) to ensure it has not been impersonated. Furthermore, to further prevent leakage, after successful authentication, each participating node can be protected by establishing a gateway (or security gateway) for data security processing. Since establishing gateways at the boundaries of each trust domain is costly, a unified security gateway can be established within the computing power network to save on construction costs. This unified security gateway can then be invoked as needed for data security processing.

[0103] Among related technologies, the Kerberos protocol is a commonly used technique for authenticating node identities. The Kerberos protocol is typically applied in distributed architecture systems (or systems as a whole), using one or more (or at least one) KDCs (Kerberos servers) to authenticate the nodes (specifically, servers, clients, etc.) within the system.

[0104] For example, in a scenario where a client requests resources from a server, the client can interact with the KDC (Kerberos Controller) to request service authorization. Upon receiving the request, the KDC authenticates the client. If authentication is successful, the KDC issues the client's identity certificate (which may include a ticket) to notify the client of authorization. The client then sends this identity certificate to the server. The server uses this certificate to authenticate the client's identity and determine if it can provide the service (i.e., allocate resources). If authentication is successful (the server confirms the client's identity is correct), the server can allocate the requested resources. Simultaneously, if authentication is successful, the server can return its own identity certificate (which may include a timestamp from the client's authentication) to the client, allowing the client to verify the server's identity. Thus, the server can authenticate the client, and the client can authenticate the server, achieving two-way authentication between the server and client. This method of authentication between two nodes using Kerberos technology can also be called point-to-point authentication.

[0105] However, in computing power network scenarios, due to the large number of nodes requiring authentication, the authentication efficiency of using Kerberos technology for point-to-point authentication of each node is low and the authentication overhead is high. At the same time, the security gateway established in the computing power network may be at risk of bypassing the call, which may lead to data leakage.

[0106] Based on this, in various embodiments of this application, by using the first domain as the first client, the first node in the first domain can request the KDC to authorize services for all service nodes in the first domain. In this way, the KDC only needs to authenticate the identity of the first client, and does not need to authenticate the identity of each service node in the first domain, thereby improving authentication efficiency and reducing authentication overhead.

[0107] This application provides an authentication method applied to a first node, which belongs to a first domain. The first domain contains N service nodes, where N is an integer greater than or equal to 1. Figure 1 As shown, the method includes:

[0108] Step 101: Send the first message to the KDC, the first message being used to request service authorization for N service nodes in the first domain;

[0109] Step 102: Receive the second information sent by the KDC. The second information indicates that the authorization is completed. The second information includes a first key and third information. The first key includes the first domain as a session key between the first client and the first server. The third information represents the credentials for authorized access associated with the first client and the first server.

[0110] Step 103: Send the first key and third information to the other service nodes among the N service nodes, excluding the first node. The third information is used at least for service authentication with the first server.

[0111] Here, the first domain can be specifically referred to as a security domain or a trust domain. A domain can also be understood as a cluster. The first domain contains one or more service nodes (which can also be understood as nodes participating in the service), and the one or more service nodes include the first node.

[0112] For example, in the scenario of a computing power network, a service node can also be understood as a computing power node. The computing power nodes in the computing power network can be divided into multiple domains containing the first domain according to their security levels. Each of the multiple domains corresponds to a provider, and the one or more computing power nodes contained in each domain have the same security level. The security level of each domain can be determined based on the provider of the domain, the network security protection capabilities of the nodes contained in the domain, and the security software configuration of the nodes contained in the domain.

[0113] The first node can be specifically referred to as the security management node of the first domain. In this application embodiment, the name of the first node is not limited, as long as its function is implemented.

[0114] In step 101, the first node sends information to the KDC to request service authorization for all N service nodes in the first domain. In this way, the KDC only needs to authenticate the identity of the first domain as the first client to authorize all service nodes, without needing to authenticate the identity of each service node in the first domain. This improves authentication efficiency, reduces authentication overhead, and enables one-time authorization of all service nodes in the first domain.

[0115] In practical applications, the KDC can be associated with (or held by) a database (specifically, a key database). This database contains one or more identification information (also understood as keys). Each of these identification information corresponds to a client, and only the client corresponding to that identification information and the KDC can know this identification information (it can also be understood that this identification information is shared only between the corresponding client and the KDC). When a service node within a domain requests service authorization from the KDC for all service nodes within that domain, the KDC can treat the domain as a client, or it can be understood as treating all service nodes within the domain as a single client, and use the identification information corresponding to that domain as the identification information for that client. Thus, when a service node requests service authorization from the KDC for all service nodes within its domain, the service node can send the identification information corresponding to that domain to the KDC, enabling the KDC to authenticate the identities of all service nodes within that domain using this identification information.

[0116] Based on this, in one embodiment, the first information includes the identifier of the first domain and / or fourth information, wherein the fourth information represents the services that each of the N service nodes can apply for.

[0117] Here, the first client is associated with the first domain, and the name of the first client is not limited in this embodiment of the application.

[0118] In practical applications, when the first node requests the KDC to authorize services for N service nodes in the first domain, the KDC can treat the first domain as the first client. The first node can send the identifier of the first domain (e.g., domain ID) to the KDC, so that the KDC can use the received identifier of the first domain as the identification information corresponding to the first client, and search for the identifier information in the database associated with the KDC. Based on the search result, the KDC can authenticate the identity of the N service nodes in the first domain. If the identifier information is found in the database, the KDC can consider the identity of the N service nodes in the first domain to be correct, i.e., authentication is successful; if the identifier information is not found in the database, the KDC can consider the identity of the N service nodes in the first domain to be incorrect, and the service nodes in the first domain may have been impersonated, i.e., authentication fails.

[0119] If authentication is successful, the KDC can use the fourth information to determine and record the services that each service node in the first domain can apply for.

[0120] In order to distinguish the services that each of the N service nodes can apply for in the fourth information, in one embodiment, the fourth information includes the fifth information of each of the N service nodes. The fifth information represents the service identifier that the service node can apply for by signing with the private key of the service node. By signing the service identifier that can be applied for by each service node with the private key of the service node, the KDC can receive the fourth information and decrypt the fourth information with the public key of each service node, thereby determining which services each service node can apply for.

[0121] In practical applications, during step 101, the first node can send information to the KDC to inform the KDC which services the N service nodes within the first domain specifically request when applying for services. This allows the KDC to determine whether to authorize services for each service node based on the services requested and the corresponding services that the service node is eligible to request. In this way, the KDC only authorizes services to service nodes whose requested services match their eligible services, thereby further ensuring data security.

[0122] Based on this, in one embodiment, when sending the first information in step 101, the method may further include:

[0123] Send the tenth message to the KDC. The tenth message contains the services requested by the N service nodes of the first domain this time, and the services requested this time are associated with the first server.

[0124] In practical applications, the first server may specifically include the server corresponding to the service requested in this application among the N service nodes of the first domain. This embodiment does not limit the name of the first server, as long as its functionality is implemented. The first server may belong to a second domain different from the first domain, and the security level of the second domain may differ from that of the first domain.

[0125] The KDC can utilize the tenth and fourth information to determine, for each of the N service nodes, whether the service node's current service request is a service that the service node is capable of requesting. The KDC can then use the determination result to determine whether it can authorize the service node to interact with the first server, thereby further ensuring data security. Specifically, if the determination result indicates that the service node's current service request is a service that the service node is capable of requesting, the KDC can determine that it can authorize the service node to interact with the first server; if the determination result indicates that the service node's current service request is not a service that the service node is capable of requesting, the KDC can determine that it cannot authorize the service node to interact with the first server.

[0126] When the KDC determines that it can authorize N service nodes in the first domain to interact with the first server (which can also be understood as authorizing the first client to interact with the first server), the KDC can generate the first key (i.e., the session key between the first client and the first server) and third information (i.e., the access permission credential associated with the first client and the first server), and send the first key and third information to the first node. Accordingly, in step 102, the first node receives the first key and third information sent by the KDC. Specifically, the third information may include a ticket required for the service interaction between the first client and the first server. The ticket may include: the first key encrypted with the key corresponding to the first server, the client identifier of the first client, the address of the first client, the ticket validity period, etc.

[0127] After receiving the first key and third information sent by KDC, in step 103, the first node can send the received first key and third information to other service nodes in the first domain besides itself, so that each service node in the first domain can subsequently use the third information to perform service authentication with the first server. During the service authentication process, the interaction information between the service node and the first server can be encrypted using the first key.

[0128] To ensure data transmission security, the first node can first encrypt the first key, and then send the first key to the other service nodes among the N service nodes besides the first node.

[0129] Based on this, in one embodiment, sending the first key to the other service nodes among the N service nodes besides the first node includes:

[0130] For one of the N service nodes other than the first node, encrypt the first key using the key of the service node;

[0131] Send the encrypted first key to the service node.

[0132] Accordingly, embodiments of this application also provide an authentication method applied to KDC, such as... Figure 2 As shown, it includes:

[0133] Step 201: Receive the first information sent by the first node, the first node belongs to the first domain, the first domain contains N service nodes, the first information is used to request service authorization for the N service nodes of the first domain, N is an integer greater than or equal to 1;

[0134] Step 202: Authenticate the N service nodes of the first domain by interacting with the first node;

[0135] Step 203: After successful authentication, send second information to the first node. The second information indicates that the authorization is complete. The second information includes a first key and third information. The first key includes the first domain as a session key between the first client and the first server. The third information represents the credentials for authorized access associated with the first client and the first server.

[0136] In practical applications, the KDC can receive the first information sent by the first node and authorize services to all N service nodes in the first domain. In this way, the KDC only needs to authenticate the identity of the first domain as the first client to authorize services to all service nodes, without needing to authenticate the identity of each service node in the first domain. This improves authentication efficiency, reduces authentication overhead, and enables one-time authorization of services to all service nodes in the first domain.

[0137] In practical applications, the KDC can be associated with a database containing one or more identification information entries. Each of these entries corresponds to a client, and only the client corresponding to that entry and the KDC can access that entry. When a service node within a domain requests service authorization from the KDC for all service nodes within that domain, the KDC can treat the domain as a client, or it can be understood as treating all service nodes within that domain as a single client, and using the domain's corresponding identification information as the client's identification information. Thus, when a service node requests service authorization from the KDC for all service nodes within its domain, the service node can send the domain's corresponding identification information to the KDC, enabling the KDC to authenticate the identities of all service nodes within that domain using that identification information.

[0138] Based on this, in one embodiment, the first information includes the identifier of the first domain and / or fourth information, wherein the fourth information represents the services that each of the N service nodes can apply for.

[0139] In practical applications, when the first node requests the KDC to authorize services for N service nodes in the first domain, the KDC can treat the first domain as the first client. The first node can send an identifier of the first domain to the KDC, enabling the KDC to use the received identifier as the identification information corresponding to the first client and search for the identifier in the database associated with the KDC. Based on the search result, the KDC authenticates the identities of the N service nodes in the first domain. If the identifier is found in the database, the KDC considers the identities of the N service nodes in the first domain to be correct, i.e., authentication is successful; if the identifier is not found in the database, the KDC considers the identities of the N service nodes in the first domain to be incorrect, and the service nodes in the first domain may have been impersonated, i.e., authentication fails.

[0140] If authentication is successful, the KDC can use the fourth information to determine and record the services that each service node in the first domain can apply for.

