Domain name certificate updating method and device and domain name management platform

By automatically identifying and updating the domain name certificate that is about to expire, the problem of inefficient domain name certificate update in the existing technology is solved, and more efficient and timely certificate management is achieved.

CN120200824APending Publication Date: 2025-06-24CHINA CONSTRUCTION BANK
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510456275.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In the prior art, the domain name certificate update efficiency is low and the lack of automated update mechanisms, which leads to difficulty in manual confirmation and update.

Method used

By determining the load balancing policy and usage objects associated with the target domain name certificate, an update prompt is sent based on the difference between the expiration date and the current date, and the domain name certificate that is about to expire is automatically identified and updated.

Benefits of technology

It improves the efficiency of domain name certificate updates, reduces manual intervention, ensures the timeliness of certificate updates, and reduces the risk of certificate expiration caused by human negligence.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200824A_ABST
    Figure CN120200824A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a domain name certificate updating method and device and a domain name management platform, and the method comprises the steps: determining a load balancing strategy associated with a target domain name certificate under the condition that the existence of the target domain name certificate is determined, a target difference value between the expiration date of the target domain name certificate and the current date is smaller than or equal to a first threshold value; using objects associated with the load balancing strategy are determined, and the using objects are objects for formulating the load balancing strategy; determining a target use object from the use objects; and sending an update prompt to the target use object based on the target difference value to prompt the target use object to update the target domain name certificate. According to the invention, the problem of low updating efficiency of the domain name certificate is solved, and the effect of improving the updating efficiency of the domain name certificate is further achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present invention relate to the field of communications, and in particular, to a method, apparatus, and domain name management platform for updating a domain name certificate. Background Art

[0002] In the related art, when a domain name certificate needs to be updated, only by relying on manual confirmation of the users of the domain name certificate one by one, and then reminding the users to renew and replace the certificate.

[0003] It can be seen that there is a technical problem of low efficiency in updating domain name certificates in the related art.

[0004] In view of the above problems existing in the related art, no effective solution has been proposed yet. Summary of the Invention

[0005] Embodiments of the present invention provide a method, apparatus, and domain name management platform for updating a domain name certificate, so as to at least solve the problem of low efficiency in updating domain name certificates in the related art.

[0006] According to an embodiment of the present invention, a method for updating a domain name certificate is provided, including: when it is determined that there is a target domain name certificate, determining a load balancing policy associated with the target domain name certificate, where a target difference between an expiration date of the target domain name certificate and the current date is less than or equal to a first threshold; determining a usage object associated with the load balancing policy, where the usage object is an object that formulates the load balancing policy; determining a target usage object from the usage objects; and sending an update prompt to the target usage object based on the target difference to prompt the target usage object to update the target domain name certificate.

[0007] In an exemplary embodiment, determining a target usage object from the usage objects includes: when there is one object in the usage objects, determining the usage object as the target usage object; when the usage objects include multiple objects, determining data traffic of each domain name corresponding to the usage objects within a historical predetermined time period; and determining the usage object corresponding to the maximum traffic included in the data traffic as the target usage object.

[0008] In an exemplary embodiment, sending an update prompt to the target user based on the target difference includes: when the target difference is greater than a second threshold, sending the update prompt to the target user at a first frequency, where the second threshold is less than the first threshold; when the target difference is greater than a third threshold and less than or equal to the second threshold, sending the update prompt to the target user at a second frequency, where the third threshold is less than the first threshold and the second frequency is greater than the first frequency; when the target difference is less than or equal to the third threshold, sending the update prompt to the target user at a third frequency, where the third threshold is less than the first threshold and the third frequency is greater than the second frequency.

[0009] In an exemplary embodiment, after sending an update prompt to the target user based on the target difference, the method further includes: when receiving a domain name certificate update request, determining the user permission of the update object that sends the domain name certificate update request to allow the update object to fill in the domain name certificate information to be updated within the user permission, where the domain name certificate update request is used to indicate updating the historical domain name certificate stored in the certificate server; verifying the domain name certificate information to be updated, and when the verification passes, generating a domain name certificate to be updated based on the domain name certificate information to be updated; using the domain name certificate to be updated to replace the historical domain name certificate.

[0010] In an exemplary embodiment, after generating a domain name certificate to be updated based on the domain name certificate information to be updated, the method further includes: obtaining a target association list, where the target association list includes load balancing rules and domain name certificates associated with the load balancing rules; when the target association list includes a target load balancing rule managed by the historical domain name certificate, associating the domain name certificate to be updated with the target load balancing rule in the target association list.

[0011] According to another embodiment of the present invention, there is provided a domain name management platform including the method described in any one of the above embodiments.

