Service authorization method and device based on containerized node deployment, storage medium and computer program product
Through the ECC key exchange algorithm and the generation adversarial network, the problem of manual participation in multi-sport data leakage in traditional cloud platform service authorization is solved, and the efficient interaction and security of the cloud platform is achieved.
Patent Information
- Application Number
- CN202510420083.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-03
- Publication Date
- 2025-07-22
AI Technical Summary
The traditional cloud platform service authorization method has a lot of manual participation in online and offline links, and it is impossible to fully utilize the efficient interaction characteristics of the cloud platform. Moreover, the data is easily decrypted after the private key of the RSA algorithm is leaked, which poses a risk of information leakage.
The ECC key exchange algorithm is used to combine the generation adversarial network to generate elliptic curve parameters, and the authentication information is directly processed through the cloud platform, the authorized data is encrypted using the shared key and the AES algorithm, and the key is updated regularly to improve security.
Reduce manual participation, avoid data leakage, reduce the risk of side channel attacks, and ensure the security of cloud platform service authorization and real-time interaction efficiency.
Smart Images

Figure CN120354401A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of cloud platform service authorization, and particularly to a service authorization method, device, storage medium, and computer program product based on containerized node deployment. Background Art
[0002] Containerized deployment, as a lightweight and portable software packaging technology, allows developers to package an application together with its dependencies, configurations, and runtime environment into an executable container image. On a cloud platform, these containers can run independently, be isolated from each other, and have exclusive resources, thereby improving the deployment efficiency and scalability of applications. However, traditional cloud platform service authorization is usually implemented by a hybrid method of asymmetric encryption (RSA) and symmetric encryption (AES). This method involves a lot of manual participation in online and offline links and cannot fully utilize the real-time interaction and high efficiency characteristics of the cloud platform. In addition, although the RSA algorithm ensures the security of data to a certain extent, once its private key is leaked, attackers can deduce the public key and then decrypt the encrypted data. There is a risk of information leakage when using the hybrid method of asymmetric encryption (RSA) and symmetric encryption (AES) to implement cloud platform service authorization.
[0003] Therefore, how to utilize the efficient interaction of the cloud platform and improve the security of cloud platform service authorization has become an urgent problem to be solved in this application.
[0004] The above content is only used to assist in understanding the technical solution of this application and does not represent an admission that the above content is prior art. Summary of the Invention
[0005] The main objective of this application is to provide a service authorization method based on containerized node deployment, aiming to solve the technical problem of how to utilize the efficient interaction of the cloud platform and improve the security of cloud platform service authorization.
[0006] To achieve the above objective, this application proposes a service authorization method based on containerized node deployment, which is applied to a cloud platform. The cloud platform includes a service end and a background authorization end. The method includes:
[0007] Receiving authentication information provided by a service requester, where the authentication information includes a first exchange key algorithm public key and authorization data;
[0008] Calculating a shared key by using an ECC key exchange algorithm for the first exchange key algorithm public key and a second exchange key algorithm public key, where the elliptic curve parameters of the ECC key exchange algorithm are generated by using a pre-constructed generative adversarial network;
[0009] Encrypt the authorization data through the server based on the shared key and the AES algorithm to obtain encrypted authorization data, and send the encrypted authorization data to the background authorization end;
[0010] Decrypt the encrypted authorization data through the background authorization end, and regularly call the license verification process for service authorization, where the license verification process includes updating the shared key using the elliptic curve parameters.
[0011] In one embodiment, before the step of calculating the first exchange key algorithm public key and the second exchange key algorithm public key using the ECC key exchange algorithm to obtain a shared key, and the elliptic curve parameters of the ECC key exchange algorithm are generated using a pre-constructed generative adversarial network, the following steps are included:
[0012] Combine a linear layer, a pooling layer, and a convolutional layer to obtain a generator and a discriminator respectively;
[0013] Collect an initial set of elliptic curve parameters, and perform standardization processing on the initial set of elliptic curve parameters to remove outliers, obtaining a true set of elliptic curve parameters;
[0014] Generate random noise samples using a Gaussian distribution, and input the random noise samples into the generator to obtain a false set of elliptic curve parameters;
[0015] Input the false set of elliptic curve parameters, the true set of elliptic curve parameters, and labels into the discriminator, and optimize the model parameters using an adaptive learning rate algorithm;
[0016] Perform credibility discrimination on the optimized model parameters to obtain the generative adversarial network.
[0017] In one embodiment, the step of inputting the false set of elliptic curve parameters, the true set of elliptic curve parameters, and labels into the discriminator, and optimizing the model parameters using an adaptive learning rate algorithm includes:
[0018] Input the false set of elliptic curve parameters, the true set of elliptic curve parameters, and labels into the discriminator to obtain the discriminator output result;
[0019] Calculate the loss function according to the discriminator output result and the cross-entropy loss;
[0020] Update the discriminator and the generator according to the gradient of the loss function using an adaptive learning rate algorithm to optimize the model parameters.
[0021] In one embodiment, the step of performing credibility discrimination on the optimized model parameters to obtain the generative adversarial network includes:
[0022] Perform credibility discrimination on the optimized model parameters to obtain discrimination results. The credibility discrimination includes base point verification, order verification of the base point, strong prime number verification, and curve coefficient verification in the optimized model parameters;
[0023] Adjust the training iteration times according to the discrimination results to obtain the generative adversarial network.
