Password computing service providing method and device, equipment and storage medium
By introducing routing services and multilingual request processing services into the password service container, the problem of difficult to balance the performance improvement and resource demand reduction in traditional password services is solved, and efficient and scalable password computing services are realized.
Patent Information
- Application Number
- CN202510596324.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-06-24
AI Technical Summary
Traditional password services are difficult to balance between performance improvement and resource demand reduction, and cannot ensure consistency of the operating environment during deployment, resulting in inefficiency and performance bottlenecks.
By introducing routing services and multilingual request processing services into the password service container, high-performance password computing capabilities are achieved using C language, customized computing interfaces are implemented using Java language, and container images are built through unified basic images to achieve cross-platform deployment.
Improves password computing performance, reduces resource requirements during microservice deployment, and meets the scalability of business functions, reducing hardware architecture and operating system differences.
Smart Images

Figure CN120200846A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security, and particularly to a method, device, equipment and storage medium for providing password calculation services. Background Art
[0002] Traditional password services are usually developed and implemented using a certain single programming language. However, the C language lacks a general HTTP RESTful interface development framework and requires self-implementation of the receiving and parsing modules for HTTP (HyperText Transfer Protocol) requests. The development time of business function interfaces is long and the efficiency is not high. The Java language depends on the JVM (Java Virtual Machine) environment during runtime, occupies too much memory resources, and the processing effect of concurrent requests is average, which is likely to become a performance bottleneck. In addition, password services are deployed in the form of jar (Java Archive) packages or executable programs, and need to be configured and compiled based on the source code for different target server architectures, which cannot guarantee the consistency of the running environment. Therefore, how to improve the password calculation performance while reducing the resource requirements during microservice deployment and meeting the scalability of business functions is an urgent problem to be solved at present. Summary of the Invention
[0003] In view of this, the purpose of the present invention is to provide a method, device, equipment and storage medium for providing password calculation services, which can improve the password calculation performance while reducing the resource requirements during microservice deployment and meeting the scalability of business functions. The specific solutions are as follows:
[0004] In a first aspect, the present application discloses a method for providing password calculation services, which is applied to a password service container and includes:
[0005] Obtain a target transaction request forwarded by a gateway; the target transaction request is a transaction request sent by a target application that has passed the authentication of the gateway;
[0006] Determine the uniform resource locator corresponding to the target transaction request, so as to determine the target request processing service corresponding to the target transaction request based on the uniform resource locator, and distribute the target transaction request to the target request processing service based on a preset routing rule;
[0007] Use the target request processing service to process the target transaction request to obtain a corresponding target processing result, and forward the target processing result to a target cryptographic machine, so that the target cryptographic machine performs cryptographic operations based on the target processing result to obtain the target password calculation result corresponding to the target transaction request;
[0008] Obtain the target password calculation result returned by the target cryptographic machine, and return the target password calculation result to the target application through the gateway to complete the password calculation service;
[0009] Wherein, the target request processing service is a first request processing service or a second request processing service. The first request processing service is a request processing service built based on the C language, and the second request processing service is a request processing service built based on the Java language. The first request processing service and the second request processing service are located in the same password service container.
[0010] Optionally, the process by which the gateway authenticates the target application corresponding to the target transaction request includes:
[0011] The gateway obtains the target transaction request sent by the target application;
[0012] The gateway determines whether the service call permission corresponding to the target application meets the preset service call condition corresponding to the target transaction request, so that when the service call permission of the target application meets the preset service call condition, the gateway forwards the target transaction request to the password service container.
[0013] Optionally, the method for providing the password calculation service further includes:
[0014] If the service call permission corresponding to the target application does not meet the preset service call condition corresponding to the target transaction request, the gateway generates a corresponding identity authentication request based on the target transaction request;
[0015] The gateway sends the identity authentication request to the identity authentication service to obtain the identity authentication result corresponding to the identity authentication request;
[0016] The gateway re-determines the service call permission corresponding to the target application based on the identity authentication result, and refuses to forward the target transaction request to the password service container when the service call permission does not meet the preset service call condition corresponding to the target transaction request.