[0012] According to another embodiment of the present invention, there is provided an updating device for a domain name certificate, including: a first determination module, configured to determine a load balancing policy associated with the target domain name certificate when it is determined that there is a target domain name certificate, wherein a target difference between an expiration date of the target domain name certificate and the current date is less than or equal to a first threshold; a second determination module, configured to determine a usage object associated with the load balancing policy, wherein the usage object is an object that formulates the load balancing policy; a third determination module, configured to determine a target usage object from the usage objects; and an updating module, configured to send an update prompt to the target usage object based on the target difference to prompt the target usage object to update the target domain name certificate.

[0013] According to another embodiment of the present invention, there is also provided a computer-readable storage medium storing a computer program, wherein the computer program is configured to execute the steps in any one of the above method embodiments when running.

[0014] According to another embodiment of the present invention, there is also provided an electronic device including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0015] According to another embodiment of the present invention, there is also provided a computer program product including a computer program, wherein the steps of the methods described in various embodiments of the present application are implemented when the computer program is executed by a processor.

[0016] Through the present invention, when it is determined that there is a target domain name certificate, the load balancing policy associated with the target domain name certificate and the target difference between the expiration time of the target domain name certificate and the current time can be determined. Among them, a first threshold for representing the update period can be determined in advance, and the target difference is less than or equal to the first threshold, that is, when the expiration date of the target domain name certificate does not reach the first threshold, the target domain name certificate needs to be updated in time. The usage object that formulates the load balancing policy can also be determined. After determining the target usage object from the usage objects, an update prompt can be formulated according to the target difference and sent to the target usage object to instruct the target usage object to update the target domain name certificate. Since the target usage object can be determined from the usage objects that formulate the load balancing policy, and the target usage object can update the target domain name certificate that is about to expire according to the update prompt, the technical problem of low efficiency in updating domain name certificates in the related art can be solved, and the effect of improving the efficiency of updating domain name certificates can be achieved. Description of the Drawings

[0017] Figure 1It is a hardware structure block diagram of a mobile terminal for a method of updating a domain name certificate according to an embodiment of the present invention;

[0018] Figure 2 It is a flowchart of a method for updating a domain name certificate according to an embodiment of the present invention;

[0019] Figure 3 It is a schematic diagram for identifying a method for updating a domain name certificate according to an embodiment of the present invention;

[0020] Figure 4 It is a schematic diagram for reminding the expiration of a target domain name certificate according to an embodiment of the present invention;

[0021] Figure 5 It is a flowchart for replacing a target domain name certificate according to an embodiment of the present invention;

[0022] Figure 6 It is a structure block diagram of a device for updating a domain name certificate according to an embodiment of the present invention. Detailed implementation manners

[0023] In the following, embodiments of the present invention will be described in detail with reference to the accompanying drawings and in conjunction with the embodiments.

[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence.

[0025] The method embodiments provided in the embodiments of the present application can be executed on a mobile terminal, a computer terminal or a similar computing device. Taking running on a mobile terminal as an example, Figure 1 It is a hardware structure block diagram of a mobile terminal for a method of updating a domain name certificate according to an embodiment of the present invention. As Figure 1 shown, the mobile terminal may include one or more ( Figure 1 only one is shown in Figure 1 a processor 102 (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data. Among them, the above-mentioned mobile terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those of ordinary skill in the art can understand that Figure 1 the structure shown in Figure 1 is only schematic and does not limit the structure of the above-mentioned mobile terminal. For example, the mobile terminal may further include more or fewer components than

[0026] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the method for updating domain name certificates in the embodiments of the present invention. The processor 102 executes various functional applications and data processing by running the computer programs stored in the memory 104, that is, the above-mentioned method is implemented. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the mobile terminal through a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0027] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by a communication provider of the mobile terminal. In one instance, the transmission device 106 includes a network adapter (abbreviated as NIC for Network Interface Controller), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 may be a radio frequency (abbreviated as RF) module, which is used to communicate with the Internet wirelessly.

[0028] In this embodiment, a method for updating a domain name certificate is provided. Figure 2 is a flowchart of the method for updating a domain name certificate according to an embodiment of the present invention, as Figure 2 shown, and the process includes the following steps:

[0029] Step S202, when it is determined that there is a target domain name certificate, determine the load balancing policy associated with the target domain name certificate, where the target difference between the expiration date of the target domain name certificate and the current date is less than or equal to a first threshold;

[0030] Step S204, determine the object of use associated with the load balancing policy, where the object of use is the object that formulates the load balancing policy;

[0031] Step S206, determine a target object of use from the objects of use;

[0032] Step S208, send an update prompt to the target object of use based on the target difference to prompt the target object of use to update the target domain name certificate.