[0024] In one embodiment, the step of calculating the shared key by using the ECC key exchange algorithm for the public key of the first key exchange algorithm and the public key of the second key exchange algorithm includes:
[0025] Analyze the authentication information to obtain the public key of the second key exchange algorithm, and the public key of the second key exchange algorithm is generated based on the default curve parameters of the ECC key exchange algorithm;
[0026] Perform key exchange calculation on the public key of the first key exchange algorithm and the public key of the second key exchange algorithm by using the ECC key exchange algorithm to obtain the shared key.
[0027] In one embodiment, the step of decrypting the encrypted authorization data by the background authorization end and regularly invoking the license verification process for service authorization includes:
[0028] Use the shared key to decrypt the encrypted authorization data for initial service authorization;
[0029] After the initial service authorization is completed, use the elliptic curve parameters to update the public key of the first key exchange algorithm and the public key of the second key exchange algorithm;
[0030] Update the shared key by the updated public key of the first key exchange algorithm and the public key of the second key exchange algorithm, and perform license verification based on the updated shared key.
[0031] In one embodiment, after the step of updating the shared key by the updated public key of the first key exchange algorithm and the public key of the second key exchange algorithm and performing license verification based on the updated shared key, it further includes:
[0032] Use the pre-constructed generative adversarial network to update the elliptic curve parameters;
[0033] After the elliptic curve parameters are updated, return to execute the step: use the elliptic curve parameters to update the public key of the first key exchange algorithm and the public key of the second key exchange algorithm.
[0034] In addition, to achieve the above object, the present application also proposes a service authorization device, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the service authorization method based on containerized node deployment as described above.
[0035] In addition, to achieve the above object, the present application also proposes a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by a processor, it implements the steps of the service authorization method based on containerized node deployment as described above.
[0036] In addition, to achieve the above object, the present application also provides a computer program product, which includes a computer program, and when the computer program is executed by a processor, it implements the steps of the service authorization method based on containerized node deployment as described above.
[0037] One or more technical solutions proposed by the present application have at least the following technical effects:
[0038] Receive the authentication information provided by the service requester, where the authentication information includes the public key of the first key exchange algorithm. By directly submitting the authentication information of the required authorized service through the cloud platform, there is no need for frequent online and offline communication, significantly reducing the links involving manual participation, thus giving full play to the real-time interaction feature of the cloud platform; the background authorization end of the cloud platform uses the ECC key exchange algorithm to calculate the shared key from the public key of the first key exchange algorithm and the public key of the second key exchange algorithm, and the elliptic curve parameters of the ECC key exchange algorithm are generated by using a pre-constructed generative adversarial network; the server end of the cloud platform encrypts the authorized data based on the shared key and the AES algorithm to obtain the encrypted authorized data. Using the ECC key exchange algorithm to replace the traditional RSA technology can avoid data leakage. The pre-constructed generative adversarial network is used to generate elliptic curve parameters, which are used in the ECC key exchange process, and can skip the protection limitations of known curves, reducing the risk of side-channel attacks faced by ECC; the background authorization end of the cloud platform decrypts the encrypted authorized data and invokes the license verification process for service authorization, where the license verification process includes updating the shared key using the elliptic curve parameters. Regularly invoking the license verification process and updating the shared key using the elliptic curve parameters can ensure the continuous update and security of the key, thereby improving the security of service authorization on the cloud platform. Description of the Drawings
[0039] The drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0040] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0041] Figure 1 The flowchart provided for the first embodiment of the service authorization method of the present application;
[0042] Figure 2 The flowchart provided for the second embodiment of the service authorization method of the present application;
[0043] Figure 3 The flowchart provided for the third embodiment of the service authorization method of the present application;
[0044] Figure 4 The flowchart provided for a feasible implementation manner in the third embodiment of the service authorization method of the present application;
[0045] Figure 5 The module structure diagram of the service authorization device in the embodiment of the present application;
[0046] Figure 6 The device structure diagram of the hardware operating environment involved in the service authorization method in the embodiment of the present application.
[0047] The realization of the purpose, functional features, and advantages of the present application will be further described with reference to the embodiments and the accompanying drawings. Specific Embodiments
[0048] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0049] To better understand the technical solutions of the present application, the following will be described in detail in combination with the accompanying drawings of the specification and specific embodiments.
[0050] The main solution of the embodiment of this application is as follows: The server of the cloud platform receives the authentication information provided by the service requester, and the authentication information includes the public key of the first key exchange algorithm and the authorization data; the background authorization end of the cloud platform uses the ECC key exchange algorithm to calculate the public key of the first key exchange algorithm and the public key of the second key exchange algorithm to obtain a shared key, and the elliptic curve parameters of the ECC key exchange algorithm are generated by using a pre-constructed generative adversarial network; the server of the cloud platform encrypts the authorization data based on the shared key and the AES algorithm to obtain encrypted authorization data; the background authorization end of the cloud platform decrypts the encrypted authorization data and regularly invokes the license verification process for service authorization, where the license verification process includes updating the shared key by using the elliptic curve parameters.
