Automatic deployment method and device for password service platform

Through encryption processing and hardware binding rules, the license file is generated, combined with Ansible operation and maintenance components and optimized user interface, the compatibility and security issues of the automated deployment method of the password service platform in different operating system environments is solved, and a flexible and secure deployment process is achieved.

CN120492050AActive Publication Date: 2025-08-15BEIJING CERTIFICATE AUTHORITY +1
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510563360.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-30
Publication Date
2025-08-15
Estimated Expiration
2045-04-30

AI Technical Summary

Technical Problem

The existing password service platform automation deployment method is not compatible in different operating system environments, the license file generation and activation process poses security risks, and lacks customized support.

Method used

Encryption processing and hardware binding rules are used to generate license files, collect deployment variables and generate configuration files, and pass deployment instructions through Ansible operation and maintenance components to optimize the user interface for improved flexibility and security.

Benefits of technology

It realizes compatibility and security in different operating system environments, ensures the confidentiality of license files, improves deployment flexibility and adaptability, and reduces user learning costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120492050A_ABST
    Figure CN120492050A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an automatic deployment method and device for a password service platform, and the method comprises the steps: receiving a permission request file obtained through encryption processing, generating a permission file of the platform, verifying the permission file, and completing the deployment process of the permission file; collecting deployment variables of the front-end page, and processing the deployment variables to generate a configuration file; an instruction for deploying each service is transmitted to a target deployment node, a deployment task is executed, and a configuration deployment process is completed; the security and confidentiality of the license file are ensured by adopting encryption processing and a hardware binding rule, and the deployment parameters are defined according to different deployment environments and requirements in the deployment and configuration process, so that the flexibility and adaptability of deployment are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of platform deployment technology, and more specifically, to a method and device for automated deployment of a cryptographic service platform. Background Art

[0002] The cryptographic service automated deployment platform primarily provides automated installation and supports the deployment of trusted computing systems and databases. Its underlying technology utilizes the Go language combined with Ansible operations and maintenance components. However, existing technologies may lack customized support for specific user needs during automated deployment, resulting in incompatibility when deployed across different operating systems. Furthermore, the generation and activation of license files presents security risks, such as interception or tampering during transmission. Summary of the Invention

[0003] The purpose of the embodiments of the present application is to provide a method and device for automatic deployment of a cryptographic service platform, so as to solve the problem that the existing method for automatic deployment of a cryptographic service platform is incompatible when deployed in different operating system environments, and that there are certain security risks in the generation and activation process of the license file.

[0004] In a first aspect, an embodiment of the present application provides a method for automatically deploying a cryptographic service platform, which is applied to a cryptographic service platform, including:

[0005] Receive the encrypted license request file, generate the platform's license file, verify the license file, and complete the license file deployment process;

[0006] Collect the deployment variables of the front-end page, process the deployment variables, and generate configuration files; deployment variables are deployment parameters defined according to different deployment environments and requirements;

[0007] Deliver the instructions for deploying each service to the target deployment node, execute the deployment tasks, and complete the configuration and deployment process.

[0008] In the above implementation process, the embodiment of the present application receives a license request file obtained through encryption, generates a license file for the platform, and verifies the license file to complete the deployment process of the license file; collects deployment variables of the front-end page, processes the deployment variables, and generates a configuration file; passes the instructions for deploying each service to the target deployment node, executes the deployment task, and completes the configuration deployment process; by adopting encryption processing and rules bound to hardware, the security and confidentiality of the license file are ensured. During the deployment and configuration process, deployment parameters are defined according to different deployment environments and requirements to improve the flexibility and adaptability of the deployment.

[0009] Furthermore, before receiving the encrypted license request file, the method further includes:

[0010] Assembling a related object of the license request and converting the object into a string in a first set format; wherein the fields of the related object of the license request include: license version number, product serial number, hardware information and generation date;

[0011] Use the locally generated random number to symmetric encrypt the string in the first set format, and use the built-in asymmetric encryption public key to encrypt the random number;

[0012] Concatenate the encrypted character string and the encrypted random number to obtain concatenated data;

[0013] The spliced data is written into a file to obtain a license request file.

