Signature method, device, equipment, storage medium and program product

CN122845110APending Publication Date: 2026-09-29ALIBABA CLOUD COMPUTING CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510377283.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-27
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

[0004]本申请的多个方面提供一种签名方法、装置、设备、存储介质及程序产品,用以解决相关技术中的签名方法的安全性较低的问题

Benefits of technology

[0048]本申请实施例提供一种签名方法、装置、设备、存储介质及程序产品,虚拟机可以向虚拟机对应的虚拟可信平台模块发送访问请求的签名请求,接收虚拟可信平台模块发送的消息认证码,向开放应用程序接口服务端发送使用消息认证码对访问请求签名后的信息。其中,访问请求为虚拟机中的应用程序请求访问开放应用程序接口的请求,消息认证码是基于应用程序对应的访问密钥秘钥生成的,访问密钥秘钥由云服务平台生成并发送给虚拟可信平台模块。由于访问密钥秘钥由云服务平台生成并发送给虚拟可信平台模块,且虚拟可信平台模块生成消息认证码的过程对外不可见,因此访问密钥秘钥全生命周期对用户不可见,避免访问密钥秘钥泄露,提高了签名方法的安全性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845110A_ABST
    Figure CN122845110A_ABST
Patent Text Reader

Abstract

The application provides a signature method, device, equipment, storage medium and program product, which are applied to a virtual machine. The method comprises the following steps: sending a signature request of an access request to a virtual trusted platform module corresponding to the virtual machine, wherein the access request is a request of an application program in the virtual machine for accessing an open application program interface; receiving a message authentication code sent by the virtual trusted platform module, wherein the message authentication code is generated based on an access key secret key corresponding to the application program, and the access key secret key is generated by a cloud service platform and sent to the virtual trusted platform module; and sending information in which the access request is signed by using the message authentication code to an open application program interface server. The security of the signature method is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of cloud computing, and more particularly to a signature method, apparatus, device, storage medium, and program product. Background Technology

[0002] An Open Application Programming Interface (OpenAPI) is a public, standardized interface that allows applications to access and integrate specific services or data. Cloud applications accessing OpenAPIs often employ an Access Key (AK) signature verification method. Users configure an obtained Access Key Secret (AK Secret) in their applications. The application uses the AK Secret to sign access requests to the OpenAPI, and the OpenAPI server uses the same AK Secret to verify the signature, thus validating the access request.

[0003] In the aforementioned signature methods, the AK Secret is visible to the user. During the process of copying, distributing, storing, and using the AK Secret, it is easily leaked, leading to security incidents such as identity theft and data breaches. Therefore, the signature methods in these technologies have relatively low security. Summary of the Invention

[0004] This application provides a signature method, apparatus, device, storage medium, and program product to address the problem of low security in signature methods in related technologies.

[0005] In a first aspect, embodiments of this application provide a signature method applied to a virtual machine, comprising:

[0006] A signature request for an access request is sent to the virtual trusted platform module corresponding to the virtual machine. The access request is a request from an application in the virtual machine to access the open application programming interface.

[0007] The system receives a message authentication code sent by the virtual trusted platform module. The message authentication code is generated based on the access key key corresponding to the application. The access key key is generated by the cloud service platform and sent to the virtual trusted platform module.

[0008] Send information to the Open Application Programming Interface (API) server after signing the access request using the message authentication code.

[0009] In one possible implementation, sending the signature request for the access request to the virtual trusted platform module corresponding to the virtual machine includes:

[0010] Based on the access key identifier corresponding to the application, obtain the index information of the access key key corresponding to the access key identifier from the virtual machine;

[0011] The signature request is sent to the virtual trusted platform module. The signature request includes the hash value of the access request, the index information, and the password corresponding to the access key identifier. The password is used to verify the signature request.

[0012] In one possible implementation, obtaining the index information of the access key key corresponding to the access key identifier from the virtual machine based on the access key identifier corresponding to the application includes:

[0013] Based on the access key identifier, obtain the corresponding index file from the shared file system of the virtual machine;

[0014] The index information is obtained from the index file.

[0015] In one possible implementation, prior to generating the access request, the method further includes:

[0016] Receive the access key identifier and the index information sent by the virtual trusted platform module;

[0017] An index file is generated in the shared file system. The file name of the index file is the access key identifier, and the index file includes the index information.

[0018] In one possible implementation, the virtual trusted platform module runs on an on-card microserver, which is located on the host machine where the virtual machine resides.

[0019] Secondly, embodiments of this application provide a signature method applied to a virtual trusted platform module, comprising:

[0020] Receive a signature request sent by a virtual machine, the signature request being used to request the generation of a signature for an access request, the access request being a request from an application in the virtual machine to access an open application programming interface;

[0021] A message authentication code is generated based on the access key corresponding to the application, and the message authentication code is sent to the virtual machine. The access key is generated by the cloud service platform and sent to the virtual trusted platform module.

[0022] In one possible implementation, the signature request includes the hash value of the access request, the index information of the access key key corresponding to the application, and the password corresponding to the access key identifier. The access key identifier corresponds to the application, and the password corresponding to the access key identifier is used to verify the signature request.

