Equipment service management method and device, equipment, medium and product
By generating device verification service requests and combining device signature certificates and digital signatures for device authentication, the problem of difficulty in timely detection of anomalies in existing device management methods is solved, and efficient and accurate management of device security control and service verification is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-12
- Publication Date
- 2026-03-13
AI Technical Summary
Existing equipment management methods are unable to detect in a timely manner issues such as malicious copying or replacement of equipment, data copying, and digital signature cracking. Furthermore, the management process is cumbersome and makes it difficult to improve the security control capabilities of equipment and the efficiency and accuracy of service verification.
The system generates a device verification service request, verifies the device using the device signature certificate and digital signature, generates a device authentication result, executes a device data service request based on the authentication result, and performs authentication management by combining static and dynamic device parameters.
It improved the safety management capabilities of the equipment, enhanced the efficiency and accuracy of equipment service verification, and ensured the authenticity of the equipment and the integrity of the operation process.
Smart Images

Figure CN121664533A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of equipment certification management technology, and in particular to an equipment service management method, apparatus, equipment, medium and product. Background Technology
[0002] With the continuous development of science and technology, the types and quantities of system equipment in enterprises are constantly increasing, leading to a growing management pressure on enterprises. At the same time, this also results in an increasing number of issues related to the copying or unauthorized replacement of equipment in key core systems.
[0003] Existing equipment management methods typically rely on deployed monitoring tools to monitor the online status and hardware parameters of devices in real time. When offline status or sudden changes in hardware parameters are detected, an anomaly is identified, and information about the abnormal device is reported. Alternatively, periodic on-site inspections can be conducted, and the device information is compared with the information stored in the management system to ensure consistency. In other words, existing equipment management methods depend heavily on the encryption and verification of static device data. This makes it difficult to detect anomalies in a timely manner when devices are maliciously copied or replaced, and it also makes it difficult to address issues such as data copying and digital signature cracking. Furthermore, false alarms occur during network outages and normal downtime, and the management process relies on regulations and personnel authorization, which is not only cumbersome but also makes it difficult to detect and prevent internal leaks in a timely manner.
[0004] Therefore, how to improve the safety management and control capabilities of equipment, and enhance the efficiency and accuracy of service verification of equipment to ensure the authenticity of equipment and the integrity of the operation process has become an urgent problem to be solved by those skilled in the art. Summary of the Invention
[0005] This invention provides a method, apparatus, equipment, medium, and product for equipment service management, in order to improve the safety control capabilities of equipment, enhance the efficiency and accuracy of equipment service verification, and ensure the authenticity of equipment and the integrity of the operation process.
[0006] According to one aspect of the present invention, a device service management method is provided, applied to a data service device, comprising:
[0007] In response to a device data service request for the target service initiating device, the first device configuration parameters of the target service initiating device and its corresponding first device digital signature and device signature certificate are determined.
[0008] Based on the device signature certificate, a device verification service request is generated for the device initiating the target service.
[0009] The device verification service request is sent to the verification service device, so that the verification service device can perform device verification on the target service initiating device based on the device verification service request, generate and return the first device verification result;
[0010] If the verification result of the first device is successful, then a device authentication result for the target service initiating device is generated based on the configuration parameters of the first device and the digital signature of the first device.
[0011] Based on the device authentication result, execute the device data service request of the target service initiating device to realize device service management of the target service initiating device.
[0012] According to another aspect of the present invention, a device service management method is provided, applied to a verification service device, comprising:
[0013] The system obtains a device verification service request sent by a data service device, determines the second device configuration parameters of the data service device and its corresponding second device digital signature, and determines the device signature certificate of the target service initiating device.
[0014] Based on the second device configuration parameters and the second device digital signature, a second device verification result for the data service device is generated.
[0015] If the verification result of the second device is successful, then the device signing certificate is decrypted according to the certificate center public key to generate a certificate verification result for the device signing certificate;
[0016] Based on the certificate verification result, a first device verification result is generated for the device initiating the target service;
[0017] The first device verification result is fed back to the data service device, so that the data service device can perform device authentication on the target service initiating device based on the first device verification result, and execute the device data service request for the target service initiating device based on the device authentication result, thereby realizing device service management for the target service initiating device.
[0018] According to another aspect of the present invention, a device service management apparatus is provided, configured in a data service device, comprising:
[0019] The request and response module is used to respond to a device data service request from the target service initiating device and determine the first device configuration parameters of the target service initiating device and its corresponding first device digital signature and device signature certificate.
[0020] The verification request generation module is used to generate a device verification service request for the target service initiating device based on the device signature certificate.