[0014] In the above implementation process, the security and confidentiality of the license request file are ensured by adopting the encryption algorithm and signature algorithm of the national secret standard.

[0015] Furthermore, the verification of the license file includes:

[0016] Based on the hardware binding rules, the hardware information of the license file is verified through the built-in public key;

[0017] The file information of the license file is verified through the built-in public key, where the file information includes the signature value, expiration time, product model, and product function identifier.

[0018] In the above implementation process, by adopting the rule of binding with hardware, it is ensured that the license file is associated with the specific hardware to prevent unauthorized use.

[0019] Furthermore, the deployment variables of the front-end page are collected, the deployment variables are processed, and a configuration file is generated, including:

[0020] Collect deployment variables for the front-end page; deployment variables include: deployment node IP, network card name used by the connection detection mechanism, IP and password of each database, and log storage path;

[0021] Store the deployment variables in a file in a second setting format that can be recognized by the setting operation and maintenance component, and process the variables using the setting template syntax;

[0022] Based on the specified syntax, deploy variables to different roles. Each role corresponds to a specified component or service, and ensure that the variables for each role are configured correctly.

[0023] Dynamically generates configuration files based on the deployment variables and configuration file templates assigned to the component, and replaces the variables in the default configuration file in the deployment package.

[0024] In the above implementation process, the flexibility and adaptability of deployment are improved.

[0025] Furthermore, the deployment parameters defined according to different deployment environments and requirements include:

[0026] Using packaged configuration management tools and setting operation and maintenance components, it accepts user-defined deployment parameters based on different deployment environments and requirements. Among them, supported configuration dimensions include: operating system type, operating system version, operating system architecture, secret service product version, and database type.

[0027] Among them, by setting up a dynamic inventory mechanism for the operation and maintenance components, the target host IP configured directly by the user on the deployment page is received, and a host list is dynamically generated.

[0028] In the above implementation process, deployment parameters such as operating system, operating system version, architecture and other parameters are customized according to different deployment environments and requirements of users, thereby improving the flexibility and adaptability of packaged deployment.

[0029] Furthermore, it also includes:

[0030] Optimize the user interface.

[0031] Furthermore, the optimizing of the user interface includes:

[0032] The user interface uses the Vue development framework to display the status and log information of the deployment nodes in real time; the deployment nodes include: machine initialization, middleware installation, and service node deployment;

[0033] Optimize the interactive design of the user interface.

[0034] In the above implementation process, an intuitive user interface is provided to display deployment nodes and log information in real time, improving the user interaction experience.

[0035] In a second aspect, an embodiment of the present application provides an automated deployment device for a cryptographic service platform, which is integrated into the cryptographic service platform and includes:

[0036] The license processing module is used to receive the encrypted license request file, generate the platform license file, verify the license file, and complete the license file deployment process;

[0037] The configuration processing module is used to collect the deployment variables of the front-end page, process the deployment variables, and generate configuration files; wherein, the deployment variables are deployment parameters defined according to different deployment environments and requirements;

[0038] The deployment processing module is used to pass the deployment instructions of each service to the target deployment node, execute the deployment tasks, and complete the configuration deployment process.

[0039] In a third aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a server, the automatic deployment method of the cryptographic service platform as described above is implemented.

[0040] In a fourth aspect, an embodiment of the present application provides a computer program product, which includes instructions. When the instructions are executed by a computer, the computer implements the method as described above. BRIEF DESCRIPTION OF THE DRAWINGS

[0041] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments of the present application. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other relevant drawings can be obtained based on these drawings without creative work.

[0042] Figure 1 A flowchart of a method for automatically deploying a cryptographic service platform provided in an embodiment of the present application;

[0043] Figure 2 This is a schematic diagram of the structure of an automatic deployment device for a cryptographic service platform provided in an embodiment of the present application;

[0044] Figure 3 This is a structural diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0045] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.

[0046] It should be noted that similar reference numerals and letters represent similar items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and should not be understood as indicating or implying relative importance.

[0047] Ansible operation and maintenance components refer to the core functional modules that constitute its automation architecture, which are used to implement operation and maintenance operations such as configuration management, application deployment, and task orchestration.

