Management method and system of access control list and computer readable storage medium

The access control list is legality checks and digitally signed through the signature server, which solves the problem of long and cumbersome update cycle of the access control list, realizes active user updates and real-time verification, and improves management efficiency and system flexibility.

CN120498893APending Publication Date: 2025-08-15SHANDONG YUNHAI GUOCHUANG CLOUD COMPUTING EQUIP IND INNOVATION CENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510935702.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-07
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

In the prior art, the update cycle of access control lists is long and cumbersome, and users cannot actively update, resulting in inefficient system management.

Method used

Through the signature server, the target access control list sent by the service server is subject to legality checks and digital signatures, breaking the traditional firmware update mode and real-time verification of users.

Benefits of technology

Shorten the update cycle of the access control list, and change from a long cycle that depends on the manufacturer's firmware upgrade to real-time response, improving management efficiency and system flexibility and real-timeness.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498893A_ABST
    Figure CN120498893A_ABST
Patent Text Reader

Abstract

The invention discloses an access control list management method and system and a computer readable storage medium, belongs to the field of servers, and considers the form that a manager carries out digital signature through a signature server, not only can the legality of a target access control list proposed by a user be verified, but also the validity of the target access control list can be verified. According to the method, the signature server and the service server, high efficiency can be realized through interaction with the service server, so that the signature server performs legality verification on the target access control list sent by the service server, performs digital signature and returns the target access control list after the target access control list passes the legality verification, and the service server executes access control according to the target access control list subjected to digital signature. A traditional firmware updating mode is broken through, a user can actively submit updating and sign server real-time verification, the updating period of the access control list is shortened from a long period depending on manufacturer firmware upgrading to real-time response, the management efficiency is improved, the problem that the updating period is long and tedious is solved, and the flexibility and the real-time performance of the system are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of servers, and in particular to a method and system for managing an access control list and a computer-readable storage medium. Background Art

[0002] Servers usually include many types of access control lists (such as blacklists or whitelists, etc.). Any access control list can be used to implement permission control operations for each object in the access control list. Access control lists are usually stored in the firmware, which means that the access control lists need to be updated along with the manufacturer's firmware version update operations. However, in reality, users have the need to actively update the access control lists. In this case, the user usually informs the manufacturer of the new access control list, and the manufacturer updates the access control list by updating the firmware version. This leads to the problem of a long and cumbersome access control list update cycle.

[0003] Therefore, how to provide a solution to the above technical problems is a problem that those skilled in the art need to solve at present. Summary of the Invention

[0004] The present invention aims to provide an access control list management method, system, and computer-readable storage medium. In this invention, a signature server verifies the legitimacy of a target access control list sent by a service server, digitally signs and returns the valid list if it passes. The service server then executes access control based on the digitally signed target access control list. This invention breaks with the traditional firmware update model, allowing users to proactively submit updates, which are then verified in real time by the signature server. This shortens the access control list update cycle from the long cycle typically associated with manufacturer firmware upgrades to a real-time response, improving management efficiency, resolving the issue of long and cumbersome update cycles, and enhancing system flexibility and real-time performance.

[0005] To solve the above technical problems, the present invention provides an access control list management method applied to a signature server, comprising:

[0006] Determine whether the preset members in the target access control list sent by the business server can pass the validity check, wherein the target access control list includes member information of the preset members of the target object;

[0007] If it passes, digitally sign the target access control list;

[0008] The digitally signed target access control list is sent to the business server so that the business server can perform access control on the target object according to the digitally signed target access control list.

[0009] On the other hand, the target control list is a backup power module whitelist of target components of the server, the target object is the backup power module, and the preset members include backup power modules of specified models;

[0010] Determining whether the preset members in the target access control list sent by the business server can pass the legitimacy check includes:

[0011] Determine whether the preset members in the target access control list sent by the business server can pass the model legitimacy verification;

[0012] Determine whether the preset members in the target access control list sent by the business server can pass the electrical parameter compliance check;

[0013] If both the model legality verification and the electrical parameter compliance check can be passed, it is determined that the legality check has been passed;

[0014] If the model legality verification and electrical parameter compliance check cannot be passed at the same time, it is determined that the legality check has failed.