[0021] The verification request sending module is used to send the device verification service request to the verification service device, so that the verification service device can perform device verification on the target service initiating device based on the device verification service request, generate and return a first device verification result;
[0022] The device authentication module is used to generate a device authentication result for the target service initiating device based on the configuration parameters of the first device and the digital signature of the first device if the first device authentication result is successful.
[0023] The request execution module is used to execute the device data service request of the target service initiating device according to the device authentication result, so as to realize device service management of the target service initiating device.
[0024] According to another aspect of the present invention, a device service management apparatus is provided, configured in a verification service device, comprising:
[0025] The verification request receiving module is used to obtain the device verification service request sent by the data service device, determine the second device configuration parameters of the data service device and its corresponding second device digital signature, and determine the device signature certificate of the target service initiating device.
[0026] The verification result generation module is used to generate a second device verification result for the data service device based on the second device configuration parameters and the second device digital signature;
[0027] The certificate verification module is used to decrypt the device signing certificate based on the certificate center's public key and generate a certificate verification result for the device signing certificate if the verification result of the second device is successful.
[0028] The device verification module is used to generate a first device verification result for the device initiating the target service based on the certificate verification result.
[0029] The verification result sending module is used to send the verification result of the first device back to the data service device, so that the data service device can perform device authentication on the target service initiating device according to the verification result of the first device, and execute the device data service request for the target initiating device according to the device authentication result, thereby realizing device service management of the target service initiating device.
[0030] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising: at least one processor; and
[0031] A memory communicatively connected to the at least one processor; wherein,
[0032] The memory stores a computer program that can be executed by the at least one processor, the computer program being executed by the at least one processor to enable the at least one processor to perform the device service management method according to any embodiment of the present invention.
[0033] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the device service management method according to any embodiment of the present invention.
[0034] According to another aspect of the present invention, a computer program product is provided, the computer program product comprising a computer program that, when executed by a processor, implements the device service management method described in any embodiment of the present invention.
[0035] The technical solution of this embodiment of the invention, in response to a device data service request for a target service initiating device, determines the first device configuration parameters of the target service initiating device and its corresponding first device digital signature and device signature certificate; generates a device verification service request for the target service initiating device based on the device signature certificate; sends the device verification service request to a verification service device, so that the verification service device can perform device verification on the target service initiating device based on the device verification service request, generate and return a first device verification result; if the first device verification result is successful, generates a device authentication result for the target service initiating device based on the first device configuration parameters and the first device digital signature; and executes the device data service request for the target service initiating device based on the device authentication result, thereby realizing device service management for the target service initiating device. This embodiment of the solution can generate a device verification service request for the target service initiating device based on the first device configuration parameters, the first device digital signature, and the device signature certificate of the target service initiating device, and obtain a first device verification result for the target service initiating device. Then, based on the first device verification result, it determines a device authentication result for the target service initiating device, thereby realizing device service management for the target service initiating device. By obtaining the static and dynamic device parameters of the target service initiating device and combining them with the device signature certificate, device authentication management of the target service initiating device can be achieved. This improves the security control capability of the target device, enhances the efficiency and accuracy of service verification of the device, and ensures the authenticity of the device and the integrity of the operation process.
[0036] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0037] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0038] Figure 1 This is a flowchart of a device service management method provided according to Embodiment 1 of the present invention;
[0039] Figure 2 This is a flowchart of a device service management method according to Embodiment 2 of the present invention;
[0040] Figure 3 This is a schematic diagram of the structure of an equipment service management device according to Embodiment 3 of the present invention;
[0041] Figure 4 This is a schematic diagram of the structure of an equipment service management device according to Embodiment 4 of the present invention;
[0042] Figure 5 This is a schematic diagram of the structure of an electronic device that implements the device service management method of this invention. Detailed Implementation
[0043] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0044] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover a non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0045] Example 1
[0046] Figure 1 This is a flowchart of a device service management method provided in Embodiment 1 of the present invention. This embodiment is applicable to situations where data devices have poor security management capabilities and low efficiency and accuracy in verifying device services during operation. This method can be executed by a device service management device, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 1 As shown, this method is applied to a data service device, including:
[0047] S110. In response to the device data service request for the target service initiating device, determine the first device configuration parameters of the target service initiating device and its corresponding first device digital signature and device signature certificate.
[0048] The first device configuration parameters can include static and dynamic parameters. Specifically, they can be parameter information generated by hashing the static and dynamic parameters of the target service initiating device. Static parameters can be inherent and unchanged attributes of the device, such as MAC (Media Access Control Address), electronic serial number, device model, CPU (Central Processing Unit) model, and device size. Dynamic parameters can be indicators that change with the device's operating status, reflecting its real-time operating status, such as CPU utilization, memory usage, disk utilization, bandwidth utilization, and CPU temperature.
