Account authentication method and system and related equipment

CN120034344APending Publication Date: 2025-05-23HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410217028.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-11-21
Filing Date
2024-02-27
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The existing central authentication service has a single point of failure problem, which makes the authentication service unavailable when the central node fails, reducing the reliability of account authentication.

Method used

By decentralizing the authentication function on the edge node, the edge node receives the key pair sent by the central node and issues a token for the terminal device. The terminal device requests authentication from the edge node through the token, avoiding direct dependence on the central node.

Benefits of technology

It realizes that the availability of account authentication services can be maintained when the central node fails, improves the reliability of authentication, and reduces the complexity of the authentication system and the consumption of bandwidth resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034344A_ABST
    Figure CN120034344A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an account authentication method, an account authentication system and related equipment, which are used for improving the reliability of account authentication. The account authentication method is applied to an edge node, the edge node is connected with a center node, and the method comprises the steps that a first key pair from the center node is received, the first key pair comprises a first public key and a first private key of the edge node, and the first key pair is used for authenticating a terminal account managed by the edge node. And issuing a first token to a terminal account running on the terminal device, the first token comprising a second public key and a first signature of the terminal account, and the first signature being determined according to the first private key. And receiving a first request sent by using the terminal account, the first request comprising a second token and a second signature, and the second signature being determined according to a second private key of the terminal account. The first request is authenticated based on the first key pair and the first token.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on November 21, 2023, with application number 202311558344.X and invention name “A distributed authentication method and device”, the entire contents of which are incorporated by reference in this application. Technical Field

[0002] The present application relates to the field of cloud computing, and in particular to an account authentication method, system and related equipment. Background Art

[0003] With the development of network technology, network security has also attracted public attention. In the process of network information transmission, account authentication can not only ensure communication security, but also manage the account permissions of different identities.

[0004] In the related art, a centralized authentication service is adopted, and a central service node authenticates all accounts. In other words, the authentication service is concentrated on a central node. In this technical solution, if the central node fails, all authentication services will be unable to be carried out, reducing the reliability of authentication. Summary of the invention

[0005] The present application provides an account authentication method, system and related equipment for improving the reliability of account authentication.

[0006] In a first aspect, the present application provides an account authentication method, which is applied to an edge node, where the edge node is connected to a central node.

[0007] Methods include:

[0008] The edge node receives a first key pair from the central node, the first key pair includes a first public key and a first private key of the edge node, and the first key pair is used to authenticate the terminal account managed by the edge node. In other words, the central node delegates the account authentication function to the edge node. When the terminal device connected to the edge node needs to perform authentication services, it does not need to send a request to the central node, but requests the edge node. The edge node issues a first token for the terminal account running on the terminal device, and the first token includes a second public key and a first signature of the terminal account, and the first signature is determined according to the first private key. The first token is used to verify whether the terminal account is an account issued by the edge node. The first signature is used to prevent the information in the first token from being tampered with. When the terminal device calls the relevant cloud service and needs to be authenticated by the account, the terminal account is used to send a first request to the edge node. In other words, the edge node receives the first request sent by the terminal device using the terminal account, and the first request includes a second token and a second signature, and the second signature is determined according to the second private key of the terminal account. The edge node authenticates the first request based on the first key pair and the first token. It should be noted that the second token may be a tampered token or a secure and reliable token (i.e., the first token). The authentication of the first request mentioned here includes authenticating whether the second token is a credible token (i.e., authenticating whether the second token is the first token issued by the edge node), and whether the terminal account that issued the first request is a credible terminal account.

[0009] In this application, the authentication function is sent to the edge node that communicates with the central node, which eliminates the single point problem in the original technical solution. The authentication service can be performed at the edge node that communicates with the central node, and the authentication service will not be unavailable due to the failure of the central node, which improves the reliability of account authentication. In addition, the authentication service can be sent to any edge node that communicates with the central node, which reduces the complexity of the authentication system and saves bandwidth resources.

[0010] In some optional implementations of the first aspect, the edge node authenticates the first request based on the first key pair and the first token, specifically including the following authentication process: First, the second token included in the first request is verified by the first public key of the edge node to determine whether the signature of the second token is generated based on the first private key. In other words, determine whether the second token is the first token issued by the edge node. If the signature of the second token is generated based on the first private key, it means that the second token passes the verification, and the second token is actually the first token issued by the edge node for the terminal account. The second token also includes the second public key of the terminal account. The edge node then verifies the second signature based on the second public key to determine whether the terminal account is a trusted account.