[0048] The FAQ (Frequently Asked Questions) module is an important entry point for users to obtain key information. When designing it, it should focus on user needs and provide clear and professional answers.

[0049] The Cryptographic Service Automated Deployment Platform primarily provides automated installation and supports the deployment of trusted systems and databases. Its underlying technology uses the Go language combined with Ansible operation and maintenance components. The following is a brief description of the existing technical solutions:

[0050] The CryptoCloud Deployment Module: As the core of the deployment platform, this module is responsible for the deployment and installation of each node on the CryptoCloud platform. This module includes reading deployment instructions, server testing, developing deployment strategies, configuring middleware and services, and initiating the installation process. After installation, the platform provides a detailed deployment table, allowing users to clearly understand the deployment details of each service and module.

[0051] License Management: This module manages the authorization of the cryptographic service platform. Users are required to enter information such as the production serial number, project number, and the number of cryptographic resources authorized. A signature value is calculated using a national cryptographic algorithm to generate a request file. The user submits this file to the production department to generate a license file (LIC). This file is then imported to activate and use the cryptographic service functions corresponding to the LIC.

[0052] Deployment Logs: This module displays logs generated during the deployment process, facilitating troubleshooting. Users can view and download logs to better monitor the deployment process and analyze potential issues.

[0053] FAQ: This module summarizes common deployment issues and their solutions, helping users use the platform more efficiently. It also includes dependency diagrams between modules and services, allowing users to more clearly understand the structure and components of the cryptographic services platform.

[0054] However, existing technologies may lack customized support for specific user needs during automated deployment, resulting in incompatibility or manual deployment across different operating systems. The license file generation and activation process can be cumbersome and pose security risks, such as interception or tampering during transmission. Log analysis capabilities may be limited, requiring additional tools or specialized knowledge for in-depth analysis of log data. Compatibility and scalability may also be limited, making it difficult to adapt to changing hardware and software environments.

[0055] Based on this, this application proposes a method for automatic deployment of a cryptographic service platform to solve the above problems.

[0056] Please see Figure 1 , Figure 1 This is a flow chart of a method for automatically deploying a cryptographic service platform provided in an embodiment of the present application. The method for automatically deploying a cryptographic service platform includes:

[0057] 100. Receive the encrypted license request file, generate a platform license file, verify the license file, and complete the license file deployment process.

[0058] In some embodiments, before receiving the encrypted license request file, the method further includes:

[0059] 11. Assemble the relevant object of the license request and convert the object into a character string in a first set format; wherein the fields of the relevant object of the license request include: license version number, product serial number, hardware information and generation date.

[0060] Exemplarily, assemble a licReq object: containing the following fields: version: lic version number; sn: product serial number, assigned by the production platform; hwinfo: hardware information, including MAC address, taking the hash value of the MAC address of the first network card; gendate: generation date.

[0061] 12. Use the locally generated random number to symmetric encrypt the string in the first set format, and use the built-in asymmetric encryption public key to encrypt the random number.

[0062] For example, the licReq object is converted into an XML-formatted string, the XML content is encrypted using a locally generated random number (key), and the random number is encrypted using a built-in SM2 public key.

[0063] 13. Concatenate the encrypted character string and the encrypted random number to obtain concatenated data.

[0064] Exemplarily, the encrypted string and the encrypted random number are concatenated in a fixed format, for example: [encrypted string length identifier][encrypted string][delimiter][encrypted random number length identifier][encrypted random number]; or a simple delimiter is used to connect them directly.

[0065] 14. Write the spliced data into a file and obtain a license request file.

[0066] Optionally, the spliced data is formatted to correspond to the format of the file.

[0067] Exemplarily, writing the spliced data sequentially: appending the spliced data directly to the end of the file; writing the spliced data in a formatted manner: writing the data into the file using a structure such as JSON or XML.

[0068] Optionally, a unique identifier (such as UUID) or a timestamp is used to name the license request file, and metadata (such as version number, generation time) is added in the file header or comments.

