Server health detection method and device based on TLS / SSL protocol
By analyzing the server certificate and generating a mapping table of X.509 data structure during the TLS/SSL handshake process, the problem of low TLS/SSL detection efficiency in high concurrency scenarios is solved, and efficient server health detection is achieved.
Patent Information
- Application Number
- CN202510680145.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-26
- Publication Date
- 2025-07-22
AI Technical Summary
The existing server health detection scheme based on TLS/SSL protocol. In high concurrency scenarios, frequent ASN.1 decoding operations increase system overhead and affect detection efficiency.
By parsing the server's return message during the TLS/SSL handshake process, obtaining the certificate, querying the matches in the certificate mapping table, extracting the X.509 data structure for health detection, and only performing ASN.1 decoding when the certificate is parsed for the first time, and then directly using the X.509 data structure for detection.
It significantly reduces the certificate resolution overhead during TLS/SSL health detection, and improves detection performance and system resource utilization.
Smart Images

Figure CN120358171A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer information processing. Specifically, it relates to a server health detection method and device based on the TLS / SSL protocol. Background Art
[0002] Existing server health detection solutions based on the TLS / SSL protocol generally adopt the following process: The load balancer device periodically starts a health check process and initiates a TLS / SSL handshake process with each real backend server respectively. The core of this handshake process lies in negotiating and generating the connection key required for the encrypted channel in an insecure network environment. Once the TLS / SSL connection is successfully established, the detection process sends a data request to the target server through this encrypted channel. For example, when detecting an HTTPS service, it sends an encrypted HTTP request message and receives the server's response. After decryption, if the response content meets the expectations, it is determined that the server is in a healthy state; otherwise, it is determined to be in an unhealthy state.
[0003] During the TLS / SSL handshake process, the server sends a message containing a certificate chain to the client. The client needs to sequentially parse each server certificate in the certificate chain and perform validity judgment. This certificate generally follows the format specification of the international standard ITU-T X.509. As Figure 1 shown, a standard X.509 digital certificate generally contains the following fields: version information (Version); serial number (Serial Number), which is the unique identifier of each certificate; signature algorithm (SignatureAlgorithm); issuer (Issuer), usually in the X.500 naming format; validity period (Validity Period), generally represented in UTC time; holder (Subject), which is the name of the certificate owner; public key information (Public Key); signature information (Signature), which is the digital signature of the issuing agency for the certificate.
[0004] The above X.509 certificate usually uses the ASN.1 (Abstract Syntax Notation One) encoding rule for binary encoding. During the actual parsing process, it is necessary to decode this binary data according to the ASN.1 specification and map and fill the parsed fields into the local X.509 certificate structure for subsequent verification and business logic use.
[0005] However, this approach has performance bottlenecks. Especially in the face of high-concurrency health check scenarios, frequent ASN.1 decoding operations will significantly increase the system overhead and affect the overall detection efficiency. Therefore, how to improve the certificate parsing efficiency and optimize the TLS / SSL health detection mechanism has become a technical problem that urgently needs to be solved in this field.
[0006] Therefore, a new server health detection method and device based on the TLS / SSL protocol are needed.
[0007] The above information disclosed in the background art section is only used to enhance the understanding of the background of the present application. Therefore, it may include information that does not constitute the prior art known to those of ordinary skill in the art. Summary of the Invention
[0008] In view of this, the present application provides a server health detection method and device based on the TLS / SSL protocol, which can significantly reduce the certificate parsing overhead during TLS / SSL health detection and improve the detection performance and system resource utilization rate.
[0009] Other features and advantages of the present application will become apparent through the following detailed description, or will be learned in part through the practice of the present application.
[0010] According to one aspect of the present application, a server health detection method based on the TLS / SSL protocol is proposed. The method includes: a load balancing device performing a TLS / SSL handshake with a server to be health detected; parsing the return message of the server during the TLS / SSL handshake to obtain a certificate; querying a matching item of the certificate in a certificate mapping table; after determining the matching item, extracting an X.509 data structure from the matching item; and performing health detection of the server based on the X.509 data structure and the certificate.
[0011] In an exemplary embodiment of the present application, it further includes: when no matching item is found, parsing the certificate to obtain its corresponding X.509 data structure; and generating a table entry corresponding to the certificate in the certificate mapping table through the X.509 data structure.