[0049] The first device digital signature can be a unique identifier used to verify the device identity information of the target service initiating device. Specifically, it can be obtained by encrypting the first device configuration parameters of the target service initiating device using its private key. The device signature certificate can be a data certificate used to verify that the device identity information is trustworthy and has not been tampered with. Specifically, it can be generated by sending the target service initiating device's public key to a certificate management center and encrypting the public key using the certificate management center's private key. Specifically, when the data service device responds to a received device data service request from the target service initiating device, it determines the target service initiating device's device configuration parameters, the device digital signature generated after encrypting the device configuration parameters using its private key, and the target service initiating device's device signature certificate.
[0050] Optionally, before determining the first device configuration parameters of the target service initiating device and its corresponding first device digital signature and device signature certificate in response to the device data service request initiated by the target service initiating device, the method further includes: determining the device identifier of the service initiating device based on the request parsing result of the obtained device data service request of the service initiating device; determining whether the service initiating device meets the pre-set device service management requirements based on the device identifier; if so, identifying the service initiating device as the target service initiating device and generating a first data acquisition request for the service initiating device; sending the first data acquisition request to the service initiating device so that the service initiating device can generate the first device configuration parameters and the first device digital signature based on the first data acquisition request, and obtain the device signature certificate for feedback.
[0051] The device identifier can be a unique identifier used to determine the device's identity information. Further, determining whether the service-initiating device meets the pre-defined device service management requirements can specifically involve determining whether the service-initiating device is an enhanced security authentication device. An enhanced security authentication device can refer to a service-initiating device that requires additional equipment for signature verification and identity information verification; this can be pre-defined by technical personnel based on actual needs.
[0052] For example, if there are device 1 and device 2, when device 1 initiates a device data service request to device 2, the device identifier A of device 1 can be determined by parsing the request. Then, based on device identifier A, it can be determined whether device 1 is an enhanced security authentication device, that is, whether device 1 meets the pre-set device service management requirements. Furthermore, if device identifier A determines that device 1 is an enhanced security authentication device, then when device 1 initiates a device data service request to device 2, an additional device 3 will be used to verify the device signature and identity information of device 1. This embodiment does not impose specific limitations on this.
[0053] Specifically, a data acquisition request generated by the data service device enables the service-initiating device to acquire its own static and dynamic device parameters. These acquired parameters are then hashed to obtain the first device configuration parameters. During the acquisition of these parameters, the obtained static and dynamic parameters are not pre-defined between the data service device and the service-initiating device. Instead, at least one parameter is randomly selected from a pre-defined list of static and dynamic parameters to serve as the first device configuration parameter. Furthermore, the service-initiating device can encrypt the first device configuration parameters using its private key to obtain a first device digital signature. The first device configuration parameters, the first device digital signature, and the device certificate are then sent to the data service device.
[0054] S120. Based on the device signature certificate, generate a device verification service request for the target service initiating device.
[0055] Specifically, the device verification service request can be an operation request generated by the data service device to enhance the authentication of the enhanced security authentication device. Specifically, when the data service device receives a device data service request from the target service initiating device and determines that the target service initiating device is an enhanced security authentication device, it can generate a device verification service request for the target service initiating device based on the device signature certificate of the target service initiating device, thereby enhancing the authentication of the device identity information of the target service initiating device.
[0056] S130. Send the device verification service request to the verification service device so that the verification service device can perform device verification on the target service initiating device based on the device verification service request, generate and return the first device verification result.
[0057] Specifically, the first device verification result can be the verification service device verifying the device signature certificate of the target service initiating device to obtain a verification result for the device identity information of the target service initiating device. Specifically, the data service device generates a verification request for the device identity information of the target service initiating device based on the device data service request of the target service initiating device, and sends the device verification service request to the verification service device to verify the device identity information of the target service initiating device, determining whether the device information of the target service initiating device meets the pre-set device identity information verification conditions. Specifically, this can involve determining whether the device signature certificate of the target service initiating device is valid, and generating a first device verification result for the target service initiating device based on the valid verification result of the device signature certificate.
[0058] S140. If the verification result of the first device is successful, then generate the device authentication result for the target service initiating device based on the configuration parameters of the first device and the digital signature of the first device.