[0017] Optionally, the determination of the uniform resource locator corresponding to the target transaction request, based on the uniform resource locator to determine the target request processing service corresponding to the target transaction request, and distributing the target transaction request to the target request processing service based on the preset routing rule includes:
[0018] Use the routing service in the password service container to identify the uniform resource locator in the target transaction request;
[0019] Determine a target request processing service corresponding to the target transaction request based on the uniform resource locator;
[0020] Use the routing service to distribute the target transaction request to the target request processing service based on a preset routing rule.
[0021] Optionally, the using the target request processing service to process the target transaction request to obtain a corresponding target processing result includes:
[0022] Use the target request processing service to parse the target transaction request to obtain a corresponding parsed message;
[0023] Assemble the parsed message based on a preset adaptation format to obtain an assembled message after assembly;
[0024] Use a pre-acquired target key to encrypt the assembled message after assembly based on a preset encryption algorithm to obtain a target processing result corresponding to the target transaction request.
[0025] Optionally, the target key is a key saved locally by the password service container or a key obtained by the target request processing service from a key management center using the target transaction request.
[0026] Optionally, the forwarding the target processing result to a target cipher machine includes:
[0027] Communicate with a management platform of a cipher machine pool through a preset communication link to determine an idle cipher machine from all cipher machines in the cipher machine pool based on load balancing;
[0028] Determine a target cipher machine from all the idle cipher machines;
[0029] Forward the target processing result to the target cipher machine.
[0030] In a second aspect, the present application discloses a password calculation service providing device, which is applied to a password service container and includes:
[0031] A transaction request acquisition module, configured to acquire a target transaction request forwarded by a gateway; the target transaction request is a transaction request sent by a target application that has passed the authentication of the gateway;
[0032] A transaction request distribution module, configured to determine a uniform resource locator corresponding to the target transaction request, so as to determine a target request processing service corresponding to the target transaction request based on the uniform resource locator, and distribute the target transaction request to the target request processing service based on a preset routing rule;
[0033] A password calculation result acquisition module, configured to use the target request processing service to process the target transaction request to obtain a corresponding target processing result, and forward the target processing result to a target cryptographic machine, so that the target cryptographic machine performs password operations based on the target processing result to obtain a target password calculation result corresponding to the target transaction request;
[0034] A password calculation result return module, configured to obtain the target password calculation result returned by the target cryptographic machine, and return the target password calculation result to the target application through the gateway to complete the password calculation service;
[0035] Wherein, the target request processing service is a first request processing service or a second request processing service, the first request processing service is a request processing service built based on the C language, the second request processing service is a request processing service built based on the Java language, and the first request processing service and the second request processing service are located in the same password service container.
[0036] In a third aspect, the present application discloses an electronic device, including:
[0037] A memory, configured to store a computer program;
[0038] A processor, configured to execute the computer program to implement the foregoing password calculation service providing method.
[0039] In a fourth aspect, the present application discloses a computer-readable storage medium, configured to store a computer program, wherein the computer program, when executed by a processor, implements the foregoing password calculation service providing method.
