Cluster security access method and cluster security verification method based on Openharmony
By introducing strong security authentication and simple authentication mechanisms into the cluster, the problem of low security access and verification efficiency of clusters is solved, and more efficient access and security verification is achieved.
Patent Information
- Application Number
- CN202510205871.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-06-27
AI Technical Summary
When existing cluster secure access and security authentication technologies cope with complex cluster environments and changing needs, there are problems such as low access efficiency of nodes within the cluster and cluster security verification efficiency.
The cluster and authentication platform respond to the user's cluster access operation, perform strong security authentication. After the general node detects that the strong security authentication is passed, each secondary node is simply authenticated, and a simple authentication table is generated to send it to the authentication platform to complete the access operation of the general node and the secondary node.
The secure access of the cluster is realized, the access efficiency of nodes in the cluster and the security verification efficiency of the cluster are improved, and the problems of low access efficiency and security verification efficiency in the prior art are solved.
Smart Images

Figure CN120223353A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of computer networks, and in particular, to a cluster security access method, a cluster security verification method, a device, a device, and a medium. Background Art
[0002] With the rapid development of information technology, the number and types of nodes in the network are constantly increasing, and cluster systems have been widely used in many fields. In the operation of cluster systems, secure access has become a crucial link. Currently, secure access technologies are constantly evolving, but there are still some limitations. Common secure access technologies mostly rely on simple authentication password means, such as account passwords, challenge-response, certificate signature authentication, etc.
[0003] However, these methods have many deficiencies when dealing with cluster environments. For cluster authentication, the common processing method is to convert it into independent access authentication for each node within the cluster. Although this method achieves access authentication to a certain extent, due to each node operating independently, there is a lack of overall coordination and management, which easily leads to chaos and inconsistency in the authentication process. In addition, some solutions use a separate access gateway or access point, allowing all nodes in the cluster to access the platform through this unified entrance. Although this centralized access method is convenient for management to a certain extent, there is a risk of single-point failure. Once the access gateway or access point fails, the access of the entire cluster will be severely affected. Moreover, when the cluster scales, this centralized authentication method requires synchronizing the authentication status, which consumes a large amount. As the cluster scale expands or shrinks, the process of adjusting the authentication status becomes complex and time-consuming, and at the same time, a unified platform is required for centralized management, increasing the complexity and management cost of the system.
[0004] In summary, the existing cluster security access and security authentication technologies have problems of low access efficiency of nodes within the cluster and low security verification efficiency of the cluster when dealing with complex cluster environments and changing requirements. Summary of the Invention
[0005] The present invention provides a cluster security access method, a cluster security verification method, a device, a device, and a medium, which can solve the problems of low access efficiency of nodes within the cluster and low security verification efficiency of the cluster existing in the existing cluster security access and security authentication technologies.
[0006] In a first aspect, an embodiment of the present invention provides a cluster security access method, which is executed by a cluster and an authentication platform. The cluster includes a master node and at least one slave node. The method includes:
[0007] In response to a user's cluster access operation, perform strong security authentication on the master node through the authentication platform;
[0008] After the master node detects that the strong security authentication is passed, it performs simple authentication on each slave node, obtains a simple authentication table matching the cluster access operation, and sends it to the authentication platform;
[0009] In response to receiving the simple authentication table, the authentication platform completes the access operations for the master node and each slave node.
[0010] In a second aspect, an embodiment of the present invention provides a cluster security verification method, which is executed by an authentication platform. The method includes:
[0011] In response to a strong message request from the master node, determine whether the strong message request includes a direct trust identifier and an identity authentication key that match the authentication platform, and determine whether the master node is within the trust validity period according to the strong message request, and perform security verification on the master node according to the determination result;
[0012] In response to a simple message request from a slave node, determine whether the master node passes the security verification, and after determining that the master node passes the security verification, perform security verification on the slave node according to a preset simple authentication table and the simple message request; wherein, the simple message request includes a slave node identification code and an indirect trust identifier that match the slave node.
[0013] In a third aspect, an embodiment of the present invention provides a cluster security access device, which is executed by a security access system configured with one master node, at least one slave node, and an authentication platform. The device includes:
[0014] A master node authentication module, configured to perform strong security authentication on the master node through the authentication platform in response to a user's cluster access operation;
[0015] A slave node authentication module, configured to perform simple authentication on each slave node after the master node detects that the strong security authentication is passed, obtain a simple authentication table matching the cluster access operation, and send it to the authentication platform;
[0016] An access module, configured to complete the access operations for the master node and each slave node in response to the authentication platform receiving the simple authentication table.