[0051] The embodiment of this application takes into account that: Since containerized deployment is a lightweight and portable software packaging technology, it allows developers to package an application together with its dependencies, configurations, and runtime environment into an executable container image. On the cloud platform, these containers can run independently, be isolated from each other, and enjoy exclusive resources, thereby improving the deployment efficiency and scalability of applications. However, traditional cloud platform service authorization is usually implemented by a hybrid method of asymmetric encryption (RSA) and symmetric encryption (AES). This method involves a lot of manual participation in online and offline links and cannot fully utilize the characteristics of real-time interaction and high efficiency of the cloud platform. In addition, although the RSA algorithm ensures the security of data to a certain extent, once its private key is leaked, an attacker can deduce the public key and then decrypt the encrypted data. There is a risk of information leakage in implementing cloud platform service authorization by using a hybrid method of asymmetric encryption (RSA) and symmetric encryption (AES).
[0052] Therefore, the present application provides a solution that receives authentication information provided by a service requester, where the authentication information includes a public key of a first key exchange algorithm. By directly submitting the authentication information of the required authorized service through the cloud platform, frequent online and offline communication is not required, significantly reducing the links involving manual participation, thereby giving full play to the real-time interaction feature of the cloud platform. The background authorization end of the cloud platform uses the ECC key exchange algorithm to calculate the first public key of the key exchange algorithm and the second public key of the key exchange algorithm to obtain a shared key. The elliptic curve parameters of the ECC key exchange algorithm are generated by using a pre-constructed generative adversarial network. The server end of the cloud platform encrypts the authorized data based on the shared key and the AES algorithm to obtain encrypted authorized data. Using the ECC key exchange algorithm to replace the traditional RSA technology can avoid data leakage. The pre-constructed generative adversarial network is used to generate elliptic curve parameters, which are used in the ECC key exchange process. It can skip the protection limitations of known curves and reduce the risk of side-channel attacks faced by ECC. The background authorization end of the cloud platform decrypts the encrypted authorized data and invokes a license verification process for service authorization, where the license verification process includes updating the shared key using the elliptic curve parameters. Regularly invoking the license verification process and updating the shared key using the elliptic curve parameters can ensure the continuous update and security of the key, thereby improving the security of service authorization on the cloud platform.
[0053] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication, and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device, a cloud platform, etc. that can implement the above functions. Hereinafter, the cloud platform is taken as an example to illustrate this embodiment and the following embodiments.
[0054] Based on this, the embodiment of the present application provides a service authorization method based on containerized node deployment, which is applied to a cloud platform. The cloud platform includes a server end and a background authorization end. Refer to Figure 1 , Figure 1 is a schematic flowchart of the first embodiment of the service authorization method based on containerized node deployment of the present application.
[0055] In this embodiment, the service authorization method based on containerized node deployment includes steps S10 to S40:
[0056] Step S10, receiving authentication information provided by a service requester, where the authentication information includes a first public key of a key exchange algorithm and authorized data;
[0057] Authentication information refers to a set of data provided by the service requester to the cloud platform for review to prove its legal identity. The authentication information particularly includes the first exchange key algorithm public key and authorization data. The first exchange key algorithm public key is a public key generated based on the Elliptic Curve Cryptography (ECC) algorithm and is used for subsequent key exchange processes.
[0058] The cloud platform, as the service provider, receives the authentication information from the service requester. The authentication information includes the first exchange key algorithm public key A generated using the Elliptic Curve Cryptography (ECC) algorithm. Specifically, the public key A is generated based on a default elliptic curve parameter. When the service requester requests service authorization, it submits the public key A and other necessary information (such as the required service type and duration) to the cloud platform.
[0059] Step S20: Calculate the shared key using the ECC key exchange algorithm for the first exchange key algorithm public key and the second exchange key algorithm public key. The elliptic curve parameter of the ECC key exchange algorithm is generated using a pre - constructed generative adversarial network.
[0060] The cloud platform receives the first exchange key algorithm public key (i.e., public key A) generated using the ECC algorithm. By parsing the authentication information provided by the service requester, it can determine the second exchange key algorithm public key (i.e., public key B). The background authorization end of the cloud platform can use the ECC key exchange algorithm to calculate a shared key K by combining public key A and public key B. In this process, no third party can easily obtain or deduce the shared key K, thus ensuring the security of the data.
[0061] Furthermore, the cloud platform uses a pre - constructed generative adversarial network (GAN) to generate elliptic curve parameters. Through the adversarial training of the generator and discriminator, the GAN model can generate realistic and highly confident data samples. The GAN is used to randomly generate elliptic curve parameters for the ECC algorithm. The generated elliptic curve parameters have high reliability and confidence, can effectively avoid the protection limitations of known curves, and reduce the risk of side - channel attacks faced by ECC.
[0062] Specifically, to effectively reduce the risk of side - channel attacks faced by ECC and enhance the security of the encryption process, during the initial authorization process, the cloud platform uses the default elliptic curve parameter to generate public key A and public key B, and generates the next curve parameter through GAN. When starting the license verification process, the cloud platform decrypts using the previous elliptic curve parameter and updates the new elliptic curve parameter for key generation. This process is repeated regularly to ensure the security and reliability of the encryption process.
[0063] Step S30: Encrypt the authorization data through the server based on the shared key and the AES algorithm to obtain encrypted authorization data, and send the encrypted authorization data to the background authorization end.
[0064] The AES algorithm is a symmetric encryption algorithm, that is, the same key is used for encryption and decryption. In this application, the shared key K obtained through the ECC key exchange algorithm is used as the key for the AES encryption algorithm.
[0065] The authorization data, that is, the relevant information of the service or resource that the service requester needs to be authorized to use, will be used as the input data for the AES encryption algorithm. The AES encryption algorithm will perform a series of encryption operations on the input data, including steps such as byte substitution, row shift, and column mixing, and finally generate the encrypted authorization data.