[0033] In the above embodiments, the domain name certificate can be an SSL (Secure Sockets Layer) certificate or a TLS (Transport Layer Security) certificate, which can be understood as a digital certificate issued by an authoritative and trusted third-party digital certificate certification authority (CA, Certificate Authority) to mark the identity of a website. It can include single-domain versions, multi-domain versions, and wildcard versions. Among them, a single domain name can be understood as protecting only one domain name, such as single domain names like yun.ccb.com, www.example.com, etc.; a multi-domain name can be understood as a certificate that can protect multiple different domain names, such as sub.example.com, mail.example.com, etc.; a general domain name can be understood as a certificate that protects all sub-domains at the same level under the same main domain name, such as *.yun.ccb.com. The domain name certificate encrypts the transmitted data by establishing a secure channel between the client browser and the website server, which can ensure that the data is not eavesdropped, tampered with, or forged during the transmission process. The load balancing strategy can be understood as a method and rule for distributing tasks or data traffic to multiple servers or processing nodes in a distributed system to optimize resource utilization, improve system performance, and reliability. That is, the load balancer can be used as the front end of the domain name certificate encryption, and can manage and unload the domain name certificate, thereby improving the overall performance and security of the system.

[0034] In the above embodiments, when configuring the HTTPS rule on the software load balancer, it is necessary to use the domain name certificate to ensure the security of user data and improve user trust. Since the domain name certificate itself lacks information about the user of use during the use process, it is very difficult for the software load balancer product side to directly obtain the user of use of the domain name certificate, which brings great difficulties to the daily management of the domain name certificate. Therefore, in the case where it is determined that there is one or more target domain name certificates to be updated, for the problem that the user information of the domain name certificate cannot be obtained, the load balancing strategy associated with the target domain name certificate and the target difference between the expiration date of the target domain name certificate and the current date can be determined first. Among them, a first threshold for representing the update period can be determined in advance. If the target difference is less than or equal to the first threshold, that is, when the expiration date of the target domain name certificate has not reached the first threshold, the target domain name certificate needs to be updated in a timely manner. The first threshold can be 2 months, 3 months, 4 months, etc., and the present invention does not limit this. Judging the urgency of the certificate based on the target difference (that is, the difference between the certificate expiration date and the current date) can ensure that the user of use can receive timely reminders at the critical moment when the certificate is about to expire, so that there is enough time for certificate update.

[0035] In the above embodiments, after determining the load balancing policy, the user information of the domain name certificate (i.e., the above-mentioned usage object) can be automatically mapped and matched according to the association relationships between the target domain name certificate and the load balancing policy, and between the load balancing policy and the rule user. The target domain name certificate updater (i.e., the above-mentioned target usage object) can be determined from the usage objects. Different methods for sending update prompts to the target usage object can be selected according to different target differences. After receiving the update prompt, the target usage object can complete the update operation of the target domain name certificate. By automatically identifying the domain name certificate that is about to expire and its associated usage object, the frequency and workload of manual intervention can be significantly reduced, the efficiency of certificate management can be improved, and the timeliness of certificate update can be ensured. In addition, there is no need to rely on manual memory and manual confirmation, reducing the risk of certificate expiration caused by human negligence. At the same time, automatically associating certificate update with the load balancing policy can avoid the complexity and potential errors of manually reconfiguring the load balancing rules after the update.

[0036] Through the present invention, in the case where a target domain name certificate exists, the load balancing policy associated with the target domain name certificate, the expiration time of the target domain name certificate, and the target difference between the expiration time and the current time can be determined. Among them, a first threshold for indicating the update period can be determined in advance. When the target difference is less than or equal to the first threshold, that is, when the expiration date of the target domain name certificate has not reached the first threshold, the target domain name certificate needs to be updated in a timely manner. The user who formulates the load balancing policy can also be determined. After determining the target usage object from the usage objects, an update prompt can be formulated according to the target difference and sent to the target usage object to instruct the target usage object to update the target domain name certificate. Since the target usage object can be determined from the users who formulate the load balancing policy, and the target usage object can update the target domain name certificate that is about to expire according to the update prompt, the technical problem of low efficiency in updating domain name certificates in the related art can be solved, and the effect of improving the efficiency of updating domain name certificates can be achieved.

[0037] Optionally, the execution subject of the above steps may be a domain name management platform, a terminal, a server, a background processor, etc., but is not limited thereto.

[0038] In an exemplary embodiment, determining the target usage object from the usage objects includes: when there is one object in the usage objects, determining the usage object as the target usage object; when there are multiple objects in the usage objects, determining the data traffic of the domain name corresponding to each usage object within a historical predetermined time period; and determining the usage object corresponding to the maximum traffic included in the data traffic as the target usage object.

[0039] In the above embodiments, since the target domain name certificate can be associated with multiple load balancing policies, the target user can be determined according to different situations. Figure 3 It is a schematic diagram for identifying the domain name certificate update method according to an embodiment of the present invention. As Figure 3 shown, for the case where a single domain name has a target domain name certificate (certificate 2 or certificate 3) associated with a load balancing policy (rule 3 or rule 4) (that is, the user includes one object), the user of the load balancing policy can be automatically and directly used as the update party (that is, the above-mentioned target user); for the case where multiple domain names or general domain names have a target domain name certificate (certificate 1) associated with multiple load balancing policies (rule 1 and rule 2), the data traffic of different users within a historical predetermined period can be automatically calculated, and the user with the largest data traffic within the historical predetermined period is determined as the update party (that is, the above-mentioned target user). Among them, the historical predetermined period can be the last month, the last two months, etc., and the present invention does not limit this. By intelligently identifying the user of the certificate update, the subjectivity and uncertainty of manual judgment are avoided, and at the same time, it is ensured that services with large traffic and high service requirements are not affected by the expiration of the certificate, which can improve the stability of the overall system and the user experience.

