A cloud password service platform and method for a server
The method enhances cloud platform key distribution by securely segmenting and encrypting cloud passwords using Shamir's secret sharing, ensuring only authorized terminals can reconstruct them, thereby improving security and efficiency.
Patent Information
- Application Number
- CN202510519735.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-24
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2045-04-24
AI Technical Summary
There are security challenges in key distribution of existing cloud platforms, and the security of the system needs to be further improved.
By selecting several application servers to generate an application program interface list, generating and segmenting cloud passwords, using the Shamir password sharing method to distribute the key fragments to the application server, and encrypting and signing through the terminal's public key and the server's private key, and the terminal decrypts and restores the cloud password.
It improves the security and controllability of cloud password distribution, reduces the risk of information leakage, and enhances the security of the system.
Smart Images

Figure CN120034332B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information security, and particularly relates to a cloud password service platform and method for a server. Background Art
[0002] Currently, the key distribution of cloud platforms remains a challenging issue.
[0003] CN108540486A discloses a method for generating and using cloud keys. The method includes: receiving a public key of a first key pair and a key generation request sent by a user; generating a second key pair and a random number; encrypting the second key pair with the random number to obtain a first ciphertext of the second key pair; encrypting the random number with the public key of the first key pair to obtain a second ciphertext of the random number; and saving the first ciphertext and the second ciphertext. The present invention generates keys through a cloud server and adopts layer-by-layer protection for the generated keys with random codes and key pairs, enabling users to conveniently obtain the private key of the keys while having high security.
[0004] CN110830242A discloses a key generation, management method and server for solving the technical problem of easy key leakage. The key generation method includes: generating a corresponding key pair at regular intervals, where a key pair includes a private key and a public key; dividing the generated private key into multiple private key segments and storing them in multiple second servers respectively, and sending the generated public key to a target terminal. The key management method includes: storing a corresponding private key segment; receiving a service request encrypted with a public key sent by the target terminal, and determining the terminal identifier of the target terminal; respectively obtaining the private key segments corresponding to the target terminal from each other second server and splicing them to obtain a complete private key; and performing decryption verification based on the private key. The key generation, management method and server improve the security of user key information.
[0005] CN106603485B discloses a key negotiation method and device. The method includes: generating a first random number, encrypting the first random number and the identification information of the terminal device with the first public key of the cloud server to generate a first ciphertext; sending a key negotiation request including the first ciphertext and the second public key of the terminal device to the cloud server; receiving, after the cloud server verifies the legality of the terminal device, a key negotiation response including a second ciphertext sent after encrypting a session key including the first random number with the second public key; decrypting the second ciphertext with the second private key, encrypting a first string previously negotiated with the cloud server with the session key when obtaining the first random number, and sending a key confirmation response including a third ciphertext to the cloud server. The method can complete the mutual authentication of the terminal device and the cloud server, establish a reliable secure connection, reduce costs, improve the security of data transmission and have high efficiency.
[0006] CN116886317B discloses a method, system and device for distributing keys between a server and a terminal device. The method includes: after the terminal device and the server verify the legality of the received certificates of each other, they each generate a key pair. After the server verifies the legality of the terminal device hardware serial number sent by the terminal device based on the terminal device certificate and the terminal device verifies the legality of the server code based on the server certificate, the terminal device and the server respectively generate an intermediate key according to the private key of the key pair generated by themselves and the public key of the key pair generated by the other party, generate a protection key according to the intermediate key, the terminal device hardware serial number and the server code, the server generates an application master key according to the terminal device information and stores it, encrypts the application master key with the protection key to obtain an application master key ciphertext, and sends the application master key ciphertext to the terminal device; the terminal device decrypts the application master key ciphertext with the protection key to obtain the application master key, and stores the terminal device information and the application master key in correspondence.
[0007] WO2025016183A1 provides a data processing method and related devices. The method includes: when detecting a service request initiated by an application program, obtaining a temporary key randomly allocated for the service request; encrypting the temporary key with a certificate public key to obtain an encrypted temporary key; the certificate public key is preset in the source code of the application program; the certificate private key corresponding to the certificate public key is stored in the server; encrypting the request data of the service request with the temporary key to obtain a ciphertext; generating a network response request packet according to the encrypted temporary key and the ciphertext, and sending the network response request packet to the server, where the network response request packet is used to request the server to respond to the service request. Embodiments of the present application can ensure data security during data transmission and can save resource overhead of the server.
