Access Request Processing Method, Device, Electronic Device and Readable Medium

By introducing intermediate proxy services into the container platform, linking the national secret communication service, and handling access requests in the national secret communication method, the problem of how to ensure the security of the Chinese secret communication service access of the container platform is solved, and secure and efficient national secret communication access is achieved.

CN119854026BActive Publication Date: 2025-06-27龙芯中科(合肥)技术有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510295662.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-12
Publication Date
2025-06-27
Estimated Expiration
2045-03-12

AI Technical Summary

Technical Problem

In the prior art, how to ensure that the State-Confidential Communication method is adopted when interacting with the State-Confidential Communication Service in the container platform to ensure access security.

Method used

The intermediate proxy service is introduced into the container platform. This service is associated with the State Secret Communication Service, receives the target access request from the access party, and sends the request to the target service in the form of State Secret Communication based on the pre-configured State Secret Communication related information and target address information.

Benefits of technology

Through the intervention of intermediate agent services, we ensure that the State Secret Communication Method is adopted when accessing the State Secret Communication Service, which improves the access security and ensures the security of the State Secret Communication Service.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119854026B_ABST
    Figure CN119854026B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention provides a method, apparatus, electronic device, and readable medium for processing access requests, relating to the field of network technologies. In this method, an intermediate proxy service receives a target access request sent by an access party; the target access request is used to access a target service, and the target service is a national cryptography communication service associated with the intermediate proxy service. The domain name of the national cryptography communication service recorded by the access party has been pre-synchronized to the domain name of the intermediate proxy service. Based on the national cryptography communication-related information and target address information pre-configured in a first configuration file, the target access request is sent to the target service in the manner of national cryptography communication; the first configuration file is the configuration file of the intermediate proxy service, and the target address information is the address information of the target service. The response data returned by the target service is sent to the access party. In this way, it is ensured that national cryptography communication is used when interacting with the target service, thereby ensuring the access security of the national cryptography communication service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network technologies, and in particular, to a method, apparatus, electronic device, and readable medium for processing access requests. Background Art

[0002] With the continuous development of network technologies, container platforms have been used more and more. Multiple containers can be created in a container platform. One container can be used to deploy an application service, and each application service provides its own functions that can be realized, such as a login function, a detection function, a data query function, and so on. During actual use, data can be sent to an application service or obtained from an application service by accessing the application service.

[0003] In the prior art, in order to ensure security, some services need to be accessed in the manner of national cryptographic communication. Correspondingly, how to ensure the use of national cryptographic communication when interacting with these services has become a technical problem that urgently needs to be solved. Summary of the Invention

[0004] Embodiments of the present invention provide a method, apparatus, electronic device, and readable medium for processing access requests, which can solve the above technical problems.

[0005] To solve the above problems, an embodiment of the present invention discloses a method for processing an access request, which is applied to any intermediate proxy service in a container platform. The intermediate proxy service is associated with at least one national cryptographic communication service in the container platform. The method includes:

[0006] Receiving a target access request sent by an access party; the target access request is used to access a target service, the target service is the national cryptographic communication service associated with the intermediate proxy service, and the domain name of the national cryptographic communication service recorded by the access party is pre-synchronized as the domain name of the intermediate proxy service;

[0007] Based on the national cryptographic communication-related information and target address information pre-configured in a first configuration file, sending the target access request to the target service in the manner of national cryptographic communication; the first configuration file is the configuration file of the intermediate proxy service, and the target address information is the address information of the target service;

[0008] Sending the response data returned by the target service to the access party.

[0009] On the other hand, an embodiment of the present invention discloses an apparatus for processing an access request, which is applied to any intermediate proxy service in a container platform. The intermediate proxy service is associated with at least one national cryptographic communication service in the container platform. The apparatus includes:

[0010] A receiving module, configured to receive a target access request sent by an access party; the target access request is used to access a target service, and the target service is the national cryptography communication service associated with the intermediate proxy service. The domain name of the national cryptography communication service recorded by the access party has been pre-synchronized to the domain name of the intermediate proxy service;

[0011] A first processing module, configured to send the target access request to the target service in a national cryptography communication manner based on the national cryptography communication-related information and target address information pre-configured in a first configuration file; the first configuration file is the configuration file of the intermediate proxy service, and the target address information is the address information of the target service;

[0012] A return module, configured to send the response data returned by the target service to the access party.

[0013] In another aspect, an embodiment of the present invention discloses an electronic device, including: a processor, a memory, a communication interface, and a communication bus. The processor, the memory, and the communication interface complete communication with each other through the communication bus; the memory is used to store executable instructions, and the executable instructions cause the processor to execute the foregoing method.

[0014] An embodiment of the present invention also discloses one or more machine-readable media, on which instructions are stored. When executed by one or more processors, the instructions cause the processor to execute the foregoing method.

[0015] The embodiments of the present invention include the following advantages: In the access request processing method provided by the embodiments of the present invention, an intermediate proxy service receives a target access request sent by an access party; the target access request is used to access a target service, and the target service is the national cryptography communication service associated with the intermediate proxy service. The domain name of the national cryptography communication service recorded by the access party has been pre-synchronized to the domain name of the intermediate proxy service. Based on the national cryptography communication-related information and target address information pre-configured in a first configuration file, the target access request is sent to the target service in a national cryptography communication manner; the first configuration file is the configuration file of the intermediate proxy service, and the target address information is the address information of the target service. The response data returned by the target service is sent to the access party. In this way, by pre-associating a national cryptography communication service with the intermediate proxy service in the container platform, since the domain name of the national cryptography communication service associated with the intermediate proxy service recorded by the access party is pre-synchronized to the domain name of the intermediate proxy service, when the access party requests to access the target service associated with the intermediate proxy service, the target access request is received by the intermediate proxy service, and the intermediate proxy service interacts with the target service on behalf of the access party in a national cryptography communication manner according to the target access request, ensuring that the national cryptography communication manner is adopted when interacting with the target service, that is, ensuring that the target service is accessed in a national cryptography communication manner, and further ensuring the access security of the national cryptography communication service. Brief Description of the Drawings

[0016] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.

[0017] Figure 1 is a flowchart of the steps of a method for processing access requests provided by an embodiment of the present invention;

[0018] Figure 2 is a block diagram of a device for processing access requests provided by an embodiment of the present invention;

[0019] Figure 3 is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. Detailed Embodiments

[0020] The technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0021] Figure 1 is a flowchart of the steps of a method for processing access requests provided by an embodiment of the present invention, which is applied to any intermediate proxy service in a container platform. The intermediate proxy service is associated with at least one national cryptography communication service in the container platform. As Figure 1 shown, the method for processing access requests may include the following steps:

[0022] Step 101: Receive a target access request sent by an access party; the target access request is used to access a target service, and the target service is the national cryptography communication service associated with the intermediate proxy service. The domain name of the national cryptography communication service recorded by the access party is pre-synchronized as the domain name of the intermediate proxy service.