[0066] After being encrypted by the AES encryption algorithm, the original authorization data will be converted into an unreadable ciphertext, that is, the encrypted authorization data. Specifically, the cloud platform is divided into a server and a background authorization end. After the server encrypts to obtain the encrypted authorization data, it sends it to the background authorization end for decryption. After the background authorization end calculates the shared key K using the public key of the first exchange key algorithm and the public key of the second exchange key algorithm, it uses K to decrypt the encrypted authorization data, thereby realizing service authorization.
[0067] Step S40: Decrypt the encrypted authorization data through the background authorization end, and regularly call the license verification process to perform service authorization, where the license verification process includes updating the shared key using the elliptic curve parameters.
[0068] The background authorization end of the cloud platform first decrypts the encrypted authorization data. The service requester can submit the required authorization service information through the cloud platform, and can also decrypt the encrypted authorization data through the cloud platform. The encrypted authorization data contains the authorization information required by the service requester. By decrypting the encrypted authorization data, the service requester can obtain authorization immediately.
[0069] After decryption is completed, the cloud platform will regularly call the license verification process to ensure the continuous validity and security of service authorization. The core of this verification process is to update the shared key using the elliptic curve parameters. Specifically, the cloud platform will use the elliptic curve parameters generated in the previous verification process for decryption, and combine the newly received elliptic curve parameters currently, and recalculate the new shared key through the ECC key exchange algorithm.
[0070] This embodiment provides a service authorization method based on containerized node deployment, which receives authentication information provided by a service requester, and the authentication information includes a public key of a first key exchange algorithm. By directly submitting the authentication information of the required authorized service through the cloud platform, there is no need for frequent online and offline communication, significantly reducing the manual participation links, thus giving play to the real-time interaction characteristics of the cloud platform; the background authorization end of the cloud platform uses the ECC key exchange algorithm to calculate the public key of the first key exchange algorithm and the public key of the second key exchange algorithm to obtain a shared key, and the elliptic curve parameters of the ECC key exchange algorithm are generated by using a pre-constructed generative adversarial network; the service end of the cloud platform encrypts the authorized data based on the shared key and the AES algorithm to obtain encrypted authorized data. Using the ECC key exchange algorithm to replace the traditional RSA technology can avoid data leakage. The pre-constructed generative adversarial network is used to generate elliptic curve parameters, which are used in the ECC key exchange process, and can skip the protection restrictions of known curves, reducing the risk of side-channel attacks faced by ECC; the background authorization end of the cloud platform decrypts the encrypted authorized data and invokes the license verification process for service authorization, where the license verification process includes updating the shared key using the elliptic curve parameters. Regularly invoking the license verification process and updating the shared key using the elliptic curve parameters can ensure the continuous update and security of the key, thereby improving the security of cloud platform service authorization.
[0071] Specifically, in a feasible implementation manner, the step S20 of calculating the shared key by using the ECC key exchange algorithm for the public key of the first key exchange algorithm and the public key of the second key exchange algorithm may include steps S21 to S22:
[0072] Step S21, analyzing the authentication information to obtain the public key of the second key exchange algorithm, where the public key of the second key exchange algorithm is generated based on the default curve parameters of the ECC key exchange algorithm;
[0073] After the cloud platform receives the authentication information submitted by the service requester, it first analyzes this information in detail. The authentication information includes but is not limited to the identity information of the service requester, the selected service type, the service period, etc. The cloud platform uses this information and combines preset default curve parameters (these parameters are fixed parameters used to generate public keys in the elliptic curve cryptography (ECC) algorithm) to generate the public key of the second key exchange algorithm. This public key is based on the ECC algorithm and is specific to this authorization process, ensuring the uniqueness and security of the public key.
[0074] Step S22, performing a key exchange calculation on the public key of the first key exchange algorithm and the public key of the second key exchange algorithm by using the ECC key exchange algorithm to obtain the shared key.
[0075] The cloud platform uses the ECC key exchange algorithm to perform key exchange calculations on the first exchange key algorithm public key (public key A) and the second exchange key algorithm public key. This calculation process follows the principle of the ECC algorithm and generates a shared key (i.e., shared key K) through the public keys of both parties. This shared key K will be used in the subsequent encryption and decryption process to ensure the secure transmission of authorized data.
[0076] Based on the first embodiment of the present application, the second embodiment of the present application is proposed. In the second embodiment of the present application, the same or similar contents as those of the above-mentioned embodiment 1 can be referred to the above introduction, and will not be repeated in the following.
[0077] On this basis, please refer to Figure 2 Before step S20, the service authorization method based on containerized node deployment also includes steps S01 to S05:
[0078] Step S01, combining a linear layer, a pooling layer, and a convolutional layer to obtain a generator and a discriminator respectively;
[0079] In this application, both the generator and the discriminator are constructed using a deep learning model. Specifically, the network structure of the generator and the discriminator is formed by combining a linear layer, a pooling layer, and a convolutional layer.
[0080] Generator: Designed to receive random noise as input and generate fake elliptic curve parameters. Its internal structure is combined through multiple layers of linear transformations and nonlinear activation functions (such as ReLU) to capture the potential distribution characteristics of the data.