[0011] In this application, authenticating the first request includes authenticating the second token and the second signature included in the first request, and verifying the first request from multiple perspectives, which further improves the reliability of account verification.

[0012] In some alternative implementation manners of the first aspect, when the verification of the second signature based on the second public key is successful, further verification is required. The edge node parses the second token to determine the identifier of the terminal account. Then, the identifier of the terminal account is compared with the blacklist and the revoked account list. When the identifier of the terminal account is not included in the blacklist and not included in the revoked account list, it is determined that the first request passes the authentication. That is to say, even if the verification of the second signature is successful, it is still necessary to further determine whether the terminal account is a trustworthy account at the current moment. This is because in the case where the token has not been tampered with, the token in the first request was issued by the edge node previously. With the change of the business, etc., the terminal account may become an untrustworthy account (such as being added to the blacklist or having been revoked, etc.). After the verification of the second signature passes, the terminal account is further verified to ensure that the verification of the terminal account matches the actual situation at the current moment and avoid errors.

[0013] In this application, after the verification of the second signature passes, the terminal account can also be compared with the blacklist and the revocation list to prevent requests from accounts that have been blacklisted or revoked from being processed by the edge node, which further improves the reliability of account authentication.

[0014] In some alternative implementation manners of the first aspect, when the verification of the second signature based on the second public key is successful, it indicates that the second private key used to generate the second signature and the second public key are included in the same key pair, and the terminal account that issues the first request is trustworthy. The edge node then determines that the first request passes the authentication.

[0015] In this application, after the verification of the second token included in the first request passes, the edge node will also verify the second signature of the first request to determine whether the terminal account that issues the first request is trustworthy, which further improves the reliability of account authentication.

[0016] In some alternative implementation manners of the first aspect, after determining that the first request passes the authentication, the edge can also parse the second token to determine the permission information corresponding to the terminal account. When the permission information corresponding to the terminal account includes the permission indicated by the first request, that is, the operation indicated by the first request is included in the permission scope of the terminal account, the edge node executes the first request.

[0017] In this application, after the authentication of the first request is passed, the first request can also be authenticated. If the operation indicated by the first request is included in the authority range of the terminal account that issues the first request, the first request is executed to avoid operations beyond the authority, further ensuring the security of communication.

[0018] In some optional implementations of the first aspect, after executing the first request, the edge node returns a request result to the terminal device.

[0019] In some optional implementations of the first aspect, if verification of the second token based on the first public key fails, it indicates that the terminal account is not issued by the edge node, and the first request authentication fails. The edge node may return a verification failure result to the terminal device.

[0020] In some optional implementations of the first aspect, if the verification of the second token based on the first public key succeeds, but the verification of the second signature based on the second public key fails, it means that the edge account is not a trusted account and the first request authentication fails. The edge node can return the verification failure result to the terminal device.

[0021] In a second aspect, the present application provides an account authentication system, including a central node and an edge node.

[0022] The central node is used to send a first key pair to the edge node, where the first key pair includes a first public key and a first private key of the edge node, and the first key pair is used to authenticate a terminal account managed by the edge node.

[0023] The edge node is used to issue a first token for a terminal account running on a terminal device, the first token including a second public key and a first signature of the terminal account, the first signature being determined according to the first private key. A first request sent using the terminal account is received, the first request including a second token and a second signature, the second signature being determined according to the second private key of the terminal account. The first request is authenticated based on the first key pair and the first token.

[0024] In a third aspect, the present application provides an edge node, which is connected to a central node. The edge node includes:

[0025] A transceiver unit is used to receive a first key pair from a central node, the first key pair includes a first public key and a first private key of an edge node, and the first key pair is used to authenticate a terminal account managed by the edge node. A first token is issued for a terminal account running on a terminal device, the first token includes a second public key and a first signature of the terminal account, and the first signature is determined based on the first private key. A first request is received using the terminal account, the first request includes a second token and a second signature, and the second signature is determined based on the second private key of the terminal account;

[0026] The processing unit is configured to authenticate the first request based on the first key pair and the first token.

[0027] The edge node is used to execute the method shown in the aforementioned first aspect, or any possible implementation of the first aspect, and its beneficial effects are as shown in the first aspect, or any possible implementation of the first aspect, and are not repeated here.

[0028] In a fourth aspect, the present application provides a computing device cluster, comprising at least one computing device, each computing device comprising a processor and a memory; the processor of at least one computing device is used to execute instructions stored in the memory of at least one computing device, so that the computing device cluster implements the method disclosed in the first aspect and any possible implementation manner of the first aspect.

