Server health monitoring method and device for load balancing equipment
By using the certificate whitelisting mechanism in load balancing devices, the certificate verification process in SSL health checks is simplified, and the problem of excessive resource consumption in the existing technology is solved, achieving more efficient health checks and system performance improvements.
Patent Information
- Application Number
- CN202510234457.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-30
AI Technical Summary
The existing server health detection scheme based on SSL protocol consumes a lot of resources during frequent certificate verification, affecting system performance and efficiency.
By implementing the certificate whitelisting mechanism in the load balancing device, only the certificate length and binary data information are compared after the first verification, reducing complex certificate chain verification and asymmetric algorithm calculations.
It significantly reduces equipment resource consumption, improves health inspection efficiency and system performance, and enhances the overall competitiveness of the system.
Smart Images

Figure CN120075093A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer information processing, and in particular, to a method and device for server health monitoring for a load balancing device. Background Art
[0002] With the continuous development of network technology, network traffic has increased sharply, and a single server can no longer meet the needs of users for high concurrency, high freshness, and high processing speed. At the same time, the cost performance of server hardware upgrades is relatively low. Therefore, in order to improve the business processing capacity and speed, the server load balancing technology has emerged. The load balancing device becomes an important part of the load balancing technology by detecting the running state of real servers and reasonably scheduling client traffic to multiple servers according to the state. Accurately judging the running state of the server has important guiding significance for traffic scheduling.
[0003] The existing detection scheme based on the SSL protocol is to start a health detection process and periodically establish an SSL handshake with each real server. The SSL handshake negotiates a connection key on an insecure network. After the handshake is successful, data is sent to the server through an encrypted channel. For example, when detecting the state of an HTTPS server, after the SSL connection is successful, an encrypted HTTP request is sent, the response message of the server is received and decrypted, and it is detected whether it meets the expectation. If it meets, the server state is healthy (up), otherwise it is unhealthy (down). During the handshake process, the server sends a certificate chain to the client, and the client needs to verify the validity of the server certificate to ensure the authenticity of the identity.
[0004] For security considerations, the client usually needs to verify the server-side certificate during each interaction. Even in some cases where certificate verification is not set (such as not setting verification in the OpenSSL source code), the system still performs verification, but it will not report an error when the verification fails, and the handshake continues without interruption. This frequent certificate verification process consumes a large amount of resources, especially in scenarios with frequent new connections, which affects the performance and efficiency of the system.
[0005] Therefore, a new method and device for server health monitoring for a load balancing device are needed.
[0006] The above information disclosed in the background art section is only used to enhance the understanding of the background of this application, and therefore it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0007] In view of this, the present application provides a server health monitoring method and device for a load balancing device, which can optimize the certificate verification process in SSL health checks, simplify subsequent verification using a certificate whitelist after the first verification, significantly reduce device resource consumption, and improve the efficiency of health checks and system performance.
[0008] Other features and advantages of the present application will become apparent from the following detailed description, or will be learned in part through the practice of the present application.
[0009] According to one aspect of the present application, a server health monitoring method for a load balancing device is proposed. The method includes: the load balancing device obtains a handshake message from the server; extracts certificate information based on the handshake message; matches the public key information in the certificate information with the entry data in the certificate whitelist; when the entry information is matched, the certificate information is compared and verified; after the verification passes, health monitoring is performed on the server.
[0010] In an exemplary embodiment of the present application, before the load balancing device obtains a handshake message from the server, it further includes: the load balancing device creates an SSL client and sets the certificate verification mode to the optimized mode.
[0011] In an exemplary embodiment of the present application, the load balancing device obtains a handshake message from the server, including: the load balancing device obtains an SSL handshake message from the server.
[0012] In an exemplary embodiment of the present application, extracting certificate information based on the handshake message includes: when the certificate verification mode of the server is the optimized mode, extracting certificate information based on the handshake message; when the certificate verification mode of the server is not the optimized mode, performing a certificate chain verification based on verify_mode.
[0013] In an exemplary embodiment of the present application, when the entry information is matched, comparing and verifying the certificate information further includes: when the entry information is not matched, performing a certificate chain verification on the certificate information; after the certificate chain verification passes, adding the server to the certificate whitelist.