[0023] Step 102: Based on the national cryptography communication-related information and target address information pre-configured in the first configuration file, send the target access request to the target service in the manner of national cryptography communication; the first configuration file is the configuration file of the intermediate proxy service, and the target address information is the address information of the target service.

[0024] Step 103: Send the response data returned by the target service to the access party.

[0025] The access request processing method provided by the embodiments of the present invention can be applied to the container scenario, and in this scenario, the access to the national secret communication service in the container platform is realized in the manner of national secret communication. Among them, the container platform can be built using a container orchestration platform (kubernetes, K8s). There are multiple containers in the container platform. Specifically, containerized deployment is adopted during application deployment for convenient management. An application can have at least one application service, and one application service is deployed in one container. One application service can be regarded as an application instance. The container platform can be a container cloud platform. In the container cloud platform, through various provided access types, such as headless service, cluster IP, node port, etc., the internal access and external access to the application service can be realized. The containers in the container cloud platform share the host operating system kernel of the cloud environment. Each container only contains the minimum components required to run the application. A container is an independent and executable software unit that contains all the content required to run the application service, such as code, runtime environment, system tools, and system libraries. Multiple containers are run on the same physical server.

[0026] The intermediate proxy service is a proxy service added for the national secret communication service in the container platform. The intermediate proxy service can run on a proxy server that provides a national secret proxy for the national secret communication service. The national secret communication service can be an application service in the container platform that needs to be accessed in the manner of national secret communication. There is one or more national secret communication services in the container platform. In the embodiments of the present invention, at least one intermediate proxy service can be added to the container platform in advance. For any intermediate proxy service, this intermediate proxy service can execute the above access request processing method to interact with the national secret communication service associated with this intermediate proxy service in the manner of national secret communication on behalf of the access party. Specifically, the national secret communication related information required for access in the manner of national secret communication, and the address information of the national secret communication service associated with this intermediate proxy service can be configured in advance in the configuration file of the intermediate proxy service (i.e., the first configuration file). The intermediate proxy service can be accessed in the manner of national secret communication, that is, the intermediate proxy service has the ability of national secret communication. At least one intermediate proxy service can provide proxy services for all the national secret communication services in the container platform.

[0027] Among them, an intermediate proxy service can provide proxy services for at least one national cryptography communication service. Accessing in the manner of national cryptography communication is equivalent to interacting in the manner of national cryptography communication. Specifically, accessing in the manner of national cryptography communication includes: establishing a connection with the application service according to the national cryptography protocol information, sending an access request encrypted with the national cryptography algorithm information to the application service. The application service executes the operation indicated by the access request, generates response data encrypted with the national cryptography algorithm information for the access request, and returns the encrypted response data to the access party. Among them, the national cryptography algorithm information is used to represent the national cryptography algorithm used, and the national cryptography algorithm refers to the domestic cryptography algorithm.

[0028] Specifically, for any intermediate proxy service, the intermediate proxy service is associated with at least one national cryptography communication service. Correspondingly, the intermediate proxy service provides proxy services for the at least one national cryptography communication service it is associated with. All the national cryptography communication services associated with all intermediate proxy services are all the national cryptography communication services included in the container platform. The target service is one of the at least one national cryptography communication services associated with the intermediate proxy service, and any national cryptography communication service associated with the intermediate proxy service can be used as the target service. Exemplarily, assume that the intermediate proxy service is associated with national cryptography communication service a and national cryptography communication service b. When the target access request is used to access national cryptography communication service a, national cryptography communication service a is the target service. When the target access request is used to access national cryptography communication service b, national cryptography communication service b is the target service. For any received target access request, it is processed based on the above steps 102 to 103.

[0029] Furthermore, the access request used to access the target service is the target access request. The intermediate proxy service providing proxy services for the national cryptography communication service means that the access request used to access the national cryptography communication service is submitted to the intermediate proxy service, and the intermediate proxy service is responsible for forwarding the target access request to the national cryptography communication service in the manner of national cryptography communication, and forwarding the response data returned by the national cryptography communication service to the access party.

[0030] Accordingly, in order to ensure that the access request for accessing the target service is submitted to the intermediate proxy service, in the embodiments of the present invention, the domain name of the national cryptography communication service (including the above target service) associated with the intermediate proxy service recorded by the access party is pre-synchronized to the domain name of the intermediate proxy service. Among them, when the access party needs to access a service, it often sends an access request to the application service according to the domain name of the application service recorded internally. If the domain name of the national cryptography communication service associated with the intermediate proxy service recorded by the access party is not synchronized to the domain name of the intermediate proxy service, the access request will be directly sent to the national cryptography communication service. Accordingly, synchronizing the domain name of the national cryptography communication service associated with the intermediate proxy service recorded by the access party to the domain name of the intermediate proxy service causes the target access request to be actually sent to the intermediate proxy service.

[0031] In summary, in the access request processing method provided by the embodiments of the present invention, the intermediate proxy service receives a target access request sent by an access party; the target access request is used to access a target service, and the target service is a national cryptography communication service associated with the intermediate proxy service, and the domain name of the national cryptography communication service recorded by the access party is pre-synchronized to the domain name of the intermediate proxy service. Based on the national cryptography communication-related information and the target address information pre-configured in the first configuration file, the target access request is sent to the target service in the manner of national cryptography communication; the first configuration file is the configuration file of the intermediate proxy service, and the target address information is the address information of the target service. The response data returned by the target service is sent to the access party. In this way, by pre-associating the national cryptography communication service with the intermediate proxy service in the container platform, since the domain name of the national cryptography communication service associated with the intermediate proxy service recorded by the access party is pre-synchronized to the domain name of the intermediate proxy service, when the access party requests to access the target service associated with the intermediate proxy service, the target access request is received by the intermediate proxy service, and the intermediate proxy service interacts with the target service in the manner of national cryptography communication on behalf of the access party according to the target access request, ensuring that the national cryptography communication method is used when interacting with the target service, that is, ensuring that the target service is accessed in the manner of national cryptography communication, and further ensuring the access security of the national cryptography communication service.

[0032] Optionally, in the case where the intermediate proxy service is associated with multiple national cryptography communication services, the service identifiers and address information of the national cryptography communication services associated with the intermediate proxy service are pre-configured in the first configuration file. Accordingly, the embodiments of the present invention may further include the following steps:

[0033] Step S21: Extract the service identifier of the target service carried in the target access request as the target identifier.

[0034] Step S22: Obtain, from the first configuration file, the address information corresponding to the service identifier that is the same as the target identifier as the target address information.

[0035] Specifically, when the intermediate proxy service is associated with multiple national cryptography communication services, the service identifiers and address information of the national cryptography communication services associated with the intermediate proxy service are pre-configured in the first configuration file, that is, the service identifiers and address information of these multiple national cryptography communication services are recorded in the first configuration file. Specifically, the service identifiers and address information of the national cryptography communication services can be recorded correspondingly. Correspondingly, for the target access request received this time, the content of the bit field used to represent the service identifier in the target access request can be extracted to obtain the target identifier. Among them, the bit field used to represent the service identifier can be predefined during the development stage. Exemplarily, the bit field used to represent the service identifier can be the 5th to 8th bits, and the embodiments of the present invention do not limit this.