[0023] The generation of the message authentication code based on the access key secret key corresponding to the application includes:

[0024] In the storage space corresponding to the index information, find the access key and the password corresponding to the access key identifier in the storage space;

[0025] If the password in the storage space matches the password in the signature request, the message authentication code is generated based on the access key and the hash value of the access request.

[0026] In one possible implementation, before receiving the signature request sent by the virtual machine, the method further includes:

[0027] The system receives access key information sent by a cloud service platform. The access key information includes the access key key, the access key identifier, and the password corresponding to the access key identifier.

[0028] The access key and the password corresponding to the access key identifier are stored in the storage space, and the index information is generated according to the location information of the storage space.

[0029] The access key identifier and the index information are sent to the virtual machine.

[0030] Thirdly, embodiments of this application provide a signature method applied to a virtual trusted platform module, comprising:

[0031] In response to an access key generation request, access key information is generated, the access key information including an access key secret;

[0032] The access key information is sent to the virtual trusted platform module. The access key is used to generate a message authentication code. The access request is a request from an application in the virtual machine to access the open application programming interface.

[0033] In one possible implementation, the access key information further includes an access key identifier corresponding to the application and a password corresponding to the access key identifier. The password corresponding to the access key identifier is used to verify the signature request, and the signature request is used to request the generation of a signature for the access request.

[0034] Fourthly, embodiments of this application provide a signature device applied to a virtual machine. The device includes: a request signature module, a receiving module, and a request access module, wherein...

[0035] The request signature module is used to send a signature request for the access request to the virtual trusted platform module corresponding to the virtual machine. The access request is a request from the application in the virtual machine to access the open application interface.

[0036] The receiving module is used to receive a message authentication code sent by the virtual trusted platform module. The message authentication code is generated based on the access key key corresponding to the application. The access key key is generated by the cloud service platform and sent to the virtual trusted platform module.

[0037] The request access module is used to send information to the open application interface server after the access request has been signed using the message authentication code.

[0038] Fifthly, embodiments of this application provide a signature device applied to a virtual trusted platform module. The device includes a receiving module and a sending module, wherein...

[0039] The receiving module is used to receive a signature request sent by a virtual machine. The signature request is used to request a signature for an access request, which is a request from an application in the virtual machine to access an open application programming interface.

[0040] The sending module is used to generate a message authentication code based on the access key key corresponding to the application, and send the message authentication code to the virtual machine. The access key key is generated by the cloud service platform and sent to the virtual trusted platform module.

[0041] Sixthly, embodiments of this application provide a signature device applied to a cloud service platform. The device includes a response module and a sending module, wherein...

[0042] The response module is used to generate access key information in response to an access key generation request, the access key information including an access key secret.

[0043] The sending module is used to send the access key information to the virtual trusted platform module. The access key is used to generate a message authentication code. The access request is a request from an application in the virtual machine to access the open application programming interface.

[0044] In a seventh aspect, embodiments of this application provide an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor;

[0045] The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, cause the electronic device to perform the method described in any one of the first, second, or third aspects.

[0046] Eighthly, embodiments of this application provide a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, are used to implement the method described in any one of the first, second, or third aspects.

[0047] Ninthly, embodiments of this application provide a computer program product, including a computer program that, when executed by a processor, implements the method described in any one of the first, second, or third aspects.

[0048] This application provides a signature method, apparatus, device, storage medium, and program product. A virtual machine can send a signature request for an access request to a virtual trusted platform module corresponding to the virtual machine, receive a message authentication code sent by the virtual trusted platform module, and send information after signing the access request using the message authentication code to an open application interface server. The access request is a request from an application in the virtual machine to access the open application interface. The message authentication code is generated based on the access key corresponding to the application, which is generated by a cloud service platform and sent to the virtual trusted platform module. Because the access key is generated and sent to the virtual trusted platform module by the cloud service platform, and the process of the virtual trusted platform module generating the message authentication code is not visible to the outside world, the access key is invisible to the user throughout its entire lifecycle, preventing access key leakage and improving the security of the signature method. Attached Figure Description

[0049] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:

[0050] Figure 1 This is a schematic diagram of the access key-based signature process in related technologies;

[0051] Figure 2 A flowchart illustrating a signature method provided for an exemplary embodiment of this application. Figure 1 ;

[0052] Figure 3 A schematic diagram illustrating the communication process between a virtual machine and a VTPM, provided as an exemplary embodiment of this application;

[0053] Figure 4A schematic diagram illustrating a process for sending a signature request, provided as an exemplary embodiment of this application;

[0054] Figure 5 A flowchart illustrating a signature method provided for an exemplary embodiment of this application. Figure 2 ;

[0055] Figure 6 A flowchart illustrating a signature method provided for an exemplary embodiment of this application. Figure 3 ;

[0056] Figure 7 A flowchart illustrating a signature method provided for an exemplary embodiment of this application. Figure 4 ;

[0057] Figure 8 A flowchart illustrating a signature method provided for an exemplary embodiment of this application. Figure 5 ;

[0058] Figure 9 A schematic diagram of the structure of a first signature device provided for an exemplary embodiment of this application;

[0059] Figure 10 A schematic diagram of the structure of a second signature device provided as an exemplary embodiment of this application;

[0060] Figure 11 A schematic diagram of the structure of a third signature device provided as an exemplary embodiment of this application;

[0061] Figure 12 A schematic diagram of the structure of a fourth signature device provided as an exemplary embodiment of this application;

[0062] Figure 13 A schematic diagram of the structure of a fifth signature device provided as an exemplary embodiment of this application;

[0063] Figure 14 This is a schematic diagram of the structure of an electronic device provided as an exemplary embodiment of this application. Detailed Implementation

[0064] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of the relevant data must comply with relevant laws, regulations and standards, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0065] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of them. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0066] Below, in conjunction with Figure 1 The relevant technologies will be explained in detail.