[0017] In a fourth aspect, an embodiment of the present invention provides a cluster security verification device, which is executed by an authentication platform. The device includes:
[0018] A master node verification module, configured to respond to a strong message request from the master node, determine whether the strong message request includes a direct trust identifier and an identity authentication key that match the authentication platform, and determine whether the master node is within the trust validity period according to the strong message request, and perform security verification on the master node according to the determination result;
[0019] A secondary node verification module, configured to, in response to a simple message request of a secondary node, determine whether a primary node passes a security verification, and after determining that the primary node passes the security verification, perform a security verification on the secondary node according to a preset simple authentication table and the simple message request; wherein, the simple message request includes a secondary node identification code and an indirect trust identifier that match the secondary node.
[0020] In a fifth aspect, an embodiment of the present invention provides an electronic device, which includes:
[0021] At least one processor; and
[0022] A memory communicatively connected to the at least one processor; wherein,
[0023] The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute a cluster security access method and a cluster security verification method according to any embodiment of the present invention.
[0024] In a sixth aspect, an embodiment of the present invention provides a computer-readable storage medium, which stores computer instructions for causing a processor to implement a cluster security access method and a cluster security verification method according to any embodiment of the present invention when executed.
[0025] The technical solution of the embodiment of the present invention first responds to a user's cluster access operation through a cluster and an authentication platform, performs a strong security authentication on the primary node through the authentication platform. After the primary node detects that the strong security authentication passes, it performs a simple authentication on each secondary node, obtains a simple authentication table that matches the cluster access operation, and sends it to the authentication platform. Then, the authentication platform responds to the reception of the simple authentication table to complete the access operations for the primary node and each secondary node, realizing the secure access of the cluster. Then, the authentication platform responds to a strong message request of the primary node, determines whether the strong message request includes a direct trust identifier and an identity authentication key that match the authentication platform, and determines whether the primary node is within the trust validity period according to the strong message request, and performs a security verification on the primary node according to the judgment result. Finally, in response to a simple message request of the secondary node, it determines whether the primary node passes the security verification, and after determining that the primary node passes the security verification, performs a security verification on the secondary node according to the preset simple authentication table and the simple message request, solving the problem that the access efficiency of nodes in the cluster and the security verification efficiency of the cluster are both relatively low in the existing cluster security access and security authentication technologies, realizing the security verification of each node in the cluster by the authentication platform, and improving the access efficiency of nodes in the cluster and the security verification efficiency of the cluster.
[0026] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS
[0027] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0028] Figure 1 is a flowchart of a cluster security access method provided according to Embodiment 1 of the present invention;
[0029] Figure 2 is a flowchart of a cluster security verification method provided according to Embodiment 2 of the present invention;
[0030] Figure 3 is a schematic structural diagram of a cluster security access device provided according to Embodiment 3 of the present invention;
[0031] Figure 4 is a schematic structural diagram of a cluster security verification device provided according to Embodiment 4 of the present invention;
[0032] Figure 5 is a schematic structural diagram of an electronic device for implementing a cluster security access method and a cluster security verification method according to the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0033] In order to enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only some of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0034] It should be noted that the terms "first", "second", etc. in the description, claims and the above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "comprising" and "having" any variations are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0035] Embodiment 1
[0036] Figure 1 FIG. is a flowchart of a cluster security access method provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation where each node in the cluster is securely accessed to the authentication platform. This method can be executed by a cluster security access device, which can be implemented in the form of hardware and / or software, and can be configured in an Openharmony cluster and an Openharmony authentication platform with cluster security access functions.
[0037] As Figure 1 shown, the method includes:
[0038] S110. In response to a user's cluster access operation, perform strong security authentication on the master node through the authentication platform.
[0039] Among them, the cluster access operation refers to an instruction behavior initiated by the user to prompt the device cluster to connect to the service platform. This operation triggers a series of processes such as strong security authentication of the cluster master node to achieve the legal access of the device cluster to the service platform and subsequent service development. For example, in a smart home system, an administrator executes an operation on the control terminal to access a cluster composed of a batch of newly purchased smart devices (such as smart cameras, smart door locks, smart sensors, etc.) to the home intelligent management platform. This is a cluster access operation, which triggers a series of subsequent authentication processes to ensure the security and legality of the access.
[0040] Furthermore, the authentication platform is responsible for identity authentication and security assessment of the master node that requests access. The authentication platform can be a server cluster deployed in the cloud, with powerful computing power and security protection mechanism. It stores key information such as the system's root certificate, authentication policy, and various encryption keys, and is the authority to determine whether the master node can be legally accessed. For example, in a large industrial Internet of Things project, the authentication platform deployed on the enterprise's private cloud is responsible for authenticating the master nodes of the equipment cluster distributed in various production workshops. Only the master nodes that pass the authentication can lead their subordinate devices to access the enterprise's production management system and obtain corresponding permissions and data access qualifications.
