Method and device for processing digital certificate
Through the certificate control node, the application and distribution of digital certificates is uniformly managed, the problem of wasting certificate resources and network resources in the cloud computing environment is solved, and the efficient utilization of resources is achieved.
Patent Information
- Application Number
- CN202311844205.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-07-01
AI Technical Summary
In the cloud computing environment, the service nodes of the service provider apply for digital certificates from the CA certification center have problems such as wasting certificate resources and waste of network resources.
Introduce certificate control nodes, send application requests to the certificate issuing center in a unified manner, receive and distribute digital certificates to the service nodes, and avoid the service nodes directly applying to the certificate issuing center.
Through the unified management of certificate control nodes, the number of applications to the certificate issuance center is reduced, and certificate resources and network resources are saved.
Smart Images

Figure CN120238309A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing technology, and in particular, to a method and apparatus for processing digital certificates. Background Art
[0002] In recent years, with the popularization of cloud computing and virtual technologies, many excellent cloud computing application service platforms have emerged. These platforms aggregate a large number of physical hardware resources and use virtualization technology to abstract the hardware resources of physical hardware devices, realizing the unified allocation, scheduling, and management of heterogeneous network computing resources, thereby achieving the purpose of fully utilizing software and hardware resources and improving utilization efficiency.
[0003] In the cloud computing environment, the security authentication problem of cloud services has received increasing attention. Traditional security authentication solutions are mostly based on digital certificate-based schemes to achieve security authentication through digital certificates, ensuring the confidentiality, integrity, and non-repudiation of data.
[0004] Among them, the CA (Certificate Authority) authentication center, as an authoritative and trusted third party, is an important part of the public key infrastructure, mainly responsible for the full life cycle management of digital certificates such as application, review, issuance, and cancellation.
[0005] In the cloud environment, the service nodes of the service provider can apply for digital certificates from the CA authentication center, and the CA authentication center can issue digital certificates to the service nodes to achieve security authentication through digital certificates.
[0006] However, the method of "the service nodes of service providers apply for digital certificates from the CA authentication center, and the CA authentication center issues digital certificates to the service nodes" has problems such as waste of certificate resources and waste of network resources. Summary of the Invention
[0007] This application discloses a method and apparatus for processing digital certificates.
[0008] In a first aspect, this application discloses a method for processing digital certificates, which is applied to a certificate control node. The method includes: sending an application request to a certificate issuing center, where the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit a service node to provide data services; receiving the first digital certificate returned by the certificate issuing center according to the application request; and distributing the first digital certificate to the service node.
[0009] Second aspect, the present application discloses a method for processing digital certificates, which is applied to a service node. The method includes: receiving a first digital certificate distributed by a certificate management and control node, where the first digital certificate is returned by a certificate authority to the certificate management and control node after the certificate management and control node sends an application request to the certificate authority, and the application request is used to apply for the first digital certificate, and the first digital certificate is used to authorize or permit the service node to provide data services; deploying the first digital certificate in the service node.
[0010] Third aspect, the present application discloses a device for processing digital certificates, which is applied to a certificate management and control node. The device includes: a first sending module, configured to send an application request to a certificate authority, where the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit a service node to provide data services; a first receiving module, configured to receive the first digital certificate returned by the certificate authority according to the application request; a first distributing module, configured to distribute the first digital certificate to the service node.
[0011] Fourth aspect, the present application discloses a device for processing digital certificates, which is applied to a service node. The device includes: a third receiving module, configured to receive a first digital certificate distributed by a certificate management and control node, where the first digital certificate is returned by a certificate authority to the certificate management and control node after the certificate management and control node sends an application request to the certificate authority, and the application request is used to apply for the first digital certificate, and the first digital certificate is used to authorize or permit the service node to provide data services; a first deployment module, configured to deploy the first digital certificate in the service node.
[0012] Fifth aspect, the present application discloses an electronic device, which includes: a processor; a memory for storing instructions executable by the processor; wherein, the processor is configured to execute the method shown in any of the foregoing aspects.
[0013] Sixth aspect, the present application discloses a non-transitory computer-readable storage medium, when the instructions in the storage medium are executed by a processor of an electronic device, enabling the electronic device to execute the method shown in any of the foregoing aspects.
[0014] Seventh aspect, the present application discloses a computer program product, when the instructions in the computer program product are executed by a processor of an electronic device, enabling the electronic device to execute the method shown in any of the foregoing aspects.
[0015] Compared with the prior art, the present application has the following advantages:
[0016] In this application, the certificate control node can send an application request to the certificate issuing center. The application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit the service node to provide data services. Then, it receives the first digital certificate returned by the certificate issuing center according to the application request and distributes the first digital certificate to the service node. The service node can receive the first digital certificate distributed by the certificate control node and deploy the first digital certificate in the service node to provide data services based on the first digital certificate.
[0017] Through this application, the certificate control node can achieve unified application, unified control, and unified distribution of digital certificates. For example, the service node does not apply to the certificate issuing center for the digital certificate used to authorize or permit the service node to provide data services. Instead, the certificate control node uniformly applies to the certificate issuing center for the digital certificate and can distribute the applied digital certificate to the service node, so that the service node can provide data services based on the digital certificate distributed by the certificate control node.
[0018] In one example, when there are multiple service nodes, each service node among the multiple service nodes does not separately apply to the certificate issuing center for the digital certificate used to authorize or permit the service node to provide data services. Instead, the certificate control node uniformly applies to the certificate issuing center for the digital certificate and can distribute the applied digital certificate to each service node among the multiple service nodes, so that each service node among the multiple service nodes can respectively provide data services based on the digital certificate distributed by the certificate control node.
[0019] Secondly, in this application, when there are multiple service nodes, the digital certificate uniformly applied by the certificate control node to the certificate issuing center can be reused among the multiple service nodes. In this way, each service node among the multiple service nodes does not need to separately apply to the certificate issuing center for a digital certificate, which can reduce the number of digital certificates applied to the certificate issuing center and save certificate resources.
[0020] In addition, through this application, when there are multiple service nodes, the certificate issuing center can only dock with the certificate control node and does not need to separately dock with each service node among the multiple service nodes. In this way, the certificate issuing center only needs to issue digital certificates to the certificate control node and does not need to separately issue digital certificates to each service node among the multiple service nodes, thereby saving the network resources of the certificate issuing center. Brief Description of the Drawings
[0021] Figure 1 is a structural block diagram of a system for processing digital certificates according to this application.
[0022] Figure 2 is a step flowchart of a method for processing digital certificates according to this application.
[0023] Figure 3 It is a structural block diagram of a device for processing digital certificates in this application.
[0024] Figure 4 It is a structural block diagram of a device for processing digital certificates in this application.
[0025] Figure 5 It is a structural block diagram of a device in this application. Specific implementation manners
[0026] To make the above objects, features, and advantages of this application more obvious and understandable, the following further details this application in conjunction with the accompanying drawings and specific implementation manners.
[0027] In one way, each service node in the service cluster of the service provider applies for a digital certificate to the certificate authority respectively, and the certificate authority issues digital certificates to each service node respectively. That is, the number of digital certificates that the certificate authority needs to issue for the service cluster of the service provider is the same as the number of service nodes in the service cluster of the service provider.