[0067] Figure 1 This is a schematic diagram of the access key-based signature process in related technologies. Please refer to [link / reference]. Figure 1 In related technologies, users can obtain an Access Key Identity Document (AK ID) and an AK Secret, configure the AK ID and AK Secret in an application (APP) created in a virtual machine, and when the APP accesses the OpenAPI, the APP generates an access request to the OpenAPI, encrypts the access request according to the configured AK Secret, obtains a message authentication code, and further sends the access request, AK ID and message authentication code to the OpenAPI server for signature verification. If the OpenAPI server verifies the signature, the requesting application is allowed to access the OpenAPI service.

[0068] In related technologies, after obtaining the AK Secret, users can copy it to a location in the file system for storage and configure it for use by applications. They can also distribute the AK Secret to personnel or systems that need to use it. During the process of users copying, distributing, storing, and using the AK Secret, the AK Secret may be leaked, leading to security incidents such as identity theft and data leakage.

[0069] In summary, the security of signature methods in related technologies is relatively low.

[0070] To address the aforementioned issues, this application provides a signature method in which the Virtual Trusted Platform Module (VTPM) corresponding to the virtual machine implements the signature step of generating a message authentication code based on the AK Secret. The AK Secret is generated by a cloud service platform and sent to the VTPM. In this signature method, when a virtual machine application requests access to an OpenAPI, the virtual machine sends a signature request for the access request to the corresponding VTPM. The VTPM generates a message authentication code based on the AK Secret and sends the message authentication code to the virtual machine. The virtual machine then sends the access request, AK ID, and message authentication code to the OpenAPI server, thus signing the access request using the message authentication code. Since the AK Secret is generated by the cloud service platform and sent to the VTPM, and the process of the VTPM generating the message authentication code is not publicly visible, the AK Secret remains invisible to the user throughout its entire lifecycle, preventing AK Secret leakage and improving the security of the signature method.

[0071] The technical solutions shown in this application will now be described in detail through specific embodiments. It should be noted that the following embodiments may exist independently or in combination with each other; for identical or similar content, the description will not be repeated in different embodiments.

[0072] Below, in conjunction with Figure 2 This application describes a signature method for use in virtual machines.

[0073] Figure 2 A flowchart illustrating a signature method provided for an exemplary embodiment of this application. Figure 1 This signature method applies to virtual machines; please refer to [link / reference]. Figure 2 The methods may include:

[0074] S201. Send a signature request for the access request to the virtual trusted platform module corresponding to the virtual machine.

[0075] An access request is a request from an application in a virtual machine to access an OpenAPI. To access an OpenAPI, an application needs to send an access request to the OpenAPI server, requesting access to a specific resource. The OpenAPI server can then parse the requested resource from the received access request and provide the corresponding service to the application.

[0076] VTPM is the implementation of Trusted Platform Module (TPM) technology in a virtualized environment, providing functions such as secure storage, encrypted operations, and integrity verification. VTPM provides a virtualized TPM instance for each virtual machine through software emulation. Each virtual machine can be associated with a specific VTPM, and the corresponding virtual trusted platform module provides signature services for the virtual machine.

[0077] The access request signature request is a request used to request VTPM to sign the access request.

[0078] For example, a virtual machine can parse the interface specifications defined in the OpenAPI documentation and generate an access request conforming to the Hypertext Transfer Protocol (HTTP) based on the interface specifications of the application in the OpenAPI to be accessed. This access request may include a request method, a request Uniform Resource Locator (URL), request headers, and a request body.

[0079] After generating an access request, the virtual machine can send a signature request for the access request to the corresponding VTPM. For example, the virtual machine can perform a hash operation on the generated access request to obtain a hash value of the access request, and send the hash value of the access request to the corresponding VTPM to request the VTPM to sign the hash value of the access request.

[0080] Optionally, VTPM can run on a Micro Server on a Card (MOC). An MOC is a standalone hardware component plugged into a physical server, providing cloud disk read / write and virtual network access capabilities. VTPM can run on an MOC, and virtual machines communicate with the VTPM through the MOC.

[0081] S202, Receive the message authentication code sent by the virtual trusted platform module.

[0082] The message authentication code is generated based on the AK Secret corresponding to the application.

[0083] The AK Secret is generated by the cloud service platform and sent to VTPM. Each AK Secret corresponds to an AK ID, which is the user's identifier. The AK Secret verifies whether a user has permission to access resources.