[0029] In a fifth aspect, the present application provides a computer program product comprising instructions, which, when executed by a computer device cluster, enables the computer device cluster to implement the method disclosed in the first aspect and any possible implementation manner of the first aspect.

[0030] In a sixth aspect, the present application provides a computer-readable storage medium, comprising computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method disclosed in the first aspect or any possible implementation of the first aspect.

[0031] The beneficial effects shown in the fourth to sixth aspects of the present application are similar to the methods disclosed in the first aspect and any possible implementation method of the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0032] Figure 1 A schematic diagram of a system architecture provided for an embodiment of the present application;

[0033] Figure 2 Another schematic diagram of a system architecture provided for an embodiment of the present application;

[0034] Figure 3 A flowchart of an account authentication method provided in an embodiment of the present application;

[0035] Figure 4 A schematic diagram of the structure of an edge node provided in an embodiment of the present application;

[0036] Figure 5 A schematic diagram of a structure of a computing device provided in an embodiment of the present application;

[0037] Figure 6 A schematic diagram of the structure of a computing device cluster provided in an embodiment of the present application;

[0038] Figure 7Another structural diagram of a computing device cluster provided in an embodiment of the present application. DETAILED DESCRIPTION

[0039] The embodiments of the present application provide an account authentication method, system and related devices for improving the reliability of account authentication.

[0040] The embodiments of the present application are described below in conjunction with the accompanying drawings. Those skilled in the art will appreciate that, with the development of technology and the emergence of new scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0041] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the terms used in this way can be interchanged in appropriate circumstances, which is only to describe the distinction mode adopted by the objects of the same attribute in the embodiments of the present application when describing. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment containing a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment. In addition, "at least one" refers to one or more, and "multiple" refers to two or more. "And / or", describes the association relationship of associated objects, indicating that three relationships can exist, for example, A and / or B, can represent: A exists alone, A and B exist simultaneously, and B exists alone, wherein A, B can be singular or plural. The character " / " generally represents that the associated objects before and after are a kind of "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, or c can mean: a, b, c, ab, ac, bc, or abc, where a, b, and c can be single or plural.

[0042] First, the proper nouns and related concepts that may be involved in the embodiments of the present application are explained.

[0043] 1. Edge node.

[0044] Edge nodes are relative to cloud computing data centers. They refer to network nodes with fewer intermediate links between them and the final access users. They can be a computer room or a physical device. Compared with direct access to the source station, terminal access to edge nodes will have better responsiveness and connection speed.

[0045] 2. Cloud platform and infrastructure:

[0046] The cloud platform is used to manage the cloud vendor's infrastructure, which is multiple cloud data centers located in different regions, where each region is equipped with at least one cloud data center. The cloud platform can provide interfaces related to cloud computing services, such as configuration pages (i.e., interfaces) or APIs for tenants to access cloud services. Tenants can log in to the cloud platform using a pre-registered account and password, and after a successful login, select and purchase cloud services provided by the cloud data center in the predetermined region, such as object storage services, virtual machine services, container services, or other known cloud services.

[0047] 3. Tenants:

[0048] A top-level object used to manage cloud services and / or cloud resources. Tenants register their tenant accounts and set their tenant passwords on the cloud platform through a local client (such as a browser). The local client remotely logs in to the cloud platform through the tenant account and the set tenant password. The cloud platform provides a configuration interface or API for tenants to configure and use cloud services, wherein the cloud services are specifically provided by the infrastructure managed by the cloud platform as described above.

[0049] See below. Figure 1 and Figure 2 , Figure 1 and Figure 2 All of them are schematic diagrams of system architecture provided in embodiments of the present application.

[0050] like Figure 1 As shown, the tenant logs into the cloud platform 30 through the client 10 via the Internet 20, using the account and password registered on the cloud platform 30. The cloud platform 30 manages the infrastructure, which includes multiple data centers set up in different regions, such as Figure 1 The region 1 shown includes cloud data center 1 and cloud data center 2, and region 2 includes cloud data center 3 and cloud data center 4. Each cloud data center is provided with multiple servers, and service instances (including at least one of virtual machines, containers, and dedicated hosts) are run on the servers.

[0051] In the embodiment of the present application, an authentication service is deployed in the business instance. When the tenant uses other services provided by the cloud platform, the authentication service can be used to authenticate the relevant account and ensure that the operation requested by the account is executed within the corresponding authority range, thereby ensuring the security of network communication. The specific authentication and authorization process is described in detail later.

[0052] like Figure 2 As shown, the account authentication system provided in the embodiment of the present application adopts a distributed architecture, and the central node can deploy an authentication module for the edge node, thereby realizing a distributed authentication service. The edge node where the authentication module is deployed can be synchronized with the central node.

