Authentication information storage method, system, device and product of edge computing device

By using a sharded bundle filter and mirror center design in edge computing devices, the problem of reduced accuracy caused by the accumulation of revoked authentication information is solved, and efficient revoked authentication information is realized, ensuring the legality and permission verification of edge computing devices.

CN120281590AActive Publication Date: 2025-07-08BEIJING VOLCANO ENGINE TECH CO LTD

Patent Information

Application Number
CN202510780847.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-11
Publication Date
2025-07-08
Estimated Expiration
2045-06-11

AI Technical Summary

Technical Problem

In the edge computing scenario, when the prior art stores revocation authentication information through the Bloom filter, as the revocation authentication information accumulates, the accuracy of revocation inspection gradually decreases, and the initialization loads are slow, resulting in slow service cold start and poor timeliness.

Method used

The sharded bundle filter solution is adopted to store the revoked authentication information in the effective deadline, and all revoked authentication information stored in the sharded bundle filter is cleared after the expiration of the revoked authentication information. The design of the mirror center can achieve rapid cold loading and incremental loading to ensure the expiration deletion of revoked authentication information.

Benefits of technology

It realizes local authentication revocation inspection of large data level in edge computing scenarios, reduces storage space usage, ensures the accuracy and reliability of authentication revocation inspection, and reduces the performance impact caused by network latency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281590A_ABST
    Figure CN120281590A_ABST
Patent Text Reader

Abstract

An authentication information storage method, system, device and product of an edge computing device relate to the technical field of edge computing, and the method comprises the following steps: receiving first revoked authentication information in response to a service instance of a cluster, according to the effective deadline of the first revocation authentication information and a preset time interval corresponding to a plurality of fragmented Bloom filters of the service instance, determining a first fragmented Bloom filter, and storing the first revocation authentication information into the first fragmented Bloom filter; and in response to the expiration of all the revoked authentication information stored in the first fragmentation Bloom filter, emptying all the revoked authentication information stored in the first fragmentation Bloom filter. According to the technical scheme, the revoked authentication information is stored in the fragmented mode according to the effective deadline, expired deletion of the revoked authentication information in the fragmented Bloom filter is achieved, a guarantee is provided for local authentication revoked inspection of the big data magnitude in the edge computing scene, the storage space is saved, and the accuracy and reliability of authentication revoked inspection can be guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of edge computing technologies, and in particular, to a method, system, device, and product for storing authentication information of an edge computing device. Background Art

[0002] In an edge computing scenario, an edge computing device needs to confirm its legality and permissions through device authentication information. In some scenarios, it is necessary to revoke the authentication information that has not yet expired. The revoked edge computing device will no longer be able to pass the authentication, so it is necessary to perform a revocation check on the authentication information of the edge computing device.

[0003] In related technologies, a Bloom filter is used to store the revoked authentication information to implement local revocation checks. However, as the revoked authentication information accumulates continuously, the accuracy of the revocation check will gradually decrease. Summary of the Invention

[0004] This Summary of the Invention section is provided to introduce concepts in a brief form, which will be described in detail in the following Detailed Implementation section. This Summary of the Invention section is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to be used to limit the scope of the claimed technical solution.

[0005] In a first aspect, the present disclosure provides a method for storing authentication information of an edge computing device. The authentication information storage method includes: In response to a service instance of a cluster receiving first revoked authentication information, determining a first sharded Bloom filter from the plurality of sharded Bloom filters according to the effective expiration time of the first revoked authentication information and a preset time interval corresponding to the plurality of sharded Bloom filters of the service instance, and storing the first revoked authentication information in the first sharded Bloom filter; the service instance includes a plurality of sharded Bloom filters, and one sharded Bloom filter is used to store revoked authentication information with an effective expiration time within a corresponding preset time interval; By the service instance, in response to all the revoked authentication information stored in the first sharded Bloom filter being expired, clearing all the revoked authentication information stored in the first sharded Bloom filter.

[0006] In a second aspect, the present disclosure provides a system for storing authentication information of an edge computing device. The authentication information storage system includes: A controller, configured to receive a device revocation request, determine first revoked authentication information according to the device authentication information carried in the device revocation request, and send the first revoked authentication information to a service instance of a cluster. The service instance includes a plurality of sharded Bloom filters, and one sharded Bloom filter is used to store revoked authentication information with an effective expiration time within a corresponding preset time interval; The service instance is configured to, in response to receiving the first revocation authentication information, determine a first sharded Bloom filter from the multiple sharded Bloom filters according to the expiration time of the first revocation authentication information and the preset time intervals corresponding to the multiple sharded Bloom filters, and store the first revocation authentication information in the first sharded Bloom filter; The service instance is configured to, in response to all the revocation authentication information stored in the first sharded Bloom filter expiring, clear all the revocation authentication information stored in the first sharded Bloom filter.

[0007] In a third aspect, the present disclosure provides a computer-readable medium having a computer program stored thereon, and when the program is executed by a processing device, the steps of the method described in the first aspect are implemented.

[0008] In a fourth aspect, the present disclosure provides an electronic device, including: A storage device having a computer program stored thereon; A processing device configured to execute the computer program in the storage device to implement the steps of the method described in the first aspect.

[0009] In a fifth aspect, the present disclosure provides a computer program product including a computer program, and when the computer program is executed by a processor, the steps of the method described in the first aspect are implemented.

[0010] Through the above technical solutions, the service instances of the cluster can determine the first sharded Bloom filter according to the expiration time of the first revocation authentication information and the preset time intervals corresponding to the multiple sharded Bloom filters, and then store the first revocation authentication information in the first sharded Bloom filter. Moreover, when all the revocation authentication information stored in the first sharded Bloom filter expires, all the revocation authentication information stored in the first sharded Bloom filter can be cleared. By adopting this method, through the sharded Bloom filters corresponding to different preset time intervals, the revocation authentication information can be shard-stored according to the expiration time, so that the revocation authentication information can be directly cleared by clearing the sharded Bloom filter to achieve expired deletion, providing a guarantee for implementing local authentication revocation checks for large data volumes in edge computing scenarios, reducing the performance impact caused by network latency, not only saving storage space, but also ensuring the accuracy and reliability of authentication revocation checks.