[0059] Specifically, when the verification service device determines that the device signature certificate of the target service initiating device is valid, i.e., the first device verification result for the target service initiating device is successful, the data service device verifies the device identity information of the target service initiating device based on the first device configuration parameters and the first device digital signature. Specifically, this can involve comparing the first device configuration parameters and the first device digital signature for consistency, obtaining a consistency comparison result, and generating a device authentication result for the target service initiating device based on the consistency comparison result.
[0060] Optionally, based on the first device configuration parameters and the first device digital signature, a device authentication result for the target service initiating device is generated, including: obtaining the first device public key of the target service initiating device; decrypting the first device digital signature based on the first device public key to obtain the first device authentication parameters of the target service initiating device; performing a consistency comparison between the first device authentication parameters and the first device configuration parameters to obtain a consistency comparison result; and generating a device authentication result for the target service initiating device based on the consistency comparison result.
[0061] The first device authentication parameter can be parameter information used to prove the device identity information of the target service initiating device. Specifically, it can be obtained by decrypting the device signature certificate of the target service initiating device to obtain the device public key of the target service initiating device, and then using the device public key to decrypt the first device digital signature to obtain the first device authentication parameter of the target service initiating device. The first device authentication parameter and the first device configuration parameter are compared for consistency to obtain the consistency comparison result. It should be noted that the first device digital signature can be generated by encrypting the first device configuration parameter using the device private key of the target service initiating device. When the data service device needs to authenticate the device identity information of the target service initiating device, it can use the device public key published by the target service initiating device to decrypt the first device digital signature to obtain the first device authentication parameter for the target service initiating device. Furthermore, if the consistency comparison result between the first device authentication parameter and the first device configuration parameter is the same, the device authentication result for the target service initiating device can be determined to be successful; if the consistency comparison result is different, the device authentication result for the target service initiating device can be determined to be unsuccessful.
[0062] S150. Based on the device authentication result, execute the device data service request of the target service initiating device to realize device service management of the target service initiating device.
[0063] Specifically, if the device authentication result is successful, it can be determined that the device information of the target service initiating device is legitimate and the device is functioning normally, and the data service device will execute the device data service request from the target service initiating device. Furthermore, if the device authentication result is unsuccessful, it can be determined that the device information of the target service initiating device has been tampered with or forged, and the device information of the target service initiating device is deemed to be abnormal, thus rejecting the device data service request from the target service initiating device.
[0064] The technical solution of this embodiment of the invention, in response to a device data service request for a target service initiating device, determines the first device configuration parameters of the target service initiating device and its corresponding first device digital signature and device signature certificate; generates a device verification service request for the target service initiating device based on the device signature certificate; sends the device verification service request to a verification service device, so that the verification service device can perform device verification on the target service initiating device based on the device verification service request, generate and return a first device verification result; if the first device verification result is successful, generates a device authentication result for the target service initiating device based on the first device configuration parameters and the first device digital signature; and executes the device data service request for the target service initiating device based on the device authentication result, thereby realizing device service management for the target service initiating device. This embodiment of the solution can generate a device verification service request for the target service initiating device based on the first device configuration parameters, the first device digital signature, and the device signature certificate of the target service initiating device, and obtain a first device verification result for the target service initiating device. Then, based on the first device verification result, it determines a device authentication result for the target service initiating device, thereby realizing device service management for the target service initiating device. By obtaining the static and dynamic device parameters of the target service initiating device and combining them with the device signature certificate, device authentication management of the target service initiating device can be achieved. This improves the security control capabilities of the target service initiating device, enhances the efficiency and accuracy of service verification of the device, and ensures the authenticity of the device and the integrity of the operation process.
[0065] Example 2
[0066] Figure 2 This is a flowchart of a device service management method provided in Embodiment 2 of the present invention. This embodiment is applicable to situations where data devices have poor security management capabilities and low efficiency and accuracy in verifying device services during operation. This method can be executed by a device service management device, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 2 As shown, this method is applied to a verification service device, including:
[0067] S210. Obtain the device verification service request sent by the data service device, determine the second device configuration parameters of the data service device and its corresponding second device digital signature, and determine the device signature certificate of the target service initiating device.
[0068] The second device configuration parameters can be parameter information generated by hashing the static and dynamic parameters of the data service device. The second device digital signature is a unique identifier used to verify the device identity of the data service device; specifically, it can be obtained by encrypting the second device configuration parameters using the data service device's private key. Specifically, when the verification service device receives a device verification service request from the data service device for the target service initiating device, it can determine the second device configuration parameters and the second device digital signature of the data service device, as well as the device signature certificate of the target service initiating device.