[0081] Discriminator: It is designed to distinguish whether the input data comes from a real elliptic curve parameter set or a fake elliptic curve parameter set generated by the generator. It also uses a multi-layer linear layer and convolution layer (possibly accompanied by a pooling layer) structure, and finally outputs a probability value, indicating the possibility that the input data is real data.
[0082] Step S02, collecting an initial elliptic curve parameter set, and standardizing the initial elliptic curve parameter set to remove abnormal values to obtain a true elliptic curve parameter set;
[0083] In order to improve the training effect of the GAN model, a set of initial elliptic curve parameter sets are first collected. These parameter sets may contain parameters of elliptic curve equations with different shapes and characteristics. Subsequently, these initial parameter sets are standardized to eliminate the dimensional differences and numerical range differences between different parameters. At the same time, outliers that obviously deviate from the normal range are eliminated to ensure the accuracy and validity of the input data, thereby obtaining the true elliptic curve parameter set.
[0084] Step S03: Generate random noise samples using Gaussian distribution and input the random noise samples into the generator to obtain a set of false elliptic curve parameters;
[0085] Generate random noise samples using Gaussian distribution. These noise samples are used as the input of the generator and are transformed through the multi-layer network structure of the generator, and finally a set of false elliptic curve parameters is output. This process simulates the mapping relationship from the latent space to the data space.
[0086] Exemplarily, the formula for generating random noise samples using Gaussian distribution is as follows:
[0087] Gaussian distribution:
[0088] μ represents the mean, and σ 2 represents the variance
[0089] Step S04: Input the set of false elliptic curve parameters, the set of true elliptic curve parameters, and the labels into the discriminator, and optimize the model parameters using an adaptive learning rate algorithm;
[0090] Input the set of false elliptic curve parameters, the set of true elliptic curve parameters, and the corresponding labels (true or false) into the discriminator for discrimination. The error between the output of the discriminator and the true label is quantified by the loss function. To optimize the model parameters, this application uses an adaptive learning rate algorithm (such as the Adam algorithm), which can dynamically adjust the learning rate of each parameter according to the first-order moment estimate and second-order moment estimate of the gradient. Through multiple iterative trainings, the parameters of the discriminator and the generator are continuously optimized until a convergence state is reached.
[0091] Specifically, in a feasible implementation manner, step S04 may include steps A1 to A3:
[0092] Step A1: Input the set of false elliptic curve parameters, the set of true elliptic curve parameters, and the labels into the discriminator to obtain the discriminator output result;
[0093] The input of the discriminator includes two parts: the set of false elliptic curve parameters and the set of true elliptic curve parameters. These two parts of the data set respectively represent the data generated by the generator (i.e., false data) and the real data obtained from actual use or predefined. In addition, each set of data is accompanied by a label to clearly indicate whether the data is real data or false data. The task of the discriminator is to learn to distinguish these data, that is, for the input data, the discriminator needs to output a result indicating the probability that it believes the data is real data.
[0094] Step A2: Calculate the loss function according to the discriminator output result and the cross-entropy loss;
[0095] Once the discriminator has evaluated the input data, it is necessary to calculate the loss based on the output result of the discriminator and a preset loss function. In this application, the loss function is constructed based on the cross-entropy loss. The cross-entropy loss is a commonly used method for measuring the difference between two probability distributions, and is particularly suitable for classification tasks. One probability distribution is represented by the result output by the discriminator (i.e., the probability of considering the input data as real data), while the other probability distribution is represented by the true label of the data (i.e., the probability that the data is actually real data, which is 0 for false data and 1 for real data). By calculating the cross-entropy loss between these two distributions, the performance of the discriminator can be quantified, and the model parameters can be optimized based on this.
[0096] The specific calculation formula is as follows:
[0097]
[0098] L(G) represents the loss function of the generator, L(D) represents the loss function of the discriminator, and E z ~p z (z) represents the expected value of the set of false elliptic curve parameters z, and E x ~p data (x) represents the expected value of the set of real elliptic curve parameters x, D(x) represents the probability that the discriminator considers the set of real elliptic curve parameters x as real data, and 1 - D(G(z)) represents the probability that the discriminator considers the set of false elliptic curve parameters z as false data.
[0099] Step A3, update the discriminator and the generator according to the gradient of the loss function by using an adaptive learning rate algorithm to optimize the model parameters.
[0100] After obtaining the calculation result of the loss function, the gradient of the loss function with respect to the model parameters can be calculated through the backpropagation algorithm. An adaptive learning rate algorithm (such as the Adam algorithm) is used to update the model parameters of the discriminator and the generator. Specifically, the first-order moment estimate and the second-order moment estimate of the gradient are used to dynamically adjust the learning rate of each parameter, and the learning rate has a definite range for each iteration, making the parameters relatively stable. The final optimization objective is as follows:
[0101]
[0102] Among them, E x ~p data (x) represents the expected value of the set of real elliptic curve parameters x, D(x) represents the probability that the discriminator considers the set of real elliptic curve parameters x as real data, and 1 - D(G(z)) represents the probability that the discriminator considers the set of false elliptic curve parameters z as false data.
[0103] The Adam algorithm combines the ideas of the momentum method and the RMSprop algorithm, which can dynamically adjust the learning rate of each parameter, thereby accelerating the training process and reducing oscillations. In each iteration, the value of each parameter is updated based on the current gradient estimate in order to minimize the loss function. This step is the core of the GAN model training. By continuously optimizing the model parameters, the generator can gradually generate increasingly realistic fake data, while the discriminator can more and more accurately identify real data and fake data.