[0084] During the access request signing process, VTPM can use the stored AK Secret corresponding to the application to sign the access request according to the encryption algorithm, thereby obtaining the access request signature, i.e., the message authentication code. The application is configured with an AK ID, and there is a one-to-one correspondence between the AK ID and the AK Secret. The AK Secret corresponding to the application refers to the AK Secret associated with the AK ID configured in the application.

[0085] Figure 3 This is a schematic diagram illustrating a communication process between a virtual machine and a VTPM, provided as an exemplary embodiment of this application. Please refer to... Figure 3 An application was created in the virtual machine. The MOC includes the VTPM corresponding to the virtual machine, and the VTPM stores the AK Secret.

[0086] For example, a virtual machine can generate an access request based on an application, send a signature request for the access request to the VTPM corresponding to the virtual machine, and receive a message authentication code sent by the VTPM. The message authentication code is obtained by the VTPM signing the access request based on the stored AKSecret.

[0087] S203. Send the information after signing the access request using a message authentication code to the open application programming interface server.

[0088] OpenAPI server refers to the application server that provides API services.

[0089] For example, a virtual machine can send information that has been signed with a message authentication code to the OpenAPI server, i.e., a signed access request, to request access to the resources of the Open API server.

[0090] Optionally, the OpenAPI server can verify whether the sender of the access request has permission to access the API resource based on the received signed access request.

[0091] For example, a signed access request includes a message authentication code, the access request itself, and an AK ID. The OpenAPI server can obtain the corresponding AK Secret based on the AK ID and use the AK Secret to sign the access request, thus obtaining a message authentication code for verification. If the message authentication code used for verification matches the message authentication code in the received signed access request, it is determined that the application of the virtual machine that generated the access request has the right to access the API resource, and the OpenAPI server provides services to that application. If the message authentication code used for verification does not match the message authentication code in the received signed access request, it is determined that the application does not have the right to access the API resource, and the OpenAPI server refuses to provide services.

[0092] In the technical solution of this application, the virtual machine can send a signature request for an access request to the VTPM corresponding to the virtual machine, receive a message authentication code sent by the VTPM, and send information after signing the access request with the message authentication code to the OpenAPI server. The access request is a request from an application in the virtual machine to access the OpenAPI. The message authentication code is generated based on the AK Secret corresponding to the application, and the AK Secret is generated and sent to the VTPM by the cloud service platform. Since the AK Secret is generated and sent to the VTPM by the cloud service platform, and the process of the VTPM generating the message authentication code is not visible to the outside world, the AK Secret is invisible to the user throughout its entire lifecycle, preventing AK Secret leakage and improving the security of the signature method.

[0093] Optionally, a signature request for the access request is sent to the VTPM corresponding to the virtual machine. The index information of the AK Secret corresponding to the AK ID can be obtained from the virtual machine based on the AK ID corresponding to the application. The signature request sent to the VTPM includes the hash value of the access request, the index information, and the password corresponding to the AK ID.

[0094] The password corresponding to the AK ID is used to verify the signature request. For example, there is a one-to-one correspondence between the password and the AK Secret. When the VTPM receives a signature request, it can determine whether the password of the AK Secret corresponding to the AK ID in the VTPM is consistent with the password in the signature request. If they are consistent, the VTPM responds to the signature request; if they are inconsistent, the VTPM does not respond to the signature request.

[0095] The index information of the AK Secret corresponding to the AK ID is the index information of the storage space storing the AK Secret corresponding to the AK ID in VTPM.

[0096] Figure 4 This is a schematic diagram illustrating a process for sending a signature request, provided as an exemplary embodiment of this application. Please refer to... Figure 4 The application pre-configures the AK ID and its corresponding password. In this case, the virtual machine can perform a hash operation on the access request used to access the OpenAPI to obtain the hash value of the access request, and obtain the index information of the AK Secret corresponding to the AK ID from the virtual machine. The password corresponding to the AK ID, the hash value of the access request, and the index information of the AK Secret corresponding to the AK ID are used as a signature request for the access request and sent to the VTPM corresponding to the virtual machine.

[0097] In the technical solution of this application, the virtual machine sends a signature request for the access request to the VTPM corresponding to the virtual machine. Based on the AK ID corresponding to the application, the index information of the AK Secret corresponding to the AK ID can be obtained from the virtual machine, and a signature request is sent to the VTPM. The signature request includes the hash value of the access request, the index information, and the password corresponding to the AK ID. The password corresponding to the AK ID is used to verify the signature request. During the signing process, the virtual machine sends the signature request for the access request to the VTPM and receives the message authentication code returned by the VTPM. The user only configures the AK ID and password to the virtual machine; the AK Secret is only visible in the VTPM, preventing AK Secret leakage. Furthermore, the signature request sent by the virtual machine to the VTPM includes the password corresponding to the AK ID, which can verify the signature request. If the password in the signature request matches the password in the VTPM, the VTPM responds to the signature request, improving the security of the signing method.

[0098] Optionally, before generating an access request, the virtual machine can also receive the AK ID and index information sent by VTPM. An index file is then generated in the shared file system; the index file name is the AK ID, and the index file includes index information.