[0015] On the other hand, determining whether the preset members in the target access control list sent by the business server can pass the model validity verification includes:

[0016] Determine whether each preset member of the target access list contains a preset member whose model is the same as the model in the existing whitelist, wherein the model in the existing whitelist is the model of each backup power module in the current backup power module whitelist of the target component;

[0017] If the model included is the same as the existing whitelist model, it is determined that the model legitimacy verification has failed;

[0018] Determining whether each preset member of the target access list includes a preset member whose manufacturer is not a preset authorized manufacturer;

[0019] If the manufacturer included is not a preset member of the preset authorized manufacturers, it is determined that the model legitimacy verification has not been passed;

[0020] If the model is not the same as the existing whitelist model and the manufacturer is not a preset member of the preset authorized manufacturer, it is determined that the preset member in the target access control list has passed the model legitimacy verification.

[0021] On the other hand, determining whether the preset members in the target access control list sent by the business server can pass the electrical parameter compliance check includes:

[0022] Determining whether electrical parameters of each preset member of the target access list meet hardware design requirements of the target component, wherein the electrical parameters include voltage, capacity, and charge and discharge rate;

[0023] If none of them meet the hardware design requirements of the target component, it is determined that the electrical parameter compliance check has failed;

[0024] Determining whether the electrical parameters of each preset member of the target access list meet the technical standards of the data backup power scenario of the target component, wherein the technical standards of the data backup power scenario include the power supply duration after power failure and energy storage efficiency;

[0025] If the technical standards of the data backup power scenario of the target component are not met, it is determined that the electrical parameter compliance check has failed;

[0026] If both meet the hardware design requirements of the target component and the technical standards of the data backup power scenario of the target component, the electrical parameter compliance check is determined to have passed.

[0027] On the other hand, digitally signing a target access control list includes:

[0028] Perform hash operation on the target access control list to generate the corresponding original hash value;

[0029] Encrypt the original hash value using the issuer's private key to obtain a digital signature;

[0030] The target access control list and the digital signature are encapsulated so as to be returned together.

[0031] On the other hand, the step of digitally signing the target access control list is performed in the hardware security module, including:

[0032] Creating a security sandbox in the trusted execution environment, and digitally signing the target access control list in the security sandbox, so as to isolate the operation of digitally signing the target access control list from the operating system kernel of the signing server;

[0033] Abnormal electromagnetic signals are detected in real time through the electromagnetic radiation monitoring module. When signs of side channel attacks are detected, the signing process is automatically terminated and an alarm is triggered. The signing process is: digitally signing the target access control list.

[0034] To solve the above technical problems, the present invention further provides an access control list management method, which is applied to a business server and includes:

[0035] Sending the target access control list to a signature server so that the signature server digitally signs the target access control list if the preset members in the target access control list pass the validity check, wherein the target access control list includes member information of the preset members of the target object;

[0036] Access control is performed on the target object based on the digitally signed target access control list sent by the signature server.

[0037] On the other hand, according to the digitally signed target access control list sent by the signature server, access control on the target object includes:

[0038] Receive the encapsulated target access control list and its data signature sent by the signature server;

[0039] Perform hash operation on the target access control list in the encapsulation to obtain the hash value to be verified;

[0040] Decrypting the encapsulated digital signature using a pre-stored public key to obtain an original hash value of the target access control list, wherein the digital signature is a digital signature obtained by performing a hash operation on the target access control list by the signature server and encrypting the original hash value using the issuer's private key, where the pre-stored public key and the issuer's private key together form an asymmetric key;

[0041] When the hash value to be verified is consistent with the original hash value, storing the target access control list in the encapsulation;

[0042] Access control is performed on the target object according to the stored target access control list.

[0043] To solve the above technical problems, the present invention further provides an access control list management system, comprising:

[0044] A signature server, configured to implement the access control list management method described above when executing a computer program;

[0045] The business server is used to implement the access control list management method described above when executing a computer program.

[0046] To solve the above technical problems, the present invention further provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the access control list management method described above are implemented.

[0047] Beneficial effects: The present invention provides a method for managing access control lists. Considering that the management party uses a signature server to perform digital signatures, it can not only verify the legitimacy of the target access control list proposed by the user, but also achieve high efficiency through interaction with the business server. Therefore, in the present invention, the signature server verifies the legitimacy of the target access control list sent by the business server, digitally signs and returns it after passing the verification, and the business server executes access control based on the digitally signed target access control list. The present invention breaks the traditional firmware update mode. Users can actively submit updates, and the signature server verifies them in real time, shortening the access control list update cycle from a long cycle that depends on the manufacturer's firmware upgrade to a real-time response, thereby improving management efficiency, solving the problem of long and cumbersome update cycles, and enhancing system flexibility and real-time performance.

