Password service management method and device, equipment and storage medium
By registering routing information in the password service platform and adopting a scenario-based management method of exclusive or shared mode, the problem of waste of resources and low utilization in the traditional 1-to-1 mode is solved, and a 1-to-1 or 1-to-N service model is realized, which improves the utilization rate of password services.
Patent Information
- Application Number
- CN202510851025.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-24
- Publication Date
- 2025-09-02
AI Technical Summary
The traditional 1-to-1 password service model leads to low service utilization and waste of resources, and it is difficult to meet the diversified needs of business application systems for password services.
The scenario-based password service management method based on the exclusive or shared mode is adopted, and the routing information is registered in the password service platform through the gateway, and a 1-to-1 or 1-to-N service model is realized, providing exclusive or shared password service capabilities for the business application system.
It improves the utilization rate of password services, eliminates resource waste, and meets the diversified needs of business application systems for password services.
Smart Images

Figure CN120583145A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cryptographic service management, and in particular to a cryptographic service management method, a cryptographic service management device, an electronic device, and a computer-readable storage medium. Background Art
[0002] Traditional cryptographic service platforms typically use a one-to-one cryptographic service model to provide cryptographic service capabilities to tenants' business application systems, meaning one service corresponds to one business application system. Tenants have a wide variety of business application systems, with widely varying business processes and cryptographic service capability requirements. If a business application system has low access service capability requirements, or if the cryptographic service capabilities provided by the service far exceed the service capabilities required by the business application system, this can lead to low service utilization and resource waste. Summary of the Invention
[0003] The purpose of the present invention is to provide a cryptographic service management method, device, equipment and storage medium, which are applied to the field of cryptographic service management. The method proposes a scenario-based cryptographic service management method based on an exclusive or shared mode to realize a 1-to-1 or 1-to-N service mode between cryptographic services and business application systems, provide exclusive or shared cryptographic service capabilities for business application systems, improve the utilization rate of cryptographic services, and eliminate the waste of cryptographic service resources.
[0004] To solve the above technical problems, the present invention provides a cryptographic service management method, comprising:
[0005] Registering the business application system to the password service platform and subscribing to the password service of each business application system in the password service platform;
[0006] Register routing information in a cryptographic service routing table in a gateway based on a subscription relationship between the business application system and the cryptographic service;
[0007] When receiving a password service request from the business application system, forwarding the password service request to the password service subscribed by the business application system through the gateway according to the routing information;
[0008] When the processing result of the cryptographic service is received, the processing result is forwarded to the business application system subscribed to the cryptographic service through the gateway according to the routing information.
[0009] Optionally, registering routing information in a cryptographic service routing table in the gateway based on a subscription relationship between the business application system and the cryptographic service includes:
[0010] Determining a subscription model between the business application system and the cryptographic service;
[0011] When the subscription mode is an exclusive subscription mode, registering the routing information in the exclusive cryptographic service routing table of the gateway based on the subscription relationship between the business application system and the cryptographic service;
[0012] When the subscription mode is a shared subscription mode, the routing information is registered in a shared cryptographic service routing table of the gateway based on the subscription relationship between the business application system and the cryptographic service.
[0013] Optionally, forwarding the cryptographic service request to the cryptographic service subscribed by the business application system according to the routing information by the gateway includes:
[0014] Parsing the cryptographic service request based on the gateway to obtain a business application system identifier and a cryptographic service identifier;
[0015] Determining the routing information in the cryptographic service routing table based on the business application system identifier and the cryptographic service identifier;
[0016] The cryptographic service request is forwarded by the gateway to the cryptographic service subscribed by the business application system according to the routing information.
[0017] Optionally, determining the routing information in the cryptographic service routing table based on the business application system identifier and the cryptographic service identifier includes:
[0018] Parsing the cryptographic service request based on the gateway to obtain a subscription mode identifier;
[0019] When the subscription mode identifier is an exclusive subscription mode, determining the routing information in an exclusive cryptographic service routing table based on the business application system identifier and the cryptographic service identifier;
[0020] When the subscription mode identifier is a shared subscription mode, the routing information is determined in a shared cryptographic service routing table based on the business application system identifier.