[0069] Specifically, determining the second device configuration parameters of the data service device and its corresponding second device digital signature, as well as determining the device signature certificate of the target service initiating device, can involve generating a second data acquisition request for the data service device based on the device verification service request sent by the data service device, and sending the second data acquisition request to the data service device so that the data service device can generate the second device configuration parameters and the second device digital signature based on the second data acquisition request, and embedding the device signature certificate of the target service initiating device into the second device digital signature for feedback.
[0070] Specifically, the data service device can obtain its own static and dynamic parameters through a data acquisition request generated by the verification service device. The acquired static and dynamic parameters are then hashed to obtain second device configuration parameters. During the acquisition of its own static and dynamic parameters, the data service device does not use pre-defined parameters between the verification service device and the data service device. Instead, it randomly selects at least one parameter from a pre-defined list of static and dynamic parameters and uses it as the second device configuration parameter. Furthermore, the data service device can encrypt the second device configuration parameter using its own device private key to obtain a second device digital signature. This second device digital signature is then embedded with the device signature certificate of the target service initiating device and sent to the verification service device.
[0071] S220. Based on the configuration parameters of the second device and the digital signature of the second device, generate the second device verification result for the data service device.
[0072] Specifically, the verification service device can verify the device identity information of the data service device based on the second device configuration parameters and the second device digital signature to determine whether the device information of the data service device is correct. Specifically, this can involve comparing the second device configuration parameters and the second device digital signature for consistency, obtaining a consistency comparison result, and generating a verification result for the device identity information of the data service device based on the consistency comparison result.
[0073] Optionally, based on the second device configuration parameters and the second device digital signature, a second device verification result for the data service device is generated, including: determining the second device public key of the data service device; decrypting the second device digital signature based on the second device public key to obtain the second device authentication parameters for the data service device; comparing the second device authentication parameters and the second device configuration parameters for consistency to obtain a consistency comparison result; and generating the second device verification result for the data service device based on the consistency comparison result.
[0074] The second device authentication parameters can be parameters used to prove the device identity of the data service device. Specifically, the second device digital signature can be decrypted using the data service device's public key to obtain the second device authentication parameters for the target service initiating device. The second device authentication parameters and the second device configuration parameters are then compared for consistency to obtain a result. It should be noted that the second device digital signature can be generated by encrypting the second device configuration parameters using the data service device's private key. When the verification service device needs to verify the data service device's device identity, it can decrypt the second device digital signature using the data service device's published public key to obtain the second device authentication parameters for the target service initiating device. The second device authentication parameters and the second device configuration parameters are then compared for consistency. If the consistency comparison result is the same, the second device verification of the data service device is considered successful; if the consistency comparison result is different, the second device verification of the data service device is considered unsuccessful.
[0075] S230. If the verification result of the second device is successful, the device signing certificate is decrypted according to the certificate center's public key to generate a certificate verification result for the device signing certificate.
[0076] The certificate center's public key can be a publicly shareable key from the signing device publishing center. Specifically, it can be used to encrypt device signing certificates and verify their validity. If the second device's authentication parameters and configuration parameters are consistent, meaning the second device verification result for the data service device is successful, the certificate center's public key can be used to decrypt the target service initiating device's device signing certificate. This yields the certificate verification result for the target service initiating device's device signing certificate, determining its legitimacy and immutability.
[0077] S240. Based on the certificate verification result, generate the first device verification result for the device initiating the target service.
[0078] Specifically, based on the verification result of the device signature certificate of the device initiating the target service, if the verification result of the device signature certificate of the device initiating the target service is successful, a first device verification result of successful verification of the device initiating the target service can be generated; if the verification result is unsuccessful, a first device verification result of unsuccessful verification of the device initiating the target service can be generated.
[0079] S250. The first device verification result is fed back to the data service device so that the data service device can perform device authentication on the target service initiating device based on the first device verification result, and execute the device data service request on the target initiating device based on the device authentication result, thereby realizing device service management on the target service initiating device.
[0080] Specifically, the verification service device can send the first device verification result of the target service initiating device to the data service device, enabling the data service device to perform device authentication operations on the target service initiating device based on the first device verification result. Specifically, if the verification result of the device signature certificate of the target service initiating device is successful (i.e., the first device verification result is successful), then device authentication is performed on the target data service device, and if the device authentication result of the target service initiating device is successful, the device data service request for the target service initiating device is executed. Furthermore, if the verification result of the device signature certificate of the target service initiating device is unsuccessful (i.e., the first device verification result is unsuccessful), then device authentication is not required for the target data service device, and the device data service request for the target service initiating device is rejected.