[0048] The present invention also provides an access control list management system and a computer-readable storage medium, which have the same beneficial effects as the above access control list management method. BRIEF DESCRIPTION OF THE DRAWINGS

[0049] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the relevant technologies and the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0050] Figure 1 A schematic flow chart of a first access control list management method provided by the present invention;

[0051] Figure 2 A schematic structural diagram of an access control list management system provided by the present invention;

[0052] Figure 3 A schematic flow chart of a second access control list management method provided by the present invention;

[0053] Figure 4 A schematic flow chart of a third access control list management method provided by the present invention;

[0054] Figure 5 A schematic structural diagram of another access control list management system provided by the present invention;

[0055] Figure 6 A schematic structural diagram of a computer-readable storage medium provided by the present invention. DETAILED DESCRIPTION

[0056] The core of the present invention is to provide an access control list management method, system, and computer-readable storage medium. In this invention, a signature server verifies the legitimacy of a target access control list sent by a service server, digitally signs and returns the valid list. The service server then executes access control based on the digitally signed target access control list. This invention breaks with the traditional firmware update model. Users can proactively submit updates, and the signature server verifies them in real time. This shortens the access control list update cycle from the long cycle of relying on manufacturer firmware upgrades to a real-time response, improving management efficiency, resolving the problem of long and cumbersome update cycles, and enhancing system flexibility and real-time performance.

[0057] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0058] Please refer to Figure 1 , Figure 1 This is a flow chart of a first access control list management method provided by the present invention. The access control list management method is applied to a signature server and includes:

[0059] S101: Determine whether the preset members in the target access control list sent by the service server can pass the validity check, wherein the target access control list includes member information of the preset members of the target object;

[0060] Specifically, considering the technical problems in the above background technology, and considering that the management party uses the digital signature of the signature server, it can not only verify the legitimacy of the target access control list proposed by the user, but also achieve high efficiency through interaction with the business server. Therefore, in the embodiment of the present invention, the signature server and the business server are intended to cooperate, so that the user can submit the target access control list set by the business server, and the signature server can verify the legitimacy of the target access control list, and finally the business server can restrict access to the target object according to the verified target access control list, thereby realizing the "access control list update" efficiently, flexibly and conveniently, and improving work efficiency and user experience. The signature server is an important party in this process. Therefore, in the embodiment of the present invention, the access control list management method is first introduced from the perspective of the signature server.

[0061] Specifically, based on the above ideas, the task of the signature server is to wait for and process the target access control list sent by the business server. Therefore, in this step, it can be determined whether the preset members in the target access control list sent by the business server can pass the legitimacy check and trigger the relevant actions of the subsequent steps.

[0062] Among them, the target object is a type of object controlled by the target access control list. The target object can be of multiple types, for example, it can be a backup power module, and the preset member can be a backup power module of a specified model, etc., which is not limited in this embodiment of the present invention.

[0063] Specifically, the specific verification content of the legitimacy check is determined according to the management party's relevant requirements for the target object, which is related to the specific type of the target object. The specific verification content can be set independently by the management party. After the legitimacy check is passed, it indicates that the management party allows the preset members to exist legally in the target access control list, and the management party is responsible for this.

[0064] S102: If approved, digitally sign the target access control list;

[0065] Specifically, if the validity check can be passed, the signature server can digitally sign the target access control list for management convenience. On the one hand, it indicates that each preset member in the target access control list is legitimate and can be used by the business server as access control for the target object. On the other hand, it can also ensure the integrity of the target access control list, so that the business server uses a complete and correct target access control list.

[0066] S103: Sending the digitally signed target access control list to the service server so that the service server can perform access control on the target object according to the digitally signed target access control list.

[0067] Specifically, the digitally signed target access control list can then be sent to the business server, so that the business server can perform access control on the target object according to the digitally signed target access control list during operation.