[0021] Optionally, when receiving the cryptographic service request from the business application system, forwarding the cryptographic service request to the cryptographic service subscribed by the business application system according to the routing information by the gateway includes:
[0022] When receiving a password service request from the business application system, parsing the password service request based on the gateway to obtain a business application system identifier and a password service identifier;
[0023] Determining the routing information in the cryptographic service routing table based on the business application system identifier and the cryptographic service identifier;
[0024] Determining a current load of the cryptographic service subscribed to by the business application system based on the routing information;
[0025] If the current load is lower than the load threshold of the cryptographic service, the cryptographic service request is forwarded to the cryptographic service through the gateway according to the routing information.
[0026] Optionally, when receiving the cryptographic service request from the business application system, forwarding the cryptographic service request to the cryptographic service subscribed by the business application system according to the routing information by the gateway includes:
[0027] When receiving cryptographic service requests from multiple business application systems that call the same cryptographic service, ranking the cryptographic service requests by importance based on the priority sequence of the business application systems;
[0028] The gateway forwards the sorted cryptographic service requests in sequence according to the routing information to the cryptographic service subscribed by the business application system.
[0029] Optionally, when receiving the cryptographic service request from the business application system, forwarding the cryptographic service request to the cryptographic service subscribed by the business application system according to the routing information by the gateway includes:
[0030] When receiving a password service request from the business application system, performing authentication processing on the password service request;
[0031] When it is determined based on the authentication process that the password service request is an authorization request, the password service request is forwarded to the password service subscribed by the business application system through the gateway according to the routing information.
[0032] To solve the above technical problems, the present invention provides a cryptographic service management device, comprising:
[0033] The first module is used to register the business application system to the password service platform and subscribe to the password service of each business application system in the password service platform;
[0034] The second module is used to register routing information in the cryptographic service routing table in the gateway based on the subscription relationship between the business application system and the cryptographic service;
[0035] A third module is configured to, upon receiving a password service request from the business application system, forward the password service request to the password service subscribed by the business application system through the gateway according to the routing information;
[0036] The fourth module is configured to forward the processing result of the cryptographic service to the business application system subscribed to the cryptographic service through the gateway according to the routing information when the processing result of the cryptographic service is received.
[0037] To solve the above technical problems, the present invention provides an electronic device, comprising:
[0038] Memory for storing computer programs;
[0039] A processor is used to implement the above-mentioned cryptographic service management method when executing the computer program.
[0040] In order to solve the above technical problems, the present invention provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, the above-mentioned cryptographic service management method is implemented.
[0041] It can be seen that the present invention registers the business application system with the cryptographic service platform, subscribes to the cryptographic services of each business application system in the cryptographic service platform; registers routing information in the cryptographic service routing table in the gateway based on the subscription relationship between the business application system and the cryptographic service; when receiving a cryptographic service request from the business application system, the gateway forwards the cryptographic service request to the cryptographic service subscribed by the business application system according to the routing information; when receiving the processing result of the cryptographic service, the gateway forwards the processing result to the business application system subscribed to the cryptographic service according to the routing information. The present invention proposes a scenario-based cryptographic service management method based on an exclusive or shared mode, realizing a 1-to-1 or 1-to-N service mode between the cryptographic service and the business application system, providing the business application system with exclusive or shared cryptographic service capabilities, improving the utilization rate of the cryptographic service, and eliminating the waste of cryptographic service resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0043] Figure 1 A flowchart of a cryptographic service management method provided by an embodiment of the present invention;
[0044] Figure 2 This is a structural block diagram of a cryptographic service management device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0045] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0046] The traditional 1-to-1 cryptographic service model has the following shortcomings: the cryptographic service has a fixed relationship with the business application system, and cannot meet the diversified application scenario requirements of the upper-level business application system for exclusive or shared use; when a business application system has low access service capability requirements, or the cryptographic service capabilities provided by the service to the outside world are far greater than the service capability range required by the business application system, there will be problems of low service utilization and resource waste; because the cryptographic service has a fixed 1-to-1 relationship with the business application system, it is not easy to expand and cannot provide a scenario-based management method for the cryptographic service.