[0036] Furthermore, for the address information of any national cryptography communication service recorded in the first configuration file, the service identifier corresponding to the address information is compared with the target identifier. If the two are the same, it means that the address information of the national cryptography communication service requested to be accessed this time is the recorded address information. Correspondingly, this address information can be used as the target address information.

[0037] In the embodiments of the present invention, the service identifiers and address information of the national cryptography communication services associated with the intermediate proxy service are pre-configured in the first configuration file. The service identifier of the target service carried in the target access request is extracted as the target identifier. The address information with the corresponding service identifier consistent with the target identifier is obtained from the first configuration file as the target address information. In this way, when the intermediate proxy service is associated with multiple national cryptography communication services, the address information of the target service accessed this time can be accurately known. At the same time, one intermediate proxy service acts as an agent for multiple national cryptography communication services, which can reduce the total number of intermediate proxy services required by the container platform, and thus save costs to a certain extent.

[0038] Optionally, when the intermediate proxy service is associated with one national cryptography communication service, the address information of the national cryptography communication service associated with the intermediate proxy service is pre-configured in the first configuration file. Correspondingly, the embodiments of the present invention may further include the following steps: Step S31, directly read the address information in the first configuration file as the target address information.

[0039] Specifically, when the intermediate proxy service is only associated with one national cryptography communication service, only the address information of one national cryptography communication service is pre-configured in the first configuration file. Correspondingly, for the target access request received this time, there is no need to extract the target identifier, nor to search in the first configuration file. The address information in the first configuration file can be directly read to obtain the target address information. In this way, the processing steps can be simplified, and the overall processing efficiency can be improved.

[0040] Optionally, in the embodiments of the present invention, the intermediate proxy service is associated with the at least one national cryptography communication service through the following steps pre-executed by the control service:

[0041] Step S41: Determine the service that requires access through national cryptography communication in the container platform as the national cryptography communication service.

[0042] Step S42: Determine the national cryptography communication service to be associated for the intermediate proxy service.

[0043] Step S43: When the number of the national cryptography communication services to be associated is 1, set the address information of the national cryptography communication service to be associated in the proxy information configuration item of the first configuration file.

[0044] Step S44: When the number of the national cryptography communication services to be associated is greater than 1, set the service identifier and address information of each of the national cryptography communication services to be associated in the proxy information configuration item.

[0045] In the embodiments of the present invention, the control service is a service in the container platform, and the control service can be pre-specified. The control service can first count the services that require access through national cryptography communication in the container platform as national cryptography communication services. Create m containers in the container platform, and deploy a preset code file in these m containers to obtain m intermediate proxy services, which is equivalent to creating a service for the preset code file. Wherein, m is an integer, and m is not greater than the total number of national cryptography communication services in the container platform. The preset code file is the code for implementing the functions of the above intermediate proxy service. The preset code file can be written independently by developers in advance, or can directly obtain the national cryptography module code provided by open source software. The embodiments of the present invention do not limit this.

[0046] Further, in one implementation, m can be equal to the total number of national cryptography communication services in the container platform. In this way, by creating the same number of intermediate proxy services, a corresponding national cryptography communication service can be assigned to each intermediate proxy service. In the embodiments of the present invention, by creating a container and deploying a preset code file in the container, the intermediate proxy service can be obtained. Therefore, the creation cost of a single intermediate proxy service is relatively low. Correspondingly, creating the same number of intermediate proxy services and assigning a national cryptography communication service to be associated to each intermediate proxy service can simplify the configuration operation of the proxy information configuration item of the intermediate proxy service and simplify the subsequent operation of determining the target address information while avoiding excessive costs.

[0047] Exemplarily, one intermediate proxy service can be selected from the unassigned intermediate proxy services, and one national cryptography communication service can be selected from the unassigned national cryptography communication services as the national cryptography communication service to be associated with the intermediate proxy service. Then, the intermediate proxy service is determined as an assigned intermediate proxy service, and the unassigned national cryptography communication service is determined as an assigned national cryptography communication service, and the steps of selecting one intermediate proxy service from the unassigned intermediate proxy services and selecting a corresponding national cryptography communication service from the unassigned national cryptography communication services are returned until a national cryptography communication service to be associated is selected for all intermediate proxy services. Among them, in the initial state, the unassigned intermediate proxy services include all intermediate proxy services, and the unassigned national cryptography communication services include all national cryptography communication services in the container platform. When selecting one intermediate proxy service from the unassigned intermediate proxy services, it can be randomly selected. When selecting one national cryptography communication service from the unassigned national cryptography communication services, it can also be randomly selected, or it can be the national cryptography communication service closest to the intermediate proxy service. The embodiments of the present invention do not limit this.

[0048] In another implementation, m can be less than the total number of national cryptography communication services in the container platform. Correspondingly, m intermediate proxy services can be arranged in sequence first. For example, m intermediate proxy services can be randomly arranged in a sequence. According to the arrangement order of the intermediate proxy services, a national cryptography communication service is selected for each intermediate proxy service in turn. After one round of selection, it is judged whether there are still remaining unselected national cryptography communication services. If there are, a new round of selection is started, that is, from the remaining unselected national cryptography communication services, continue to select a national cryptography communication service for each intermediate proxy service in the arrangement order of the intermediate proxy services until there are no remaining unselected national cryptography communication services. For any intermediate proxy service, the national cryptography communication service selected for the intermediate proxy service is determined as the national cryptography communication service to be associated with the intermediate proxy service.

[0049] For any intermediate proxy service, a first configuration file can be set for the intermediate proxy service. Among them, the first configuration file of the intermediate proxy service includes multiple configuration items, and each configuration item can be used to configure the corresponding information. In the initial state, the values of the configuration items in the first configuration file are all empty. After configuration, the values of the configuration items are set to the corresponding information. Specifically, the proxy information configuration item can be used to configure the address information of the national cryptography communication service to be associated with the intermediate proxy service. Exemplarily, the proxy information configuration item can be expressed as: location / {proxy_pass}. The address information of the national cryptography communication service to be associated with the intermediate proxy service can be used as the specific value of the proxy information configuration item in the first configuration file of the intermediate proxy service, so as to realize the association of the intermediate proxy service with the national cryptography communication service to be associated, that is, the intermediate proxy service is added for these national cryptography communication services to be associated.