[0014] In an exemplary embodiment of the present application, adding the server to the certificate whitelist includes: creating a certificate whitelist node according to the certificate public key information, certificate binary data, and certificate length information of the server; using the certificate whitelist node as the value and the certificate public key information as the key; storing in the certificate whitelist in the form of a key-value pair.
[0015] In an exemplary embodiment of the present application, it is stored in the certificate whitelist in the form of key-value pairs, including: storing key-value pairs through a map hash table data structure.
[0016] In an exemplary embodiment of the present application, the certificate information is compared and verified, including: comparing and verifying the certificate length information; and / or comparing and verifying the certificate binary data; and / or comparing and verifying the current time; and / or comparing and verifying the certificate validity period information.
[0017] In an exemplary embodiment of the present application, the server is monitored for health, including: sending an encrypted message through the encryption and decryption channel of the SSL handshake and decrypting the message of the server.
[0018] According to an aspect of the present application, a server health monitoring device for a load balancing device is proposed. The device includes: a message module for the load balancing device to obtain a handshake message from the server; an information module for extracting certificate information based on the handshake message; a matching module for matching the public key information in the certificate information with the entry data in the certificate whitelist; a verification module for comparing and verifying the certificate information when the entry information is matched; and a detection module for monitoring the health of the server after the verification passes.
[0019] According to an aspect of the present application, an electronic device is proposed. The electronic device includes: one or more processors; a storage device for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described above.
[0020] According to an aspect of the present application, a computer-readable medium is proposed, on which a computer program is stored, and when the program is executed by a processor, the method as described above is implemented.
[0021] According to the server health monitoring method and device for a load balancing device of the present application, by obtaining a handshake message from the server through the load balancing device; extracting certificate information based on the handshake message; matching the public key information in the certificate information with the entry data in the certificate whitelist; comparing and verifying the certificate information when the entry information is matched; and monitoring the health of the server after the verification passes, it can optimize the certificate verification process in the SSL health check, simplify subsequent verification using the certificate whitelist after the first verification, significantly reduce the consumption of device resources, and improve the health check efficiency and system performance.
[0022] It should be understood that the above general description and the following detailed description are only exemplary and do not limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] By describing its exemplary embodiments in detail with reference to the accompanying drawings, the above and other objects, features, and advantages of the present application will become more apparent. The accompanying drawings described below are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0024] Figure 1 is a system block diagram of a server health monitoring method and device for a load balancing device shown according to an exemplary embodiment.
[0025] Figure 2 is a flowchart of a server health monitoring method for a load balancing device shown according to an exemplary embodiment.
[0026] Figure 3 is a schematic diagram of a server health monitoring method for a load balancing device shown according to another exemplary embodiment.
[0027] Figure 4 is a flowchart of a server health monitoring method for a load balancing device shown according to another exemplary embodiment.
[0028] Figure 5 is a block diagram of a server health monitoring device for a load balancing device shown according to an exemplary embodiment.
[0029] Figure 6 is a block diagram of an electronic device shown according to an exemplary embodiment.
[0030] Figure 7 is a block diagram of a computer-readable medium shown according to an exemplary embodiment. Detailed Embodiments
[0031] Exemplary embodiments will now be described more fully with reference to the accompanying drawings. However, the exemplary embodiments can be implemented in various forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this application will be thorough and complete, and will fully convey the concept of the exemplary embodiments to those skilled in the art. Like reference numerals in the figures denote like or similar parts, and thus their repeated description will be omitted.
[0032] In addition, the described features, structures, or characteristics may be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of the present application. However, those skilled in the art will realize that the technical solutions of the present application may be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. may be employed. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of the present application.
[0033] The block diagrams shown in the drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities may be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0034] The flowcharts shown in the drawings are only exemplary illustrations and do not necessarily include all the content and operations / steps, nor do they necessarily have to be executed in the described order. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined, so the actual execution order may change according to the actual situation.