[0011] Other features and advantages of the present disclosure will be described in detail in the subsequent specific implementation section. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic and the original elements and elements are not necessarily drawn to scale. In the drawings: Figure 1 is a schematic flowchart of a method for storing authentication information of an edge computing device according to an exemplary embodiment of the present disclosure; Figure 2 is a schematic diagram of a sharded Bloom filter according to an exemplary embodiment of the present disclosure; Figure 3 is a schematic diagram of an authentication information storage architecture of an edge computing device according to an exemplary embodiment of the present disclosure; Figure 4 is an interaction schematic diagram of an authentication information storage architecture of an edge computing device according to an exemplary embodiment of the present disclosure; Figure 5 is a schematic diagram of an interaction process between a service instance and an image center according to an exemplary embodiment of the present disclosure; Figure 6 is a schematic diagram of a process of backup and compression of an image center according to an exemplary embodiment of the present disclosure; Figure 7 is a schematic diagram of a process of backing up an image center according to an exemplary embodiment of the present disclosure; Figure 8 is a schematic diagram of a process of authentication revocation check according to an exemplary embodiment of the present disclosure; Figure 9 is a schematic diagram of the structure of an authentication information storage system of an edge computing device according to an exemplary embodiment of the present disclosure; Figure 10 is a schematic diagram of the structure of an electronic device according to an exemplary embodiment of the present disclosure. Specific Embodiments

[0013] The embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.

[0014] It should be understood that the various steps described in the method embodiments of the present disclosure can be executed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.

[0015] As used herein, the term "including" and its variations are open-ended, that is, "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0016] It should be noted that the concepts such as "first", "second", etc. mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.

[0017] It should be noted that the modifications of "one" and "multiple" mentioned in the present disclosure are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more".

[0018] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only for illustrative purposes and are not used to limit the scope of these messages or information.

[0019] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the user and the user's authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0020] For example, when responding to receiving an active request from a user, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application program, a server, or a storage medium that performs the operations of the technical solutions of the present disclosure according to the prompt message.

[0021] As an optional but non-limiting implementation manner, when responding to receiving an active request from a user, the manner of sending a prompt message to the user can be, for example, in the form of a pop-up window, and the prompt message can be presented in text in the pop-up window. In addition, the pop-up window can also carry a selection control for the user to choose "agree" or "disagree" to provide personal information to the electronic device.

[0022] It is understandable that the above notification and the process of obtaining user authorization are only illustrative and do not limit the implementation manner of the present disclosure. Other manners that comply with relevant laws and regulations can also be applied to the implementation manner of the present disclosure.

[0023] Meanwhile, it is understandable that the data involved in the present technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the corresponding laws, regulations and related provisions.

[0024] Edge computing is a distributed computing architecture that pushes data processing and analysis from the cloud or data center to the network edge, closer to the data source or user device. In the edge computing scenario, edge computing devices need to confirm their legality and permissions through device authentication information to ensure that only authorized edge computing devices can access the network, access resources or communicate with other edge computing devices.

[0025] Taking the zero-trust architecture as an example, the authentication information of edge computing devices usually uses standard structures such as certificates, and the unique identifier is usually disordered. To enhance security, the authentication information requires complete lifecycle management. In some scenarios, it is necessary to revoke the authentication information that has not expired yet. The revoked authentication information cannot be used anymore to prevent malicious exploitation.

[0026] In the related art, for the revocation check of the zero-trust architecture, a third-party data source can be requested through the network. By this method, there are problems of slow response speed and low performance for the authentication revocation check. And the local revocation check scheme based on memory includes two schemes: hot data caching and Bloom filter.

[0027] The hot data caching scheme, such as caches like LRU (Least Recently Used) and LFU (Least Frequently Used), consumes too much memory and is usually applied to scenarios with small data sets or more accesses to hot data, and cannot be applied to the caching scenario with a large amount of data in the edge computing scenario.

[0028] The Bloom filter scheme, by sacrificing some accuracy and using bit operations, can cache a large amount of data with less memory. The required storage space can be determined by a calculation formula:

[0029] Among them, n represents the number of revoked authentication information, p represents the false positive rate, and m represents the required memory. When the false positive rate is 1%, storing 100 million revoked authentication information only requires 480MB, which is about 1 / 20 of the memory required by schemes such as LRU, and the occupied space is extremely small. However, this scheme still has defects: one is that it cannot delete data, which will cause the revoked authentication information to accumulate continuously, and then lead to a lower and lower accuracy; the other is that the initialization loading is slower, and it is necessary to pull the full amount of revoked authentication information and reconstruct the Bloom filter, resulting in a slow cold start of the service and poor timeliness.

[0030] In view of this, the present disclosure provides a method, system, device and product for storing authentication information of an edge computing device to solve the above technical problems. It can be applied to the authentication revocation check in the above edge computing scenario or zero-trust architecture, especially for the billion-level zero-trust architecture, and can also be used for the authentication revocation check with other architectures. The present disclosure does not limit this.

[0031] The following further explains the embodiments of the present disclosure with reference to the accompanying drawings.

[0032] Figure 1 is a flowchart of a method for storing authentication information of an edge computing device shown according to an exemplary embodiment of the present disclosure. Referring to Figure 1 , the method for storing authentication information includes: S101: In response to a service instance of a cluster receiving first revoked authentication information, determine a first sharded Bloom filter from multiple sharded Bloom filters according to the effective expiration time of the first revoked authentication information and the preset time intervals corresponding to the multiple sharded Bloom filters of the service instance, and store the first revoked authentication information in the first sharded Bloom filter.