[0141] In order to distinguish the services that each of the N service nodes can apply for in the fourth information, in one embodiment, the fourth information includes the fifth information of each of the N service nodes. The fifth information represents the service identifier that the service node can apply for by signing with the private key of the service node. By signing the service identifier that can be applied for by each service node with the private key of the service node, the KDC can receive the fourth information and decrypt the fourth information with the public key of each service node, thereby determining which services each service node can apply for.

[0142] In practical applications, the first node can send information to the KDC to inform the KDC which services the N service nodes within the first domain specifically request when applying for services. This allows the KDC to determine whether to authorize services for each service node based on the services requested and the services that the service node is eligible to request. In this way, the KDC only authorizes services to service nodes whose requested services match their eligible services, thereby further ensuring data security.

[0143] Based on this, in one embodiment, the method may further include:

[0144] The system receives the tenth message sent by the first node, which contains the services requested by N service nodes in the first domain, and the services requested are associated with the first server.

[0145] In practical application, the KDC can utilize the tenth and fourth information to determine, for each of the N service nodes, whether the service node's current service request is a service that the service node is capable of requesting. The KDC can then use this determination to decide whether to authorize the service node to interact with the first server, thereby further ensuring data security. Specifically, if the determination result indicates that the service node's current service request is a service that the service node is capable of requesting, the KDC can determine that it can authorize the service node to interact with the first server; if the determination result indicates that the service node's current service request is not a service that the service node is capable of requesting, the KDC can determine that it cannot authorize the service node to interact with the first server.

[0146] Once the KDC determines that it can authorize N service nodes in the first domain to interact with the first server (which can also be understood as authorizing the first client to interact with the first server), the KDC can generate the first key (i.e., the session key between the first client and the first server) and the third information (i.e., the access permission credential associated with the first client and the first server). Then, in step 203, the KDC can send the first key and the third information to the first node to inform the first node that the authorization is complete.

[0147] Accordingly, this application also provides an authentication method applied to a second node, the second node comprising one of N service nodes contained in the first domain, where N is an integer greater than or equal to 1, such as... Figure 3 As shown, it includes:

[0148] Step 301: Receive a first key and third information sent by the first node. The first node belongs to the first domain. The first key contains the first domain as a session key between the first client and the first server. The third information represents the authorized access credentials associated with the first client and the first server. The third information is used at least for service authentication with the first server.

[0149] Step 302: Send fifth information to the first server. The fifth information is used to request the first server to authenticate the second node. The fifth information includes authentication information encrypted with the first key and third information.

[0150] Step 303: Receive the sixth information sent by the first server, the sixth information including the service authentication result.

[0151] Here, the N service nodes included in the first domain include the second node. This application embodiment does not limit the name of the second node, as long as its function is implemented. Specifically, the second node can be the first node, or it can be any of the other service nodes among the N service nodes included in the first domain besides the first node.

[0152] In practical applications, the first node within the first domain can interact with the KDC to authorize services for the N service nodes within the first domain and request services related to the first server. After authorizing the N service nodes, the KDC sends a first key and third information to the first node. The first node can then send the received first key and third information to other service nodes within the first domain besides itself. Here, if the other service nodes include the second node, in step 301, the second node receives the first key and third information sent by the first node. However, in practical applications, if the second node is the same as the first node, the second node does not need to execute step 301 and can use the received first key and third information sent by the KDC to authenticate with the first server.

[0153] After obtaining the first key and the third information, the second node can use the first key to encrypt the authentication information and the third information to obtain the fifth information. The authentication information can also be understood as an authentication token, which may specifically include the node identifier of the second node (such as node ID, which can be expressed as nodeid), timestamp, etc.

[0154] In step 302, the second node may send authentication information and third information encrypted with the first key to the first server, so that the first server can perform service authentication on the second node.

[0155] After receiving the fifth message sent by the second node, the first server can use the fifth message to determine the node identifier of the second node and the client identifier of the first client. The first server can then interact with the KDC to determine whether the node identifier of the second node and the client identifier of the first client are correct, i.e., to authenticate the identity of the second node, and thus generate a service authentication result.

[0156] In practical applications, the first server may belong to a second domain different from the first domain, and the security level of the second domain may differ from that of the first domain. When the first server, belonging to the second domain, interacts with a second node, belonging to the first domain (which can also be understood as cross-domain transmission), there is a risk of data leakage due to the different security levels of the first and second domains. Therefore, before the first server returns the service authentication result to the second node, the security levels of the second domain to which the first server belongs and the first domain to which the second node belongs can be determined, and corresponding security processing can be performed. In this way, firstly, the risk of data leakage can be effectively reduced by performing security processing; secondly, by performing security processing during the service authentication process, it is effectively ensured that nodes with different security levels can only pass service authentication and carry out normal service interaction after security processing, thus avoiding behavior that bypasses security processing; thirdly, the corresponding security processing is only invoked when the security levels of the two nodes are different, eliminating the need to deploy security processing-related functions across all domains, thereby saving construction costs.

[0157] Based on this, in one embodiment, when sending the fifth information to the first server, the method may further include:

[0158] A seventh message is sent to a second server, which is used at least to perform data security processing authentication when the security levels of the first domain and the second domain to which the first server belongs are different. The seventh message contains relevant information about the first domain.

[0159] Receive the eighth message sent by the second server, the eighth message being used to instruct the second node and / or the first server to perform security processing on the data;

[0160] Authentication related to security processing is performed with the second server and the first server.

[0161] In practical applications, the second server can be specifically referred to as a data processing authentication server. This application embodiment does not limit the name of the second node, as long as its function is implemented.

[0162] In practical applications, the second server can receive information related to the first domain sent by the second node, and simultaneously, the second server can receive information related to the second domain sent by the first server. The second server can then determine whether the security levels of the first domain and the second domain are the same by comparing the information related to the first domain and the information related to the second domain. Specifically, the information related to the first domain may include the domain identifier of the first domain, which the second server can use to determine the security level of the first domain; the information related to the second domain may include the server identifier of the first server (e.g., server ID), which the second server can use to determine the security level of the second domain.

[0163] For example, the specific implementation of the second server determining the security level of the first domain using the domain identifier of the first domain may include: a preset correspondence in the second server, where each item in the correspondence corresponds to a domain, and each item contains a domain identifier and the security level corresponding to that domain. Thus, the second server can search for the item corresponding to the domain identifier of the first domain in the preset correspondence, and determine the security level corresponding to the first domain using the security level contained in the found item.

[0164] If the security levels of the first domain and the second domain are the same, the second server can determine that no security processing is required, and the first server and the second node can directly perform service authentication. If the security levels of the first domain and the second domain are different, the second server can determine, based on the security levels of the first domain and the second domain, that the second node and / or the first server need to perform security processing on the data, and send the eighth information to the second node and the first server.

[0165] Upon receiving the eighth message from the second server, the second node can use the eighth message to determine whether the second node and / or the first server will perform security processing on the data and conduct authentication related to the security processing; wherein, depending on the object of the security processing, there are the following two cases:

[0166] In the first scenario, the eighth piece of information is at least used to indicate to the second node that it needs to perform security processing on the data. In this case, the second node can authenticate with both the second and first servers regarding the security processing through a security gateway.

[0167] Specifically, in one embodiment, the authentication related to security processing with the second server and the first server includes:

[0168] Receive the first token sent by the second server;

[0169] The first token is used to invoke the security gateway for security processing and authentication.

[0170] If the security processing authentication is successful, the first security processing authentication credential is sent to the second server;

[0171] Receive a second credential associated with security processing authentication sent by the second server, the second credential being generated based on the first credential;

[0172] Service authentication is performed with the first server based on the second credential.

[0173] In practical application, after the second server determines that the second node needs to perform security processing on the data, it can determine the data processing identifier (e.g., data processing ID, or dpid) that the second node needs to invoke in the security gateway based on the security levels of the first and second domains. This data processing identifier corresponds to at least one data processing capability in the security gateway (specifically, it can include data anonymization, tagging, or adding a digital watermark). The second server can then generate and send the first token (or token) to the second node. This first token, specifically a capability invocation token, can include: a node identifier of the second node signed with the second server's private key, a data processing identifier, and a timestamp.

[0174] Upon receiving the first token, the specific implementation of the second node's security processing authentication via the security gateway may include: the second node using the first token to request access to the data processing capabilities corresponding to the data processing identifier from the security gateway; the security gateway verifying the second server signature in the first token and the node identifier of the second node; if the verification is successful, the security gateway can use the data processing identifier to determine and provide the second node with the interface for accessing the data processing capabilities corresponding to the data processing identifier; the second node can use the access interface provided by the security gateway to perform security processing on the data (which can also be understood as security gateway processing); after the second node completes the security processing of the data, the security gateway can issue the first credential to the second node, indicating that the second node's security processing authentication has passed. Specifically, the first credential may include: the node identifier of the second node signed with the security gateway's private key, the data processing identifier, and a timestamp, etc.

[0175] After receiving the first credential sent by the security gateway, the second node can send the received first credential to the second server to inform the second server that the second node has completed the security processing of the data.

[0176] The second server can use the first credential received from the second node to verify the security gateway signature invoked by the second node and the node identifier of the second node, etc., to determine whether the second node has indeed completed the security processing. If it is determined that the second node has indeed completed the security processing, the second server generates and sends the second credential to the second node. The second credential may specifically include a timestamp encrypted using the key corresponding to the second node, and the node identifier and data processing identifier of the second node signed using the private key of the second server.

[0177] Upon receiving the second credential from the second server, the second node can inform the first server that it has completed the security processing and can continue with service authentication. Specifically, the second node can decrypt the second credential using its corresponding key to obtain the credential content, encrypt the credential content using the first server's corresponding key, and send the encrypted information to the first server to inform it that the second node has completed the security processing.

[0178] In the second scenario, the eighth piece of information is at least used to indicate to the first server that it needs to perform security processing on the data. In this case, the first server can authenticate with the second server and the second node related to the security processing through a security gateway. After completing the authentication related to the security processing, the first server can inform the second node, based on the corresponding credentials obtained by the first server, that the first server has completed the security processing.

[0179] Based on this, in one embodiment, the method may further include:

[0180] Service authentication is performed between the second server and the first server based on a third credential; wherein the third credential is generated by the second server for the first server based on a fourth credential, and the fourth credential is sent by the security gateway after the first server has passed security processing authentication.

[0181] In practical applications, after the first server and the second node complete the security processing, they can continue with service authentication. Specifically, the first server can use the generated service authentication result to determine and send the sixth information to the second node. Thus, in step 303, the second node can receive the sixth information sent by the first server to complete service authentication.

[0182] In practical applications, when the first server sends the sixth piece of information to the second node, it can also send information to the second node to instruct the second node to authenticate the first server. The second node authenticating the first server can be understood as authenticating the identity of the first server. In this way, the first server can authenticate the identity of the second node, and the second node can also authenticate the identity of the first server, achieving two-way authentication and further ensuring the security of data transmission.

[0183] Based on this, in one embodiment, during step 303, the method may further include:

[0184] The second node receives the eleventh message sent by the first server, the eleventh message being used to instruct the second node to perform service authentication on the first server.

