Service requesting method, device and system and storage medium

By using a trusted root private key and environment attribute information authentication mechanism between the host and the server, the problem of identity fraud caused by the leakage of private authentication credentials is solved, achieving higher cloud service security and identity authentication accuracy.

CN120729952APending Publication Date: 2025-09-30HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410389121.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-29
Publication Date
2025-09-30

AI Technical Summary

Technical Problem

In the prior art, private authentication credentials and private authentication credential identifiers may be leaked, causing virtual instances to impersonate identities and reducing the security of cloud services.

Method used

By using the trusted root private key and environment attribute information on the host side to generate authentication and authorization information, and authenticating with the trusted root public key associated with the private access credentials and credential identifier, the server verifies the legitimacy of the identity to ensure that only legitimate virtual instances obtain services.

Benefits of technology

It improves the security of cloud services, prevents illegal virtual instances from obtaining services, and enhances the accuracy and security of identity authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120729952A_ABST
    Figure CN120729952A_ABST
Patent Text Reader

Abstract

The invention discloses a service requesting method, device and system and a storage medium, and belongs to the field of communication. The method comprises the steps that an access request is sent to a server side, the access request is used for requesting a first service, and the first service is a service needed by the virtual instance; based on a private access credential, the access request, the first environment attribute information of the virtual instance and the trusted root private key, obtaining authentication authorization information, a private access credential identifier corresponding to the private access credential and association with second environment attribute information, and the private access credential identifier also being associated with a trusted root public key; an authentication and authorization request is sent to the server side, the authentication and authorization request comprises the authentication and authorization information, and the authentication and authorization request is used for requesting the server side to determine whether the first service is provided for the virtual instance or not based on the authentication and authorization information. According to the invention, the service security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communications, and in particular to a method, device, system, and storage medium for requesting a service. Background Art

[0002] In order to improve the security of cloud services, the authentication gateway generally authenticates the identity of the virtual instance requesting cloud services or authorizes the virtual instance based on private authentication credentials and private authentication credential identifiers, and provides cloud services to the virtual instance when the identity of the virtual instance is authenticated or when the virtual instance is authorized.

[0003] In related technologies, the private authentication credential identifier can be an access key identifier (AK), and the private authentication credential can be a secret access key (SK). The virtual instance stores the correspondence between the AK and the SK, and the authentication gateway also stores the correspondence between the AK and the SK. The virtual instance signs the access request based on the SK to obtain first signature information. The access request is used to request the cloud service, and the virtual instance sends the access request, the AK, and the signature information to the authentication gateway. The authentication gateway obtains the SK based on the AK, and signs the access request based on the SK to obtain second signature information. When the first signature information and the second signature information are identical, the virtual instance's identity is authenticated as legitimate, and cloud services are provided to the virtual instance.

[0004] The private authentication credentials and the private authentication credential identifier (such as the AK and the SK) may be leaked. In this way, when other virtual instances use the private authentication credentials and the private authentication credential identifier to perform identity authentication or authorization, the authentication gateway also authenticates the identity of the other virtual instances as legitimate or authorizes the other virtual instances, and provides cloud services to the other virtual instances, thereby reducing the security of the service. Summary of the Invention

[0005] This application provides a method, device, system, and storage medium for requesting a service, for improving the security of the service. The technical solution is as follows:

[0006] In a first aspect, an embodiment of the present application provides a method for requesting a service, which can be applied to a host side, such as a host or a communication module in a host, or a circuit or chip in a host responsible for a communication function (such as a modem chip, also known as a baseband chip, or a system on chip (SoC) chip or a system in package (SIP) chip containing a modem core). Taking the method applied to a host as an example, in the method, the host includes a virtual instance and a trusted root private key, and the host sends an access request to a server, the access request being used to request a first service, which is a service required by the virtual instance. Based on a private access credential, the access request, first environmental attribute information of the virtual instance, and the trusted root private key, authentication and authorization information is obtained, a private access credential identifier corresponding to the private access credential is associated with the second environmental attribute information, and the private access credential identifier is also associated with the trusted root public key; and an authentication and authorization request is sent to the server, the authentication and authorization request including the authentication and authorization information, and the authentication and authorization request is used to request the server to determine whether to provide the first service to the virtual instance based on the authentication and authorization information.

[0007] Since the private access credential and the private access credential identifier correspond to each other, the private access credential identifier is associated with the second environment attribute information, and the private access credential identifier is associated with the trusted root public key, if the private access credential and the private access credential identifier are not leaked and belong to the virtual instance on the host, the host obtains authentication and authorization information based on the private access credential, the access request, the first environment attribute information of the virtual instance and the trusted root private key, and the server can determine to provide the first service to the virtual instance based on the authentication and authorization information. If the private access credential and the private access credential identifier are leaked and do not belong to the virtual instance on the host, the host obtains authentication and authorization information based on the private access credential, the access request, the first environment attribute information of the virtual instance and the trusted root private key, and the server can determine not to provide the first service to the virtual instance based on the authentication and authorization information. In this way, the security of the first service is improved.

[0008] In one possible design, the private access credential is a secret access key SK, and the private access credential identifier is an access key identifier AK. AK is sent to the server, and the authentication and authorization request is used to request the server to determine whether to provide the first service to the virtual instance based on the authentication and authorization information and AK.

[0009] In another possible design, the authentication authorization information includes a first ciphertext, a second ciphertext and a first signature confirmation information. The first authentication challenge information sent by the server is received, and the first authentication challenge information is obtained by the server obtaining the SK corresponding to the AK and based on the SK and the access request. The second authentication challenge information is obtained based on the first authentication challenge information and the first environmental attribute information. A one-time key is generated, and the one-time key is encrypted based on the public key of the server to obtain the first ciphertext. The second authentication challenge information is encrypted based on the one-time key to obtain the second ciphertext. The first ciphertext and the second ciphertext are signed and confirmed based on the trusted root private key to obtain the first signature confirmation information. Since the first signature confirmation information is obtained based on the trusted root private key of the host and the first environmental attribute information of the virtual instance of the host, the server can accurately verify whether the identity of the virtual instance using the AK and SK is legal based on the trusted root public key and the second environmental attribute information associated with the AK, as well as the first signature confirmation information.

[0010] In another possible design, the authentication authorization information includes first signature information, first environment attribute information, and second signature confirmation information. The access request is signed based on the SK to obtain the first signature information; the first signature information is signed and confirmed based on the trusted root private key to obtain the second signature confirmation information. Because the second signature confirmation information is obtained based on the host's trusted root private key and the first environment attribute information of the host's virtual instance, the server can determine whether to provide the first service to the virtual instance based on the trusted root public key associated with the AK, the second environment attribute information, and the second signature confirmation information, thereby improving the security of the first service.

[0011] In another possible design, the private access credential is the access credential access token, the private access credential identifier is the user identifier corresponding to the access token, the access token includes the user identifier, and the authentication authorization information includes a third ciphertext. The first environment attribute information is signed and verified based on the trusted root private key to obtain third signature verification information. The access token and the third signature verification information are encrypted based on the public key of the server to obtain a third ciphertext. Since the third ciphertext is obtained based on the trusted root private key of the host and the first environment attribute information of the virtual instance of the host, the server can determine whether to provide the first service to the virtual instance based on the trusted root public key associated with the user identifier and the second environment attribute information, as well as the third ciphertext, thereby improving the security of the first service.

[0012] In another possible design, the first environment attribute information includes one or more of the following: the service account of the virtual instance, the architecture information of the host, the size of the memory space of the virtual instance, the identification information of the virtual instance, the kernel identification information associated with the virtual instance, the time information of starting the virtual instance, the dedicated address of the virtual instance, the identification information of the disk associated with the virtual instance, or the partition where the virtual instance is running.

[0013] On the second aspect, the method can be applied to the network side, such as the server side of the network or a component in the server side (such as a circuit, a chip or a chip system, etc.). Taking the application of the method to the server side as an example, in the method, an access request sent by a host is received, and the host includes a virtual instance and a trusted root private key. The access request is used to request a first service, and the first service is a service required by the virtual instance. Authentication and authorization information sent by the host is received, and the authentication and authorization information is obtained by the host based on the private access credential, the access request, the first environment attribute information of the virtual instance and the trusted root private key. The private access credential identifier corresponding to the private access credential is associated with the second environment attribute information, and the private access credential identifier is also associated with the trusted root public key. Based on the authentication and authorization information, it is determined whether to provide the first service to the virtual instance.

[0014] Since the private access credential corresponds to the private access credential identifier, the private access credential identifier is associated with the second environment attribute information, and the private access credential identifier is associated with the trusted root public key, the received authentication and authorization information is obtained by the host based on the private access credential, the access request, the first environment attribute information of the virtual instance, and the trusted root private key. If the private access credential and the private access credential identifier are not leaked and belong to the virtual instance on the host, the server can determine to provide the first service to the virtual instance based on the authentication and authorization information. If the private access credential and the private access credential identifier are leaked and do not belong to the virtual instance on the host, the server can determine not to provide the first service to the virtual instance based on the authentication and authorization information. In this way, the security of the first service is improved.

[0015] In one possible design, the private access credential is a secret access key SK, and the private access credential identifier is an access key identifier AK. The AK sent by the receiving host is received. Based on the authentication authorization information and the AK, it is determined whether to provide the first service to the virtual instance.

[0016] In another possible design, the authentication authorization information includes a first ciphertext, a second ciphertext, and first signature verification information. The first ciphertext is the ciphertext of a one-time key generated by the host, the second ciphertext is the ciphertext of the second authentication challenge information, and the first signature verification information is obtained by the host based on the trusted root private key, the first ciphertext, and the second ciphertext. The SK corresponding to the AK is obtained; the first authentication challenge information is obtained based on the SK and the access request; and the first authentication challenge information is sent to the host, so that the host obtains the second authentication challenge information based on the first authentication challenge information and the first environment attribute information.