[0008] Based on the prior art, it is desired to further improve the security of the system. Summary of the Invention
[0009] At least one aspect and advantage of the present invention will be partially described in the following description, or will be obvious from the description, or can be obtained by practicing the subject matter of the present disclosure for password distribution.
[0010] According to an embodiment of the present invention, a cloud password service method for a server includes:
[0011] A first terminal sends a first request to a first server;
[0012] The first server responds to the first request, selects several application servers from the first list of application servers to obtain the first list of application program interfaces, generates the first information according to the first list of application program interfaces, sends the first information to the first terminal, and generates and sends the first message to the first list of application program interfaces based on the first request and the first information;
[0013] The second server generates a cloud password at least in response to the first message, sets the password for the target terminal through the host, and after the setting is completed, segments the cloud password and sends it as a secret to the first list of application program interfaces;
[0014] The first terminal obtains the key shards based on the first list of application program interfaces or through the first server, and obtains the cloud password based on the decryption of the key shards.
[0015] According to an embodiment of the present invention, the first request includes a request entity and the public key of the user, and the request entity contains information of the target terminal;
[0016] The first information is obtained according to the following method:
[0017] Determine the available list of application servers according to the region where the first terminal is located, select several application servers from the list of application servers to obtain the second list of servers; determine the list of application program interface information according to the application servers in the second list of servers, and generate the first information based on the application program interface information. The first information includes the application program interface information and the public key of the second server.
[0018] According to an embodiment of the present invention, in response to the number of available application servers determined according to the region where the first terminal is located being lower than the first threshold, the available list of application servers determined according to the region where the first terminal is located is used as the second list of application servers, and the application servers in other regions are sorted in ascending order of the distance from the region of the first terminal. The region of the first terminal is determined by its IP address, and the first m items are taken as the third list of application servers. The first list of application servers is obtained according to the second list of application servers and the third list of application servers, where m is a natural number not exceeding 20.
[0019] According to an embodiment of the present invention, the second server generates a cloud password at least in response to the first message and the second message;
[0020] The first message contains the target terminal information and the first information in the first request;
[0021] The process of obtaining the second message includes:
[0022] The first terminal selects a third server from the first application server list. The first terminal sends second request information to the third server. The third server creates a second message in response to the second request information and sends it to the second server. The second message includes the public key of the first terminal.
[0023] According to an embodiment of the present invention, when distributing sub-ciphertexts, the m segmented sub-ciphertexts and access tokens are distributed to the application servers within the fourth application server list, where the fourth application server list is a subset of the application servers corresponding to the first application programming interface list and does not include the third application server.
[0024] According to an embodiment of the present invention, the first message includes the target terminal information, the first information, and the public key of the first terminal in the first request.
[0025] According to an embodiment of the present invention, the second server sending the cloud password segmented as a secret to the first application programming interface list includes:
[0026] The cloud password is encrypted using the public key of the first terminal to obtain the encrypted cloud password. Then, the encrypted cloud password is signed using the private key of the second server to obtain the encrypted cloud password signature. The encrypted cloud password and the password signature are combined to obtain the first ciphertext.
[0027] The first ciphertext is divided into m segments. The m segmented sub-ciphertexts and access tokens are distributed to the application servers within the first application server list through the application programming interfaces within the first application programming interface list using the Shamir secret sharing method. The access token is used for the application server to authenticate the first terminal or the first server.
[0028] According to an embodiment of the present invention, the process by which the first terminal obtains the encrypted key information includes:
[0029] The first terminal sends a sub-ciphertext acquisition request to the application programming interfaces within the first application programming interface list.
[0030] In response to obtaining sub-ciphertexts not less than the first value, the first terminal performs secret recovery.
[0031] After completely obtaining the secret distributed by the second server, the obtained secrets are combined and decrypted to obtain the cloud password.
[0032] According to an embodiment of the present invention, in response to the token included in the user request corresponding to the saved token, the application programming interface returns the secret as a response and deletes the request token of the first terminal and the corresponding secret on the application server.
[0033] According to an embodiment of the present invention, the first terminal obtains key shards based on a first application programming interface list or through a first server:
[0034] The first terminal initiates a ciphertext acquisition request to the first server. The first server responds to the request of the first terminal, obtains the secret shared by the second server from the second application server, sends the obtained secret to the first terminal, and generates a third message based on the obtained secret and sends it to the second server.
