Method and system for safely accessing Ali cloud OSS address
Through encryption and decryption technology combined with edge scripts of Alibaba Cloud CDN, users can access the Alibaba Cloud OSS address securely without changing the Bucket's public read permissions, solving the problem of users illegally modifying paths and parameters.
Patent Information
- Application Number
- CN202510699704.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, users can access the Alibaba Cloud OSS address by changing the URL address path or removing the OSS parameters, resulting in security issues with the Bucket's public read permissions.
By encrypting the target URL address and using Alibaba Cloud CDN's edge script decryption, the rewrite back to the source URL operation is realized, hiding the storage path and OSS parameters, ensuring that the user cannot change the path and parameters.
Without changing the Bucket public read permissions, users can access the Alibaba Cloud OSS address securely, preventing illegal modification of paths and parameters.
Smart Images

Figure CN120342760A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network security technology, and in particular to a method and system for securely accessing Alibaba Cloud OSS addresses. Background Art
[0002] In Alibaba Cloud OSS (Object Storage Service), the URL (Uniform Resource Locator) address rule is "domain name + object path", such as: "http: / / xxx.oss.com / a / b / c.jpg". Bucket is the basic container for storing data in Alibaba Cloud OSS. If the permission of the Bucket allows public reading, then the user can access other OSS files by changing the URL address path. Or, if there are some OSS parameters added to the end of a URL address, and these OSS parameters support the processing of images, then the user can directly remove the OSS parameters at the end to get the original image file. Therefore, how to enable users to access the Alibaba Cloud OSS address in a way that cannot change the path address and parameters without changing the public read permission of the Bucket is an urgent problem to be solved. Summary of the invention
[0003] The purpose of this application is to provide a method and system for securely accessing Alibaba Cloud OSS addresses, which can enable users to access Alibaba Cloud OSS addresses in a way that the path address and parameters cannot be changed without changing the public read permissions of the Bucket.
[0004] To achieve the above objectives, this application provides the following solutions:
[0005] First, the present application provides a method for securely accessing the Alibaba Cloud OSS address, including:
[0006] The client initiates an access request to Alibaba Cloud CDN based on the encrypted target URL address;
[0007] After receiving the access request sent by the client, Alibaba Cloud CDN uses the configured edge script to decrypt the encrypted target URL address to obtain the target URL address;
[0008] Alibaba Cloud CDN rewrites the target URL address back to the source URL to obtain the corresponding source site OSS URL address.
[0009] In the second aspect, this application provides a system for securely accessing Alibaba Cloud OSS addresses, including:
[0010] The client is used to initiate an access request to Alibaba Cloud CDN based on the encrypted target URL address;
[0011] Alibaba Cloud CDN, used for:
[0012] After receiving an access request sent by a client, use the configured edge script to decrypt the encrypted target URL address to obtain the target URL address;
[0013] According to the target URL address, perform a rewrite back to the source URL operation to obtain the corresponding origin OSS URL address.
[0014] According to the specific embodiments provided by this application, this application has the following technical effects:
[0015] This application provides a method and system for securely accessing Alibaba Cloud OSS addresses. The client sends an access request to Alibaba Cloud CDN based on the encrypted target URL address. Since the encrypted target URL address hides the storage path and OSS parameters in the target URL address, users are unable to modify the target URL address. Then, after receiving the access request sent by the client, Alibaba Cloud CDN uses the configured edge script to decrypt the encrypted target URL address to obtain the target URL address, and according to the target URL address, performs a rewrite back to the source URL operation to obtain the corresponding origin OSS URL address, thus realizing the normal access of users to Alibaba Cloud OSS addresses. By using encryption-decryption technology and the edge script of Alibaba Cloud CDN, this application enables users to access Alibaba Cloud OSS addresses in a way that cannot modify the path address and parameters without changing the public read permission of the Bucket. BRIEF DESCRIPTION OF THE DRAWINGS
[0016] In order to more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0017] Figure 1 It is a flowchart of a method for securely accessing Alibaba Cloud OSS addresses provided by an embodiment of this application;
[0018] Figure 2 It is a flowchart of another method for securely accessing Alibaba Cloud OSS addresses provided by an embodiment of this application;
[0019] Figure 3 It is a schematic diagram of a system for securely accessing Alibaba Cloud OSS addresses provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0020] Edge scripts have built-in variables and simple judgment statements that can be recognized by Alibaba Cloud CDN nodes, and provide a large number of Alibaba Cloud CDN packaged functions for direct calling. Through simple variable judgment and calling ready-made functions, most customized authentication, caching, speed limit, request header increase and decrease and other customized configuration requirements can be met, which can effectively solve the problem of customized configuration requirements cannot be realized and business changes are not agile.
[0021] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0022] In order to make the above-mentioned objects, features and advantages of the present application more obvious and easy to understand, the present application is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.