[0068] The present invention provides a method for managing access control lists. Considering that the management party digitally signs the access control list through a signature server, not only can the legitimacy of the target access control list submitted by the user be verified, but high efficiency can also be achieved through interaction with the business server. Therefore, in the present invention, the signature server verifies the legitimacy of the target access control list sent by the business server, digitally signs and returns the valid access control list if it passes the verification, and the business server executes access control based on the digitally signed target access control list. This invention breaks away from the traditional firmware update model. Users can actively submit updates, and the signature server verifies them in real time. This shortens the access control list update cycle from the long cycle that depends on the manufacturer's firmware upgrade to a real-time response, improving management efficiency, solving the problem of long and cumbersome update cycles, and enhancing system flexibility and real-time performance.

[0069] Based on the above embodiment:

[0070] As an optional embodiment, the target control list is a backup power module whitelist of target components of the server, the target object is the backup power module, and the preset members include backup power modules of specified models;

[0071] Determining whether the preset members in the target access control list sent by the business server can pass the legitimacy check includes:

[0072] Determine whether the preset members in the target access control list sent by the business server can pass the model legitimacy verification;

[0073] Determine whether the preset members in the target access control list sent by the business server can pass the electrical parameter compliance check;

[0074] If both the model legality verification and the electrical parameter compliance check can be passed, it is determined that the legality check has been passed;

[0075] If the model legality verification and electrical parameter compliance check cannot be passed at the same time, it is determined that the legality check has failed.

[0076] Specifically, in the embodiment of the present invention, for the whitelist management of server backup power modules, in order to ensure that the connected backup power modules meet the requirements and avoid the use of incompatible or low-quality backup power modules that affect the server data security and backup power function, strict verification is performed from both the model and electrical parameters to ensure the reliability and compatibility of the backup power modules.

[0077] For example, in an enterprise's server cluster, one of the server components is a RAID card (Redundant Arrays of Independent Disks), and its backup power module whitelist is the target access control list. The business server sends a target access control list (TACL) containing a specified backup power module model (e.g., a supercapacitor of a certain brand, model XYZ, an electrochemical component that stores energy through polarized electrolytes) to the signature server. When the signature server identifies a member in the TACL sent by the business server, it first checks whether the supercapacitor model passes model validity verification, specifically checking whether its model matches the existing whitelisted supercapacitor model and whether the manufacturer is a pre-authorized vendor. It then checks its electrical parameters, such as voltage, whether the voltage falls within the RAID card hardware design requirements, whether the capacity meets the requirements, and whether the charge and discharge rate complies with the requirements. Only if both the model validity verification and electrical parameter compliance checks pass is the supercapacitor deemed valid and can proceed with subsequent signature operations.

[0078] Specifically, to better illustrate the embodiments of the present invention, please refer to Figure 2 and Figure 3 , Figure 2 A schematic diagram of the structure of an access control list management system provided by the present invention. Figure 3 This is a flow chart of the second access control list management method provided by the present invention. The configuration tool refers to the configuration tool in the business server. The business server can use the configuration tool to send the target access control list (the backup power module whitelist of the RAID controller) to the signature server and perform subsequent operations. The configuration tool can store the target access control list in the flash memory of the RAID controller after performing integrity verification on the digitally signed server sent by the signature server, so that the RAID controller can control access to its own backup power module through the target access control list during the startup process. The member information of the preset members in the target access control list here is actually capacitor information, which can include Vendor ID (vendor identifier), Device ID (device identifier), electrical parameters, etc., which is not limited in the embodiments of the present invention.

[0079] Among them, Figure 3In the example, the target access control list includes the capacitance information of certain capacitors. Therefore, the business server can first receive the capacitance information input, and the business server can generate and submit a whitelist request (target access control list) based on the input capacitance information. The signature server can perform a legitimacy check, and the signature server returns the whitelist (after digitally signing). The business server can write the whitelist into the flash memory (of the RAID controller), and the RAID controller loads the whitelist for capacitance verification.

[0080] Specifically, the configuration tool can send the target access control list to the RAID controller through a secure communication protocol (a new NVMe Controller (Non-Volatile Memory Express Controller, Non-Volatile Memory Host Controller Interface Specification Controller) protocol is added).

[0081] Of course, in addition to the above specific forms, the target access control list, the target object and the corresponding legality verification form can all be other types, which are not limited in the embodiment of the present invention.