[0050] When there is only one national cryptography communication service to be associated with the intermediate proxy service, only the address information of this national cryptography communication service is written in the proxy information configuration item. When there are multiple national cryptography communication services to be associated with the intermediate proxy service, the address information and service identifiers of these multiple national cryptography communication services are written in the proxy information configuration item. Among them, the service identifier can be information used to uniquely indicate the national cryptography communication service. Exemplarily, the service identifier can be a number, name, etc. pre-assigned to the national cryptography communication service. For any national cryptography communication service to be associated with the intermediate proxy service, the address information and service identifier of the national cryptography communication service to be associated can be stored correspondingly. Exemplarily, the service identifier can be used as the key name, and the address information can be used as the key value, and stored in the form of key-value pairs. Or, using the service identifier as the subfolder name, create a subfolder, and store the address information in this subfolder to achieve corresponding storage.

[0051] The address information of the national cryptography communication service can be the information required to access the national cryptography communication service. The address information can be regarded as the communication address of the national cryptography communication service. Exemplarily, the address information can be the domain name of the national cryptography communication service. Correspondingly, the intermediate proxy service can send the target access request to the target service in the manner of national cryptography communication based on the address information of the target service and relevant national cryptography communication information.

[0052] In the embodiments of the present invention, the services that require access in the manner of national cryptography communication in the container platform are determined as national cryptography communication services in advance. Determine the national cryptography communication services to be associated with the intermediate proxy service. When the number of national cryptography communication services to be associated is 1, set the address information of the national cryptography communication service to be associated in the proxy information configuration item of the first configuration file. In this way, when the intermediate proxy service proxies the target access request of the access party, the target access request can be accurately forwarded to the corresponding national cryptography communication service directly based on the configured address information, ensuring the processing efficiency. When the number of national cryptography communication services to be associated is greater than 1, set the service identifiers and address information of each national cryptography communication service to be associated in the proxy information configuration item. In this way, the total number of intermediate proxy services required can be reduced, thereby reducing costs.

[0053] Optionally, the step of determining the service that requires access via national cryptography communication in the container platform as the national cryptography communication service may specifically include: Step S41a, determining the application service with a specified identification field set in the container platform as the national cryptography communication service. And / or, Step S41b, determining the application service with a specified service type in the container platform as the national cryptography communication service. That is, in the embodiments of the present invention, the national cryptography communication service may include an application service with a specified identification field set, or an application service with a specified service type, or an application service with a specified identification field set and an application service with a specified service type.

[0054] In an actual application scenario, the container platform can be deployed first, and then each application service of the application can be deployed in the container platform. Among them, the way of deploying the container platform can be selected as needed, and the embodiments of the present invention do not limit this. The user can set a specified identification field for the application service as needed in advance. Among them, the specified identification field is used to represent that the application service requires access in the way of national cryptography communication, and the specific form of the specified identification field can be set as needed. Exemplarily, the specified identification field can be GM. When setting the specified identification field for the application service, the specified identification field can be set in the configuration file of the application service. Correspondingly, in Step S41a, the control service can detect whether there is a specified identification field in the configuration files of each application service in the container platform. If it exists, it is determined that the application service has the specified identification field set, and the application service is determined as the national cryptography communication service.

[0055] Furthermore, the specified type can be set by the user as needed in advance. The specified type is used to represent the service type that requires access in the way of national cryptography communication. Exemplarily, the data source type can be used as the specified type, so that all application services of the data source type are used as the national cryptography communication service. The embodiments of the present invention do not limit this. Specifically, a type field representing the specified type can be added to the configuration file of the control service in advance. After each application service of the application is deployed in the container platform, the type of each application service can be recorded, and a type field is set in the configuration file of the application service. The type field is used to represent the type of the application service. In Step S41b, the control service can detect whether the type field in the configuration file of each application service is the same as the type field representing the specified type. If they are the same, the application service is determined as the national cryptography communication service.

[0056] In the embodiments of the present invention, by identifying the application service with a specified identification field set in the container platform and / or the application service with a specified service type, the national cryptography communication service in the container platform can be determined, and thus to a certain extent, the determination efficiency of the national cryptography communication service can be ensured.

[0057] In an embodiment of the present invention, the domain name of the intermediate proxy service can be pre-synchronized to the access party as the domain name of the associated national cryptography communication service. Optionally, the domain name of the intermediate proxy service is pre-synchronized through the following steps:

[0058] Step S51: Determine the services in the container platform that do not support national cryptography communication as the access party, and obtain the domain name of the intermediate proxy service.

[0059] Step S52: For any one of the access parties, modify the domain names of the national cryptography communication services associated with the intermediate proxy service saved in the second configuration file to the domain name of the intermediate proxy service; the second configuration file is the configuration file of the access party.

[0060] Among them, the above Step S51 to Step S52 can be executed by the control service, or can also be executed by the intermediate proxy service, and the embodiments of the present invention do not limit this.

[0061] In an actual application scenario, for application services in the container platform, when accessing the application services internally, access is performed through the domain name of the application service. Some internal services do not support national cryptography communication and can only be accessed through the Hypertext Transfer Protocol Secure (https). However, the security requirements of some services are relatively high. For example, some services involve data with a relatively high security level. To ensure data security, access needs to be performed in the manner of national cryptography communication to avoid the problem that the information in the service can be easily accessed by network attackers through https access and data security cannot be ensured. Among them, https adds a security protocol (such as the Transport Layer Security (TLS) / Secure Sockets Layer (SSL) protocol) on the basis of the Hypertext Transfer Protocol (http) to achieve secure data transmission. In an embodiment of the present invention, services in the container platform that do not support national cryptography communication can be collected. Exemplarily, a service list input by the user can be received, and the service identifiers of the services that do not support national cryptography communication are recorded in the service list. Correspondingly, the services represented by the service identifiers recorded in the service list can be determined as the aforementioned access party. The domain names of other application services in the container platform will be recorded in the second configuration file of the access party. Exemplarily, the service identifier of the application service and the domain name of the application service can be correspondingly recorded in the second configuration file of the access party.

[0062] The domain names of the intermediate proxy service and the national secret communication service are generated through the domain name proxy service. Among them, the domain name proxy service is a component used to provide Domain Name System (DNS) proxy for the container platform. After the application service is successfully deployed, the domain name proxy service generates a domain name for the application service. Exemplarily, the domain name proxy service can be the default DNS service in the container platform, and the default DNS service can be a CoreDNS server. In the embodiment of the present invention, after the intermediate proxy service is created, the domain name proxy service generates a domain name for the intermediate proxy service. Correspondingly, for any intermediate proxy service, the domain name previously generated for the intermediate proxy service can be read. The domain name proxy service can generate a domain name according to the namespace and service name of the service. The generated domain name can be used for mutual positioning between services. Since the domain name generated by the domain name proxy service is not affected by the change of the Internet Protocol (IP) address of the service, that is, no matter how the service IP address changes, the domain name generated by the domain name proxy service for the service will not change. Therefore, compared with the method of using the service IP address, the problem of being unable to locate the service can be avoided.