[0033] Among them, a sharded Bloom filter is used to store revoked authentication information whose effective expiration time is within the corresponding preset time interval.

[0034] It should be noted that the authentication information of the edge computing device is the unique identifier of the edge computing device. For example, it can be a digital certificate, which is an important credential for verifying the device. The revoked authentication information refers to the revoked device authentication information. For example, when the digital certificate is revoked, the corresponding device will lose the corresponding authentication qualification, etc. The present disclosure does not limit this.

[0035] S102: Through the service instance, in response to all the revoked authentication information stored in the first sharded Bloom filter being expired, clear all the revoked authentication information stored in the first sharded Bloom filter.

[0036] Exemplarily, a sharded Bloom filter can be constructed according to the distribution of the authentication validity period of edge computing devices. Taking the distribution of the validity period of the authentication information of edge computing devices within 60 days as an example, multiple sharded Bloom filters can be created according to different time intervals as needed. For example, if sharding is done on a daily basis, at least 60 sharded Bloom filters need to be created, and the revoked authentication information expiring on the same day is stored in the same sharded Bloom filter.

[0037] For another example, if sharding is done every 10 days, at least 6 sharded Bloom filters need to be created. For example, shard 1 is used to store the revoked authentication information with an expiration deadline within 1 - 10 days, and shard 2 is used to store the revoked authentication information with an expiration deadline within 11 - 20 days. In this way, the upper limit value of the time interval can be used as the validity period of the sharded Bloom filter for each sharded Bloom filter, and the expiration countdown is set to trigger clearing. For example, if partition 1 expires after 10 days, all the revoked authentication information in partition 1 will expire and be cleared.

[0038] Exemplarily, a preset time interval can also be set according to specific time. For example, shard 1 is used to store the revoked authentication information with an expiration deadline between January 1, 2025 and January 10, 2025, and so on. This disclosure will not elaborate further here. Similarly, the upper limit value of the time interval can be used as the validity period of the sharded Bloom filter for each sharded Bloom filter, and the expiration countdown is set to trigger clearing. For example, if partition 1 expires after January 10, 2025, all the revoked authentication information in partition 1 will expire and be cleared.

[0039] In this way, as time goes by, all the revoked authentication information stored in the sharded Bloom filter will expire. By clearing this sharded Bloom filter, the problem that the Bloom filter cannot delete data is solved.

[0040] By adopting the above method, through the sharded Bloom filters corresponding to different preset time intervals, the revoked authentication information can be shard - stored according to the expiration deadline, so that the sharded Bloom filter can be directly cleared to achieve the expired deletion of the revoked authentication information, providing guarantee for the local authentication revocation check of large - data volume in the edge computing scenario, reducing the performance impact caused by network latency, not only saving storage space, but also ensuring the accuracy and reliability of the authentication revocation check.

[0041] In a possible way, when all the revoked authentication information stored in the first sharded Bloom filter has expired, the service instance clears all the revoked authentication information stored in the first sharded Bloom filter, including: when all the revoked authentication information stored in the first sharded Bloom filter has expired, the service instance marks the first sharded Bloom filter as a sharded Bloom filter to be cleared, and enables an idle sharded Bloom filter, where the idle sharded Bloom filter corresponds to a new preset time interval; the service instance clears all the revoked authentication information stored in the first sharded Bloom filter. The authentication information storage method further includes: the service instance marks the cleared first sharded Bloom filter as an idle sharded Bloom filter.

[0042] Exemplarily, in order to implement a rolling sharded Bloom filter, more sharded Bloom filters than the number of time intervals can be created. Continuing with the example where the validity period distribution of the authentication information of the edge computing device is within 60 days and day-level sharded Bloom filters are created, as Figure 2 shown, 62 sharded Bloom filters can be created. In addition to the 60 sharded Bloom filters 1 to 60 for storing revoked authentication information that expires within 60 days, it also includes the sharded Bloom filter 0 to be cleared and the idle sharded Bloom filter 61 to be enabled.

[0043] Furthermore, after one day, the sharded Bloom filter 0 is cleared, the sharded Bloom filter 1 is marked as the new sharded Bloom filter to be cleared, the idle sharded Bloom filter 61 is enabled, and a new idle sharded Bloom filter 62 to be enabled is created. Of course, the cleared sharded Bloom filter 0 can also be used as the idle sharded Bloom filter 62, and the present disclosure does not limit this. Thus, the rotation use of the sharded Bloom filter can be achieved, and the problem that the revoked authentication information cannot be deleted from the Bloom filter can be solved.

[0044] In other possible implementation ways, after one day, the sharded Bloom filter 0 can be directly deleted, and then a new idle sharded Bloom filter 62 to be enabled is created. It can be specifically selected according to requirements, and the present disclosure does not limit this.

[0045] It should be understood that the sharded Bloom filter 0 can prevent new revoked authentication information from being inserted during the clearing process, and the sharded Bloom filter 61 can prevent new revoked authentication information from being inserted during the creation process. Therefore, creating more sharded Bloom filters than the number of time intervals can ensure the rotation use of the sharded Bloom filter. The specific number can be set according to requirements. For example, (the number of time intervals + 2) sharded Bloom filters are set, and the present disclosure does not limit this.