[0035] According to an embodiment of the present invention, the servers in the second server list respond to the requests of the first terminal or the first application server, send ciphertext fragments, corresponding tokens, and the saved ciphertext fragments, and construct a fourth request to send to the second application server. When the number of responses to the fourth request reaches a first threshold, the second server sends a fourth message to the servers in the second server list, and the second server deletes the ciphertext in response to the fourth message.
[0036] According to an embodiment of the present invention, the second application server deletes the saved ciphertext in response to a user request, an instruction from the second server, or when the save duration of the ciphertext reaches a first duration threshold.
[0037] According to an embodiment of the present invention, a cloud password service platform for a server includes:
[0038] A first server, configured to respond to a first request issued by a first terminal used by a user, select several application servers from a first application server list to obtain a first application programming interface list, generate first information according to the first application programming interface list, send the first information to the first terminal, and generate a first message based on the first request and the first information and send it to the first application programming interface list;
[0039] A second server, at least generating a cloud password in response to the first message, setting the password for the target terminal through the host, and after the setting is completed, segmenting the cloud password as a secret and sending it to the first application programming interface list;
[0040] The first terminal obtains key shards based on the first application programming interface list or through the first server, and obtains the cloud password based on the decryption of the key shards.
[0041] The method and system of the present invention can enhance the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 It is a flowchart of a cloud password service method for a server in an embodiment of the present invention;
[0043] Figure 2 It is a structural diagram of a cloud password service platform for a server in an embodiment of the present invention. Detailed implementation manners
[0044] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0045] The terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that such used data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices. When expressing with an application server, it means that the corresponding application program is deployed on the server. It should also be understood that the loading of a new application program can be achieved in the form of hot deployment, or similar functions can be achieved through containerization technology, so that the server provides services in the form of an application server.
[0046] According to an embodiment of the present invention, referring to Figure 1 as shown, a cloud password service method for a server includes:
[0047] A first terminal sends a first request to a first server;
[0048] The first server responds to the first request, selects several application servers from the first application server list to obtain a first application program interface list, generates first information according to the first application program interface list, sends the first information to the first terminal, and generates a first message based on the first request and the first information, and sends it to the first application program interface list;
[0049] A second server generates a cloud password at least in response to the first message, sets the password for the target terminal through the host, and after the setting is completed, segments the cloud password and sends it as a secret to the first application program interface list;
[0050] The first terminal obtains key shards based on the first application program interface list or through the first server, and obtains the cloud password based on the decryption of the key shards.
[0051] Among them, the first terminal is the terminal used by the user, which can be a browser, an application App, or a developer SDK; usually, when the user logs in to the cloud server website, a temporary credential, i.e., a token, is obtained to indicate the user's identity. In the following text, the first terminal uses the user token for authentication. Since the cloud password is usually set within a cloud service platform, a unified token can be used; in some scenarios, the user's token is variable and can be dynamically generated by the server or generated locally by the user.
[0052] When the user resets the password, dynamically generates the password, or batch-generates the password, the first terminal sends a first request to the first server. Here, the first server can be pre-set by the application, or the server built into the SDK, or the request application server corresponding to the function triggered by the user operation.
[0053] The first terminal can configure its own certificate or key for encryption and decryption. Among them, the user's public key can be temporary. For example, it is generated during a session and then destroyed after the session ends, so as to achieve the secure transmission of information. Correspondingly, during a session, it is expected to achieve secure communication or signature by transmitting the public key to the corresponding server.
[0054] The first server responds to the first request and selects the application servers that can respond to the first terminal. These application servers implement the distribution of the cloud password based on the Shamir secret sharing method. The first application interface is used to respond to the requests of the first terminal or the first server and send the saved encrypted shard information. Then, the first server or the first terminal decrypts the encrypted shards of each piece to obtain the cloud password. For this purpose, the number of the selected first application interfaces should be greater than the minimum number of secret holders required for decryption. Furthermore, considering that the first terminal may not be able to access some application service interfaces, such as the corresponding application service runs on an IPv6 server and the first terminal does not support the IPv6 protocol, or the first terminal cannot access due to network reasons, a larger value should be considered. That is, the user can flexibly select the number of the first application interfaces according to the requirements of the security classification level. For example, if it is set to 20, 20 should be selected from the corresponding available application interfaces as the first application interface list. Those skilled in the art can understand that in order to achieve secret sharing and communication, the application interfaces running on these application servers must be able to communicate with the first server and the second server and accept the requests of the first terminal.