[0035] It should be understood that although terms such as first, second, and third may be used herein to describe various components, these components should not be limited by these terms. These terms are used to distinguish one component from another. Thus, the first component discussed below may be referred to as the second component without departing from the teachings of the concepts of the present application. As used herein, the term "and / or" includes any one and all combinations of one or more of the associated listed items.
[0036] Those skilled in the art can understand that the drawings are only schematic diagrams of exemplary embodiments, and the modules or processes in the drawings are not necessarily essential for implementing the present application, so they cannot be used to limit the protection scope of the present application.
[0037] The technical abbreviations related to the present application are explained as follows:
[0038] The SSL protocol (Secure Sockets Layer) is a network security protocol designed to ensure the confidentiality, integrity, and authenticity of data during transmission between a client and a server by establishing an encrypted communication channel between the application layer and the transport layer. SSL was initially developed by Netscape in the mid-1990s and later evolved into the TLS (Transport Layer Security) protocol, which can be regarded as the successor and improved version of SSL. The SSL / TLS protocol is widely used in scenarios where secure data transmission is required:
[0039] 1. HTTPS: SSL / TLS is the core of HTTPS, protecting the communication between web browsers and servers.
[0040] 2. Email transmission: Secure versions of protocols such as SMTP, IMAP, POP3 (such as SMTPS).
[0041] 3. VPN: SSL VPN protects data through encrypted communication.
[0042] The SSL protocol is a protocol that protects network communication through encryption. It ensures the confidentiality, integrity, and authentication of data transmission and is an important cornerstone of modern Internet security.
[0043] Load Balancing (LB for short) is a clustering technology for servers or network devices. Load balancing distributes specific services (network services, network traffic, etc.) to multiple servers or network devices, thereby improving the service processing capacity and ensuring the high availability of the service. Server load balancing is divided into layer 4 server load balancing and layer 7 load balancing according to the packet layer processed by the LB device. Layer 4 processes the IP header of the IP packet and does not parse the payload above layer 4 of the packet (L4 server LB); layer 7 processes the payload part of the packet, such as the HTTP, RTSP, SIP packet headers, and sometimes also includes the packet content part (L7 server LB).
[0044] Health check: Load balancing determines the service availability of servers through health checks. The health check mechanism improves the overall service availability and avoids the impact of server anomalies on the overall service. After enabling the health check function, when a certain server is found to be abnormal during the health check, the load balancer will automatically distribute new requests to other servers with normal health checks; when the server resumes normal operation, the load balancer will automatically restore it to the load balancing service.
[0045] During the health monitoring process of the SSL protocol, certificate verification involves the signature verification stage, which uses asymmetric algorithms for calculation, resulting in a large consumption of device resources. Since the certificate chain sent by the server contains multiple certificates, each certificate needs to be independently verified, further increasing the computational complexity of the asymmetric algorithm and exacerbating the consumption of device resources. Health monitoring usually needs to be performed periodically, and performing a complete certificate verification each time will significantly increase the system burden. If certificate verification is not performed, although resource consumption is reduced, security will be compromised and the reliability of communication cannot be guaranteed. In addition, frequent certificate verification will also limit the number of servers that can be detected and occupy the resources of other system processes, affecting the overall performance.
[0046] To solve the problems existing in the prior art, this application proposes an optimized method for server health monitoring based on the SSL protocol. In the first health check, the server certificate is completely verified, including certificate chain verification and asymmetric algorithm calculation. Once the verification passes, subsequent health checks will use the optimized mode (SSL_VERIFY_OPTIMIZE) for certificate verification. In the optimized mode, only the length of the certificate and binary data information need to be compared, without repeating complex certificate chain verification and asymmetric algorithm calculation, thus significantly reducing the consumption of device resources. In this way, both the security of the server is ensured, and the resource occupancy is greatly reduced, improving the number of servers detected by the system and the processing efficiency.
[0047] In this application, during the health check process, the optimized mode is enabled by setting the certificate verification option to SSL_VERIFY_OPTIMIZE. After the first verification passes, the public key and binary data information of the server certificate are added to the certificate whitelist. During subsequent health checks, the public key of the server certificate is used to search in the certificate whitelist. If a matching item is found, only the certificate length, binary data information, and certificate validity period need to be compared, without performing complex asymmetric algorithm calculations. This mechanism not only reduces resource consumption but also improves the efficiency of health checks, enhancing the overall performance and competitiveness of the system.