[0046] Figure 3 This is a schematic diagram of the authentication information storage architecture of the edge computing device provided by the embodiments of the present disclosure, as Figure 3As shown, the user can configure the edge computing devices to be revoked on the device revocation platform, generate a device revocation request based on the authentication information of these edge computing devices. After receiving the device revocation request, the controller determines the device authentication information carried in the device revocation request as the revocation authentication information, and can publish the revocation authentication information to the subscribed sharded Bloom filter and the image center in a broadcast manner. The broadcast revocation authentication information can also be consumed in the form of a message queue, which is not limited in this disclosure. The revocation authentication information can also be written into the first storage space and the second storage space. Among them, the first storage space is used to cache the full amount of revocation authentication information, which can be a key-value storage database, such as a Redis database, and the second storage space is used to persistently store the full amount of revocation authentication information.

[0047] The following is an example description of the authentication information storage method for edge computing devices in an embodiment of the present disclosure based on the authentication information storage architecture of edge computing devices as Figure 3 shown.

[0048] In the construction stage of this architecture, each service instance that needs to perform authentication revocation checks will have a sharded Bloom filter built in. When the user performs device authentication revocation, as Figure 4 shown, the controller will incrementally write the revocation authentication information into the Bloom filter, image center, first storage space, and second storage space of each service instance. Moreover, the image center will periodically compress the currently built Bloom filter and store it in the third storage space.

[0049] In the startup stage of the service instance, in a possible manner, the authentication information storage method further includes: in response to the startup of the service instance, obtaining a target authentication information queue and a target image Bloom filter from the image center through the service instance. The target authentication information queue is used to store the revocation authentication information received after the construction of the target image Bloom filter; constructing a sharded Bloom filter of the service instance by the service instance according to the target authentication information queue and the target image Bloom filter.

[0050] Exemplarily, the sharded Bloom filter does not need to be built from scratch at startup and can directly pull the built image Bloom filter from the image center. Since the image center constructs the image Bloom filter periodically, it is also necessary to pull the revocation authentication information received after the construction of the target image Bloom filter, that is, the revocation authentication information in the target authentication information queue. The service instance writes the revocation authentication information in the target authentication information queue into the sharded Bloom filter obtained based on the target image Bloom filter, and a sharded Bloom filter with complete data can be obtained. Thus, the integrity of the revocation authentication information in the constructed sharded Bloom filter can be guaranteed.

[0051] Furthermore, as Figure 5As shown, in addition to pulling the mirror Bloom filter and the revocation authentication information in the incremental target authentication information queue from the mirror center, the service instance can also continuously receive the revocation authentication information broadcast by the controller and store it in the message queue (Message Queue, MQ). The service instance can complete the subsequent revocation authentication information incrementally based on the message queue, ensuring that the data real-time performance can reach the second level.

[0052] Through the mirror center, the sharded Bloom filter can achieve fast cold loading to solve the problem in the related technology that it cannot be quickly loaded due to the excessive number of historical revocation authentication information during the cold start process, reducing the construction duration of the sharded Bloom filter in the service instance and the service startup duration. And through the caching scheme combining the stock loading and incremental loading, the real-time performance of the revocation authentication information is improved.

[0053] In a possible way, the authentication information storage method further includes: in response to the update of the service instance, obtaining the target authentication information queue and the target mirror Bloom filter from the mirror center through the service instance, where the target authentication information queue is used to store the revocation authentication information received after the construction of the target mirror Bloom filter; and updating the sharded Bloom filter of the service instance by the service instance according to the target authentication information queue and the target mirror Bloom filter.

[0054] Exemplarily, the service instance can also be set to be updated regularly, and the target authentication information queue and the target mirror Bloom filter are also obtained from the mirror center to update the sharded filter of the service instance, further improving the accuracy of the revocation authentication information in the service instance.

[0055] In a possible way, the target mirror Bloom filter is constructed by the mirror center in the following manner: in response to receiving the second revocation authentication information, writing the second revocation authentication information into the first authentication information queue, where the first authentication information queue is used to store the revocation authentication information received after the construction of the first mirror Bloom filter stored in the mirror center; copying the first mirror Bloom filter to obtain the second mirror Bloom filter; and writing the revocation authentication information in the first authentication information queue into the second mirror Bloom filter to obtain the target mirror Bloom filter.

[0056] Exemplarily, in the Figure 3 shown storage architecture, the mirror center will back up the mirror Bloom filter periodically, which can be set according to requirements, such as once every 10 minutes, and the present disclosure does not limit this. The backup process of the mirror Bloom filter in the mirror center is as Figure 6As shown, after startup, the mirror center will periodically and persistently back up its own data to the third storage space. The mirror center mainly includes the mirror Bloom filter that completed the last persistent backup and the revocation authentication information (MQ messages) newly revoked since the last backup. The newly revoked revocation authentication information can be written into the first authentication information queue.

[0057] In a possible approach, the authentication information storage method further includes: constructing a second authentication information queue through the mirror center and stopping writing the received revocation authentication information into the first authentication information queue. The second authentication information queue is used to store the revocation authentication information received after replicating to obtain the second mirror Bloom filter; deleting the first authentication information queue and the first mirror Bloom filter.

[0058] Exemplarily, as Figure 7 shown, when the mirror center backs up the mirror Bloom filter, it can first construct a replication of the first mirror Bloom filter to obtain the second mirror Bloom filter, and then construct an empty second authentication information queue to receive subsequent revocation authentication information. At this time, the first authentication information queue stops writing revocation authentication information. Then, write the revocation authentication information in the first authentication information queue into the replicated second mirror Bloom filter to obtain the target mirror Bloom filter. Furthermore, the pointer can be pointed to the target mirror Bloom filter and the second authentication information queue, so that when the service instance performs a pull operation, it will obtain the target mirror Bloom filter and the second authentication information queue.

[0059] Exemplarily, to avoid data redundancy in the mirror center, when the reference counts of the first authentication information queue and the first mirror Bloom filter are 0, the first authentication information queue and the first mirror Bloom filter can be deleted, that is, the mirror center only needs to retain the latest mirror Bloom filter and the authentication information queue.