[0040] In an exemplary embodiment, sending an update prompt to the target user based on the target difference includes: when the target difference is greater than a second threshold, sending the update prompt to the target user at a first frequency, where the second threshold is less than the first threshold; when the target difference is greater than a third threshold and less than or equal to the second threshold, sending the update prompt to the target user at a second frequency, where the third threshold is less than the first threshold and the second frequency is greater than the first frequency; when the target difference is less than or equal to the third threshold, sending the update prompt to the target user at a third frequency, where the third threshold is less than the first threshold and the third frequency is greater than the second frequency.

[0041] In the above embodiments, a target domain name certificate expiration reminder service can be provided. For the service scenario of a domain name using HTTPS (Hypertext Transfer Protocol Secure) communication, different frequencies can be selected according to different target differences to send update prompts to the target user. Figure 4 It is a schematic diagram of the target domain name certificate expiration reminder according to an embodiment of the present invention. As Figure 4As shown, relying on the software load balancing policy management system, the certificate expiration reminder scheduled task can automatically check the certificate information of the target domain name that is about to expire. When the target difference is greater than the second threshold, an update prompt for the target domain name certificate update can be sent to the target user object at the first frequency. The update prompt can include the target domain name certificate on the operation side, the certificate association rule vip (Virtual IP), vport (Virtual Port), and the certificate expiration time. Among them, the first frequency can be a frequency in weeks, and the second threshold is a value less than the first threshold, which can be 30 days, 45 days, etc. The present invention does not limit this. When the target difference is greater than the third threshold and less than or equal to the second threshold, an update prompt indicating that the target domain name certificate is about to expire can be sent to the target user object at the second frequency. Among them, the second frequency can be a frequency in days, and the third threshold can be 0 days. When the target difference is less than or equal to the third threshold, an update prompt indicating that the target domain name certificate has expired can be sent to the target user object at the third frequency. Among them, the third frequency can be a frequency in hours.

[0042] In an exemplary embodiment, after sending the update prompt to the target user object based on the target difference, the method further includes: when receiving a domain name certificate update request, determining the user permission of the update object that sends the domain name certificate update request, so as to allow the update object to fill in the domain name certificate information to be updated within the scope of the user permission, where the domain name certificate update request is used to indicate updating the historical domain name certificate stored in the certificate server; verifying the domain name certificate information to be updated, and when the verification passes, generating a domain name certificate to be updated based on the domain name certificate information to be updated; and replacing the historical domain name certificate with the domain name certificate to be updated.

[0043] In the above embodiment, the domain name certificate user permission can set two user rights, namely the domain name certificate ordinary user and the domain name certificate administrator. Among them, the domain name certificate ordinary user can be understood as the applicant for domain name certificate replacement, and the domain name certificate administrator can be understood as the reviewer for domain name certificate replacement. Therefore, when receiving a domain name certificate update request, the user permission of the update object that sends the domain name certificate update request can be determined first, which can ensure that the update object fills in the domain name certificate information to be updated within the corresponding user permission range. Figure 5 is a flowchart of target domain name certificate replacement according to an embodiment of the present invention, as Figure 5 shown, the flowchart includes:

[0044] Step S502, start;

[0045] Step S504, control the user permission for domain name certificate replacement;

[0046] Step S506, fill in the domain name certificate information;

[0047] Step S508, review the domain name certificate application information;

[0048] Step S510, add new domain name certificate information;

[0049] Step S512, automatically save certificate information such as the private key to the dedicated server for domain name certificates;

[0050] Step S514, determine whether the certificate is associated with a software load balancing rule. If so, execute Step S516; if not, execute Step S522;

[0051] Step S516, obtain the associated rule list;

[0052] Step S518, determine whether the domain name certificate of the rule is a new certificate. If so, execute Step S522; if not, execute Step S520;

[0053] Step S520, update the load balancing rule configuration;

[0054] Step S522, end.

[0055] In the above embodiment, after completing the filling of the domain name certificate information to be updated, the update object can apply for the renewal of the domain name certificate to be updated through a third party institution, initiate a request to replace the domain name certificate to be updated on the domain name certificate management platform, and complete the replacement operation of the domain name certificate to be updated after the corresponding application system administrator approves it, that is, the historical domain name certificate can be replaced with the domain name certificate to be updated.

[0056] In an exemplary embodiment, after generating the domain name certificate to be updated based on the domain name certificate information to be updated, the method further includes: obtaining a target association list, where the target association list includes load balancing rules and domain name certificates associated with the load balancing rules; in the case that the target association list includes the target load balancing rule managed by the historical domain name certificate, associate the domain name certificate to be updated with the target load balancing rule in the target association list.