[0099] For example, based on the AK ID corresponding to the application, the index information of the AK Secret corresponding to the AK ID is obtained from the virtual machine. Specifically, the corresponding index file can be obtained from the shared file system of the virtual machine based on the AK ID, and the index information can be obtained from the index file.

[0100] Figure 5 A flowchart illustrating a signature method provided for an exemplary embodiment of this application. Figure 2 Please see. Figure 5 When an AK is created, the AK service generates an AK ID, password, and AK Secret, and sends the AK Secret corresponding to the AK ID to the VTPM. The VTPM uses the index of the storage space that stores the AK Secret corresponding to the AK ID as index information and sends the AK ID and index information to the virtual machine. The virtual machine generates an index file with the AK ID as the filename in the virtual machine's shared file system and saves the index information in the index file.

[0101] After generating the access request, the virtual machine can perform a hash operation on the access request through the application to obtain the hash value of the access request. It then retrieves an index file from the virtual machine's shared file system, whose filename matches the AK ID in the application. The index information in the index file is the index information of the AK Secret corresponding to the AK ID. Furthermore, the virtual machine can use the password corresponding to the AK ID, the hash value of the access request, and the index information of the AK Secret corresponding to the AK ID as a signature request for the access request, and send it to the VTPM.

[0102] Optionally, the index file in the virtual machine's shared file system can be set to read-only permissions.

[0103] In the technical solution of this application, the virtual machine can obtain the corresponding index file from the virtual machine's shared file system according to the AK ID, and obtain the index information from the index file. Since the shared file system adopts multiple security mechanisms, storing the index information through the shared file system can improve the security of the index information during transmission and storage.

[0104] Below, in conjunction with Figure 6 This application describes a signature method for use in VTPM.

[0105] Figure 6 A flowchart illustrating a signature method provided for an exemplary embodiment of this application. Figure 3 Please see. Figure 6 The methods may include:

[0106] S601, Receive the signature request sent by the virtual machine.

[0107] A signature request is used to request the generation of a signature for an access request, which is a request from an application in the virtual machine to access an open application programming interface (API).

[0108] S602. Generate a message authentication code based on the access key corresponding to the application, and send the message authentication code to the virtual machine.

[0109] The message authentication code is the signature of the access request. The AK Secret is generated by the cloud service platform and sent to VTPM.

[0110] A message authentication code is generated based on the AK Secret corresponding to the application. For example, based on the AK Secret corresponding to the application, the access request is signed using a Hash-based Message Authentication Code (HMAC) algorithm to generate the message authentication code. HMAC is an encryption algorithm used to verify message integrity and identity legitimacy, as shown in equation (1):

[0111]

[0112] Where K is the AK Secret, m is the access request, H is the hash function, K' is the processed AK Secret with the same length as the block size of the hash function, ipad and opad are two fixed padding values: ipad is 0x363636...36 (0x36 per byte), and opad is 0x5C5C5C...5C (0x5C per byte). || represents a join operation. This indicates a bitwise XOR operation.

[0113] For example, VTPM can encrypt the access request in the signature request using the HMAC algorithm based on the AK Secret in the signature request, and generate a message authentication code.

[0114] It should be noted that, in Figure 6 The various processing steps (S601-S602) shown in the embodiments do not constitute a specific limitation on the signature process. In other embodiments of this application, the signature process may include... Figure 6 The embodiments may involve more or fewer steps. For example, the signing process may include... Figure 6 Some steps in the embodiments, or, Figure 6 Some steps in the embodiments can be replaced by steps with the same function, or Figure 6 Some steps in the embodiments can be broken down into multiple steps, etc.

[0115] In the technical solution of this application, the VTPM can receive a signature request sent by a virtual machine. The signature request is used to request the generation of a signature for the access request, generate a message authentication code based on the AK Secret corresponding to the application, and send the message authentication code to the virtual machine. The access key information includes the AK Secret, which is generated by the cloud service platform. The access request is a request from the application in the virtual machine to access the OpenAPI, and the AK Secret is generated by the cloud service platform and sent to the VTPM. Since the message authentication code is generated by the VTPM based on the AK Secret corresponding to the application, the process of the signature device generating the message authentication code is not visible to the outside world. Therefore, the AK Secret is only visible within the VTPM and is invisible to the user during the signature process, preventing AK Secret leakage and improving the security of the signature method.

[0116] Optionally, the signature request includes the hash value of the access request, the index information of the AK Secret corresponding to the application, and the password corresponding to the AK ID. The AK ID corresponds to the application, and the password corresponding to the AK ID is used to verify the signature request.

[0117] For example, to generate a message authentication code based on the AK Secret corresponding to the application, the password corresponding to the AK Secret and AK ID can be found in the storage space corresponding to the index information. If the password in the storage space matches the password in the signature request, the message authentication code is generated based on the AK Secret and the hash value of the access request.

[0118] Optionally, the access key information may include the AK Secret, AK ID, and the password corresponding to the AK ID. In this mode, the VTPM can receive the access key information sent by the cloud service platform, namely the AK ID, AK Secret, and the password corresponding to the AK ID. The AK Secret and the password corresponding to the AK ID are stored in the storage space, and index information is generated based on the location information of the storage space. The AK ID and the index information are then sent to the virtual machine.