[0081] The technical solution of this embodiment of the invention can determine the second device configuration parameters and their corresponding second device digital signature of the data service device, and determine the device signature certificate of the target service initiating device, by obtaining the device verification service request sent by the data service device; generate a second device verification result for the data service device based on the second device configuration parameters and the second device digital signature; if the second device verification result is successful, decrypt the device signature certificate based on the certificate center's public key to generate a certificate verification result for the device signature certificate; generate a first device verification result for the target service initiating device based on the certificate verification result; and feed the first device verification result back to the data service device so that the data service device can perform device authentication on the target service initiating device based on the first device verification result, and execute a device data service request for the target initiating device based on the device authentication result, thereby realizing device service management for the target service initiating device. In this embodiment, the second device verification result for the data service device can be determined based on the second device configuration parameters and the second device digital signature of the data service device, and the device signature certificate of the target data service device can be verified using this result to generate a first device verification result for the target service initiating device and feed it back to the data service device. By obtaining the static and dynamic device parameters of the data service device and combining them with the device signature certificate of the target service initiating device, secondary device authentication of the target service initiating device can be performed. This improves the security control capabilities of the target service initiating device, enhances the efficiency and accuracy of service verification of the device, and ensures the authenticity of the device and the integrity of the operation process.
[0082] Example 3
[0083] Figure 3 This is a schematic diagram of a device service management apparatus provided in Embodiment 3 of the present invention. The device service management apparatus provided in this embodiment of the present invention is applicable to situations where data devices have poor security management capabilities and low verification efficiency and accuracy of device services during operation. This device service management apparatus can be implemented in hardware and / or software, such as... Figure 3 As shown, the device is configured in a data service device and includes: a request response module 310, a verification request generation module 320, a verification request sending module 330, a device authentication module 340, and a request execution module 350. Among them,
[0084] Request response module 310 is used to respond to a device data service request for the target service initiating device and determine the first device configuration parameters of the target service initiating device and its corresponding first device digital signature and device signature certificate.
[0085] The verification request generation module 320 is used to generate a device verification service request for the target service initiating device based on the device signature certificate.
[0086] The verification request sending module 330 is used to send the device verification service request to the verification service device, so that the verification service device can perform device verification on the target service initiating device based on the device verification service request, generate and return the first device verification result;
[0087] The device authentication module 340 is used to generate a device authentication result for the target service initiating device based on the configuration parameters of the first device and the digital signature of the first device if the first device authentication result is successful.
[0088] The request execution module 350 is used to execute the device data service request of the target service initiating device according to the device authentication result, so as to realize device service management of the target service initiating device.
[0089] This solution generates a device verification service request for the target service initiating device based on its initial device configuration parameters, digital signature, and device signature certificate, and obtains the initial device verification result. Then, based on the initial device verification result, it determines the device authentication result for the target service initiating device, thereby achieving device service management. By obtaining the static and dynamic device parameters of the target service initiating device and combining them with the device signature certificate, device authentication management of the target service initiating device is achieved, improving the security control capabilities of the target service initiating device and enhancing the efficiency and accuracy of device service verification, ensuring the authenticity of the device and the integrity of the operation process.
[0090] Optionally, the device authentication module 340 is specifically used to obtain the first device public key of the target service initiating device;
[0091] Based on the public key of the first device, the digital signature of the first device is decrypted to obtain the first device authentication parameters of the target service initiating device;
[0092] The consistency comparison between the first device authentication parameters and the first device configuration parameters is performed to obtain the consistency comparison result.
[0093] Based on the consistency comparison result, a device authentication result for the target service initiating device is generated.
[0094] Optionally, the device may also include:
[0095] The device identification module is used to determine the device identifier of the service initiating device based on the request parsing result of the obtained device data service request of the service initiating device before determining the first device configuration parameters of the target service initiating device and its corresponding first device digital signature and device signature certificate in response to the device data service request initiated by the target service initiating device.
[0096] Based on the device identifier, determine whether the service initiating device meets the pre-defined device service management requirements;
[0097] If so, the service initiating device is identified as the target service initiating device, and a first data acquisition request is generated for the service initiating device;
[0098] The first data acquisition request is sent to the service initiating device, so that the service initiating device can generate the first device configuration parameters and the first device digital signature according to the first data acquisition request, and obtain the device signature certificate for feedback.
[0099] The device service management device provided in the embodiments of the present invention can execute the device service management method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.