[0047] How to transform the traditional one-to-one cryptographic service model and provide exclusive or shared scenario-based cryptographic service capabilities for business application systems through cryptographic service management methods to meet the urgent requirements of business application systems for diversified cryptographic services will become the focus of cryptographic service platform construction.
[0048] In order to solve the various drawbacks and defects in the use of the above-mentioned traditional 1-to-1 cryptographic service mode, improve the cryptographic service management capabilities, and meet the business application system's requirements for diversified cryptographic service scenarios, the present invention proposes a scenario-based cryptographic service management method based on exclusive or shared mode.
[0049] The following combination Figure 1 , Figure 1 A flowchart of a cryptographic service management method provided by an embodiment of the present invention may include:
[0050] S101: Register the business application system to the password service platform, and subscribe to the password service of each business application system in the password service platform.
[0051] In this embodiment, the business application system can first be registered with the password service platform to enter the business application system information. The password service platform in this embodiment provides password services to the business application system. This embodiment does not limit the type of password services and can be set based on actual applications.
[0052] In this embodiment, the cryptographic service platform can include multiple cryptographic services to provide shared or exclusive cryptographic service resources to business application systems. In this embodiment, an administrator can log in to the cryptographic service platform and, through the cryptographic device and service management, complete information entry and registration for each business application system. Based on the type of cryptographic service (shared, exclusive) and specification required by the business application system, the administrator can also use the cryptographic device and service management to subscribe to and publish cryptographic services.
[0053] This embodiment allows for subscriptions to cryptographic services based on the cryptographic services required by the business application systems. For example, if business application systems 1 and 2 need to share cryptographic service 1, then cryptographic service 1 can be used as a subscription service for both business application systems 1 and 2 on the cryptographic service platform. If business application system 3 requires exclusive use of cryptographic service 2, and business application system N requires exclusive use of cryptographic service N, then cryptographic service 2 can be used as a subscription service for business application system 3, and cryptographic service N can be used as a subscription service for business application system N on the cryptographic service platform.
[0054] S102: Register routing information in the cryptographic service routing table in the gateway based on the subscription relationship between the business application system and the cryptographic service.
[0055] In this embodiment, after completing the subscription, routing information can be registered in the cryptographic service routing table in the gateway based on the subscription relationship between the business application system and the cryptographic service. The gateway can have a shared cryptographic service routing table and an exclusive cryptographic service routing table, each recording the association information between the business application system and the cryptographic service, providing a basis for the routing module to forward cryptographic service requests.
[0056] In this embodiment, since the cryptographic service can provide exclusive or shared cryptographic service capabilities for the business application system, that is, the subscription relationship between the cryptographic service and the business application system can be a shared subscription model and an exclusive subscription model, this application can construct a cryptographic service routing table based on the subscription model of the business application system and the cryptographic service.
[0057] Specifically, first, the subscription mode of the business application system and the cryptographic service can be determined; when the subscription mode is an exclusive subscription mode, the routing information is registered in the exclusive cryptographic service routing table of the gateway based on the subscription relationship between the business application system and the cryptographic service; when the subscription mode is a shared subscription mode, the routing information is registered in the shared cryptographic service routing table of the gateway based on the subscription relationship between the business application system and the cryptographic service.
[0058] For example, if the subscription mode between business application system 1 and business application system 2 and shared cryptographic service 1 is shared subscription mode, the routing information of business application system 1 and business application system 2 and shared cryptographic service 1 can be added to the shared cryptographic service routing table. If the subscription mode between business application system 3 and cryptographic service 2 is exclusive subscription mode, and the subscription mode between business application system N and cryptographic service N is exclusive subscription mode, the routing information of business application system 3 and cryptographic service 2 and the routing information of business application system N and cryptographic service N can be added to the exclusive cryptographic service routing table. This is shown in Tables 1 and 2.