[0069] In some embodiments, verifying the license file includes: verifying the hardware information of the license file through the built-in public key based on the hardware binding rules; verifying the file information of the license file through the built-in public key, wherein the file information includes the signature value, expiration time, product model, and product function identification; thereby, by adopting the rules binding to the hardware, it is ensured that the license file is associated with specific hardware to prevent unauthorized use.

[0070] 200. Collect deployment variables of the front-end page, process the deployment variables, and generate a configuration file; wherein the deployment variables are deployment parameters defined according to different deployment environments and requirements.

[0071] Among them, the deployment parameters defined according to different deployment environments and requirements include: using packaged configuration management tools and setting operation and maintenance components to receive user-defined deployment parameters based on different deployment environments and requirements; among them, the supported configuration dimensions are: operating system type, operating system version, operating system architecture, secret service product version, and database type.

[0072] Among them, by setting up a dynamic inventory mechanism for the operation and maintenance components, the target host IP configured directly by the user on the deployment page is received, and a host list is dynamically generated.

[0073] For example, the introduction of Jenkins packaging configuration management and Ansible operation and maintenance components allows users to customize deployment parameters according to different deployment environments and requirements.

[0074] Supported configuration dimensions: Operating system type: supports multiple trusted operating systems; Operating system version: supports different versions of operating systems; Operating system architecture: supports both x86 and ARM architectures; Secret service product version: supports different versions of secret service products to meet customers' functional requirements; Database type: supports multiple mainstream databases, including MySQL, Kingbase, Dameng, Gauss, etc.; Dynamic management: Through Ansible's dynamic inventory mechanism, users can directly configure the target host IP on the deployment page and dynamically generate a host list, thereby flexibly meeting multi-machine deployment needs.

[0075] Jenkins is an open-source automation server used for continuous integration and continuous delivery. Inventory is a file used by Ansible to manage hosts and host groups.

[0076] 210. Collect deployment variables of the front-end page; wherein, the deployment variables include: deployment node IP, network card name used by the connection detection mechanism, IP and password of each database, and log storage path.

[0077] For example, front-end page variable collection: users fill in the following variables on the front-end page of the deployment platform: deployment node IP; network card name used by the connection detection mechanism Keepalive; database, Kafka, Zookeeper, Elasticsearch IP and password; log storage path and other related variables.

[0078] As you can imagine, Kafka, Zookeeper, and Elasticsearch are commonly used technical components in the fields of big data and distributed systems. They each have distinct responsibilities and often work together in the technology stack. Kafka is a distributed stream processing platform used to build real-time data streaming pipelines and stream processing applications. Zookeeper is a distributed coordination service used to manage configuration, naming, and synchronization services. Elasticsearch is a distributed search and analytics engine used for real-time search and analysis of large amounts of text data.

[0079] 220. Store the deployment variables in a file of a second setting format recognizable by the setting operation and maintenance component, and process the variables using the setting template syntax.

[0080] For example, the collected variables are stored in a YAML file that is recognizable by the Ansible operation and maintenance component. Some variables are processed using Jinja2 template syntax, such as: multi-IP format processing: formatting multiple IP addresses into a format that meets the requirements of the configuration file; password encryption: encrypting sensitive information (such as database passwords, Kafka passwords, etc.).

[0081] Among them, Jinja2 is a powerful and flexible template engine in Python, which is widely used to generate dynamic HTML, XML, JSON and other text content.

[0082] 230. Based on the set syntax, assign deployment variables to different roles; each role corresponds to a set component or service, and ensure that the variables of each role are configured correctly.

[0083] For example, based on the Role syntax of Ansible Playbook, the processed variables are assigned to different roles: each role corresponds to a set component or service (such as database role, Kafka role, Zookeeper role, etc.), ensuring that the variables in each role are configured correctly and independently.

[0084] 240. Dynamically generate configuration files based on the deployment variables and configuration file templates assigned to the component, and replace the variables in the default configuration file in the deployment package.

[0085] For example, the Ansible operation and maintenance component dynamically generates a real configuration file based on the deployment variables and configuration file template assigned to the Role; replaces the default configuration file in the deployment package, and ensures that the variables in the configuration file are correctly filled.