[0100] Example 4
[0101] Figure 4 This is a schematic diagram of a device service management apparatus provided in Embodiment 3 of the present invention. The device service management apparatus provided in this embodiment of the present invention is applicable to situations where data devices have poor security management capabilities and low verification efficiency and accuracy of device services during operation. This device service management apparatus can be implemented in hardware and / or software, such as... Figure 4 As shown, the device is configured in the verification service equipment and includes: a verification request receiving module 410, a verification result generation module 420, a certificate verification module 430, a device verification module 440, and a verification result sending module 450. Among them,
[0102] The verification request receiving module 410 is used to obtain the device verification service request sent by the data service device, determine the second device configuration parameters of the data service device and its corresponding second device digital signature, and determine the device signature certificate of the target service initiating device.
[0103] The verification result generation module 420 is used to generate a second device verification result for the data service device based on the second device configuration parameters and the second device digital signature;
[0104] The certificate verification module 430 is used to decrypt the device signing certificate according to the certificate center public key and generate a certificate verification result for the device signing certificate if the verification result of the second device is successful.
[0105] The device verification module 440 is used to generate a first device verification result for the device initiating the target service based on the certificate verification result;
[0106] The verification result sending module 450 is used to send the first device verification result back to the data service device, so that the data service device can perform device authentication on the target service initiating device according to the first device verification result, and execute the device data service request for the target initiating device according to the device authentication result, thereby realizing device service management for the target service initiating device.
[0107] This solution can determine the second device verification result of the data service device based on its second device configuration parameters and second device digital signature. This result is then used to verify the device signature certificate of the target data service device, generating a first device verification result for the target service initiating device and feeding it back to the data service device. By obtaining the static and dynamic device parameters of the data service device and combining them with the device signature certificate of the target service initiating device, secondary device authentication of the target service initiating device can be performed. This improves the security control capabilities of the target service initiating device, enhances the efficiency and accuracy of service verification, and ensures the authenticity of the device and the integrity of the operational process.
[0108] Optionally, the verification result generation module 420 is specifically used to determine the second device public key of the data service device;
[0109] Based on the second device public key, the digital signature of the second device is decrypted to obtain the second device authentication parameters for the data service device;
[0110] The consistency comparison between the second device authentication parameters and the second device configuration parameters is performed to obtain the consistency comparison result.
[0111] Based on the consistency comparison result, a second device verification result for the data service device is generated.
[0112] The device service management device provided in the embodiments of the present invention can execute the device service management method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects of executing the method.
[0113] Example 5
[0114] Figure 5A schematic diagram of an electronic device 50 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0115] like Figure 5 As shown, the electronic device 50 includes at least one processor 51 and a memory, such as a read-only memory (ROM) 52 or a random access memory (RAM) 53, communicatively connected to the at least one processor 51. The memory stores computer programs executable by the at least one processor. The processor 51 can perform various appropriate actions and processes based on the computer program stored in the ROM 52 or loaded from storage unit 58 into the RAM 53. The RAM 53 can also store various programs and data required for the operation of the electronic device 50. The processor 51, ROM 52, and RAM 53 are interconnected via a bus 54. An input / output (I / O) interface 55 is also connected to the bus 54.
[0116] Multiple components in electronic device 50 are connected to I / O interface 55, including: input unit 56, such as keyboard, mouse, etc.; output unit 57, such as various types of monitors, speakers, etc.; storage unit 58, such as disk, optical disk, etc.; and communication unit 59, such as network card, modem, wireless transceiver, etc. Communication unit 59 allows electronic device 50 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0117] Processor 51 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 51 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 51 performs the various methods and processes described above, such as device service management methods.
[0118] In some embodiments, the device service management method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 58. In some embodiments, part or all of the computer program may be loaded and / or installed on the electronic device 50 via ROM 52 and / or communication unit 59. When the computer program is loaded into RAM 53 and executed by processor 51, one or more steps of the device service management method described above may be performed. Alternatively, in other embodiments, processor 51 may be configured to perform the device service management method by any other suitable means (e.g., by means of firmware).
[0119] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0120] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0121] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0122] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0123] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or middleware components (e.g., application servers), or frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0124] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system. It addresses the shortcomings of traditional physical hosts and VPS (Virtual Private Server) services, such as high management difficulty and weak business scalability.
[0125] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0126] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A method for managing equipment services, characterized in that, Applications in data service equipment, including: In response to a device data service request for the target service initiating device, the first device configuration parameters of the target service initiating device and its corresponding first device digital signature and device signature certificate are determined. Based on the device signature certificate, a device verification service request is generated for the device initiating the target service. The device verification service request is sent to the verification service device, so that the verification service device can perform device verification on the target service initiating device based on the device verification service request, generate and return the first device verification result; If the verification result of the first device is successful, then a device authentication result for the target service initiating device is generated based on the configuration parameters of the first device and the digital signature of the first device. Based on the device authentication result, execute the device data service request of the target service initiating device to realize device service management of the target service initiating device.