[0017] In another possible design, based on the AK, the trusted root public key and the second environmental attribute information associated with the AK are obtained. The first signature confirmation information is verified based on the trusted root public key, the first ciphertext and the second ciphertext. When the verification of the first signature confirmation information is passed, the first ciphertext is decrypted based on the public key of the server to obtain a one-time key. The second authentication challenge information is decrypted based on the one-time key. The identity of the virtual instance is authenticated based on the first authentication challenge information, the second environmental attribute information and the second authentication challenge information. When the identity is verified to be legitimate, it is determined to provide the first service to the virtual instance. Since the first signature confirmation information and the second authentication challenge information are obtained based on the trusted root private key of the host and the first environmental attribute information of the virtual instance of the host, the server can accurately verify whether the identity of the virtual instance using the AK and SK is legitimate based on the trusted root public key and the second environmental attribute information associated with the AK, as well as the first signature confirmation information.

[0018] In another possible design, the authentication authorization information includes first signature information, first environmental attribute information, and second signature confirmation information. The first signature information is information obtained by the host based on the access request and SK, and the second signature confirmation information is information obtained by the host based on the trusted root private key and the first signature information. Based on the AK, the SK corresponding to the AK is obtained; based on the AK, the trusted root public key and the second environmental attribute information associated with the AK are obtained; when the first environmental attribute information and the second environmental attribute information are the same, the second signature confirmation information is verified based on the SK, the trusted root public key, and the first signature information; when the verification of the second signature confirmation information passes, it is determined that the first service is provided to the virtual instance. Since the second signature confirmation information is obtained based on the trusted root private key of the host and the first environmental attribute information of the virtual instance of the host, the server can determine whether to provide the first service to the virtual instance based on the trusted root public key and the second environmental attribute information associated with the AK, as well as the second signature confirmation information, thereby improving the security of the first service.

[0019] In another possible design, the private access credential is an access token, the private access credential identifier is the user identifier corresponding to the access token, the access token includes the user identifier, and the authentication authorization information includes a third ciphertext. The third ciphertext is obtained by the host encrypting the access token and third signature verification information based on the server's public key. The third signature verification information is obtained by the host signing and verifying the first environment attribute information based on the trusted root private key. The third ciphertext is decrypted using the server's private key to obtain the access token and the third signature verification information. Based on the user identifier included in the access token, the trusted root public key and second environment attribute information associated with the user identifier are obtained. The third signature verification information is decrypted using the trusted root public key to obtain the first environment attribute information. If the first environment attribute information and the second environment attribute information are the same, it is determined that the first service is provided to the virtual instance. Because the third ciphertext is obtained based on the host's trusted root private key and the first environment attribute information of the host's virtual instance, the server can determine whether to provide the first service to the virtual instance based on the trusted root public key associated with the user identifier, the second environment attribute information, and the third ciphertext, thereby improving the security of the first service.

[0020] In another possible design, the first environment attribute information includes one or more of the following: the service account of the virtual instance, the architecture information of the host, the size of the memory space of the virtual instance, the identification information of the virtual instance, the kernel identification information associated with the virtual instance, the time information of starting the virtual instance, the dedicated address of the virtual instance, the identification information of the disk associated with the virtual instance, or the partition running the virtual instance.

[0021] In a third aspect, the present application provides a device for requesting a service, which has the function of implementing the above-mentioned first aspect. For example, the device includes a module or unit or means corresponding to performing the operations involved in the above-mentioned first aspect. The module or unit or means can be implemented through software, or through hardware, or through a combination of software and hardware.

[0022] In a fourth aspect, the present application provides a device for requesting a service, which has the function of implementing the above-mentioned second aspect. For example, the communication device includes a module or unit or means corresponding to the operation involved in the above-mentioned second aspect. The module or unit or means can be implemented by software, or by hardware, or by a combination of software and hardware.

[0023] In a fifth aspect, the present application provides a device for requesting a service, the device comprising a memory and one or more processors. The memory is used to store part or all of the necessary computer programs or instructions for implementing the functions described in the first aspect. The one or more processors can execute the computer programs or instructions. When the computer programs or instructions are executed, the device implements the method in any possible design or implementation of the first aspect.

[0024] In one possible design, the device may further include an interface circuit, wherein the processor is configured to communicate with other devices or components through the interface circuit.

[0025] In one possible design, the device may further include the memory.

[0026] The above-mentioned device can be a host, or a communication module in the host, or a chip in the host responsible for communication functions such as a modem chip (also called a baseband chip) or a SoC or SIP chip containing a modem module.

[0027] In a sixth aspect, the present application provides a device for requesting a service, the device comprising a memory and one or more processors. The memory is used to store part or all of the necessary computer programs or instructions for implementing the functions described in the second aspect. The one or more processors can execute the computer programs or instructions. When the computer programs or instructions are executed, the device implements the method in any possible design or implementation of the second aspect.

[0028] In a seventh aspect, the present application provides a system for requesting services, the system comprising the apparatus described in the third aspect and the apparatus described in the fourth aspect, or the system comprising the apparatus described in the fifth aspect and the apparatus described in the sixth aspect.

[0029] In an eighth aspect, the present application provides a computer-readable storage medium, in which computer-readable instructions are stored. When a computer reads and executes the computer-readable instructions, the computer executes the method in any possible design of the first to second aspects above.

[0030] In a ninth aspect, the present application provides a computer program product, which, when read and executed by a computer, enables the computer to execute the method in any possible design of the first to second aspects above. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] Figure 1 This is a schematic diagram of the structure of a communication system provided by an embodiment of the present application;

[0032] Figure 2is a structural diagram of another communication system provided in an embodiment of the present application;

[0033] Figure 3 is a structural diagram of another communication system provided in an embodiment of the present application;

[0034] Figure 4 is a structural diagram of another communication system provided in an embodiment of the present application;

[0035] Figure 5 This is a flow chart of a method for requesting a service provided by an embodiment of the present application;

[0036] Figure 6 This is a flow chart of another method for requesting a service provided by an embodiment of the present application;

[0037] Figure 7 This is a flow chart of another method for requesting a service provided by an embodiment of the present application;

[0038] Figure 8 This is a flow chart of another method for requesting a service provided by an embodiment of the present application;

[0039] Figure 9 This is a flow chart of another method for requesting a service provided by an embodiment of the present application;

[0040] Figure 10 This is a flow chart of another method for requesting a service provided by an embodiment of the present application;

[0041] Figure 11 This is a schematic diagram of the structure of a device for requesting a service provided in an embodiment of the present application;

[0042] Figure 12 This is a schematic diagram of a host structure provided by an embodiment of the present application;

[0043] Figure 13 This is a schematic diagram of a server structure provided in an embodiment of the present application. DETAILED DESCRIPTION

[0044] The technical solutions in the embodiments of the present application will be described below in conjunction with the accompanying drawings in the embodiments of the present application. The technical solutions in the embodiments of the present application can be applied to various communication systems, such as universal mobile telecommunications system (UMTS), wireless local area network (WLAN), wireless fidelity (Wi-Fi) system, 4th generation (4G) mobile communication system, such as long term evolution (LTE) system, fifth generation (5G) mobile communication system, such as new radio (NR) system, and future evolved communication systems, such as sixth generation (6G) mobile communication system.

[0045] This application will present various aspects, embodiments, or features in the context of systems that may include multiple devices, components, modules, etc. It should be understood and appreciated that each system may include additional devices, components, modules, etc., and / or may not include all of the devices, components, modules, etc. discussed in conjunction with the figures. Furthermore, combinations of these aspects may also be used.

[0046] In addition, in the embodiments of the present application, words such as "exemplarily" and "such as" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as an "example" in the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of the word "example" is intended to present concepts in a concrete way. In the embodiments of the present application, "of", "corresponding, relevant" and "corresponding" can sometimes be used interchangeably. It should be noted that when the distinction between them is not emphasized, the meanings to be expressed are consistent.

[0047] The communication system and business scenarios described in the embodiments of the present application are intended to more clearly illustrate the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided in the embodiments of the present application. A person skilled in the art will appreciate that, with the evolution of network architecture and the emergence of new business scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0048] To facilitate understanding of the embodiments of the present application, first Figure 1 The communication system shown in FIG is used as an example to describe in detail the communication system applicable to the embodiment of the present application. Figure 1 As shown, the communication system includes a host and a server.

[0049] The host can be connected to the server, that is, the host can communicate with the server, for example, the server receives information sent by the host, and the host can also receive information sent by the server.

[0050] The host and server are introduced below.

[0051] (1) Host

[0052] A host may be a device or module that accesses the above-mentioned communication system and has corresponding communication functions. The host may include a trusted root and a virtual instance. The host may also be referred to as a server, user equipment (UE), terminal, user device, access terminal, user unit, user station, mobile station, mobile station (MS), remote station, remote terminal, mobile device, user terminal, terminal unit, terminal station, terminal device, wireless communication device, user agent or user device, etc. The host is usually provided with a communication module, circuit or chip that performs the corresponding communication function. The host is also configured with program instructions for performing the corresponding communication function.

[0053] For example, the host in the embodiment of the present application can be a server, a mobile phone, a personal digital assistant (PDA), a laptop computer, a tablet computer, a drone, a computer with wireless transceiver function, a machine type communication (MTC) terminal, a virtual reality (VR) terminal, an augmented reality (AR) terminal, an Internet of Things (IoT) terminal, a wireless terminal in industrial control, a wireless terminal in self-driving, a wireless terminal in remote medical, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, a wireless terminal in a smart home (such as a game console, a smart TV, a smart speaker, a smart refrigerator, and fitness equipment, etc.), a transport vehicle with wireless communication function, a communication module, and a road side unit (RSU) with a terminal function.

[0054] (2) Server

[0055] The server is used to authenticate the identity of the virtual instance included in the host or to authorize the virtual instance included in the host. When the identity of the virtual instance included in the host is authenticated as legitimate or the virtual instance included in the host is authorized, the server determines to provide the first service to the virtual instance included in the host and performs the operation of providing the first service to the virtual instance included in the host. For example, the server in the embodiment of the present application can be a device or network element deployed on the network side, such as an authentication gateway, or a server that owns the first service, etc., which is not limited in the embodiment of the present application.