[0059] Table 1: Shared password service routing table
[0060]
[0061] Table 2: Exclusive cryptographic service routing table
[0062]
[0063] S103: When receiving the cryptographic service request from the business application system, the gateway forwards the cryptographic service request to the cryptographic service subscribed by the business application system according to the routing information.
[0064] In this embodiment, when a cryptographic service request is received from a business application system, the gateway can forward the request to the cryptographic service subscribed by the business application system according to the routing information. Specifically, the cryptographic service request is first sent to the gateway, which forwards the request. The gateway parses the cryptographic service request to obtain the business application system identifier and the cryptographic service identifier. Routing information is then determined in the cryptographic service routing table based on the business application system identifier and the cryptographic service identifier. The gateway then forwards the request to the cryptographic service subscribed by the business application system according to the routing information.
[0065] This embodiment does not limit the specific method of reading routing information. Generally, the subscription mode identifier can be obtained based on the gateway parsing the cryptographic service request; when the subscription mode identifier is an exclusive subscription mode, the routing information is determined in the exclusive cryptographic service routing table based on the business application system identifier and the cryptographic service identifier; when the subscription mode identifier is a shared subscription mode, the routing information is determined in the shared cryptographic service routing table based on the business application system identifier.
[0066] S104: When the processing result of the cryptographic service is received, the processing result is forwarded to the business application system that subscribes to the cryptographic service through the gateway according to the routing information.
[0067] When the cryptographic service receives a cryptographic service request from a business application system, it can provide cryptographic services based on the cryptographic service request, generate a processing result, and forward the processing result to the business application system that subscribed to the cryptographic service through the gateway according to the routing information. This embodiment does not limit the gateway access method; business application systems generally access the gateway through an SDK (Software Development Kit).
[0068] The example of the calling process of the shared password service in this embodiment can be as follows:
[0069] Business application system 1 accesses the gateway of the cryptographic service platform through the SDK. The gateway receives the cryptographic service request and completes the authentication process of the cryptographic service request.
[0070] Determine that the subscription mode of the cryptographic service is a shared subscription mode, obtain routing information from the shared cryptographic service routing table, and the gateway forwards the cryptographic service request of business application system 1 to cryptographic service 1 based on the routing information;
[0071] The cryptographic service 1 completes the transaction business processing, generates a processing result, and returns the processing result to the gateway, which returns the processing result to the business application system 1.
[0072] Business application system 2 accesses the gateway of the password service platform through the SDK. The gateway receives the password service request and completes the authentication process of the password service request.
[0073] Determine that the subscription mode of the cryptographic service is the shared subscription mode, obtain routing information from the shared cryptographic service routing table, and the gateway forwards the cryptographic service request of business application system 2 to cryptographic service 1 based on the routing information;
[0074] The cryptographic service 1 completes the transaction business processing, generates a processing result, and returns the processing result to the gateway, which returns the processing result to the business application system 2.
[0075] At this point, the business application systems 1 and 2 complete the business processing of the shared cryptographic service with the cryptographic service 1.
[0076] An example of the calling process of the exclusive password service in this embodiment can be as follows:
[0077] Business application system 3 accesses the gateway of the password service platform through the SDK. The gateway receives the password service request and completes the authentication process of the password service request.
[0078] Determine that the subscription mode of the cryptographic service is the shared subscription mode, obtain routing information from the exclusive cryptographic service routing table, and the gateway forwards the cryptographic service request of the business application system 3 to the cryptographic service 2 based on the routing information;
[0079] The cryptographic service 2 completes the transaction business processing, generates a processing result, and returns the processing result to the gateway, which returns the processing result to the business application system 3.
[0080] Business application system N accesses the gateway of the cryptographic service platform through the SDK. The gateway receives the cryptographic service request and completes the authentication process of the cryptographic service request.
[0081] Determine that the subscription mode of the cryptographic service is a shared subscription mode, obtain routing information from the exclusive cryptographic service routing table, and the gateway forwards the cryptographic service request of the business application system 2 to the cryptographic service N based on the routing information;
[0082] The cryptographic service N completes the transaction business processing, generates a processing result, and returns the processing result to the gateway, which returns the processing result to the business application system N.