[0185] Specifically, the eleventh piece of information may include a new timestamp encrypted using the first key. This new timestamp may specifically include the value of the timestamp contained in the authentication information received by the first server plus 1. Thus, upon receiving the eleventh piece of information, the second node can decrypt it using the first key to obtain the new timestamp. The second node can then use this new timestamp to authenticate the identity of the first server. Specifically, the second node determines whether the new timestamp matches the timestamp contained in the authentication information sent by the second node, i.e., whether the new timestamp is equal to the value of the timestamp corresponding to the authentication information sent by the second node plus 1. If the two timestamps match, the second node can determine that the first server is the server that received the authentication information sent by the second node, and by authenticating the service of the first server, the identity of the first server is authenticated.

[0186] After the service authentication between the second node and the first server is successful, the second node can interact with the first server to carry out relevant services.

[0187] Accordingly, embodiments of this application also provide an authentication method applied to a first server, such as... Figure 4 As shown, it includes:

[0188] Step 401: Receive the fifth information sent by the second node, where the second node includes one of the N service nodes contained in the first domain, where N is an integer greater than or equal to 1. The fifth information is used to request the first server to authenticate the second node. The fifth information includes authentication information encrypted with a first key and third information. The first key includes the first domain as a session key between the first client and the first server. The third information represents the authorized access credentials associated with the first client and the first server. The third information is used at least for service authentication with the second node.

[0189] Step 402: Perform service authentication on the second node to obtain the service authentication result;

[0190] Step 403: Send the sixth information to the second node, the sixth information containing the service authentication result.

[0191] In practical application, after receiving the fifth information sent by the second node, in step 402, the first server can use the fifth information to determine the node identifier of the second node and the client identifier of the first client. The first server can then interact with the KDC to determine whether the node identifier of the second node and the client identifier of the first client are correct, i.e., to authenticate the identity of the second node, and thus generate a service authentication result.

[0192] In practical applications, the first server may belong to a second domain different from the first domain, and the security level of the second domain may differ from that of the first domain. When the first server, belonging to the second domain, interacts with a second node, belonging to the first domain (which can also be understood as cross-domain transmission), there may be a risk of data leakage due to the different security levels of the first and second domains. Therefore, before step 403, the security levels of the second domain to which the first server belongs and the first domain to which the second node belongs can be determined, and corresponding security processing can be performed. In this way, firstly, the risk of data leakage can be effectively reduced by performing security processing; secondly, by performing security processing during service authentication, it is effectively ensured that nodes with different security levels can only pass service authentication and carry out normal service interaction after security processing, thus avoiding behavior that bypasses security processing; thirdly, the corresponding security processing is only invoked when the security levels of the two nodes are different, eliminating the need to deploy security processing-related functions across all domains and saving construction costs.

[0193] Based on this, in one embodiment, step 401 of the method may further include:

[0194] Send a ninth message to a second server, the ninth message containing relevant information about the second domain to which the first server belongs, the second server being used at least to perform data security processing authentication when the security levels of the first domain and the second domain are different;

[0195] Receive the eighth message sent by the second server, the eighth message being used to instruct the second node and / or the second server to perform security processing on the data;

[0196] Authentication related to security processing is performed with the second server and the second node.

[0197] In practical application, the second server can receive information related to the first domain sent by the second node, and simultaneously, it can receive information related to the second domain (i.e., the ninth information) sent by the first server. The second server can then determine whether the security levels of the first and second domains are the same by comparing the information related to the first and second domains. Specifically, the information related to the first domain may include the domain identifier of the first domain, which the second server can use to determine the security level of the first domain; similarly, the information related to the second domain may include the server identifier of the first server, which the second server can use to determine the security level of the second domain.

[0198] If the security levels of the first domain and the second domain are the same, the second server can determine that no security processing is required, and the first server and the second node can directly perform service authentication. If the security levels of the first domain and the second domain are different, the second server can determine, based on the security levels of the first domain and the second domain, that the second node and / or the first server need to perform security processing on the data, and send the eighth information to the second node and the first server.

[0199] Upon receiving the eighth message from the second server, the first server can use the eighth message to determine whether the second node and / or the first server will perform security processing on the data, and perform authentication related to the security processing; wherein, depending on the object of the security processing, there are the following two cases:

[0200] In the first scenario, the eighth piece of information is at least used to indicate to the first server that it needs to perform security processing on the data. In this case, the first server can perform authentication related to security processing with the second server and the second node through a security gateway.

[0201] Specifically, in one embodiment, the method may further include:

[0202] Receive the second token sent by the second server;

[0203] The second token is used to invoke the security gateway for security authentication.

[0204] If the security processing authentication is successful, a fourth security processing authentication credential is sent to the second server;

[0205] Receive a third credential associated with security processing authentication sent by the second server, the third credential being generated based on the fourth credential;

[0206] Service authentication is performed with the second node based on the third credential.

[0207] In practical application, after the second server determines that the first server needs to perform security processing on the data, the second server can determine, based on the security levels of the first and second domains, the data processing identifier that the first server needs to invoke in the security gateway. This data processing identifier corresponds to at least one data processing capability in the security gateway. The second server can then generate and send the second token to the first server. Specifically, the second token can be called a capability invocation token, and it may include the server identifier of the first server signed with the second server's private key, the data processing identifier, and a timestamp, etc.

[0208] Upon receiving the second token, the specific implementation of the first server's security processing authentication via the security gateway may include: the first server using the second token to request access to the data processing capabilities corresponding to the data processing identifier from the security gateway; the security gateway verifying the second server signature and the first server's server identifier in the first token; if the verification is successful, the security gateway can use the data processing identifier to determine and provide the first server with the interface for accessing the data processing capabilities corresponding to the data processing identifier; the first server can use the access interface provided by the security gateway to perform security processing on the data (which can also be understood as security gateway processing); after the first server completes the security processing of the data, the security gateway can issue the fourth credential to the first server, indicating that the first server's security processing authentication has passed. Specifically, the fourth credential may include the first server's server identifier signed using the security gateway's private key, the data processing identifier, and a timestamp, etc.

[0209] After receiving the fourth credential from the security gateway, the first server can send the received fourth credential to the second server to inform the second server that the first server has completed the security processing of the data.

[0210] The second server can use the fourth credential received from the first server to verify the security gateway signature invoked by the first server and the server identifier of the first server, thereby determining whether the first server has indeed completed the security processing. If the first server has indeed completed the security processing, the second server generates and sends the third credential to the first server. The third credential may specifically include a timestamp encrypted using the key corresponding to the first server, and the server identifier and data processing identifier of the first server signed using the private key of the second server.

[0211] Upon receiving the third credential from the second server, the first server can inform the second node that it has completed the security processing and can continue with service authentication. Specifically, the first server can decrypt the third credential using its own key to obtain the credential content, encrypt the credential content using the second node's key, and send the encrypted information to the second node to inform it that the first server has completed the security processing.

[0212] In the second scenario, the eighth piece of information is at least used to indicate that the second node needs to perform security processing on the data. In this case, the second node can authenticate with both the second and first servers through a security gateway. After completing the authentication related to security processing, the second node can inform the first server, based on the corresponding credentials obtained by the second node, that the second node has completed the security processing.

[0213] Based on this, in one embodiment, the method may further include:

[0214] Authentication is performed between the second server and the second node based on the second credential; wherein the second credential is generated by the second server for the first server based on the first credential, and the first credential is sent by the security gateway after the second node has passed security processing authentication.

[0215] In practical applications, after the first server and the second node complete the security processing, they can continue with service authentication. Specifically, the first server can use the generated service authentication result to determine the sixth information, and then in step 403, the first server sends the sixth information to the second node.

[0216] In practical applications, when the first server sends the sixth piece of information to the second node, it can also send information to the second node to instruct the second node to authenticate the first server. The second node authenticating the first server can be understood as authenticating the identity of the first server. In this way, the first server can authenticate the identity of the second node, and the second node can also authenticate the identity of the first server, achieving two-way authentication and further ensuring the security of data transmission.

[0217] Based on this, in one embodiment, step 403 of the method may further include:

[0218] The eleventh message is sent to the second node, which instructs the second node to perform service authentication on the first server.

[0219] In practical application, the second node can use the received eleventh information to authenticate the identity of the first server. After successful service authentication between the second node and the first server, the second node can interact with the first server to perform relevant services.

[0220] Accordingly, embodiments of this application also provide an authentication method applied to a second server, such as... Figure 5 As shown, it includes:

[0221] Step 501: Receive the seventh information sent by the second node, the second node belongs to the first domain, the first domain contains N service nodes, N is an integer greater than or equal to 1, and the seventh information contains relevant information of the first domain;

[0222] Step 502: Receive the ninth message sent by the first server, the ninth message containing relevant information about the second domain to which the first server belongs;

[0223] Step 503: Using the seventh and ninth information, determine that the security levels of the first domain and the second domain are different, and send the eighth information to the second node and the first server. The eighth information is used to instruct the second node and / or the second server to perform security processing on the data; and perform data security processing authentication.

[0224] In practical application, the second server can receive information related to the first domain sent by the second node, and simultaneously, it can receive information related to the second domain sent by the first server. Thus, in step 503, the second server can determine whether the security levels of the first and second domains are the same by comparing the information related to the first and second domains. Specifically, the information related to the first domain may include the domain identifier of the first domain, which the second server can use to determine the security level of the first domain; similarly, the information related to the second domain may include the server identifier of the first server, which the second server can use to determine the security level of the second domain.

[0225] When the security levels of the first domain and the second domain are the same, the second server can determine that no security processing is required, and the first server and the second node can directly perform service authentication. When the security levels of the first domain and the second domain are different, the second server can determine, based on the security levels of the first domain and the second domain, that the second node and / or the first server need to perform security processing on the data. Therefore, in step 503, the second server can send the eighth message to the second node and the first server, instructing the second node and / or the second server that security processing on the data is required.

[0226] After receiving the eighth message sent by the second server, the second node and the second server can use the eighth message to determine whether the second node and / or the first server will perform security processing on the data, and perform authentication related to the security processing with the second server; wherein, depending on the object of the security processing, there are the following two cases:

[0227] In the first case, the eighth information is at least used to indicate that the second node needs to perform security processing on the data. In this case, the second node can perform authentication related to security processing with the second server and the first server through the security gateway.

[0228] Specifically, in one embodiment, the method may further include:

[0229] Send a first token to the second node so that the second node can use the first token to call the security gateway for security authentication.

[0230] Receive the first security processing authentication credential sent by the second node if the security processing authentication is successful;

[0231] A second credential is generated based on the first credential and associated with security processing authentication;

[0232] Send the second credential to the second node.

[0233] In practical application, after the second server determines that the second node needs to perform security processing on the data, the second server can determine, based on the security levels of the first and second domains, the data processing identifier that the second node needs to invoke in the security gateway. This data processing identifier corresponds to the data processing capability in at least one security gateway. The second server can then generate and send the first token to the second node.

[0234] After receiving the first token, the second node can invoke the security gateway to perform security processing and authentication, and receive the first credential sent by the security gateway. The second node can then send the received first credential to the second server to inform the second server that the second node has completed the security processing of the data.

[0235] Upon receiving the first credential sent by the second node, the second server can use the first credential to verify the security gateway signature invoked by the second node and the node identifier of the second node, etc., to determine whether the second node has indeed completed the security processing. If it is determined that the second node has indeed completed the security processing, the second server generates and sends the second credential to the second node.