[0056] It is understandable that Figure 1 This is a simplified schematic diagram for ease of understanding. The communication system may also include other possible devices, such as wireless relay devices and wireless backhaul devices. Each device may also include different functional units. Figure 1 Not drawn in the figure. The communication between different devices involved in the embodiments of the present application may refer to direct communication between different devices (i.e., no other devices are required to transfer or forward), or may refer to communication between different devices through other devices (i.e., other devices are required to transfer or forward), or may refer to the functional unit inside the device communicating with other devices through another functional unit. That is to say, in this application, "sending information to... (host or server end)" can be understood as the destination end of the information being the host or server end. It can include sending information to the host or server end directly or indirectly. "Receiving information from... (host or server end)" can be understood as the source end of the information being the host or server end, and can include receiving information from the host or server end directly or indirectly. The information may be subjected to necessary processing between the source end and the destination end of the information transmission, such as format change, digital-to-analog conversion, amplification, filtering, etc., but the destination end can understand the valid information from the source end. Similar expressions in this application can be understood similarly and will not be repeated here.

[0057] See also Figure 1 An embodiment of the present application provides a communication system 100, including a host 101 and a server 102, where the host 101 communicates with the server 102.

[0058] In an example, the host 101 may establish a communication connection with the server 102 to enable communication between the host 101 and the server 102 .

[0059] See also Figure 1 The host 101 includes a virtual instance 1011 and a trusted root 1012. The virtual instance 1011 includes a private access credential, which corresponds to a private access credential identifier.

[0060] In one example, the virtual instance 1011 may be a virtual machine or a container, etc., and the trusted root 1012 may be a TEE, etc.

[0061] In one example, the virtual instance 1011 stores a correspondence between the private access credential and the private access credential identifier, or the virtual instance 1011 includes the private access credential, and the private access credential includes the private access credential identifier.

[0062] For example, the private access credential identifier is AK, the private access credential is SK, and the virtual instance 1011 stores the correspondence between the AK and the SK. Alternatively, the private access credential is an access token, the private access credential identifier is a user identifier, and the access token includes the user identifier.

[0063] In one example, the server 102 may store a correspondence between the private access credential and the private access credential identifier. For example, the server 102 may store a correspondence between the AK and the SK.

[0064] Host 101 includes environmental attribute information of virtual instance 1011, and trusted root 1012 of host 101 includes a trusted root private key and a public key of server 102. On server 102, the private access credential identifier is associated with the environmental attribute information of virtual instance 1011, and the private access credential identifier is also associated with the trusted root public key corresponding to the trusted root private key.

[0065] For ease of explanation, the environment attribute information of the virtual instance 1011 included in the host 101 is referred to as first environment attribute information, and the environment attribute information associated with the private access credential identifier on the server 102 is referred to as second environment attribute information.

[0066] In an example, the server 102 stores the corresponding relationship between the private access credential identifier and the second environment attribute information, and stores the corresponding relationship between the private access credential identifier and the trusted root public key.

[0067] For example, the private access credential is identified as the AK, and the server 102 stores the corresponding relationship between the AK and the second environment attribute information, and stores the corresponding relationship between the AK and the trusted root public key.

[0068] For another example, the private access credential identifier is the user identifier included in the access token, and the server 102 stores the corresponding relationship between the user identifier and the second environment attribute information, and stores the corresponding relationship between the user identifier and the trusted root public key.

[0069] In an example, the host 101 may register the private access credential identifier in association with the second environment attribute information with the server 102 , and register the private access credential identifier in association with the trusted root public key.

[0070] For example, the private access credential is identified as the AK, and the host 101 may request the server 102 to allocate the AK and the SK corresponding to the AK to the virtual instance 1011, and send the second environment attribute information and the trusted root public key to the server 102. The server 102 stores the correspondence between the AK and the second environment attribute information, and stores the correspondence between the AK and the trusted root public key.

[0071] In one example, see Figure 2 The network architecture 100 further includes an identity and access management (IAM) server 103 . The IAM server 103 communicates with the host 101 , and the IAM server 103 also communicates with the server 102 .

[0072] Host 101 can send a credential generation request to IAM server 103. The credential generation request includes a user identifier, first environment attribute information, and the trusted root public key. After receiving the credential generation request, IAM server 103 generates an access token including the user identifier and sends the user identifier, second environment attribute information, and the trusted root public key to server 102. Server 102 stores the corresponding relationship between the user identifier and the second environment attribute information to associate the user identifier with the second environment attribute information, and stores the corresponding relationship between the user identifier and the trusted root public key to associate the user identifier with the trusted root public key.

[0073] In one example, the server 102 includes a first service. For example, the server 102 is a server including the first service or an authentication gateway including the first service.

[0074] In one example, see Figure 3 or Figure 4 The server 102 may be an authentication gateway. The network architecture 100 also includes a cloud service platform 104 . The cloud service platform 104 includes a first service. The server 102 communicates with the cloud service platform 104 .

[0075] In an example, the first service may be a storage service, a data reading service, or an interface calling service.

[0076] In this application example, the service virtual machine 1011 in the host 101 may need a first service, and the host 101 may request the first service from the server 102. The host 101 may request the first service through any of the following embodiments.

[0077] See also Figure 5 , the embodiment of the present application provides a method 500 for requesting a service, the method 500 is applied to Figure 1 or Figure 3 In the communication system 100 shown, in the method 500, the private access credential is SK and the private access credential identifier is AK. The method 500 includes the following process.

[0078] Step 501: The host sends an access request and an AK to the server. The access request is used to request a first service, which is a service required by the virtual instance.

[0079] See also Figure 6 In step 501, the host includes a virtual instance. When the virtual instance needs a first service, the virtual instance in the host can generate an access request including identification information of the first service, and the virtual instance in the host sends the access request and AK to the server.

[0080] Step 502: The server receives the access request and the AK, and obtains first authentication challenge information based on the access request and the AK.

[0081] In step 502, the server receives the access request and the AK, obtains the SK corresponding to the AK from the correspondence between the AK and the SK, and obtains first authentication challenge information based on the SK and the access request.

[0082] In an example, the server obtains first authentication challenge information through an authentication challenge algorithm based on the SK and the access request.

[0083] Optionally, the authentication challenge algorithm can be a hash-based message authentication code (HMAC) algorithm, etc. The server can input the access request and the SK into the HMAC algorithm, and the HMAC algorithm calculates the first authentication challenge information based on the access request and the SK. The server obtains the first authentication challenge information output by the HMAC algorithm.

[0084] Step 503: The server sends a first authentication challenge message to the host.

[0085] See also Figure 6 In step 502, the server sends a first authentication challenge message (represented by MAC1) to the virtual instance in the host.

[0086] Step 504: The host receives the first authentication challenge information, and obtains the second authentication challenge information based on the first authentication challenge information and the first environment attribute information.

[0087] The first environment attribute information is environment attribute information of the virtual instance on the host. Optionally, the first environment attribute information includes one or more of the following: a service account of the virtual instance, host architecture information, memory size of the virtual instance, identification information of the virtual instance, kernel identification information associated with the virtual instance, time information of starting the virtual instance, a private address of the virtual instance, identification information of a disk associated with the virtual instance, or a partition where the virtual instance is running.

[0088] In step 504, the host obtains the second authentication challenge information through the following operations 5041-5042.

[0089] 5041: The host verifies the first authentication challenge information.

[0090] See also Figure 6 The virtual instance in the host verifies the first authentication challenge information. During implementation, the virtual instance in the host obtains the SK corresponding to the AK and calculates the authentication challenge information based on the SK and the access request. If the calculated authentication challenge information is the same as the first authentication challenge information, the first authentication challenge information is verified successfully. If the calculated authentication challenge information is different from the first authentication challenge information, the first authentication challenge information is verified unsuccessfully, and the process ends.

[0091] 5042: After the host verifies the first authentication challenge information, it obtains the second authentication challenge information based on the first environment attribute information and the first authentication challenge information.

[0092] See also Figure 6 The virtual instance in the host obtains the first environment attribute information of the virtual instance, and obtains the second authentication challenge information (expressed by MAC2) through the authentication challenge algorithm based on the first environment attribute information and the first authentication challenge information.

[0093] For example, the virtual instance in the host can input the first environment attribute information and the first authentication challenge information into the HMAC algorithm, and the HAMC algorithm calculates the second authentication challenge information based on the first environment attribute information and the first authentication challenge information. The virtual instance in the host obtains the second authentication challenge information output by the HMAC algorithm.

[0094] Step 505: The host generates a one-time key and encrypts the one-time key based on the public key of the server to obtain a first ciphertext.

[0095] See also Figure 6In addition to the virtual instance, the host also includes a trusted root. Both the virtual instance and the trusted root include a pre-shared secret key (PSK). In order to ensure the security of the second authentication challenge information, the virtual instance can use the PSK to authenticate and encrypt the second authentication challenge information to obtain first authentication encryption information. The first authentication encryption information includes the ciphertext of the second authentication challenge information and the first hash value, and the first authentication encryption information is input into the trusted root (represented by C2).

[0096] The host authenticates and decrypts the first authentication encrypted information in the trusted root. If the authentication and decryption of the first authentication encrypted information is successful, it is determined that the virtual instance is a legitimate instance, and a one-time key (expressed as OTK) is generated.

[0097] Optionally, during implementation, the host can use the PSK in the trusted root to decrypt the ciphertext included in the first authentication encryption information to obtain authentication challenge information, and calculate a second hash value of the decrypted authentication challenge information. If the first hash value and the second hash value are the same, the authentication and decryption of the first authentication encryption information succeeds, and the virtual instance is determined to be a legitimate instance. If the first hash value and the second hash value are different, the authentication and decryption of the first authentication encryption information fails, and the virtual instance is determined to be not a legitimate instance, and the process ends.