[0055] Further, the first server first responds to the first terminal, that is, it informs that the request has been created and the list of second servers that the first terminal can access. In most cases, it is not desired that the first terminal can access the interfaces in the first application programming interface list. For example, the user's device may be located in a public network. At this time, the generated first message may not include the specific information of the interfaces, but only include information such as the number of servers generated based on the first application programming interface list. In an enterprise internal network, where the user can access the interfaces in the first application programming interface list without significantly posing a risk to information security, the response interface information can be returned to the first terminal as the content of the first message. Subsequently, the first server sends the request for creating information to the second server. Generally, the second server isolates the first terminal, or the second server does not directly provide interfaces that can be accessed by the first terminal. For example, user access is controlled by configuring permitted host information. The information sent by the first server to the second server contains the content created based on the first request and the first information. The first request is used to indicate the creation of a cloud host corresponding to a cloud password task, which is usually a string and may further include, for example, the user's token information to determine whether the user has the permission to operate on the cloud host. In the present invention, it further includes the first application programming interface list information for the second server to process the corresponding cloud password after generating it and distribute it to the second application programming interface list for the first terminal to decrypt and obtain the corresponding cloud password.
[0056] In most scenarios, a TLS communication mode can be configured between various communicating parts, and on this basis, encryption can be further used to obtain better information security to reduce information leakage.
[0057] The host is a physical computer or server running virtualization software or container management program, responsible for providing hardware resources and managing the operation of virtual machines or containers. It sets or resets passwords through the SDK provided by the platform. In some cases, shutting down the cloud host is required for password setting or resetting here. At this time, there may be a possibility that the new password generation fails due to the cloud host not being shut down. Therefore, for a system where the cloud host is running and shutting down is required to modify the password, it is possible to check the status of the cloud host before performing the password operation.
[0058] After setting or resetting the password, the new cloud password can be processed and distributed to the first application interface by calling the API. For example, a cloud password (19 digits) can be split into 10 parts, and at least 4 parts are required to reconstruct the secret. Then the corresponding cloud password is first converted into binary or other processable forms, and then a polynomial is constructed to calculate the secret value of each character or shard. For example, when calculating by character, the secret corresponding to one character is generally less than 128, while if the secret value is the value corresponding to two characters, the corresponding secret value will be higher than 128. Generally speaking, the time required to set the password and distribute the password is relatively short, usually within a few seconds. Therefore, the first terminal or the first server can obtain each secret after a fixed time, such as 6 seconds, and restore the message based on the obtained secret.
[0059] Taking the ciphertext above as an example, a series of secrets are obtained after the cloud password is segmented. These secrets are distributed to the first application interface. The first terminal or the first server can obtain a series of messages by accessing the interface. After obtaining each secret, a segment of the password can be obtained through decryption. Combining all the password segments together obtains the original password. For example, if a cloud password has 20 secrets to be shared, the first terminal or the first server needs to perform 20 reconstructions of the secrets. When any one fails, it means that an attack may occur, and the user should take other security operations.
[0060] Obviously, what is sent to the list of the first application interfaces can be the shards of the password or the encrypted information. For example, in a process, the second server can further encrypt the password using the public key of the first terminal, and then sign the obtained message using the private key. The obtained encrypted message and signature are shared as secrets.
[0061] In this way, the security factor of the system can be improved.
[0062] According to an embodiment of the present invention, the first request includes a request entity and the public key of the user, and the request entity contains information about the target terminal;
[0063] The first information is obtained according to the following method:
[0064] Determine a list of available application servers according to the region where the first terminal is located, and select several application servers from the list of application servers to obtain a second server list; determine a list of application interface information based on the application servers in the second server list, and generate the first information based on the application interface information. The first information includes application interface information and the public key of the second server.
[0065] The first server can select a suitable server according to the region to provide a faster response speed. When a user makes a creation request, it is generally targeted at a server in a specific region, such as "Tianjin Area 1", "Guangzhou Area 2", "Beijing Area 3". Based on the region, an application programming interface server can be selected to provide services; the request entity of the user can contain the ID of the server to be reset; since the user's information can be retrieved on the server side, in most cases, the user's terminal information and the user's authentication information need to be provided. For example, the user token information mentioned above can be used to complete the identification of the user.
[0066] Furthermore, the region where the first terminal is located can be obtained based on its actual IP address. For example, the first two digits of an IP address in the form of xx.xx.xx.xx can be obtained through an IP address library to obtain the region where the user is located, and then the registered application server can be obtained in the corresponding region.