[0028] It can be seen that, on the one hand, when the number of digital certificates issued by the certificate authority for the service cluster of the service provider is large, a lot of certificate resources will be consumed.
[0029] On the other hand, the process of the certificate authority issuing digital certificates to each service node in the service cluster of the service provider will consume a lot of network resources of the certificate authority.
[0030] Therefore, in order to save certificate resources and the network resources of the certificate authority, this application is proposed. See Figure 1 , which shows a system for processing digital certificates in this application. The system includes: a certificate control node, a service cluster, and a certificate authority.
[0031] The certificate control node and the certificate authority can be docked (such as communication connection, etc.), and data interaction can be carried out between the certificate control node and the certificate authority.
[0032] The certificate authority can include a CA authentication center, etc.
[0033] The certificate control node and the service cluster can be docked (such as communication connection, etc.), and data interaction can be carried out between the certificate control node and the service cluster.
[0034] The service cluster can include one service node or multiple service nodes. Multiple service nodes are all at least used to provide data services (the data services can include multiple types of data services, such as video type data services, music type data services, or instant messaging type data services, etc.).
[0035] In one embodiment, multiple service nodes in the service cluster can be docked with the certificate control node respectively.
[0036] Secondly, in another embodiment, any two service nodes among the multiple service nodes in the service cluster can be docked, and data interaction can be performed between any two service nodes among the multiple service nodes in the service cluster.
[0037] In this application, the service nodes in the service cluster can include cloud-based service nodes (such as service nodes in a cloud computing scenario), for example, virtual machines, etc. The virtual machines can include ECS (Elastic Compute Service, cloud server), etc., and the service nodes can also include off-cloud service nodes, etc.
[0038] The service providers to which the respective service nodes in the service cluster belong can be the same.
[0039] Alternatively, the service providers to which the respective service nodes in the service cluster belong can be not all the same or all different. For example, the service providers to which a part of the service nodes in the service cluster belong are different from those to which another part of the service nodes belong. The service provider to which a service node belongs can be the manufacturer that rents the service node, and the manufacturer that rents the service node can use the service node to provide the services involved by the manufacturer that rents the service node externally.
[0040] In one embodiment, the data services that the service node can provide include: CDN (Content Delivery Network) service, SLB (Server Load Balancing) service, and WAF (Web Application Firewall) service, etc. Of course, it can be understood that other types of services can also be included, which will not be elaborated one by one here.
[0041] For the off-cloud service node, an auxiliary script can be installed on the off-cloud service node. The auxiliary script can include Agent scripts, etc. The auxiliary script can have multiple functions, such as heartbeat reporting function, certificate update function, node restart function, certificate backup function, path scanning function, file verification function, and service detection function, etc.
[0042] The heartbeat reporting function is used to regularly report the heartbeat information of the service node where the auxiliary script is located to the certificate control node.
[0043] The certificate update function is used to request the certificate control node to update the digital certificate deployed on the service node where the auxiliary script is located, receive the digital certificate distributed by the certificate control node, and deploy the digital certificate on the service node, etc.
[0044] The node restart function is used to control the restart of the service node where the auxiliary script is located after the digital certificate is deployed on the service node where the auxiliary script is located.
[0045] The certificate backup function is used to back up the digital certificate deployed on the service node where the auxiliary script is located for subsequent traceability.
[0046] The path scanning function is used to scan the path / position of the digital certificate deployed on the service node where the auxiliary script is located on the service node where the auxiliary script is located.
[0047] The file verification function is used to respond to the verification of the identity of the service node by the certificate issuing center in the case where the certificate control node applies for a digital certificate from the certificate issuing center for the service node in the service cluster.
[0048] The service detection function is used to detect whether the service node where the auxiliary script is located has provided data services within a period of time. For example, whether it has received data requests sent from the outside (for example, the service node provides data services based on data requests), and report the detection situation to the certificate control node.
[0049] In addition, the certificate control node can have multiple functions. For example, the certificate management function, the certificate application function, the monitoring service function, the DNS (Domain Name System) management function, the alarm service function, the certificate distribution function, the node management function, the deployment detection function, the multi-vendor cloud product management function, and the cloud data resource management function, etc.
[0050] The certificate management function is used to manage the digital certificate applied from the certificate issuing center. For example, it is used to store / backup the digital certificate applied from the certificate issuing center, etc.
[0051] The certificate application function is used to apply for a digital certificate from the certificate issuing center.
[0052] The monitoring service function is used to receive the detection situation reported by the service node. The detection situation includes whether the service node has provided data services within a period of time. For example, whether it has received data requests sent from the outside (for example, the service node provides data services based on data requests).
[0053] The DNS management function is used to set the DNS information of the service nodes in the service cluster, etc.
[0054] An alarm service function for outputting alarm information when a digital certificate is about to expire or has expired.
[0055] A certificate distribution function for distributing the applied digital certificate to the service nodes in the service cluster.
[0056] A node management function for managing the service nodes in the service cluster and for docking with the service nodes in the service cluster.
[0057] A deployment detection function for detecting whether the digital certificate distributed to the service node is effective or successfully deployed in the service node.
[0058] A multi-vendor cloud product management function for docking with and managing the cloud products of multiple service vendors.
[0059] A cloud data resource management function for managing the cloud data resources in the service node.
[0060] See Figure 2 , which shows a method for processing digital certificates according to the present application. This method can be applied to Figure 1 the system for processing digital certificates shown. Among them, the method may include:
[0061] In step S101, the certificate control node sends an application request to the certificate authority. The application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit the service node to provide data services.
[0062] Among them, the service nodes in the service cluster can provide data services based on the first digital certificate. For example, they can provide data services of the types mentioned above.
[0063] In one embodiment, multiple service nodes in the service cluster can respectively provide data services. For example, they can respectively provide data services of the types mentioned above, and the types of data services that each service node can provide can be the same, etc.
[0064] For any one type of data service that multiple service nodes can respectively provide, the multiple service nodes need to have a digital certificate for authorizing or permitting the service node to provide this type of data service. In this way, they can provide this type of data service based on the digital certificate for authorizing or permitting the service node to provide this type of data service. The same applies to each of the other types of data services that multiple service nodes can respectively provide.
[0065] The present application takes the example that multiple service nodes in the service cluster can respectively provide one of the multiple types of data services, but it does not limit the protection scope of the present application.
[0066] If a service node in the service cluster needs to provide this type of data service, the service node in the service cluster needs to have a digital certificate for authorizing or licensing the service node to provide this type of data service. In this way, this type of data service can be provided based on the digital certificate for authorizing or licensing the service node to provide this type of data service.
[0067] In this application, the certificate control node uniformly schedules digital certificates for service nodes in the service cluster. In this way, the certificate control node can send an application request to the certificate issuing center to obtain a first digital certificate for authorizing or licensing service nodes to provide data services from the certificate issuing center.
[0068] In step S102, the certificate control node receives the first digital certificate returned by the certificate issuing center according to the application request.
[0069] In step S103, the certificate control node distributes the first digital certificate to the service nodes in the service cluster.
[0070] For example, after the certificate control node applies to the certificate issuing center for a first digital certificate for authorizing or licensing service nodes to provide data services, the first digital certificate can be distributed to the service nodes in the service cluster, so that the service nodes in the service cluster can deploy the first digital certificate, and then the service nodes in the service cluster can provide data services with the first digital certificate.