[0098] In the trusted root, the host uses the server's public key to encrypt the one-time key to obtain the first ciphertext (denoted by C3).

[0099] Step 506: The host encrypts the second authentication challenge information based on the one-time key to obtain a second ciphertext.

[0100] In step 506, see Figure 6 , the host encrypts the second authentication challenge information based on the one-time key in the trusted root to obtain a second ciphertext (expressed using OTC).

[0101] Step 507: The host performs signature verification on the first ciphertext and the second ciphertext based on the trusted root private key to obtain first signature verification information.

[0102] In step 507, see Figure 6 The trusted root includes a trusted root private key. In the trusted root, the host signs and verifies the first ciphertext and the second ciphertext based on the trusted root private key to obtain first signature verification information.

[0103] Optionally, the host encrypts the first ciphertext and the second ciphertext using the trusted root private key in the trusted root to obtain first signature confirmation information.

[0104] Step 508: The host sends an authentication and authorization request to the server, where the authentication and authorization request includes the first ciphertext, the second ciphertext, and the first signature confirmation information.

[0105] See also Figure 6 The trusted root of the host sends the first ciphertext, the second ciphertext, and the first signature confirmation information to the virtual instance in the host. The virtual instance in the host sends an authentication and authorization request to the server, which includes the first ciphertext, the second ciphertext, and the first signature confirmation information.

[0106] The first ciphertext, the second ciphertext and the first signature confirmation information are authentication and authorization information. Next, the server determines whether to provide the first service to the virtual instance based on the authentication and authorization information.

[0107] Step 509: The server receives the authentication and authorization request, and obtains the trusted root public key and the second environment attribute information associated with the AK based on the AK.

[0108] In step 509, the server obtains the trusted root public key associated with the AK from the correspondence between the AK and the trusted root public key based on the AK, and obtains the second environmental attribute information associated with the AK from the correspondence between the AK and the environmental attribute information based on the AK.

[0109] Optionally, in the above step 502, the server may obtain the trusted root public key and the second environment attribute information associated with the AK based on the AK.

[0110] Step 510: The server verifies the first signature confirmation information based on the trusted root public key, the first ciphertext and the second ciphertext.

[0111] In step 510, the server decrypts the first signature verification information using the trusted root public key to obtain a first ciphertext and a second ciphertext. If the received first ciphertext and the decrypted first ciphertext are identical, and if the received second ciphertext and the decrypted second ciphertext are identical, verification of the first signature verification information succeeds. If the received first ciphertext and the decrypted first ciphertext differ, and / or if the received second ciphertext and the decrypted second ciphertext differ, verification of the first signature verification information fails, and the process ends.

[0112] Step 511: When the server verifies that the first signature confirmation information is passed, the server decrypts the first ciphertext based on the public key of the server to obtain a one-time key.

[0113] Step 512: The server decrypts the second ciphertext based on the one-time key to obtain second authentication challenge information.

[0114] Step 513: The server authenticates the identity of the virtual instance based on the first authentication challenge information, the second environment attribute information, and the second authentication challenge information.

[0115] In step 513, the server obtains third authentication challenge information using an authentication challenge algorithm based on the second environment attribute information and the first authentication challenge information. If the third authentication challenge information and the second authentication challenge information are the same, the identity of the authentication virtual instance is valid. If the third authentication challenge information and the second authentication challenge information are different, the identity of the authentication virtual instance is invalid, and the process ends.

[0116] Optionally, the server inputs the second environment attribute information and the first authentication challenge information into the HMAC algorithm, the HMAC algorithm calculates the third authentication challenge information based on the second environment attribute information and the first authentication challenge information, and the server obtains the third authentication challenge information output by the HMAC algorithm.

[0117] Step 514: When the server verifies that the identity of the virtual instance is legitimate, it determines to provide the first service to the virtual instance.

[0118] In step 514 , the server determines the first service based on the identification information of the first service included in the access request, and determines to provide the determined first service to the virtual instance.

[0119] For example, the first service is a service that calls an interface. When the virtual instance's identity is verified to be legitimate, the server allows the virtual instance to call the interface. For another example, the first service is a service that stores data or reads data on a cloud service platform. When the virtual instance's identity is verified to be legitimate, the server allows the virtual instance to store data on the cloud service platform or read data from the cloud service platform.

[0120] In an embodiment of the present application, the server obtains the SK corresponding to the AK and obtains the first authentication challenge information based on the SK and the access request. The host obtains the second authentication challenge information based on the first authentication challenge information and the first environmental attribute information, encrypts the one-time key based on the public key of the server to obtain the first ciphertext, encrypts the second authentication challenge information based on the one-time key to obtain the second ciphertext, signs and verifies the first ciphertext and the second ciphertext based on the trusted root private key to obtain the first signature verification information, and sends the first ciphertext, the second ciphertext, and the first signature verification information to the server. Because the AK is associated with the trusted root public key of the host and the second environmental attribute information of the virtual instance in the host, the server can obtain the trusted root public key and the second environmental attribute information based on the AK, and verify the first signature verification information based on the trusted root public key, the first ciphertext, and the second ciphertext; when the verification of the first signature verification information passes, the server decrypts the first ciphertext based on the public key of the server to obtain the one-time key; decrypts the second ciphertext based on the one-time key to obtain the first authentication challenge information; authenticates the identity of the virtual instance based on the first authentication challenge information, the second environmental attribute information, and the second authentication challenge information; and when the identity is verified to be legitimate, determines to provide the first service to the virtual instance. Since the AK is associated with the trusted root public key of the host and the second environment attribute information of the virtual instance in the host, even if the AK and the SK are leaked, when other virtual instances use the AK and the SK to request the first service, the server can verify that the identity of the other virtual instances is illegal, and thus will not provide the first service to other virtual instances, thereby improving the security of the first service.

[0121] See also Figure 7 , the embodiment of the present application provides a method 700 for requesting a service, the method 700 is applied to Figure 1 or Figure 3 In the communication system 100 shown, in the method 700, the private access credential is SK and the private access credential identifier is AK. The method 700 includes the following process.

[0122] Step 701: The host signs the access request based on SK to obtain first signature information.

[0123] See also Figure 8 In step 701, a host includes a virtual instance, which includes an AK and an SK corresponding to the AK. When the virtual instance requires a first service, the virtual instance in the host may generate an access request including identification information of the first service. The virtual instance in the host uses the SK to sign the access request to obtain first signature information.

[0124] Optionally, the virtual instance in the host uses SK to encrypt the access request to obtain first signature information (denoted by S1).

[0125] See also Figure 8In addition to the virtual instance, the host also includes a trusted root. Both the virtual instance and the trusted root include PSK. In order to ensure the security of the first signature information, the virtual instance can use PSK to authenticate and encrypt the first signature information to obtain second authentication encryption information. The second authentication encryption information includes the ciphertext of the first signature information and the third hash value, and inputs the second authentication encryption information (represented by C1) into the trusted root.

[0126] Step 702: The host verifies the signature of the first signature information based on the trusted root private key to obtain second signature verification information.

[0127] In step 702, the host verifies the signature of the first signature information in the trusted root based on the trusted root private key to obtain second signature verification information. Optionally, during implementation, the host encrypts the first signature information in the trusted root based on the trusted root private key to obtain second signature verification information.

[0128] See also Figure 8 After the virtual instance inputs the second authentication encrypted information into the trusted root, the host authenticates and decrypts the second authentication encrypted information in the trusted root. If the authentication and decryption of the second authentication encrypted information succeeds, the virtual instance is determined to be legitimate. If the authentication and decryption of the second authentication encrypted information fails, the virtual instance is determined to be illegitimate, and the process ends.

[0129] Optionally, the host can use the PSK in the trusted root to decrypt the ciphertext included in the second authentication encrypted information to obtain signature information, and calculate a fourth hash value of the decrypted signature information. If the third hash value and the fourth hash value are the same, the authentication and decryption of the second authentication encrypted information succeeds, and the virtual instance is determined to be a legitimate instance. If the third hash value and the fourth hash value are different, the authentication and decryption of the second authentication encrypted information fails, and the virtual instance is determined to be an illegitimate instance.

[0130] After determining that the virtual instance is a legitimate instance, the host uses the trusted root private key to sign and verify the first signature information in the trusted root to obtain second signature verification information. Optionally, during implementation, the host uses the trusted root private key to encrypt the first signature information in the trusted root to obtain second signature verification information (using A1).

[0131] Step 703: The host sends an access request and an authentication and authorization request to the server. The authentication and authorization request includes first environment attribute information, first signature information, AK and second signature confirmation information. The first environment attribute information is the environment attribute information of the virtual instance in the host.

[0132] See also Figure 8The host's root of trust sends the second signature verification information to the virtual instance in the host. The virtual instance in the host sends an access request and an authentication and authorization request to the server. The authentication and authorization request includes authentication and authorization information, which includes the first environment attribute information, the first signature information, the AK, and the second signature verification information. The server then determines whether to provide the first service to the virtual instance based on the authentication and authorization information.

[0133] Step 704: The server receives the access request and the authentication and authorization request, where the authentication and authorization request includes the first environment attribute information, the first signature information, the AK, and the second signature confirmation information. Based on the AK, the server obtains the SK corresponding to the AK.

[0134] In step 704, the server obtains the SK corresponding to the AK from the correspondence between AK and SK based on the AK.

[0135] Step 705: The server obtains the trusted root public key and second environment attribute information associated with the AK based on the AK.

[0136] In step 705, the server obtains the trusted root public key associated with the AK from the correspondence between the AK and the trusted root public key based on the AK, and obtains the second environmental attribute information associated with the AK from the correspondence between the AK and the environmental attribute information based on the AK.

[0137] Step 706: When the first environment attribute information and the second environment attribute information are the same, the server verifies the second signature confirmation information based on the SK, the trusted root public key and the first signature information.