[0012] In an exemplary embodiment of the present application, parsing the certificate to obtain its corresponding X.509 data structure includes: obtaining the binary data corresponding to the certificate; decoding the certificate according to the ASN.1 encoding rule to generate certificate content; and setting the certificate content into an X.509 certificate structure to generate the X.509 data structure.
[0013] In an exemplary embodiment of the present application, setting the certificate content into the X.509 certificate structure to generate the X.509 data structure includes: setting the version, serial number, signature algorithm, signature hash algorithm, validity, user, public key information, and extensions in the certificate content to corresponding positions in the X.509 certificate structure according to preset rules to generate the X.509 data structure.
[0014] In an exemplary embodiment of the present application, generating an entry corresponding to the certificate in the certificate mapping table through the X.509 data structure includes: using the binary data of the certificate as the key value; using the X.509 data structure as the value value; generating an entry corresponding to the certificate in the certificate mapping table through the key value and the value value.
[0015] In an exemplary embodiment of the present application, a load balancing device performs a TLS / SSL handshake with a server to be health detected, including: the load balancing device creates a client; constructs a client hello message based on the client; and sends the client hello message to the server to be health detected for a TLS / SSL handshake.
[0016] In an exemplary embodiment of the present application, parsing the return message of the server during the TLS / SSL handshake to obtain a certificate includes: obtaining the server hello message and the server certificate message returned by the server during the TLS / SSL handshake; parsing the server certificate message to obtain a certificate.
[0017] In an exemplary embodiment of the present application, parsing the server certificate message to obtain certificate data includes: parsing the server certificate message to obtain a certificate chain; traversing the certificate chain to extract each certificate.
[0018] In an exemplary embodiment of the present application, querying a matching item of the certificate data from the certificate mapping table includes: obtaining the binary data corresponding to the certificate; querying the matching item of the certificate data from the locally cached certificate mapping table according to the binary data.
[0019] According to one aspect of the present application, a server health detection device based on the TLS / SSL protocol is provided. The device includes: a handshake module for performing a TLS / SSL handshake between a load balancing device and a server to be health-detected; a parsing module for parsing the return message of the server during the TLS / SSL handshake to obtain a certificate; a query module for querying a matching item of the certificate in a certificate mapping table; a structure module for extracting an X.509 data structure from the matching item after determining the matching item; and a detection module for performing health detection of the server based on the X.509 data structure and the certificate.
[0020] According to one aspect of the present application, an electronic device is provided. The electronic device includes: one or more processors; a storage device for storing one or more programs; when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described above.
[0021] According to one aspect of the present application, a computer-readable medium is provided, on which a computer program is stored. When the program is executed by a processor, the method as described above is implemented.
[0022] According to the server health detection method and device based on the TLS / SSL protocol of the present application, by performing a TLS / SSL handshake between a load balancing device and a server to be health-detected; parsing the return message of the server during the TLS / SSL handshake to obtain a certificate; querying a matching item of the certificate in a certificate mapping table; extracting an X.509 data structure from the matching item after determining the matching item; and performing health detection of the server based on the X.509 data structure and the certificate, the certificate parsing overhead during TLS / SSL health detection can be significantly reduced, and the detection performance and system resource utilization rate can be improved.
[0023] It should be understood that the above general description and the following detailed description are only exemplary and do not limit the present application. Brief Description of the Drawings
[0024] By referring to the accompanying drawings and describing its exemplary embodiments in detail, the above and other objectives, features, and advantages of the present application will become more apparent. The following described drawings are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0025] Figure 1 It is a schematic diagram of a digital certificate shown according to an exemplary embodiment.
[0026] Figure 2It is a flowchart of a server health detection method based on the TLS / SSL protocol shown according to an exemplary embodiment.
[0027] Figure 3 It is a flowchart of a server health detection method based on the TLS / SSL protocol shown according to another exemplary embodiment.
[0028] Figure 4 It is a flowchart of a server health detection method based on the TLS / SSL protocol shown according to another exemplary embodiment.
[0029] Figure 5 It is a block diagram of a server health detection device based on the TLS / SSL protocol shown according to an exemplary embodiment.