[0104] Step S05: Perform a credibility discrimination on the optimized model parameters to obtain the generative adversarial network.
[0105] After the model training is completed, it is necessary to perform a credibility discrimination on the generated elliptic curve parameters. This step aims to ensure that the generated parameters not only conform to the mathematical definition of the elliptic curve, but also have sufficient security and reliability in practical applications.
[0106] Specifically, in a feasible implementation, step S05 may include steps B1 to B2:
[0107] Step B1: Perform a credibility discrimination on the optimized model parameters to obtain a discrimination result. The credibility discrimination includes the base point verification, the verification of the order of the base point, the strong prime number verification, and the curve coefficient verification in the optimized model parameters.
[0108] After the model training is completed, it is necessary to perform a credibility discrimination on the generated elliptic curve parameters. This step aims to ensure that the generated parameters not only conform to the mathematical definition of the elliptic curve, but also have sufficient security and reliability in practical applications. The credibility discrimination can be carried out in the following aspects:
[0109] Verify the base point G in the generated parameters: Ensure that the base point G has a large order and can traverse most or all valid points.
[0110] Check the order of the base point G: Ensure that the order is a large prime number to increase the difficulty of the discrete logarithm problem.
[0111] Verify the prime number p in the prime field: Ensure that p is a strong prime number and at least 256 bits long to enhance the security of the parameters.
[0112] Check the elliptic curve coefficients a and b: Ensure that they satisfy the standard equation of the elliptic curve.
[0113] Step B2: Adjust the number of training iterations according to the discrimination result to obtain the generative adversarial network.
[0114] The discrimination result usually refers to the classification accuracy of the discriminator for the input data, that is, the proportion of correctly distinguishing real data and fake data.
[0115] Based on the discrimination result, the training status of the current GAN model can be evaluated.
[0116] If the discriminator can easily distinguish between real data and fake data (i.e., the discrimination result is very accurate), this may mean that the generator has not generated sufficiently realistic fake data, or the discriminator has become too powerful, making it difficult for the generator to improve the quality of the data it generates. On the contrary, if the discriminator has difficulty distinguishing between real data and fake data (i.e., the discrimination result is not accurate enough), this may mean that the generator has generated fairly realistic fake data, or the discriminator needs more training to improve its classification ability.
[0117] Therefore, the number of training iterations can be adjusted to optimize the GAN model. If the discrimination result is too accurate, it may be necessary to increase the training time of the generator (i.e., increase the number of iterations of the generator), or reduce the training time of the discriminator (i.e., reduce the number of iterations of the discriminator), to balance the performance of the two. If the discrimination result is not accurate enough, it may be necessary to increase the training time of both the generator and the discriminator simultaneously, or adopt other strategies to improve the performance of the model, such as adjusting the learning rate, using a more complex network structure, etc.
[0118] By continuously adjusting the number of training iterations and other training parameters, the GAN model can be gradually optimized. When the generator can generate sufficiently realistic fake data and the discriminator has difficulty distinguishing these fake data from real data, it can be considered that the GAN model has been trained.
[0119] In this embodiment, the cloud platform authorizes the server to run the GAN model, and the training network parameters are calculated by using a common and highly reliable elliptic curve equation. The generator is used to randomly generate noise data, and the discriminator is a model architecture that discriminates between random data and real highly reliable data. The loss is calculated by judging the result and backpropagation is used for optimization. This process is repeated until the GAN can tend to be stable and generate highly reliable curve parameters.
[0120] Based on the first embodiment and / or the second embodiment of the present application, the third embodiment of the present application is proposed. In the third embodiment of the present application, for the same or similar content as in the above embodiments, reference can be made to the above introduction and will not be elaborated hereinafter.
[0121] As Figure 3 shown, Figure 3 FIG. 3 is a schematic flowchart of the third embodiment provided for the service authorization method based on containerized node deployment of the present application.
[0122] In this embodiment, the step S40 of decrypting the encrypted authorization data by the background authorization end and regularly invoking the license verification process for service authorization may include steps S41 to S43:
[0123] Step S41, decrypt the encrypted authorization data using the shared key for initial service authorization;
[0124] The cloud platform decrypts the encrypted authorization data using the shared key obtained through the ECC key exchange algorithm before. After successful decryption, the service requester obtains the authorization data and performs initial service authorization based on this.
[0125] Step S42, when the initial service authorization is completed, update the public key of the first key exchange algorithm and the public key of the second key exchange algorithm using the elliptic curve parameters;
[0126] When the initial service authorization is completed, to improve the security of the authorization process, the cloud platform will use a pre - constructed generative adversarial network (GAN) for the generated elliptic curve parameters. GAN is a deep learning model that can generate data similar to real data and is used here to generate new and more secure elliptic curve parameters.
[0127] The public key of the first key exchange algorithm and the public key of the second key exchange algorithm are generated using default curve parameters. Further, the elliptic curve parameters generated by GAN are used to update the public key of the first key exchange algorithm and the second key exchange algorithm. This step ensures the dynamic nature of the keys and elliptic curve parameters and improves the security of the authorization process.
[0128] Step S43, update the shared key using the updated public key of the first key exchange algorithm and the public key of the second key exchange algorithm, and perform license verification based on the updated shared key.