[0138] In step 706, the second signature confirmation information may be verified through the following operations 7061-7063.

[0139] 7061: The server signs the access request based on the SK to obtain second signature information.

[0140] See also Figure 8 In step 7061, the server uses SK to sign the access request to obtain second signature information (denoted by S2).

[0141] 7062: The server compares the first signature information and the second signature information.

[0142] 7063: When the first signature information and the second signature information are the same, the server uses the trusted root public key to decrypt the second signature confirmation information. If the second signature confirmation information can be successfully decrypted, the verification of the second signature confirmation information is successful.

[0143] If the first signature information and the second signature information are different, the verification of the second signature confirmation information fails. Alternatively, if the server cannot successfully decrypt the second signature confirmation information using the trusted root public key, the verification of the second signature confirmation information fails.

[0144] Step 707: When the server verifies that the second signature confirmation information is successful, it determines to provide the first service to the virtual instance.

[0145] In step 707 , the server determines the first service based on the identification information of the first service included in the access request, and determines to provide the determined first service to the virtual instance.

[0146] For example, the first service is a service that calls an interface. When the virtual instance's identity is verified to be legitimate, the server allows the virtual instance to call the interface. For another example, the first service is a service that stores data or reads data on a cloud service platform. When the virtual instance's identity is verified to be legitimate, the server allows the virtual instance to store data on the cloud service platform or read data from the cloud service platform.

[0147] In an embodiment of the present application, the host signs the access request based on the SK to obtain the first signature information, verifies the signature of the first signature information based on the trusted root private key to obtain the second signature verification information, and sends the first signature information, the first environment attribute information, and the second signature verification information to the server. The server obtains the SK corresponding to the AK based on the AK; obtains the trusted root public key and the second environment attribute information associated with the AK based on the AK; when the first environment attribute information and the second environment attribute information are the same, verifies the second signature verification information based on the SK, the trusted root public key, and the first signature information; when the verification of the second signature verification information passes, determines to provide the first service to the virtual instance. Since the AK is associated with the trusted root public key of the host and the second environment attribute information of the virtual instance in the host, even if the AK and the SK are leaked, when other virtual instances use the AK and the SK to request the first service, the server determines that the first service will not be provided to other virtual instances, thereby improving the security of the first service.

[0148] See also Figure 9 , the embodiment of the present application provides a method 900 for requesting a service, the method 900 is applied to Figure 2 or Figure 4 In the communication system 100 shown, in the method 900, the private access credential is an access token, and the private access credential identifier is a user identifier in the access token. The method 900 includes the following process.

[0149] Step 901: The host signs and verifies the first environment attribute information based on the trusted root private key to obtain third signature verification information. The first environment attribute information is the environment attribute information of the virtual instance in the host.

[0150] See also Figure 10 The host includes a trusted root and a virtual instance, and the virtual instance includes an access token. The virtual instance can obtain first environment attribute information and input the first environment attribute information to the trusted root.

[0151] The trusted root in the host includes a trusted root private key. In the trusted root, the host performs signature verification on the first environment attribute information based on the trusted root private key to obtain third signature verification information.

[0152] Optionally, during implementation, the host encrypts the first environment attribute information in the trusted root based on the trusted root private key to obtain third signature confirmation information (denoted by A3).

[0153] Step 902: The host encrypts the access token and the third signature verification information based on the public key of the server to obtain a third ciphertext.

[0154] See also Figure 10 The trusted root in the host can send the third signature verification information to the virtual instance in the host. The virtual instance in the host includes the public key of the server. The virtual instance in the host encrypts access token and the third signature verification information based on the public key of the server to obtain a third ciphertext.

[0155] Step 903: The host sends an access request and an authentication and authorization request to the server, where the authentication and authorization request includes the third ciphertext.

[0156] Optionally, the authentication and authorization request includes authentication and authorization information, and the authentication and authorization information includes the third ciphertext. Next, the server determines whether to provide the first service to the virtual instance based on the authentication and authorization information.

[0157] Step 904: The server receives the access request and the authentication and authorization request, where the authentication and authorization request includes the third ciphertext, decrypts the third ciphertext based on the server's private key, and obtains the access token and the third signature confirmation information.

[0158] Step 905: The server obtains the trusted root public key and the second environment attribute information associated with the user identifier based on the user identifier included in the access token.

[0159] In step 905, the server obtains the trusted root public key associated with the user identifier from the correspondence between the user identifier and the trusted root public key based on the user identifier, and obtains the second environmental attribute information associated with the user identifier from the correspondence between the user identifier and the environmental attribute information based on the user identifier.

[0160] Step 906: The server decrypts the third signature verification information based on the trusted root public key to obtain the first environment attribute information.

[0161] Step 907: When the first environment attribute information and the second environment attribute information are the same, the server determines to provide the first service to the virtual instance.

[0162] In step 907 , the server determines the first service based on the identification information of the first service included in the access request, and determines to provide the determined first service to the virtual instance.

[0163] For example, the first service is a service that calls an interface. When the virtual instance's identity is verified to be legitimate, the server allows the virtual instance to call the interface. For another example, the first service is a service that stores data or reads data on a cloud service platform. When the virtual instance's identity is verified to be legitimate, the server allows the virtual instance to store data on the cloud service platform or read data from the cloud service platform.

[0164] In an embodiment of the present application, the host signs and verifies the first environment attribute information based on the trusted root private key to obtain third signature verification information; encrypts the access token and the third signature verification information based on the public key of the server to obtain a third ciphertext, and sends the third ciphertext to the server. The server decrypts the third ciphertext based on the private key of the server to obtain the access token and the third signature verification information; based on the user identifier included in the access token, obtains the trusted root public key and the second environment attribute information associated with the user identifier; decrypts the third signature verification information based on the trusted root public key to obtain the first environment attribute information; when the first environment attribute information and the second environment attribute information are the same, it is determined to provide the first service to the virtual instance. In this way, even if the access token is leaked, when other virtual instances use the access token to request the first service, the server determines that the first service will not be provided to other virtual instances, thereby improving the security of the first service.

[0165] Figure 11 FIG. 1 shows a possible exemplary block diagram of a device for requesting a service involved in an embodiment of the present application. Figure 11 As shown, the apparatus 900 may include modules or units for implementing the above method embodiments. In one possible design, the apparatus 1100 includes: a sending unit 1102, a processing unit 1103, and a receiving unit 1104. Optionally, the apparatus 1100 may also include a storage unit 1101 for storing apparatus program code and / or data.

[0166] (1) The device 1100 may be the host-side device in the above embodiments, for example, a terminal or a communication module in the terminal, or a circuit or chip in the terminal responsible for the communication function.

[0167] For example, in one embodiment, the device 1100 includes a virtual instance and a trusted root private key.

[0168] The sending unit 1102 is configured to send an access request to the server, where the access request is used to request a first service, where the first service is a service required by the virtual instance;

[0169] Processing unit 1103 is configured to obtain authentication authorization information based on the private access credential, the access request, the first environment attribute information of the virtual instance, and the trusted root private key, and associate the private access credential identifier corresponding to the private access credential with the second environment attribute information, wherein the private access credential identifier is further associated with the trusted root public key;

[0170] The sending unit 1102 is further configured to send an authentication and authorization request to the server, where the authentication and authorization request includes authentication and authorization information. The authentication and authorization request is used to request the server to determine whether to provide the first service to the virtual instance based on the authentication and authorization information.

[0171] In a possible design, the detailed implementation process of the sending unit 1102 sending the access request to the server is shown in Figure 5 Steps 501, 502, and 503 of the method 500 are shown. Figure 7 Step 703 of the method 700 or Figure 9 The relevant contents of step 903 of the method 900 are not described in detail here.

[0172] In a possible design, the detailed implementation process of the processing unit 1103 obtaining the authentication authorization information is shown in Figure 5 Steps 504-507 of the method 500 are shown. Figure 7 Step 702 of the method 700 or Figure 9 The relevant content of step 902 of the method 900 is not described in detail here.

[0173] In a possible design, the detailed implementation process of the sending unit 1102 sending the authentication and authorization request to the server is shown in Figure 5 Step 508 of the method 500 is shown. Figure 7 Step 703 of the method 700 or Figure 9 The relevant contents of step 903 of the method 900 are not described in detail here.

[0174] In one possible design, the private access credential is a secret access key SK, the private access credential identifier is an access key identifier AK, and the sending unit 1102 is further configured to:

[0175] An AK is sent to the server, where the authentication and authorization request is used to request the server to determine whether to provide the first service to the virtual instance based on the authentication and authorization information and the AK.

[0176] In a possible design, the detailed implementation process of the sending unit 1102 sending the AK to the server is shown in Figure 5 Steps 501, 502, and 503 of the method 500 are shown. Figure 7 Step 703 of the method 700 or Figure 9 The relevant contents of step 903 of the method 900 are not described in detail here.

[0177] In one possible design, the authentication authorization information includes a first ciphertext, a second ciphertext, and first signature confirmation information. The receiving unit 1104 is configured to receive first authentication challenge information sent by the server, where the first authentication challenge information is obtained by the server based on the SK corresponding to the AK and the access request.

[0178] The processing unit 1103 is configured to obtain second authentication challenge information based on the first authentication challenge information and the first environment attribute information;

[0179] The processing unit 1103 is further configured to generate a one-time key and encrypt the one-time key based on the public key of the server to obtain a first ciphertext;

[0180] The processing unit 1103 is further configured to encrypt the second authentication challenge information based on the one-time key to obtain a second ciphertext;

[0181] The processing unit 1103 is further configured to perform signature verification on the first ciphertext and the second ciphertext based on the trusted root private key to obtain first signature verification information.

[0182] In a possible design, the detailed implementation process of the receiving unit 1104 receiving the first authentication challenge information sent by the server is shown in Figure 5 The relevant contents of step 504 of the method 500 are not described in detail here.