[0086] 300. Deliver the instructions for deploying each service to the target deployment node, execute the deployment task, and complete the configuration and deployment process.

[0087] Specifically, the deployment instructions for each service are delivered to the target deployment node, and each target deployment node executes the deployment task according to the generated configuration file. Optionally, verification is performed after the deployment task is executed, such as executing automated test cases to verify whether the new configuration is effective, verifying the service status (such as HTTP response code, port listening), and checking log files to confirm that there are no error logs. This completes the configuration and deployment process.

[0088] As described above, the embodiment of the present application receives a license request file obtained through encryption, generates a license file for the platform, and verifies the license file to complete the deployment process of the license file; collects deployment variables from the front-end page, processes the deployment variables, and generates a configuration file; passes the instructions for deploying each service to the target deployment node, executes the deployment task, and completes the configuration deployment process; by adopting encryption processing and rules bound to hardware, the security and confidentiality of the license file are ensured. During the deployment and configuration process, deployment parameters are defined according to different deployment environments and requirements to improve the flexibility and adaptability of the deployment.

[0089] In some embodiments, the automatic deployment method of the cryptographic service platform of the present application can also be concretized as follows: further comprising: optimizing the user interface.

[0090] Specifically, the Vue development framework is used for the user interface to display the status and log information of the deployment nodes in real time; thus, users can quickly understand the deployment progress and status.

[0091] Deployment nodes include: machine initialization, middleware installation, and service node deployment. For example, machine initialization completes basic environment configuration, such as server optimization and JDK environment installation.

[0092] For example, middleware installation includes databases (such as MySQL, PostgreSQL, Gauss), Redis, Kafka, Elasticsearch, etc.

[0093] Exemplarily, the deployed service nodes include: monitoring platform, configuration center, authentication service, microservice management platform, API gateway, log platform, inspection service, Craas service, CFaas service, and KMS (key management service).

[0094] Specifically, we optimized the interactive design of the user interface, thereby providing clear navigation and help prompts, and reducing the user's learning cost.

[0095] Specifically, set up real-time log monitoring in the user interface: the logs generated during the deployment process are updated in real time, and users can view and download the logs at any time.

[0096] For example, the cryptographic service platform of the embodiment of the present application is designed with full consideration of the characteristics of domestic software and hardware to ensure compatibility with domestic environments. Extensive compatibility testing is performed during the development process to ensure that the platform can run stably in various domestic software and hardware environments.

[0097] It is understandable that in today's digital age, data security is of vital importance, especially in the field of cryptographic service management. The security of the license file is directly related to the stable operation of the entire system and the protection of user rights and interests. The embodiment of the present application adopts the national secret SM4 encryption algorithm to encrypt the contents of the license file, and then uses the national secret SM2 asymmetric algorithm to perform built-in public key encryption on the key in the above process. The SM4 algorithm has extremely high security and reliability. It uses a 256-bit key length and encrypts the data through complex nonlinear transformations and round function operations. It can effectively resist various forms of attacks, ensure the confidentiality of the license file during transmission and storage, and prevent data from being stolen or tampered with. During the data transmission process, even if the data is intercepted, due to the high-intensity protection of the encryption algorithm, it is difficult for the attacker to obtain valid information.

[0098] During the license generation process, the embodiment of the present application binds the license to specific hardware by reading specific information of the hardware device, such as the MAC address. The MAC address is the unique identifier of a network device and is globally unique. By reading the MAC address, the hardware device can be accurately identified. In actual operation, when a user applies for a license, the system automatically reads the MAC address of the user's device and associates it with the content of the license request file. This binding method ensures that the license can only be used on authorized hardware devices, effectively preventing the illegal copying and dissemination of the license. Even if someone else obtains the license file, if the MAC address of their hardware device is inconsistent with the bound MAC address, they will not be able to activate and use the license, thereby protecting the intellectual property rights and legal rights of the software provider.