[0030] Figure 6 It is a block diagram of an electronic device shown according to an exemplary embodiment.
[0031] Figure 7 It is a block diagram of a computer-readable medium shown according to an exemplary embodiment. Detailed Implementation Manner
[0032] Example embodiments will now be described more fully with reference to the accompanying drawings. However, the example embodiments can be implemented in various forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided so that this application will be thorough and complete, and will fully convey the concept of the example embodiments to those skilled in the art. Like reference numerals in the figures denote like or similar parts, and thus their repeated description will be omitted.
[0033] In addition, the described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a thorough understanding of the embodiments of this application. However, those skilled in the art will realize that the technical solutions of this application can be practiced without one or more of the specific details, or other methods, components, devices, steps, etc. can be adopted. In other cases, well-known methods, devices, implementations, or operations are not shown or described in detail to avoid obscuring aspects of this application.
[0034] The block diagrams shown in the drawings are only functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or in one or more hardware modules or integrated circuits, or in different networks and / or processor devices and / or microcontroller devices.
[0035] The flowcharts shown in the accompanying drawings are merely illustrative and not necessarily inclusive of all content and operations / steps, nor are they necessarily to be executed in the order described. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined, so the actual execution order may change according to the actual situation.
[0036] It should be understood that although terms such as first, second, third, etc. may be used herein to describe various components, these components should not be limited by these terms. These terms are used to distinguish one component from another. Thus, the first component discussed below may be referred to as the second component without departing from the teachings of the concepts of this application. As used herein, the term "and / or" includes any one of the associated listed items and all combinations of one or more of them.
[0037] Those skilled in the art can understand that the drawings are only schematic diagrams of exemplary embodiments, and the modules or processes in the drawings are not necessarily essential for implementing this application, so they cannot be used to limit the protection scope of this application.
[0038] The technical abbreviations involved in this application are explained as follows:
[0039] SSL protocol: The SSL (Secure Sockets Layer) protocol is a network security protocol designed to ensure the confidentiality, integrity, and authenticity of data during transmission between the client and the server by establishing an encrypted communication channel between the application layer and the transport layer. SSL was initially developed by Netscape in the mid-1990s and later evolved into the TLS (Transport Layer Security) protocol, which can be regarded as the successor and improved version of SSL. The SSL / TLS protocol is widely used in scenarios where secure data transmission is required:
[0040] 1. HTTPS: SSL / TLS is the core of HTTPS, protecting the communication between web browsers and servers.
[0041] 2. Email transmission: Secure versions of protocols such as SMTP, IMAP, POP3 (such as SMTPS).
[0042] 3. VPN: SSL VPN protects data through encrypted communication.
[0043] The SSL protocol is a protocol that protects network communication through encryption. It ensures the confidentiality, integrity, and authentication of data transmission and is an important cornerstone of modern Internet security.
[0044] Load Balancing (LB for short) is a clustering technology for servers or network devices. Load balancing distributes specific services (such as network services, network traffic, etc.) to multiple servers or network devices, thereby improving the service processing capacity and ensuring the high availability of services. Server load balancing is divided into layer 4 server load balancing and layer 7 load balancing according to the packet layer processed by the LB device. Layer 4 processes the IP header of the IP packet and does not parse the payload above layer 4 of the packet (L4 server LB); layer 7 processes the payload part of the packet, such as the HTTP, RTSP, SIP packet headers, and sometimes also includes the packet content part (L7 server LB).
[0045] A digital certificate is a series of data that marks the identity information of all parties in Internet communication. It provides a way to verify your identity on the Internet, and its function is similar to a driver's license or an ID card in daily life. It is issued by an authoritative institution - the CA institution, also known as the Certificate Authority Center. People can use it to identify the identity of the other party on the Internet. A digital certificate is a file containing the information of the owner of the public key and the public key, digitally signed by a certificate authority (such as WoTong CA). The simplest certificate contains a public key, a name, and the digital signature of the certificate authority. Generally, the certificate also includes information such as the valid time of the key, the name of the issuing authority (certificate authority), and the serial number of the certificate. The format of the certificate follows the ITUT X.509 international standard.