[0040] In this application, when providing password calculation services, a password service container obtains a target transaction request forwarded by a gateway; the target transaction request is a transaction request sent by a target application that has passed the authentication of the gateway; determine the uniform resource locator corresponding to the target transaction request, so as to determine the target request processing service corresponding to the target transaction request based on the uniform resource locator, and distribute the target transaction request to the target request processing service based on a preset routing rule; use the target request processing service to process the target transaction request to obtain a corresponding target processing result, and forward the target processing result to a target cipher machine, so that the target cipher machine performs password operations based on the target processing result to obtain the target password calculation result corresponding to the target transaction request; obtain the target password calculation result returned by the target cipher machine, and return the target password calculation result to the target application through the gateway to complete the password calculation service; wherein, the target request processing service is a first request processing service or a second request processing service, the first request processing service is a request processing service built based on the C language, the second request processing service is a request processing service built based on the Java language, and the first request processing service and the second request processing service are located in the same password service container. It can be seen that in this application, after the password service container receives an interface request, the routing service matches the routing rules according to the URL of the interface, so as to forward the target transaction request to the corresponding target request processing service according to different business requirements. The first request processing service built based on the C language can make full use of the characteristics of the C language to provide high-concurrency and high-throughput password calculation capabilities under the condition of low memory occupancy; the second request processing service built based on the Java language can utilize the rich development frameworks and ecosystems of the Java language to quickly implement customized scenario-based calculation interfaces, or complete the adaptation of the password calculation service to password devices of different manufacturers, and provide calculation interfaces that are more matched and user-friendly to the business scenario. At the same time, this application integrates the routing service, the first request processing service and the second request processing service, and builds a password service container image based on a unified base image, so that it has good cross-platform deployment characteristics and reduces the differences in hardware architectures and operating systems in the actual deployment environment. Description of the Drawings
[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0042] Figure 1 It is a flowchart of a method for providing a password calculation service disclosed in this application;
[0043] Figure 2 It is a schematic diagram of the architecture of a password service container for password calculation services disclosed in this application;
[0044] Figure 3 It is a signaling diagram of a specific password calculation service providing process disclosed in this application;
[0045] Figure 4 It is a schematic diagram of the structure of a password calculation service providing device disclosed in this application;
[0046] Figure 5 It is a structural diagram of an electronic device disclosed in this application. Detailed implementation manners
[0047] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0048] Traditional password services are usually developed and implemented using a certain single programming language. However, the C language lacks a general HTTP RESTful interface development framework and requires self-implementation of the HTTP request receiving and parsing modules. The development time of business function interfaces is long and the efficiency is not high; the Java language depends on the JVM environment during runtime, occupies too much memory resources, and the concurrent request processing effect is average, which is likely to become a performance bottleneck. In addition, password services are deployed in the form of jar packages or executable programs, and need to be configured and compiled based on the source code for different target server architectures, and the consistency of the running environment cannot be guaranteed. To solve the above technical problems, this application discloses a method for providing password calculation services, which can improve the password calculation performance while reducing the resource requirements during microservice deployment and meet the scalability of business functions.
[0049] See Figure 1 As shown, an embodiment of the present invention discloses a method for providing password calculation services, which is applied to a password service container and includes:
[0050] Step S11, obtaining a target transaction request forwarded by a gateway; the target transaction request is a transaction request sent by a target application that has passed the gateway authentication.
[0051] In this embodiment, as Figure 2The figure shows a schematic diagram of the architecture of a specific cryptographic service container for cryptographic computing services, which includes a routing service, a high-performance cryptographic computing service (i.e., a first request processing service built on the C language) and a cryptographic function extension service (i.e., a second request processing service built on the Java language). That is to say, this embodiment is based on a multi-language fusion cryptographic service implemented by containerization, and the cryptographic computing service divides the computing interface according to the business performance requirements. The high-performance cryptographic computing interface is used to provide the first request processing service, and the customized extension interface is used to provide the second request processing service. The two constitute a complete cryptographic computing service, realize the collaborative processing of interfaces with different performance requirements, and jointly provide cryptographic service capabilities to the outside world. The high-performance cryptographic computing service implemented in C language makes full use of the characteristics of C language to provide high concurrency and high throughput cryptographic computing capabilities under low memory usage conditions. The cryptographic function extension service can quickly implement a customized scenario-based computing interface based on the rich development framework and ecology of the Java language, or complete the adaptation of the cryptographic computing service to cryptographic devices from different manufacturers, and provide a computing interface that is more compatible with the business scenario and easy to use.