[0041] Furthermore, the master node may be a device with strong processing power and resources in the cluster, responsible for managing and coordinating other nodes in the cluster (such as the master node in the Star Flash technology); in this embodiment, the master node may be selected in the cluster by automatic election based on parameters such as device configuration performance, signal strength, remaining running memory size, remaining storage size, etc., using algorithms such as Gossip protocol, ZooKeeper, Chubby, Paxos, Raft, etc., or may be manually specified by the user according to actual needs; illustratively, taking the smart factory as an example, the master node may be an edge computing device in the workshop, which communicates with the authentication platform on the one hand to complete the access authentication process, and on the other hand, it also manages and controls the numerous sensors, actuators and other devices connected to it. The master node needs to have high stability and security to ensure the normal operation of the entire cluster.
[0042] Among them, in response to the user's cluster access operation, the main node is strongly authenticated through the authentication platform, including: the authentication platform performs signature verification on the standard certificate preset in the main node; after the authentication platform detects that the signature verification is passed, it uses a preset key generation algorithm to generate an identity authentication key matching the main node and sends it to the main node; in response to the reception of the identity authentication key, the main node obtains a preset main node identification code and main node business attribute information, and generates a direct trust identifier matching the main node based on the main node identification code and the main node business attribute information and sends it to the authentication platform to complete the strong security authentication of the node.
[0043] In a specific implementation scenario of this embodiment, the specific steps of strong security authentication are as follows:
[0044] Step 1) "Verify the signature of the preset standard certificate in the master node through the authentication platform": The standard certificate is an electronic document issued by an authoritative certificate issuing authority to the master node to prove the identity and legality of the master node. The certificate contains basic information of the master node (such as device identifier, affiliated organization, etc.), public key, and the signature of the certificate issuer, etc. Taking the common SSL / TLS certificate as an example, it is widely used for identity verification in network communication, and the standard certificate in the master node adopts a similar structure and principle. The signature verification process is like verifying whether the signature on a document is true and valid, that is, the authentication platform uses the public key of the certificate issuer to decrypt the signature on the standard certificate, and then compares the decrypted content with other information in the certificate. If the comparison is consistent, it indicates that the certificate is issued by a legitimate certificate issuing authority and the certificate content has not been tampered with, and the signature verification passes; otherwise, the signature verification fails and the identity of the master node cannot be confirmed.
[0045] Step 2) "After the authentication platform detects that the signature verification passes, use the preset key generation algorithm to generate an identity authentication key that matches the master node and send it to the master node": When the authentication platform confirms that the signature of the standard certificate of the master node is valid, it will start the preset key generation algorithm. The key generation algorithm is a carefully designed mathematical algorithm used to generate high-strength and unpredictable encryption keys. For example, the SM3_HMAC algorithm, which combines the principles of hash functions and message authentication codes, generates an identity authentication key by inputting specific parameters (such as the key seed of the authentication platform, relevant information of the master node, etc.). This identity authentication key is an important credential in the subsequent communication process between the master node and the authentication platform, and is used to verify whether each communication request of the master node is legal. The authentication platform sends the generated identity authentication key to the master node through a secure communication channel (such as a network connection using an encrypted transmission protocol) to ensure the security of the key during transmission.
[0046] Step 3) "In response to the receipt of the identity authentication key, the master node obtains the preset master node identification code and the master node business attribute information, and generates a direct trust mark matching the master node based on the master node identification code and the master node business attribute information and sends it to the authentication platform to complete the strong security authentication of the node": After receiving the identity authentication key sent by the authentication platform, the master node will obtain the preset master node identification code and the master node business attribute information from its own storage area. The master node identification code is the unique identifier of the master node, similar to the ID card number of the device, which is used to uniquely determine the identity of the master node in the system, such as the serial number, MAC address, and other identification codes generated by specific encoding. The master node business attribute information describes the business functions, authority scope, and other business-related attributes undertaken by the master node. For example, in an intelligent transportation system, the business attribute information of the master node may include the road section range it manages, the type of equipment that can be accessed, and the data processing priority. Based on this information, the master node uses a specific algorithm (such as a combination of hash algorithm and encryption technology) to generate a direct trust mark matching itself. Finally, the master node sends the generated direct trust mark to the authentication platform, and the authentication platform verifies the direct trust mark after receiving it. If the verification is successful, it means that the main node has successfully passed the strong security authentication and can officially access the system to conduct business; if the verification fails, the authentication platform will reject the access request of the main node and record relevant information for subsequent analysis and processing.
[0047] S120: After the main node detects that the strong security authentication has passed, it performs a simple authentication on each secondary node, obtains a simple authentication table that matches the cluster access operation, and sends it to the authentication platform.
[0048] Among them, after the main node detects that the strong security authentication has passed, it performs a simple authentication on each sub-node and obtains a simple authentication table that matches the cluster access operation, including: obtaining the sub-node identification code and cluster attribute information of each sub-node in the cluster through the main node, and generating an indirect trust identifier that matches each sub-node according to the above-generated information; sending each indirect trust identifier to the sub-node that matches the indirect trust identifier through the main node to perform a simple authentication on each sub-node; aggregating and storing the sub-node identification codes of each sub-node through the main node to obtain a simple authentication table that matches the cluster access operation.