[0046] Load balancing determines the service availability of servers through health checks. The health check mechanism improves the overall availability of services and avoids the impact of server anomalies on the overall service. After enabling the health check function, when a certain server is found to be abnormal during the health check, the load balancer will automatically distribute new requests to other servers that pass the health check; when the server resumes normal operation, the load balancer will automatically restore it to the load balancing service.
[0047] The present application provides a method for high-performance health detection of a server based on the TLS / SSL protocol. By leveraging the characteristics of the TLS / SSL health detection service, the certificates of the real servers received are generally fixed and have the characteristic of periodically probing the server. Through the technical solution of the present application, only for the first time, each certificate in the server certificate chain needs to decode the certificate data according to the ASN.1 (Abstract Syntax Notation One) encoding rule to parse out all the contents of the certificate, such as fields like version, serial number, signature algorithm, signature hash algorithm, validity, subject, public key information, extensions, etc. After the certificate is parsed, the parsed data is set into the structure of the X.509 digital certificate and converted into the X.509 data structure, which is saved in the certificate X.509 map key-value table; for subsequent health detections, when a certificate is received later, the X.509 data structure can be directly obtained according to the certificate binary data, without the need to parse the data in the ASN.1 format,
[0048] Through the above method, the present application can provide a scheme for quickly parsing certificates. For subsequent health detections, when the client receives the certificate chain sent by the server, it only needs to directly obtain the parsed X.509 data structure from the certificate X.509 map key-value table according to the certificate binary data information, without the need to parse the data in the complex ASN.1 format, and basically does not consume device resources. Thus, the certificate can be quickly parsed, reducing the consumption of system resources and improving the performance of the TLS / SSL protocol for server health detection.
[0049] The following will elaborate on the content of the present application with the aid of specific embodiments.
[0050] Figure 2 is a flowchart of a server health detection method based on the TLS / SSL protocol shown according to an exemplary embodiment. The server health detection method 20 based on the TLS / SSL protocol at least includes steps S202 to S210.
[0051] As Figure 2 shown, in S202, the load balancing device conducts a TLS / SSL handshake with the server to be health-detected. The load balancing device creates a client; constructs a client hello message based on the client; and sends the client hello message to the server to be health-detected for a TLS / SSL handshake.
[0052] More specifically, the load balancing device creates a client instance to simulate a client initiating a connection; constructs a Client Hello message in a standard format based on the client; and sends the Client Hello message to the target server to initiate the TLS / SSL handshake process.
[0053] This step can negotiate the encryption parameters required for secure communication between the client and the server and lay a foundation for subsequent certificate acquisition and health detection.
[0054] In S204, during the TLS / SSL handshake process, parse the server's return message to obtain the certificate. During the TLS / SSL handshake process, obtain the server hello message and server certificate message returned by the server; parse the server certificate message to obtain the certificate.
[0055] During the TLS / SSL handshake process, the server will return a series of response messages, including the Server Hello message and the Server Certificate message. The load balancing device parses the above messages, specifically including:
[0056] Parse the Server Hello message to confirm the server handshake response;
[0057] Parse the Server Certificate message to extract the certificate chain information sent by the server.
[0058] Through the decoding operation of the Server Certificate message, the complete certificate chain can be obtained for subsequent matching and health status assessment.
[0059] In S206, query the matching item of the certificate in the certificate mapping table. More specifically, parse the servercertificate message to obtain the certificate chain; traverse the certificate chain to extract each certificate.
[0060] More specifically, the certificate chain extracted from the Server Certificate message can be traversed; the binary data (i.e., ASN.1 encoding format) corresponding to each certificate can be extracted; and based on this binary data as the key, query in the locally cached certificate mapping table to find the entry that matches the certificate data.
[0061] In S208, after determining the matching item, extract the X.509 data structure from the matching item. The binary data corresponding to the certificate can be obtained; and according to the binary data, query the matching item of the certificate data in the locally cached certificate mapping table.
[0062] In S210, based on the X.509 data structure and the certificate, perform health detection of the server. Based on the extracted X.509 data structure and the original certificate data, the load balancing device can perform a series of health detection operations, including but not limited to: verifying whether the certificate format and structure are complete; checking whether the certificate is within the validity period; verifying whether the certificate signature can be correctly verified by the trusted root certificate chain; checking the legality of the public key and extended fields; and determining whether the certificate meets the set health standards according to business rules or policies.