[0048] The content of this application will be described in detail below with the help of specific embodiments.
[0049] Figure 1 It is a system block diagram of a server health monitoring method and device for a load balancing device shown according to an exemplary embodiment.
[0050] As Figure 1 shown, the system architecture 10 may include servers 101, 102, 103, a network 104, and a load balancing device 105. The network 104 is used to provide a medium for communication links between the servers 101, 102, 103 and the load balancing device 105. The network 104 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.
[0051] Users can use the load balancing device 105 to interact with the servers 101, 102, 103 through the network 104 to receive or send health monitoring messages, etc.
[0052] The load balancing device 105 can, for example, obtain handshake messages from servers 101, 102, and 103; the load balancing device 105 can, for example, extract certificate information based on the handshake messages; the load balancing device 105 can, for example, match the public key information in the certificate information with the entry data in the certificate whitelist; the load balancing device 105 can, for example, perform comparison and verification on the certificate information when matching the entry information; the load balancing device 105 can, for example, perform health monitoring on the servers after the verification passes.
[0053] It should be noted that the server health monitoring method for the load balancing device provided in the embodiments of the present application can be executed by the load balancing device 105. Correspondingly, the server health monitoring device for the load balancing device can be set in the load balancing device 105.
[0054] Figure 2 It is a flowchart of a server health monitoring method for a load balancing device shown according to an exemplary embodiment. The server health monitoring method 20 for the load balancing device includes at least steps S202 to S208.
[0055] As Figure 2 shown, in S202, the load balancing device obtains handshake messages from the servers. The load balancing device obtains SSL handshake messages from the servers.
[0056] In one embodiment, before the load balancing device obtains handshake messages from the servers, it further includes: the load balancing device creates an SSL client and sets the certificate verification mode to the optimized mode.
[0057] In S204, certificate information is extracted based on the handshake messages.
[0058] More specifically, when the certificate verification mode of the server is the optimized mode, certificate information is extracted based on the handshake messages; when the certificate verification mode of the server is not the optimized mode, certificate chain verification is performed based on verify_mode.
[0059] In S206, the public key information in the certificate information is matched with the entry data in the certificate whitelist.
[0060] In S208, when matching the entry information, comparison and verification are performed on the certificate information. Comparison and verification are performed on the certificate length information; and / or comparison and verification are performed on the certificate binary data; and / or comparison and verification are performed on the current time; and / or comparison and verification are performed on the certificate validity period information.
[0061] In one embodiment, for example, when no entry information is matched, the certificate information is subjected to a certificate chain verification; after the certificate chain verification passes, the server is added to the certificate whitelist.
[0062] More specifically, a certificate whitelist node can be created according to the certificate public key information, certificate binary data, and certificate length information of the server; the certificate whitelist node is used as the value, and the certificate public key information is used as the key; and it is stored in the certificate whitelist in the form of a key-value pair.
[0063] In one embodiment, the key-value pair can be stored through a map hash table data structure.
[0064] In S210, after the verification passes, the server is subjected to a health monitoring. An encrypted message can be sent using the encryption and decryption channels of the SSL handshake, and the message of the server is decrypted.
[0065] According to the server health monitoring method for a load balancing device of the present application, a handshake message from a server is obtained through the load balancing device; certificate information is extracted based on the handshake message; the public key information in the certificate information is matched with the entry data in the certificate whitelist; when the entry information is matched, the certificate information is subjected to a comparison verification; and after the verification passes, the server is subjected to a health monitoring method, which can optimize the certificate verification process in the SSL health check, simplify the subsequent verification using the certificate whitelist after the first verification, significantly reduce the consumption of device resources, and improve the health check efficiency and system performance.
[0066] It should be clearly understood that the present application describes how to form and use specific examples, but the principles of the present application are not limited to any details of these examples. On the contrary, based on the teachings of the content disclosed in the present application, these principles can be applied to many other embodiments.