[0049] Among them, the sub-node can be a device managed by the main node, which undertakes specific business functions in the cluster; exemplarily, if the main node is the main node in the Star Flash technology, then the sub-node can be the sub-node in the Star Flash technology; further, simple authentication is a relatively simplified authentication method, based on the trust relationship established by the main node through strong security authentication, to quickly authenticate the identity of the sub-node to improve the overall access efficiency of the cluster.
[0050] Specifically, during simple authentication, the master node will perform a series of specific operations. First, the master node obtains the slave node identification codes and cluster attribute information of each slave node in the cluster. The slave node identification code is the unique identifier of each slave node in the cluster, similar to the ID card number of a device, used to accurately distinguish different slave nodes. For example, it can be a unique identifier generated by encoding the MAC address or device serial number of the slave node. The cluster attribute information is the relevant characteristics of the current slave node, including information such as the type, scale, business scope, and communication protocol of the node device. After that, based on this information, the master node uses a specific algorithm, such as combining a hash function and encryption technology, to generate indirect trust identifiers that match each slave node respectively. This indirect trust identifier is generated based on the strong security authentication trust foundation of the master node and represents the trust level of the master node in the slave node, which is used for subsequent authentication processes. Next, the master node sends each indirect trust identifier to the slave node that matches the indirect trust identifier to perform simple authentication on each slave node. After receiving the indirect trust identifier, the slave node will use it as one of the proofs of its own legitimacy. In actual application scenarios, such as in a smart home system, after slave nodes such as smart door locks and smart cameras receive the indirect trust identifier, they will compare and verify it with the relevant information stored in themselves. After confirmation, they can complete part of the simple authentication process. Finally, the master node will aggregate and store the slave node identification codes of each slave node to obtain a simple authentication table that matches the cluster access operation. Aggregate storage means storing the identification codes of each slave node centrally in a data structure. For example, a list or database table containing all slave node identification codes is constructed. This simple authentication table records the basic information of all slave nodes participating in this cluster access operation, similar to an authentication list. After being sent to the authentication platform, the authentication platform can, based on this list and combined with the strong security authentication results of the master node, comprehensively manage and monitor the access situation of the entire cluster. The authentication platform can confirm information such as the number and identity of slave nodes in the cluster based on the information in the simple authentication table, further ensuring the legitimacy and security of cluster access. Through the above series of operations, the master node completes the simple authentication of each slave node and generates a simple authentication table to send to the authentication platform, which not only ensures the security of cluster access but also improves the authentication efficiency, meeting the requirements of fast network formation and secure access of distributed clusters in an unstable communication environment.
[0051] S130. In response to the reception of the simple authentication table, the authentication platform completes the access operations for the master node and each slave node.
[0052] Specifically, in response to the receipt of the simple authentication form, the authentication platform completes the access operation for each sub-node, including: sending, by the sub-node, identity authentication information and an indirect trust identifier matching the sub-node to the authentication platform; after receiving the identity authentication information and the indirect trust identifier sent by the sub-node, the authentication platform parses the indirect trust identifier and determines whether the indirect trust identifier matches the simple authentication form according to the parsing result; if it matches, the authentication platform verifies the identity authentication information and allows the sub-node to access the authentication platform after the verification passes.
[0053] Wherein, the identity authentication information is a user name and a user password matching the sub-node.
[0054] Exemplarily, after receiving the identity authentication information and the indirect trust identifier sent by the sub-node, the authentication platform will parse the indirect trust identifier. The parsing is that the authentication platform extracts key information in the indirect trust identifier, such as the identity association information and trust level of the sub-node, through a preset algorithm and key. Then the authentication platform will determine whether the indirect trust identifier matches the simple authentication form according to the parsing result. For example, the authentication platform will check whether the sub-node identification code in the indirect trust identifier exists in the simple authentication form, and whether information such as the trust level conforms to the access policy of the cluster. If the indirect trust identifier matches the simple authentication form, the authentication platform will further verify the identity authentication information. The authentication platform will compare the identity authentication information of the sub-node with the legitimate device information stored in itself, or verify it by interacting with other relevant systems to ensure the authenticity and reliability of the identity of the sub-node. However, if the indirect trust identifier does not match the simple authentication form, the authentication platform will take a series of measures. The authentication platform will record this non-matching event, including the relevant information of the sub-node, the specific reason for the non-matching, etc., for subsequent security auditing and analysis. The authentication platform will reject the access request of the sub-node and send a notification of access failure to the sub-node and the master node. The notification content may include the specific reason for the non-matching, such as "the indirect trust identifier is inconsistent with the information in the simple authentication form", etc., to help the relevant parties troubleshoot problems. In some scenarios with high security requirements, the authentication platform may also trigger an alarm mechanism to notify the system administrator of potential security risks, so that the administrator can take timely measures, such as checking whether the authentication process of the master node has been tampered with, whether there is an abnormality in the sub-node, etc., to ensure the security and stability of the entire cluster.