[0057] In the above embodiment, the domain name certificate management platform can, according to the identification of the logged-in user's identity, only display its relevant certificate list (i.e., the above target association list), and the certificates that are not of the update party will not be displayed on the page, which can avoid human misoperations. Among them, the target association list can contain all current load balancing rules and the domain name certificate information associated with these rules, ensuring that the system understands the certificate status currently used by each rule, so as to be able to determine whether the certificate needs to be updated and associated.

[0058] In the above embodiments, when replacing the domain name certificate, the certificate file, secret key, etc. can be stored on a specified certificate server to improve the security of the domain name certificate. At the same time, when it is determined that the target association list includes the target load balancing rules for historical domain name certificate management, the target load balancing rules associated with the domain name certificate can be automatically and uniformly associated to the domain name certificate to be updated, without manual association, improving the efficiency of domain name certificate replacement.

[0059] In the above embodiments, for the problem of low certificate replacement efficiency, the party replacing the domain name certificate can be automatically identified. That is, based on the association relationships between the domain name certificate and the software load balancing rules, and between the software load balancing rules and the rule users, the user information of the domain name certificate can be automatically mapped and matched. For the case where there are multiple users for one certificate in the case of multiple domain names or general domain names, the user with the largest traffic in the past month can be automatically calculated as the certificate replacement party by the system, changing from the original need for a large amount of manual analysis to automatic dynamic matching by the system, greatly reducing the labor cost. By designing the domain name certificate expiration reminder period and content more precisely, the reminder message can be sent to the person in charge more timely and accurately. In addition, the domain name certificate replacement service supports online domain name certificate update operations, can control user permissions, and also supports automatic linkage update of the domain name certificate information corresponding to the software load balancing rules, without manual maintenance, which can further improve the efficiency of domain name certificate replacement.

[0060] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc), and includes several instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods described in various embodiments of the present invention.

[0061] In this embodiment, a domain name management platform is further provided, including the method described in any of the above embodiments.

[0062] In the above embodiments, the domain name certificate can be an SSL (Secure Sockets Layer) certificate or a TLS (Transport Layer Security) certificate, which can be understood as a digital certificate issued by an authoritative and trustworthy third-party digital certificate certification authority (CA, Certificate Authority) for marking the identity of a website. It can include single-domain version, multi-domain version, and wildcard version. Among them, a single domain can be understood as protecting only one domain name, such as single domain names like yun.ccb.com, www.example.com, etc.; a multi-domain can be understood as a single certificate protecting multiple different domain names, such as sub.example.com, mail.example.com, etc.; a universal domain name can be understood as a certificate protecting all sub-domains of the same level under the same main domain name, such as *.yun.ccb.com. The domain name certificate encrypts the transmitted data by establishing a secure channel between the client browser and the website server, which can ensure that the data is not eavesdropped, tampered with, or forged during the transmission process. The load balancing strategy can be understood as a method and rule for distributing tasks or data traffic to multiple servers or processing nodes in a distributed system to optimize resource utilization, improve system performance, and reliability. That is, the load balancer can be used as the front end of the domain name certificate encryption, and can manage and unload the domain name certificate, thereby improving the overall performance and security of the system.

[0063] In the above embodiments, when configuring HTTPS rules on software load balancing, it is necessary to use a domain name certificate to ensure the security of user data and improve user trust. Since the user information of the domain name certificate itself is lacking during use, it is very difficult for the software load balancing product party to directly obtain the user of the domain name certificate, which brings great difficulties to the daily management of the domain name certificate. Therefore, in the case where it is determined that there is one or more target domain name certificates to be updated, for the problem that the user information of the domain name certificate cannot be obtained, the load balancing strategy associated with the target domain name certificate and the target difference between the expiration date of the target domain name certificate and the current date can be determined first. Among them, a first threshold for representing the update period can be determined in advance. If the target difference is less than or equal to the first threshold, that is, when the expiration date of the target domain name certificate has not reached the first threshold, the target domain name certificate needs to be updated in a timely manner. The first threshold can be 2 months, 3 months, 4 months, etc., and the present invention does not limit this. Judging the urgency of the certificate based on the target difference (i.e., the difference between the certificate expiration date and the current date) can ensure that the user can receive timely reminders at the critical moment when the certificate is about to expire, so that there is enough time for certificate update.

[0064] In the above embodiments, after determining the load balancing policy, the user information of the domain name certificate (i.e., the above-mentioned usage object) can be automatically mapped and matched according to the association relationship between the target domain name certificate and the load balancing policy, and between the load balancing policy and the rule user. The target domain name certificate updater (i.e., the above-mentioned target usage object) can be determined from the usage objects. Different methods for sending update prompts to the target usage object can be selected according to different target differences. After receiving the update prompt, the target usage object can complete the update operation of the target domain name certificate. By automatically identifying the domain name certificate that is about to expire and its associated usage object, the frequency and workload of manual intervention can be significantly reduced, the efficiency of certificate management can be improved, and the timeliness of certificate update can be ensured. In addition, there is no need to rely on manual memory and manual confirmation, reducing the risk of certificate expiration caused by human negligence. At the same time, associating certificate update with the load balancing policy automatically can avoid the complexity and potential errors of manually reconfiguring the load balancing rules after the update.