[0099] During license activation, the cryptographic service platform module subsystem automatically verifies that the hardware information matches the binding information in the license. The verification process generally proceeds as follows: the system first reads the current device's MAC address and then compares it with the MAC address recorded in the license file. If the two are identical, verification succeeds, and the user can activate and use the license normally. If they are inconsistent, such as due to expiration or license content decryption failure, verification fails, the system denies activation, and alerts the user of possible illegal use. This rigorous verification mechanism further enhances license management security, ensures the legal use of software, and provides reliable protection for users and software providers.

[0100] The user interface of the embodiment of the present application has the function of displaying the status of deployment nodes and log information in real time, so that users can understand the deployment progress and status in real time and intuitively. During the deployment process, the user interface will display the detailed information of each deployment node in the form of a graphic or list, including node name, IP address, deployment progress, current status (such as being deployed, deployment successful, deployment failed, etc.) and related log information. Through this real-time display function, users can keep abreast of the dynamics of deployment at any time, and promptly discover and solve possible problems. When a certain node fails to deploy, the user can immediately view the corresponding log information, quickly locate the problem, and take corresponding solutions, which greatly improves deployment efficiency and success rate.

[0101] The log monitoring system of the embodiment of the present application realizes a real-time log monitoring function. During the deployment process, the system will record and update the log information generated in real time. These log information records in detail each operation step, time and possible error information in the deployment process. Users can view these real-time logs at any time through the user interface to understand the detailed process and current status of the deployment. Users can also filter and query the logs according to their needs, for example, according to conditions such as time range and node name, so as to quickly find the information they are concerned about. This real-time log monitoring function provides users with timely and accurate deployment information, helps users to discover and solve problems in a timely manner, and ensures the smooth progress of deployment work.

[0102] To facilitate users' in-depth analysis and processing of logs, embodiments of the present application support users downloading logs at any time. Users can download log files locally and use professional log analysis tools for further analysis and processing. The downloaded log files can serve as records and backups of the deployment process for subsequent review and auditing. When problems arise, users can provide the downloaded log files to technical support personnel to help them quickly locate and resolve the problems. This log download function provides users with greater flexibility and convenience, helping to improve the quality and efficiency of deployment work.

[0103] The embodiment of the present application introduces Jenkins packaged configuration management and Ansible operation and maintenance components, which greatly improves the flexibility of deployment. Users can customize deployment parameters according to different deployment environments and requirements. Different configuration parameters may be required in development environments, test environments, and production environments, such as database connection addresses, server port numbers, log levels, etc. Through inventory files, Roles, Facts, Jinja2 templates, etc. in the Ansible operation and maintenance components, you can easily set corresponding parameters for different environments to achieve one-click installation and deployment. It can be completed without too much intervention in the server backend, which lowers the deployment threshold for front-line implementation and effectively improves efficiency. The compatibility of Xinchuang is wide.

[0104] During the platform design phase, the characteristics of domestically produced software and hardware were fully considered. From architectural design to functional module implementation, targeted optimization and adjustments were made to ensure compatibility with domestic environments. Regarding hardware, comprehensive adaptation and testing of domestically produced servers and storage devices were conducted to ensure the platform's stable operation across diverse domestic hardware platforms. Regarding software, deep integration and optimization with domestically produced operating systems, databases, and middleware were implemented to achieve seamless integration. Compatibility testing and optimization with various databases were conducted to ensure the platform's normal operation within these software environments, fully leveraging its functionality and performance.

[0105] The above steps are not to be performed in a strict order as described in the numbers, but should be understood as an overall solution.

[0106] In the second aspect, based on the above embodiments, Figure 2 This is a schematic diagram of the structure of an automatic deployment device for a cryptographic service platform provided in an embodiment of the present application. Figure 2 The automatic deployment device for the cryptographic service platform provided in this embodiment specifically includes: a license processing module 201 , a configuration processing module 202 and a deployment processing module 203 .

[0107] Among them, the license processing module 201 is used to receive the license request file obtained through encryption, generate the platform's license file, and verify the license file to complete the deployment process of the license file; the configuration processing module 202 is used to collect the deployment variables of the front-end page, process the deployment variables, and generate a configuration file; among them, the deployment variables are deployment parameters defined according to different deployment environments and requirements; the deployment processing module 203 is used to pass the instructions for deploying each service to the target deployment node, execute the deployment task, and complete the configuration deployment process.