[0023] In an exemplary embodiment, Figure 1 As shown, a method for securely accessing the Alibaba Cloud OSS address is provided, including the following steps 101 to 103. Among them:
[0024] Step 101: The client initiates an access request to Alibaba Cloud CDN based on the encrypted target URL address.
[0025] Step 102: After receiving the access request sent by the client, Alibaba Cloud CDN uses the configured edge script to decrypt the encrypted target URL address to obtain the target URL address.
[0026] Step 103: Alibaba Cloud CDN rewrites the target URL address back to the source URL to obtain the corresponding source site OSS URL address.
[0027] In another exemplary embodiment, the method for securely accessing the Alibaba Cloud OSS address further includes:
[0028] The server encrypts the target URL address using an encryption algorithm to obtain the encrypted target URL address, and sends the encrypted target URL address to the client.
[0029] In another exemplary embodiment, the method for securely accessing the Alibaba Cloud OSS address further includes:
[0030] The server configures an edge script according to the decryption algorithm corresponding to the encrypted target URL address, obtains the configured edge script, and publishes the configured edge script to Alibaba Cloud CDN.
[0031] As an alternative implementation, the target URL address includes a domain name and a storage path; the server encrypts the target URL address using an encryption algorithm to obtain the encrypted target URL address, specifically including:
[0032] The server encrypts the storage path in the target URL address using an encryption algorithm to obtain the encrypted target URL address.
[0033] As an alternative implementation, the target URL address includes a domain name, a storage path, and OSS parameters; the server encrypts the target URL address using an encryption algorithm to obtain the encrypted target URL address, specifically including:
[0034] The server encrypts the storage path and OSS parameters in the target URL address using an encryption algorithm to obtain the encrypted target URL address.
[0035] In another exemplary embodiment, the method for securely accessing an Alibaba Cloud OSS address further includes:
[0036] (10-1) Alibaba Cloud CDN initiates an access request to the origin OSS according to the corresponding origin OSS URL address.
[0037] (10-2) The origin OSS receives the access request initiated by Alibaba Cloud CDN, and locates the corresponding resource according to the corresponding origin OSS URL. If the corresponding resource exists, the origin OSS returns the corresponding resource to Alibaba Cloud CDN.
[0038] (10-3) Alibaba Cloud CDN receives the corresponding resource returned by the origin OSS and returns the corresponding resource to the client.
[0039] In another exemplary embodiment, referring to Figure 2 , another method for securely accessing an Alibaba Cloud OSS address is provided, including the following steps:
[0040] Step 201, the server encrypts the target URL (corresponding to the URL in Figure 2 ) address using AES encryption (corresponding to AES-ECB encryption in Figure 2 ) and sends the encrypted target URL to the client.
[0041] For example, encrypt: "http: / / www.oss.com / a / b / c.jpg",
[0042] into: "http: / / www.oss.com / 217e22ffcfc083ee0d5043d2d21bb412".
[0043] Step 202, the client sends an access request to Alibaba Cloud CDN (i.e., Figure 2 the CDN in [description]), requesting to access the encrypted target URL.
[0044] Step 203, after receiving the access request, Alibaba Cloud CDN performs edge computing based on the configured edge script to perform AES decryption on the encrypted target URL.
[0045] For example, decrypt: "http: / / www.oss.com / 217e22ffcfc083ee0d5043d2d21bb412",
[0046] into: "http: / / www.oss.com / a / b / c.jpg".
[0047] Step 204, after decryption, Alibaba Cloud CDN rewrites the back-to-source URL and requests to access the origin OSS.
[0048] Step 205, after receiving the request, the origin OSS returns the response content (corresponding resource) to the Alibaba Cloud CDN node.
[0049] Step 206, the client obtains the request result (corresponding resource) and directly displays it.
[0050] This embodiment realizes the OSS address mapping and hides the real address based on CDN rewrite back-to-source URL and edge script. It enables users to access the Alibaba Cloud OSS address in a way that the path address and parameters cannot be changed without changing the public read permission of the bucket.
[0051] The method for securely accessing the Alibaba Cloud OSS address provided in this embodiment can be applied to scenarios where the Alibaba Cloud OSS address is securely accessed.
[0052] Based on the same inventive concept, the embodiment of the present application also provides a system for securely accessing the Alibaba Cloud OSS address. The implementation solution provided by this system to solve the problem is similar to the implementation solution described in the above method. Therefore, the specific limitations in the embodiment of the system for securely accessing the Alibaba Cloud OSS address provided below can refer to the limitations on the method for securely accessing the Alibaba Cloud OSS address in the above text, and will not be elaborated here.
[0053] In an exemplary embodiment, as Figure 3 shown, a system for securely accessing an Alibaba Cloud OSS address is provided, including:
[0054] A client for sending an access request to Alibaba Cloud CDN according to the encrypted target URL address.
[0055] Alibaba Cloud CDN for:
[0056] After receiving the access request sent by the client, decrypting the encrypted target URL address using the configured edge script to obtain the target URL address;
[0057] Performing a rewrite back to the source URL operation according to the target URL address to obtain the corresponding source OSS URL address.