[0071] For the service nodes in the service cluster, the following processes of S104 - S105 can be executed:
[0072] In step S104, receive the first digital certificate distributed by the certificate control node.
[0073] In step S105, deploy the first digital certificate in the service node.
[0074] To provide data services based on the first digital certificate.
[0075] In this application, the certificate control node can send an application request to the certificate issuing center. The application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or license service nodes to provide data services. Then, receive the first digital certificate returned by the certificate issuing center according to the application request, and distribute the first digital certificate to the service nodes. The service node can receive the first digital certificate distributed by the certificate control node and deploy the first digital certificate in the service node to provide data services based on the first digital certificate.
[0076] Through this application, the certificate control node can achieve unified application, unified control, and unified distribution of digital certificates. For example, the service node does not apply to the certificate authority for the digital certificate used to authorize or permit the service node to provide data services. Instead, the certificate control node uniformly applies to the certificate authority for the digital certificate and can distribute the applied digital certificate to the service node, so that the service node can provide data services based on the digital certificate distributed by the certificate control node.
[0077] In one example, when there are multiple service nodes, each service node among the multiple service nodes does not separately apply to the certificate authority for the digital certificate used to authorize or permit the service node to provide data services. Instead, the certificate control node uniformly applies to the certificate authority for the digital certificate and can distribute the applied digital certificate to each service node among the multiple service nodes, so that each service node among the multiple service nodes can respectively provide data services based on the digital certificate distributed by the certificate control node.
[0078] Secondly, in this application, when there are multiple service nodes, the digital certificates uniformly applied by the certificate control node to the certificate authority can be reused among the multiple service nodes. In this way, each service node among the multiple service nodes does not need to separately apply to the certificate authority for digital certificates, which can reduce the number of digital certificates applied to the certificate authority and save certificate resources.
[0079] In addition, through this application, when there are multiple service nodes, the certificate authority can only interface with the certificate control node and does not need to separately interface with each service node among the multiple service nodes. In this way, the certificate authority only needs to issue digital certificates to the certificate control node and does not need to separately issue digital certificates to each service node among the multiple service nodes, thus saving the network resources of the certificate authority.
[0080] In an embodiment of this application, the service nodes in the service cluster can regularly send heartbeat messages to the certificate control node.
[0081] Correspondingly, after the certificate control node receives the heartbeat message sent by a service node, it can determine that this service node is running (not down).
[0082] Alternatively, in the case where the certificate control node does not receive the heartbeat message sent by a certain service node for a long time, it can be defaulted that this certain service node is not running (has gone down).
[0083] Service nodes that are not running (down) often do not have the ability to provide data services. Thus, when the certificate control node distributes digital certificates later, it can refrain from distributing digital certificates to service nodes that are not running (down), so as to save the network resources involved in the scenario of distributing digital certificates (for example, saving the network resources within the system for processing digital certificates, etc.).
[0084] Thus, before the certificate control node distributes the first digital certificate to the service nodes in the service cluster, for any service node in the service cluster, the certificate control node can determine whether it has received the heartbeat information sent by the service node within the first preset duration before the current moment.
[0085] Among them, in the case where the certificate control node receives the heartbeat information sent by the service node for the first time, the certificate control node can record the reception moment when the certificate control node receives the heartbeat information sent by the service node in the certificate control node. Later, in the case where the certificate control node receives the heartbeat information sent by the service node for the Nth time, N is greater than or equal to 2, the certificate control node can use the reception moment when the certificate control node receives the heartbeat information sent by the service node for the Nth time to replace the previously recorded reception moment when the certificate control node received the heartbeat information sent by the service node.
[0086] Thus, when determining whether the certificate control node has received the heartbeat information sent by the service node within the first preset duration before the current moment, the duration between the current moment of the certificate control node and the recorded reception moment in the certificate control node can be calculated. In the case where this duration is less than or equal to the first preset duration, it can be determined that the certificate control node has received the heartbeat information sent by the service node within the first preset duration before the current moment. Or, in the case where this duration is greater than the first preset duration, it can be determined that the certificate control node has not received the heartbeat information sent by the service node within the first preset duration before the current moment.
[0087] In the case where the certificate control node has received the heartbeat information sent by the service node within the first preset duration before the current moment, it indicates that the service node is running, and the first digital certificate can be distributed to the service node again.
[0088] Or, in the case where the certificate control node has not received the heartbeat information sent by the service node within the first preset duration before the current moment, it indicates that the service node is not running, and the first digital certificate can refrain from being distributed to the service node.
[0089] The current moment can be the current moment of the certificate control node.
[0090] The first preset duration can include 1 s (second), 2 s, 3 s, or 4 s, etc., and can be determined according to the actual situation specifically. This application does not limit this.
[0091] In another embodiment of the present application, after the first digital certificate is deployed in the service node, the service node may send first deployment information to the certificate control node, and the first deployment information is used to indicate that the first digital certificate has been deployed in the service node. Correspondingly, the certificate control node may receive the first deployment information, and according to the first deployment information, it can be known that the first digital certificate has been deployed in the service node.
[0092] However, in another case, the service node does not send the first deployment information to the certificate control node. Correspondingly, the certificate control node does not receive the first deployment information sent by the service node.
[0093] Among them, "the service node does not send the first deployment information to the certificate control node" may be because: the service node does not receive the digital certificate distributed by the certificate control node, or it may also be because: the service node receives the digital certificate distributed by the certificate control node but the service node fails to successfully deploy the first digital certificate in the service node, etc.
[0094] Therefore, within a second preset duration after the certificate control node distributes the first digital certificate to the service node, the certificate control node may detect whether it receives the first deployment information sent by the service node.
[0095] If the certificate control node does not receive the first deployment information sent by the service node within the second preset duration after the certificate control node distributes the first digital certificate to the service node, the certificate control node may distribute the first digital certificate to the service node again.
[0096] On the one hand, it can make the service node obtain the first digital certificate as much as possible, and on the other hand, it can make the service node try to deploy the first digital certificate in the service node again to increase the possibility of successfully deploying the first digital certificate in the service node.
[0097] Or, if the certificate control node receives the first deployment information sent by the service node within the second preset duration after distributing the first digital certificate to the service node, the certificate control node may no longer distribute the first digital certificate to the service node.
[0098] The second preset duration may include 1 s (second), 2 s, 3 s, or 4 s, etc., and may be specifically determined according to the actual situation, and the present application does not limit this.
[0099] In addition, in another embodiment of the present application, if no first deployment information sent by the service node is received within a second preset duration after the first digital certificate is distributed to the service node multiple times, it often indicates that the service node is abnormal (although the service node may be running and not down, but there is an abnormality in the service node's reception of digital certificates, or the service node can receive digital certificates, but there is an abnormality in the deployment of digital certificates). In this case, a first warning message can be output, and the first warning message is used to prompt that the first digital certificate cannot be deployed in the service node.
[0100] In one embodiment, the first warning message can be output to relevant staff so that the staff can intervene as soon as possible to eliminate the abnormality of the service node as soon as possible, so as to enable the first digital certificate to be successfully deployed in the service node as soon as possible, and then enable the service node to provide data services as soon as possible.