[0108] As described above, the embodiment of the present application receives a license request file obtained through encryption, generates a license file for the platform, and verifies the license file to complete the deployment process of the license file; collects deployment variables from the front-end page, processes the deployment variables, and generates a configuration file; passes the instructions for deploying each service to the target deployment node, executes the deployment task, and completes the configuration deployment process; by adopting encryption processing and rules bound to hardware, the security and confidentiality of the license file are ensured. During the deployment and configuration process, deployment parameters are defined according to different deployment environments and requirements to improve the flexibility and adaptability of the deployment.

[0109] The automatic deployment device for the cryptographic service platform provided in the embodiment of the present application can be used to execute the automatic deployment method for the cryptographic service platform provided in the above embodiment, and has corresponding functions and beneficial effects.

[0110] In a third aspect, an embodiment of the present application further provides an electronic device that can integrate the automatic deployment device of the cryptographic service platform provided in an embodiment of the present application. Figure 3 This is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Figure 3 The electronic device includes: an input device 33, an output device 34, a memory 32, and one or more processors 31; the memory 32 is used to store one or more programs; when the one or more programs are executed by the one or more processors 31, the one or more processors 31 implement the automatic deployment method of the cryptographic service platform provided in the above embodiment. The input device 33, the output device 34, the memory 32, and the processor 31 can be connected by a bus or other means. Figure 3 The bus connection is taken as an example.

[0111] The processor 31 executes various functional applications and data processing of the device by running the software programs, instructions and modules stored in the memory 32, thereby realizing the above-mentioned automatic deployment method of the cryptographic service platform.

[0112] The electronic device provided above can be used to execute the automatic deployment method of the cryptographic service platform provided in the above embodiment, and has corresponding functions and beneficial effects.

[0113] In a fourth aspect, an embodiment of the present application also provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned method for automated deployment of the cryptographic service platform, and can achieve the same beneficial effects.

[0114] Of course, the storage medium containing computer-executable instructions provided in an embodiment of the present application is not limited to the automatic deployment method of the cryptographic service platform as described above, and can also execute related operations in the automatic deployment method of the cryptographic service platform provided in any embodiment of the present application.

[0115] In a fifth aspect, the embodiments of the present application further provide a computer program product, and the methods described in the various embodiments of the present application can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer programs or instructions. When the computer program or instruction is loaded and executed on a computer, the processes or functions described in the various embodiments of the present application are executed in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, a network device, a user device, a core network device, an OAM (Open Application Model) or other programmable device.

[0116] The computer program or instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer program or instructions may be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via a wired or wireless method. The computer-readable storage medium may be any available medium that can be accessed by a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium may be a magnetic medium, such as a floppy disk, a hard disk, or a magnetic tape; an optical medium, such as a digital video disk; or a semiconductor medium, such as a solid-state drive. The computer-readable storage medium may be a volatile or non-volatile storage medium, or may include both volatile and non-volatile types of storage media.

[0117] In the several embodiments provided in this application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely illustrative. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architectures, functions and operations of the devices, methods and computer program products according to the multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of the code, and the module, program segment or a part of the code contains one or more executable instructions for implementing the specified logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in an order different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart, can be implemented using a dedicated hardware-based system that performs the specified function or action, or can be implemented using a combination of dedicated hardware and computer instructions.

[0118] In addition, the functional modules in each embodiment of the present application can be integrated together to form an independent part, or each module can exist independently, or two or more modules can be integrated to form an independent part.

[0119] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling an electronic device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0120] The foregoing is merely an embodiment of the present application and is not intended to limit the scope of protection of the present application. Various modifications and variations are possible for those skilled in the art. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included within the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following figures. Therefore, once an item is defined in one figure, it does not need to be further defined or explained in subsequent figures.

[0121] The above description is merely a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

[0122] It should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply the existence of any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of other identical elements in the process, method, article, or device comprising the element.