[0053] exist Figure 2 In the illustrated embodiment, edge nodes B and C are deployed with authentication modules, and edge node B can authenticate the accounts on client 1 and client 2, without requiring the client to request authentication from the central node. Similarly, when client 3 uses related cloud services, it only needs to request authentication from edge node C, without requesting from the central node.

[0054] In other words, the central authentication server of the central node generates a central account through an algorithm and issues an account to the edge node, such as account B of edge node B and account C of edge node C. For clients communicating with edge nodes, when the service used requires authentication, the edge node issues an account, such as account userB01 of client 1 and account userC01 of client 3. When the client initiates a request to the corresponding edge node, the edge node verifies the account information in the request to implement authentication. The specific process is described in detail later.

[0055] For example, assuming that the central node is the cloud desktop service account B, when client 1 uses the cloud desktop service, the edge node B issues the user account userB01. When client 1 uses the cloud desktop service, for the request sent by client 1 to edge node B, edge node B can perform authentication services to ensure the safe operation of the service.

[0056] It should be noted that the central node can issue authentication services to some or all edge nodes communicating with it. Figure 2 In the illustrated embodiment, the central node does not send authentication services to the edge node A. The account userA01 of the client 4 is issued by the central node, and the authentication of the account is also performed by the central node.

[0057] It should also be noted that the embodiments of the present application are applied to a representational state transfer application programming interface (REST API) scenario, which is characterized in that the mode between the two ends of the communication is a question-and-answer type.

[0058] See below. Figure 3 , Figure 3 A flowchart of an account authentication method provided in an embodiment of the present application includes:

[0059] 301. The edge node receives a first key pair from the central node for authenticating a terminal account managed by the edge node.

[0060] The central node generates the first private key of the edge node through the issuance algorithm, and generates the first public key based on the first private key, thereby obtaining the first key pair of the edge node. Among them, the first private key is generally not publicly transmitted, but stored on the edge node. The edge node can use the first private key to sign the information sent to ensure that the information is sent by the edge node, which plays a role in preventing data tampering. The first public key can be public and can be transmitted externally. The first public key uniquely corresponds to the first private key and is used to verify whether the private key used for the signature is the first private key.

[0061] Exemplarily, the central node may generate the first private key by issuing the algorithm ED25519. The first private key and the first public key may be as follows:

[0062] First public key: ADWN6GJJXJJ5AV2O32T46CZRVN6ORPOZMAAGTBJEAMK5EBWGBSFMFPZK

[0063] First private key: SAANCMEWHFWFA4U7YAFB65BGIJWJHEXMHZWXKORX3JRKJVXBWFOBO45PGE

[0064] In addition, in the technical solution of the present application, the edge node manages the terminal account. The management here means that the edge node issues a token for the terminal account running on the terminal device communicating with it, and the authentication and authorization of the terminal account are also performed by the edge node.

[0065] 302. The edge node sends a first token to the terminal device.

[0066] The edge node generates a first token for the terminal account through an issuance algorithm, the first token including the second public key of the terminal account and a first signature generated based on the first private key of the edge node. The first signature is used to indicate that the first token is issued by the edge node.

[0067] Exemplarily, assume that the type of the first token is JSON web token, i.e., JWT token. Then the first token is a string including a header, a payload, and a signature. The header is used to describe the encryption algorithm and the format requirements of the token. The payload is used to indicate the first public key of the edge node, the second public key of the terminal account, the attribute information of the terminal account, etc. The attribute information of the terminal account includes the identity, permissions, purchased services, etc. of the terminal account. The signature is the signature of the first token.

[0068] For example, in the JWT token shown below, the edge node encodes the header and payload using base64url to obtain a variable-length string, which is then signed using the first private key.

[0069] JWT token: {"typ":"JWT","alg":"ed25519-nkey"}.{"iat":1670654746,"iss":"ADWN6GJJXJJ5AV2O","name":"SYS","sub":"UAR7DYYJ DPEKDZ","default_permissions":{"access":{},"deny":{}},"type":"user"}}.{EgYQPkXfow9S3gV2hL6w1oc1Rqc_mQCYKG2vaMViOB J6p3BtI4g7FSmMsfse1HgpRO6fqx1_mX7UwWPV9JpDDA}

[0070] In the above example, "ADWN6GJJXJJ5AV2O" is the first public key of the edge node, and "UAR7DYYJDPEKDZ" is the second public key of the terminal account.

[0071] 303. The edge node receives a first request including a second token and a second signature from a terminal device.