[0063] Furthermore, the domain name proxy service can generate multiple domain names in different formats for one service. Exemplarily, generating multiple domain names in different formats for one service can include the following three formats: short domain name format, namespace-qualified domain name format, and global domain name format. The short domain name format, namespace-qualified domain name format, and global domain name format can be respectively expressed as: yourapp, yourapp.namespace, yourapp.namespace.svc.cluster.local.

[0064] Correspondingly, for any national secret communication service associated with the intermediate proxy service, the domain names in each format corresponding to the service identifier of the national secret communication service saved in the second configuration file of the access party can be modified to the domain names in the same format of the intermediate proxy service. For example, the domain name in the short domain name format of the national secret communication service can be modified to the domain name in the short domain name format of the intermediate proxy service, the domain name in the namespace-qualified domain name format of the national secret communication service can be modified to the domain name in the namespace-qualified domain name format of the intermediate proxy service, and the domain name in the global domain name format of the national secret communication service can be modified to the domain name in the global domain name format of the intermediate proxy service.

[0065] Exemplarily, assume that the domain name in the global domain name format of a national cryptographic communication service associated with this intermediate proxy service is: kubernetes.namespace.svc.cluster.local, and the domain name in the global domain name format of the intermediate proxy service is: gmproxy.namespace.svc.cluster.local.

[0066] Then, the domain name saved in the second configuration file of the access party: kubernetes.namespace.svc.cluster.local, can be modified to:

[0067] gmproxy.namespace.svc.cluster.local.

[0068] Furthermore, after modifying the domain name, the access party can be restarted to enable the access party to reload the second configuration file, so as to send an access request with the new domain name. It should be noted that after the access party has the national cryptographic communication capability, the domain name of the national cryptographic communication service saved in the second configuration file of the access party can be modified to the actual domain name of each national cryptographic communication service. In this way, flexible switching can be achieved. Through the switching, the access request sent by the access party to the national cryptographic communication service can be directly received by the national cryptographic communication service.

[0069] In the embodiment of the present invention, by determining the service that does not support national cryptographic communication in the container platform as the access party, and obtaining the domain name of this intermediate proxy service. For any access party, the domain names of each national cryptographic communication service associated with the intermediate proxy service saved in the second configuration file are modified to the domain name of the intermediate proxy service; the second configuration file is the configuration file of the access party. In this way, without modifying the access party itself, by modifying the domain names of each national cryptographic communication service associated with this intermediate proxy service saved in the second configuration file of the service that does not support national cryptographic communication to the domain name of this intermediate proxy service, the domain name of this intermediate proxy service is pre-synchronized to the access party as the domain name of the associated national cryptographic communication service, so that the service that does not support national cryptographic communication can access the national cryptographic communication service through the intermediate proxy service. In this way, it is equivalent to realizing the national cryptographic communication between the access party that does not have the national cryptographic communication capability and the national cryptographic communication service, and realizing the interaction between the access party and the national cryptographic communication service in the manner of national cryptographic communication.

[0070] It should be noted that the service that supports national cryptographic communication in the container platform can also be used as the access party. In this way, it is equivalent to performing another national cryptographic encryption on the basis of the target access request that has been encrypted by the access party using national cryptography.

[0071] Optionally, in the embodiments of the present invention, the information related to national cryptography communication includes: the storage path of the national cryptography encryption information corresponding to the domain name of the intermediate proxy service and the national cryptography protocol information; the first configuration file is configured by the following steps performed in advance:

[0072] Step S61: Set the values of the encryption information item and the protocol information item in the first configuration file to the storage path of the national cryptography encryption information and the national cryptography protocol information, respectively.

[0073] Correspondingly, the step of sending the target access request to the target service in the manner of national cryptography communication based on the information related to national cryptography communication and the target address information pre-configured in the first configuration file may specifically include:

[0074] Step 1021a: Load the national cryptography encryption information based on the storage path of the national cryptography encryption information.

[0075] Step 1021b: Establish a connection with the target service based on the national cryptography protocol information and the target address information, and negotiate a communication key with the target service based on the national cryptography encryption information.

[0076] Step 1021c: Encrypt the target access request based on the communication key, and send the encrypted target access request to the target service.

[0077] Among them, step S61 can be executed by the control service. The encryption information item and the protocol information item are configuration items for setting the storage path of the national cryptography encryption information and the national cryptography protocol information, respectively. The storage path of the national cryptography encryption information and the national cryptography protocol information can be set to the specific values of the encryption information item and the protocol information item, respectively. In this way, by setting the storage path, the problem of too long specific value of the encryption information item can be avoided. The national cryptography encryption information may be the information required for encryption. Specifically, the national cryptography encryption information may include an encryption public key and an encryption private key. Among them, the encryption public key is stored in the national cryptography encryption certificate, and the storage of the encryption public key can be realized by storing the national cryptography encryption certificate. The encryption private key can also be referred to as the national cryptography encryption certificate key. The national cryptography protocol information may be the version number of the national cryptography protocol. The national cryptography protocol is a specification for establishing secure communication using national cryptography algorithms described by national cryptography standards and technologies. The intermediate proxy service establishes a connection with the corresponding national cryptography communication service based on the national cryptography protocol information and the address information and performs subsequent interactions. In this way, it is equivalent to transforming the TLS communication into national cryptography secure communication that conforms to the national cryptography standard.

[0078] In an embodiment of the present invention, the first configuration file of the intermediate proxy service may further include an algorithm information item, which is a configuration item for setting national cryptography algorithm information, and the national cryptography algorithm information can be set as the specific value of the algorithm information item. The national cryptography algorithm information can be the national cryptography algorithm itself, or it can also be an identifier for characterizing the national cryptography algorithm. For example, SM1, SM4, SM5, SM6, SM7, SM8, etc. The national cryptography algorithm information can indicate the supported national cryptography algorithms.

[0079] Specifically, the intermediate proxy service loads the value of the encryption information item in the first configuration file and accesses the storage path represented by the value of the encryption information item to load the national cryptography encryption information. The intermediate proxy service can load the value of the protocol information item in the first configuration file and use the national cryptography handshake rules defined by the national cryptography protocol indicated by the value of the protocol information item to handshake with the target service, and establish a connection after the handshake is completed. Among them, during the handshake process, the intermediate proxy service synchronizes the supported national cryptography algorithm information to the target service, and the target service selects the national cryptography algorithm used for this interaction and synchronizes it to the intermediate proxy service.

[0080] Further, during the handshake process, a communication key is negotiated with the target service based on the national cryptography encryption information. Specifically, the intermediate proxy service sends the encryption public key to the target service. Exemplarily, the intermediate proxy service can send a national cryptography encryption certificate to the target service so that the target service can obtain the encryption public key in the national cryptography encryption certificate. The target service encrypts the randomly generated pre-master key based on the encryption public key and then sends it to the intermediate proxy service. The pre-master key can be a random byte sequence of a fixed length. The intermediate proxy service decrypts the pre-master key using the encryption private key in the national cryptography encryption information. The intermediate proxy service and the target service respectively calculate the master key according to the plaintext pre-master key, the random number of the intermediate proxy service, and the random number of the target service. The random number of the intermediate proxy service and the random number of the target service can be synchronized to each other in advance. The plaintext pre-master key, the random number of the intermediate proxy service, and the random number of the target service can be used as the input of the pseudo-random function, and the output of the pseudo-random function is used as the master key. Then, the master key is used as the input of the key derivation function, and the output of the key derivation function is used as the symmetric key, and the symmetric key is the above-mentioned communication key. In this way, both the intermediate proxy service and the target service obtain the communication key.