[0055] In the technical solution of the embodiment of the present invention, in response to the cluster access operation of the user, the cluster and the authentication platform perform strong security authentication on the master node through the authentication platform. After the master node detects that the strong security authentication is passed, it performs simple authentication on each slave node, obtains a simple authentication table matching the cluster access operation, and sends it to the authentication platform. After that, in response to the reception of the simple authentication table, the authentication platform completes the access operations for the master node and each slave node, realizing the secure access of the cluster and improving the access efficiency of the nodes in the cluster.
[0056] Embodiment 2
[0057] Figure 2 As shown in the flowchart of a cluster security verification method provided by the second embodiment of the present invention, this embodiment is applicable to the situation of performing security verification on each node in a cluster connected to an authentication platform. This method can be executed by a cluster security verification device, which can be implemented in the form of hardware and / or software, and can be configured in an authentication platform with cluster security verification functions.
[0058] As Figure 2 shown, the method includes:
[0059] S210. In response to a strong message request from the master node, determine whether the strong message request includes a direct trust identifier and an identity authentication key that match the authentication platform, and determine whether the master node is within the trust validity period according to the strong message request, and perform security verification on the master node according to the judgment result.
[0060] S220. In response to a simple message request from a slave node, determine whether the master node passes the security verification, and after determining that the master node passes the security verification, perform security verification on the slave node according to a preset simple authentication table and the simple message request.
[0061] Wherein, the simple message request includes a slave node identification code and an indirect trust identifier that match the slave node.
[0062] Specifically, it is determined whether the master node passes the security verification, and after determining that the master node passes the security verification, the slave node is subjected to security verification according to a preset simple authentication table and the simple message request, including: obtaining the directly trusted identifier and the identity authentication key pre-stored in the master node, and verifying whether the directly trusted identifier and the identity authentication key conform to the preset trusted verification rules; after determining the preset trusted verification rules, obtaining the current time, and judging whether the master node is within the trust validity period according to the preset rules; after determining that the master node is within the trust validity period, judging that the master node passes the security authentication, and parsing the simple message request to obtain a slave node identification code and an indirect trust identifier matching the slave node; verifying the indirect trust identifier based on the preset rules, and verifying the slave node identification code based on the preset simple authentication table; when the indirect trust identifier verification passes and the slave node identification code verification passes, it is determined that the security verification of the slave node passes.
[0063] In a specific implementation scenario of this embodiment, for example, after the system receives a simple message request from a slave node, it first determines whether the master node passes the security verification. The system obtains the directly trusted identifier and the identity authentication key pre-stored in the master node, and verifies them according to the preset trusted verification rules. The preset rules are based on technologies such as encryption algorithms and hash functions. For example, it checks the format and hash value of the directly trusted identifier, and verifies the encryption algorithm and key length of the identity authentication key. If the hash value of the directly trusted identifier calculated using a specific hash algorithm is inconsistent with the pre-stored one, the verification fails. After verifying that the directly trusted identifier and the identity authentication key conform to the preset rules, the system obtains the current time and judges whether the master node is within the trust validity period according to the preset rules. Assuming that the preset trust validity period of the master node is 24 hours, the system compares the current time with the time when the master node passed the strong security authentication. If it exceeds 24 hours, the master node is not within the trust validity period. If the master node is within the trust validity period, that is, it passes the security authentication, the system further processes the simple message request of the slave node. The system parses the request to extract the slave node identification code and the indirect trust identifier. Then, it verifies the indirect trust identifier based on the preset rules, checks whether its format and generation algorithm are compliant and whether they are consistent with the generation rules of the master node; at the same time, it verifies the slave node identification code according to the preset simple authentication table to check whether the identification code is in the table. The simple authentication table is obtained by aggregating and storing the identification codes of each slave node after the master node completes the simple authentication of each slave node, and is an important basis for the system to verify the slave node. If the slave node identification code is not in the simple authentication table, it means that the slave node may not have passed the simple authentication of the master node, and the verification fails. Only when both the indirect trust identifier and the slave node identification code pass the verification, the system determines that the security verification of the slave node passes, and the slave node can access the system and communicate and cooperate with other devices.
[0064] Optionally, if the verification fails during the verification process, if the direct trust identifier or identity authentication key of the master node does not conform to the preset trusted verification rules, the system will reject the simple message request of the slave node, and record the error information at the same time, such as the error type, master node identifier, etc., which is convenient for subsequent security audits and troubleshooting. It may also send an alarm to the administrator, indicating that there is a problem with the master node's identity authentication and that strong security authentication needs to be performed again. If the master node is not within the trust validity period, the system will also reject the slave node request, notify the master node that the trust validity period has expired, and require it to perform strong security authentication again. Before the re-authentication is passed, the slave nodes it manages cannot access the system normally. In the slave node verification link, if the indirect trust identifier does not conform to the preset rules, the system determines that the slave node security verification fails, records the slave node information and rejects the access request. It may be that the master node makes a mistake in generating the indirect trust identifier, or it is tampered with during the transmission process. The system will require the master node to regenerate and re-authenticate the slave node. If the slave node identification code is not in the simple authentication table, the system believes that the slave node has not passed the legal simple authentication, rejects the access request, and notifies the master node to perform simple authentication on it and update the simple authentication table.