[0101] The same applies to each of the other service nodes in the service cluster.
[0102] In the present application, digital certificates usually have a validity period. When the digital certificate deployed in the service node has not expired, the service node can provide data services based on the unexpired digital certificate. However, when the digital certificate deployed in the service node has expired, the service node cannot provide data services based on the expired digital certificate.
[0103] Thus, in order to avoid the interruption of data services provided by the service node as much as possible or shorten the duration of interruption of data services provided by the service node as much as possible, in another embodiment of the present application, the certificate control node can detect whether the remaining valid duration of the first digital certificate is less than a third preset duration.
[0104] When the remaining valid duration of the first digital certificate is less than the third preset duration, the certificate control node can output a second warning message. The second warning message is used to prompt that the first digital certificate is about to expire or has expired.
[0105] In one embodiment, the second warning message can be output to relevant staff so that the staff can intervene as soon as possible to renew the first digital certificate as soon as possible, so as to improve the continuity of data services provided by the service node.
[0106] The third preset duration can include 10 s (seconds), 12 s, 15 s, 18 s, etc., and can be determined according to actual situations specifically. The present application does not limit this.
[0107] Furthermore, in order to improve the automation level, reduce the labor cost, and improve the efficiency of renewing the first digital certificate, in another embodiment of the present application, when the remaining valid duration of the first digital certificate is less than the third preset duration, the certificate control node may send a renewal request for the first digital certificate to the certificate authority.
[0108] The certificate authority may receive the renewal request, and then issue a second digital certificate to the certificate control node according to the renewal request. The second digital certificate is used to authorize or permit the service node to provide data services. The expiration deadline of the second digital certificate is later than the expiration deadline of the first digital certificate.
[0109] After that, the certificate control node may receive the second digital certificate returned by the certificate authority according to the renewal request, and distribute the second digital certificate to the service nodes in the service cluster.
[0110] Then, the service nodes in the service cluster may receive the second digital certificate distributed by the certificate control node, and deploy the second digital certificate in the service nodes in the service cluster. For example, the second digital certificate may be used to replace the deployed first digital certificate in the service nodes in the service cluster to provide data services based on the second digital certificate.
[0111] The second digital certificate can be regarded as the digital certificate obtained after renewing the first digital certificate.
[0112] For example, the second digital certificate may be a certificate different from the first digital certificate. The common point of the two is that both are used to authorize or permit the service node to provide data services. However, the expiration deadline of the second digital certificate is later than the expiration deadline of the first digital certificate. That is, starting from the current moment, the validity period of the second digital certificate is longer. After that, the service node may provide data services based on the second digital certificate, and may no longer provide data services based on the first digital certificate, achieving the purpose of renewing the first digital certificate.
[0113] In another embodiment of the present application, the sharing of digital certificates between service nodes is illustrated by taking the first service node and the second service node as examples, but it does not limit the protection scope of the present application. The first service node is one of the multiple service nodes in the service cluster, and the second service node is one of the multiple service nodes in the service cluster. The first service node is different from the second service node.
[0114] Generally, the certificate control node distributes digital certificates to the service nodes in the service cluster at the same time. Therefore, generally, if the service nodes in the service cluster can receive the digital certificates distributed by the certificate control node, they often receive the digital certificates distributed by the certificate control node at the same time.
[0115] However, sometimes the following situation occurs: within a period of time after some service nodes receive the digital certificates distributed by the certificate control node, other service nodes have not received the digital certificates distributed by the certificate control node.
[0116] If the above situation occurs, sometimes it may be due to a temporary communication failure between other service nodes and the certificate control node. For example, the delay suddenly increases. For example, the amount of data exchanged between other service nodes and the certificate control node surges at this time, resulting in very little idle network resources between other service nodes and the certificate control node at this time, affecting the transmission of digital certificates, and further causing other service nodes to not receive the digital certificates distributed by the certificate control node, and often may not be able to receive the digital certificates distributed by the certificate control node for a period of time.
[0117] In view of this, based on the above situation, in the case where some service nodes have received the digital certificates distributed by the certificate control node while other service nodes have not received the digital certificates distributed by the certificate control node within a period of time, in order to enable other service nodes to obtain the digital certificates distributed by the certificate control node as soon as possible, and further enable other service nodes to provide data services based on the digital certificates as soon as possible, in another embodiment of the present application, other service nodes can obtain the digital certificates distributed by the certificate control node via these some service nodes.
[0118] For example, after deploying the first digital certificate in the first service node, the first service node can broadcast the first deployment information in the service cluster, and the first deployment information is used to indicate that the first digital certificate has been deployed in the first service node.
[0119] Other service nodes in the service cluster except the first service node can receive the first deployment information broadcast by the first service node. For example, the second service node can receive the first deployment information broadcast by the first service node.
[0120] After that, the second service node can learn from the first deployment information that the first digital certificate has been deployed in the first service node.
[0121] Since both the second service node and the first service node are service nodes in the service cluster and can both provide data services, thus, the second service node will think that the second service node should also have the first digital certificate according to the first deployment information. For example, the second service node should receive the first digital certificate distributed by the certificate control node, otherwise it will affect the second service node to provide data services.
[0122] For this purpose, in this embodiment, within a fourth preset duration after the second service node receives the first deployment information broadcast by the first service node, the second service node may detect whether it receives the first digital certificate distributed by the certificate control node.
[0123] In one example, within the fourth preset duration after the second service node receives the first deployment information, if the second service node receives the first digital certificate distributed by the certificate control node, the second service node may deploy the first digital certificate in the second service node to provide data services based on the first digital certificate.
[0124] Alternatively, in another example, within the fourth preset duration after the second service node receives the first deployment information, if the second service node does not receive the first digital certificate distributed by the certificate control node, it indicates that the second service node may not be able to receive the first digital certificate distributed by the certificate control node in a short period of time. However, in order to enable the second service node to obtain the first digital certificate as soon as possible and then be able to provide data services based on the first digital certificate, the second service node may send a first acquisition request to the first service node. The first acquisition request is used to acquire the first digital certificate.
[0125] The first service node may receive the first acquisition request sent by the second service node. The second service node is one of the multiple service nodes in the service cluster, and the second service node is different from the first service node. Then the first service node may distribute the first digital certificate to the second service node according to the first acquisition request.
[0126] In this way, the second service node may receive the first digital certificate returned by the first service node according to the first acquisition request. Then the second service node may deploy the first digital certificate in the second service node to provide data services based on the first digital certificate.
[0127] The fourth preset duration may include 0.5 s (seconds), 1 s, 1.5 s, 2 s, 2.5 s, etc., and may be specifically determined according to the actual situation. The present application does not limit this.
[0128] Through the present application, in the case that the second service node has not received the first digital certificate distributed by the certificate control node for a period of time after the first service node receives the first digital certificate distributed by the certificate control node, the second service node may obtain the first digital certificate distributed by the certificate control node via the first service node, so that the second service node can obtain the first digital certificate distributed by the certificate control node as soon as possible, and further enable the second service node to provide data services based on the first digital certificate as soon as possible.
[0129] In this application, usually, the digital certificates of service nodes in a service cluster are directly distributed by a certificate control node, and the certificate control node can achieve direct control over the digital certificates of service nodes in the service cluster.