[0067] Figure 3 It is a flowchart of a server health monitoring method for a load balancing device shown according to another exemplary embodiment. Figure 3 The shown process 30 is a detailed description of the "SSL health monitoring process".
[0068] As Figure 3 shown, in S302, the health monitoring process creates an SSL client and sets the certificate verification mode to SSL_VERIFY_OPTIMIZE. For example, calling SSL_set_verify or SSL_CTX_set_verify to set the verification mode to SSL_VERIFY_OPTIMIZE means that the certificate verification method is to verify in an optimized mode.
[0069] In S304, an SSL handshake is performed with the real server.
[0070] In S306, after the handshake is successful, an encrypted message is sent using the encryption and decryption channels of the SSL handshake, and the message sent by the server is decrypted.
[0071] In S308, health monitoring verification is performed to monitor the server status.
[0072] Figure 4 It is a flowchart of a server health monitoring method for a load balancing device shown according to another exemplary embodiment. Figure 4 The shown process 40 is for Figure 2 a detailed description of the "process of verifying the server-side certificate" in S102 of the shown process.
[0073] As Figure 4 shown, in S402, the SSL client and the server perform an SSL handshake and receive the certificate message sent by the server. The certificate message may include the certificate chain sent by the server, which contains multiple certificates, including the server certificate and the intermediate certificate (which is issued by the upper-level certificate and is used to issue the server certificate). It may include, for example:
[0074] Server certificate: The specific certificate that identifies the server.
[0075] Intermediate certificate (there may be multiple): The upper-level certificate of the server certificate, usually issued by a trusted intermediate certificate authority (CA).
[0076] Root certificate: The certificate at the top of the chain, a self-signed and CA certificate trusted by the client. Generally, the root certificate is not sent because it is usually already included in the client's trusted certificate store.
[0077] In S404, the certificate verification mode is checked. The client checks whether the certificate verification mode verify_mode is SSL_VERIFY_OPTIMIZE to check whether the certificate verification is performed in the optimized mode.
[0078] In S406, the certificate chain is verified according to verify_mode.
[0079] In S408, check whether there is an entry in the certificate whitelist. The certificate validity is verified in the optimized mode, the public key information of the server certificate in the certificate chain is extracted, and according to the public key information of the server certificate, an entry is searched for in the certificate whitelist to check whether there is an entry for the public key information of the server certificate in the certificate whitelist.
[0080] In S410, other information of the certificate is compared. If there is an entry in the whitelist, then other information is compared.
[0081] In S412, check whether all verifications pass. Compare the certificate length information. If the lengths are equal, further compare the certificate binary data sent by the server with the server certificate binary data in the entry. If they are consistent, further compare other certificate information, such as comparing the current time and the certificate validity period information to verify whether it is valid.
[0082] In S414, if all verifications pass, it means the certificate is valid and health monitoring can be performed. Otherwise, if the verification fails, go to step S406 and follow the previous process for verification.
[0083] In S416, perform certificate chain verification.
[0084] In S418, check whether it passes.
[0085] In S420, add the certificate to the white list. If the certificate verification passes, create a certificate white list node based on the server certificate public key, certificate binary data, and certificate length information. The node information includes fields such as <server certificate public key, certificate binary data, certificate length information>. Since queries need to be made in the certificate white list based on the server certificate public key, to speed up the query, a map hash table data structure can be used, for example, where the key is the server certificate public key information and the value is the white list node, and then add this node to the certificate white list map for subsequent certificate verification.
[0086] This application provides a method for efficiently health monitoring a server based on the SSL protocol. It only needs to verify the server certificate for the first time. Once the verification passes, subsequent health detections will verify the server certificate in an optimized mode. The optimized mode verification only needs to compare the certificate length and certificate binary data information, without the need for multiple complex certificate chain verifications, and thus does not require asymmetric algorithm calculations. Therefore, verifying the signature basically does not consume device resources, which not only ensures the security of the server but also greatly reduces resource consumption, thereby increasing the number of detected real servers and enhancing the product competitiveness.