[0183] In one possible design, the detailed implementation process of the processing unit 1103 obtaining the second authentication challenge information is shown in Figure 5 The relevant contents of step 504 of the method 500 are not described in detail here.

[0184] In one possible design, the processing unit 1103 generates a one-time key and obtains the first ciphertext. Figure 5 The relevant contents of step 505 of the method 500 are not described in detail here.

[0185] In one possible design, the processing unit 1103 encrypts the second authentication challenge information based on the one-time key to obtain the second ciphertext. Figure 5 The relevant contents of step 506 of the method 500 are not described in detail here.

[0186] In one possible design, the detailed implementation process of the processing unit 1103 obtaining the first signature confirmation information is shown in Figure 5 The relevant contents of step 507 of the method 500 are not described in detail here.

[0187] In one possible design, the authentication authorization information includes first signature information, first environment attribute information, and second signature confirmation information; the processing unit 1103 is configured to:

[0188] Signing the access request based on SK to obtain first signature information;

[0189] The first signature information is signed and verified based on the trusted root private key to obtain second signature verification information.

[0190] In one possible design, the processing unit 1103 signs the access request based on SK to obtain the first signature information. Figure 7 The relevant contents of step 701 of the method 700 are not described in detail here.

[0191] In one possible design, the processing unit 1103 performs signature verification on the first signature information based on the trusted root private key, and obtains the second signature verification information. Figure 7 The relevant contents of step 702 of the method 700 are not described in detail here.

[0192] In one possible design, the private access credential is an access credential access token, the private access credential identifier is a user identifier corresponding to the access token, the access token includes the user identifier, and the authentication authorization information includes the third ciphertext; the processing unit 1103 is configured to:

[0193] Performing signature verification on the first environment attribute information based on the trusted root private key to obtain third signature verification information;

[0194] The access token and the third signature confirmation information are encrypted based on the public key of the server to obtain the third ciphertext.

[0195] In one possible design, the detailed implementation process of the processing unit 1103 obtaining the third signature confirmation information is shown in Figure 9 The relevant contents of step 901 of the method 900 are not described in detail here.

[0196] In one possible design, the detailed implementation process of the processing unit 1103 obtaining the third ciphertext is shown in Figure 9 The relevant content of step 902 of the method 900 is not described in detail here.

[0197] In one possible design, the first environment attribute information includes one or more of the following: the service account of the virtual instance, the architecture information of the device 1100, the size of the memory space of the virtual instance, the identification information of the virtual instance, the kernel identification information associated with the virtual instance, the time information of starting the virtual instance, the dedicated address of the virtual instance, the identification information of the disk associated with the virtual instance, or the partition where the virtual instance is running.

[0198] In one possible design, when the device 1100 is a host or a communication module within the host, the functions of the processing unit 1103 may be implemented by one or more processors. Specifically, the processor may include a modem chip, or a system-on-chip (SoC) chip or SIP chip containing a modem core. The functions of the transmitting unit 1102 and the receiving unit 1104 may be implemented by transceiver circuits.

[0199] In one possible design, when the device 1100 is a circuit or chip responsible for communication functions in a host, such as a modem chip or a system-on-chip (SoC) chip or SIP chip containing a modem core, the functions of the processing unit 1103 can be implemented by a circuit system including one or more processors or processor cores in the aforementioned chip. The functions of the transmitting unit 1102 and the receiving unit 1104 can be implemented by an interface circuit or data transceiver circuit on the aforementioned chip.

[0200] (2) The device 1100 may be the server in the above embodiment.

[0201] For example, in one embodiment, the receiving unit 1104 is configured to receive an access request sent by a host, the host including a virtual instance and a trusted root private key, the access request being used to request a first service, the first service being a service required by the virtual instance;

[0202] The receiving unit 1104 is further configured to receive authentication and authorization information sent by the host, where the authentication and authorization information is obtained by the host based on the private access credential, the access request, the first environment attribute information of the virtual instance, and the trusted root private key, and is associated with a private access credential identifier corresponding to the private access credential and the second environment attribute information, and the private access credential identifier is also associated with the trusted root public key;

[0203] The processing unit 1103 is configured to determine whether to provide the first service to the virtual instance based on the authentication and authorization information.

[0204] In a possible design, the detailed implementation process of the receiving unit 1104 receiving the access request sent by the host is shown in FIG. Figure 5 Step 502 of the method 500 is shown. Figure 7 Step 704 of the method 700 shown or Figure 9 The relevant contents in step 904 of the method 900 are not described in detail here.

[0205] In a possible design, the detailed implementation process of the receiving unit 1104 receiving the authentication and authorization information sent by the host is shown in FIG. Figure 5 Step 509 of the method 500 is shown. Figure 7 Steps 704-707 of the method 700 shown or Figure 9 The relevant contents in steps 904-907 of the method 900 are not described in detail here.

[0206] In a possible design, the processing unit 1103 determines whether to provide the first service to the virtual instance based on the authentication authorization information. Figure 5 Steps 509-514 of the method 500 are shown. Figure 7 Steps 704-707 of the method 700 shown or Figure 9 The relevant contents in steps 904-907 of the method 900 are not described in detail here.

[0207] In one possible design, the private access credential is a secret access key SK, the private access credential identifier is an access key identifier AK, and the receiving unit 1104 is further configured to receive the AK sent by the host;

[0208] The processing unit 1103 is configured to determine whether to provide the first service to the virtual instance based on the authentication and authorization information and the AK.

[0209] In a possible design, the detailed implementation process of the receiving unit 1104 receiving the AK sent by the host is shown in FIG. Figure 5 Step 502 of the method 500 is shown. Figure 7 Step 704 of the method 700 shown or Figure 9 The relevant contents in step 904 of the method 900 are not described in detail here.

[0210] In one possible design, the processing unit 1103 determines whether to provide the first service to the virtual instance based on the authentication authorization information and the AK. Figure 5 Steps 509-514 of the method 500 are shown. Figure 7 Steps 704-707 of the method 700 shown or Figure 9 The relevant contents in steps 904-907 of the method 900 are not described in detail here.

[0211] In one possible design, the authentication authorization information includes a first ciphertext, a second ciphertext, and first signature confirmation information. The first ciphertext is a ciphertext of a one-time key generated by the host, the second ciphertext is a ciphertext of the second authentication challenge information, and the first signature confirmation information is obtained by the host based on the trusted root private key, the first ciphertext, and the second ciphertext. The processing unit 1103 is further configured to obtain an SK corresponding to the AK; and obtain the first authentication challenge information based on the SK and the access request.

[0212] The sending unit 1102 is configured to send the first authentication challenge information to the host, so that the host obtains the second authentication challenge information based on the first authentication challenge information and the first environment attribute information.

[0213] In one possible design, the processing unit 1103 obtains the SK corresponding to the AK; the detailed implementation process of obtaining the first authentication challenge information based on the SK and the access request is shown in FIG. Figure 5 The relevant contents in step 502 of the method 500 are not described in detail here.

[0214] In one possible design, the detailed implementation process of the sending unit 1102 sending the first authentication challenge information to the host is shown in Figure 5 The relevant contents in step 503 of the method 500 are not described in detail here.

[0215] In one possible design, the processing unit 1103 is configured to:

[0216] Based on the AK, obtain the trusted root public key and second environment attribute information associated with the AK;

[0217] verifying the first signature confirmation information based on the trusted root public key, the first ciphertext, and the second ciphertext;

[0218] When the first signature confirmation information is verified to be successful, the first ciphertext is decrypted based on the public key of the device 1100 to obtain a one-time key;

[0219] Decrypting the second ciphertext based on the one-time key to obtain second authentication challenge information;

[0220] authenticating the identity of the virtual instance based on the first authentication challenge information, the second environment attribute information, and the second authentication challenge information;

[0221] When the identity is verified to be legitimate, it is determined to provide the first service to the virtual instance.

[0222] In a possible design, the processing unit 1103 obtains the trusted root public key and the second environment attribute information associated with the AK based on the AK. Figure 5 The relevant contents in step 509 of the method 500 are not described in detail here.

[0223] In one possible design, the processing unit 1103 verifies the first signature confirmation information based on the trusted root public key, the first ciphertext and the second ciphertext. Figure 5 The relevant contents in step 510 of the method 500 are not described in detail here.

[0224] In one possible design, the processing unit 1103 decrypts the first ciphertext based on the public key of the device 1100 to obtain the one-time key. Figure 5 The relevant contents in step 511 of the method 500 are not described in detail here.

[0225] In one possible design, the processing unit 1103 decrypts the second ciphertext based on the one-time key to obtain the second authentication challenge information. Figure 5 The relevant contents in step 512 of the method 500 are not described in detail here.

[0226] In a possible design, the detailed implementation process of the processing unit 1103 authenticating the identity of the virtual instance is shown in Figure 5 The relevant contents in step 513 of the method 500 are not described in detail here.

[0227] In a possible design, the processing unit 1103 determines to provide the first service to the virtual instance. Figure 5 The relevant contents in step 514 of the method 500 are not described in detail here.

[0228] In one possible design, the authentication and authorization information includes first signature information, first environment attribute information, and second signature verification information. The first signature information is information obtained by the host based on the access request and the SK, and the second signature verification information is information obtained by the host based on the trusted root private key and the first signature information.

[0229] The processing unit 1103 is configured to:

[0230] Based on AK, obtain the SK corresponding to AK;

[0231] Based on the AK, obtain the trusted root public key and second environment attribute information associated with the AK;

[0232] When the first environment attribute information and the second environment attribute information are the same, verifying the second signature confirmation information based on SK, the trusted root public key and the first signature information;

[0233] When the second signature confirmation information is verified to be successful, it is determined to provide the first service to the virtual instance.

[0234] In a possible design, the processing unit 1103 obtains the SK corresponding to the AK based on the AK. Figure 7 The relevant contents in step 704 of the method 700 are not described in detail here.

[0235] In a possible design, the detailed implementation process of the processing unit 1103 obtaining the trusted root public key and the second environment attribute information associated with the AK is shown in FIG. Figure 7 The relevant contents in step 705 of the method 700 are not described in detail here.