[0130] There are many service nodes in the service cluster. Sometimes, some service nodes in the service cluster are qualified to provide data services, while some other service nodes in the service cluster may temporarily not be qualified to provide data services due to some reasons (but may regain the qualification to provide data services later).
[0131] In the case where a certain service node is not qualified to provide data services at this time, this certain service node should not obtain a digital certificate.
[0132] The certificate control node can accurately know which service nodes in the service cluster are qualified to provide data services at any given time.
[0133] In the scenario where the certificate control node distributes data certificates to service nodes in the service cluster, the certificate control node can distribute digital certificates to service nodes in the service cluster that are qualified to provide data services at this time, and not distribute digital certificates to service nodes in the service cluster that are not qualified to provide data services at this time, so as to prevent service nodes that are not qualified to provide data services at this time from obtaining digital certificates for authorizing or permitting service nodes to provide data services. For example, to prevent illegal nodes from obtaining digital certificates to engage in illegal activities in the case where service nodes that are not qualified to provide data services at this time are invaded, thereby ensuring the data security of the service cluster.
[0134] Thus, in another embodiment of this application, in the scenario where a first service node distributes a first digital certificate to a second service node according to a first acquisition request, the first service node can request the certificate control node whether it can share the first digital certificate with the second service node. For example, the first service node can send a first sharing request to the certificate control node according to the first acquisition request, and the first sharing request is used to request sharing the first digital certificate with the second service node.
[0135] The certificate control node receives the first sharing request sent by the first service node according to the first acquisition request, and then the certificate control node can decide whether to allow the first service node to share the first digital certificate with the second service node according to the first acquisition request.
[0136] For example, the certificate control node can determine whether the second service node simultaneously meets the following conditions: the second service node is located in the service cluster, the second service node has the objective ability to provide data services, the second service node has the service qualification to provide data services, and the second service node has not been invaded, etc.
[0137] When the second service node simultaneously meets the above conditions, the first service node is allowed to share the first digital certificate with the second service node; or, when the second service node does not simultaneously meet the above conditions, the first service node is not allowed to share the first digital certificate with the second service node.
[0138] Among them, when the certificate control node allows the first service node to share the first digital certificate with the second service node, the certificate control node may send a first sharing response to the first service node according to the first sharing request. The first sharing response is used to indicate that sharing the first digital certificate with the second service node is allowed. After that, the first service node receives the first sharing response returned by the certificate control node according to the first sharing request, and distributes the first digital certificate to the second service node according to the first sharing response.
[0139] Or, when the certificate control node does not allow the first service node to share the first digital certificate with the second service node, the certificate control node may send a first rejection response to the first service node according to the first sharing request. The first rejection response is used to indicate that sharing the first digital certificate with the second service node is not allowed. After that, the first service node may receive the first rejection response returned by the certificate control node according to the first sharing request, and then does not distribute the first digital certificate to the second service node.
[0140] In another embodiment of the present application, after the first digital certificate is deployed in the second service node, the second service node may send second deployment information to the first service node. The second deployment information is used to indicate that the first digital certificate has been deployed in the second service node, so that the first service node sends the second deployment information to the certificate control node.
[0141] After that, the first service node may receive the second deployment information sent by the second service node, and then may send the second deployment information to the certificate control node.
[0142] After that, the certificate control node may receive the second deployment information sent by the first service node, and then may determine that the first digital certificate has been deployed in the second service node according to the second deployment information.
[0143] In this embodiment, after the first digital certificate is deployed in the second service node, the second service node may send the second deployment information to the certificate control node via the first service node, so as to notify the certificate control node that the first digital certificate has been deployed in the second service node, thereby increasing the possibility that the certificate control node can receive the second deployment information. On the other hand, when the certificate control node knows that the first digital certificate has been deployed in the second service node, the certificate control node can avoid repeatedly distributing the first digital certificate to the second service node, thus avoiding wasting the system resources and network resources of the certificate control node.
[0144] Under normal circumstances, the certificate control node distributes digital certificates to the service nodes in the service cluster at the same time. Therefore, under normal circumstances, if the service nodes in the service cluster can receive the digital certificates distributed by the certificate control node, they usually receive the digital certificates distributed by the certificate control node at the same time.
[0145] However, sometimes the following situation occurs: within a period of time after some service nodes receive the digital certificates distributed by the certificate control node, some other service nodes have not received the digital certificates distributed by the certificate control node.
[0146] If the above situation occurs, sometimes it may be due to a temporary communication failure between some other service nodes and the certificate control node. For example, the delay suddenly increases. For example, the amount of data exchanged between some other service nodes and the certificate control node surges at this time, resulting in very little idle network resources between some other service nodes and the certificate control node at this time, affecting the transmission of digital certificates, and further causing some other service nodes not to receive the digital certificates distributed by the certificate control node, and often may not be able to receive the digital certificates distributed by the certificate control node for a period of time.
[0147] In view of this, based on the above situation, in the case where some service nodes have received the digital certificates distributed by the certificate control node and some other service nodes have not received the digital certificates distributed by the certificate control node within a period of time, in order to enable some other service nodes to obtain the digital certificates distributed by the certificate control node as soon as possible, and further enable some other service nodes to provide data services based on the digital certificates as soon as possible, in another embodiment of the present application, some other service nodes can obtain the digital certificates distributed by the certificate control node via these some service nodes.
[0148] For example, in the case where the first service node obtains the second digital certificate distributed by the certificate control node, other service nodes in the service cluster except the first service node can obtain the second digital certificate from the first service node.
[0149] For example, when the remaining valid duration of the first digital certificate is less than the fifth preset duration, the second service node may detect whether it has received the second digital certificate distributed by the certificate control node; the second digital certificate is applied by the certificate control node to the certificate issuing center when the remaining valid duration of the first digital certificate is less than the third preset duration, and is distributed by the certificate control node to the first service node. The second digital certificate is used to authorize or permit the service node to provide data services; the effective expiration time of the second digital certificate is later than that of the first digital certificate; the first service node is one of multiple service nodes in the service cluster, and the first service node is different from the second service node; the fifth preset duration is less than the third preset duration.
[0150] In one example, when receiving the second digital certificate distributed by the certificate control node, the second service node may deploy the second digital certificate in the second service node to provide data services based on the second digital certificate.
[0151] Alternatively, in another example, when the second service node does not receive the second digital certificate distributed by the certificate control node, it indicates that the second service node may not be able to receive the second digital certificate distributed by the certificate control node in a short period of time. However, in order to enable the second service node to obtain the second digital certificate as soon as possible and then be able to provide data services based on the second digital certificate, the second service node may broadcast a second acquisition request in the service cluster; the second acquisition request is used to obtain the second digital certificate.
[0152] The first service node receives the second acquisition request broadcast by the second service node. Then the first service node distributes the second digital certificate to the second service node according to the second acquisition request.
[0153] In this way, the second service node can receive the second digital certificate returned by the first service node according to the second acquisition request; then the second service node may deploy the second digital certificate in the second service node to provide data services based on the second digital certificate.
[0154] The fifth preset duration may include 1 s (second), 2 s, 3 s, 4 s, or 5 s, etc., and can be determined according to the actual situation specifically. This application does not limit this.