[0236] In the second scenario, the eighth piece of information is at least used to indicate to the first server that it needs to perform security processing on the data. In this case, the first server can perform authentication related to security processing with the second server and the second node through a security gateway.

[0237] Specifically, in one embodiment, the method may further include:

[0238] Send a second token to the first server so that the first server can use the second token to invoke the security gateway for security authentication.

[0239] Receive the fourth security authentication credential sent by the first server if the security authentication is successful.

[0240] A third credential is generated based on the fourth credential and associated with security processing authentication;

[0241] Send the third credential to the first server.

[0242] In practical application, after the second server determines that the first server needs to perform security processing on the data, the second server can determine, based on the security levels of the first and second domains, the data processing identifier that the first server needs to invoke in the security gateway. This data processing identifier corresponds to at least one data processing capability in the security gateway. The second server can then generate and send the second token to the first server.

[0243] After receiving the second token, the first server can invoke the security gateway to perform security authentication and receive the fourth credential sent by the security gateway. The first server can then send the received fourth credential to the second server to inform the second server that the first server has completed the security processing of the data.

[0244] Upon receiving the first credential from the first server, the second server can use the fourth credential to verify the security gateway signature invoked by the first server and the server identifier of the first server, thereby determining whether the first server has indeed completed the security processing. If it is determined that the first server has indeed completed the security processing, the second server generates and sends the third credential to the first server.

[0245] This application also provides an authentication method, such as... Figure 6 As shown, the method includes:

[0246] Step 601: The first node sends first information to the KDC. The first information is used to request service authorization for N service nodes in the first domain. The first node belongs to the first domain, and the first domain contains N service nodes, where N is an integer greater than or equal to 1.

[0247] Step 602: After receiving the first information sent by the first node, KDC authenticates the N service nodes of the first domain by interacting with the first node.

[0248] Step 603: After successful authentication, KDC sends second information to the first node. The second information indicates that authorization is complete. The second information includes a first key and third information. The first key includes the first domain as a session key between the first client and the first server. The third information represents the credentials for authorized access associated with the first client and the first server.

[0249] Step 604: After receiving the second information sent by KDC, the first node sends the first key and the third information to the other service nodes among the N service nodes, excluding the first node. The third information is used at least for service authentication with the first server.

[0250] In one embodiment, the method may further include:

[0251] After receiving the first key and third information sent by the first node, the second node among the N service nodes sends the fifth information to the first server and the seventh information to the second server. The fifth information is used to request the first server to authenticate the second node. The fifth information includes authentication information encrypted with the first key and the third information. The second server is used at least to perform data security processing authentication when the security levels of the first domain and the second domain to which the first server belongs are different. The seventh information includes relevant information of the first domain.

[0252] The first server receives the fifth message sent by the second node and sends the ninth message to the second server, the ninth message containing relevant information about the second domain to which the first server belongs;

[0253] The second server uses the received seventh and ninth information to determine that the security levels of the first domain and the second domain are different, and sends the eighth information to the second node and the first server. The eighth information is used to instruct the second node and / or the second server to perform security processing on the data.

[0254] After receiving the eighth message sent by the second server, the second node, the first server, and the second server perform data security processing and authentication.

[0255] After the data security processing authentication is passed, the first server performs service authentication on the second node and obtains the service authentication result;

[0256] The second node receives the sixth information sent by the first server, the sixth information including the service authentication result.

[0257] It should be noted that the specific processing procedures for the first node, KDC, second node, first server, and second server have been detailed above and will not be repeated here.

[0258] The authentication method provided in this application embodiment involves a first node sending first information to a KDC (Knowledge Distribution Center). This first information requests service authorization for N service nodes in a first domain. The first node belongs to the first domain, which contains N service nodes, where N is an integer greater than or equal to 1. After receiving the first information from the first node, the KDC authenticates the N service nodes in the first domain through interaction with the first node. Upon successful authentication, the KDC sends second information to the first node. This second information indicates that authorization is complete. The second information includes a first key and third information. The first key contains a session key between the first client and the first server, and the third information represents a credential for authorized access associated with the first client and the first server. After receiving the second information from the KDC, the first node sends the first key and the third information to the other N service nodes besides the first node. The third information is used at least for service authentication with the first server. The solution provided in this application embodiment allows the first node in the first domain to request service authorization from the KDC for all service nodes within the first domain. In this way, the KDC only needs to authenticate the identity of the first domain as the first client to authorize services for all service nodes, without needing to authenticate the identity of each service node in the first domain, thus improving authentication efficiency and reducing authentication overhead.

[0259] The following section provides a more detailed description of this application with reference to application examples.

[0260] The ubiquitous and multi-source nature of nodes in computing networks increases the security risks associated with data transfer between different computing resources. Communication between ubiquitous nodes can be compromised by issues such as node spoofing, potentially leading to data leaks.

[0261] Based on this, this application example proposes a Kerberos-based multi-trust domain authentication method, which is applied in computing power networks, such as... Figure 7The computing network system using this method can specifically include: a security gateway, a data processing authentication server (i.e., the second server mentioned above), a KDC, cluster 1 (i.e., the first domain mentioned above), and cluster 2 (i.e., the second domain mentioned above). The KDC mainly includes: an authentication server (AS) for providing authentication services, a ticket granting server (TGS) for providing ticket granting services, etc., and the AS and TGS can be deployed on the same device or two different devices; cluster 1 and cluster 2 contain at least one node (i.e., the service node mentioned above); cluster 1 contains a security management node 1 (i.e., the first node mentioned above), responsible for authentication management of cluster 1; cluster 2 contains a security management node 2, responsible for authentication management of cluster 2; cluster 1 and cluster 2 have different security levels.

[0262] Based on the above system, the service authentication process can include two parts: inter-domain authentication and authorization, and service request. Specifically, when different security domains need to conduct business interactions, Kerberos authentication is first established on a per-security-domain basis to obtain service authorization. Then, during service execution, node A in the domain initiates a specific service request to complete the service.

[0263] In network service interactions, the cluster initiating the service request (e.g., cluster 1) can be called the client, and the cluster responding to the service request (e.g., cluster 2) can be called the server. Before service authentication, the security gateway can generate a domain identifier (e.g., domainID) for each domain and inform the security management node of each domain. Each domain's security management node can then assign a node identifier (e.g., nodeid) to each node in the domain according to preset rules. For ease of description, in the following description, domainID will be used to represent the domain identifier, and nodeid will be used to represent the node identifier.

[0264] like Figure 8 As shown, the process of inter-domain authentication and authorization between the Client and the Server includes the following steps:

[0265] Step 801: The Client security management node sends a service request to the AS;

[0266] In practical applications, the security management node in the Client (i.e., the first node mentioned above) requests service information from the AS. This can also be understood as the security management node authorizing each node in the Client that can participate in the service to apply for the services. The service request information may include a client identifier (such as ClientID). For example, the service request information may specifically be a plaintext message, such as "User Sunny, including N nodes, wants to request services".

[0267] The ClientID may specifically include: the domain ID of the security domain corresponding to the Client, and the services that each participating node in the Client can apply for (i.e., the fourth information mentioned above). The specific format may include:

[0268] {domainID,sign1(service1,service2,...service n ),..sign nodeid (service1,service2,...service) n )}

[0269] Where nodeid represents the node number (i.e., node identifier) ​​corresponding to the node, service n The sign represents the service number (i.e., service identifier, such as serviceid) corresponding to the nth available service. nodeid () indicates that the private key of nodeid is used for signing.

[0270] Step 801: AS receives the service request information, authenticates the ClientID contained in the service request information, and after successful authentication, sends message A and message B to the Client security management node;

[0271] Message A may include a Client-TGS session key (hereinafter referred to as K_clientTGS-session, which is the key assigned by AS to the Client for the Client to conduct a session with TGS) encrypted using the Client key (hereinafter referred to as K-Client). Message A can be specifically expressed as {K-client(TGS-session)}.

[0272] Message B may include a Ticket Granting Ticket (TGT) encrypted using the TGS key (hereinafter referred to as K_TGS). The TGT may specifically include K_clientTGS-session, ClientID, user URL, TGT validity period, etc. Message B can be specifically expressed as {K_TGS(TGT)}.

[0273] In practical applications, the specific implementation of AS authenticating the ClientID contained in the requested service information may include: checking whether the domainID contained in the ClientID is consistent with the domainID recorded in the AS (which can also be understood as correct or valid). If the domainID contained in the ClientID is consistent with the domainID recorded in the AS, the AS can consider the identity of the Client security management node to be correct, that is, the authentication is successful; if the domainID contained in the ClientID is inconsistent with the domainID recorded in the AS, the AS can consider the identity of the Client security management node to be incorrect, and the Client security management node may have been impersonated, that is, the authentication fails.

[0274] Step 803: The Client security management node decrypts the received message A to obtain K_clientTGS-session;

[0275] In practical applications, the Client security management node can use the Client's own key (hereinafter referred to as K_client) to decrypt message A.

[0276] Step 804: The Client security management node sends message C and message D to the TGS;

[0277] Specifically, message C (i.e., the tenth information mentioned above) may include message B and the serviceid of the service to be obtained;

[0278] Message D may specifically include an authentication token encrypted using K_clientTGS-session, and the authentication token may specifically include ClientID and timestamp.

[0279] Step 805: TGS uses messages C and D to return messages E and F to the Client security management node;

[0280] In practical applications, TGS can use K_TGS to decrypt message B in message C to obtain TGT, thereby obtaining K_clientTGS-session provided by AS; TGS can then use K_clientTGS-session to decrypt message D to obtain ClientID (i.e., complete Client authentication). After obtaining ClientID, TGS can send messages E and F to the Client security management node.

[0281] Specifically, message E may include a Client-Server ticket (such as a Ticket, i.e., the third information mentioned above) encrypted using the server key (hereinafter referred to as K_Server) of the server corresponding to serviceid (i.e., the first server mentioned above). The Ticket may specifically include: Client ID, user URL, Client-Server session key (hereinafter referred to as K_clientServer-session, i.e., the first key mentioned above), and Ticket validity period.

[0282] Message F may specifically include a K_clientServer-session encrypted using K_clientTGS-session.

[0283] Step 806: The Client security management node decrypts message F and sends messages a and E to all nodes in the Client that are participating in the service.

[0284] In practical applications, the Client security management node can decrypt message F using K_clientTGS-session to obtain K_clientServer-session, and then send messages a and E to all nodes in the Client that participated in this service request, except for the Client security management node itself. Of course, the Client security management node itself can also participate in this service request.

[0285] For example, message a sent to node 1 may specifically include node 1's nodeid and K_clientServer-session encrypted using node 1's key (hereinafter referred to as Knode1, i.e., the key of the aforementioned service node).

[0286] As can be seen from the above description, the Client security management node only needs to authenticate with the KDC once to complete the authentication of multiple nodes in the Client. It can achieve mutual authentication between trust domains of different security levels (i.e., domain-to-domain authentication), and a single authentication can satisfy multiple service requests from multiple nodes in the Client.

[0287] like Figure 9 As shown, the process of node 1 (i.e., the second node mentioned above) in the Client making a service request to the Server includes the following steps:

[0288] Step 900: The Client security management node sends message a and message E to node 1 in the Client that is participating in the service;

[0289] In practical applications, the specific implementation of step 900 can be understood with reference to step 806, and will not be repeated here.