[0052] In this embodiment, Figure 3 As shown, before the cryptographic service container obtains the target transaction request forwarded by the gateway, the gateway will authenticate the target application that initiated the target transaction request. Different target applications are integrated by the application system using SDK (Software Development Kit, Software Development Kit), and the target transaction request issued by the target application is actually a call to a specific service implemented through an interface. In a specific implementation, the process of the gateway authenticating the target application corresponding to the target transaction request may include: the gateway obtains the target transaction request sent by the target application; the gateway determines whether the service call permission corresponding to the target application meets the preset service call condition corresponding to the target transaction request, so that the gateway forwards the target transaction request to the cryptographic service container when the service call permission of the target application meets the preset service call condition. If the service call permission corresponding to the target application does not meet the preset service call condition corresponding to the target transaction request, the gateway generates a corresponding identity authentication request based on the target transaction request; the gateway sends the identity authentication request to the identity authentication service to obtain the identity authentication result corresponding to the identity authentication request; the gateway determines the service call permission corresponding to the target application again based on the identity authentication result, and refuses to forward the target transaction request to the cryptographic service container when the service call permission does not meet the preset service call condition corresponding to the target transaction request. That is to say, the gateway will forward the target transaction request to the cryptographic service container only when the service call permissions of the target application meet the permissions required to execute the target transaction request.
[0053] Step S12: Determine the Uniform Resource Locator (URL) corresponding to the target transaction request, determine the target request processing service corresponding to the target transaction request based on the URL, and distribute the target transaction request to the target request processing service based on a preset routing rule.
[0054] In this embodiment, as Figure 3 shown, after receiving an interface request, the password service container first needs to determine the URL (Uniform Resource Locator) corresponding to the target request. After determining the Uniform Resource Locator corresponding to the target transaction request, then determine the request processing service corresponding to the target transaction request as the target request processing service based on this URL, and distribute the target transaction request to this target request processing service for processing. In a specific implementation manner, this process may include: using the routing service in the password service container to identify the Uniform Resource Locator in the target transaction request; determining the target request processing service corresponding to the target transaction request based on the Uniform Resource Locator; using the routing service to distribute the target transaction request to the target request processing service based on a preset routing rule. That is to say, the routing service performs routing rule matching according to the URL of the interface. Requests that meet the high-performance password calculation interface are forwarded to the high-performance password calculation service implemented in C language, and the remaining interface requests are forwarded to the password function extension service implemented in Java language. It can be understood that the target request processing service is the first request processing service or the second request processing service. The first request processing service is a request processing service built based on C language, and the second request processing service is a request processing service built based on Java language. The first request processing service and the second request processing service are located in the same password service container. By integrating the routing service, high-performance password calculation service, and password function extension service, a password calculation service container image is built based on a unified base image, enabling it to have good cross-platform deployment characteristics and reducing the differences in hardware architecture and operating system in the actual deployment environment.
[0055] Step S13: Use the target request processing service to process the target transaction request to obtain a corresponding target processing result, and forward the target processing result to the target cryptographic machine so that the target cryptographic machine performs a cryptographic operation based on the target processing result to obtain the target cryptographic calculation result corresponding to the target transaction request.
[0056] In this embodiment, the password service container processes the target transaction request by using the target request processing service to obtain a corresponding target processing result, which may specifically include: parsing the target transaction request by using the target request processing service to obtain a corresponding parsed message; assembling the parsed message based on a preset adaptation format to obtain an assembled message; encrypting the assembled message by using a preset encryption algorithm with a pre-obtained target key to obtain the target processing result corresponding to the target transaction request. The target key is a key saved locally by the password service container or a key obtained by the target request processing service from the key management center by using the target transaction request. When forwarding the target processing result to the target cipher machine, the password service container may communicate with the management platform of the cipher machine pool through a preset communication link to determine an idle cipher machine from all the cipher machines in the cipher machine pool based on load balancing; determining a target cipher machine from all the idle cipher machines; and forwarding the target processing result to the target cipher machine. After receiving the target processing result, the target cipher machine performs a password operation to obtain a target password calculation result corresponding to the target transaction request. It can be understood that the cipher machines included in the cipher machine pool include not only physical cipher machines and virtual cipher machines, but also the compatibility with devices of different manufacturers is realized according to user requirements.