[0087] Those skilled in the art can understand that all or part of the steps to implement the above embodiments are realized as a computer program executed by the CPU. When this computer program is executed by the CPU, it performs the above functions defined by the above method provided by this application. The program can be stored in a computer-readable storage medium, which can be a read-only memory, a disk, an optical disc, etc.
[0088] In addition, it should be noted that the above-mentioned drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present application, rather than for limiting purposes. It is easy to understand that the processes shown in the above-mentioned drawings do not indicate or limit the chronological order of these processes. Additionally, it is also easy to understand that these processes can be executed synchronously or asynchronously in, for example, multiple modules.
[0089] The following is an embodiment of the apparatus of the present application, which can be used to execute the method embodiment of the present application. For details not disclosed in the apparatus embodiment of the present application, please refer to the method embodiment of the present application.
[0090] Figure 5 is a block diagram of a server health monitoring device for a load balancing device shown according to an exemplary embodiment. As Figure 5 shown, the server health monitoring device 50 for the load balancing device includes: a message module 502, an information module 504, a matching module 506, a verification module 508, and a detection module 510.
[0091] The message module 502 is used for the load balancing device to obtain a handshake message from the server; the message module 502 is also used for the load balancing device to obtain an SSL handshake message from the server.
[0092] The information module 504 is used to extract certificate information based on the handshake message; the information module 504 is also used to extract certificate information based on the handshake message when the certificate verification mode of the server is the optimization mode; when the certificate verification mode of the server is not the optimization mode, perform certificate chain verification based on verify_mode.
[0093] The matching module 506 is used to match the public key information in the certificate information with the entry data in the certificate whitelist; the matching module 506 is also used to perform certificate chain verification on the certificate information when no entry information is matched; after the certificate chain verification passes, add the server to the certificate whitelist.
[0094] The verification module 508 is used to perform comparison verification on the certificate information when entry information is matched; the verification module 508 is also used to perform comparison verification on the certificate length information; and / or perform comparison verification on the certificate binary data; and / or perform comparison verification on the current time; and / or perform comparison verification on the certificate validity period information.
[0095] The detection module 510 is used to perform health monitoring on the server after the verification passes.
[0096] The server health monitoring device for a load balancing device according to the present application obtains handshake messages from a server through the load balancing device; extracts certificate information based on the handshake messages; matches the public key information in the certificate information with the entry data in the certificate whitelist; when entry information is matched, the certificate information is compared and verified; after the verification passes, the server is health monitored, which can optimize the certificate verification process in SSL health checks, simplify subsequent verification using the certificate whitelist after the first verification, significantly reduce device resource consumption, and improve the efficiency of health checks and system performance.
[0097] Figure 6 is a block diagram of an electronic device shown according to an exemplary embodiment.
[0098] The following refers to Figure 6 to describe the electronic device 600 according to this embodiment of the present application. Figure 6 The shown electronic device 600 is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.
[0099] As Figure 6 shown, the electronic device 600 is presented in the form of a general-purpose computing device. The components of the electronic device 600 may include but are not limited to: at least one processing unit 610, at least one storage unit 620, a bus 630 connecting different system components (including the storage unit 620 and the processing unit 610), a display unit 640, etc.
[0100] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 610, so that the processing unit 610 executes the steps according to various exemplary embodiments of the present application described in this specification. For example, the processing unit 610 can execute as Figure 2 , Figure 3 , Figure 4 shown in the steps.
[0101] The storage unit 620 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 6201 and / or a cache storage unit 6202, and may further include a read-only storage unit (ROM) 6203.
[0102] The storage unit 620 may also include a program / utilities 6204 having a set (at least one) of program modules 6205. Such program modules 6205 include but are not limited to: an operating system, one or more application programs, other program modules, and program data. The implementation of a network environment may be included in each or some combination of these examples.
[0103] The bus 630 can represent one or more of several types of bus structures, including a memory bus or a memory controller, a peripheral bus, an accelerated graphics port, a processing unit, or a local bus using any of the various bus structures.