[0155] Through this application, when the second service node has not received the second digital certificate distributed by the certificate control node for some time after the first service node has received the second digital certificate distributed by the certificate control node, the second service node may obtain the second digital certificate distributed by the certificate control node via the first service node, so that the second service node can obtain the second digital certificate distributed by the certificate control node as soon as possible, and further enable the second service node to provide data services based on the second digital certificate as soon as possible.
[0156] In this application, usually, the digital certificates of service nodes in the service cluster are directly distributed by the certificate control node, and the certificate control node can directly manage the digital certificates of service nodes in the service cluster.
[0157] There are many service nodes in the service cluster. Sometimes, some service nodes in the service cluster are eligible to provide data services, while some other service nodes in the service cluster may temporarily not be eligible to provide data services due to some reasons (but may regain the eligibility to provide data services later).
[0158] In the case where a certain service node is not eligible to provide data services at this time, this certain service node should not obtain a digital certificate.
[0159] The certificate control node can accurately know which service nodes in the service cluster are eligible to provide data services at any given time.
[0160] In the scenario where the certificate control node distributes data certificates to service nodes in the service cluster, the certificate control node can distribute digital certificates to service nodes in the service cluster that are eligible to provide data services at this time, and not distribute digital certificates to service nodes in the service cluster that are not eligible to provide data services at this time, so as to prevent service nodes that are not eligible to provide data services at this time from obtaining digital certificates for authorizing or permitting service nodes to provide data services. For example, to prevent illegal nodes from obtaining digital certificates to engage in illegal activities in the case where service nodes that are not eligible to provide data services at this time are invaded, thus ensuring the data security of the service cluster.
[0161] Thus, in another embodiment of this application, in the scenario where the first service node distributes a second digital certificate to the second service node according to a second acquisition request, the first service node can request the certificate control node whether it can share the second digital certificate with the second service node. For example, the first service node can send a second sharing request to the certificate control node according to the second acquisition request, and the second sharing request is used to request sharing the second digital certificate with the second service node.
[0162] The certificate control node receives the second sharing request sent by the first service node according to the second acquisition request, and then the certificate control node can decide whether to allow the first service node to share the second digital certificate with the second service node according to the second acquisition request.
[0163] For example, the certificate control node can determine whether the second service node simultaneously meets the following conditions: the second service node is located in the service cluster, the second service node has the objective ability to provide data services, the second service node has the service qualification to provide data services, and the second service node has not been invaded, etc.
[0164] When the second service node satisfies the above conditions simultaneously, the first service node is allowed to share the second digital certificate with the second service node; or when the second service node does not satisfy the above conditions simultaneously, the first service node is not allowed to share the second digital certificate with the second service node.
[0165] Among them, when the certificate control node allows the first service node to share the second digital certificate with the second service node, the certificate control node may send a second sharing response to the first service node according to the second sharing request, and the second sharing response is used to indicate that sharing the second digital certificate with the second service node is allowed. After that, the first service node receives the second sharing response returned by the certificate control node according to the second sharing request, and sends the second digital certificate to the second service node according to the second sharing response.
[0166] Or, when the certificate control node does not allow the first service node to share the second digital certificate with the second service node, the certificate control node may send a second rejection response to the first service node according to the second sharing request, and the second rejection response is used to indicate that sharing the second digital certificate with the second service node is not allowed. After that, the first service node may receive the second rejection response returned by the certificate control node according to the second sharing request, and then does not distribute the second digital certificate to the second service node.
[0167] In another embodiment of the present application, after the second digital certificate is deployed in the second service node, the second service node may send third deployment information to the first service node, and the third deployment information is used to indicate that the second digital certificate has been deployed in the second service node, so that the first service node sends the third deployment information to the certificate control node.
[0168] After that, the first service node may receive the third deployment information sent by the second service node, and then may send the third deployment information to the certificate control node.
[0169] After that, the certificate control node may receive the third deployment information sent by the first service node, and then may determine that the second digital certificate has been deployed in the second service node according to the third deployment information.
[0170] In this embodiment, after the second digital certificate is deployed in the second service node, the second service node may send third deployment information to the certificate control node via the first service node, so as to notify the certificate control node that the second digital certificate has been deployed in the second service node, thereby increasing the possibility that the certificate control node can receive the third deployment information. On the other hand, when the certificate control node knows that the second digital certificate has been deployed in the second service node, the certificate control node may not repeatedly distribute the second digital certificate to the second service node. In this way, the system resources and network resources of the certificate control node can be avoided from being wasted.
[0171] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all optional embodiments, and the actions involved are not necessarily essential to this application.
[0172] Refer to Figure 3 , which shows a structural block diagram of a device for processing digital certificates according to this application, applied to a certificate control node, including: a first sending module 11, configured to send an application request to a certificate issuing center, where the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit a service node to provide data services; a first receiving module 12, configured to receive the first digital certificate returned by the certificate issuing center according to the application request; a first distribution module 13, configured to distribute the first digital certificate to the service node.
[0173] In an optional implementation manner, the device further includes: a determination module, configured to determine whether heartbeat information sent by the service node is received within a first preset duration before the current moment after receiving the first digital certificate returned by the certificate issuing center according to the application request; the distribution module is further configured to: when the heartbeat information sent by the service node is received within a first preset duration before the current moment, distribute the first digital certificate to the service node again.
[0174] In an optional implementation manner, the device further includes: a detection module, configured to detect whether first deployment information sent by the service node is received within a second preset duration after distributing the first digital certificate to the service node, where the first deployment information is used to indicate that the first digital certificate has been deployed in the service node; the distribution module is further configured to: when the first deployment information sent by the service node is not received, distribute the first digital certificate to the service node again.
[0175] In an alternative implementation, the device further includes: a first output module, configured to output a first warning message if the first deployment information sent by the service node is not received within a second preset duration after the first digital certificate is distributed to the service node multiple times, where the first warning message is used to indicate that the first digital certificate cannot be deployed in the service node.
[0176] In an alternative implementation, the device further includes: a second sending module, configured to send a renewal request for the first digital certificate to the certificate authority when the remaining valid duration of the first digital certificate is less than a third preset duration; a second receiving module, configured to receive a second digital certificate returned by the certificate authority according to the renewal request; the second digital certificate is used to authorize or permit the service node to provide data services; the effective expiration time of the second digital certificate is later than that of the first digital certificate; a second distribution module, configured to distribute the second digital certificate to the service node.
[0177] In an alternative implementation, the device further includes: a second output module, configured to output a second warning message when the remaining valid duration of the first digital certificate is less than a third preset duration; the second warning message is used to indicate that the first digital certificate is about to expire or has expired.
[0178] In the present application, a certificate control node may send an application request to a certificate authority, where the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit a service node to provide data services. Then, the certificate control node receives the first digital certificate returned by the certificate authority according to the application request and distributes the first digital certificate to the service node. The service node may receive the first digital certificate distributed by the certificate control node and deploy the first digital certificate in the service node to provide data services based on the first digital certificate.
[0179] Through the present application, unified application, unified control, and unified distribution of digital certificates by the certificate control node can be achieved. For example, the service node does not apply to the certificate authority for a digital certificate used to authorize or permit the service node to provide data services. Instead, the certificate control node uniformly applies to the certificate authority for a digital certificate and can distribute the applied digital certificate to the service node, so that the service node can provide data services based on the digital certificate distributed by the certificate control node.