[0082] As an optional embodiment, determining whether a preset member in the target access control list sent by the service server can pass the model validity verification includes:

[0083] Determine whether each preset member of the target access list contains a preset member whose model is the same as the model in the existing whitelist, wherein the model in the existing whitelist is the model of each backup power module in the current backup power module whitelist of the target component;

[0084] If the model included is the same as the existing whitelist model, it is determined that the model legitimacy verification has failed;

[0085] Determining whether each preset member of the target access list includes a preset member whose manufacturer is not a preset authorized manufacturer;

[0086] If the manufacturer included is not a preset member of the preset authorized manufacturers, it is determined that the model legitimacy verification has not been passed;

[0087] If the model is not the same as the existing whitelist model and the manufacturer is not a preset member of the preset authorized manufacturer, it is determined that the preset member in the target access control list has passed the model legitimacy verification.

[0088] Specifically, in order to more accurately determine the legitimacy of the preset member models in the target access control list, avoid repeated addition of existing models, and prevent access of products from unauthorized manufacturers, the embodiment of the present invention performs verification from two key perspectives: model duplication and manufacturer authorization, to ensure the uniqueness and source reliability of the backup power module model in the whitelist.

[0089] Specifically, in a cloud computing data center, the server's target component is a cache module used for data caching, and its backup power module whitelist is the target access control list. A business server submits a new target access control list containing multiple pre-set members, such as supercapacitors of different brands and models. When verifying the model legitimacy, the signature server first checks each pre-set member in the list to see if any of them match the supercapacitor model currently in the cache module backup power module whitelist. If any of them match, the model legitimacy verification is considered to have failed. The server then checks whether the manufacturer of each pre-set member is an authorized manufacturer. If any of them are not, the model legitimacy verification is also considered to have failed. Only when there is neither a pre-set member with the same model as an existing whitelisted model nor a pre-set member with a manufacturer that is not an authorized manufacturer, does the pre-set member in the target access control list pass the model legitimacy verification.

[0090] Of course, in addition to this specific form, "determining whether the preset members in the target access control list sent by the service server can pass the model legitimacy verification" can also be other specific forms, which are not limited in the embodiment of the present invention.

[0091] As an optional embodiment, determining whether a preset member in the target access control list sent by the service server can pass the electrical parameter compliance check includes:

[0092] Determining whether electrical parameters of each preset member of the target access list meet hardware design requirements of the target component, wherein the electrical parameters include voltage, capacity, and charge and discharge rate;

[0093] If none of them meet the hardware design requirements of the target component, it is determined that the electrical parameter compliance check has failed;

[0094] Determining whether the electrical parameters of each preset member of the target access list meet the technical standards of the data backup power scenario of the target component, wherein the technical standards of the data backup power scenario include the power supply duration after power failure and energy storage efficiency;

[0095] If the technical standards of the data backup power scenario of the target component are not met, it is determined that the electrical parameter compliance check has failed;

[0096] If both meet the hardware design requirements of the target component and the technical standards of the data backup power scenario of the target component, the electrical parameter compliance check is determined to have passed.

[0097] Specifically, the electrical parameters of the backup power module are crucial to its ability to provide stable and effective backup power support for target components. The embodiments of the present invention conduct checks based on both hardware design requirements and technical standards for data backup scenarios, enabling a comprehensive assessment of electrical parameter compliance and ensuring the backup power module's reliable performance in actual use, meeting the requirements for secure data storage and recovery.

[0098] For example, assume that in a financial institution's data processing server, the target component is a storage array used to store critical business data. The business server sends a target access control list containing specific supercapacitors (backup power modules) to the signature server. When determining whether the electrical parameters of these supercapacitors meet the requirements, the signature server first checks whether their voltage, capacity, charge and discharge rates, and other electrical parameters meet the hardware design requirements of the storage array. For example, if the storage array requires a supercapacitor voltage between 4.5V and 5.5V, a supercapacitor voltage of 4V would be considered to have failed the hardware design requirement check. Furthermore, the server checks whether these electrical parameters meet the technical standards for data backup power scenarios, such as a power supply duration of at least 10 minutes after a power outage and an energy storage efficiency exceeding 80%. If a supercapacitor's power supply duration after a power outage is only 8 minutes or its energy storage efficiency is 70%, the data backup power scenario technical standard check is considered to have failed. Only when the electrical parameters meet both the hardware design requirements and the data backup power scenario technical standards will the electrical parameter compliance check be considered passed.