[0060] Furthermore, after obtaining the target mirror Bloom filter, as Figure 6 shown, a compressed target mirror Bloom filter can be stored in the third storage space.

[0061] In a possible way, the service instance obtains the target authentication information queue and the target mirror Bloom filter from the mirror center, including: when the mirror center includes a first authentication information queue, a second authentication information queue, a first mirror Bloom filter, and a second mirror Bloom filter, the service instance obtains the first authentication information queue, the second authentication information queue, and the first mirror Bloom filter from the mirror center; wherein, the second mirror Bloom filter is obtained by copying the first mirror Bloom filter, the first authentication information queue is used to store the revocation authentication information received after the construction of the first mirror Bloom filter and before the second mirror Bloom filter is copied, and the second authentication information queue is used to store the revocation authentication information received after the second mirror Bloom filter is copied. The service instance constructs the sharded Bloom filter of the service instance according to the target authentication information queue and the target mirror Bloom filter, including: the service instance constructs the sharded Bloom filter of the service instance based on the first authentication information queue, the second authentication information queue, and the first mirror Bloom filter.

[0062] Exemplarily, as Figure 7 shown, before the backup of the mirror center is completed, there may be two authentication information queues and two mirror Bloom filters at the same time. At this time, the service instance obtains the first authentication information queue, the second authentication information queue, and the first mirror Bloom filter, and writes the revocation authentication information in the first authentication information queue and the second authentication information queue into the sharded Bloom filter obtained based on the first mirror Bloom filter to obtain its own sharded Bloom filter, which can avoid incomplete incremental revocation authentication information obtained during the backup process.

[0063] When the mirror center is started for the first time, there is no mirror Bloom filter from the previous backup in the mirror center. Therefore, in a possible way, the target mirror Bloom filter is constructed by the mirror center in the following way: in response to the first startup of the mirror center, obtain the unexpired third revocation authentication information from the second storage space, where the second storage space is used to persistently store the full amount of revocation authentication information; construct the target mirror Bloom filter based on the third revocation authentication information.

[0064] Exemplarily, the full amount of revocation authentication information can be obtained from the second storage space to construct the target mirror Bloom filter. Since the Bloom filter is used to store the unexpired revocation authentication information, the unexpired revocation authentication information can be obtained to construct the target mirror Bloom filter. Correspondingly, a compressed target mirror Bloom filter can be stored in the third storage space for use when starting up next time.

[0065] In a possible way, the target mirror Bloom filter is constructed by the mirror center in the following manner: In response to the restart of the mirror center, the latest compressed mirror Bloom filter is loaded from the third storage space, which is used to store the compressed mirror Bloom filters corresponding to the mirror Bloom filters historically constructed by the mirror center; according to the timestamp corresponding to the latest compressed mirror Bloom filter, the unexpired fourth revocation authentication information stored after the timestamp is obtained from the second storage space, which is used to persistently store the full amount of revocation authentication information; the target mirror Bloom filter is constructed based on the latest compressed mirror Bloom filter and the fourth revocation authentication information.

[0066] Exemplarily, continuing to refer to Figure 6 , when the mirror center restarts, the latest compressed mirror Bloom filter can be loaded from the third storage space, and then, according to the timestamp at the time of the backup of the mirror Bloom filter corresponding to the compressed mirror Bloom filter, the incremental revocation authentication information after the timestamp is obtained from the second storage space. Here, the unexpired revocation authentication information can also be obtained. In this way, by combining the compressed mirror Bloom filter and the fourth revocation authentication information to construct the target mirror Bloom filter of the mirror center, the loss of revocation authentication information can be avoided, while ensuring the data integrity of the target mirror Bloom filter and reducing the cold start duration of the mirror center.

[0067] In other possible ways, the persistently stored mirror Bloom filter can record the time A of the last revocation authentication information. After the mirror pull is completed, the latest revocation authentication information in the MQ can continue to be consumed, and the time B of the first consumption record can be recorded. In this way, the revocation authentication information stored in the time range of A - B in the second storage space can be pulled. Additionally, to prevent errors in the times A and B, the revocation authentication information in the time range from (A - x) to (B + x) can be pulled, where x can be set according to requirements, and the present disclosure does not limit this.

[0068] In a possible way, the authentication information storage method further includes: receiving a device authentication verification request through a service instance, and when the authentication information to be verified carried in the device authentication verification request is revocation authentication information, sending the authentication information to be verified to the first storage space for verification, where the first storage space is a key - value storage database for caching the full amount of revocation authentication information; receiving the verification result returned by the first storage space.

[0069] Exemplarily, when performing the authentication revocation check, since the Bloom filter sacrifices some accuracy, it is necessary to perform a secondary verification on the device authentication information. For example Figure 8As shown, the service provider and the service instance are the same device. To distinguish and separately represent the timing of the verification steps, after receiving an authentication verification request, the service provider queries in the sharded Bloom filter whether there is corresponding revoked authentication information according to the device authentication information carried in the authentication verification request. If no corresponding revoked authentication information is found, the device authentication information has not been revoked and the authentication verification passes. If corresponding revoked authentication information is found, the device authentication information is further sent to the first storage space for accuracy verification. If the revoked authentication information corresponding to the device authentication information is found in the first storage space, a verification result indicating that the device authentication information has been revoked is returned. Thus, the accuracy rate of authentication revocation check can be further improved.

[0070] In the above storage architecture, by constructing a sharded Bloom filter in each service instance, it is possible to cache a large amount of revoked authentication information in the edge computing scenario with a small memory space, automatically delete expired revoked authentication information, and implement a memory caching solution with an interception rate of more than 99% for authentication revocation check, greatly reducing the number of request networks, improving service performance, and maintaining a stable accuracy rate of authentication revocation check without reducing reliability over time. In addition, through the design of the mirror center, the startup time of the sharded Bloom filter is greatly shortened. After the sharded Bloom filter of the mirror center is fully loaded, a subsequent MQ broadcast scheme is used to continuously and real-time incrementally construct an incremental sharded Bloom filter, improving the timeliness of authentication revocation check.