[0290] Step 901: Node 1 receives message a and message E sent by the Client security management node, and decrypts message a;

[0291] In practical applications, node 1 can use Knode1 to decrypt message a and obtain K_clientServer-session.

[0292] Step 902: Node 1 sends message b to the data processing authentication server, and sends message c and message E to the Server;

[0293] Specifically, message b may include the domainID, nodeid, and serviceid corresponding to the service requested by node 1. Message b can be specifically represented as {domainID, nodeid, serviceid}.

[0294] Message c can specifically include a "new authentication token" encrypted with K_clientServer_session. This new authentication token can specifically include: the nodeid corresponding to node 1, the serviceid corresponding to the service requested by node 1, and a timestamp. Message c can be specifically represented as {K_clientServer_session(nodeid, serviceid, timestamp)}.

[0295] Step 903: The Server decrypts the received messages E and c to verify the identity of node 1;

[0296] In practical applications, the server can use K_Server to decrypt message E to obtain the Ticket, and then obtain the K_clientServer_session and ClientID provided by TGS contained in the Ticket. The server can then use K_clientServer_session to decrypt message c to obtain the nodeid and timestamp corresponding to node 1.

[0297] After obtaining the nodeid, the server can use the public key of node1's nodeid to sign the node in the ClientID in message E (i.e., sign). nodeidThe server performs verification to determine whether the first node sending message c belongs to the node indicated in message E that has undergone inter-domain authentication and authorization. If the signature verification of the node in ClientID is successful (which can also be understood as successful signature verification), the server can compare the serviceid of the node that can apply for services contained in ClientID with the serviceid in message c. If the serviceids match (i.e., the serviceid in message c belongs to the serviceid that can apply for services), it means that the server can provide services to node 1.

[0298] Step 904: The Server sends message d to the data processing authentication server;

[0299] Specifically, message d may include the server identifier (e.g., ServerID) corresponding to Server, the domainID corresponding to Node1, the nodeid corresponding to Node1, and the serviceid of the service requested by Node1. Message d can be specifically expressed as {ServerID, domainID, nodeid, serviceid}.

[0300] Step 905: The data processing authentication server receives messages b and d and performs security processing requirement analysis;

[0301] In practical applications, the data processing authentication server uses messages b and d to determine the security domain level of node 1 (i.e., security can also be understood as analyzing which data processing capability in the security gateway needs to be used for data security processing), the server security domain level, the type of service requested by node 1, and analyze the type of data security processing required.

[0302] For example, if the domain corresponding to Server has a high security level and the domain of Node 1 has a low security level, when Node 1 requests to read data from Server, Server needs to perform data anonymization processing first. If the domain of Node 1 has a high security level and the domain corresponding to Server has a low security level, when Node 1 wants to transfer data to Server for storage, Node 1 needs to perform data anonymization processing. In this way, data leakage can be effectively avoided.

[0303] Step 906: The data processing authentication server sends message e (i.e., the eighth message mentioned above) to Node 1 and Server;

[0304] The message e includes the nodeid corresponding to node 1 that needs to perform data security processing, and / or the ServerID corresponding to server that needs to perform data security processing, and the type of data processing required (such as dataprocessid). The data processing authentication server notifies both parties in the service interaction (i.e., node 1 and server) that data security processing is required first by sending message e.

[0305] Step 907: After receiving message e, Node 1 and Server perform data security processing with the data processing authentication server;

[0306] In practical applications, Node 1 and Server can use message e to determine which party or both parties need to perform security processing, and perform data security processing by calling the security gateway's capabilities.

[0307] For example, assuming message e indicates that node 1 needs to perform security processing, the data processing authentication server can issue a capability invocation token (i.e., the first token mentioned above) to node 1. The token may specifically include the nodeid of node 1 signed by the data processing authentication server, the symmetric key of the dataprocessid to be invoked (hereinafter referred to as SKdpid), and a timestamp. After receiving the token, node 1 can use it to request capability invocation from the security gateway. The security gateway verifies the signature of the data processing authentication server in the token (hereinafter referred to as sign). DA Upon successful verification, the security gateway uses the SKdpid to locate the required processing capabilities and provides a calling interface to Node 1. Node 1 performs data security processing through the interface provided by the security gateway. After confirming the completion of processing, the security gateway issues a processing credential (i.e., the first credential mentioned above) to Node 1. The processing credential may include the nodeid of Node 1 signed by the security gateway, the dataprocessid to be called, and a new timestamp (specifically, it may include the timestamp in the token incremented by 1). Node 1 can send the received processing credential to the data processing authentication server. The data processing authentication server signs the security gateway in the processing credential (hereinafter referred to as sign). gw The token is verified using the nodeid, dataprocessid, and new timestamp to determine whether node 1 has indeed performed the security procedures instructed by the data processing authentication server. Specifically, the token can be represented as token{sign}. DA (nodeid, Skdpid, timestamp)}, processing credentials can be specifically expressed as Cert{sign gw (nodeid,dataprocessid,timestamp)}

[0308] The following explanation is based on the object undergoing security processing, and is divided into two cases:

[0309] Under the condition that node 1 performs security procedures:

[0310] Step 908a: The data processing authentication server sends message f (i.e., the second credential mentioned above) to node 1;

[0311] In practical applications, the data processing authentication server verifies the processing credentials sent by node 1. After successful verification, it can send message f to node 1 to inform node 1 that the authentication of the security processing is complete, that is, the data processing authentication server acknowledges that node 1 has completed the security processing.

[0312] At this point, message f can specifically include the message obtained after the data processing authentication server signs the nodeid and dataprocessid, adds a timestamp, and then encrypts it using Knode1. Here, the timestamp is used for time-related verification, such as network packet loss and latency. Message f can be specifically expressed as {Knode1(sign DA (nodeid, dataprocessid)), timestamp)}.

[0313] Step 909a: Node 1 sends message g to the Server;

[0314] In practical applications, node 1 can decrypt the received message f, obtain the decryption result, and then use K_Server to encrypt the decryption result to obtain message g. Message g can be specifically represented as {K_Server(signDA(nodeid, dataprocessid))}.

[0315] Step 910a: The Server decrypts the received message g and verifies the signature of the data processing authentication server;

[0316] In practical applications, the server can verify the signature of the authentication server in the data processing of message g. If the verification is successful, the server can determine that node 1 has completed the security processing and can respond to the service request of node 1.

[0317] Step 911a: Server sends message h to node 1;

[0318] Specifically, message h may include a new timestamp encrypted with K_clientServer_session, and the new timestamp may include the timestamp in message c plus 1.

[0319] Step 912a: Node 1 verifies the identity of the Server using message h.

[0320] In practical applications, Node 1 can use K_clientServer_session to decrypt message h, obtain a new timestamp, and then determine whether the new timestamp is equal to the timestamp in message c plus 1, thereby verifying the server's identity. Specifically, if the result is equal, Node 1 can consider that the server that sent message h is the server that received message c, achieving two-way authentication between Node 1 and the server; if the result is not equal, Node 1 can consider that the server that sent message h is not the server that received message c, and the server may have been impersonated.

[0321] Under server-side security measures:

[0322] Step 908b: The data processing authentication server sends message f (i.e., the aforementioned third credential) to the Server;

[0323] In practical applications, the data processing authentication server verifies the processing credentials sent by the server (i.e., the fourth credential mentioned above). After successful verification, it can send message f to the server to inform the server that the authentication of the security processing is complete, that is, the data processing authentication server acknowledges that the server has completed the security processing.

[0324] At this point, message f can specifically include the message obtained after the data processing authentication server signs ServerID and dataprocessid, adds a timestamp, and encrypts it using K_Server. Message f can be specifically expressed as {K_Server(sign DA (ServerID, dataprocessid)), timestamp)}.

[0325] In practical applications, if node 1 does not require security processing, the server, upon receiving message f, can respond to node 1's service request and begin service interaction. This ensures secure data processing when services are provided between different security domains.

[0326] Step 909b: Server sends message h to node 1;

[0327] Specifically, message h may include the encrypted "new timestamp" of K_clientServer_session, as well as relevant information on the server's security processing.

[0328] In practical applications, the server can decrypt the received message f, obtain the decryption result, and use Knode1 to encrypt the decryption result to obtain the relevant information in message h that the server performs security processing.

[0329] Step 910b: Node 1 verifies the identity of the Server using message h.

[0330] In practical applications, Node 1 can use Knode1 to decrypt the information related to the security processing of the Server in message h, and can verify the signature of the data processing authentication server in the information related to the security processing of the Server. If the verification is successful, Node 1 can determine that the Server has completed the security processing, and Node 1 can carry out service interaction with the Server.

[0331] Meanwhile, Node 1 can use K_clientServer_session to decrypt the portion of message h corresponding to the new timestamp, obtain the new timestamp, and then determine whether the new timestamp is equal to the timestamp in message c plus 1, thereby verifying the server's identity. Specifically, if the determination result is equal, Node 1 can consider that the server that sent message h is the server that received message c, achieving two-way authentication between Node 1 and the server; if the determination result is not equal, Node 1 can consider that the server that sent message h is not the server that received message c, and the server may have been impersonated.

[0332] The solution provided in this application example implements trust domain-level security authentication based on the Kerberos protocol. Service authentication is performed on a trust domain basis. After one authentication is completed, multiple nodes participating in the service within the domain can connect to provide services, improving authentication efficiency and enhancing the security of data interaction between nodes from different sources on the computing network, thus preventing impersonating nodes from stealing data.

[0333] Meanwhile, a data security processing authentication step is added to the authentication process. A call token is constructed through the data processing authentication server. Nodes use the token to call the security gateway for processing and generate authentication credentials. This enables data security processing authentication between different security domains. When authenticating between different domains, the data gateway must be called for data processing. Authentication can only be achieved after data security processing, and only then can normal service interaction be carried out. This saves construction costs, avoids bypassing behavior, and reduces the risk of sensitive data leakage.

[0334] To implement the method on the first node side of this application embodiment, this application embodiment also provides an authentication device, which is set on the first node. The first node belongs to a first domain, and the first domain contains N service nodes, where N is an integer greater than or equal to 1. Figure 10 As shown, the device includes:

[0335] The first sending unit 1001 is configured to send first information to the KDC, the first information being used to request service authorization for N service nodes in the first domain; and to send a first key and third information to the N service nodes, the third information being used at least for service authentication with the first server.

[0336] The first receiving unit 1002 is configured to receive second information sent by the KDC, the second information indicating that authorization is completed, the second information including the first key and third information, the first key including the first domain as a session key between the first client and the first server, and the third information representing the authorized access credentials associated with the first client and the first server.

[0337] In one embodiment, the first transmitting unit 1001 is further configured to:

[0338] For one of the N service nodes other than the first node, encrypt the first key using the key of the service node;

[0339] Send the encrypted first key to the service node.

[0340] In practical applications, the first sending unit 1001 and the first receiving unit 1002 can be implemented by the processor in the authentication device in combination with the communication interface.

[0341] To implement the KDC-side method of this application embodiment, this application embodiment also provides an authentication device, which is installed on the KDC, such as... Figure 11 As shown, the device includes:

[0342] The second receiving unit 1101 is used to receive first information sent by the first node, the first node belongs to the first domain, the first domain contains N service nodes, and the first information is used to request service authorization for the N service nodes of the first domain, where N is an integer greater than or equal to 1.