[0104] The electronic device 600 can also communicate with one or more external devices 600' (such as a keyboard, a pointing device, a Bluetooth device, etc.), enabling communication with devices that allow a user to interact with the electronic device 600, and / or any device with which the electronic device 600 can communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 650. Moreover, the electronic device 600 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 660. The network adapter 660 can communicate with other modules of the electronic device 600 through the bus 630. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in conjunction with the electronic device 600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0105] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented through software, or through a combination of software and necessary hardware. Therefore, as Figure 7 shown, the technical solution according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, or a network device, etc.) to execute the above method according to the embodiments of the present application.
[0106] The software product can adopt any combination of one or more readable media. The readable media can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0107] The computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable storage medium may also be any readable medium other than the readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0108] The program code for performing the operations of this application may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as a stand-alone software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by connecting through the Internet using an Internet service provider).
[0109] The above computer-readable medium carries one or more programs, and when the one or more programs are executed by a device, the computer-readable medium realizes the following functions: the load balancing device obtains a handshake message from the server; extracts certificate information based on the handshake message; matches the public key information in the certificate information with the entry data in the certificate whitelist; when the entry information is matched, the certificate information is compared and verified; after the verification passes, the server is monitored for health.
[0110] Those skilled in the art can understand that the above-mentioned modules can be distributed in the device according to the description of the embodiments, or can be correspondingly changed and distributed in one or more devices that are uniquely different from this embodiment. The modules of the above embodiments can be combined into one module, or can be further split into multiple sub-modules.
[0111] From the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (such as a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.
[0112] The exemplary embodiments of the present application have been specifically illustrated and described above. It should be understood that the present application is not limited to the detailed structures, setting manners, or implementation methods described herein; on the contrary, the present application is intended to cover various modifications and equivalent settings included within the spirit and scope of the appended claims.
Claims
1. A server health monitoring method for a load balancing device, characterized in that: include: The load balancing device obtains the handshake message from the server; extracting certificate information based on the handshake message; Matching the public key information in the certificate information with the entry data in the certificate whitelist; When the table entry information is matched, the certificate information is compared and verified; After the verification is passed, health monitoring is performed on the server.
2. The method according to claim 1, characterized in that Before the load balancing device receives the handshake message from the server, it also includes: Create an SSL client on the load balancing device and set the certificate verification mode to optimized mode.
3. The method according to claim 1, characterized in that The load balancing device receives the handshake message from the server, including: The load balancing device receives the SSL handshake message from the server.
4. The method according to claim 1, characterized in that Extracting certificate information based on the handshake message includes: When the certificate verification mode of the server is an optimization mode, extracting certificate information based on the handshake message; When the certificate verification mode of the server is not the optimization mode, the certificate chain verification is performed based on verify_mode.
5. The method according to claim 1, characterized in that When the table entry information is matched, the certificate information is compared and verified, which also includes: When no matching table entry information is found, performing a certificate chain verification on the certificate information; After the certificate chain verification passes, the server is added to the certificate whitelist.
6. The method according to claim 5, characterized in that Adding the server to the certificate whitelist includes: Create a certificate whitelist node according to the server's certificate public key information, certificate binary data, and certificate length information; Use the certificate whitelist node as the value and the certificate public key information as the key; The certificate is stored in the certificate whitelist in the form of key-value pairs.
7. The method according to claim 6, characterized in that The certificate whitelist is stored in the form of key-value pairs, including: The key-value pairs are stored in the map hash table data structure.
8. The method according to claim 1, characterized in that Comparing and verifying the certificate information includes: Verify the certificate length information; and / or Performing a comparison to verify the certificate binary data; and / or Verify the current time; and / or Compare and verify the certificate validity period information.
9. The method according to claim 1, characterized in that Performing health monitoring on the server, including: The encrypted message is sent using the encryption and decryption channel of the SSL handshake, and the message of the server is decrypted.
10. A server health monitoring device for a load balancing device, characterized in that: include: The message module is used for the load balancing device to obtain the handshake message from the server; An information module, configured to extract certificate information based on the handshake message; A matching module, used to match the public key information in the certificate information with the table item data in the certificate whitelist; A verification module, used to compare and verify the certificate information when the table entry information is matched; The detection module is used to perform health monitoring on the server after the verification is passed.