[0071] Based on the same inventive concept, an embodiment of the present disclosure provides an authentication information storage system for an edge computing device, as Figure 9 shown. The authentication information storage system 900 includes: A controller 901, configured to receive a device revocation request, determine first revoked authentication information according to the device authentication information carried in the device revocation request, and send the first revoked authentication information to service instances of the cluster. The service instances include a plurality of sharded Bloom filters, and one sharded Bloom filter is used to store revoked authentication information with an effective expiration time within a corresponding preset time interval; A service instance 902, configured to, in response to receiving the first revoked authentication information, determine a first sharded Bloom filter from the plurality of sharded Bloom filters according to the effective expiration time of the first revoked authentication information and the preset time intervals corresponding to the plurality of sharded Bloom filters, and store the first revoked authentication information in the first sharded Bloom filter; The service instance 902 is configured to, in response to all the revoked authentication information stored in the first sharded Bloom filter being expired, clear all the revoked authentication information stored in the first sharded Bloom filter.

[0072] Optionally, the service instance 902 is configured to: In response to all the revoked authentication information stored in the first sharded Bloom filter having expired, mark the first sharded Bloom filter as a sharded Bloom filter to be emptied, and enable an idle sharded Bloom filter, where the idle sharded Bloom filter corresponds to a new preset time interval; Empty all the revoked authentication information stored in the first sharded Bloom filter; The service instance 902 is further configured to: Mark the emptied first sharded Bloom filter as an idle sharded Bloom filter.

[0073] Optionally, the authentication information storage system 900 further includes a first storage space, where the first storage space is a key-value storage database for caching all revoked authentication information, and the service instance 902 is further configured to: Receive a device authentication verification request, and when the authentication information to be verified carried in the device authentication verification request is revoked authentication information, send the authentication information to be verified to the first storage space for verification; Receive the verification result returned by the first storage space.

[0074] Optionally, the authentication information storage system 900 further includes a mirror center; The mirror center is configured to store a target authentication information queue and a target mirror Bloom filter, where the target authentication information queue is used to store revoked authentication information received after the target mirror Bloom filter is constructed; The service instance 902 is further configured to, in response to the startup of the service instance, obtain the target authentication information queue and the target mirror Bloom filter from the mirror center, and construct a sharded Bloom filter of the service instance according to the target authentication information queue and the target mirror Bloom filter.

[0075] Optionally, the service instance 902 is configured to: When the mirror center includes a first authentication information queue, a second authentication information queue, a first mirror Bloom filter, and a second mirror Bloom filter, obtain the first authentication information queue, the second authentication information queue, and the first mirror Bloom filter from the mirror center; Wherein, the second mirror Bloom filter is obtained by copying the first mirror Bloom filter, the first authentication information queue is used to store revoked authentication information received after the first mirror Bloom filter is constructed and before the second mirror Bloom filter is copied, and the second authentication information queue is used to store revoked authentication information received after the second mirror Bloom filter is copied; The service instance 902 is configured to: Construct a sharded Bloom filter for the service instance based on the first authentication information queue, the second authentication information queue, and the first mirror Bloom filter.

[0076] Optionally, the mirror center is used for: In response to receiving the second revocation authentication information, write the second revocation authentication information into the first authentication information queue, where the first authentication information queue is used to store the revocation authentication information received after constructing the first mirror Bloom filter stored in the mirror center; Copy the first mirror Bloom filter to obtain a second mirror Bloom filter; Write the revocation authentication information in the first authentication information queue into the second mirror Bloom filter to obtain the target mirror Bloom filter.

[0077] Optionally, the mirror center is used for: Construct a second authentication information queue and stop writing the received revocation authentication information into the first authentication information queue. The second authentication information queue is used to store the revocation authentication information received after obtaining the second mirror Bloom filter by copying; Delete the first authentication information queue and the first mirror Bloom filter.

[0078] Optionally, the authentication information storage system 900 further includes a second storage space for persistently storing all revocation authentication information. The mirror center is used for: In response to the initial startup of the mirror center, obtain unexpired third revocation authentication information from the second storage space; Construct the target mirror Bloom filter based on the third revocation authentication information.

[0079] Optionally, the authentication information storage system 900 further includes a second storage space and a third storage space. The second storage space is used for persistently storing all revocation authentication information, and the third storage space is used for storing the compressed mirror Bloom filter corresponding to the mirror Bloom filter historically constructed by the mirror center. The mirror center is used for: In response to the restart of the mirror center, load the latest compressed mirror Bloom filter from the third storage space; According to the timestamp corresponding to the latest compressed mirror Bloom filter, obtain unexpired fourth revocation authentication information stored after the timestamp from the second storage space; Construct the target mirror Bloom filter based on the latest compressed mirror Bloom filter and the fourth revocation authentication information.

[0080] Optionally, the service instance 902 is further used for: In response to the update of the service instance, obtain a target authentication information queue and a target mirror Bloom filter from the mirror center, where the target authentication information queue is used to store revocation authentication information received after the target mirror Bloom filter is constructed; Update the shard Bloom filter of the service instance according to the target authentication information queue and the target mirror Bloom filter.

[0081] For the interaction process between the controller, service instance, mirror center, first storage space, second storage space, and third storage space in the above storage system of device authentication information, reference can be made to the embodiments of the above method for storing authentication information of edge computing devices, and details are not described herein again in the present disclosure.

[0082] Based on the same concept, an embodiment of the present disclosure further provides a computer-readable medium, on which a computer program is stored, and when the program is executed by a processing device, the steps of the above method for storing authentication information of edge computing devices are implemented.