[0343] The first authentication unit 1102 is used to authenticate N service nodes of the first domain by interacting with the first node.

[0344] The second sending unit 1103 is used to send second information to the first node after authentication is successful. The second information indicates that authorization is completed. The second information includes a first key and third information. The first key includes the first domain as a session key between the first client and the first server. The third information represents the credentials for authorized access associated with the first client and the first server.

[0345] In practical applications, the second receiving unit 1101 and the second sending unit 1103 can be implemented by the communication interface in the authentication device, and the first authentication unit 1102 can be implemented by the processor in the authentication device.

[0346] To implement the method on the second node side of this application embodiment, this application embodiment also provides an authentication device, which is set on the second node. The second node includes one of the N service nodes included in the first domain, where N is an integer greater than or equal to 1. Figure 12 As shown, the device includes:

[0347] The third receiving unit 1201 is configured to receive a first key and third information sent by a first node, wherein the first node belongs to the first domain, the first key contains the first domain as a session key between the first client and the first server, and the third information represents an authorized access credential associated with the first client and the first server, and the third information is used at least for service authentication with the first server; and to receive a sixth information sent by the first server, wherein the sixth information contains a service authentication result.

[0348] The third sending unit 1202 is used to send fifth information to the first server. The fifth information is used to request the first server to perform service authentication on the second node. The fifth information includes authentication information encrypted with the first key and third information.

[0349] In one embodiment, the third receiving unit 1201 is further configured to:

[0350] A seventh message is sent to a second server, which is used at least to perform data security processing authentication when the security levels of the first domain and the second domain to which the first server belongs are different. The seventh message contains relevant information about the first domain.

[0351] Receive the eighth message sent by the second server, the eighth message being used to instruct the second node and / or the first server to perform security processing on the data;

[0352] The device may also include:

[0353] The fourth authentication unit is used for: performing authentication related to security processing with the second server and the first server.

[0354] In one embodiment, when the eighth information is used at least to indicate that the second node needs to perform security processing on the data, the fourth authentication unit is specifically used for:

[0355] Receive the first token sent by the second server;

[0356] The first token is used to invoke the security gateway for security processing and authentication.

[0357] If the security processing authentication is successful, the first security processing authentication credential is sent to the second server;

[0358] Receive a second credential associated with security processing authentication sent by the second server, the second credential being generated based on the first credential;

[0359] Service authentication is performed with the first server based on the second credential.

[0360] In one embodiment, when the eighth information is used at least to indicate to the first server that data security processing is required, the fourth authentication unit is specifically used for:

[0361] Service authentication is performed between the second server and the first server based on a third credential; wherein the third credential is generated by the second server for the first server based on a fourth credential, and the fourth credential is sent by the security gateway after the first server has passed security processing authentication.

[0362] In practical applications, the third receiving unit 1201 and the third sending unit 1202 can be implemented by the communication interface in the authentication device, and the fourth authentication unit can be implemented by the processor in the authentication device.

[0363] To implement the method on the first server side of this application embodiment, this application embodiment also provides an authentication device, which is set on the first server, such as... Figure 13 As shown, the device includes:

[0364] The fourth receiving unit 1301 is used to receive fifth information sent by the second node, wherein the second node includes one of the N service nodes contained in the first domain, where N is an integer greater than or equal to 1, the fifth information is used to request the first server to perform service authentication on the second node, the fifth information includes authentication information encrypted with a first key and third information, the first key includes the first domain as a session key between the first client and the first server, the third information represents the authorized access credentials associated with the first client and the first server, and the third information is used at least for service authentication with the second node;

[0365] The second authentication unit 1302 is used to perform service authentication on the second node and obtain the service authentication result;

[0366] The fourth sending unit 1303 is used to send sixth information to the second node, the sixth information including the service authentication result.

[0367] In one embodiment, the fourth transmitting unit 1303 is further configured to:

[0368] Send a ninth message to a second server, the ninth message containing relevant information about the second domain to which the first server belongs, the second server being used at least to perform data security processing authentication when the security levels of the first domain and the second domain are different;

[0369] The fourth receiving unit 1301 is further configured to:

[0370] Receive the eighth message sent by the second server, the eighth message being used to instruct the second node and / or the second server to perform security processing on the data;

[0371] The second authentication unit 1302 is further configured to:

[0372] Authentication related to security processing is performed with the second server and the second node.

[0373] In one embodiment, when the eighth information is used at least to indicate that the first server needs to perform security processing on the data, the fourth receiving unit 1301 is further configured to:

[0374] Receive a second token sent by the second server; receive a third credential sent by the second server that is associated with security processing authentication, the third credential being generated based on the fourth credential;

[0375] The fourth transmitting unit 1303 is further configured to:

[0376] If the security processing authentication is successful, a fourth security processing authentication credential is sent to the second server;

[0377] The second authentication unit 1302 is further configured to:

[0378] The second token is used to invoke the security gateway for security processing and authentication; the third credential is used to authenticate the service with the second node.

[0379] In one embodiment, when the eighth information is used at least to indicate that the second node needs to perform security processing on the data, the second authentication unit 1302 is further configured to:

[0380] Authentication is performed between the second server and the second node based on the second credential; wherein the second credential is generated by the second server for the first server based on the first credential, and the first credential is sent by the security gateway after the second node has passed security processing authentication.

[0381] In practical applications, the fourth receiving unit 1301 and the fourth sending unit 1303 can be implemented by the communication interface in the authentication device, and the second authentication unit 1302 can be implemented by the processor in the authentication device.

[0382] To implement the method on the second server side of this application embodiment, this application embodiment also provides an authentication device, which is set on the second server, such as... Figure 14 As shown, the device includes:

[0383] The fifth receiving unit 1401 is used to receive the seventh information sent by the second node, the second node belonging to the first domain, the first domain containing N service nodes, where N is an integer greater than or equal to 1, and the seventh information containing relevant information of the first domain; and to receive the ninth information sent by the first server, the ninth information containing relevant information of the second domain to which the first server belongs.

[0384] The determining unit 1402 is used to determine, using the seventh information and the ninth information, that the security levels of the first domain and the second domain are different.

[0385] The fifth sending unit 1403 is used to send eighth information to the second node and the first server, the eighth information being used to instruct the second node and / or the second server to perform security processing on the data;

[0386] The third authentication unit 1404 is used for data security processing authentication.

[0387] In one embodiment, when the eighth information is used at least to indicate that the second node needs to perform security processing on the data, the fifth sending unit 1403 is further configured to:

[0388] Send a first token to the second node so that the second node can use the first token to invoke the security gateway for security authentication; send a second credential to the second node;

[0389] The fifth receiving unit 1401 is further configured to:

[0390] Receive the first security processing authentication credential sent by the second node if the security processing authentication is successful;

[0391] The third authentication unit 1404 is also used for:

[0392] A second credential is generated based on the first credential and associated with security processing authentication.

[0393] In one embodiment, when the eighth information is used at least to indicate to the first server that data security processing is required, the fifth sending unit 1403 is further configured to:

[0394] Send a second token to the first server so that the first server can use the second token to invoke the security gateway for security authentication; send a third credential to the first server;

[0395] The fifth receiving unit 1401 is further configured to:

[0396] Receive the fourth security authentication credential sent by the first server if the security authentication is successful.

[0397] The third authentication unit 1404 is also used for:

[0398] A third credential is generated based on the fourth credential and associated with security processing authentication.

[0399] In practical applications, the fifth receiving unit 1401 and the fifth sending unit 1403 can be implemented by the communication interface in the authentication device, and the determining unit 1402 and the third authentication unit 1404 can be implemented by the processor in the authentication device.

[0400] It should be noted that the authentication device provided in the above embodiments is only illustrated by the division of the above-described program units. In practical applications, the above processing can be assigned to different program units as needed, that is, the internal structure of the device can be divided into different program units to complete all or part of the processing described above. In addition, the authentication device and authentication method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.

[0401] Based on the hardware implementation of the above program modules, and in order to implement the method on the first node side of the embodiments of this application, the embodiments of this application also provide a first node, such as... Figure 15 As shown, the first node 1500 includes:

[0402] The first communication interface 1501 is capable of exchanging information with other devices;

[0403] The first processor 1502 is connected to the first communication interface 1501 to enable information interaction with other devices and to execute the methods provided by one or more technical solutions on the first node side when running a computer program.

[0404] The computer program is stored in the first memory 1503.

[0405] Specifically, the first communication interface 1501 is used for:

[0406] Send a first message to the Key Distribution Center (KDC), the first message being used to request service authorization for N service nodes of the first domain; receive a second message sent by the KDC, the second message indicating that authorization is complete, the second message containing a first key and third information, the first key containing the first domain as a session key between the first client and the first server, the third information representing the authorized access credentials associated with the first client and the first server; send the first key and the third information to the other service nodes among the N service nodes besides the first node, the third information being used at least for service authentication with the first server.

[0407] In one embodiment, the first processor 1502 is used for

[0408] For one of the N service nodes other than the first node, encrypt the first key using the key of the service node;

[0409] The first communication interface 1501 is also used for:

[0410] Send the encrypted first key to the service node.

[0411] It should be noted that the specific processing procedures of the first processor 1502 and the first communication interface 1501 can be understood by referring to the above method.

[0412] Of course, in practical applications, the various components in the first node 1500 are coupled together through the bus system 1504. It can be understood that the bus system 1504 is used to implement communication between these components. In addition to the data bus, the bus system 1504 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 15 The general labeled all buses as Bus System 1504.

[0413] The first memory 1503 in this embodiment is used to store various types of data to support the operation of the first node 1500. Examples of such data include any computer program used to operate on the first node 1500.

[0414] The methods disclosed in the embodiments of this application can be applied to the first processor 1502, or implemented by the first processor 1502. The first processor 1502 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware or by instructions in the form of software in the first processor 1502. The first processor 1502 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 1502 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly reflected as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the first memory 1503. The first processor 1502 reads the information in the first memory 1503 and completes the steps of the aforementioned method in conjunction with its hardware.

[0415] In an exemplary embodiment, the first node 1500 may be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to perform the aforementioned method.

[0416] Based on the hardware implementation of the above program modules, and in order to implement the KDC-side method of the embodiments of this application, the embodiments of this application also provide a KDC, such as... Figure 16 As shown, the KDC1600 includes:

[0417] The second communication interface 1601 is capable of exchanging information with other devices;

[0418] The second processor 1602 is connected to the second communication interface 1601 to enable information interaction with other devices and to execute the methods provided by one or more technical solutions on the KDC side when running computer programs.

[0419] The computer program is stored in the second memory 1603.

[0420] Specifically, the second communication interface 1601 is used for:

[0421] The system receives first information from a first node, which belongs to a first domain and contains N service nodes. The first information is used to request service authorization from the N service nodes in the first domain, where N is an integer greater than or equal to 1. After successful authentication, the system sends second information to the first node, which indicates that authorization is complete. The second information includes a first key and third information. The first key contains the first domain as a session key between the first client and the first server, and the third information represents the credentials for authorized access associated with the first client and the first server.

[0422] The second processor 1602 is used for:

[0423] The second communication interface 1601 is used to interact with the first node to authenticate the N service nodes of the first domain.