[0067] Furthermore, the public key of the user can be provided to the first server, and this key can be synchronized to the second server, which can make the information distributed by the second server encrypted ciphertext when distributing the cloud password, and this encrypted information can only be read by the first terminal. To avoid information forgery, the first server can send the public key of the second server it stores as a component of the first information to the first terminal, so that the first terminal can verify the signature of the message decrypted based on secret sharing.
[0068] Furthermore, the application programming interface information list can be provided in the form of URL:port. The URL is the address of the application server, and the port is the corresponding port. The corresponding information can be obtained through the POST or get method, or through a restful form call. When the first terminal accesses the interface, a corresponding token can be provided to obtain the corresponding resources. For example, the user token included in the first request can be provided to the corresponding application programming interface by the second server for verification, or the second server can generate a new user token for the first terminal or the first server to obtain the corresponding information.
[0069] In an embodiment of the present invention, the first message further includes the public key of the second server. The public key of the second server is regularly synchronized to the first server, or obtained from the second server upon request before generating the first message.
[0070] In this way, the security of information can be further guaranteed.
[0071] According to an embodiment of the present invention, in response to determining that the number of available application servers determined according to the region where the first terminal is located is lower than the first threshold, the list of available application servers determined for the region where the first terminal is located is used as the second server list, and the application servers in other regions are sorted in ascending order of distance from the region of the first terminal. The region of the first terminal is determined by its IP address, and the first m items are taken as the third server list. The first application program interface list is obtained according to the second application server list and the third application server list; and the first application server list is obtained according to the application program information provided thereby, where m is a natural number not exceeding 20. The first application program interface list can be obtained by merging (for example, if 20 items are needed and the number of second application servers is 12, then 8 more servers are taken from the second application servers to construct the first application program interface list), or by randomly removing elements after merging sets.
[0072] In this way, the number of people for secret distribution can meet the requirements, that is, at this time, the first server determines the first application server list depending on the region where the first terminal is located and the adjacent regions of the region where the first terminal is located. However, it should be noted that such processing may potentially increase the response time. Therefore, the available servers within the region can be arranged according to the required number of requests.
[0073] According to an embodiment of the present invention, the second server generates cloud passwords at least in response to the first message and the second message;
[0074] The first message includes the target terminal information and the first information in the first request;
[0075] The process of obtaining the second message includes:
[0076] The first terminal selects a third server from the first application server list, the first terminal sends second request information to the third server, the third server creates a second message in response to the second request information, and sends it to the second server. The second message includes the public key of the first terminal.
[0077] In this way, the request for creating cloud passwords can be established based on a channel different from the first server. Correspondingly, the server side can also establish a verification mechanism. When receiving a first message and a second message, cloud passwords will be created and distributed. If other terminals outside the first terminal create the second message, the user will be unable to create cloud passwords, that is, the user will receive a prompt. If other users construct approximate requests (such as creating a third message similar to the second message) after the first message and the second message are sent, since the second server lacks a new first message corresponding to the third message, the second server will reject the illegal request, thereby improving the security factor.
[0078] According to an embodiment of the present invention, when distributing the sub-ciphertext, the m segmented sub-ciphertexts and access tokens are distributed to the application servers in the fourth application server list, where the fourth application server list does not include the third application server.
[0079] In this way, the application program server that acts as a "bridge" can be excluded from the secret sharing scope, further improving the security factor. It should be understood that the selected third application server can be the application server corresponding to the application interface in the first application interface list, or other servers, such as resources pre-configured on the page in other forms.
[0080] According to an embodiment of the present invention, the first message includes the target terminal information, the first information, and the public key of the first terminal in the first request.
[0081] By configuring the first message to include the target terminal information in the first request, authentication information can be provided to avoid unauthorized access; by providing the first information, the second server can distribute the secret to the first terminal or the terminal known to the first server, so that the secret distribution is carried out in a controlled way; by providing the public key of the first terminal, the secondary encryption of the cloud password can be realized, improving the security factor.
[0082] According to an embodiment of the present invention, the second server encrypts and segments the cloud password and sends it to the first application interface list, including:
[0083] The cloud password is encrypted using the public key of the first terminal to obtain the encrypted cloud password, and then the encrypted cloud password is signed using the private key of the second server to obtain the encrypted cloud password signature. The encrypted cloud password and the password signature are combined to obtain the first ciphertext;
[0084] The first ciphertext is divided into m segments, and the m segmented sub-ciphertexts and access tokens are distributed to the application servers in the first application server list through the application interfaces in the first application interface list. The access token is used for the application server to authenticate the first terminal or the first server.