[0236] In one possible design, the processing unit 1103 verifies the second signature confirmation information based on SK, the trusted root public key and the first signature information. Figure 7 The relevant contents in step 706 of the method 700 are not described in detail here.

[0237] In a possible design, the processing unit 1103 determines to provide the first service to the virtual instance. Figure 7 The relevant contents in step 707 of the method 700 are not described in detail here.

[0238] In one possible design, the private access credential is an access credential access token, the private access credential identifier is a user identifier corresponding to the access token, the access token includes the user identifier, and the authentication authorization information includes a third ciphertext. The third ciphertext is obtained by the host encrypting the access token and third signature verification information based on the public key of the device 1100. The third signature verification information is obtained by the host signing and verifying the first environment attribute information based on the trusted root private key.

[0239] The processing unit 1103 is configured to:

[0240] decrypting the third ciphertext based on the private key of the device 1100 to obtain access token and third signature confirmation information;

[0241] Based on the user identifier included in the access token, obtain the trusted root public key and the second environment attribute information associated with the user identifier;

[0242] decrypting the third signature confirmation information based on the trusted root public key to obtain the first environment attribute information;

[0243] When the first environment attribute information and the second environment attribute information are the same, it is determined to provide the first service to the virtual instance.

[0244] It is understandable that the division of units in the above-mentioned device is merely a division of logical functions, and each function may correspond to a functional unit, or two or more functions may be integrated into one functional unit. In actual implementation, all or part of the units may be integrated into one physical entity, or distributed across different physical entities. In addition, the above-mentioned functional units may be implemented in the form of hardware, software, or a combination of hardware and software. Whether a function is executed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0245] In one example, the functional unit in any of the above devices can be one or more integrated circuits configured to implement the above method, such as: one or more application specific integrated circuits (ASICs), or, one or more central processing units (CPUs), one or more microprocessors (MCUs), one or more digital signal processors (DSPs), or, one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms.

[0246] In an example, the storage unit 1101 may include a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory and / or a register.

[0247] See also Figure 12 , is a structural diagram of a host 1000 provided in an embodiment of the present application, the host 1000 may correspond to Figure 1-4 The host shown in the communication system 100 is, or is Figure 5-10 The host in the method of requesting service shown in FIG. 1 is used to implement the operation of the host in the above embodiment. Figure 12 As shown, the host includes: one or more antennas 1010 , a radio frequency processing system 1020 , and a processor system 1030 .

[0248] In the downlink direction, the RF processing system 1020 receives RF signals through the antenna 1010 and sends the processed signals to the processor system 1030 for further processing. In the uplink direction, the processor system 1030 processes the host-side information and sends it to the RF processing system 1020. The RF processing system 1020 processes the signal and sends it through the antenna 1010.

[0249] In one example, the RF processing system 1020 serves as the host's external communication interface and may include an RF front end (RFFE) 1021 and an RF transceiver 1022. The RFFE 1021 primarily performs shaping, passband selection, and / or gain processing on RF signals received by the antenna or to be transmitted through the antenna. It may include one or more components such as an RF switch, a duplexer, a filter, a power amplifier, an antenna tuner, and a low-noise amplifier. The RFFE 1021 may be a circuit system composed of multiple discrete components or integrated into one or more chips. The RF transceiver 1022 processes the RF signals received by the RFFE into baseband / IF signals for further processing by the processor system 1030, and processes the baseband / IF signals provided by the processor system 1030 into RF signals for transmission to the RFFE 1021. The baseband / IF signals transmitted between the transceiver 1020 and the processor system 1030 may be either digital or analog. The RF transceiver 1022 may be implemented by one or more chips, which are often referred to as radio frequency integrated circuits (RFICs).

[0250] In one example, the processor system 1030 may include one or more processors for processing signals and executing one or more communication protocols, and memory 1036. In one example, the one or more processors include at least one baseband processor 1031 (also known as a modem processor). Memory 1036 is used to store data and / or computer program instructions. Optionally, the processor system 1030 may also include one or more application processors 1032 for processing the host operating system and application layer. Optionally, the processor system 1030 may also include a voice subsystem 1033, a multimedia subsystem 1034, an interface circuit 1035, and / or memory 1036. The voice subsystem 1033 is used to process voice signals, the multimedia subsystem 1034 is used to handle multimedia-related operations such as video encoding and decoding, image processing, etc., and the interface circuit 1035 is used to communicate with other host components, such as the display 1040, input device 1050, and memory 1060. The aforementioned components in the processor system 1030 may communicate with each other via a bus or communication interface circuit.

[0251] In one example, the processor system 1030 can be packaged into a processor chip, such as a SoC chip or a SIP chip. In another example, the processor system 1030 can be a system consisting of multiple chips, for example, the baseband processor 1031 can be packaged into a single chip, or it can be packaged into a single chip with part or all of the circuits of the radio frequency processing system.

[0252] In one example, the memory 1036 may be an on-chip memory, that is, located on the chip of the processor system 1030. In one example, the memory 1060 may be an off-chip memory, that is, located outside the chip of the processor system 1030.

[0253] In one example, the baseband processor 1031 may include one or more processor cores 10311, a memory 10312, and an interface circuit 10314. The one or more processor cores 10311 are configured to process signals and execute one or more communication protocols. The memory 10312 is configured to store at least a portion of corresponding computer program instructions and / or data. In one example, the one or more processor cores 10311 implement the relevant operations in the above-described method embodiments (such as the relevant operations performed by the host in the above-described method for requesting a service) by executing the computer program instructions stored in the memory 10312. In the present disclosure, the memory 10312 is used to store corresponding computer program instructions and / or data. This may refer to the memory 10312 being used to store all corresponding computer program instructions and / or data for execution by the processor core 10311, or it may refer to the memory 10312 being used to store a portion of the corresponding computer program instructions and / or data, including the computer program instructions and / or data currently required to be executed by the processor 10311. The memory 10312 may store different portions of computer program instructions and / or data multiple times for execution by the processor core 10311 to implement the relevant operations in the above-mentioned method embodiments. The interface circuit 10314 serves as a communication interface for communicating with other components, such as transmitting signals with the RF processing system 1020, communicating with other subsystems and related components of the processor system 1030 via a bus, such as transmitting data and control signals between the application processor 1032 and the voice subsystem 1033, and transmitting data or computer program instructions between the memory 1036 or the memory 1060. Optionally, in order to reduce the load of the processor core, a baseband signal processing circuit 10313 may be provided to implement at least part of the baseband signal processing, including signal demodulation, modulation, encoding or decoding.

[0254] In one example, the communication device provided in this application may be a host 1000 , a communication module including a processor system 1030 and a radio frequency system 1020 , a processor system 1030 or a baseband processor 1031 .

[0255] The above-mentioned processor, processor system, application processor, baseband processor, processor circuit or processor core can be collectively referred to as a processor, which may include one or more combinations of a central processing unit (CPU), a digital signal processor (DSP), a microprocessor unit (MPU), a microcontroller unit (MCU), a graphics processing unit (GPU), a field programmable gate array (FPGA), an artificial intelligence processor (AI processor) or a neural network processor (NPU).

[0256] The aforementioned memory may include one or more of the following storage media: random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), phase-change memory (PCM), resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), cache, register, read-only memory (ROM), flash memory, erasable programmable read-only memory (EPROM), hard disk, etc. In one example, computer program instructions for executing the aforementioned embodiments may be stored in a non-volatile memory, such as at least a portion of the aforementioned memory 1060 (e.g., one or more of ROM, flash memory, EPROM, or hard disk). When the host is running, the corresponding computer program instructions can be partially or completely loaded into a memory with a faster transmission speed to the processor, such as at least a part of the above-mentioned memory 1036 and / or memory 10312 (such as one or more of RAM, SRAM, DRAM, PCM, RERAM, MRAM, FRAM, cache, or register), for execution by the processor to implement the steps in the above-mentioned method embodiments.

[0257] In one example, the RF transceiver 1022 and the RF front end 1021 may also be packaged in one chip. In one example, the RF transceiver 1022, the RF front end 1021 and the baseband processor 1031 may also be packaged in one chip.

[0258] See also Figure 13 , the embodiment of the present application provides a schematic diagram of a server 1300. The server 1300 may be the above Figure 1-4 The server 102 in the communication system 100 shown, or Figure 5-10 The server 1300 includes at least one processor 1301 , an internal connection 1302 , a memory 1303 and at least one port 1304 .

[0259] The server 1300 is a hardware device that can be used to implement Figure 11The functional modules in the device 1100 are as follows. For example, those skilled in the art may think of Figure 11 The processing unit 1103 in the device 1100 shown can be implemented by the at least one processor 1301 calling the code in the memory 1303. Figure 11 The sending unit 1102 and the receiving unit 1104 in the illustrated apparatus 1100 may be implemented through the at least one port 1304 .

[0260] Optionally, the server 1300 may also be used to implement the functions of the hybrid deployment system in any of the above embodiments.

[0261] Optionally, the processor 1301 may be a general-purpose central processing unit (CPU), a network processor (NP), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present application.

[0262] The internal connection 1302 may include a path for transmitting information between the components. Optionally, the internal connection 1302 is a single board or a bus.

[0263] The at least one port 1304 is used for communicating with other devices or communication networks.

[0264] The memory 1303 may be a read-only memory (ROM) or other static storage device capable of storing static information and instructions, a random access memory (RAM) or other dynamic storage device capable of storing information and instructions, or an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact disc, laser disc, optical disc, digital versatile disc, Blu-ray disc, etc.), a magnetic disk storage medium or other magnetic storage device, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and capable of being accessed by a computer, but not limited thereto. The memory may be independent and connected to the processor via a bus. The memory may also be integrated with the processor.