[0083] Based on the same concept, an embodiment of the present disclosure further provides an electronic device, which may include: A storage device, on which a computer program is stored; A processing device, configured to execute the computer program in the storage device to implement the steps of the above method for storing authentication information of edge computing devices.

[0084] Based on the same concept, an embodiment of the present disclosure further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the above method for storing authentication information of edge computing devices are implemented.

[0085] Next, refer to Figure 10 , which shows a schematic structural diagram of an electronic device 1000 suitable for implementing the embodiments of the present disclosure. The terminal devices in the embodiments of the present disclosure may include, but are not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 10 The shown electronic device is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.

[0086] As Figure 10As shown, the electronic device 1000 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 1001, which may perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1002 or a program loaded from a storage device 1008 into a random access memory (RAM) 1003. In the RAM 1003, various programs and data required for the operation of the electronic device 1000 are also stored. The processing device 1001, the ROM 1002, and the RAM 1003 are connected to each other through a bus 1004. An input / output (I / O) interface 1005 is also connected to the bus 1004.

[0087] Generally, the following devices may be connected to the I / O interface 1005: an input device 1006 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 1007 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 1008 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the electronic device 1000 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 10 an electronic device 1000 with various devices is shown, it should be understood that it is not required to implement or have all the shown devices. Instead, more or fewer devices may be implemented or had.

[0088] Specifically, according to an embodiment of the present disclosure, the process described above with reference to the flowchart may be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for performing the method shown in the flowchart. In such an embodiment, the computer program may be downloaded and installed from a network through the communication device 1009, or installed from the storage device 1008, or installed from the ROM 1002. When the computer program is executed by the processing device 1001, the above functions defined in the method of the embodiment of the present disclosure are executed.

[0089] It should be noted that the above-mentioned computer-readable medium in the present disclosure may be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium may be any tangible medium that contains or stores a program, and the program may be used by or in combination with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, in which computer-readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium may also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable signal medium may send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0090] In some embodiments, communication can be performed using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0091] The above-mentioned computer-readable medium may be included in the above-mentioned electronic device; or it may exist separately and not be assembled into the electronic device.

[0092] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: in response to a service instance of a cluster receiving first revocation authentication information, determine a first sharded Bloom filter from the multiple sharded Bloom filters according to the effective expiration time of the first revocation authentication information and a preset time interval corresponding to the multiple sharded Bloom filters of the service instance, and store the first revocation authentication information in the first sharded Bloom filter, where a sharded Bloom filter is used to store revocation authentication information with an effective expiration time within the corresponding preset time interval; and cause the service instance to empty all the revocation authentication information stored in the first sharded Bloom filter in response to all the revocation authentication information stored in the first sharded Bloom filter expiring.

[0093] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on the remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).

[0094] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur in an order different from that noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0095] The modules involved in the embodiments of the present disclosure can be implemented in software or in hardware. In some cases, the name of a module does not constitute a limitation on the module itself.

[0096] The functions described above herein can be performed, at least in part, by one or more hardware logic components. By way of example, and without limitation, the types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0097] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0098] The above description is only a preferred embodiment of the present disclosure and an illustration of the technical principles applied. Those skilled in the art should understand that the scope of the disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, a technical solution formed by mutually replacing the above features with technical features having similar functions (but not limited to) disclosed in the present disclosure.

[0099] In addition, although the operations are depicted in a particular order, this should not be construed as requiring that the operations be performed in the particular order shown or in sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, although a number of specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments may also be implemented combinatorially in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0100] Although the subject matter has been described in language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. On the contrary, the specific features and acts described above are merely example forms for implementing the claims. Regarding the apparatus in the above embodiments, the specific manner in which each module performs operations has been described in detail in the embodiments related to the method, and will not be elaborated here.

Claims

1. A method for storing authentication information of an edge computing device, characterized in that, The described authentication information storage method includes: In response to a service instance of a cluster receiving first revocation authentication information, determining a first sharded Bloom filter from the multiple sharded Bloom filters according to the effective expiration time of the first revocation authentication information and the preset time intervals corresponding to the multiple sharded Bloom filters of the service instance, and storing the first revocation authentication information in the first sharded Bloom filter, where a sharded Bloom filter is used to store revocation authentication information with an effective expiration time within the corresponding preset time interval; By the service instance, in response to all the revocation authentication information stored in the first sharded Bloom filter expiring, clearing all the revocation authentication information stored in the first sharded Bloom filter.

2. The authentication information storage method for the edge computing device according to claim 1, characterized in that, The step of "By the service instance, in response to all the revocation authentication information stored in the first sharded Bloom filter expiring, clearing all the revocation authentication information stored in the first sharded Bloom filter" includes: By the service instance, in response to all the revocation authentication information stored in the first sharded Bloom filter expiring, marking the first sharded Bloom filter as a sharded Bloom filter to be cleared, and enabling an idle sharded Bloom filter, where the idle sharded Bloom filter corresponds to a new preset time interval; By the service instance, clearing all the revocation authentication information stored in the first sharded Bloom filter; The authentication information storage method further includes: By the service instance, marking the cleared first sharded Bloom filter as an idle sharded Bloom filter.

3. The authentication information storage method of the edge computing device according to claim 1, wherein, The authentication information storage method further includes: By the service instance, receiving a device authentication verification request, and when the authentication information to be verified carried in the device authentication verification request is revocation authentication information, sending the authentication information to be verified to a first storage space for verification, where the first storage space is a key-value storage database for caching all revocation authentication information; Receiving the verification result returned by the first storage space.

4. The authentication information storage method for the edge computing device according to any one of claims 1-3, characterized in that, The authentication information storage method further includes: In response to the startup of the service instance, by the service instance, obtaining a target authentication information queue and a target mirror Bloom filter from an image center, where the target authentication information queue is used to store revocation authentication information received after the construction of the target mirror Bloom filter; By the service instance, constructing the sharded Bloom filter of the service instance according to the target authentication information queue and the target mirror Bloom filter.