[0085] In this way, encrypted information can be transmitted, and only the first terminal can read this information.
[0086] In another embodiment of the present invention, the second server encrypts and segments the cloud password and sends it to the servers in the second server list, including:
[0087] The cloud password is segmented into n segments. The n segmented passwords are encrypted using the public key of the first terminal to obtain a series of password shards. Then, the private key of the second server is used to sign the password shards to obtain signatures corresponding to the password shards. The password shards and the corresponding signatures are combined to obtain the first sequence to be distributed;
[0088] After that, the first sequence to be distributed is traversed, and each element in it is divided into m segments. The Shamir password sharing method is used to distribute the m segmented sub-ciphertexts and access tokens to the application servers in the second server list through the application interfaces in the first application interface list. The access token is used for the application server to authenticate the first terminal or the first server;
[0089] The first terminal or the first server obtains the corresponding secrets from the second server list, combines and decrypts the secrets to obtain secret values, combines multiple secret values to obtain one containing the encrypted password shards and a digest. Then, the public key of the second server is used to verify the signature. If the signature is correct, the private key of the first terminal is used to decrypt the encrypted password shards to obtain a password fragment, and all the password fragments are combined to obtain the complete cloud password. This method further improves the security performance by increasing the encoding and transmission rules of the password.
[0090] It should be understood that the access token here can be the same as the user's token, or it can be a new token generated by the second server. If it is the latter, the token generated by the second server can be sent to the first server, and the first terminal can obtain the access token by querying or through two-way communication; if it is the former, each application server can prevent a message from being obtained by multiple terminals by deleting the token in combination with the access times limit. For example, after the first terminal finishes accessing, the acceptable token is deleted, so that other terminals cannot obtain the secret information, or other terminals obtain the next secret information. When the first terminal continues to access after it obtains the message, it will prompt a failure, thus prompting the user of a security risk.
[0091] According to an embodiment of the present invention, the process for the first terminal to obtain the encrypted key information includes:
[0092] The first terminal sends a sub-ciphertext acquisition request to the application interfaces in the first application interface list;
[0093] In response to obtaining sub-ciphertexts not less than the first value, the first terminal performs secret recovery;
[0094] After completely obtaining the secrets distributed by the second server, the obtained secrets are combined and decrypted to obtain the cloud password.
[0095] Through this process, the first terminal can obtain the complete password.
[0096] It should be understood that this process is executed multiple times. For example, when a first terminal sends a sub-ciphertext acquisition request to an application programming interface in the application interface list of a second server, the returned JSON object may contain the total number of secrets. The first terminal can obtain secrets from multiple application programming interfaces multiple times or one by one, and obtain the secret value based on the restoration of the secrets. After completing the restoration of the secret values that are consistent with the number of secrets of the second server, the secret values can be combined to obtain the encrypted cloud password. The first value mentioned above is the minimum number of sub-ciphertexts required to restore the secret.
[0097] According to an embodiment of the present invention, in response to the token included in the user request corresponding to the saved token, the application programming interface returns the secret as a response, and deletes the request token of the first terminal and the corresponding secret on the application server.
[0098] In this way, one or more acceptable numbers of secrets can always be saved on the application server to prevent the secrets from being read by multiple people. After a secret is read, other terminals cannot obtain the same message. If combined with global information, such as the number of times a secret is read, and combined with the reading records reported by the first terminal or the first server, the security can be further improved.
[0099] According to an embodiment of the present invention, the first terminal obtains key shards based on the first application programming interface list or through the first server:
[0100] The first terminal sends a ciphertext acquisition request to the first server. The first server responds to the request of the first terminal, obtains the secret shared by the second server from the second application server, sends the obtained secret to the first terminal, and generates a third message based on the obtained secret and sends it to the second server.
[0101] In this way, the secret distributed by the second server is sent to the first terminal through the first server; at the same time, after obtaining the secret that meets the requirement for restoring the secret value, the first server generates a message based on the obtained secret and sends it to the second server. The second server can delete the secret that has been obtained by the first terminal through the application programming interface in the first application programming interface list, thereby improving the security factor.
[0102] According to an embodiment of the present invention, the servers in the second server list respond to the request of the first terminal or the first application server, send ciphertext fragments, the corresponding tokens and the saved ciphertext fragments, and construct a fourth request and send it to the second server. The second server responds when the number of fourth requests reaches a second threshold, sends a fourth message to the servers in the second server list, and the second server deletes the ciphertext in response to the fourth message.