[0099] As an optional embodiment, digitally signing the target access control list includes:

[0100] Perform hash operation on the target access control list to generate the corresponding original hash value;

[0101] The original hash value is encrypted using the issuer's private key to obtain a digital signature;

[0102] The target access control list and the digital signature are encapsulated and returned together.

[0103] Specifically, considering that digital signatures are an important means of ensuring the security and integrity of access control lists, embodiments of the present invention utilize hashing and private key encryption to prevent tampering with access control lists during transmission and storage, while also providing signer identity authentication to ensure that the access control lists received by the service server are from a reliable source and have not been modified.

[0104] Consider an e-commerce company's server system. A business server sends a target access control list (ACL) to a signature server, which manages user access rights to a product database. Upon receiving the ACL, the signature server first hashes the ACL using the SHA-256 (Secure Hash Algorithm 256) algorithm to generate a corresponding raw hash value. The signature server then encrypts the raw hash value using its own issuer private key (e.g., the private key of the RSA algorithm, an asymmetric encryption algorithm), generating a digital signature. Finally, the signature server encapsulates the target ACL with the generated digital signature and securely sends it back to the business server. Upon receiving the encapsulated data, the business server decrypts the digital signature using the signature server's public key, then performs the same hash operation on the target ACL. Comparing the two hash values, the server verifies the integrity and source of the ACL.

[0105] As an optional embodiment, the step of digitally signing the target access control list is performed in the hardware security module, including:

[0106] Creating a security sandbox in the trusted execution environment, and digitally signing the target access control list in the security sandbox, so as to isolate the operation of digitally signing the target access control list from the operating system kernel of the signing server;

[0107] The electromagnetic radiation monitoring module detects abnormal electromagnetic signals in real time. When signs of side-channel attacks are detected, the signing process is automatically terminated and an alarm is triggered. The signing process is: digitally signing the target access control list.

[0108] Specifically, in order to further enhance the security of the digital signature process, prevent the signature operation from external attacks, such as side-channel attacks, and protect the confidentiality and integrity of the access control list data during the signature process, the embodiments of the present invention ensure that the signature operation is performed in a safe environment by creating a security sandbox and real-time monitoring of abnormal electromagnetic signals.

[0109] Specifically, assume that within a high-performance computing server network at a scientific research institution, a signature server is responsible for digitally signing target access control lists (ACCLs) used to manage access rights to computing resources. The signature server creates a security sandbox within a trusted execution environment (TEE) and digitally signs the ACCLs within this sandbox. For example, the ELECTRIC CURVE DIGITAL SIGNATURE (ECDSA) algorithm is used to sign the ACCLs. Furthermore, the signature server is equipped with an EMRM (Electromagnetic Radiation Monitoring Module) that monitors electromagnetic signals in the surrounding environment in real time. Upon detecting an abnormal EM signal, such as a specific frequency fluctuation that could indicate a side-channel attack, the monitoring module automatically terminates the signing process and triggers an alarm to notify the system administrator. This effectively protects the security of the digital signature process, ensuring that the ACCLs cannot be illegally obtained or tampered with during the signing process.

[0110] Of course, the execution environment of "digitally signing the target access control list" can also be other various environments, and the embodiment of the present invention does not limit this.

[0111] In addition, as an optional embodiment, determining whether the electrical parameters of each preset member of the target access list meet the hardware design requirements of the target component includes:

[0112] Federated learning parameter calibration: The federated learning framework aggregates historical operating data of multiple target components of the same type to train parameter compliance prediction models without leaking the original data.

[0113] Dynamic standard generation: Based on the parameter distribution characteristics output by the parameter compliance prediction model, the electrical parameter compliance range that matches the hardware design requirements is dynamically generated, replacing the static preset technical standards.

[0114] Specifically, considering that traditional statically preset electrical parameter technical standards may not adapt to the diversity and variability of different target components in actual operation, federated learning aggregates historical operating data of multiple target components of the same type and dynamically generates electrical parameter compliance intervals. This can more accurately match hardware design requirements and improve the accuracy and adaptability of backup power module electrical parameter judgments.