[0081] Furthermore, the intermediate proxy service can encrypt the target access request using the communication key according to the national cryptography algorithm used in this interaction, and send the encrypted target access request to the target service. In this way, data protection during communication is achieved. Correspondingly, the target service can use the communication key to decrypt the received encrypted target access request to obtain the plaintext target access request, execute the operation indicated by the plaintext target access request, and generate response data. Then, according to the national cryptography algorithm used in this interaction, use the communication key to encrypt the response data, and return the encrypted response data to the intermediate proxy service. Correspondingly, the intermediate proxy service sends the response data returned by the target service to the access party, which may include: the intermediate proxy service uses the communication key to decrypt the received encrypted response data to obtain the plaintext response data and returns it to the access party.

[0082] Among them, the target access request will include the domain name of the access party. After receiving the target access request, the intermediate proxy service will record the domain name of the access party that sent the target access request. When returning the response data, establish a connection with the access party based on the recorded domain name of the access party, and then return the plaintext response data to the access party. Exemplarily, the intermediate proxy service and the access party can interact through https.

[0083] In the embodiment of the present invention, by pre-configuring the storage path of the national cryptography encryption information and the national cryptography protocol information in the first configuration file, the intermediate proxy service can send the target access request to the target service in the manner of national cryptography communication based on the storage path of the national cryptography encryption information and the national cryptography protocol information, ensuring the smooth progress of national cryptography communication between the intermediate proxy service and the target service.

[0084] Optionally, the above national cryptography communication related information further includes: the storage path of the national cryptography signature information corresponding to the domain name of the intermediate proxy service; the first configuration file is also configured through the following steps performed in advance:

[0085] Step S71: Set the signature information item in the first configuration file to the storage path of the national cryptography signature information.

[0086] Correspondingly, the embodiment of the present invention may further include:

[0087] Step S81: Load the national cryptography signature information based on the storage path of the national cryptography signature information.

[0088] Step S82: Generate a signature value for the target access request based on the national cryptography signature information for signature verification by the target service.

[0089] Among them, step S71 can be executed by the control service. The signature information item is a configuration item for setting the storage path of the national cryptography signature information. The storage path of the national cryptography signature information can be set as the signature information item. In this way, by setting the storage path, the specific value of the signature information item can be prevented from being too long. The national cryptography signature information can be the information required for signature verification. Specifically, the national cryptography signature information can include a signature public key and a signature private key. Among them, the signature public key is stored in the national cryptography signature certificate, and the storage of the signature public key can be achieved by storing the national cryptography signature certificate. The signature private key can also be referred to as the national cryptography signature certificate key. In the embodiments of the present invention, the national cryptography algorithm information and the national cryptography protocol information can be input by the user to the control service, and the national cryptography signature information and the national cryptography encryption information are generated by calling the certificate issuance service provided by the certificate authority. The certificate issuance service can be implemented in the form of a website, and the certificate issuance service can be used to generate corresponding national cryptography signature information and national cryptography encryption information for the domain name of the intermediate proxy service. Among them, the national cryptography signature information corresponding to each domain name of the intermediate proxy service can be the same, and the national cryptography encryption information corresponding to each domain name of the intermediate proxy service can also be different. The embodiments of the present invention do not limit this. After obtaining the national cryptography signature information and the national cryptography encryption information, the control service can store the national cryptography signature information and the national cryptography encryption information locally and generate the storage paths of the national cryptography signature information and the national cryptography encryption information respectively.

[0090] Exemplarily, the signature information item can include a national cryptography signature certificate item and a national cryptography signature certificate key item, and the encryption information item can include a national cryptography encryption certificate item and a national cryptography encryption certificate key item. The national cryptography signature certificate item, the national cryptography signature certificate key item, the national cryptography encryption certificate item, and the national cryptography encryption certificate key item can be respectively represented as: ssl_sign_certificate, ssl_sign_certificate_key, ssl_enc_certificate, ssl_enc_certificate_key.

[0091] Assume that the storage paths of the national cryptography signature certificate, the national cryptography signature certificate key, the national cryptography encryption certificate, and the national cryptography encryption certificate key are respectively:

[0092] / etc / gmproxy / certs / tls.crt;

[0093] / etc / gmproxy / certs / tls.key;

[0094] / etc / gmproxy / certs2 / tls.crt;

[0095] / etc / gmproxy / certs2 / tls.key;

[0096] Then, the four configuration items, namely the SM2 signature certificate item, the SM2 signature certificate key item, the SM2 encryption certificate item, and the SM2 encryption certificate key item, can be respectively set to the above storage paths. Further, the protocol information item can be represented as ssl_protocols, and the protocol information item can be configured as NTLS.

[0097] In an embodiment of the present invention, specifically, the intermediate proxy service can, when the SM2 switch is turned on, based on the SM2 communication-related information and the target address information pre-configured in the first configuration file, send the target access request to the target service in the manner of SM2 communication. Correspondingly, the first configuration file may further include an SM2 switch item. In an embodiment of the present invention, the value of the SM2 switch item can also be set to a value representing "turned on". Exemplarily, the SM2 switch item can be represented as: enable_ntls, and the value of the SM2 switch item can be set to a value representing "turned on": on. In this way, the SM2 switch of the intermediate proxy service can be turned on to control the intermediate proxy service to process the target access request. Further, the first configuration file may further include a service domain name item for configuring the domain name of the intermediate proxy service and a port item for configuring the listening port. The service domain name item and the port item can be respectively represented as server_name and listen. Taking the kubernetes service with the k8s namespace of "default" as an example, the service domain name item can be configured as: gmproxy.default.svc.cluster.local, and the port item can be configured as "443 ssl http2". Among them, "443 ssl http2" represents the port defaultly used by the access party.

[0098] Specifically, the intermediate proxy service can synchronize the SM2 signature certificate to the target service during the handshake process, so that the target service can obtain the signature public key in the SM2 signature certificate. After encrypting the target access request based on the communication key, the intermediate proxy service generates a signature value for the encrypted target access request based on the signature private key in the SM2 signature information, and sends the signature value to the target service. For example, first perform a hash calculation on the encrypted target access request to obtain a hash value, and then encrypt the hash value with the signature private key to obtain the signature value.