[0424] It should be noted that the specific processing procedures of the second processor 1602 and the second communication interface 1601 can be understood by referring to the above method.

[0425] Of course, in practical applications, the various components in the KDC1600 are coupled together through the bus system 1604. It can be understood that the bus system 1604 is used to implement communication between these components. In addition to the data bus, the bus system 1604 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 16 The general labeled all buses as Bus System 1604.

[0426] The second memory 1603 in this embodiment is used to store various types of data to support the operation of the KDC1600. Examples of such data include any computer program used to operate on the KDC1600.

[0427] The methods disclosed in the embodiments of this application can be applied to the second processor 1602, or implemented by the second processor 1602. The second processor 1602 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware or by instructions in the form of software in the second processor 1602. The second processor 1602 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The second processor 1602 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the second memory 1603. The second processor 1602 reads the information in the second memory 1603 and completes the steps of the aforementioned method in conjunction with its hardware.

[0428] In an exemplary embodiment, the KDC1600 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0429] Based on the hardware implementation of the above program modules, and in order to implement the method on the second node side of the embodiments of this application, the embodiments of this application also provide a second node, such as... Figure 17 As shown, the second node 1700 includes:

[0430] The third communication interface 1701 is capable of exchanging information with other devices;

[0431] The third processor 1702 is connected to the third communication interface 1701 to enable information interaction with other devices and to execute the methods provided by one or more technical solutions on the second node side when running computer programs.

[0432] The computer program is stored in the third memory 1703.

[0433] Specifically, the third communication interface 1701 is used for:

[0434] The system receives a first key and third information sent by a first node, wherein the first node belongs to the first domain, the first key contains the first domain as a session key between the first client and the first server, and the third information represents an authorized access credential associated with the first client and the first server, and the third information is used at least for service authentication with the first server; the system receives a sixth information sent by the first server, the sixth information containing a service authentication result; and the system sends a fifth information to the first server, the fifth information being used to request the first server to perform service authentication on the second node, the fifth information containing authentication information encrypted using the first key and the third information.

[0435] In one embodiment, the third communication interface 1701 is used for:

[0436] Send a seventh message to a second server, the second server being used at least to perform data security processing authentication when the security levels of the first domain and the second domain to which the first server belongs are different, the seventh message containing relevant information about the first domain; receive an eighth message sent by the second server, the eighth message being used to indicate that the second node and / or the first server need to perform security processing on the data;

[0437] The third processor 1702 is used for:

[0438] Authentication related to security processing is performed with the second server and the first server.

[0439] In one embodiment, when the eighth information is used at least to indicate that the second node needs to perform security processing on the data, the third processor 1702 is specifically used for:

[0440] The third communication interface 1701 is used to receive the first token sent by the second server;

[0441] The first token is used to invoke the security gateway for security processing and authentication.

[0442] If the security processing authentication is successful, the first security processing authentication credential is sent to the second server;

[0443] Receive a second credential associated with security processing authentication sent by the second server, the second credential being generated based on the first credential;

[0444] Service authentication is performed with the first server based on the second credential.

[0445] In one embodiment, when the eighth information is used at least to indicate to the first server that data security processing is required, the third processor 1702 is specifically used for:

[0446] Service authentication is performed between the second server and the first server based on a third credential; wherein the third credential is generated by the second server for the first server based on a fourth credential, and the fourth credential is sent by the security gateway after the first server has passed security processing authentication.

[0447] It should be noted that the specific processing procedures of the third processor 1702 and the third communication interface 1701 can be understood by referring to the above method.

[0448] Of course, in practical applications, the various components in the second node 1700 are coupled together through the bus system 1704. It can be understood that the bus system 1704 is used to implement communication between these components. In addition to the data bus, the bus system 1704 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 17 The general labeled all buses as Bus System 1704.

[0449] The third memory 1703 in this embodiment is used to store various types of data to support the operation of the second node 1700. Examples of such data include any computer program used to operate on the second node 1700.

[0450] The methods disclosed in the embodiments of this application can be applied to, or implemented by, the third processor 1702. The third processor 1702 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuitry of the hardware or by instructions in the software form of the third processor 1702. The third processor 1702 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The third processor 1702 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, specifically a third memory 1703. The third processor 1702 reads information from the third memory 1703 and, in conjunction with its hardware, completes the steps of the aforementioned method.

[0451] In an exemplary embodiment, the second node 1700 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0452] Based on the hardware implementation of the above program modules, and in order to implement the method on the first server side of the embodiments of this application, the embodiments of this application also provide a first server, such as... Figure 18 As shown, the first server 1800 includes:

[0453] The fourth communication interface 1801 enables information exchange with other devices;

[0454] The fourth processor 1802 is connected to the fourth communication interface 1801 to enable information interaction with other devices and to execute the methods provided by one or more technical solutions on the first server side when running computer programs.

[0455] The fourth memory 1803, on which the computer program is stored.

[0456] Specifically, the fourth communication interface 1801 is used for:

[0457] The system receives a fifth message from a second node, where the second node comprises one of N service nodes contained in the first domain, where N is an integer greater than or equal to 1. The fifth message is used to request the first server to authenticate the second node. The fifth message includes authentication information encrypted with a first key and third information. The first key contains the first domain as a session key between the first client and the first server. The third information represents the authorized access credentials associated with the first client and the first server. The third information is used at least for service authentication with the second node. The system then sends a sixth message to the second node, which contains the service authentication result.

[0458] The fourth processor 1802 is used for:

[0459] Perform service authentication on the second node to obtain the service authentication result.

[0460] In one embodiment, the fourth communication interface 1801 is further used for:

[0461] Send a ninth message to the second server, the ninth message containing relevant information about the second domain to which the first server belongs, the second server being used at least to perform data security processing authentication when the security levels of the first domain and the second domain are different; receive an eighth message sent by the second server, the eighth message being used to indicate that the second node and / or the second server need to perform security processing on the data;

[0462] The fourth processor 1802 is also used for:

[0463] Authentication related to security processing is performed with the second server and the second node.

[0464] In one embodiment, where the eighth information is at least used to indicate to the first server that data security processing is required, the fourth communication interface 1801 is further used to:

[0465] Receive a second token sent by the second server; receive a third credential associated with security processing authentication sent by the second server, the third credential being generated based on the fourth credential; if security processing authentication is successful, send the fourth credential of security processing authentication to the second server;

[0466] The fourth processor 1802 is also used for:

[0467] The second token is used to invoke the security gateway for security processing and authentication; the third credential is used to authenticate the service with the second node.

[0468] In one embodiment, where the eighth information is used at least to indicate that the second node needs to perform security processing on the data, the fourth processor 1802 is further configured to:

[0469] Authentication is performed between the second server and the second node based on the second credential; wherein the second credential is generated by the second server for the first server based on the first credential, and the first credential is sent by the security gateway after the second node has passed security processing authentication.

[0470] It should be noted that the specific processing procedures of the fourth processor 1802 and the fourth communication interface 1801 can be understood by referring to the above method.

[0471] Of course, in practical applications, the various components in the first server 1800 are coupled together via a bus system 1804. It can be understood that the bus system 1804 is used to implement communication between these components. In addition to a data bus, the bus system 1804 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 18The general labeled all buses as Bus System 1804.

[0472] The fourth memory 1803 in this embodiment is used to store various types of data to support the operation of the first server 1800. Examples of such data include any computer program used to operate on the first server 1800.

[0473] The methods disclosed in the embodiments of this application can be applied to, or implemented by, the fourth processor 1802. The fourth processor 1802 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuitry of the hardware or by instructions in the software form of the fourth processor 1802. The fourth processor 1802 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The fourth processor 1802 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, specifically a fourth memory 1803. The fourth processor 1802 reads information from the fourth memory 1803 and, in conjunction with its hardware, completes the steps of the aforementioned method.

[0474] In an exemplary embodiment, the first server 1800 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0475] Based on the hardware implementation of the above program modules, and in order to implement the method on the second server side of the embodiments of this application, the embodiments of this application also provide a second server, such as... Figure 19 As shown, the second server 1900 includes:

[0476] The fifth communication interface, 1901, enables information exchange with other devices;

[0477] The fifth processor 1902 is connected to the fifth communication interface 1901 to enable information interaction with other devices and to execute the methods provided by one or more technical solutions on the second server side when running computer programs.

[0478] The fifth memory 1903, on which the computer program is stored.

[0479] Specifically, the fifth communication interface 1901 is used for:

[0480] The system receives a seventh message from a second node, which belongs to a first domain. The first domain contains N service nodes, where N is an integer greater than or equal to 1. The seventh message contains relevant information about the first domain. The system also receives a ninth message from a first server, which contains relevant information about the second domain to which the first server belongs. Finally, the system sends an eighth message to the second node and the first server, which instructs the second node and / or the second server to perform security processing on the data.

[0481] The fifth processor 1902 is used for:

[0482] Using the seventh and ninth pieces of information, it is determined that the security levels of the first domain and the second domain are different; and data security processing and authentication are performed.

[0483] In one embodiment, where the eighth information is used at least to indicate that the second node needs to perform security processing on the data, the fifth communication interface 1901 is further used for:

[0484] Send a first token to the second node so that the second node can use the first token to invoke the security gateway for security processing authentication; receive the first security processing authentication credential sent by the second node if the security processing authentication is successful; send a second credential to the second node;

[0485] The fifth processor 1902 is also used for:

[0486] A second credential is generated based on the first credential and associated with security processing authentication.

[0487] In one embodiment, where the eighth information is at least used to indicate to the first server that data security processing is required, the fifth communication interface 1901 is further used to:

[0488] Send a second token to the first server so that the first server can use the second token to invoke the security gateway for security processing authentication; receive a fourth security processing authentication credential sent by the first server if the security processing authentication is successful; send a third credential to the first server;

[0489] The fifth processor 1902 is also used for:

[0490] A third credential is generated based on the fourth credential and associated with security processing authentication.

[0491] It should be noted that the specific processing procedures of the fifth processor 1902 and the fifth communication interface 1901 can be understood by referring to the above method.

[0492] Of course, in practical applications, the various components in the second server 1900 are coupled together via a bus system 1904. It can be understood that the bus system 1904 is used to implement communication between these components. In addition to a data bus, the bus system 1904 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 19 The general labeled all buses as Bus System 1904.

[0493] The fifth memory 1903 in this embodiment is used to store various types of data to support the operation of the second server 1900. Examples of such data include any computer program used to operate on the second server 1900.

[0494] The methods disclosed in the embodiments of this application can be applied to, or implemented by, the fifth processor 1902. The fifth processor 1902 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above method can be completed by the integrated logic circuitry of the hardware or by instructions in the form of software within the fifth processor 1902. The fifth processor 1902 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The fifth processor 1902 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly manifested as execution by a hardware decoding processor, or execution by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, specifically a fifth memory 1903. The fifth processor 1902 reads information from the fifth memory 1903 and, in conjunction with its hardware, completes the steps of the aforementioned method.

[0495] In an exemplary embodiment, the second server 1900 may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0496] It is understood that the memories (first memory 1503, second memory 1603, third memory 1703, fourth memory 1803, and fifth memory 1903) in the embodiments of this application can be volatile memories or non-volatile memories, or may include both volatile and non-volatile memories. Specifically, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk storage device or a magnetic tape storage device. Volatile memory can be random access memory (RAM), which is used as an external cache.By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM). The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memory.