[0072] The terminal device running the terminal account sends a first request to the edge node. In other words, the first request is sent by the terminal device to the edge node using the terminal account. The first request includes a second token and a second signature, and the second signature is determined according to the second private key of the terminal account.

[0073] The first request is of type Rest API, including path, request header and request body. Path usually adopts a fixed format, indicating the interface accessed by the first request, etc. The request header includes the second signature and the second token. The request body includes the account password and other related information of the terminal account.

[0074] It should be noted that the format and content of the second token are similar to the format and content of the first token introduced above, and will not be repeated here.

[0075] Optionally, the second token also includes an identifier of the terminal account and attribute information of the terminal account. The identifier of the terminal account is used to uniquely indicate the terminal account, and the attribute information of the terminal account includes the identity, authority, etc. of the terminal account.

[0076] 304. The edge node authenticates the first request based on the first key pair and the first token.

[0077] The edge node obtains the first request, and first verifies the second token included in the first request to determine whether the terminal account is an account issued by the edge node. Specifically, the edge node verifies the signature of the second token based on the first public key in the first key pair to determine whether the signature of the second token is generated according to the first private key.

[0078] It is understandable that, when the data has not been tampered with, the first token issued by the edge node for the terminal account is the same as the second token included in the first request. The private key used for the signature of the second token is the first private key included in the same key pair as the first public key of the edge node. Then, when it is determined based on the first public key verification that the signature of the second token is generated based on the first private key, it means that the second token is actually the first token issued by the edge node for the terminal account, and the terminal account run by the terminal device is the account issued by the edge node. Then, the second token also includes the second public key of the terminal account. Afterwards, the edge node verifies the second signature based on the second public key.

[0079] In the present application, the first request is authenticated, including authenticating the second token and the second signature included in the first request, and the first request is verified from multiple angles, further improving the reliability of account verification.

[0080] As mentioned above, the first request includes path, header and body, and the second token and the second signature are included in the header. Among them, the second signature is obtained by the terminal device signing the string composed of path, header and body based on the second private key of the terminal account. The terminal device verifies the second signature based on the second public key, specifically using the second public key and the second signature to verify the string composed of path, header and body. If the verification passes, it means that the second private key is the key corresponding to the second public key. In other words, the second private key and the second public key are included in the same key pair.

[0081] In some optional implementations, when the second signature is successfully verified according to the second public key, the edge node can determine that the terminal account that issues the first request is credible, that is, the first request is authenticated.

[0082] In the present application, after the second token included in the first request is verified, the edge node will also verify the second signature of the first request to determine whether the terminal account that issued the first request is credible, further improving the reliability of account authentication.

[0083] In some optional implementations, when the second signature is successfully verified according to the second public key, the edge node can further verify the terminal account. The edge node parses the second token to determine the identifier of the terminal account. The identifier of the terminal account is used to uniquely indicate the terminal account, and there are multiple optional forms, such as: user name, user ID, facial ID, fingerprint information, etc., which are not specifically limited here. The edge node compares the identifier of the terminal account with the blacklist and the revoked account list. If the identifier of the terminal account is not included in the blacklist and the revoked account list, it is determined that the first request is authenticated.

[0084] It is understandable that further verification of the terminal account is based on the consideration that, in the absence of token tampering, the token in the first request was previously issued by the edge node. As business changes, etc., the terminal account may become an untrustworthy account (for example, being added to a blacklist or revoked, etc.). After the second signature verification is passed, the terminal account is further verified to ensure that the verification of the terminal account matches the actual situation at the current moment to avoid errors.

[0085] In this application, after the second signature verification is passed, the terminal account can also be compared with the blacklist and revocation list to prevent requests from accounts that have been blacklisted or revoked from being processed by the edge node, further improving the reliability of account authentication.

[0086] In some optional implementations, if the edge node fails to authenticate the first request in step 304, the edge node may return a failure result to the terminal device. The failure reasons include: failure of the second token verification (that is, the current terminal account is not an account issued by the edge node), failure of the second signature verification, the terminal account being blacklisted or revoked, etc.

[0087] In some optional implementations, after the first request is authenticated, the edge node can also perform authentication services on the first request. Specifically, the edge node parses the second token to determine the attribute information of the terminal account. The attribute information includes the identity and permission information of the terminal account. In the case where the permission indicated by the first request is included in the permission information corresponding to the terminal account, it means that the first indicated operation is included in the permission scope of the terminal account, and the edge node can execute the first request.