[0115] For example, in a large internet company's server room, there are multiple web servers of the same type. The target component is the motherboard storage module (MSM), which is responsible for data storage and processing. The signature server uses a federated learning framework to aggregate historical operational data from these web server MSMs, such as voltage fluctuations, capacity usage, and charge / discharge rate changes over different time periods. Without leaking the server's original data, a parameter compliance prediction model is trained. Based on the parameter distribution characteristics output by the model, an electrical parameter compliance range is dynamically generated to match the hardware design requirements of the MSM. For example, the statically preset supercapacitor voltage standard of 5V±0.5V can be changed to 4.8V-5.2V through the dynamically generated compliance range to better adapt to actual operating conditions. When the business server sends a target access control list containing a supercapacitor, the signature server uses the dynamically generated compliance range to determine whether the supercapacitor's electrical parameters meet the hardware design requirements of the MSM, thereby more accurately performing electrical parameter compliance checks.

[0116] Please refer to Figure 4 , Figure 4 A flowchart of a third access control list management method provided by the present invention is provided. The access control list management method is applied to a service server and includes:

[0117] S201: Sending a target access control list to a signature server, so that the signature server digitally signs the target access control list if the preset members in the target access control list pass the validity check, wherein the target access control list includes member information of the preset members of the target object;

[0118] S202: Perform access control on the target object according to the digitally signed target access control list sent by the signature server.

[0119] As an optional embodiment, performing access control on a target object according to a digitally signed target access control list sent by a signature server includes:

[0120] Receive the encapsulated target access control list and its data signature sent by the signature server;

[0121] Perform hash operation on the target access control list in the encapsulation to obtain the hash value to be verified;

[0122] The digital signature in the package is decrypted using the pre-stored public key to obtain the original hash value of the target access control list, where the digital signature is: the signature server performs a hash operation on the target access control list to obtain the original hash value, and encrypts the original hash value using the issuer's private key to obtain the digital signature. The pre-stored public key and the issuer's private key together form an asymmetric key;

[0123] When the hash value to be verified is consistent with the original hash value, the target access control list in the encapsulation is stored;

[0124] Access control is performed on the target object according to the stored target access control list.

[0125] For an introduction to the access control list management method provided by an embodiment of the present invention, please refer to the aforementioned embodiment of the access control list management method, and the embodiment of the present invention will not be described in detail here.

[0126] Please refer to Figure 5 , Figure 5 A schematic diagram of the structure of another access control list management system provided by the present invention, wherein the access control list management system includes:

[0127] The signature server 51 is used to implement the above access control list management method when executing a computer program;

[0128] The business server 52 is used to implement the above-mentioned access control list management method when executing a computer program.

[0129] For an introduction to the access control list management system provided by the embodiment of the present invention, please refer to the aforementioned embodiment of the access control list management method, and the embodiment of the present invention will not be described in detail here.

[0130] Please refer to Figure 6 , Figure 6 This is a structural diagram of a computer-readable storage medium provided by the present invention. A computer program 62 is stored on the computer-readable storage medium 61. When the computer program 62 is executed by a processor, the steps of the access control list management method are implemented.

[0131] For an introduction to the computer-readable storage medium provided in an embodiment of the present invention, please refer to the aforementioned embodiment of the access control list management method, and the embodiment of the present invention will not be described in detail here.

[0132] The present invention also provides a computer program product, comprising a computer program / instruction, which implements the steps of the access control list management method in the aforementioned embodiment when executed by a processor.

[0133] For an introduction to the computer program product provided by the embodiment of the present invention, please refer to the aforementioned embodiment of the access control list management method, and the embodiment of the present invention will not be described in detail here.

[0134] In this specification, the various embodiments are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same and similar parts between the various embodiments can be referred to each other. It should also be noted that in this specification, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device that includes a series of elements includes not only those elements, but also includes other elements that are not explicitly listed, or also includes elements that are inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a..." does not exclude the presence of other identical elements in the process, method, article or device that includes the element.

[0135] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for managing an access control list, characterized in that: Applicable to the signature server, including: Determine whether the preset members in the target access control list sent by the business server can pass the validity check, wherein the target access control list includes member information of the preset members of the target object; If it passes, digitally sign the target access control list; The digitally signed target access control list is sent to the business server so that the business server can perform access control on the target object according to the digitally signed target access control list.