[0058] In an exemplary embodiment, the system for securely accessing an Alibaba Cloud OSS address further includes:
[0059] A server for:
[0060] Encrypting the target URL address using an encryption algorithm to obtain the encrypted target URL address, and sending the encrypted target URL address to the client;
[0061] Configuring an edge script according to the decryption algorithm corresponding to the encrypted target URL address to obtain the configured edge script, and publishing the configured edge script to Alibaba Cloud CDN.
[0062] As an alternative implementation, the target URL address includes a domain name and a storage path; the server encrypts the target URL address using an encryption algorithm to obtain the encrypted target URL address, specifically including:
[0063] The server encrypts the storage path in the target URL address using an encryption algorithm to obtain the encrypted target URL address.
[0064] As an alternative implementation, the target URL address includes a domain name, a storage path, and OSS parameters; the server encrypts the target URL address using an encryption algorithm to obtain the encrypted target URL address, specifically including:
[0065] The server encrypts the storage path and OSS parameters in the target URL address using an encryption algorithm to obtain the encrypted target URL address.
[0066] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0067] Specific examples are used in this article to elaborate on the principles and implementation manners of the present application. The descriptions of the above embodiments are only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A method for securely accessing Alibaba Cloud OSS addresses, characterized in that, Including: The client sends an access request to Alibaba Cloud CDN according to the encrypted target URL address; After receiving the access request sent by the client, Alibaba Cloud CDN decrypts the encrypted target URL address by using the configured edge script to obtain the target URL address; Alibaba Cloud CDN performs a rewrite back-to-origin URL operation according to the target URL address to obtain the corresponding origin OSS URL address.
2. The method for securely accessing the Alibaba Cloud OSS address according to claim 1, wherein Also including: The server encrypts the target URL address by using an encryption algorithm to obtain the encrypted target URL address, and sends the encrypted target URL address to the client.
3. The method for securely accessing the Alibaba Cloud OSS address according to claim 2, wherein Also including: The server configures the edge script according to the decryption algorithm corresponding to the encrypted target URL address to obtain the configured edge script, and publishes the configured edge script to Alibaba Cloud CDN.
4. The method for securely accessing the Alibaba Cloud OSS address according to claim 2, wherein Also including: The target URL address includes a domain name and a storage path; The server encrypts the target URL address by using an encryption algorithm to obtain the encrypted target URL address, specifically including: The server encrypts the storage path in the target URL address by using an encryption algorithm to obtain the encrypted target URL address.
5. The method for securely accessing the Alibaba Cloud OSS address according to claim 2, wherein The target URL address includes a domain name, a storage path, and OSS parameters; The server encrypts the target URL address by using an encryption algorithm to obtain the encrypted target URL address, specifically including: The server encrypts the storage path and OSS parameters in the target URL address by using an encryption algorithm to obtain the encrypted target URL address.
6. The method for securely accessing the Alibaba Cloud OSS address according to claim 1, wherein Also including: Alibaba Cloud CDN sends an access request to the origin OSS according to the corresponding origin OSS URL address; The origin OSS receives the access request sent by Alibaba Cloud CDN, and searches for the corresponding resource according to the corresponding origin OSS URL. If the corresponding resource exists, the corresponding resource is returned to Alibaba Cloud CDN; Alibaba Cloud CDN receives the corresponding resource returned by the origin OSS, and returns the corresponding resource to the client.
7. A system for securely accessing Alibaba Cloud OSS addresses, characterized in that, Including: A client, configured to send an access request to Alibaba Cloud CDN according to the encrypted target URL address; Alibaba Cloud CDN, configured to: After receiving the access request sent by the client, decrypt the encrypted target URL address by using the configured edge script to obtain the target URL address; Perform a rewrite back-to-origin URL operation according to the target URL address to obtain the corresponding origin OSS URL address.
8. The system for securely accessing the Alibaba Cloud OSS address according to claim 7, wherein Also including: A server, configured to: Encrypt the target URL address by using an encryption algorithm to obtain the encrypted target URL address, and send the encrypted target URL address to the client; Configure the edge script according to the decryption algorithm corresponding to the encrypted target URL address to obtain the configured edge script, and publish the configured edge script to Alibaba Cloud CDN.
9. The system for securely accessing the Alibaba Cloud OSS address according to claim 8, wherein, The target URL address includes a domain name and a storage path; The server encrypts the target URL address by using an encryption algorithm to obtain the encrypted target URL address, specifically including: The server encrypts the storage path in the target URL address using an encryption algorithm to obtain the encrypted target URL address.
10. The system for securely accessing the Alibaba Cloud OSS address according to claim 8, wherein The target URL address includes a domain name, a storage path, and OSS parameters; The server encrypts the target URL address using an encryption algorithm to obtain the encrypted target URL address, specifically including: The server encrypts the storage path and OSS parameters in the target URL address using an encryption algorithm to obtain the encrypted target URL address.