2. The method according to claim 1, characterized in that, The step of generating a device authentication result for the target service initiating device based on the first device configuration parameters and the first device digital signature includes: Obtain the first public key of the target service initiating device; Based on the public key of the first device, the digital signature of the first device is decrypted to obtain the first device authentication parameters of the target service initiating device; The consistency comparison between the first device authentication parameters and the first device configuration parameters is performed to obtain the consistency comparison result. Based on the consistency comparison result, a device authentication result for the target service initiating device is generated.
3. The method according to claim 1, characterized in that, Before determining the first device configuration parameters of the target service initiating device and its corresponding first device digital signature and device signature certificate in response to a device data service request initiated by the target service initiating device, the method further includes: Based on the request parsing result of the obtained device data service request from the service initiating device, the device identifier of the service initiating device is determined; Based on the device identifier, determine whether the service initiating device meets the pre-defined device service management requirements; If so, the service initiating device is identified as the target service initiating device, and a first data acquisition request is generated for the service initiating device; The first data acquisition request is sent to the service initiating device, so that the service initiating device can generate the first device configuration parameters and the first device digital signature according to the first data acquisition request, and obtain the device signature certificate for feedback.
4. A method for equipment service management, characterized in that, Applied to verification service equipment, including: The system obtains a device verification service request sent by a data service device, determines the second device configuration parameters of the data service device and its corresponding second device digital signature, and determines the device signature certificate of the target service initiating device. Based on the second device configuration parameters and the second device digital signature, a second device verification result for the data service device is generated. If the verification result of the second device is successful, then the device signing certificate is decrypted according to the certificate center public key to generate a certificate verification result for the device signing certificate; Based on the certificate verification result, a first device verification result is generated for the device initiating the target service; The first device verification result is fed back to the data service device, so that the data service device can perform device authentication on the target service initiating device based on the first device verification result, and execute the device data service request for the target service initiating device based on the device authentication result, thereby realizing device service management for the target service initiating device.
5. The method according to claim 4, characterized in that, The step of generating a second device verification result for the data service device based on the second device configuration parameters and the second device digital signature includes: Determine the second public key of the data service device; Based on the second device public key, the digital signature of the second device is decrypted to obtain the second device authentication parameters for the data service device; The consistency comparison between the second device authentication parameters and the second device configuration parameters is performed to obtain the consistency comparison result. Based on the consistency comparison result, a second device verification result for the data service device is generated.
6. A device for managing equipment services, characterized in that, Configured in data service equipment, including: The request and response module is used to respond to a device data service request from the target service initiating device and determine the first device configuration parameters of the target service initiating device and its corresponding first device digital signature and device signature certificate. The verification request generation module is used to generate a device verification service request for the target service initiating device based on the device signature certificate. The verification request sending module is used to send the device verification service request to the verification service device, so that the verification service device can perform device verification on the target service initiating device based on the device verification service request, generate and return a first device verification result; The device authentication module is used to generate a device authentication result for the target service initiating device based on the configuration parameters of the first device and the digital signature of the first device if the first device authentication result is successful. The request execution module is used to execute the device data service request of the target service initiating device according to the device authentication result, so as to realize device service management of the target service initiating device.
7. An equipment service management device, characterized in that, Configured on the verification service equipment, including: The verification request receiving module is used to obtain the device verification service request sent by the data service device, determine the second device configuration parameters of the data service device and its corresponding second device digital signature, and determine the device signature certificate of the target service initiating device. The verification result generation module is used to generate a second device verification result for the data service device based on the second device configuration parameters and the second device digital signature; The certificate verification module is used to decrypt the device signing certificate based on the certificate center's public key and generate a certificate verification result for the device signing certificate if the verification result of the second device is successful. The device verification module is used to generate a first device verification result for the device initiating the target service based on the certificate verification result. The verification result sending module is used to send the verification result of the first device back to the data service device, so that the data service device can perform device authentication on the target service initiating device according to the verification result of the first device, and execute the device data service request for the target initiating device according to the device authentication result, thereby realizing device service management of the target service initiating device.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that is executed by the at least one processor to enable the at least one processor to perform the device service management method according to any one of claims 1-3 or 4-5.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the device service management method according to any one of claims 1-3 or 4-5.
10. A computer program product, characterized in that, The computer program product includes a computer program that, when executed by a processor, implements the device service management method according to any one of claims 1-3 or 4-5.