[0119] In the technical solution of this application, VTPM can receive a signature request sent by a virtual machine, generate a message authentication code based on the AK Secret corresponding to the application, and send the message authentication code to the virtual machine. The signature request is used to request the generation of a signature for the access request. The signature request includes a password corresponding to the AK ID of the application. The password corresponding to the AK ID is used to verify the signature request. The access request is a request from the application in the virtual machine to access the OpenAPI. Since the message authentication code is generated by VTPM based on the AK Secret corresponding to the application, the process of VTPM generating the message authentication code is not visible to the outside world. Therefore, the AK Secret is only visible within VTPM and is invisible to the user during the signature process, preventing AK Secret leakage. Furthermore, VTPM can verify the signature request based on the password in the received signature request, improving the security of the signature method.

[0120] Below, in conjunction with Figure 7 This application describes a signature method for use on a cloud service platform.

[0121] Figure 7 A flowchart illustrating a signature method provided for an exemplary embodiment of this application. Figure 4 Please see. Figure 7 The methods may include:

[0122] S701. In response to the access key generation request, generate access key information.

[0123] The access key information includes the AK Secret.

[0124] For example, a user triggers an access key generation request on a cloud service platform, and the cloud service platform responds to the access key generation request by generating access key information.

[0125] S702. Send access key information to the virtual trusted platform module.

[0126] The AK Secret is used to generate a message authentication code. The access request is a request from an application in the virtual machine to access the OpenAPI.

[0127] Optionally, the access key information also includes the AK ID corresponding to the application and the password corresponding to the AK ID. The password corresponding to the AK ID is used to verify the signature request, and the signature request is used to request the generation of a signature for the access request.

[0128] In the technical solution of this application, the cloud service platform can respond to an access key generation request, generate access key information, and send the access key information to the VTPM. The access key information includes an AK Secret. Since the cloud service platform generates the AK Secret and then sends it to the VTPM, the AK Secret remains invisible to the user throughout its entire lifecycle, preventing AK Secret leakage and improving the security of the signature method.

[0129] Below, in conjunction with Figure 8 The specific implementation of the signature method in this application will be explained.

[0130] Figure 8 A flowchart illustrating a signature method provided for an exemplary embodiment of this application. Figure 5 Please see. Figure 8 In response to the access key generation request, the cloud service platform generates access key information, including AK1 ID, password 1, and AK1 Secret. The AK1 ID and password 1 can be configured by the user in the virtual machine's application, while the AK1 Secret is stored in the VTPM running on the VTPM. Figure 8 The VTPM corresponding to the virtual machine.

[0131] After storing the AK1 Secret in VTPM, VTPM sends the AK1 ID and index information of the AK1 Secret to the virtual machine. The virtual machine receives the AK1 ID and index information sent by VTPM and generates an index file in the shared file system. The file name of the index file is AK1 ID.

[0132] Please see Figure 8The VTPM stores multiple AK Secrets and their corresponding passwords. AK1 Secret corresponds to password 'a', and AK2 Secret corresponds to password 'b'. VTPM can verify access requests using these passwords. For example, after receiving a signature request from the virtual machine, if the password in the signature request matches password 'a', VTPM can sign the access request based on AK1 Secret. The shared file system stores multiple index files. The index file named AK1 ID stores the index information of the AK1 Secret corresponding to AK1 ID, and the index file named AK2 ID stores the index information of the AK2 Secret corresponding to AK2 ID.

[0133] After the virtual machine's application generates an access request, it retrieves the corresponding index file from the virtual machine's shared file system based on the AK1 ID, and then obtains the index information from the index file. The hash value of the access request, the index information, and password 1 are then used as a signature request, which is sent to the VTPM.

[0134] VTPM receives a signature request from the virtual machine, searches for the AK1 Secret and password 'a' stored in the storage space corresponding to the index information in the signature request, and if the password 'a' in the storage space matches the password '1' in the signature request, it generates a message authentication code based on the AK1 Secret and the hash value of the access request, and sends the message authentication code to the virtual machine.

[0135] The virtual machine receives the message authentication code sent by VTPM, and further sends an access request, AK1 ID, and access request signature to the open application interface server, wherein the access request signature is the message authentication code.

[0136] Figure 9 A schematic diagram of the structure of a first signature device provided for an exemplary embodiment of this application. Please refer to... Figure 9 The signature device 900, applied to a virtual machine, may include: a request signature module 901, a receiving module 902, and a request access module 903, wherein...

[0137] The request signature module 901 is used to send a signature request for the access request to the virtual trusted platform module corresponding to the virtual machine, wherein the access request is a request from the application in the virtual machine to access the open application interface.

[0138] The receiving module 902 is used to receive a message authentication code sent by the virtual trusted platform module. The message authentication code is generated based on the access key key corresponding to the application. The access key key is generated by the cloud service platform and sent to the virtual trusted platform module.

[0139] The request access module 903 is used to send information after the access request is signed using a message authentication code to the open application interface server.