[0103] In this way, when the number of secret requests associated with the same secret value by the user reaches the minimum threshold required for decryption, the secret sharing can be stopped and the secret can be deleted. Among them, the second threshold is not less than the number of the lowest secrets required to recover the secret. In most cases, it is the number of the lowest secrets required to recover the secret.
[0104] According to an embodiment of the present invention, the second server deletes the saved ciphertext in response to a user's request, an instruction of the second server, or when the saving duration of the ciphertext reaches a first duration threshold.
[0105] In this way, the controllability of secret access can be ensured. Among them, the secret is deleted in response to a user request. Deleting in response to an instruction of the second server can stop the secret sharing and delete the secret when the number of secret requests associated with the same secret value by the user reaches the minimum threshold required for decryption. To implement this function, when each application programming interface responds to a request, a request record of the secret can be sent to the second server at the same time; setting timeout deletion can empty the secret within an expected time, such as deleting the saved secret within 500 ms.
[0106] According to an embodiment of the present invention, as shown in Figure 2 a cloud password service platform for a server includes:
[0107] A first server, configured to respond to a first request sent by a first terminal used by a user, select several application servers from a first application server list to obtain a first application programming interface list, generate first information according to the first application programming interface list, send the first information to the first terminal, and generate a first message based on the first request and the first information and send it to the first application programming interface list;
[0108] A second server, configured to generate a cloud password at least in response to the first message, set a password for a target terminal through a host, and after the setting is completed, send the cloud password in segments as a secret to the first application programming interface list;
[0109] The first terminal obtains key shards based on the first application programming interface list or through the first server, and obtains the cloud password based on the decryption of the key shards.
[0110] An embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored. When the computer program runs on an electronic device, the electronic device is enabled to execute the foregoing method.
[0111] An embodiment of the present application further provides a computer program product, including: computer program code. When the computer program code runs on an electronic device, the electronic device is enabled to execute the foregoing method.
[0112] An embodiment of the present application further provides a chip, including: a processor, configured to call and run a computer program from a memory, so that an electronic device installed with the chip executes the foregoing method.
[0113] Through the description of the above embodiments, those skilled in the art can understand that for the convenience and brevity of description, only the above division of each functional module is used as an example for illustration. In actual applications, the above functions can be allocated to different functional modules according to needs, that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above.
[0114] It should be understood that the devices and processes disclosed in several embodiments of the present application can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another device. In addition, some features can be ignored or not executed. In addition, the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the device or unit can be in an electrical, mechanical or other form.
[0115] The units described as separate components may or may not be physically separated. The components displayed as units may be one physical unit or multiple physical units. That is, it can be located in one place, or it can be distributed to multiple different places. The part or all of the units can be selected according to actual needs to achieve the purpose of this solution.
[0116] In addition, each functional unit in various embodiments of the present application can be integrated in a processing unit; it can also exist physically separately; it can also be that some units are integrated in one unit and some units exist physically separately. The above integrated units can be implemented in the form of hardware or in the form of software functional units.
[0117] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on such an understanding, all or part of the technical solutions of the embodiments of the present application can be embodied in the form of a software product. The software product is stored in a storage medium. The software product includes several instructions for causing a device (which can be a single-chip microcomputer, a chip, etc.) or a processor to execute all or part of the steps of the methods in various embodiments of the present application. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disc that can store program codes.
[0118] It should be noted that all or part of the above-described various embodiments provided in the present application (for example, part or all of any feature) can be arbitrarily combined or used in combination with each other.
[0119] The above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A cloud password service method for a server, characterized in that Including: The first terminal sends a first request to the first server; The first server responds to the first request, selects several application servers from the first application server list to obtain a first application programming interface list, generates first information according to the first application programming interface list, sends the first information to the first terminal, and generates a first message based on the first request and the first information and sends it to the first application programming interface list; The second server generates a cloud password at least in response to the first message, sets the password for the target terminal through the host, and after the setting is completed, sends the cloud password in segments to the first application programming interface list; The second server sending the cloud password in segments to the first application programming interface list includes: The cloud password is encrypted using the public key of the first terminal to obtain the encrypted cloud password, and then the encrypted cloud password is signed using the private key of the second server to obtain the encrypted cloud password signature. The encrypted cloud password and the password signature are combined to obtain the first ciphertext; The first ciphertext is divided into m segments. The m segmented secrets and access tokens are distributed to the application servers in the first application server list through the application programming interfaces in the first application programming interface list. The access token is used for the application server to authenticate the first terminal. The first terminal obtains the secrets from multiple application programming interfaces in the first application programming interface list multiple times, and restores the secrets based on the restoration of the secrets to obtain the secret values. After the restoration of the secret values with the same number as the secrets of the second server is completed, the secret values are combined to obtain the encrypted cloud password; The application programming interface returns the secret as a response in response to the token included in the user request corresponding to the saved token, and deletes the request token and the corresponding secret of the first terminal on the application server; The second server deletes the saved ciphertext in response to the user's request, the instruction of the second server, or when the storage duration of the ciphertext reaches the first duration threshold; deleting the ciphertext in response to the user's request or the instruction of the second server means that when the number of secret requests by the user for the same secret value reaches the minimum threshold required for decryption, the secret sharing is stopped and the secret is deleted.