[0099] Correspondingly, the target service first performs signature verification on the signature value using the signature public key. If the verification passes, then perform the operation of decrypting the received encrypted target access request using the communication key. Exemplarily, when performing signature verification on the signature value using the signature public key, first perform a hash calculation on the encrypted target access request to obtain a verification hash value. Then, decrypt the signature value using the signature public key to obtain the decrypted hash value. If the verification hash value is the same as the decrypted hash value, it is determined that the signature value passes the signature verification. Otherwise, it is determined that the signature value fails the signature verification.

[0100] In the embodiments of the present invention, by pre-configuring the storage path of the national cryptography signature information in the first configuration file, the intermediate proxy service can obtain the national cryptography signature information based on the storage path of the national cryptography signature information, and perform signature verification with the target service based on the national cryptography signature information, further improving the security of national cryptography communication.

[0101] Refer to Figure 2 , which shows a block diagram of an access request processing device provided by an embodiment of the present invention. The device can be applied to any intermediate proxy service in the container platform, and the intermediate proxy service is associated with at least one national cryptography communication service in the container platform, such as Figure 2 As shown, the access request processing device may specifically include:

[0102] A receiving module 201, configured to receive a target access request sent by an access party; the target access request is used to access a target service, and the target service is the national cryptography communication service associated with the intermediate proxy service. The domain name of the national cryptography communication service recorded by the access party has been pre-synchronized as the domain name of the intermediate proxy service;

[0103] A first processing module 202, configured to send the target access request to the target service in a national cryptography communication manner based on the national cryptography communication related information and the target address information pre-configured in the first configuration file; the first configuration file is the configuration file of the intermediate proxy service, and the target address information is the address information of the target service;

[0104] A return module 203, configured to send the response data returned by the target service to the access party.

[0105] Optionally, in the case where the intermediate proxy service is associated with multiple national cryptography communication services, the service identifiers and address information of the national cryptography communication services associated with the intermediate proxy service are pre-configured in the first configuration file; the device further includes:

[0106] An extraction module, configured to extract the service identifier of the target service carried in the target access request as a target identifier;

[0107] An acquisition module, configured to acquire, from the first configuration file, the address information corresponding to the service identifier that is the same as the target identifier as the target address information.

[0108] Optionally, in the case where the intermediate proxy service is associated with one national cryptography communication service, the address information of the national cryptography communication service associated with the intermediate proxy service is pre-configured in the first configuration file; the device further includes:

[0109] A reading module, configured to directly read the address information in the first configuration file as the target address information.

[0110] Optionally, the intermediate proxy service and the at least one national cryptography communication service are pre-associated through the following modules in the control service:

[0111] A first determination module, configured to determine the services in the container platform that require access through national cryptography communication as the national cryptography communication services;

[0112] A second determination module, configured to determine the national cryptography communication services to be associated for the intermediate proxy service;

[0113] A first setting module, configured to, when the number of the national cryptography communication services to be associated is 1, set the address information of the national cryptography communication service to be associated in the proxy information configuration item of the first configuration file;

[0114] A second setting module, configured to, when the number of the national cryptography communication services to be associated is greater than 1, set the service identifiers and address information of the national cryptography communication services to be associated in the proxy information configuration item.

[0115] Optionally, the first determination module is specifically configured to:

[0116] Determine the application services in the container platform with a specified identification field as the national cryptography communication services;

[0117] And / or, determine the application services in the container platform with a specified service type as the national cryptography communication services.

[0118] Optionally, the domain name of the intermediate proxy service is pre-synchronized through the following modules:

[0119] A second processing module, configured to determine the services in the container platform that do not support national cryptography communication as the access parties, and obtain the domain name of the intermediate proxy service;

[0120] A modification module, configured to, for any one of the access parties, modify the domain names of the national cryptography communication services associated with the intermediate proxy service saved in the second configuration file to the domain name of the intermediate proxy service; the second configuration file is the configuration file of the access party.

[0121] Optionally, the information related to national cryptography communication includes: the storage path of the national cryptography encryption information corresponding to the domain name of the intermediate proxy service and the national cryptography protocol information; the first configuration file is pre-configured through the following modules: a third setting module, configured to set the values of the encryption information item and the protocol information item in the first configuration file to the storage path of the national cryptography encryption information and the national cryptography protocol information respectively;

[0122] The first processing module 202 is specifically configured to:

[0123] Load the national cryptography encryption information based on the storage path of the national cryptography encryption information;

[0124] Establish a connection with the target service based on the national cryptography protocol information and the target address information, and negotiate a communication key with the target service based on the national cryptography encryption information;

[0125] Encrypt the target access request based on the communication key and send the encrypted target access request to the target service.

[0126] Optionally, the information related to national cryptography communication further includes: the storage path of the national cryptography signature information corresponding to the domain name of the intermediate proxy service; the first configuration file is further pre-configured through the following module: a fourth setting module, configured to set the signature information item in the first configuration file to the storage path of the national cryptography signature information;

[0127] The device further includes:

[0128] A loading module, configured to load the national cryptography signature information based on the storage path of the national cryptography signature information;

[0129] A generating module, configured to generate a signature value for the target access request based on the national cryptography signature information for signature verification by the target service.

[0130] In summary, in the access request processing device provided by the embodiments of the present invention, the intermediate proxy service receives a target access request sent by an access party; the target access request is used to access a target service, and the target service is a national cryptography communication service associated with the intermediate proxy service. The domain name of the national cryptography communication service recorded by the access party is pre-synchronized as the domain name of the intermediate proxy service. Based on the national cryptography communication-related information and the target address information pre-configured in the first configuration file, the target access request is sent to the target service in the manner of national cryptography communication; the first configuration file is the configuration file of the intermediate proxy service, and the target address information is the address information of the target service. The response data returned by the target service is sent to the access party. In this way, by pre-associating the national cryptography communication service with the intermediate proxy service in the container platform, since the domain name of the national cryptography communication service associated with the intermediate proxy service recorded by the access party is pre-synchronized as the domain name of the intermediate proxy service, when the access party requests to access the target service associated with the intermediate proxy service, the target access request is received by the intermediate proxy service, and the intermediate proxy service, according to the target access request, interacts with the target service on behalf of the access party in the manner of national cryptography communication, ensuring that the national cryptography communication method is used when interacting with the target service, that is, ensuring that the target service is accessed in the manner of national cryptography communication, and further ensuring the access security of the national cryptography communication service.

[0131] Referring to Figure 3 is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. As Figure 3 shown, the electronic device includes: a processor, a memory, a communication interface, and a communication bus.

[0132] The processor, the memory, and the communication interface complete communication with each other through the communication bus; the memory is used to store executable instructions, and the executable instructions cause the processor to execute the access request processing method of the foregoing embodiment. The executable instructions can form a program. Embodiments of the present invention also provide one or more machine-readable media, on which instructions are stored, and when executed by one or more processors, cause the processors to be able to execute the access request processing method of the foregoing embodiment.

[0133] Each embodiment in this specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other.