[0140] In one possible implementation, the request signature module 901 is specifically used for:

[0141] Based on the access key identifier corresponding to the application, obtain the index information of the access key key corresponding to the access key identifier from the virtual machine;

[0142] The signature request is sent to the virtual trusted platform module. The signature request includes the hash value of the access request, the index information, and the password corresponding to the access key identifier. The password is used to verify the signature request.

[0143] In one possible implementation, the request signature module 901 is specifically used for:

[0144] Based on the access key identifier, obtain the corresponding index file from the shared file system of the virtual machine;

[0145] The index information is obtained from the index file.

[0146] In one possible implementation, the virtual trusted platform module runs on a management expansion card.

[0147] The signature device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.

[0148] Figure 10 A schematic diagram of a second signature device provided for an exemplary embodiment of this application. Please refer to... Figure 10 ,exist Figure 9 Based on the illustrated embodiment, the signature device 900 may further include: a storage index module 904, wherein,

[0149] In one possible implementation, prior to generating the access request, the receiving module 902 is specifically configured to:

[0150] Receive the access key identifier and the index information sent by the virtual trusted platform module;

[0151] Accordingly, the storage index module 904 is specifically used for:

[0152] An index file is generated in the shared file system. The file name of the index file is the access key identifier, and the index file includes the index information.

[0153] The signature device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.

[0154] Figure 11 A schematic diagram of a third signature device provided for an exemplary embodiment of this application. Please refer to... Figure 11 The signature device 1100 is applied to the virtual trusted platform module and may include: a receiving module 1101 and a sending module 1102, wherein...

[0155] The receiving module 1101 is used to receive a signature request sent by a virtual machine. The signature request is used to request the generation of a signature for an access request. The access request is a request from an application in the virtual machine to access an open application programming interface.

[0156] The sending module 1102 is used to generate a message authentication code based on the access key key corresponding to the application, and send the message authentication code to the virtual machine. The access key key is generated by the cloud service platform and sent to the virtual trusted platform module.

[0157] In one possible implementation, the signature request includes the hash value of the access request, the index information of the access key key corresponding to the application, and the password corresponding to the access key identifier. The access key identifier corresponds to the application, and the password corresponding to the access key identifier is used to verify the signature request. The sending module 1102 is specifically used for:

[0158] In the storage space corresponding to the index information, find the access key and the password corresponding to the access key identifier in the storage space;

[0159] If the password in the storage space matches the password in the signature request, the message authentication code is generated based on the access key and the hash value of the access request.

[0160] The signature device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.

[0161] Figure 12 A schematic diagram of a fourth signature device provided for an exemplary embodiment of this application. Please refer to... Figure 11 ,exist Figure 11 Based on the illustrated embodiment, the signature device 1100 may further include: a key storage module 1103, wherein,

[0162] In one possible implementation, prior to receiving the signature request sent by the virtual machine, the key storage module 1103 is specifically used for:

[0163] The system receives access key information sent by a cloud service platform. The access key information includes the access key key, the access key identifier, and the password corresponding to the access key identifier.

[0164] The access key and the password corresponding to the access key identifier are stored in the storage space, and the index information is generated according to the location information of the storage space.

[0165] The access key identifier and the index information are sent to the virtual machine.

[0166] The signature device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.

[0167] Figure 13 A schematic diagram of the structure of a fifth signature device provided for an exemplary embodiment of this application. Please refer to... Figure 13 The signature device 1300 is applied to a cloud service platform and may include: a response module 1301 and a sending module 1302, wherein...

[0168] The response module 1301 is used to generate access key information in response to an access key generation request, wherein the access key information includes an access key secret.

[0169] The sending module 1302 is used to send the access key information to the virtual trusted platform module. The access key is used to generate a message authentication code. The access request is a request from an application in the virtual machine to access the open application programming interface.

[0170] In one possible implementation, the access key information further includes an access key identifier corresponding to the application and a password corresponding to the access key identifier. The password corresponding to the access key identifier is used to verify the signature request, and the signature request is used to request the generation of a signature for the access request.

[0171] The signature device provided in this application embodiment can execute the technical solution shown in the above method embodiment. Its implementation principle and beneficial effects are similar, and will not be described again here.

[0172] Figure 14 This is a schematic diagram of the structure of an electronic device provided for an exemplary embodiment of this application. Please refer to... Figure 14 The electronic device 1400 can implement any signature method executed by a virtual machine or VTPM, and may include a processor 1401 and a memory 1402. Exemplarily, the processor 1401 and the memory 1402 are interconnected via a bus 1403.

[0173] The memory 1402 stores computer-executed instructions;

[0174] The processor 1401 executes the computer execution instructions stored in the memory 1402, causing the processor 1401 to perform the method as shown in the above method embodiment.

[0175] Accordingly, this application provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, are used to implement the method described in the above-described method embodiments.

[0176] Accordingly, embodiments of this application may also provide a computer program product, including a computer program, which, when executed by a processor, can implement the methods shown in the above-described method embodiments.