[0063] If all detection conditions are met, determine that the server status is healthy (up); otherwise, determine it as unhealthy (down).
[0064] According to the server health detection method based on the TLS / SSL protocol of the present application, perform a TLS / SSL handshake between the load balancing device and the server to be health-detected; parse the return message of the server during the TLS / SSL handshake to obtain the certificate; query the matching item of the certificate in the certificate mapping table; after determining the matching item, extract the X.509 data structure from the matching item; based on the X.509 data structure and the certificate, perform the health detection of the server, which can significantly reduce the certificate parsing overhead during TLS / SSL health detection and improve the detection performance and system resource utilization rate.
[0065] It should be clearly understood that the present application describes how to form and use specific examples, but the principles of the present application are not limited to any details of these examples. On the contrary, based on the teachings disclosed in the present application, these principles can be applied to many other embodiments.
[0066] Figure 3 It is a flowchart of a server health detection method based on the TLS / SSL protocol shown according to another exemplary embodiment. Figure 3 The shown process 30 is a supplementary description of Figure 2 the shown process.
[0067] As Figure 3 shown, in S302, when no matching item is found, obtain the binary data corresponding to the certificate. Obtain the original binary encoded data from the server certificate extracted during the handshake process. This data is usually in the DER encoding format of ASN.1 (Abstract Syntax Notation One) that conforms to the ITU-T X.690 standard.
[0068] The binary data can be directly sourced from the certificate_list field in the Server Certificate message body; after extraction, it is saved in the cache buffer or the parsing module and used as the decoding input.
[0069] In S304, the certificate is decoded according to the ASN.1 encoding rule to generate the certificate content. In practical applications, the binary data of the certificate can be parsed according to the ASN.1 encoding rule to restore the semantic content of each certificate field.
[0070] The decoding result includes but is not limited to: certificate version (Version), serial number (Serial Number), signature algorithm (Signature Algorithm), signature hash algorithm (Signature Hash Algorithm), validity period (Validity), user (Subject), issuer (Issuer), public key information (Subject Public Key Info), extension fields (Extensions), etc.
[0071] It is worth mentioning that during the decoding process, strict verification can also be performed on the field type, length, order, etc. to ensure compliance with the X.509v3 standard.
[0072] In S306, the certificate content is set into the X.509 certificate structure to generate the X.509 data structure. The version, serial number, signature algorithm, signature hash algorithm, validity, user, public key information, and extensions in the certificate content can be set to the corresponding positions in the X.509 certificate structure according to preset rules to generate the X.509 data structure.
[0073] For example, basic information such as version, serialNumber, and signatureAlgorithm can be set to the corresponding fields of the structure; the issuer and subject are filled respectively after being formatted according to the X.500 naming rule; the notBefore and notAfter fields are converted into local timestamps for processing; the public key algorithm type, public key length, key content, etc. are filled into the public key field; the extension fields (such as key usage, basic constraints, subject alternative name, etc.) are classified and parsed and encapsulated.
[0074] In S308, the table entry corresponding to the certificate is generated in the certificate mapping table through the X.509 data structure. The binary data of the certificate can be used as the key value; the X.509 data structure can be used as the value value; the table entry corresponding to the certificate is generated in the certificate mapping table through the key value and the value value.
[0075] Figure 4 It is a flowchart of a server health detection method based on the TLS / SSL protocol shown according to another exemplary embodiment. Figure 4The process 40 shown is a detailed description of the process of this application.
[0076] As Figure 4 shown, in S402, a client is created to send data to the TLS / SSL server for TLS / SSL handshake. The health detection process creates a TLS / SSL client to send data to the TLS / SSL real server, initiates a TLS / SSL handshake according to the configuration, generally sets information such as cipher suites and supported TLS / SSL protocol versions, constructs a client hello message and sends it to the server.
[0077] In S404, a Client Hello message is constructed and sent to the server.
[0078] In S406, the server hello message and server certificate message returned by the server are received. The client receives the server hello message and server certificate message from the real server, parses the server certificate message. The certificate message is usually a certificate chain, extracts each certificate. The certificate is usually binary data encoded in DER.
[0079] In S408, the certificate chain is parsed to extract each certificate.