[0129] After the public keys of the key exchange algorithm are updated, the cloud platform will re - perform the ECC key exchange algorithm calculation using the updated public key of the first key exchange algorithm and the public key of the second key exchange algorithm to obtain a new shared key. Then, the cloud platform will encrypt the license using the new shared key, decrypt the encrypted license using the new shared key, and verify the validity of the license. This step ensures the security of the license verification process and prevents security risks brought by the leakage of old keys.
[0130] In this embodiment, generating elliptic curve parameters through GAN improves the security and flexibility of the cloud platform service authorization process, reduces the risks of key leakage and the authorization system being cracked. In particular, by dynamically updating keys and elliptic curve parameters, it effectively avoids security hazards brought by static keys and fixed encryption algorithms.
[0131] As Figure 4 shown, Figure 4A schematic flowchart of a feasible implementation manner provided for the service authorization method based on containerized node deployment. Specifically, in a feasible implementation manner, after step S43, steps S44 to S45 are further included:
[0132] Step S44, updating the elliptic curve parameters using the pre-constructed generative adversarial network;
[0133] Reusing the generative adversarial network to update the elliptic curve parameters aims to ensure that the shared key used in each license verification process is random and unused, thereby ensuring the dynamics of the key and the elliptic curve parameters and improving the security of the authorization process.
[0134] Step S45, when the elliptic curve parameters are updated, periodically return to execute the step: updating the public key of the first key exchange algorithm and the public key of the second key exchange algorithm using the elliptic curve parameters.
[0135] To improve the continuous security of the authorization process, the cloud platform will periodically return to execute the step: updating the public key of the first key exchange algorithm and the public key of the second key exchange algorithm using the elliptic curve parameters.
[0136] This application also provides a service authorization device. Please refer to Figure 5 The service authorization device includes:
[0137] An authentication information receiving module 10, configured to receive authentication information provided by a service requester, where the authentication information includes a public key of a first key exchange algorithm and authorization data;
[0138] A shared key generation module 20, configured to calculate a shared key by using an ECC key exchange algorithm for the public key of the first key exchange algorithm and the public key of the second key exchange algorithm, where the elliptic curve parameters of the ECC key exchange algorithm are generated by using a pre-constructed generative adversarial network;
[0139] An encryption module 30, configured to encrypt the authorization data through the server and based on the shared key and the AES algorithm to obtain encrypted authorization data, and send the encrypted authorization data to the background authorization end;
[0140] A decryption module 40, configured to decrypt the encrypted authorization data through the background authorization end and periodically call a license verification process for service authorization, where the license verification process includes updating the shared key by using the elliptic curve parameters.
[0141] The service authorization device provided by this application adopts the service authorization method in the above embodiment, and can solve the technical problem of service authorization. Compared with the prior art, the beneficial effects of the service authorization device provided by this application are the same as those of the service authorization method provided by the above embodiment, and other technical features in the service authorization device are the same as the features disclosed in the method of the above embodiment, which will not be elaborated here.
[0142] This application provides a service authorization device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the service authorization method in the first embodiment above.
[0143] Refer to the following Figure 6 , which shows a schematic structural diagram of a service authorization device suitable for implementing the embodiments of this application. The service authorization device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 6 The service authorization device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of this application.
[0144] As Figure 6As shown, the service authorization device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 1002 or the program loaded from the storage device 1003 into the random access memory (RAM) 1004. In the RAM 1004, various programs and data required for the operation of the service authorization device are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. The input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the service authorization device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a service authorization device having various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems may be implemented or had alternatively.
[0145] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program may be downloaded and installed from a network through the communication device, or installed from the storage device 1003, or installed from the ROM 1002. When the computer program is executed by the processing device 1001, the above functions defined in the methods of the embodiments disclosed in the present application are executed.
[0146] The service authorization device provided by the present application, adopting the service authorization method in the above embodiments, can solve the technical problems of service authorization. Compared with the prior art, the beneficial effects of the service authorization device provided by the present application are the same as those of the service authorization method provided by the above embodiments, and the other technical features in the service authorization device are the same as the features disclosed in the method of the previous embodiment, and will not be elaborated here.
[0147] It should be understood that each part disclosed in this application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.
[0148] As described above, the above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in this application, and all should be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
[0149] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the service authorization method in the above embodiments.
[0150] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or combined with an instruction execution system, device, or device. The program code contained on the computer-readable storage medium can be transmitted by any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0151] The above computer-readable storage medium can be included in the service authorization device; it can also exist separately without being assembled into the service authorization device.
[0152] The above computer-readable storage medium carries one or more programs, which, when executed by a service authorization device, cause the service authorization device to: receive authentication information provided by a service requester, the authentication information including a first exchange key algorithm public key and authorization data; calculate a shared key by using an ECC key exchange algorithm for the first exchange key algorithm public key and a second exchange key algorithm public key, wherein elliptic curve parameters of the ECC key exchange algorithm are generated by using a pre-constructed generative adversarial network; encrypt the authorization data through the server and based on the shared key and the AES algorithm to obtain encrypted authorization data, and send the encrypted authorization data to the background authorization end; decrypt the encrypted authorization data through the background authorization end, and periodically call a license verification process for service authorization, wherein the license verification process includes updating the shared key by using the elliptic curve parameters.
[0153] Computer program code for performing the operations of the present application may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, execute as a stand-alone software package, execute partially on the user's computer and partially on a remote computer, or execute entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0154] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur in a different order than that noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0155] The modules described in the embodiments of the present application can be implemented in software or in hardware. In some cases, the name of the module does not constitute a limitation on the unit itself.