[0177] Those skilled in the art will understand that embodiments of the present invention can be provided as methods, systems, or computer program products. Therefore, the present invention can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, the present invention can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0178] This invention is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0179] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0180] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0181] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0182] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0183] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0184] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0185] The above description is merely an embodiment of this application and is not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A signature method, characterized in that, Applied to virtual machines, including: A signature request for an access request is sent to the virtual trusted platform module corresponding to the virtual machine. The access request is a request from the application in the virtual machine to access the open application interface. The system receives a message authentication code sent by the virtual trusted platform module. The message authentication code is generated based on the access key key corresponding to the application. The access key key is generated by the cloud service platform and sent to the virtual trusted platform module. Send information to the Open Application Programming Interface (API) server after signing the access request using the message authentication code.

2. The method according to claim 1, characterized in that, The signature request for sending the access request to the virtual trusted platform module corresponding to the virtual machine includes: Based on the access key identifier corresponding to the application, obtain the index information of the access key key corresponding to the access key identifier from the virtual machine; The signature request is sent to the virtual trusted platform module. The signature request includes the hash value of the access request, the index information, and the password corresponding to the access key identifier. The password is used to verify the signature request.

3. The method according to claim 2, characterized in that, The step of obtaining the index information of the access key key corresponding to the access key identifier from the virtual machine based on the access key identifier corresponding to the application includes: Based on the access key identifier, obtain the corresponding index file from the shared file system of the virtual machine; The index information is obtained from the index file.

4. The method according to claim 3, characterized in that, Before generating the access request, the method further includes: Receive the access key identifier and the index information sent by the virtual trusted platform module; An index file is generated in the shared file system. The file name of the index file is the access key identifier, and the index file includes the index information.

5. The method according to any one of claims 1-4, characterized in that, The virtual trusted platform module runs on an on-card microserver, which is located on the host machine where the virtual machine is located.

6. A signature method, characterized in that, Applied to the virtual trusted platform module, including: Receive a signature request sent by a virtual machine, the signature request being used to request a signature for an access request, the access request being a request from an application in the virtual machine to access an open application programming interface; A message authentication code is generated based on the access key corresponding to the application, and the message authentication code is sent to the virtual machine. The access key is generated by the cloud service platform and sent to the virtual trusted platform module.

7. The method according to claim 6, characterized in that, The signature request includes the hash value of the access request, the index information of the access key key corresponding to the application, and the password corresponding to the access key identifier. The access key identifier corresponds to the application, and the password corresponding to the access key identifier is used to verify the signature request. The generation of the message authentication code based on the access key secret key corresponding to the application includes: In the storage space corresponding to the index information, find the access key and the password corresponding to the access key identifier in the storage space; If the password in the storage space matches the password in the signature request, the message authentication code is generated based on the access key and the hash value of the access request.

8. The method according to claim 7, characterized in that, Before receiving the signature request sent by the virtual machine, the method further includes: The system receives access key information sent by a cloud service platform. The access key information includes the access key key, the access key identifier, and the password corresponding to the access key identifier. The access key and the password corresponding to the access key identifier are stored in the storage space, and the index information is generated according to the location information of the storage space. The access key identifier and the index information are sent to the virtual machine.

9. A signature method, characterized in that, Applied to cloud service platforms, including: In response to an access key generation request, access key information is generated, the access key information including an access key secret; The access key information is sent to the virtual trusted platform module. The access key is used to generate a message authentication code. The access request is a request from an application in the virtual machine to access the open application programming interface.

10. The method according to claim 9, characterized in that, The access key information also includes an access key identifier corresponding to the application and a password corresponding to the access key identifier. The password corresponding to the access key identifier is used to verify the signature request, and the signature request is used to request the generation of a signature for the access request.

11. A signature device, characterized in that, Applied to virtual machines, the device includes: a request signature module, a receiving module, and a request access module, wherein, The request signature module is used to send a signature request for the access request to the virtual trusted platform module corresponding to the virtual machine. The access request is a request from the application in the virtual machine to access the open application interface. The receiving module is used to receive a message authentication code sent by the virtual trusted platform module. The message authentication code is generated based on the access key key corresponding to the application. The access key key is generated by the cloud service platform and sent to the virtual trusted platform module. The request access module is used to send information to the open application interface server after the access request has been signed using the message authentication code.

12. A signature device, characterized in that, Applied to a virtual trusted platform module, the device includes: a receiving module and a transmitting module, wherein, The receiving module is used to receive a signature request sent by a virtual machine. The signature request is used to request a signature for an access request, which is a request from an application in the virtual machine to access an open application programming interface. The sending module is used to generate a message authentication code based on the access key key corresponding to the application, and send the message authentication code to the virtual machine. The access key key is generated by the cloud service platform and sent to the virtual trusted platform module.

13. A signature device, characterized in that, Applied to a cloud service platform, the device includes: a response module and a sending module, wherein, The response module is used to generate access key information in response to an access key generation request, the access key information including an access key secret. The sending module is used to send the access key information to the virtual trusted platform module. The access key is used to generate a message authentication code. The access request is a request from an application in the virtual machine to access the open application programming interface.

14. An electronic device, characterized in that, include: At least one processor; and a memory communicatively connected to the at least one processor; The memory stores instructions executable by the at least one processor, which, when executed by the at least one processor, cause the electronic device to perform the method according to any one of claims 1-10.

15. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, implement the method as described in any one of claims 1-10.

16. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the method as described in any one of claims 1-10.