[0080] In S410, the certificate chain is traversed, and for each certificate, a search is performed according to the certificate binary data. The certificate X.509 key value table is searched according to the certificate binary data, and the certificate data is compared.
[0081] In S412, if no matching item is found, an X.509 data structure is generated according to the certificate data, and a new table entry is created for storage. If the certificate binary data cannot be found in the certificate X.509 key value table, it means that the corresponding certificate is not in the certificate X.509 key value table.
[0082] The certificate binary data can be used to decode the certificate data according to the ASN.1 (Abstract Syntax Notation One) encoding rule, and all contents of the certificate are parsed, such as fields like version, serial number, signature algorithm, signature hash algorithm, validity, user, public key information, extensions, etc.
[0083] After the certificate is parsed, the parsed data is set into the structure of the X.509 digital certificate to be converted into an X.509 data structure. The key is the certificate binary data, and the value is the parsed X.509 data structure. The data is saved to the certificate X.509 map key value table, and then the subsequent process of health detection is continued to detect the server status.
[0084] In S414, if a match is found, the X.509 data structure is directly extracted. If it is found in the certificate X.509 key value table, then the X.509 data structure is directly obtained from the certificate X.509 key value table without parsing the certificate binary data again to parse out the X.509 data structure, and the subsequent process of health detection is continued to detect the server status.
[0085] In S416, the TLS / SSL handshake is continued for health detection.
[0086] Those skilled in the art can understand that all or part of the steps for implementing the above embodiments are implemented as a computer program executed by a CPU. When the computer program is executed by the CPU, the above functions defined by the above method provided in this application are executed. The program can be stored in a computer-readable storage medium, which can be a read-only memory, a magnetic disk or an optical disc, etc.
[0087] In addition, it should be noted that the above drawings are only schematic illustrations of the processes included in the method according to the exemplary embodiments of the present application, rather than for limiting purposes. It is easy to understand that the processes shown in the above drawings do not indicate or limit the time sequence of these processes. Additionally, it is also easy to understand that these processes can be executed synchronously or asynchronously in, for example, multiple modules.
[0088] The following is an embodiment of the device of the present application, which can be used to execute the embodiment of the method of the present application. For details not disclosed in the embodiment of the device of the present application, please refer to the embodiment of the method of the present application.
[0089] Figure 5 is a block diagram of a server health detection device based on the TLS / SSL protocol shown according to an exemplary embodiment. As Figure 5 shown, the server health detection device 50 based on the TLS / SSL protocol includes: a handshake module 502, a parsing module 504, a query module 506, a structure module 508, a detection module 510. The server health detection device 50 based on the TLS / SSL protocol may further include: a new creation module 512.
[0090] The handshake module 502 is used for the load balancing device to perform a TLS / SSL handshake with the server to be health detected; the handshake module 502 is further used for the load balancing device to create a client; construct a client hello message based on the client; and send the client hello message to the server to be health detected for a TLS / SSL handshake.
[0091] The parsing module 504 is used to parse the return message of the server during the TLS / SSL handshake process to obtain the certificate; the parsing module 504 is also used to obtain the server hello message and the server certificate message returned by the server during the TLS / SSL handshake process; parse the server certificate message to obtain the certificate.
[0092] The query module 506 is used to query the matching item of the certificate in the certificate mapping table; the query module 506 is also used to obtain the binary data corresponding to the certificate; query the matching item of the certificate data from the locally cached certificate mapping table according to the binary data.
[0093] The structure module 508 is used to extract the X.509 data structure from the matching item after determining the matching item;
[0094] The detection module 510 is used to perform health detection of the server based on the X.509 data structure and the certificate.
[0095] The new module 512 is used to parse the certificate to obtain its corresponding X.509 data structure when no matching item is found; generate the table item corresponding to the certificate in the certificate mapping table through the X.509 data structure.
[0096] According to the server health detection device based on the TLS / SSL protocol of the present application, perform a TLS / SSL handshake with the server to be health-detected through a load balancing device; parse the return message of the server during the TLS / SSL handshake process to obtain the certificate; query the matching item of the certificate in the certificate mapping table; after determining the matching item, extract the X.509 data structure from the matching item; based on the X.509 data structure and the certificate, perform the server health detection method, which can significantly reduce the certificate parsing overhead during TLS / SSL health detection and improve the detection performance and system resource utilization rate.