[0134] Those skilled in the art should understand that the embodiments of the present invention may be provided as a method, an apparatus, or a computer program product. Therefore, the embodiments of the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the embodiments of the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0135] It should be noted that all actions of obtaining signals, information, or data in this application are carried out on the premise of complying with the corresponding data protection regulations and policies of the country where it is located and obtaining authorization from the owner of the corresponding device.

[0136] The embodiments of the present invention are described with reference to the flowcharts and / or block diagrams of methods, terminal devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram, as well as the combination of flows and / or blocks in the flowchart and / or block diagram, can be realized by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing terminal devices generate a device for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0137] These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing terminal device to work in a predictive manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device realizes the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0138] These computer program instructions can also be loaded onto a computer or other programmable data processing terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable terminal device provide steps for realizing the functions specified in Figure 1 one flow or multiple flows and / or blocks Figure 1 one block or multiple blocks.

[0139] Although the preferred embodiments of the embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications once they know the basic creative concept. Therefore, the appended claims are intended to be construed to include the preferred embodiments as well as all changes and modifications falling within the scope of the embodiments of the present invention.

[0140] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0141] Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or terminal device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the element.

[0142] The above has introduced in detail a method for processing access requests, a device for processing access requests, an electronic device, and one or more machine-readable media provided by the present invention. Specific examples are used in this text to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A method for processing an access request, characterized in that: Applied to any intermediate proxy service in a container platform, the intermediate proxy service is associated with at least one national secret communication service in the container platform, the method comprising: Receive a target access request sent by a visitor; the target access request is used to access a target service, the target service is the national secret communication service associated with the intermediate proxy service, and the domain name of the national secret communication service recorded by the visitor is pre-synchronized as the domain name of the intermediate proxy service; the national secret communication service is a service in the container platform that requires national secret communication for access, and the visitor is a service in the container platform that does not support national secret communication; Based on the storage path of the national secret encryption information corresponding to the domain name of the intermediate proxy service in the national secret communication related information pre-configured in the first configuration file and the target address information, the target access request is sent to the target service in the form of national secret communication; the first configuration file is the configuration file of the intermediate proxy service, and the target address information is the address information of the target service; the national secret encryption information includes a national secret encryption certificate and an encrypted private key; The response data returned by the target service is sent to the accessing party.

2. The method according to claim 1, characterized in that In the case where the intermediate proxy service is associated with a plurality of the national secret communication services, the first configuration file is pre-configured with service identifiers and address information of each of the national secret communication services associated with the intermediate proxy service; the method further includes: Extracting the service identifier of the target service carried in the target access request as the target identifier; Acquire address information corresponding to the service identifier and consistent with the target identifier from the first configuration file as the target address information.

3. The method according to claim 1, characterized in that: In the case where the intermediate proxy service is associated with one of the national secret communication services, the first configuration file is pre-configured with address information of the national secret communication service associated with the intermediate proxy service; The method further comprises: The address information in the first configuration file is directly read as the target address information.

4. The method according to any one of claims 1 to 3, characterized in that: The intermediate proxy service is associated with the at least one national secret communication service through the following steps pre-performed by the control service: Determine the service in the container platform that requires access via national secret communication as the national secret communication service; Determining a national secret communication service to be associated for the intermediate proxy service; When the number of the national secret communication service to be associated is 1, in the proxy information configuration item of the first configuration file, the address information of the national secret communication service to be associated is set; When the number of the national secret communication services to be associated is greater than 1, the service identifier and address information of each of the national secret communication services to be associated are set in the proxy information configuration item.

5. The method according to claim 4, characterized in that The determining the service in the container platform that requires national secret communication for access as the national secret communication service includes: Determine the application service with the specified identification field set in the container platform as the national secret communication service; And / or, determining an application service of a specified type of service in the container platform as the national secret communication service.

6. The method according to any one of claims 1 to 3, characterized in that: The domain name of the intermediate proxy service is pre-synchronized through the following steps: Determine the service that does not support national secret communication in the container platform as the access party, and obtain the domain name of the intermediate proxy service; For any of the access parties, the domain names of the national secret communication services associated with the intermediate proxy service stored in the second configuration file are modified to the domain name of the intermediate proxy service; the second configuration file is the configuration file of the access party.

7. The method according to claim 1, characterized in that The information related to national secret communication includes: the storage path of the national secret encryption information corresponding to the domain name of the intermediate proxy service and the national secret protocol information; the first configuration file is configured by pre-performing the following steps: setting the values ​​of the encryption information item and the protocol information item in the first configuration file to the storage path of the national secret encryption information and the national secret protocol information respectively; The method of sending the target access request to the target service in a national secret communication manner based on the storage path of the national secret encrypted information corresponding to the domain name of the intermediate proxy service in the national secret communication related information pre-configured in the first configuration file and the target address information includes: Loading the national secret encrypted information based on the storage path of the national secret encrypted information; Based on the national secret protocol information and the target address information, establish a connection with the target service, and negotiate a communication key with the target service based on the national secret encryption information; The target access request is encrypted based on the communication key, and the encrypted target access request is sent to the target service.

8. The method according to claim 7, characterized in that The information related to national secret communication also includes: a storage path of national secret signature information corresponding to the domain name of the intermediate proxy service; the first configuration file is also configured by the following steps performed in advance: setting the signature information item in the first configuration file to the storage path of the national secret signature information; After encrypting the target access request based on the communication key, the method further includes: Load the national secret signature information based on the storage path of the national secret signature information; A signature value is generated for the target access request based on the national secret signature information, so that the target service can perform signature verification.

9. An access request processing device, characterized in that: Applied to any intermediate proxy service in a container platform, the intermediate proxy service is associated with at least one national secret communication service in the container platform, the device comprising: A receiving module, configured to receive a target access request sent by a visitor; the target access request is used to access a target service, the target service is the national secret communication service associated with the intermediate proxy service, and the domain name of the national secret communication service recorded by the visitor is pre-synchronized as the domain name of the intermediate proxy service; the national secret communication service is a service in the container platform that requires national secret communication for access, and the visitor is a service in the container platform that does not support national secret communication; A first processing module, configured to send the target access request to the target service in a national secret communication manner based on the storage path of the national secret encryption information corresponding to the domain name of the intermediate proxy service in the national secret communication related information pre-configured in the first configuration file and the target address information; the first configuration file is the configuration file of the intermediate proxy service, the target address information is the address information of the target service; the national secret encryption information includes a national secret encryption certificate and an encryption private key; The return module is used to send the response data returned by the target service to the accessing party.

10. An electronic device, characterized in that: include: A processor, a memory, a communication interface and a communication bus, wherein the processor, the memory and the communication interface communicate with each other via the communication bus; The memory is used to store executable instructions, and the executable instructions enable the processor to execute the method according to any one of claims 1 to 8.

11. One or more machine-readable media, characterized in that Instructions are stored thereon, which, when executed by one or more processors, cause the processors to perform the method as claimed in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Method and device for accessing Kubernetes cluster, electronic equipment and medium

    CN111274591A