[0065] In the above embodiments, since the target domain name certificate can be associated with multiple load balancing policies, the target usage object can be determined in different cases. Figure 3 It is a schematic diagram for identifying the domain name certificate update method according to the embodiment of the present invention. As Figure 3 shown, for the case where there is one target domain name certificate (Certificate 2 or Certificate 3) associated with one load balancing policy (Rule 3 or Rule 4) for a single domain name (i.e., there is one object in the usage object), the user of the load balancing policy can be directly used as the updater (i.e., the above-mentioned target usage object); for the case where there is one target domain name certificate (Certificate 1) associated with multiple load balancing policies (Rule 1 and Rule 2) for multiple domain names or a general domain name, the data traffic of different usage objects within a historical predetermined period can be automatically calculated, and the usage object with the largest data traffic within the historical predetermined period is determined as the updater (i.e., the above-mentioned target usage object). Among them, the historical predetermined period can be the recent one month, the recent two months, etc., and the present invention does not limit this. A single domain name can be understood as protecting only one domain name, such as single domain names like yun.ccb.com, www.example.com, etc.; multiple domain names can be understood as one certificate can protect multiple different domain names, such as sub.example.com, mail.example.com, etc.; a general domain name can be understood as one certificate protecting all sub-domains of the same level under the same main domain name, such as *.yun.ccb.com. By intelligently identifying the usage object for certificate update, the subjectivity and uncertainty of manual judgment are avoided, and at the same time, it is ensured that services with large traffic and high service requirements are not affected by certificate expiration, which can improve the stability of the overall system and the user experience.

[0066] In the above embodiments, a service for reminding of the expiration of the target domain name certificate can be provided. For the business scenario of a domain name using HTTPS (Hypertext Transfer Protocol Secure) communication, different frequencies can be selected according to different target differences to send update reminders to the target user. Figure 4 is a schematic diagram of reminding of the expiration of the target domain name certificate according to an embodiment of the present invention, as Figure 4 shown. Relying on the software load balancing policy management system, the certificate expiration reminder timing task can automatically check the information of the target domain name certificate that is about to expire. When the target difference is greater than the second threshold, an update reminder for updating the target domain name certificate can be sent to the target user object at the first frequency. The update reminder can include the target domain name certificate of the operation end, the certificate association rule vip (Virtual IP), vport (Virtual Port), and the certificate expiration time. Among them, the first frequency can be a frequency in weeks, and the second threshold is a value less than the first threshold, which can be 30 days, 45 days, etc. The present invention does not limit this. When the target difference is greater than the third threshold and less than or equal to the second threshold, an update reminder that the target domain name certificate is about to expire can be sent to the target user object at the second frequency. Among them, the second frequency can be a frequency in days, and the third threshold can be 0 days. When the target difference is less than or equal to the third threshold, an update reminder that the target domain name certificate has expired can be sent to the target user object at the third frequency. Among them, the third frequency can be a frequency in hours.

[0067] In the above embodiments, the user permissions of the domain name certificate can set two user rights, namely the ordinary user of the domain name certificate and the administrator of the domain name certificate. Among them, the ordinary user of the domain name certificate can be understood as the applicant for replacing the domain name certificate, and the administrator of the domain name certificate can be understood as the reviewer for replacing the domain name certificate. Therefore, when receiving a domain name certificate update request, the user permissions of the update object that sends the domain name certificate update request can be determined first, which can ensure that the update object fills in the information of the domain name certificate to be updated within the corresponding user permissions. Figure 5 is a flow chart of replacing the target domain name certificate according to an embodiment of the present invention, as Figure 5 shown. The flow chart includes:

[0068] Step S502, start;

[0069] Step S504, control the user permissions for replacing the domain name certificate;

[0070] Step S506, fill in the domain name certificate information;

[0071] Step S508, review the application information of the domain name certificate;

[0072] Step S510, add domain name certificate information;

[0073] Step S512, automatically save certificate information such as private keys to the exclusive server for domain name certificates;

[0074] Step S514, determine whether the certificate is associated with a software load balancing rule. If so, execute Step S516; if not, execute Step S522;

[0075] Step S516, obtain the list of associated rules;

[0076] Step S518, determine whether the domain name certificate of the rule is a new certificate. If so, execute Step S522; if not, execute Step S520;

[0077] Step S520, update the load balancing rule configuration;

[0078] Step S522, end.

[0079] In the above embodiment, after completing the filling of the domain name certificate information to be updated, the update object can apply for the renewal of the domain name certificate to be updated through a third-party institution, initiate a request to replace the domain name certificate to be updated on the domain name certificate management platform, and complete the replacement operation of the domain name certificate to be updated after the corresponding application system administrator approves, that is, the historical domain name certificate can be replaced with the domain name certificate to be updated.