[0097] Figure 6 It is a block diagram of an electronic device shown according to an exemplary embodiment.
[0098] Refer to the following Figure 6 to describe the electronic device 600 according to this embodiment of the present application. Figure 6 The displayed electronic device 600 is only an example and should not bring any limitations to the functions and usage scopes of the embodiments of the present application.
[0099] Such as Figure 6As shown, the electronic device 600 is presented in the form of a general computing device. The components of the electronic device 600 may include, but are not limited to: at least one processing unit 610, at least one storage unit 620, a bus 630 connecting different system components (including the storage unit 620 and the processing unit 610), a display unit 640, etc.
[0100] Among them, the storage unit stores program code, and the program code can be executed by the processing unit 610, so that the processing unit 610 executes the steps according to various exemplary embodiments of the present application described in this specification. For example, the processing unit 610 can execute steps such as Figure 2 , Figure 3 , Figure 4 shown in.
[0101] The storage unit 620 may include a readable medium in the form of a volatile storage unit, such as a random access storage unit (RAM) 6201 and / or a cache storage unit 6202, and may further include a read-only storage unit (ROM) 6203.
[0102] The storage unit 620 may further include a program / utility 6204 having a set (at least one) of program modules 6205. Such program modules 6205 include, but are not limited to: an operating system, one or more application programs, other program modules, and program data. Each or some combination of these examples may include the implementation of a network environment.
[0103] The bus 630 may represent one or more of several types of bus structures, including a storage unit bus or a storage unit controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any bus structure in a variety of bus structures.
[0104] The electronic device 600 can also communicate with one or more external devices 600' (such as a keyboard, a pointing device, a Bluetooth device, etc.), so that the user can communicate with the device that enables interaction with the electronic device 600, and / or the electronic device 600 can communicate with any device that can communicate with one or more other computing devices (such as a router, a modem, etc.). Such communication can be carried out through the input / output (I / O) interface 650. Moreover, the electronic device 600 can also communicate with one or more networks (such as a local area network (LAN), a wide area network (WAN), and / or a public network, such as the Internet) through the network adapter 660. The network adapter 660 can communicate with other modules of the electronic device 600 through the bus 630. It should be understood that, although not shown in the figure, other hardware and / or software modules can be used in combination with the electronic device 600, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems, etc.
[0105] Through the description of the above embodiments, those skilled in the art can easily understand that the example embodiments described herein can be implemented by software, or can be implemented by the way of software combined with necessary hardware. Therefore, as Figure 7 shown, the technical solution according to the embodiment of the present application can be embodied in the form of a software product, and the software product can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on a network, including several instructions to enable a computing device (which can be a personal computer, a server, or a network device, etc.) to execute the above method according to the embodiment of the present application.
[0106] The software product can adopt any combination of one or more readable media. The readable medium can be a readable signal medium or a readable storage medium. The readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples (a non-exhaustive list) of the readable storage medium include: an electrical connection with one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above.
[0107] The computer-readable storage medium may include a data signal propagated in a baseband or as part of a carrier wave, in which the readable program code is carried. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. The readable storage medium may also be any readable medium other than the readable storage medium, which may send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the readable storage medium may be transmitted using any appropriate medium, including but not limited to wireless, wired, optical fiber cable, RF, etc., or any suitable combination of the foregoing.
[0108] The program code for performing the operations of this application may be written in any combination of one or more programming languages, including object-oriented programming languages such as Java, C++, etc., and also including conventional procedural programming languages such as the "C" language or similar programming languages. The program code may be executed entirely on the user computing device, partially on the user device, executed as a stand-alone software package, partially on the user computing device and partially on a remote computing device, or entirely on a remote computing device or server. In the case of a remote computing device, the remote computing device may be connected to the user computing device through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computing device (e.g., by using an Internet service provider to connect through the Internet).
[0109] The above computer-readable medium carries one or more programs, and when the one or more programs are executed by a device, the computer-readable medium realizes the following functions: the load balancing device performs a TLS / SSL handshake with the server to be health-detected; parses the return message of the server during the TLS / SSL handshake to obtain a certificate; queries the matching item of the certificate in the certificate mapping table; after determining the matching item, extracts the X.509 data structure from the matching item; and performs the health detection of the server based on the X.509 data structure and the certificate.