[0088] For example, assume that an authentication service is applied in a cloud conference service. The terminal account is authenticated, and the attribute information indicates that the terminal account is a "conference host". The permission information includes: adding or deleting participants, enabling screen recording, and enabling mute. If the operation indicated by the first request is screen recording, which is included in the aforementioned permission information, the edge node performs the screen recording operation.

[0089] For example, assume that an authentication service is applied in a cloud conference service. The authentication of the terminal account is passed, and the attribute information indicates that the identity of the terminal account is a "conference participant", and the permission information includes: turning on and off the microphone, leaving messages. If the operation indicated by the first request is screen recording, which is not in the aforementioned permission information, the edge node does not perform the screen recording operation, and returns an execution failure to the terminal device, or returns a permission application reminder.

[0090] For example, assume that an authentication service is applied in a cloud desktop service. The authentication of the terminal account is passed, and the attribute information indicates that the identity of the terminal account is the "master party", and the permission information includes: controlling the collaborative party screen, modifying the collaborative party's database information, etc. If the operation indicated by the first request is to modify a file in the collaborative party database, which is included in the aforementioned permission information, then the edge node executes the operation.

[0091] In this application, after the authentication of the first request is passed, the first request can also be authenticated. If the operation indicated by the first request is included in the authority range of the terminal account that issues the first request, the first request is executed to avoid operations beyond the authority, further ensuring the security of communication.

[0092] The embodiment of the present application also provides an account authentication system, including a central node and an edge node.

[0093] The central node is used to send a first key pair to the edge node, where the first key pair includes a first public key and a first private key of the edge node, and the first key pair is used to authenticate a terminal account managed by the edge node.

[0094] The edge node is used to: issue a first token for a terminal account running on a terminal device, the first token including a second public key and a first signature of the terminal account, the first signature being determined according to the first private key. Receive a first request sent using the terminal account, the first request including a second token and a second signature, the second signature being determined according to the second private key of the terminal account. Authenticate the first request based on the first key pair and the first token.

[0095] In some optional implementations, the edge node is further configured to determine, based on the first public key, whether the signature of the second token is generated based on the first private key. If the signature of the second token is generated based on the first private key, verify the second signature based on the second public key.

[0096] In some optional implementations, the edge node is further configured to parse the second token and determine the identifier of the terminal account if the second signature is successfully verified according to the second public key. If the identifier of the terminal account is not included in the blacklist and the identifier of the terminal account has not been revoked, it is determined that the first request has passed the authentication.

[0097] In some alternative embodiments, the edge node is further configured to determine that the first request passes the authentication if the verification of the second signature based on the second public key is successful.

[0098] In some alternative embodiments, the edge node is further configured to parse the second token and determine the permission information corresponding to the terminal account. When the permission information corresponding to the terminal account includes the permission indicated by the first request, the first request is executed.

[0099] Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of the edge node provided by the embodiments of the present application. In the embodiments of the present application, the edge node 400 is connected to the central node.

[0100] In some alternative embodiments, the edge node 400 includes a transceiver unit 401 and a processing unit 402. The transceiver unit 401 is configured to receive a first key pair from the central node. The first key pair includes the first public key and the first private key of the edge node, and the first key pair is used to authenticate the terminal account managed by the edge node. Issue a first token for the terminal account running on the terminal device. The first token includes the second public key and the first signature of the terminal account, and the first signature is determined based on the first private key. Receive a first request sent by using the terminal account. The first request includes a second token and a second signature, and the second signature is determined based on the second private key of the terminal account. The processing unit 402 is configured to authenticate the first request based on the first key pair and the first token.

[0101] In some alternative embodiments, the processing unit 402 is specifically configured to: determine whether the signature of the second token is generated based on the first private key according to the first public key. If the signature of the second token is generated based on the first private key, the second signature is verified according to the second public key.

[0102] In some alternative embodiments, the processing unit 402 is further configured to: if the verification of the second signature based on the second public key is successful, parse the second token and determine the identifier of the terminal account. If the identifier of the terminal account is not included in the blacklist and the identifier of the terminal account has not been revoked, it is determined that the first request passes the authentication.

[0103] In some alternative embodiments, the processing unit 402 is further configured to: determine that the first request passes the authentication if the verification of the second signature based on the second public key is successful.

[0104] In some alternative embodiments, the processing unit 402 is further configured to: parse the second token and determine the permission information corresponding to the terminal account. When the permission information corresponding to the terminal account includes the permission indicated by the first request, the first request is executed.

[0105] In some optional implementations, the transceiver unit 401 is further configured to send the execution result of the first request to the terminal device.