[0080] In the above embodiment, the domain name certificate management platform can, based on the identification of the logged-in user's identity, only display its relevant certificate list (i.e., the above-mentioned target association list), and the certificates that are not of the updating party will not be displayed on the page, which can avoid human error operations. Among them, the target association list can include all current load balancing rules and the domain name certificate information associated with these rules, ensuring that the system understands the certificate status currently used by each rule, so as to be able to judge whether the certificate needs to be updated and associated.

[0081] In the above embodiment, when replacing the domain name certificate, the certificate file, secret key, etc. can be stored on the designated certificate server to improve the security of the domain name certificate. At the same time, when it is determined that the target association list includes the target load balancing rules for historical domain name certificate management, the target load balancing rules associated with the domain name certificate can be automatically and uniformly associated to the domain name certificate to be updated, without manual association, improving the efficiency of domain name certificate replacement.

[0082] In the above embodiments, in view of the problem of low efficiency in certificate replacement, the party replacing the domain name certificate can be automatically identified. That is, based on the association relationship between the domain name certificate and the software load balancing rules, and between the software load balancing rules and the rule users, the user information of the domain name certificate can be automatically mapped and matched. In the case where there are multiple domain names or a general domain name and one certificate has multiple users, the user with the largest traffic in the past month is automatically calculated as the certificate replacement party. The original need for a large amount of manual analysis is adjusted to automatic dynamic matching by the system, greatly reducing the labor cost. By designing the domain name certificate expiration reminder period and content more refinedly, the reminder message can be sent to the person in charge more timely and accurately. In addition, the domain name certificate replacement service supports online domain name certificate update operations, can also control user permissions, and at the same time supports automatic linkage update of the domain name certificate information corresponding to the software load balancing rules, eliminating the need for manual maintenance, and can further improve the efficiency of domain name certificate replacement.

[0083] In this embodiment, an update device for domain name certificates is also provided. This device is used to implement the above embodiments and preferred implementation manners, and those that have been described will not be repeated. As used hereinafter, the term "module" can be a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation in hardware, or a combination of software and hardware is also possible and contemplated.

[0084] Figure 6 is a structural block diagram of an update device for domain name certificates according to an embodiment of the present invention. As Figure 6 shown, the device includes:

[0085] A first determination module 62, configured to determine a load balancing policy associated with the target domain name certificate when it is determined that there is a target domain name certificate, where a target difference between an expiration date of the target domain name certificate and the current date is less than or equal to a first threshold;

[0086] A second determination module 64, configured to determine a user object associated with the load balancing policy, where the user object is the object that formulates the load balancing policy;

[0087] A third determination module 66, configured to determine a target user object from the user objects;

[0088] An update module 68, configured to send an update reminder to the target user object based on the target difference to prompt the target user object to update the target domain name certificate.

[0089] In an exemplary embodiment, the third determination module 66 determines the target usage object from the usage objects in the following manner: when there is one object in the usage objects, the usage object is determined as the target usage object; when there are multiple objects in the usage objects, the data traffic of the domain name corresponding to each usage object within a historical predetermined time period is determined; and the usage object corresponding to the maximum traffic included in the data traffic is determined as the target usage object.

[0090] In an exemplary embodiment, the update module 68 sends an update prompt to the target usage object based on the target difference in the following manner: when the target difference is greater than a second threshold, the update prompt is sent to the target usage object at a first frequency, where the second threshold is less than the first threshold; when the target difference is greater than a third threshold and less than or equal to the second threshold, the update prompt is sent to the target usage object at a second frequency, where the third threshold is less than the first threshold and the second frequency is greater than the first frequency; when the target difference is less than or equal to the third threshold, the update prompt is sent to the target usage object at a third frequency, where the third threshold is less than the first threshold and the third frequency is greater than the second frequency.

[0091] In an exemplary embodiment, after the device sends an update prompt to the target usage object based on the target difference: when a domain name certificate update request is received, the user permission of the update object that sends the domain name certificate update request is determined to allow the update object to fill in the domain name certificate information to be updated within the scope of the user permission, where the domain name certificate update request is used to indicate updating the historical domain name certificate stored in the certificate server; the domain name certificate information to be updated is verified, and when the verification passes, a domain name certificate to be updated is generated based on the domain name certificate information to be updated; and the historical domain name certificate is replaced with the domain name certificate to be updated.

[0092] In an exemplary embodiment, after the device generates a domain name certificate to be updated based on the domain name certificate information to be updated: a target association list is obtained, where the target association list includes load balancing rules and domain name certificates associated with the load balancing rules; when the target association list includes the target load balancing rule managed by the historical domain name certificate, the domain name certificate to be updated is associated with the target load balancing rule in the target association list.