[0065] Optionally, during the operation of the cluster, when the master node is abnormal and the abnormality cannot be eliminated within the direct trust validity period, the direct trust level is reduced to indirect trust, that is, it is modified to a slave node, and other slave nodes can still perform business transfer according to the indirect trust first, ensuring the fault tolerance of the master node abnormality. The master node downgraded due to abnormality needs to be authenticated according to the simple authentication method of the slave node, and will not directly dissolve the cluster and require all nodes to re-authenticate. The platform side can also set other rules. For example, within the effective verification failure time of the direct trust, formulate the system initialization and page configuration failure handling rules: if the master node is abnormal and has not recovered for 5 minutes, and the platform side still does not receive the master node heartbeat within 5 minutes after discovery, then reject the requests of all indirectly trusted slave nodes in the cluster list and return the prompt information of "Please re-elect the master node"; if the page sets the direct trust time limit to 24 hours, the platform side counts the direct trust duration of the master node, and finds that it lasts for 24 hours, downgrade the trust level of the master node, invalidate the strong identity authentication session of the master node, and return the prompt information of "The cluster re-elects the master node" to the next request of all nodes in the cluster; if the indirect authentication slave node time limit is set to 2 hours, the platform side invalidates the indirect trust direct trust identifier in 2 hours, and requires the slave node to re-authenticate in the cluster to obtain a new direct trust identifier.
[0066] In the technical solution of the embodiment of the present invention, the authentication platform responds to the strong message request of the master node, determines whether the strong message request includes a direct trust identifier and an identity authentication key that match the authentication platform, determines whether the master node is within the trust validity period according to the strong message request, and performs security verification on the master node according to the judgment result. Finally, in response to the simple message request of the slave node, it determines whether the master node passes the security verification, and after determining that the master node passes the security verification, it performs security verification on the slave node according to the preset simple authentication table and the simple message request, realizing the security verification of each node in the cluster by the authentication platform and improving the security verification efficiency of the cluster.
[0067] Embodiment III
[0068] Figure 3 It is a schematic structural diagram of a cluster security access device provided in Embodiment III of the present invention. As Figure 3 shown, the device includes:
[0069] The master node authentication module 310 is configured to, in response to the cluster access operation of the user, perform strong security authentication on the master node through the authentication platform;
[0070] The slave node authentication module 320 is configured to, after the master node detects that the strong security authentication is passed, perform simple authentication on each slave node, obtain a simple authentication table that matches the cluster access operation, and send it to the authentication platform;
[0071] The access module 330 is configured to, in response to the reception of the simple authentication table by the authentication platform, complete the access operations for the master node and each slave node.
[0072] In the technical solution of the embodiment of the present invention, in response to the cluster access operation of the user, the cluster and the authentication platform perform strong security authentication on the master node through the authentication platform. After the master node detects that the strong security authentication is passed, it performs simple authentication on each slave node, obtains a simple authentication table that matches the cluster access operation, and sends it to the authentication platform. Then, in response to the reception of the simple authentication table, the authentication platform completes the access operations for the master node and each slave node, realizing the secure access of the cluster and improving the access efficiency of the nodes in the cluster.
[0073] On the basis of the above embodiment, the master node authentication module 310 includes:
[0074] The signature verification unit is configured to perform signature verification on the preset standard certificate in the master node through the authentication platform;
[0075] The key generation unit is configured to, after the authentication platform detects that the signature verification is passed, generate an identity authentication key that matches the master node using a preset key generation algorithm and send it to the master node;
[0076] A direct trust identifier generation unit, which is configured to, in response to receiving an identity authentication key, obtain a preset master node identification code and master node service attribute information through the master node, and generate a direct trust identifier that matches the master node according to the master node identification code and the master node service attribute information, and send the direct trust identifier to an authentication platform to complete strong security authentication for the node.
[0077] Based on the above embodiment, the secondary node authentication module 320 includes:
[0078] An indirect trust identifier generation unit, which is configured to obtain secondary node identification codes and cluster attribute information of each secondary node in the cluster through the master node, and generate indirect trust identifiers that match each secondary node according to the secondary node identification codes and the cluster attribute information respectively;
[0079] A simple authentication unit, which is configured to send each indirect trust identifier to a secondary node that matches the indirect trust identifier through the master node to perform simple authentication on each secondary node;
[0080] An aggregation unit, which is configured to aggregate and store the secondary node identification codes of each secondary node through the master node to obtain a simple authentication table that matches the cluster access operation.