[0180] In one example, when there are multiple service nodes, each of the multiple service nodes does not separately apply to the certificate authority for a digital certificate for authorizing or permitting the service node to provide data services. Instead, the certificate control node uniformly applies to the certificate authority for the digital certificate and can distribute the applied digital certificate to each of the multiple service nodes, so that each of the multiple service nodes can provide data services based on the digital certificate distributed by the certificate control node respectively.
[0181] Secondly, in the present application, when there are multiple service nodes, the digital certificate uniformly applied by the certificate control node to the certificate authority can be reused among the multiple service nodes. In this way, each of the multiple service nodes does not need to separately apply to the certificate authority for a digital certificate, the number of digital certificates applied to the certificate authority can be reduced, and certificate resources can be saved.
[0182] In addition, through the present application, when there are multiple service nodes, the certificate authority can only interface with the certificate control node and does not need to interface with each of the multiple service nodes separately. In this way, the certificate authority only needs to issue the digital certificate to the certificate control node and does not need to issue the digital certificate to each of the multiple service nodes separately, thereby saving the network resources of the certificate authority.
[0183] Refer to Figure 4 , which shows a structural block diagram of a device for processing digital certificates according to the present application, applied to a service node, including: a third receiving module 21, configured to receive a first digital certificate distributed by the certificate control node, where the first digital certificate is returned by the certificate authority to the certificate control node according to an application request after the certificate control node sends the application request to the certificate authority, the application request is used to apply for the first digital certificate, and the first digital certificate is used to authorize or permit the service node to provide data services; a first deployment module 22, configured to deploy the first digital certificate in the service node.
[0184] In an optional implementation manner, the device further includes: a third sending module, configured to periodically send heartbeat information to the certificate control node.
[0185] In an optional implementation manner, the device further includes: a fourth sending module, configured to send first deployment information to the certificate control node after the first digital certificate is deployed in the service node, where the first deployment information is used to indicate that the first digital certificate has been deployed in the service node.
[0186] In an alternative implementation, the apparatus further includes: a fourth receiving module, configured to receive a second digital certificate distributed by the certificate management and control node, where the second digital certificate is applied by the certificate management and control node to the certificate issuing center when the remaining valid duration of the first digital certificate is less than a third preset duration, and the second digital certificate is used to authorize or permit the service node to provide data services; the effective expiration time of the second digital certificate is later than the effective expiration time of the first digital certificate; and a second deployment module, configured to deploy the second digital certificate in the service node.
[0187] In the present application, the certificate management and control node may send an application request to the certificate issuing center. The application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit the service node to provide data services. Then, the certificate management and control node receives the first digital certificate returned by the certificate issuing center according to the application request and distributes the first digital certificate to the service node. The service node may receive the first digital certificate distributed by the certificate management and control node and deploy the first digital certificate in the service node to provide data services based on the first digital certificate.
[0188] Through the present application, the certificate management and control node can achieve unified application, unified management and control, and unified distribution of digital certificates. For example, the service node does not apply to the certificate issuing center for a digital certificate used to authorize or permit the service node to provide data services. Instead, the certificate management and control node uniformly applies to the certificate issuing center for a digital certificate and can distribute the applied digital certificate to the service node so that the service node can provide data services based on the digital certificate distributed by the certificate management and control node.
[0189] In an example, when there are multiple service nodes, each of the multiple service nodes does not separately apply to the certificate issuing center for a digital certificate used to authorize or permit the service node to provide data services. Instead, the certificate management and control node uniformly applies to the certificate issuing center for a digital certificate and can distribute the applied digital certificate to each of the multiple service nodes so that each of the multiple service nodes can provide data services based on the digital certificate distributed by the certificate management and control node respectively.
[0190] Secondly, in the present application, when there are multiple service nodes, the digital certificate uniformly applied by the certificate management and control node to the certificate issuing center can be reused among the multiple service nodes. In this way, each of the multiple service nodes does not need to separately apply to the certificate issuing center for a digital certificate, which can reduce the number of digital certificates applied to the certificate issuing center and save certificate resources.
[0191] In addition, through this application, in the case where there are multiple service nodes, the certificate authority can interface only with the certificate control node and does not need to interface separately with each of the multiple service nodes. In this way, the certificate authority can issue digital certificates only to the certificate control node and does not need to issue digital certificates to each of the multiple service nodes, thereby saving network resources of the certificate authority.
[0192] An embodiment of this application also provides a non-volatile readable storage medium, in which one or more modules (programs) are stored. When the one or more modules are applied to a device, they can cause the device to execute instructions for each method step in the embodiments of this application.
[0193] Embodiments of this application provide one or more machine-readable media, on which instructions are stored. When executed by one or more processors, the instructions cause an electronic device to execute the methods in one or more of the above embodiments. In the embodiments of this application, the electronic device includes a server, a gateway, a sub-device, etc., and the sub-device is a device such as an Internet of Things device.
[0194] Embodiments of the present disclosure can be implemented as a device configured as desired using any suitable hardware, firmware, software, or any combination thereof. The device may include a server (cluster), a terminal device such as an IoT device, and other electronic devices.
[0195] Figure 5 Exemplary device 1300 that can be used to implement the various embodiments in this application is schematically shown.
[0196] For one embodiment, Figure 5 Exemplary device 1300 is shown, which has one or more processors 1302, a control module (chipset) 1304 coupled to at least one of the (one or more) processors 1302, a memory 1306 coupled to the control module 1304, a non-volatile memory (NVM, Non-Volatile Memory) / storage device 1308 coupled to the control module 1304, one or more input / output devices 1310 coupled to the control module 1304, and a network interface 1312 coupled to the control module 1304.
[0197] Processor 1302 may include one or more single-core or multi-core processors. Processor 1302 may include any combination of general-purpose processors or dedicated processors (such as graphics processors, application processors, baseband processors, etc.). In some embodiments, device 1300 can act as a server device such as a gateway in the embodiments of this application.
[0198] In some embodiments, device 1300 may include one or more computer-readable media (e.g., memory 1306 or NVM / storage device 1308) having instructions 1314 and one or more processors 1302 coupled with the one or more computer-readable media and configured to execute the instructions 1314 to implement modules to perform the actions in this disclosure.
[0199] For one embodiment, control module 1304 may include any suitable interface controller to provide any suitable interface to at least one of the processor(s) 1302 and / or any suitable device or component in communication with control module 1304.
[0200] Control module 1304 may include a memory controller module to provide an interface to memory 1306. The memory controller module may be a hardware module, a software module, and / or a firmware module.
[0201] Memory 1306 may be used to load and store data and / or instructions 1314 for device 1300, for example. For one embodiment, memory 1306 may include any suitable volatile memory, such as suitable DRAM. In some embodiments, memory 1306 may include double data rate four synchronous dynamic random access memory (DDR4 SDRAM).
[0202] For one embodiment, control module 1304 may include one or more input / output controllers to provide an interface to NVM / storage device 1308 and the input / output device(s) 1310.