[0110] Those skilled in the art can understand that the above-mentioned modules may be distributed in the device according to the description of the embodiments, or may be correspondingly changed and distributed in one or more devices that are uniquely different from the embodiments. The modules of the above embodiments may be combined into one module, or may be further split into multiple sub-modules.
[0111] Through the description of the above embodiments, those skilled in the art can easily understand that the exemplary embodiments described herein can be implemented by software or by a combination of software and necessary hardware. Therefore, the technical solutions according to the embodiments of the present application can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (which can be a CD-ROM, a USB flash drive, a mobile hard disk, etc.) or on the network, including several instructions to enable a computing device (which can be a personal computer, a server, a mobile terminal, or a network device, etc.) to execute the method according to the embodiments of the present application.
[0112] The exemplary embodiments of the present application have been specifically shown and described above. It should be understood that the present application is not limited to the detailed structures, setting manners, or implementation methods described herein; on the contrary, the present application is intended to cover various modifications and equivalent settings included within the spirit and scope of the appended claims.
Claims
1. A server health detection method based on the TLS / SSL protocol, characterized in that Comprising: The load balancing device performs a TLS / SSL handshake with the server to be health-checked; During the TLS / SSL handshake, parse the return message of the server to obtain the certificate; Query the matching item of the certificate in the certificate mapping table; After determining the matching item, extract the X.509 data structure from the matching item; Based on the X.509 data structure and the certificate, perform health detection on the server.
2. The method according to claim 1, characterized in that, Also comprising: When no matching item is found, parse the certificate to obtain its corresponding X.509 data structure; Generate the table entry corresponding to the certificate in the certificate mapping table through the X.509 data structure.
3. The method according to claim 2, wherein Parsing the certificate to obtain its corresponding X.509 data structure includes: Obtain the binary data corresponding to the certificate; Decode the certificate according to the ASN.1 encoding rule to generate the certificate content; Set the certificate content into the X.509 certificate structure to generate the X.509 data structure.
4. The method according to claim 3, wherein Setting the certificate content into the X.509 certificate structure to generate the X.509 data structure includes: Set the version, serial number, signature algorithm, signature hash algorithm, validity, user, public key information, and extension in the certificate content to the corresponding positions in the X.509 certificate structure according to the preset rules to generate the X.509 data structure.
5. The method according to claim 2, wherein Generating the table entry corresponding to the certificate in the certificate mapping table through the X.509 data structure includes: Use the binary data of the certificate as the key value; Use the X.509 data structure as the value value; Generate the table entry corresponding to the certificate in the certificate mapping table through the key value and the value value.
6. The method according to claim 1, wherein The load balancing device performs a TLS / SSL handshake with the server to be health-checked, including: The load balancing device creates a client; Construct a client hello message based on the client; Send the client hello message to the server to be health-checked for TLS / SSL handshake.
7. The method according to claim 1, characterized in that Parsing the return message of the server to obtain the certificate during the TLS / SSL handshake includes: Obtain the server hello message and server certificate message returned by the server during the TLS / SSL handshake; Parse the server certificate message to obtain the certificate.
8. The method according to claim 7, wherein Parsing the server certificate message to obtain the certificate data includes: Parse the server certificate message to obtain the certificate chain; Traverse the certificate chain to extract each certificate.
9. The method according to claim 1, characterized in that, Querying the matching item of the certificate data in the certificate mapping table includes: Obtain the binary data corresponding to the certificate; Query the matching item of the certificate data in the locally cached certificate mapping table according to the binary data.
10. A server health detection device based on the TLS / SSL protocol, characterized in that, Comprising: A handshake module for performing a TLS / SSL handshake between the load balancing device and the server to be health-checked; A parsing module, configured to parse the return message of the server during the TLS / SSL handshake process to obtain a certificate; A query module, configured to query a matching item of the certificate in a certificate mapping table; A structure module, configured to extract an X.509 data structure from the matching item after determining the matching item; A detection module, configured to perform a health check on the server based on the X.509 data structure and the certificate.
Citation Information
Cited By
A method and system for automated certificate management and dynamic threshold early warning
CN122578338A