[0081] Based on the above embodiment, the access module 330 includes:
[0082] An identifier sending unit, which is configured to send identity authentication information and an indirect trust identifier that match the secondary node to the authentication platform through the secondary node;
[0083] An identifier parsing unit, which is configured to, after the authentication platform receives the identity authentication information and the indirect trust identifier sent by the secondary node, parse the indirect trust identifier, and determine whether the indirect trust identifier matches the simple authentication table according to the parsing result;
[0084] A secondary node access unit, which is configured to, if they match, verify the identity authentication information through the authentication platform, and allow the secondary node to access the authentication platform after the verification passes.
[0085] A cluster security access device provided by an embodiment of the present invention can execute a cluster security access method provided by any embodiment of the present invention, and has corresponding functional modules and beneficial effects for executing the method.
[0086] Embodiment 4
[0087] Figure 4 It is a structural schematic diagram of a cluster security verification device provided by Embodiment 4 of the present invention. As Figure 4 shown, the device includes:
[0088] The total node verification module 410 is configured to, in response to a strong message request from the total node, determine whether the strong message request includes a direct trust identifier and an identity authentication key that match the authentication platform, and determine whether the total node is within the trust validity period according to the strong message request, and perform security verification on the total node according to the determination result;
[0089] The secondary node verification module 420 is configured to, in response to a simple message request from the secondary node, determine whether the total node passes security verification, and after determining that the total node passes security verification, perform security verification on the secondary node according to a preset simple authentication table and the simple message request; wherein, the simple message request includes a secondary node identification code and an indirect trust identifier that match the secondary node.
[0090] The technical solution of the embodiment of the present invention is that, by the authentication platform in response to the strong message request of the total node, it is determined whether the strong message request includes a direct trust identifier and an identity authentication key that match the authentication platform, and it is determined whether the total node is within the trust validity period according to the strong message request, and security verification is performed on the total node according to the determination result. Finally, in response to the simple message request of the secondary node, it is determined whether the total node passes security verification, and after determining that the total node passes security verification, security verification is performed on the secondary node according to a preset simple authentication table and the simple message request, realizing the security verification of each node in the cluster by the authentication platform and improving the security verification efficiency of the cluster.
[0091] Based on the above embodiment, the secondary node verification module 420 includes:
[0092] A rule verification unit, configured to obtain the direct trust identifier and the identity authentication key pre-stored in the total node, and verify whether the direct trust identifier and the identity authentication key conform to a preset trusted verification rule;
[0093] A validity period judgment unit, configured to, after judging the preset trusted verification rule, obtain the current time, and judge whether the total node is within the trust validity period according to a preset rule;
[0094] A message parsing unit, configured to, after judging that the total node is within the trust validity period, judge that the total node passes security authentication, and parse the simple message request to obtain a secondary node identification code and an indirect trust identifier that match the secondary node;
[0095] An identification code verification unit, configured to verify the indirect trust identifier based on a preset rule, and verify the secondary node identification code based on a preset simple authentication table;
[0096] The indirect trust passing unit is used to determine that the security verification of the secondary node passes when the indirect trust identifier verification passes and the secondary node identification code verification passes.
[0097] The cluster security verification device provided by an embodiment of the present invention can execute the cluster security verification method provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0098] Embodiment Five
[0099] Figure 5 The structural schematic diagram of the electronic device 10 that can be used to implement the embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0100] As Figure 5 shown, the electronic device 10 includes at least one processor 11, and a memory communicatively connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 11 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0101] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0102] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as a cluster security access method and a cluster security verification method.
[0103] Correspondingly, a cluster security access method includes:
[0104] In response to a user's cluster access operation, perform a strong security authentication on the master node through an authentication platform;
[0105] After the master node detects that the strong security authentication is passed, perform a simple authentication on each slave node, obtain a simple authentication table matching the cluster access operation, and send it to the authentication platform;
[0106] The authentication platform completes the access operations for the master node and each slave node in response to the receipt of the simple authentication table.
[0107] In some embodiments, a cluster security access method and a cluster security verification method can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as the storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the cluster security access method and the cluster security verification method described above can be executed. Alternatively, in other embodiments, the processor 11 can be configured to execute a cluster security access method and a cluster security verification method in any other suitable manner (e.g., by means of firmware).
[0108] The various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that receives data and instructions from, and transmits data and instructions to, a storage system, at least one input device, and at least one output device.
[0109] The computer programs for implementing the methods of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer programs, when executed by the processor, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The computer programs can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine or entirely on the remote machine or server.
[0110] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0111] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) through which the user can provide input to the electronic device. Other kinds of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, speech input, or tactile input).
[0112] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected to each other by digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0113] A computing system can include a client and a server. The client and the server are generally far from each other and typically interact through a communication network. The relationship between the client and the server is created by computer programs that run on the respective computers and have a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0114] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps recited in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is imposed herein.