[0265] Among them, the memory 1303 is used to store the application code for executing the solution of the present application, and the execution is controlled by the processor 1301. The processor 1301 is used to execute the application code stored in the memory 1303 and cooperate with at least one port 1304, so that the server 1300 can implement the functions of the patent method.

[0266] In a specific implementation, as an embodiment, the processor 1301 may include one or more CPUs, such as Figure 13 CPU0 and CPU1 in.

[0267] In a specific implementation, as an embodiment, the server 1300 may include multiple processors, such as Figure 13 1 and 1307. Each of these processors may be a single-CPU processor or a multi-CPU processor. A processor herein may refer to one or more devices, circuits, and / or processing cores for processing data (e.g., computer program instructions).

[0268] The terms "system" and "network" in the embodiments of the present application can be used interchangeably. "At least one" refers to one or more, and "plurality" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships can exist. For example, A and / or B can represent: the existence of A alone, the existence of A and B at the same time, and the existence of B alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one of the following" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, "at least one of A, B or C" includes A, B, C, AB, AC, BC or ABC, and "at least one of A, B and C" can also be understood to include A, B, C, AB, AC, BC or ABC. And, unless otherwise specified, the ordinal numbers such as "first" and "second" mentioned in the embodiments of the present application are used to distinguish multiple objects and are not used to limit the order, timing, priority or importance of multiple objects.

[0269] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, optical storage, etc.) that contain computer-usable program code.

[0270] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0271] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0272] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0273] Obviously, those skilled in the art may make various changes and modifications to the present application without departing from the scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is intended to include these modifications and variations.

Claims

1. A method for requesting a service, characterized in that: The method is applied to a host, the host including a virtual instance and a trusted root private key, and includes: Sending an access request to a server, wherein the access request is used to request a first service, where the first service is a service required by the virtual instance; Based on the private access credential, the access request, the first environment attribute information of the virtual instance and the trusted root private key, obtaining authentication authorization information, associating a private access credential identifier corresponding to the private access credential with the second environment attribute information, and further associating the private access credential identifier with the trusted root public key; An authentication and authorization request is sent to the server, where the authentication and authorization request includes the authentication and authorization information, and the authentication and authorization request is used to request the server to determine whether to provide the first service to the virtual instance based on the authentication and authorization information.

2. The method according to claim 1, wherein The private access credential is a secret access key SK, the private access credential identifier is an access key identifier AK, and the method further includes: The AK is sent to the server, where the authentication and authorization request is used to request the server to determine whether to provide the first service to the virtual instance based on the authentication and authorization information and the AK.

3. The method according to claim 2, wherein The authentication authorization information includes a first ciphertext, a second ciphertext and first signature confirmation information; The obtaining of authentication and authorization information based on the private access credential, the access request, the first environment attribute information of the virtual instance, and the trusted root private key includes: receiving first authentication challenge information sent by the server, where the first authentication challenge information is obtained by the server by acquiring the SK corresponding to the AK and based on the SK and the access request; acquiring the second authentication challenge information based on the first authentication challenge information and the first environment attribute information; Generate a one-time key, and encrypt the one-time key based on the public key of the server to obtain the first ciphertext; Encrypting the second authentication challenge information based on the one-time key to obtain the second ciphertext; The first ciphertext and the second ciphertext are signed and verified based on the trusted root private key to obtain the first signature verification information.

4. The method according to claim 2, wherein The authentication authorization information includes first signature information, the first environment attribute information and second signature confirmation information; The obtaining of authentication and authorization information based on the private access credential, the access request, the first environment attribute information of the virtual instance, and the trusted root private key includes: Signing the access request based on the SK to obtain the first signature information; The first signature information is signed and verified based on the trusted root private key to obtain the second signature verification information.

5. The method according to claim 1, wherein The private access credential is an access credential accesstocken, the private access credential identifier is a user identifier corresponding to the accesstocken, the accesstocken includes the user identifier, and the authentication authorization information includes a third ciphertext; The obtaining of authentication and authorization information based on the private access credential, the access request, the first environment attribute information of the virtual instance, and the trusted root private key includes: Performing signature verification on the first environment attribute information based on the trusted root private key to obtain the third signature verification information; The access token and the third signature confirmation information are encrypted based on the public key of the server to obtain the third ciphertext.

6. The method according to any one of claims 1 to 5, wherein: The first environmental attribute information includes one or more of the following: the service account of the virtual instance, the architecture information of the host, the size of the memory space of the virtual instance, the identification information of the virtual instance, the kernel identification information associated with the virtual instance, the time information of starting the virtual instance, the dedicated address of the virtual instance, the identification information of the disk associated with the virtual instance, or the partition running the virtual instance.

7. A method for requesting a service, characterized in that: The method is applied to the server and includes: Receiving an access request sent by a host, the host including a virtual instance and a trusted root private key, the access request being used to request a first service, the first service being a service required by the virtual instance; Receiving authentication and authorization information sent by the host, the authentication and authorization information is obtained by the host based on the private access credential, the access request, the first environment attribute information of the virtual instance, and the trusted root private key, and the private access credential identifier corresponding to the private access credential is associated with the second environment attribute information, and the private access credential identifier is also associated with the trusted root public key; Determine whether to provide the first service to the virtual instance based on the authentication and authorization information.

8. The method according to claim 7, wherein The private access credential is a secret access key SK, the private access credential identifier is an access key identifier AK, and the method further includes: receiving the AK sent by the host; The determining whether to provide the first service to the virtual instance based on the authentication and authorization information includes: Determine whether to provide the first service to the virtual instance based on the authentication and authorization information and the AK.

9. The method according to claim 8, wherein The authentication authorization information includes a first ciphertext, a second ciphertext, and first signature verification information, wherein the first ciphertext is the ciphertext of a one-time key generated by the host, the second ciphertext is the ciphertext of second authentication challenge information, and the first signature verification information is obtained by the host based on the trusted root private key, the first ciphertext, and the second ciphertext. The method further includes: Obtain the SK corresponding to the AK; Obtaining first authentication challenge information based on the SK and the access request; The first authentication challenge information is sent to the host, so that the host obtains the second authentication challenge information based on the first authentication challenge information and the first environment attribute information.

10. The method according to claim 9, wherein The determining whether to provide the first service to the virtual instance based on the authentication and authorization information and the AK includes: Based on the AK, obtaining the trusted root public key and the second environment attribute information associated with the AK; verifying the first signature confirmation information based on the trusted root public key, the first ciphertext, and the second ciphertext; When the first signature confirmation information is verified to be successful, decrypting the first ciphertext based on the public key of the server to obtain the one-time key; decrypting the second ciphertext based on the one-time key to obtain the second authentication challenge information; authenticating the identity of the virtual instance based on the first authentication challenge information, the second environment attribute information, and the second authentication challenge information; When the identity is verified to be legitimate, it is determined to provide the first service to the virtual instance.

11. The method according to claim 8, wherein The authentication and authorization information includes first signature information, the first environment attribute information, and second signature verification information, wherein the first signature information is obtained by the host based on the access request and the SK, and the second signature verification information is obtained by the host based on the trusted root private key and the first signature information; The determining whether to provide the first service to the virtual instance based on the authentication and authorization information and the AK includes: Based on the AK, obtaining the SK corresponding to the AK; Based on the AK, obtaining the trusted root public key and the second environment attribute information associated with the AK; When the first environment attribute information and the second environment attribute information are the same, verifying the second signature confirmation information based on the SK, the trusted root public key and the first signature information; When the second signature confirmation information is verified to be successful, it is determined to provide the first service to the virtual instance.

12. The method according to claim 7, wherein The private access credential is an access credential accesstocken, the private access credential identifier is a user identifier corresponding to the accesstocken, the accesstocken includes the user identifier, the authentication authorization information includes a third ciphertext, the third ciphertext is obtained by the host encrypting the accesstocken and third signature confirmation information based on the public key of the server, and the third signature confirmation information is obtained by the host signing and confirming the first environment attribute information based on the trusted root private key; The determining whether to provide the first service to the virtual instance based on the authentication and authorization information and the AK includes: Decrypting the third ciphertext based on the private key of the server to obtain the access token and the third signature confirmation information; Based on the user identifier included in the access token, obtaining the trusted root public key and the second environment attribute information associated with the user identifier; decrypting the third signature confirmation information based on the trusted root public key to obtain the first environment attribute information; When the first environment attribute information and the second environment attribute information are the same, it is determined to provide the first service to the virtual instance.

13. The method according to any one of claims 7 to 12, wherein: The first environmental attribute information includes one or more of the following: the service account of the virtual instance, the architecture information of the host, the size of the memory space of the virtual instance, the identification information of the virtual instance, the kernel identification information associated with the virtual instance, the time information of starting the virtual instance, the dedicated address of the virtual instance, the identification information of the disk associated with the virtual instance, or the partition running the virtual instance.

14. A device for requesting a service, characterized in that: The method comprises a module or a unit for executing the method according to any one of claims 1 to 6.

15. A device for requesting a service, characterized in that: The method comprises a module or a unit for executing the method according to any one of claims 7 to 13.

16. A device for requesting a service, characterized in that: The device comprises a memory and one or more processors, wherein the memory is used to store a computer program; the one or more processors are used to execute the computer program in the memory, so that the device performs the method according to any one of claims 1 to 6.

17. A device for requesting a service, characterized in that: The device comprises a memory and one or more processors, wherein the memory is used to store a computer program; the one or more processors are used to call the computer program in the memory, so that the device executes the method according to any one of claims 7 to 13.

18. A system for requesting services, characterized in that: The system comprises the apparatus according to claim 14 or 16 and the apparatus according to claim 15 or 17.

19. A computer-readable storage medium, characterized in that The storage medium stores a computer program or instruction. When the computer program or instruction is executed by a computer, the method according to any one of claims 1 to 6 or the method according to any one of claims 7 to 13 is implemented.

20. A computer program product, characterized in that When a computer reads and executes the computer program product, the computer is caused to execute the method according to any one of claims 1 to 6 or the method according to any one of claims 7 to 13.