[0083] At this point, the business application system 3 completes the business processing of the exclusive cryptographic service with the cryptographic service N, and the business application system N completes the business processing of the exclusive cryptographic service with the cryptographic service N.
[0084] In this embodiment, if multiple business application systems concurrently call the same shared cryptographic service, the cryptographic service requests may be forwarded sequentially based on the importance ranking of the business application systems.
[0085] Specifically, when cryptographic service requests calling the same cryptographic service are received from multiple business application systems, the cryptographic service requests are sorted in importance based on the priority sequence of the business application systems; the sorted cryptographic service requests are forwarded to the cryptographic services subscribed to by the business application systems in sequence through the gateway according to the routing information.
[0086] In this embodiment, the load of each cryptographic service is generally limited, and the same cryptographic service can process multiple cryptographic service requests at the same time. However, when the load in the cryptographic service exceeds the load threshold, new cryptographic service requests cannot be processed at this time. Therefore, this application can perform forwarding control of cryptographic service requests based on the load of the cryptographic service.
[0087] Specifically, when a cryptographic service request from a business application system is received, the gateway parses the cryptographic service request to obtain the business application system identifier and the cryptographic service identifier; based on the business application system identifier and the cryptographic service identifier, routing information is determined in the cryptographic service routing table; based on the routing information, the current load of the cryptographic service subscribed to by the business application system is determined; if the current load is lower than the load threshold of the cryptographic service, the cryptographic service request is forwarded to the cryptographic service through the gateway according to the routing information.
[0088] In this embodiment, the gateway may also include an authentication function to prevent cryptographic service requests from non-business application systems from being forwarded to the cryptographic service. Specifically, when receiving cryptographic service requests from multiple business application systems invoking the same cryptographic service, the cryptographic service requests are ranked by importance based on the business application system's priority sequence. The gateway then forwards these ranked cryptographic service requests to the cryptographic service subscribed by the business application system in accordance with routing information. This embodiment does not limit the specific authentication method; it can generally be configured based on the actual application.
[0089] Furthermore, in this embodiment, a firewall may be configured in the gateway to ensure that the cryptographic service is used safely. Firewall rules may be configured to restrict access to the cryptographic service to a specific network address range to prevent external malicious attacks.
[0090] Additionally, the gateway can rate-limit password service requests. For example, it can limit the number of password service requests that each business application system can send per unit time to prevent brute force attacks. If the request frequency of a business application system exceeds a set threshold, the gateway can temporarily block access from that client.
[0091] Based on the above embodiments, the present invention proposes a scenario-based cryptographic service management method based on an exclusive or shared mode, which realizes a 1-to-1 or 1-to-N service mode between cryptographic services and business application systems, provides exclusive or shared cryptographic service capabilities for business application systems, improves the utilization rate of cryptographic services, and eliminates the waste of cryptographic service resources.
[0092] The following combination Figure 2 , Figure 2 This is a structural block diagram of a cryptographic service management device provided by an embodiment of the present invention, which may include:
[0093] The first module 100 is used to register the business application system with the password service platform and subscribe to the password service of each business application system in the password service platform;
[0094] The second module 200 is used to register routing information in the cryptographic service routing table in the gateway based on the subscription relationship between the business application system and the cryptographic service;
[0095] The third module 300 is configured to, upon receiving a cryptographic service request from the business application system, forward the cryptographic service request to the cryptographic service subscribed by the business application system through the gateway according to the routing information;
[0096] The fourth module 400 is configured to forward the processing result of the cryptographic service to the business application system subscribed to the cryptographic service through the gateway according to the routing information when the processing result of the cryptographic service is received.
[0097] Based on the above embodiments, the present invention proposes a scenario-based cryptographic service management method based on an exclusive or shared mode, which realizes a 1-to-1 or 1-to-N service mode between cryptographic services and business application systems, provides exclusive or shared cryptographic service capabilities for business application systems, improves the utilization rate of cryptographic services, and eliminates the waste of cryptographic service resources.