5. The authentication information storage method for the edge computing device according to claim 4, characterized in that The step of "By the service instance, obtaining a target authentication information queue and a target mirror Bloom filter from an image center" includes: When the image center includes a first authentication information queue, a second authentication information queue, a first mirror Bloom filter, and a second mirror Bloom filter, by the service instance, obtaining the first authentication information queue, the second authentication information queue, and the first mirror Bloom filter from the image center; Among them, the second mirrored Bloom filter is obtained by replicating the first mirrored Bloom filter. The first authentication information queue is used to store revocation authentication information received after the construction of the first mirrored Bloom filter and before the replication to obtain the second mirrored Bloom filter. The second authentication information queue is used to store revocation authentication information received after the replication to obtain the second mirrored Bloom filter; The method for the service instance to construct the sharded Bloom filter of the service instance according to the target authentication information queue and the target mirrored Bloom filter includes: The service instance constructs the sharded Bloom filter of the service instance based on the first authentication information queue, the second authentication information queue, and the first mirrored Bloom filter.

6. The authentication information storage method of the edge computing device according to claim 4, wherein The target mirrored Bloom filter is constructed by the mirror center in the following manner: In response to receiving the second revocation authentication information, write the second revocation authentication information into the first authentication information queue. The first authentication information queue is used to store revocation authentication information received after the construction of the first mirrored Bloom filter stored in the mirror center; Replicate the first mirrored Bloom filter to obtain a second mirrored Bloom filter; Write the revocation authentication information in the first authentication information queue into the second mirrored Bloom filter to obtain the target mirrored Bloom filter.

7. The authentication information storage method of the edge computing device according to claim 6, characterized in that, The authentication information storage method further includes: The mirror center constructs a second authentication information queue and stops writing the received revocation authentication information into the first authentication information queue. The second authentication information queue is used to store revocation authentication information received after the replication to obtain the second mirrored Bloom filter; Delete the first authentication information queue and the first mirrored Bloom filter.

8. The authentication information storage method of the edge computing device according to claim 4, wherein The target mirrored Bloom filter is constructed by the mirror center in the following manner: In response to the initial startup of the mirror center, obtain unexpired third revocation authentication information from the second storage space. The second storage space is used for persistent storage of the full amount of revocation authentication information; Construct the target mirrored Bloom filter based on the third revocation authentication information.

9. The authentication information storage method for the edge computing device according to claim 4, characterized in that, The target mirrored Bloom filter is constructed by the mirror center in the following manner: In response to the restart of the mirror center, load the latest compressed mirrored Bloom filter from the third storage space. The third storage space is used to store the compressed mirrored Bloom filter corresponding to the mirrored Bloom filter historically constructed by the mirror center; According to the timestamp corresponding to the latest compressed mirrored Bloom filter, obtain unexpired fourth revocation authentication information stored after the timestamp from the second storage space. The second storage space is used for persistent storage of the full amount of revocation authentication information; Construct the target mirrored Bloom filter based on the latest compressed mirrored Bloom filter and the fourth revocation authentication information.

10. The authentication information storage method for the edge computing device according to any one of claims 1-3, characterized in that, The authentication information storage method further includes: In response to an update of the service instance, obtain a target authentication information queue and a target mirror Bloom filter from a mirror center through the service instance, where the target authentication information queue is used to store revocation authentication information received after the target mirror Bloom filter is constructed; Update a shard Bloom filter of the service instance by the service instance according to the target authentication information queue and the target mirror Bloom filter.

11. An authentication information storage system for an edge computing device, characterized in that, The authentication information storage system includes: A controller, configured to receive a device revocation request, determine first revocation authentication information according to device authentication information carried in the device revocation request, and send the first revocation authentication information to service instances of a cluster, where the service instances include a plurality of shard Bloom filters, and one shard Bloom filter is used to store revocation authentication information whose valid expiration time is within a corresponding preset time interval; The service instance, configured to, in response to receiving the first revocation authentication information, determine a first shard Bloom filter from the plurality of shard Bloom filters according to the valid expiration time of the first revocation authentication information and the preset time intervals corresponding to the plurality of shard Bloom filters, and store the first revocation authentication information in the first shard Bloom filter; The service instance, configured to, in response to all revocation authentication information stored in the first shard Bloom filter expiring, clear all revocation authentication information stored in the first shard Bloom filter.

12. The authentication information storage system of the edge computing device according to claim 11, wherein The authentication information storage system further includes a mirror center; The mirror center, configured to store a target authentication information queue and a target mirror Bloom filter, where the target authentication information queue is used to store revocation authentication information received after the target mirror Bloom filter is constructed; The service instance is further configured to, in response to startup of the service instance, obtain the target authentication information queue and the target mirror Bloom filter from the mirror center, and construct a shard Bloom filter of the service instance according to the target authentication information queue and the target mirror Bloom filter.

13. A computer-readable medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processing device, the steps of the method according to any one of claims 1-10 are implemented.

14. An electronic device, characterized in that, including: A storage device, on which a computer program is stored; A processing device, configured to execute the computer program in the storage device to implement the steps of the method according to any one of claims 1-10.

15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1-10 are implemented.

Citation Information

Patent Citations

  • Digital certificate verification method and device

    CN105592059A

  • Block chain based digital certificate deleting method, device and system

    CN108696356A

  • Data deletion method and device, computer equipment and storage medium

    CN109828721A

  • Data judgment method, device and equipment and computer readable storage medium

    CN110990640A

  • Bloom filter-based edge node stateless identity verification method

    CN118118187A

Cited By

  • Certificate state query and update method based on three-layer filter

    CN120567582A