[0093] It should be noted that the above-mentioned modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to this: the above-mentioned modules are all located in the same processor; or, the above-mentioned modules are respectively located in different processors in any combination form.

[0094] An embodiment of the present invention also provides a computer-readable storage medium, in which a computer program is stored. Wherein, the computer program is configured to execute the steps in any one of the above method embodiments when running.

[0095] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: USB flash drives, read-only memories (ROM for short), random access memories (RAM for short), mobile hard disks, magnetic disks or optical disks and other various media that can store computer programs.

[0096] An embodiment of the present invention also provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above method embodiments.

[0097] In an exemplary embodiment, the above electronic device may further include a transmission device and an input / output device. Wherein, the transmission device is connected to the above processor, and the input / output device is connected to the above processor.

[0098] An embodiment of the present invention also provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of the methods in various embodiments of the present application are implemented.

[0099] The specific examples in this embodiment may refer to the examples described in the above embodiments and exemplary embodiments, and will not be repeated here.

[0100] Obviously, those skilled in the art should understand that the above-mentioned modules or steps of the present invention can be implemented by a general-purpose computing device. They can be concentrated on a single computing device, or distributed on a network composed of multiple computing devices. They can be implemented by program codes executable by the computing device. Thus, they can be stored in a storage device and executed by the computing device. And in some cases, the steps shown or described can be executed in a different order than here, or they can be separately made into individual integrated circuit modules, or multiple modules or steps among them can be made into a single integrated circuit module to implement. In this way, the present invention is not limited to any specific combination of hardware and software.

[0101] The above are only the preferred embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and variations. Any modification, equivalent replacement, improvement, etc. made within the principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for updating a domain name certificate, characterized in that: include: In the case of determining that there is a target domain name certificate, determining a load balancing strategy associated with the target domain name certificate, wherein a target difference between an expiration date of the target domain name certificate and a current date is less than or equal to a first threshold; Determine a usage object associated with the load balancing strategy, wherein the usage object is an object for formulating the load balancing strategy; Determine a target user from the user objects; An update prompt is sent to the target user object based on the target difference, so as to prompt the target user object to update the target domain name certificate.

2. The method according to claim 1, characterized in that Determining a target user object from the user objects includes: In a case where the usage objects include one object, determining the usage object as the target usage object; In the case where the usage object includes multiple objects, determining the data flow of the domain name corresponding to each usage object within a historical predetermined time period; The usage object corresponding to the maximum flow included in the data flow is determined as the target usage object.

3. The method according to claim 1, characterized in that Sending an update prompt to the target user object based on the target difference includes: When the target difference is greater than a second threshold, sending the update prompt to the target user at a first frequency, wherein the second threshold is less than the first threshold; When the target difference is greater than a third threshold and less than or equal to a second threshold, sending the update prompt to the target user at a second frequency, wherein the third threshold is less than the first threshold and the second frequency is greater than the first frequency; When the target difference is less than or equal to a third threshold, the update prompt is sent to the target user at a third frequency, wherein the third threshold is less than the first threshold, and the third frequency is greater than the second frequency.

4. The method according to claim 1, characterized in that: After sending an update prompt to the target usage object based on the target difference, the method further includes: In the case of receiving a domain name certificate update request, determining the user authority of the update object that sends the domain name certificate update request to allow the update object to fill in the domain name certificate information to be updated within the scope of the user authority, wherein the domain name certificate update request is used to indicate the update of the historical domain name certificate stored in the certificate server; Verifying the domain name certificate information to be updated, and if the verification passes, generating a domain name certificate to be updated based on the domain name certificate information to be updated; The historical domain name certificate is replaced by the domain name certificate to be updated.

5. The method according to claim 4, characterized in that After generating the domain name certificate to be updated based on the domain name certificate information to be updated, the method further includes: Obtaining a target association list, wherein the target association list includes a load balancing rule and a domain name certificate associated with the load balancing rule; In a case where the target association list includes a target load balancing rule managed with the historical domain name certificate, the domain name certificate to be updated is associated with the target load balancing rule in the target association list.

6. A domain name management platform, characterized in that: Used to perform the method according to any one of claims 1 to 5.

7. A device for updating a domain name certificate, characterized in that: include: A first determination module is used to determine a load balancing strategy associated with the target domain name certificate when it is determined that there is a target domain name certificate, wherein a target difference between an expiration date of the target domain name certificate and a current date is less than or equal to a first threshold; A second determination module is used to determine a use object associated with the load balancing strategy, wherein the use object is an object for formulating the load balancing strategy; A third determining module, used to determine a target user from the user objects; An update module is used to send an update prompt to the target user object based on the target difference, so as to prompt the target user object to update the target domain name certificate.

8. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program is configured to execute the method according to any one of claims 1 to 5 when executed.

9. An electronic device comprising a memory and a processor, characterized in that: A computer program is stored in the memory, and the processor is configured to run the computer program to perform the method according to any one of claims 1 to 5.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method described in any one of claims 1 to 5 are implemented.