[0098] Based on the above embodiment, the second module 200 may include:
[0099] The first unit is used to determine a subscription mode between the business application system and the cryptographic service;
[0100] A second unit is configured to, when the subscription mode is an exclusive subscription mode, register the routing information in an exclusive cryptographic service routing table of the gateway based on the subscription relationship between the business application system and the cryptographic service;
[0101] The third unit is configured to register the routing information in a shared cryptographic service routing table of the gateway based on the subscription relationship between the business application system and the cryptographic service when the subscription mode is a shared subscription mode.
[0102] Based on the above embodiments, the third module 300 may include:
[0103] A fourth unit is configured to parse the cryptographic service request based on the gateway to obtain a business application system identifier and a cryptographic service identifier;
[0104] A fifth unit is configured to determine the routing information in the cryptographic service routing table based on the business application system identifier and the cryptographic service identifier;
[0105] The sixth unit is configured to forward the cryptographic service request to the cryptographic service subscribed by the business application system through the gateway according to the routing information.
[0106] Based on the above embodiments, the fifth unit may include:
[0107] A first subunit is configured to parse the cryptographic service request based on the gateway to obtain a subscription mode identifier;
[0108] A second subunit is configured to determine the routing information in an exclusive cryptographic service routing table based on the business application system identifier and the cryptographic service identifier when the subscription mode identifier is an exclusive subscription mode;
[0109] The third subunit is configured to determine the routing information in a shared cryptographic service routing table based on the business application system identifier when the subscription mode identifier is a shared subscription mode.
[0110] Based on the above embodiments, the third module 300 may include:
[0111] A seventh unit is configured to, upon receiving a cryptographic service request from the business application system, parse the cryptographic service request based on the gateway to obtain a business application system identifier and a cryptographic service identifier;
[0112] An eighth unit is configured to determine the routing information in the cryptographic service routing table based on the business application system identifier and the cryptographic service identifier;
[0113] A ninth unit, configured to determine a current load of the cryptographic service subscribed to by the business application system based on the routing information;
[0114] A tenth unit is configured to forward the cryptographic service request to the cryptographic service through the gateway according to the routing information if the current load is lower than the load threshold of the cryptographic service.
[0115] Based on the above embodiments, the third module 300 may include:
[0116] The eleventh unit is configured to, when receiving cryptographic service requests from multiple business application systems that call the same cryptographic service, sort the cryptographic service requests by importance based on the priority sequence of the business application systems;
[0117] The twelfth unit is configured to forward the sorted cryptographic service requests in sequence to the cryptographic service subscribed by the business application system through the gateway according to the routing information.
[0118] Based on the above embodiments, the third module 300 may include:
[0119] The thirteenth unit is configured to perform authentication processing on the password service request when receiving the password service request from the business application system;
[0120] A fourteenth unit is configured to forward the cryptographic service request to the cryptographic service subscribed by the business application system according to the routing information through the gateway when it is determined that the cryptographic service request is an authorization request based on the authentication process.
[0121] Based on the above embodiments, the present invention further provides an electronic device, which may include a memory and a processor. The memory stores a computer program, and the processor, when invoking the computer program in the memory, can implement the steps provided in the above embodiments. Of course, the device may also include various necessary network interfaces, a power supply, and other components.
[0122] The present invention also provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by an execution terminal or a processor, the method provided in the embodiment of the present invention can be implemented. The storage medium may include: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk, etc., various media that can store program codes.
[0123] In this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.
Claims
1. A cryptographic service management method, characterized in that: include: Registering the business application system to the password service platform and subscribing to the password service of each business application system in the password service platform; Register routing information in a cryptographic service routing table in a gateway based on a subscription relationship between the business application system and the cryptographic service; When receiving a password service request from the business application system, forwarding the password service request to the password service subscribed by the business application system through the gateway according to the routing information; When the processing result of the cryptographic service is received, the processing result is forwarded to the business application system subscribed to the cryptographic service through the gateway according to the routing information.