[0057] Step S14: Obtain the target password calculation result returned by the target cipher machine, and return the target password calculation result to the target application through the gateway to complete the password calculation service.
[0058] In this embodiment, the target cipher machine returns the target password result to the password service container, and the password service container returns the received target password result to the target application through the gateway, thereby completing the overall password calculation service process.
[0059] It can be seen that in this application, after the password service container receives an interface request, the routing service matches the routing rules according to the URL of the interface, and thus forwards the target transaction request to the corresponding target request processing service according to different business requirements. The first request processing service built based on the C language can make full use of the characteristics of the C language to provide high-concurrency and high-throughput password calculation capabilities under the condition of low memory occupancy; the second request processing service built based on the Java language can utilize the rich development frameworks and ecosystems of the Java language to quickly implement customized scenario-based calculation interfaces, or complete the adaptation of the password calculation service to password devices of different manufacturers, and provide calculation interfaces that are more matched and easier to use with business scenarios. At the same time, this application integrates the routing service, the first request processing service, and the second request processing service, and builds a password service container image based on a unified base image, enabling it to have good cross-platform deployment characteristics and reducing the differences in hardware architectures and operating systems in the actual deployment environment.
[0060] SeeFigure 4 As shown in the figure, the present application discloses a password calculation service providing device, which is applied to a password service container and includes:
[0061] A transaction request acquisition module 11, configured to acquire a target transaction request forwarded by a gateway; the target transaction request is a transaction request sent by a target application that has passed the authentication of the gateway;
[0062] A transaction request distribution module 12, configured to determine a uniform resource locator corresponding to the target transaction request, so as to determine a target request processing service corresponding to the target transaction request based on the uniform resource locator, and distribute the target transaction request to the target request processing service based on a preset routing rule;
[0063] A password calculation result acquisition module 13, configured to use the target request processing service to process the target transaction request to obtain a corresponding target processing result, and forward the target processing result to a target cipher machine, so that the target cipher machine performs a password operation based on the target processing result to obtain a target password calculation result corresponding to the target transaction request;
[0064] A password calculation result return module 14, configured to acquire the target password calculation result returned by the target cipher machine, and return the target password calculation result to the target application through the gateway to complete the password calculation service;
[0065] Wherein, the target request processing service is a first request processing service or a second request processing service, the first request processing service is a request processing service built based on the C language, the second request processing service is a request processing service built based on the Java language, and the first request processing service and the second request processing service are located in the same password service container.
[0066] It can be seen that in the present application, after the password service container receives an interface request, the routing service matches the routing rule according to the URL of the interface, so as to forward the target transaction request to the corresponding target request processing service according to different business requirements. The first request processing service built based on the C language can make full use of the characteristics of the C language to provide high-concurrency and high-throughput password calculation capabilities under the condition of low memory occupancy; the second request processing service built based on the Java language can utilize the rich development frameworks and ecosystems of the Java language to quickly implement customized scenario-based calculation interfaces, or complete the adaptation of the password calculation service to password devices of different manufacturers, and provide calculation interfaces that are more matched and user-friendly to the business scenario. At the same time, the present application integrates the routing service, the first request processing service and the second request processing service, and constructs a password service container image based on a unified base image, so that it has good cross-platform deployment characteristics and reduces the differences in hardware architectures and operating systems in the actual deployment environment.
[0067] In a specific embodiment, the gateway may specifically include:
[0068] A request receiving module, configured to obtain the target transaction request sent by the target application;
[0069] A request forwarding module, configured to determine whether the service call permission corresponding to the target application meets the preset service call condition corresponding to the target transaction request, so as to forward the target transaction request to the password service container when the service call permission of the target application meets the preset service call condition.