Claims

1. A method for automatic deployment of a cryptographic service platform, characterized in that: Applied to a cryptographic service platform, the method includes: Receive the encrypted license request file, generate the platform's license file, verify the license file, and complete the license file deployment process; Collect the deployment variables of the front-end page, process the deployment variables, and generate configuration files; deployment variables are deployment parameters defined according to different deployment environments and requirements; Deliver the instructions for deploying each service to the target deployment node, execute the deployment tasks, and complete the configuration and deployment process.

2. The method for automatic deployment of a cryptographic service platform according to claim 1, characterized in that: Before receiving the encrypted license request file, the method further includes: Assembling a related object of the license request and converting the object into a string in a first set format; wherein the fields of the related object of the license request include: license version number, product serial number, hardware information and generation date; Use the locally generated random number to symmetric encrypt the string in the first set format, and use the built-in asymmetric encryption public key to encrypt the random number; Concatenate the encrypted character string and the encrypted random number to obtain concatenated data; The spliced data is written into a file to obtain a license request file.

3. The method for automatic deployment of a cryptographic service platform according to claim 1, characterized in that: The verification of the license file includes: Based on the hardware binding rules, the hardware information of the license file is verified through the built-in public key; The file information of the license file is verified through the built-in public key, where the file information includes the signature value, expiration time, product model, and product function identifier.

4. The method for automatic deployment of a cryptographic service platform according to claim 1, characterized in that: The process of collecting deployment variables of the front-end page, processing the deployment variables, and generating a configuration file includes: Collect deployment variables for the front-end page; deployment variables include: deployment node IP, network card name used by the connection detection mechanism, IP and password of each database, and log storage path; Store the deployment variables in a file in a second setting format that can be recognized by the setting operation and maintenance component, and process the variables using the setting template syntax; Based on the specified syntax, deploy variables to different roles. Each role corresponds to a specified component or service, and ensure that the variables for each role are configured correctly. Dynamically generates configuration files based on the deployment variables and configuration file templates assigned to the component, and replaces the variables in the default configuration file in the deployment package.

5. The method for automatic deployment of a cryptographic service platform according to claim 1, characterized in that: The deployment parameters defined according to different deployment environments and requirements include: Using packaged configuration management tools and setting operation and maintenance components, it accepts user-defined deployment parameters based on different deployment environments and requirements. Among them, supported configuration dimensions include: operating system type, operating system version, operating system architecture, secret service product version, and database type. Among them, by setting up a dynamic inventory mechanism for the operation and maintenance components, the target host IP configured directly by the user on the deployment page is received, and a host list is dynamically generated.

6. The method for automatic deployment of a cryptographic service platform according to claim 1, characterized in that: Also includes: Optimize the user interface.

7. The method for automatic deployment of a cryptographic service platform according to claim 6, characterized in that: The optimizing of the user interface includes: The user interface uses the Vue development framework to display the status and log information of the deployment nodes in real time; the deployment nodes include: machine initialization, middleware installation, and service node deployment; Optimize the interactive design of the user interface.

8. A cryptographic service platform automated deployment device, characterized in that: Integrated into the cryptographic service platform, including: The license processing module is used to receive the encrypted license request file, generate the platform license file, verify the license file, and complete the license file deployment process; The configuration processing module is used to collect the deployment variables of the front-end page, process the deployment variables, and generate configuration files; wherein, the deployment variables are deployment parameters defined according to different deployment environments and requirements; The deployment processing module is used to pass the deployment instructions of each service to the target deployment node, execute the deployment tasks, and complete the configuration deployment process.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a server, implements the method for automatic deployment of a cryptographic service platform as described in any one of claims 1 to 7.

10. A computer program product, characterized in that The computer program product includes instructions, which, when executed by a computer, enable the computer to implement the automatic deployment method for a cryptographic service platform as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Container type localization deployment method and system, equipment and storage medium

    CN113204410A

  • Method and device for constructing and deploying password service platform, terminal and storage medium

    CN114157448A

  • Application system version deployment method and system, storage medium and electronic equipment

    CN114741714A

  • Automatic deployment method and system based on YAML, electronic equipment and storage medium

    CN115811475A

  • Cloud platform management method and apparatus, electronic device and readable storage medium

    WO2019109943A1