[0106] In some optional implementations, the transceiver unit 401 is further configured to send an authentication failure result to the terminal device when the authentication of the first request fails.

[0107] It should be noted that Figure 4 The transceiver unit 401 and the processing unit 402 of the illustrated embodiment can be implemented by software or by hardware. For example, the implementation of the processing unit 402 is described below by taking the processing unit 402 as an example. Similarly, the implementation of the transceiver unit 401 can refer to the implementation of the processing unit 402.

[0108] As an example of a software functional unit, the processing unit 402 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Furthermore, the computing instance may be one or more. For example, the processing unit 402 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including one data center or multiple data centers with similar geographical locations. Typically, a region may include multiple AZs.

[0109] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Usually, a VPC is set up in a region. For cross-region communication between two VPCs in the same region and between VPCs in different regions, a communication gateway needs to be set up in each VPC to achieve interconnection between VPCs through the communication gateway.

[0110] As an example of a hardware functional unit, the processing unit 402 may include at least one computing device, such as a server, etc. Alternatively, the processing unit 402 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD), etc. The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0111] The multiple computing devices included in the processing unit 402 can be distributed in the same region or in different regions. The multiple computing devices included in the processing unit 402 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the processing unit 402 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0112] See also Figure 5 , Figure 5 A schematic diagram of the structure of a computing device provided in an embodiment of the present application. The computing device 500 includes a processor 501, a communication interface 502, a bus 503, and a memory 504. The processor 501, the communication interface 502, and the memory 504 communicate with each other via the bus 503. In practical applications, communication can also be achieved through other means such as wireless transmission, which is not limited here.

[0113] It should be understood that the present application does not limit the number of processors and memories in the computing device 500 .

[0114] The processor 501 may include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0115] The communication interface 502 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 500 and other devices or a communication network.

[0116] The bus 503 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 5 The bus 503 may include a path for transmitting information between various components of the computing device 500 (eg, the memory 504, the processor 501, and the communication interface 502).

[0117] The memory 504 may include a volatile memory, such as a random access memory (RAM). The memory 504 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0118] The memory 504 stores executable program codes, and the processor 501 executes the executable program codes to respectively implement the functions of the aforementioned transceiver unit 401 and the processing unit 402, thereby implementing the account authentication method applied to the edge node. That is, the memory 504 stores instructions for executing the account authentication method applied to the edge node.

[0119] The embodiment of the present application also provides a computing device cluster, which includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some optional implementations, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.

[0120] See also Figure 6 and Figure 7 , Figure 6 and Figure 7 All of them are structural schematic diagrams of the computing device cluster provided in embodiments of the present application.

[0121] like Figure 6As shown, the computing device cluster includes at least one computing device 500. The memory 504 in one or more computing devices 500 in the computing device cluster may store the same instructions for executing the account authentication method provided in the embodiment of the present application.

[0122] In some possible implementations, the memory 504 of one or more computing devices 500 in the computing device cluster may also store partial instructions for the account authentication method. In other words, the combination of one or more computing devices 504 may jointly execute instructions for executing the account authentication method.

[0123] It should be noted that the memory 504 in different computing devices 500 in the computing device cluster can store different instructions, which are respectively used to execute part of the functions of the edge node. That is, the instructions stored in the memory 504 in different computing devices 500 can implement the functions of one or more units in the transceiver unit 401 and the processing unit 402.

[0124] In some possible implementations, one or more computing devices in the computing device cluster may be connected via a network, which may be a wide area network or a local area network.

[0125] Figure 7 A possible implementation is shown. Figure 7 As shown, two computing devices 500A and 500B are connected via a network. Specifically, the network is connected via a communication interface in each computing device. In this type of possible implementation, the memory 504 in the computing device 500A stores instructions for executing the functions of the transceiver unit 401. At the same time, the memory 504 in the computing device 500B stores instructions for executing the functions of the processing unit 402.

[0126] Figure 7 The connection method between the computing device clusters shown can be based on the consideration that in the account authentication method provided in the present application, processing operations and operations other than processing operations are performed separately, that is, the function of the receiving and transmitting unit 401 is considered to be executed by the computing device 500A, and the function of the processing unit 402 is considered to be executed by the computing device 500B.

[0127] It should be understood that Figure 7 The functions of the computing device 500A shown in FIG. 5A may also be completed by multiple computing devices 500. Similarly, the functions of the computing device 500B may also be completed by multiple computing devices 500.

[0128] In some optional implementations, the present application embodiment also provides another computing device cluster. The connection relationship between the computing devices in the computing device cluster can be similar to that of Figure 6 and Figure 7 The connection method of the computing device cluster will not be described in detail here.