2. The cloud password service method for a server according to claim 1, wherein The first request includes a request entity and the public key of the user, and the request entity contains information about the target terminal; The first information is obtained according to the following method: Determine the available application server list according to the region where the first terminal is located, select several application servers from the application server list to obtain a second server list; determine the application programming interface information list according to the application servers in the second server list, and generate first information based on the application programming interface information. The first information includes application programming interface information and the public key of the second server.
3. A cloud password service method for a server according to claim 2, characterized in that, In response to the number of available application server lists determined according to the region where the first terminal is located being lower than the first threshold, the available application server list determined for the region where the first terminal is located is used as the second application server list. The application servers in other regions are sorted in ascending order of distance from the region of the first terminal, where the region of the first terminal is determined by its IP address, and the first m items are taken as the third application server list. The first application server list is obtained based on the second application server list and the third application server list, where m is a natural number not exceeding 20.
4. The cloud password service method for a server according to claim 1, characterized in that, The second server generates a cloud password at least in response to a first message and a second message. The first message includes the target terminal information and the first information in the first request. The process of obtaining the second message includes: The first terminal selects a third server from the first application server list, the first terminal sends second request information to the third server, the third server creates a second message in response to the second request information and sends it to the second server, and the second message includes the public key of the first terminal.
5. The cloud password service method for a server according to claim 4, characterized in that, When distributing the secret, the m segmented secrets and access tokens are distributed to the application servers within the fourth application server list, where the fourth application server list is a subset of the application servers corresponding to the first application programming interface list and does not include the third application server.
6. The cloud password service method for a server according to claim 1, wherein The first message includes the target terminal information, the first information, and the public key of the first terminal in the first request.
7. A cloud password service platform for a server, characterized in that, Includes: A first server, configured to respond to a first request issued by a first terminal used by a user, select a number of application servers from the first application server list to obtain a first application programming interface list, generate first information based on the first application programming interface list, send the first information to the first terminal, and generate a first message based on the first request and the first information and send it to the first application programming interface list. A second server, which generates a cloud password at least in response to the first message, sets a password for the target terminal through a host, and after the setting is completed, sends the segmented cloud password to the first application programming interface list. The second server sending the segmented cloud password to the first application programming interface list includes: The cloud password is encrypted using the public key of the first terminal to obtain the encrypted cloud password, and then the encrypted cloud password is signed using the private key of the second server to obtain the encrypted cloud password signature. The encrypted cloud password and the password signature are combined to obtain the first ciphertext. The first ciphertext is divided into m segments. The m segmented secrets and access tokens are distributed to the application servers within the first application server list through the application programming interfaces within the first application programming interface list using the Shamir secret sharing method. The access token is used for the application server to authenticate the first terminal. The first terminal obtains the secrets from multiple application programming interfaces in the first application programming interface list multiple times and restores the secret value based on the restoration of the secrets. After the restoration of the secret values with the same number as that of the second server is completed, the secret values are combined to obtain the encrypted cloud password. When the token included in the user request corresponding to the saved token, the application programming interface returns the secret as a response and deletes the request token of the first terminal and the corresponding secret on the application server; The second server deletes the saved ciphertext in response to a user request, an instruction from the second server, or when the save duration of the ciphertext reaches a first duration threshold; deleting the ciphertext in response to a user request or an instruction from the second server means that when the number of secret requests associated with the same secret value by the user reaches the minimum threshold required for decryption, the secret sharing is stopped and the secret is deleted.
Citation Information
Patent Citations
Key negotiation method and apparatus
CN106603485B
Cloud key generation and application method
CN108540486A
Key generation and management method and server
CN110830242A
A method, system, and device for distributing keys between a server and a terminal device.
CN116886317B
Data processing method and related device
WO2025016183A1