2. The method for managing an access control list according to claim 1, wherein: The target control list is a whitelist of backup power modules of target components of the server, the target object is the backup power module, and the preset members include backup power modules of specified models; Determining whether the preset members in the target access control list sent by the business server can pass the legitimacy check includes: Determine whether the preset members in the target access control list sent by the business server can pass the model legitimacy verification; Determine whether the preset members in the target access control list sent by the business server can pass the electrical parameter compliance check; If both the model legality verification and the electrical parameter compliance check can be passed, it is determined that the legality check has been passed; If the model legality verification and electrical parameter compliance check cannot be passed at the same time, it is determined that the legality check has failed.

3. The method for managing an access control list according to claim 2, wherein: Determining whether the preset members in the target access control list sent by the business server can pass the model legitimacy verification includes: Determine whether each preset member of the target access list contains a preset member whose model is the same as the model in the existing whitelist, wherein the model in the existing whitelist is the model of each backup power module in the current backup power module whitelist of the target component; If the model included is the same as the existing whitelist model, it is determined that the model legitimacy verification has failed; Determining whether each preset member of the target access list includes a preset member whose manufacturer is not a preset authorized manufacturer; If the manufacturer included is not a preset member of the preset authorized manufacturers, it is determined that the model legitimacy verification has not been passed; If the model is not the same as the existing whitelist model and the manufacturer is not a preset member of the preset authorized manufacturer, it is determined that the preset member in the target access control list has passed the model legitimacy verification.

4. The method for managing an access control list according to claim 3, wherein: Determining whether the preset members in the target access control list sent by the business server can pass the electrical parameter compliance check includes: Determining whether electrical parameters of each preset member of the target access list meet hardware design requirements of the target component, wherein the electrical parameters include voltage, capacity, and charge and discharge rate; If none of them meet the hardware design requirements of the target component, it is determined that the electrical parameter compliance check has failed; Determining whether the electrical parameters of each preset member of the target access list meet the technical standards of the data backup power scenario of the target component, wherein the technical standards of the data backup power scenario include the power supply duration after power failure and energy storage efficiency; If the technical standards of the data backup power scenario of the target component are not met, it is determined that the electrical parameter compliance check has failed; If both meet the hardware design requirements of the target component and the technical standards of the data backup power scenario of the target component, the electrical parameter compliance check is determined to have passed.

5. The method for managing an access control list according to claim 1, wherein: Digitally signing a target access control list involves: Perform hash operation on the target access control list to generate the corresponding original hash value; Encrypt the original hash value using the issuer's private key to obtain a digital signature; The target access control list and the digital signature are encapsulated so as to be returned together.

6. The method for managing an access control list according to any one of claims 1 to 5, characterized in that: The step of digitally signing the target access control list is performed in the hardware security module, including: Creating a security sandbox in the trusted execution environment, and digitally signing the target access control list in the security sandbox, so as to isolate the operation of digitally signing the target access control list from the operating system kernel of the signing server; Abnormal electromagnetic signals are detected in real time through the electromagnetic radiation monitoring module. When signs of side channel attacks are detected, the signing process is automatically terminated and an alarm is triggered. The signing process is: digitally signing the target access control list.

7. A method for managing an access control list, characterized in that: Applicable to business servers, including: Sending the target access control list to a signature server so that the signature server digitally signs the target access control list if the preset members in the target access control list pass the validity check, wherein the target access control list includes member information of the preset members of the target object; Access control is performed on the target object based on the digitally signed target access control list sent by the signature server.

8. The method for managing an access control list according to claim 7, wherein: Based on the digitally signed target access control list sent by the signature server, access control on the target object includes: Receive the encapsulated target access control list and its data signature sent by the signature server; Perform hash operation on the target access control list in the encapsulation to obtain the hash value to be verified; Decrypting the encapsulated digital signature using a pre-stored public key to obtain an original hash value of the target access control list, wherein the digital signature is a digital signature obtained by performing a hash operation on the target access control list by the signature server and encrypting the original hash value using the issuer's private key, where the pre-stored public key and the issuer's private key together form an asymmetric key; When the hash value to be verified is consistent with the original hash value, storing the target access control list in the encapsulation; Access control is performed on the target object according to the stored target access control list.

9. A management system for access control lists, characterized in that: include: A signature server, configured to implement the access control list management method according to any one of claims 1 to 6 when executing a computer program; A business server, configured to implement the access control list management method according to any one of claims 7 to 8 when executing a computer program.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the access control list management method according to any one of claims 1 to 8 are implemented.