[0129] The embodiment of the present application also provides a computer program product including instructions. The computer program product may be a software or program product including instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computer device, the at least one computer device executes the above-mentioned application plug-in management method based on the Internet of Things technology.

[0130] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by the computing device or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk). The computer-readable storage medium includes instructions that instruct the computing device to execute the above-mentioned application plug-in management method based on the Internet of Things technology.

[0131] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0132] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present application.

Claims

1. An account authentication method, characterized in that: The method is applied to an edge node, the edge node is connected to a central node, and the method comprises: Receiving a first key pair from the central node, the first key pair comprising a first public key and a first private key of the edge node, the first key pair being used to authenticate a terminal account managed by the edge node; issuing a first token for the terminal account running on the terminal device, wherein the first token includes a second public key and a first signature of the terminal account, and the first signature is determined according to the first private key; receiving a first request sent by using the terminal account, the first request including a second token and a second signature, the second signature being determined according to a second private key of the terminal account; The first request is authenticated based on the first key pair and the first token.

2. The method according to claim 1, characterized in that The authenticating the first request based on the first key pair and the first token includes: Determining, based on the first public key, whether the signature of the second token is generated based on the first private key; If the signature of the second token is generated based on the first private key, the second signature is verified based on the second public key.

3. The method according to claim 2, characterized in that The method further comprises: If the second signature is successfully verified according to the second public key, parsing the second token to determine the identifier of the terminal account; If the identifier of the terminal account is not included in the blacklist and the identifier of the terminal account has not been revoked, it is determined that the first request has passed the authentication.

4. The method according to claim 2, characterized in that: The method further comprises: If the second signature is successfully verified according to the second public key, it is determined that the first request has passed the authentication.

5. The method according to claim 3 or 4, characterized in that: After determining that the first request passes the authentication, the method further includes: Parsing the second token to determine permission information corresponding to the terminal account; When the authority information corresponding to the terminal account includes the authority indicated by the first request, the first request is executed.

6. An account authentication system, characterized in that: Includes central nodes and edge nodes; The central node is used to send a first key pair to the edge node, where the first key pair includes a first public key and a first private key of the edge node, and the first key pair is used to authenticate a terminal account managed by the edge node; The edge node is used to: issuing a first token for the terminal account running on the terminal device, wherein the first token includes a second public key and a first signature of the terminal account, and the first signature is determined according to the first private key; receiving a first request sent by using the terminal account, the first request including a second token and a second signature, the second signature being determined according to a second private key of the terminal account; The first request is authenticated based on the first key pair and the first token.

7. An edge node, characterized in that: The edge node is connected to the central node, including: A transceiver unit, configured to receive a first key pair from the central node, wherein the first key pair includes a first public key and a first private key of the edge node, and the first key pair is used to authenticate a terminal account managed by the edge node; The transceiver unit is further used to issue a first token for the terminal account running on the terminal device, wherein the first token includes a second public key and a first signature of the terminal account, and the first signature is determined according to the first private key; The transceiver unit is further configured to receive a first request sent using the terminal account, the first request including a second token and a second signature, the second signature being determined according to a second private key of the terminal account; A processing unit is configured to authenticate the first request based on the first key pair and the first token.

8. The edge node according to claim 7, characterized in that: The processing unit is specifically used for: Determining, based on the first public key, whether the signature of the second token is generated based on the first private key; If the signature of the second token is generated based on the first private key, the second signature is verified based on the second public key.

9. The edge node according to claim 8, characterized in that: The processing unit is further used for: If the second signature is successfully verified according to the second public key, parsing the second token to determine the identifier of the terminal account; If the identifier of the terminal account is not included in the blacklist and the identifier of the terminal account has not been revoked, it is determined that the first request has passed the authentication.

10. The edge node according to claim 8, characterized in that: The processing unit is further used for: If the second signature is successfully verified according to the second public key, it is determined that the first request has passed the authentication.

11. The edge node according to claim 9 or 10, characterized in that: The processing unit is further used for: Parsing the second token to determine permission information corresponding to the terminal account; When the authority information corresponding to the terminal account includes the authority indicated by the first request, the first request is executed.

12. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 5.

13. A computer program product comprising instructions, characterized in that When the instructions are executed by a computing device cluster, the computing device cluster is caused to perform the method according to any one of claims 1 to 5.

14. A computer-readable storage medium, characterized in that: The method comprises computer program instructions, and when the computer program instructions are executed by a computing device cluster, the computing device cluster performs the method according to any one of claims 1 to 5.