[0070] In a specific embodiment, the gateway may further include:
[0071] An authentication request generation module, configured to generate a corresponding identity authentication request based on the target transaction request if the service call permission corresponding to the target application does not meet the preset service call condition corresponding to the target transaction request;
[0072] An authentication result acquisition module, configured to send the identity authentication request to an identity authentication service to obtain an identity authentication result corresponding to the identity authentication request;
[0073] A permission non - satisfaction operation module, configured to re - determine the service call permission corresponding to the target application based on the identity authentication result, and refuse to forward the target transaction request to the password service container when the service call permission does not meet the preset service call condition corresponding to the target transaction request.
[0074] In a specific embodiment, the transaction request distribution module 12 may specifically include:
[0075] A locator recognition unit, configured to recognize a uniform resource locator in the target transaction request by using a routing service in the password service container;
[0076] A service determination unit, configured to determine a target request processing service corresponding to the target transaction request based on the uniform resource locator;
[0077] A request distribution unit, configured to distribute the target transaction request to the target request processing service based on a preset routing rule by using the routing service.
[0078] In a specific embodiment, the password calculation result acquisition module 13 may specifically include:
[0079] A request parsing unit, configured to parse the target transaction request by using the target request processing service to obtain a corresponding parsed message;
[0080] A message assembly unit for assembling the parsed message based on a preset adaptation format to obtain a corresponding assembled message;
[0081] A message encryption unit for encrypting the assembled message based on a preset encryption algorithm using a pre-acquired target key to obtain a target processing result corresponding to the target transaction request.
[0082] In a specific embodiment, the password calculation result acquisition module 13 may specifically include:
[0083] An idle cipher machine determination unit for communicating with the management platform of the cipher machine pool through a preset communication link to determine an idle cipher machine from all the cipher machines in the cipher machine pool based on load balancing;
[0084] A target cipher machine determination unit for determining a target cipher machine from all the idle cipher machines;
[0085] A processing result forwarding unit for forwarding the target processing result to the target cipher machine.
[0086] Furthermore, an embodiment of the present application also discloses an electronic device, Figure 5 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure cannot be considered as any limitation to the scope of use of the present application.
[0087] Figure 5 It is a structural schematic diagram of an electronic device 20 provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the password calculation service providing method disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0088] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is made thereto here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application requirements, and no specific limitation is made here.
[0089] In addition, as a carrier for storing resources, the memory 22 can be a read-only memory, a random access memory, a magnetic disk, an optical disc, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc. The storage method can be transient storage or permanent storage.
[0090] Among them, the operating system 221 is used to manage and control each hardware device and the computer program 222 on the electronic device 20, and it can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the password calculation service providing method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 can further include computer programs that can be used to complete other specific tasks.
[0091] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the password calculation service providing method disclosed above is implemented. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be elaborated herein.
[0092] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts between the various embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and reference can be made to the description in the method part for related parts.
[0093] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0094] The steps of the method or algorithm described in combination with the embodiments disclosed herein can be directly implemented by hardware, a software module executed by a processor, or a combination of the two. The software module can be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0095] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the said element.
[0096] The technical solutions provided in this application have been introduced in detail above. Specific examples are used in this text to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A method for providing cryptographic computing services, characterized in that: Applies to the cryptographic service container, including: Obtaining a target transaction request forwarded by the gateway; the target transaction request is a transaction request issued by a target application that has been authenticated by the gateway; Determine a uniform resource locator corresponding to the target transaction request, determine a target request processing service corresponding to the target transaction request based on the uniform resource locator, and distribute the target transaction request to the target request processing service based on a preset routing rule; Processing the target transaction request using the target request processing service to obtain a corresponding target processing result, and forwarding the target processing result to a target cryptographic machine so that the target cryptographic machine performs cryptographic calculation based on the target processing result to obtain a target cryptographic calculation result corresponding to the target transaction request; Obtaining the target cryptographic calculation result returned by the target cryptographic machine, and returning the target cryptographic calculation result to the target application through the gateway to complete the cryptographic calculation service; Among them, the target request processing service is a first request processing service or a second request processing service, the first request processing service is a request processing service built based on C language, the second request processing service is a request processing service built based on Java language, and the first request processing service and the second request processing service are located in the same cryptographic service container.