[0156] The readable storage medium provided by the present application is a computer-readable storage medium, and the computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for executing the above service authorization method, which can solve the technical problems of service authorization. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as those of the service authorization method provided by the above embodiments, and will not be elaborated herein.
[0157] The present application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the service authorization method as described above.
[0158] The computer program product provided by the present application can solve the technical problems of service authorization. Compared with the prior art, the beneficial effects of the computer program product provided by the present application are the same as those of the service authorization method provided by the above embodiments, and will not be elaborated herein.
[0159] The above are only some embodiments of the present application, and do not limit the patent scope of the present application. Any equivalent structural transformation made under the technical concept of the present application by using the content of the specification and drawings of the present application, or direct / indirect application in other related technical fields, is included in the patent protection scope of the present application.
Claims
1. A service authorization method based on containerized node deployment, characterized in that Applied to a cloud platform, the cloud platform includes a server side and a background authorization side, and the method includes: Receiving authentication information provided by a service requester, where the authentication information includes a first exchange key algorithm public key and authorization data; Calculating the first exchange key algorithm public key and the second exchange key algorithm public key using the ECC key exchange algorithm to obtain a shared key, where the elliptic curve parameters of the ECC key exchange algorithm are generated by using a pre-constructed generative adversarial network; Encrypting the authorization data through the server side and based on the shared key and the AES algorithm to obtain encrypted authorization data, and sending the encrypted authorization data to the background authorization side; Decrypting the encrypted authorization data through the background authorization side and regularly invoking a license verification process for service authorization, where the license verification process includes updating the shared key using the elliptic curve parameters.
2. The method according to claim 1, characterized in that, Before the step of calculating the first exchange key algorithm public key and the second exchange key algorithm public key using the ECC key exchange algorithm to obtain a shared key, where the elliptic curve parameters of the ECC key exchange algorithm are generated by using a pre-constructed generative adversarial network, it includes: Combining a linear layer, a pooling layer, and a convolutional layer to obtain a generator and a discriminator respectively; Collecting an initial set of elliptic curve parameters and performing standardization processing on the initial set of elliptic curve parameters to remove outliers, obtaining a set of real elliptic curve parameters; Generating a random noise sample using a Gaussian distribution and inputting the random noise sample into the generator to obtain a set of false elliptic curve parameters; Inputting the set of false elliptic curve parameters, the set of real elliptic curve parameters, and a label into the discriminator, and optimizing the model parameters using an adaptive learning rate algorithm; Performing credibility discrimination on the optimized model parameters to obtain the generative adversarial network.
3. The method according to claim 2, characterized in that, The step of inputting the set of false elliptic curve parameters, the set of real elliptic curve parameters, and a label into the discriminator, and optimizing the model parameters using an adaptive learning rate algorithm includes: Inputting the set of false elliptic curve parameters, the set of real elliptic curve parameters, and a label into the discriminator to obtain a discriminator output result; Calculating a loss function based on the discriminator output result and cross-entropy loss; Updating the discriminator and the generator using an adaptive learning rate algorithm according to the gradient of the loss function to optimize the model parameters.
4. The method according to claim 2, wherein The step of performing credibility discrimination on the optimized model parameters to obtain the generative adversarial network includes: Performing credibility discrimination on the optimized model parameters to obtain a discrimination result, where the credibility discrimination includes base point verification, order verification of the base point, strong prime number verification, and curve coefficient verification in the optimized model parameters; Adjusting the training iteration times according to the discrimination result to obtain the generative adversarial network.
5. The method according to claim 1, characterized in that, The step of calculating the first exchange key algorithm public key and the second exchange key algorithm public key using the ECC key exchange algorithm to obtain a shared key includes: Analyze the authentication information to obtain the public key of the second key exchange algorithm, where the public key of the second key exchange algorithm is generated based on the default curve parameters of the ECC key exchange algorithm; Use the ECC key exchange algorithm to perform key exchange calculation on the public key of the first key exchange algorithm and the public key of the second key exchange algorithm to obtain the shared key.
6. The method according to claim 1, characterized in that, The step of decrypting the encrypted authorization data by the background authorization end and periodically invoking the license verification process for service authorization includes: Use the shared key to decrypt the encrypted authorization data for initial service authorization; After the initial service authorization is completed, use the elliptic curve parameters to update the public key of the first key exchange algorithm and the public key of the second key exchange algorithm; Update the shared key with the updated public key of the first key exchange algorithm and the updated public key of the second key exchange algorithm, and perform license verification based on the updated shared key.
7. The method according to claim 6, characterized in that, After the step of updating the shared key with the updated public key of the first key exchange algorithm and the updated public key of the second key exchange algorithm and performing license verification based on the updated shared key, further includes: Use the pre-constructed generative adversarial network to update the elliptic curve parameters; After the elliptic curve parameters are updated, return to execute the step: use the elliptic curve parameters to update the public key of the first key exchange algorithm and the public key of the second key exchange algorithm.
8. A service authorization device, characterized in that, The device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, where the computer program is configured to implement the steps of the service authorization method based on containerized node deployment according to any one of claims 1 to 7.
9. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by a processor, it implements the steps of the service authorization method based on containerized node deployment according to any one of claims 1 to 7.
10. A computer program product, characterized in that, The computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps of the service authorization method based on containerized node deployment according to any one of claims 1 to 7.