[0497] In an exemplary embodiment, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, such as a first memory 1503 storing a computer program, which can be executed by a first processor 1502 of a first node 1500 to complete the steps described in the aforementioned first node-side method; another example is a second memory 1603 storing a computer program, which can be executed by a second processor 1602 of a KDC 1600 to complete the steps described in the aforementioned KDC-side method; yet another example is a third memory 1703 storing a computer program, which can be executed by a third processor 1702 of a second node 1700 to complete the steps described in the aforementioned second node-side method; yet another example is a fourth memory 1803 storing a computer program, which can be executed by a fourth processor 1802 of a first server 1800 to complete the steps described in the aforementioned first server-side method; and yet another example is a fifth memory 1903 storing a computer program, which can be executed by a fifth processor 1902 of a second server 1900 to complete the steps described in the aforementioned second server-side method. Computer-readable storage media can be FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.

[0498] In an exemplary embodiment, this application also provides a computer program product, including a computer program that can be executed by a first processor 1502 of a first node 1500 to complete the steps described in the aforementioned first node-side method; or, the computer program can be executed by a second processor 1602 of a KDC 1600 to complete the steps described in the aforementioned KDC-side method; or, the computer program can be executed by a third processor 1702 of a second node 1700 to complete the steps described in the aforementioned second node-side method; or, the computer program can be executed by a fourth processor 1802 of a first server 1800 to complete the steps described in the aforementioned first server-side method; or, the computer program can be executed by a fifth processor 1902 of a second server 1900 to complete the steps described in the aforementioned second server-side method.

[0499] To implement the methods of the embodiments of this application, the embodiments of this application also provide an authentication system, such as... Figure 20 As shown, the system includes: first node 2001, KDC 2002, second node 2003, first server 2004, and second server 2005.

[0500] It should be noted that the specific processing procedures for the first node 2001, KDC2002, the second node 2003, the first server 2004, and the second server 2005 have been detailed above and will not be repeated here.

[0501] It should be noted that terms such as "first" and "second" are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0502] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.

[0503] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.

Claims

1. An authentication method characterized by, The method is applied to a first node, the first node belongs to a first domain, the first domain comprises N service nodes, N is an integer greater than or equal to 1, and the method comprises the following steps of: sending first information to a key distribution center KDC, wherein the first information is used for requesting service authorization for the N service nodes of the first domain; receiving second information sent by the KDC, wherein the second information represents that authorization is completed, the second information comprises a first key and third information, the first key comprises the first domain as a session key between a first client and a first server, and the third information represents an access-allowed credential associated with the first client and the first server; sending the first key and the third information to service nodes other than the first node among the N service nodes, and the third information is used at least for service authentication between the first server.

2. The method of claim 1, wherein, The first information comprises an identifier of the first domain and / or fourth information, and the fourth information represents services that can be applied for by each service node among the N service nodes.

3. The method of claim 2, wherein, The fourth information comprises fifth information of each service node among the N service nodes, and the fifth information represents a service identifier that can be applied for by the service node using a private key of the service node.

4. The method according to any one of claims 1 to 3, characterized in that, The sending of the first key to service nodes other than the first node among the N service nodes comprises: encrypting the first key with a key of a service node for a service node other than the first node among the N service nodes; and sending the encrypted first key to the service node.

5. An authentication method characterized by, The method is applied to the KDC, and the method comprises the following steps of: receiving first information sent by a first node, wherein the first node belongs to a first domain, the first node is used at least for executing steps of the method of claim 1, the first domain comprises N service nodes, the first information is used for requesting service authorization for the N service nodes of the first domain, and N is an integer greater than or equal to 1; authenticating the N service nodes of the first domain by interacting with the first node; after authentication, sending second information to the first node, wherein the second information represents that authorization is completed, the second information comprises a first key and third information, the first key comprises the first domain as a session key between a first client and a first server, and the third information represents an access-allowed credential associated with the first client and the first server.

6. The method of claim 5, wherein, The first information comprises an identifier of the first domain and / or fourth information, and the fourth information represents services that can be applied for by each service node among the N service nodes.

7. The method of claim 6, wherein, The fourth information comprises fifth information of each service node among the N service nodes, and the fifth information represents a service identifier that can be applied for by the service node using a private key of the service node.

8. An authentication method characterized by, The method is applied to a second node, the second node comprises a service node among N service nodes of a first domain, N is an integer greater than or equal to 1, and the method comprises the following steps of: receiving a first key and third information sent by a first node, the first node belonging to the first domain, the first node being configured to perform at least the steps of the method of claim 1, the first key comprising the first domain as a first client and a first server for a session key, the third information representing an allowed access credential associated with the first client and the first server, the third information being used at least for service authentication between a service node and the first server; sending fifth information to the first server, the fifth information being used to request the first server to perform service authentication on the second node, the fifth information comprising authentication information encrypted using the first key and the third information; receiving sixth information sent by the first server, the sixth information comprising a service authentication result.

9. The method of claim 8, wherein, When sending the fifth information to the first server, the method further comprises: sending seventh information to a second server, the second server being configured to perform data security processing authentication when a security level of the first domain is different from a security level of a second domain to which the first server belongs, the seventh information comprising information related to the first domain; receiving eighth information sent by the second server, the eighth information being used to indicate that the second node and / or the first server needs to perform security processing on data; performing authentication related to security processing with the second server and the first server.

10. The method of claim 9, wherein, When the eighth information is used to indicate that the second node needs to perform security processing on data, the authentication related to security processing with the second server and the first server comprises: receiving a first token sent by the second server; calling a security gateway for security processing authentication using the first token; sending a first credential for security processing authentication to the second server when the security processing authentication is passed; receiving a second credential associated with the security processing authentication sent by the second server, the second credential being generated based on the first credential; performing service authentication with the first server based on the second credential.

11. The method of claim 9, wherein, When the eighth information is used to indicate that the first server needs to perform security processing on data, the method further comprises: performing service authentication with the first server based on a third credential, wherein the third credential is generated by the second server for the first server based on a fourth credential, the fourth credential being sent by a security gateway after passing the security processing authentication on the first server.

12. An authentication method characterized by, applicable to a first server, comprising: receiving fifth information sent by a second node, the second node comprising one of N service nodes in a first domain, the second node being configured to perform at least the steps of the method of claim 8, N being an integer greater than or equal to 1, the fifth information being configured to request the first server to perform service authentication with the second node, the fifth information comprising authentication information encrypted by using a first key and third information, the first key comprising a session key between the first domain as a first client and the first server, the third information representing an allowed access credential associated with the first client and the first server, the third information being used at least for service authentication with the second node; performing service authentication with the second node to obtain a service authentication result; sending sixth information to the second node, the sixth information comprising the service authentication result.

13. The method of claim 12, wherein, When receiving the fifth information sent by the second node, the method further comprises: sending ninth information to a second server, the ninth information comprising information about a second domain to which the first server belongs, the second server being configured to perform data security processing authentication at least when security levels of the first domain and the second domain are different; receiving eighth information sent by the second server, the eighth information being configured to indicate that the second node and / or the second server needs to perform security processing on data; performing service authentication related to security processing with the second server and the second node.

14. The method of claim 13, wherein, When the eighth information is configured to indicate that the first server needs to perform security processing on data, the method further comprises: receiving a second token sent by the second server; calling a security gateway to perform security processing authentication by using the second token; sending fourth credential of security processing authentication to the second server when the security processing authentication is passed; receiving third credential associated with the security processing authentication sent by the second server, the third credential being generated based on the fourth credential; performing service authentication with the second node based on the third credential.

15. The method of claim 13, wherein, When the eighth information is configured to indicate that the second node needs to perform security processing on data, the method further comprises: performing service authentication with the second node based on a second credential, wherein the second credential is generated by the second server for the first server based on a first credential sent by the security gateway after passing the security processing authentication.

16. An authentication method characterized by, applicable to a second server, comprising: receiving seventh information sent by a second node, the second node belonging to a first domain, the second node being configured to perform at least the steps of the method of claim 8, the first domain comprising N service nodes, N being an integer greater than or equal to 1, the seventh information comprising information about the first domain; receiving ninth information sent by a first server, the first server being configured to perform at least the steps of the method of claim 12, the ninth information comprising information about a second domain to which the first server belongs; The seventh information and the ninth information are used to determine that the security levels of the first domain and the second domain are different, eighth information is sent to the second node and the first server, the eighth information is used to indicate that the second node and / or the second server needs to perform security processing on data, and data security processing authentication is performed.

17. The method of claim 16, wherein, In a case where the eighth information is used to at least indicate that the second node needs to perform security processing on data, the method further includes: sending a first token to the second node, so that the second node calls a security gateway to perform security processing authentication by using the first token; receiving a first credential of security processing authentication sent by the second node in a case where the security processing authentication is passed; generating a second credential associated with the security processing authentication based on the first credential; sending the second credential to the second node.

18. The method of claim 16, wherein, In a case where the eighth information is used to at least indicate that the first server needs to perform security processing on data, the method further includes: sending a second token to the first server, so that the first server calls a security gateway to perform security processing authentication by using the second token; receiving a fourth credential of security processing authentication sent by the first server in a case where the security processing authentication is passed; generating a third credential associated with the security processing authentication based on the fourth credential; sending the third credential to the first server.

19. A first node, comprising: Comprise: a first processor and a first memory for storing a computer program capable of running on the processor, wherein the first processor is used to run the computer program, and the steps of the method of any one of claims 1 to 4 are performed.

20. A KDC, comprising: Comprise: a second processor and a second memory for storing a computer program capable of running on the processor, wherein the second processor is used to run the computer program, and the steps of the method of any one of claims 5 to 7 are performed.

21. A second node, comprising: Comprise: a third processor and a third memory for storing a computer program capable of running on the processor, wherein the third processor is used to run the computer program, and the steps of the method of any one of claims 8 to 11 are performed.

22. A first server, comprising: Comprise: a fourth processor and a fourth memory for storing a computer program capable of running on the processor, wherein the fourth processor is used to run the computer program, and the steps of the method of any one of claims 12 to 15 are performed.

23. A second server, characterized by Comprise: a fifth processor and a fifth memory for storing a computer program capable of running on the processor, wherein the fifth processor is used to run the computer program, and the steps of the method of any one of claims 16 to 18 are performed.

24. A storage medium having stored thereon a computer program, characterized in that The computer program is executed by the processor to implement the steps of the method of any one of claims 1 to 4, or the steps of the method of any one of claims 5 to 7, or the steps of the method of any one of claims 8 to 11, or the steps of the method of any one of claims 12 to 15, or the steps of the method of any one of claims 16 to 18.

25. A computer program product comprising a computer program, characterised in that, The computer program, which is executed by a processor, implements the steps of the method according to any one of claims 1 to 4, or the steps of the method according to any one of claims 5 to 7, or the steps of the method according to any one of claims 8 to 11, or the steps of the method according to any one of claims 12 to 15, or the steps of the method according to any one of claims 16 to 18.

Citation Information

Patent Citations

  • Authentication method between client side and server under cloud environment and authentication device thereof

    CN106656928A

  • Identity-no-pairing-based secret key agreement method for wireless network cross-domain switching authentication

    CN107360567A