2. The cryptographic service management method according to claim 1, characterized in that: Registering routing information in a cryptographic service routing table in a gateway based on a subscription relationship between the business application system and the cryptographic service includes: Determining a subscription model between the business application system and the cryptographic service; When the subscription mode is an exclusive subscription mode, registering the routing information in the exclusive cryptographic service routing table of the gateway based on the subscription relationship between the business application system and the cryptographic service; When the subscription mode is a shared subscription mode, the routing information is registered in a shared cryptographic service routing table of the gateway based on the subscription relationship between the business application system and the cryptographic service.
3. The cryptographic service management method according to claim 1, wherein: Forwarding the cryptographic service request to the cryptographic service subscribed by the business application system according to the routing information through the gateway includes: Parsing the cryptographic service request based on the gateway to obtain a business application system identifier and a cryptographic service identifier; Determining the routing information in the cryptographic service routing table based on the business application system identifier and the cryptographic service identifier; The cryptographic service request is forwarded by the gateway to the cryptographic service subscribed by the business application system according to the routing information.
4. The cryptographic service management method according to claim 3, wherein: Determining the routing information in the cryptographic service routing table based on the business application system identifier and the cryptographic service identifier includes: Parsing the cryptographic service request based on the gateway to obtain a subscription mode identifier; When the subscription mode identifier is an exclusive subscription mode, determining the routing information in an exclusive cryptographic service routing table based on the business application system identifier and the cryptographic service identifier; When the subscription mode identifier is a shared subscription mode, the routing information is determined in a shared cryptographic service routing table based on the business application system identifier.
5. The cryptographic service management method according to claim 1, wherein: When receiving the cryptographic service request from the business application system, forwarding the cryptographic service request to the cryptographic service subscribed by the business application system according to the routing information through the gateway includes: When receiving a password service request from the business application system, parsing the password service request based on the gateway to obtain a business application system identifier and a password service identifier; Determining the routing information in the cryptographic service routing table based on the business application system identifier and the cryptographic service identifier; Determining a current load of the cryptographic service subscribed to by the business application system based on the routing information; If the current load is lower than the load threshold of the cryptographic service, the cryptographic service request is forwarded to the cryptographic service through the gateway according to the routing information.
6. The cryptographic service management method according to claim 1, characterized in that: When receiving the cryptographic service request from the business application system, forwarding the cryptographic service request to the cryptographic service subscribed by the business application system according to the routing information through the gateway includes: When receiving cryptographic service requests from multiple business application systems that call the same cryptographic service, ranking the cryptographic service requests by importance based on the priority sequence of the business application systems; The gateway forwards the sorted cryptographic service requests in sequence according to the routing information to the cryptographic service subscribed by the business application system.
7. The cryptographic service management method according to claim 1, characterized in that: When receiving the cryptographic service request from the business application system, forwarding the cryptographic service request to the cryptographic service subscribed by the business application system according to the routing information through the gateway includes: When receiving a password service request from the business application system, performing authentication processing on the password service request; When it is determined based on the authentication process that the password service request is an authorization request, the password service request is forwarded to the password service subscribed by the business application system through the gateway according to the routing information.
8. A cryptographic service management device, characterized in that: include: The first module is used to register the business application system to the password service platform and subscribe to the password service of each business application system in the password service platform; The second module is used to register routing information in the cryptographic service routing table in the gateway based on the subscription relationship between the business application system and the cryptographic service; A third module is configured to, upon receiving a password service request from the business application system, forward the password service request to the password service subscribed by the business application system through the gateway according to the routing information; The fourth module is configured to forward the processing result of the cryptographic service to the business application system subscribed to the cryptographic service through the gateway according to the routing information when the processing result of the cryptographic service is received.
9. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the cryptographic service management method according to any one of claims 1 to 7 when executing the computer program.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, and when the computer-executable instructions are executed by a processor, the cryptographic service management method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Cloud password service platform based on OAuth authentication and password resource allocation method
CN115086015A