[0203] For example, NVM / storage device 1308 may be used to store data and / or instructions 1314. NVM / storage device 1308 may include any suitable non-volatile memory (e.g., flash memory) and / or may include any suitable non-volatile storage device(s) (e.g., one or more hard disk drives (HDDs), one or more optical disc (CD) drives, and / or one or more digital versatile disc (DVD) drives).
[0204] NVM / storage device 1308 may include storage resources physically part of a device on which device 1300 is installed, or it may be accessible by the device without being part of the device. For example, NVM / storage device 1308 may be accessed via the input / output device(s) 1310 over a network.
[0205] (One or more) Input / output devices 1310 may provide an interface for device 1300 to communicate with any other suitable device. The input / output devices 1310 may include communication components, pinyin components, sensor components, etc. The network interface 1312 may provide an interface for device 1300 to communicate through one or more networks. Device 1300 may wirelessly communicate with one or more components of a wireless network according to any standard and / or protocol among one or more wireless network standards and / or protocols. For example, it may access a wireless network based on a communication standard, such as WiFi, 2G, 3G, 4G, 5G, etc., or a combination thereof for wireless communication.
[0206] For one embodiment, at least one of (one or more) processors 1302 may be logically encapsulated with one or more controllers of the control module 1304 (e.g., the memory controller module). For one embodiment, at least one of (one or more) processors 1302 may be logically encapsulated with one or more controllers of the control module 1304 to form a system-in-package (SiP). For one embodiment, at least one of (one or more) processors 1302 may be logically integrated with one or more controllers of the control module 1304 on the same die. For one embodiment, at least one of (one or more) processors 1302 may be logically integrated with one or more controllers of the control module 1304 on the same die to form a system-on-chip (SoC).
[0207] In various embodiments, device 1300 may be, but is not limited to: a server, a desktop computing device, or a mobile computing device (e.g., a laptop computing device, a handheld computing device, a tablet computer, a netbook, etc.) and other terminal devices. In various embodiments, device 1300 may have more or fewer components and / or a different architecture. For example, in some embodiments, device 1300 includes one or more cameras, a keyboard, a liquid crystal display (LCD) screen (including a touch screen display), a non-volatile memory port, multiple antennas, a graphics chip, an application-specific integrated circuit (ASIC), and a speaker.
[0208] An embodiment of the present application provides an electronic device, including: one or more processors; and one or more machine-readable media storing instructions thereon, which, when executed by one or more processors, cause the electronic device to execute the methods as described in one or more of the present application.
[0209] For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, refer to the partial description of the method embodiment.
[0210] Each embodiment in this specification is described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts among the embodiments, reference can be made to each other.
[0211] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable terminal devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable terminal devices generate a device for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or multiple blocks.
[0212] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable terminal device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or multiple blocks.
[0213] These computer program instructions can also be loaded onto a computer or other programmable terminal device, so that a series of operation steps are executed on the computer or other programmable terminal device to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one process Figure 1 one process or multiple processes and / or blocks Figure 1 or multiple blocks.
[0214] Although the preferred embodiments of the embodiments of the present application have been described, those skilled in the art can make additional changes and modifications once they know the basic creative concepts. Therefore, the appended claims are intended to be construed as including the preferred embodiments and all changes and modifications that fall within the scope of the embodiments of the present application.
[0215] Finally, it should also be noted that in this text, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or terminal device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or terminal device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or terminal device comprising the element.
[0216] The method and device for processing digital certificates provided in this application have been introduced in detail above. Specific examples are used in this text to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A method for processing digital certificates, characterized in that, Applied to a certificate control node, the method includes: Sending an application request to a certificate issuing center, where the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit a service node to provide data services; Receiving the first digital certificate returned by the certificate issuing center according to the application request; Distributing the first digital certificate to the service node.
2. The method according to claim 1, characterized in that, The method further includes: After receiving the first digital certificate returned by the certificate issuing center according to the application request, determining whether heartbeat information sent by the service node is received within a first preset duration before the current moment; When the heartbeat information sent by the service node is received within the first preset duration before the current moment, then distributing the first digital certificate to the service node.
3. The method according to claim 1, characterized in that The method further includes: Within a second preset duration after distributing the first digital certificate to the service node, detecting whether first deployment information sent by the service node is received, where the first deployment information is used to indicate that the first digital certificate has been deployed in the service node; When the first deployment information sent by the service node is not received, distributing the first digital certificate to the service node again.
4. The method according to claim 3, wherein The method further includes: When the first deployment information sent by the service node is not received within the second preset duration after distributing the first digital certificate to the service node multiple times, outputting a first warning message, where the first warning message is used to prompt that the first digital certificate cannot be deployed in the service node.
5. The method according to claim 1, wherein The method further includes: When the remaining valid duration of the first digital certificate is less than a third preset duration, sending a renewal request for the first digital certificate to the certificate issuing center; Receiving a second digital certificate returned by the certificate issuing center according to the renewal request; the second digital certificate is used to authorize or permit the service node to provide data services; the effective expiration moment of the second digital certificate is later than the effective expiration moment of the first digital certificate; Distributing the second digital certificate to the service node.
6. The method according to claim 1, characterized in that The method further includes; When the remaining valid duration of the first digital certificate is less than a third preset duration, outputting a second warning message; the second warning message is used to prompt that the first digital certificate is about to expire or has expired.
7. A method for processing digital certificates, characterized in that, Applied to a service node, the method includes: Receiving the first digital certificate distributed by the certificate control node, where the first digital certificate is returned by the certificate issuing center to the certificate control node according to an application request after the certificate control node sends the application request to the certificate issuing center, the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit the service node to provide data services; Deploying the first digital certificate in the service node.
8. The method according to claim 7, characterized in that The method further includes: Regularly sending heartbeat information to the certificate control node.
9. The method according to claim 7, wherein The method further includes: After deploying the first digital certificate in the service node, send first deployment information to the certificate control node, where the first deployment information is used to indicate that the first digital certificate has been deployed in the service node.
10. The method according to claim 7, characterized in that, The method further includes: Receiving a second digital certificate distributed by the certificate control node, where the second digital certificate is applied for by the certificate control node from the certificate authority when the remaining valid duration of the first digital certificate is less than a third preset duration, and the second digital certificate is used to authorize or permit the service node to provide data services; the effective expiration time of the second digital certificate is later than the effective expiration time of the first digital certificate; Deploying the second digital certificate in the service node.
11. A device for processing digital certificates, characterized in that, Applied to a certificate control node, the apparatus includes: A first sending module, configured to send an application request to a certificate authority, where the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit a service node to provide data services; A first receiving module, configured to receive the first digital certificate returned by the certificate authority according to the application request; A first distribution module, configured to distribute the first digital certificate to the service node.
12. A device for processing digital certificates, characterized in that, Applied to a service node, the apparatus includes: A third receiving module, configured to receive a first digital certificate distributed by a certificate control node, where the first digital certificate is returned by the certificate authority to the certificate control node according to an application request after the certificate control node sends the application request to the certificate authority, the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit the service node to provide data services; A first deployment module, configured to deploy the first digital certificate in the service node.
13. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, the method according to any one of claims 1 to 10 is implemented.
14. A computer-readable storage medium, characterized in that, A computer program is stored on a computer-readable storage medium, and when the computer program is executed by a processor, the method according to any one of claims 1 to 10 is implemented.