Claims
1. A cluster security access method, executed by a cluster and an authentication platform, wherein the cluster includes a master node and at least one slave node, characterized in that: include: In response to the user's cluster access operation, the main node is strongly authenticated through the authentication platform; After the master node detects that the strong security authentication has passed, it performs a simple authentication on each slave node, obtains a simple authentication table that matches the cluster access operation, and sends it to the authentication platform; In response to receiving the simple authentication table, the authentication platform completes the access operation for the main node and each secondary node.
2. The method according to claim 1, characterized in that: In response to the user's cluster access operation, the authentication platform performs strong security authentication on the master node, including: Performing signature verification on the standard certificate preset in the master node through the authentication platform; After the authentication platform detects that the signature verification is passed, it uses a preset key generation algorithm to generate an identity authentication key that matches the master node and sends it to the master node; In response to receiving the identity authentication key, the preset main node identification code and the main node business attribute information are obtained through the main node, and a direct trust identifier matching the main node is generated based on the main node identification code and the main node business attribute information and sent to the authentication platform to complete the strong security authentication of the node.
3. The method according to claim 1, characterized in that After the main node detects that the strong security authentication has passed, it performs a simple authentication on each secondary node and obtains a simple authentication table that matches the cluster access operation, including: Obtaining the secondary node identification code and cluster attribute information of each secondary node in the cluster through the master node, and generating indirect trust identifiers matching each secondary node according to each secondary node identification code and cluster attribute information; Sending each indirect trust identifier to a secondary node matching the indirect trust identifier through the main node to perform simple authentication on each secondary node; The secondary node identification codes of the secondary nodes are aggregated and stored through the master node to obtain a simple authentication table matching the cluster access operation.
4. The method according to claim 1, characterized in that In response to receiving the simple authentication form, the authentication platform completes the access operation for each secondary node, including: Sending identity authentication information and an indirect trust identifier matching the secondary node to the authentication platform through the secondary node; After receiving the identity authentication information and the indirect trust identifier sent by the secondary node, the authentication platform parses the indirect trust identifier and determines whether the indirect trust identifier matches the simple authentication table according to the parsing result; If they match, the identity authentication information is verified through the authentication platform, and the secondary node is allowed to access the authentication platform after the verification is passed.
5. A cluster security verification method, executed by an authentication platform, characterized in that: include: In response to a strong message request from the master node, determine whether the strong message request includes a direct trust identifier and an identity authentication key that match the authentication platform, determine whether the master node is within the trust validity period according to the strong message request, and perform security verification on the master node according to the determination result; In response to a simple message request from a secondary node, determine whether the main node has passed the security verification, and after determining that the main node has passed the security verification, perform security verification on the secondary node according to a preset simple authentication table and the simple message request; wherein the simple message request includes a secondary node identification code and an indirect trust identifier that matches the secondary node.
6. The method according to claim 5, characterized in that Determining whether the main node passes the security verification, and after determining that the main node passes the security verification, performing security verification on the secondary node according to a preset simple authentication table and the simple message request, including: Obtaining the direct trust identifier and identity authentication key pre-stored in the master node, and verifying whether the direct trust identifier and identity authentication key comply with preset trusted verification rules; After determining the preset trust verification rules, obtaining the current time, and determining whether the master node is within the trust validity period according to the preset rules; After determining that the master node is within the trust validity period, determining that the master node has passed the security authentication, and parsing the simple message request to obtain a secondary node identification code and an indirect trust identifier that match the secondary node; Verifying the indirect trust identifier based on preset rules, and verifying the secondary node identification code based on a preset simple authentication table; When the indirect trust mark verification is passed, and the secondary node identification code verification is passed, it is determined that the security verification of the secondary node is passed.
7. A cluster security access device, executed by a security access system configured with a master node, at least one slave node and an authentication platform, characterized in that: include: The master node authentication module is used to respond to the user's cluster access operation and perform strong security authentication on the master node through the authentication platform; A secondary node authentication module, which is used for performing simple authentication on each secondary node after the main node detects that the strong security authentication has passed, obtaining a simple authentication table matching the cluster access operation, and sending it to the authentication platform; The access module is used for the authentication platform to respond to the receipt of the simple authentication table and complete the access operation for the main node and each secondary node.
8. A cluster security verification device, executed by a security authentication system, characterized in that: include: A total node verification module, used to respond to a strong message request from the total node, determine whether the strong message request includes a direct trust identifier and an identity authentication key that match the authentication platform, and determine whether the total node is within the trust validity period according to the strong message request, and perform security verification on the total node according to the judgment result; A secondary node verification module is used to respond to a simple message request from a secondary node, determine whether the main node has passed the security verification, and after determining that the main node has passed the security verification, perform security verification on the secondary node according to a preset simple authentication table and the simple message request; wherein the simple message request includes a secondary node identification code and an indirect trust identifier that matches the secondary node.
9. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute a cluster security access method and a cluster security verification method as described in any one of claims 1-6.
10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement a cluster security access method and a cluster security verification method according to any one of claims 1 to 6 when executed.