2. The method for providing cryptographic computing services according to claim 1, characterized in that: The process of the gateway authenticating the target application corresponding to the target transaction request includes: The gateway obtains the target transaction request sent by the target application; The gateway determines whether the service calling permission corresponding to the target application satisfies the preset service calling condition corresponding to the target transaction request, so that the gateway forwards the target transaction request to the cryptographic service container when the service calling permission of the target application satisfies the preset service calling condition.
3. The method for providing cryptographic computing services according to claim 2, characterized in that: Also includes: If the service calling authority corresponding to the target application does not satisfy the preset service calling condition corresponding to the target transaction request, the gateway generates a corresponding identity authentication request based on the target transaction request; The gateway sends the identity authentication request to the identity authentication service to obtain the identity authentication result corresponding to the identity authentication request; The gateway re-determines the service calling authority corresponding to the target application based on the identity authentication result, and refuses to forward the target transaction request to the cryptographic service container when the service calling authority does not satisfy the preset service calling condition corresponding to the target transaction request.
4. The method for providing cryptographic computing services according to claim 1, characterized in that: The determining of the uniform resource locator corresponding to the target transaction request, determining the target request processing service corresponding to the target transaction request based on the uniform resource locator, and distributing the target transaction request to the target request processing service based on a preset routing rule, includes: identifying a uniform resource locator in the target transaction request using a routing service in the cryptographic service container; Determining a target request processing service corresponding to the target transaction request based on the uniform resource locator; The routing service is used to distribute the target transaction request to the target request processing service based on a preset routing rule.
5. The method for providing cryptographic computing services according to claim 1, characterized in that: The using the target request processing service to process the target transaction request to obtain a corresponding target processing result includes: Parsing the target transaction request using the target request processing service to obtain a corresponding parsed message; Assembling the parsed messages based on a preset adaptation format to obtain corresponding assembled messages; The assembled message is encrypted using a pre-acquired target key based on a preset encryption algorithm to obtain a target processing result corresponding to the target transaction request.
6. The method for providing cryptographic computing services according to claim 5, characterized in that: The target key is a key stored locally by the cryptographic service container or a key obtained by the target request processing service from a key management center using the target transaction request.
7. The method for providing cryptographic computing services according to any one of claims 1 to 6, characterized in that: The step of forwarding the target processing result to a target cryptographic machine comprises: Communicate with a management platform of a cryptographic machine pool through a preset communication link to determine an idle cryptographic machine from all the cryptographic machines in the cryptographic machine pool based on load balancing; Determine a target cipher machine from all the idle cipher machines; The target processing result is forwarded to the target cryptographic machine.
8. A cryptographic computing service providing device, characterized in that: Applies to the cryptographic service container, including: A transaction request acquisition module, used to acquire a target transaction request forwarded by the gateway; the target transaction request is a transaction request issued by a target application that has been authenticated by the gateway; a transaction request distribution module, configured to determine a uniform resource locator corresponding to the target transaction request, determine a target request processing service corresponding to the target transaction request based on the uniform resource locator, and distribute the target transaction request to the target request processing service based on a preset routing rule; a cryptographic calculation result acquisition module, configured to process the target transaction request using the target request processing service to obtain a corresponding target processing result, and forward the target processing result to a target cryptographic machine so that the target cryptographic machine performs a cryptographic operation based on the target processing result to obtain a target cryptographic calculation result corresponding to the target transaction request; A cryptographic calculation result returning module, used for obtaining the target cryptographic calculation result returned by the target cryptographic machine, and returning the target cryptographic calculation result to the target application through the gateway to complete the cryptographic calculation service; Among them, the target request processing service is a first request processing service or a second request processing service, the first request processing service is a request processing service built based on C language, the second request processing service is a request processing service built based on Java language, and the first request processing service and the second request processing service are located in the same cryptographic service container.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the method for providing cryptographic computing services as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: Used to store a computer program, wherein when the computer program is executed by a processor, the cryptographic computing service providing method according to any one of claims 1 to 7 is implemented.