Digital certificate processing method and apparatus
Through the certificate control nodes, the problem of wasting certificate resources and network resources in the cloud computing environment is solved and efficient utilization of resources is achieved.
Patent Information
- Application Number
- PCT/CN2024/114917
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-28
- Filing Date
- 2024-08-27
- Publication Date
- 2025-07-03
AI Technical Summary
In the cloud computing environment, the way the service node applies for digital certificates from the CA certification center leads to the waste of certificate resources and network resources.
Introduce certificate control nodes, apply for digital certificates from the certificate issuing center in a unified manner, and distribute them to multiple service nodes to realize unified application, unified management and unified distribution of digital certificates.
Reduced the number of applications to the Certificate Issuance Center, saved certificate resources and network resources, and improved resource utilization.
Smart Images

Figure CN2024114917_03072025_PF_FP_ABST
Abstract
Description
Method and device for processing digital certificate
[0001] This disclosure claims priority to the Chinese patent application filed with the China Patent Office on December 28, 2023, with application number 202311844205.3 and application name “A method and device for processing digital certificates”, the entire contents of which are incorporated by reference into this disclosure. Technical Field
[0002] The present disclosure relates to the technical field of cloud computing, and in particular to a method and apparatus for processing digital certificates. Background Art
[0003] In recent years, with the popularization of cloud computing and virtualization technology, many excellent cloud computing application service platforms have emerged. They aggregate a large amount of physical hardware resources and use virtualization technology to abstract the hardware resources of physical hardware devices, realizing the unified allocation, scheduling and management of heterogeneous network computing resources, thereby fully utilizing software and hardware resources and improving utilization.
[0004] In the cloud computing environment, the security authentication of cloud services has received increasing attention. Traditional security authentication solutions are mostly based on digital certificates, which use digital certificates to achieve security authentication and ensure the confidentiality, integrity and non-repudiation of data.
[0005] Among them, the CA (Certificate Authority) certification center, as an authoritative and trusted third party, is an important part of the public key infrastructure. It is mainly responsible for the full life cycle management of digital certificates, including application, review, issuance and cancellation.
[0006] In a cloud environment, the service provider's service node can apply for a digital certificate from the CA certification center, and the CA certification center can issue a digital certificate to the service node to achieve security authentication through the digital certificate.
[0007] However, the method of "the service provider's service node applies for a digital certificate from the CA certification center, and the CA certification center issues a digital certificate to the service node" has problems such as waste of certificate resources and waste of network resources.
[0008] Summary of the Invention
[0009] The present disclosure provides a method and apparatus for processing digital certificates.
[0010] In the first aspect, the present disclosure shows a method for processing digital certificates, which is applied to a certificate management node. The method includes: sending an application request to a certificate issuing center, the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit a service node to provide data services; receiving the first digital certificate returned by the certificate issuing center based on the application request; and distributing the first digital certificate to the service node.
[0011] In the second aspect, the present disclosure shows a method for processing digital certificates, which is applied to a service node. The method includes: receiving a first digital certificate distributed by a certificate management node, the first digital certificate being returned by the certificate issuance center to the certificate management node based on the application request after the certificate management node sends an application request to the certificate issuance center, the application request being used to apply for the first digital certificate, and the first digital certificate being used to authorize or permit the service node to provide data services; and deploying the first digital certificate in the service node.
[0012] In the third aspect, the present disclosure shows a device for processing digital certificates, which is applied to a certificate management node. The device includes: a first sending module, used to send an application request to a certificate issuing center, the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit a service node to provide data services; a first receiving module, used to receive the first digital certificate returned by the certificate issuing center according to the application request; a first distribution module, used to distribute the first digital certificate to the service node.
[0013] In a fourth aspect, the present disclosure shows a device for processing digital certificates, which is applied to a service node. The device includes: a third receiving module, used to receive a first digital certificate distributed by a certificate management node, the first digital certificate is returned by the certificate issuing center to the certificate management node according to the application request after the certificate management node sends an application request to the certificate issuing center, the application request is used to apply for the first digital certificate, and the first digital certificate is used to authorize or permit the service node to provide data services; a first deployment module, used to deploy the first digital certificate in the service node.
[0014] In a fifth aspect, the present disclosure shows an electronic device, which includes: a processor; a memory for storing processor-executable instructions; wherein the processor is configured to execute the method shown in any of the aforementioned aspects.
[0015] In a sixth aspect, the present disclosure shows a non-transitory computer-readable storage medium, which, when instructions in the storage medium are executed by a processor of an electronic device, enables the electronic device to perform the method shown in any of the aforementioned aspects.
[0016] In a seventh aspect, the present disclosure shows a computer program product. When instructions in the computer program product are executed by a processor of an electronic device, the electronic device is enabled to perform the method shown in any of the aforementioned aspects.
[0017] Compared with the prior art, the present disclosure has the following advantages:
[0018] In the present disclosure, a certificate control node may send an application request to a certificate issuing center, the application request being used to apply for a first digital certificate, which is used to authorize or permit a service node to provide data services. The certificate issuing center may then return the first digital certificate based on the application request and distribute the first digital certificate to the service node. The service node may receive the first digital certificate distributed by the certificate control node and deploy the first digital certificate in the service node to provide data services based on the first digital certificate.
[0019] Through the present disclosure, it is possible to achieve unified application, unified management and unified distribution of digital certificates by certificate management nodes. For example, service nodes do not apply to the certificate issuing center for digital certificates used to authorize or permit service nodes to provide data services. Instead, the certificate management nodes uniformly apply to the certificate issuing center for digital certificates and can distribute the applied digital certificates to service nodes so that the service nodes can provide data services based on the digital certificates distributed by the certificate management node.
[0020] In one example, when there are multiple service nodes, each of the multiple service nodes does not apply to the certificate issuing center for a digital certificate for authorizing or permitting the service node to provide data services. Instead, the certificate management node applies to the certificate issuing center for a digital certificate and can distribute the applied digital certificate to each of the multiple service nodes, so that each of the multiple service nodes can provide data services based on the digital certificate distributed by the certificate management node.
[0021] Secondly, in the present disclosure, when there are multiple service nodes, the digital certificates that the certificate management node uniformly applies for from the certificate issuing center can be reused in multiple service nodes. In this way, each service node in the multiple service nodes does not need to apply for a digital certificate from the certificate issuing center separately, which can reduce the number of digital certificates applied for from the certificate issuing center and save certificate resources.
[0022] In addition, through the present disclosure, when there are multiple service nodes, the certificate issuing center can only connect with the certificate control node, and does not need to connect with each of the multiple service nodes separately. In this way, the certificate issuing center can only issue digital certificates to the certificate control node, and does not need to issue digital certificates to each of the multiple service nodes separately, thereby saving network resources of the certificate issuing center. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] FIG1 is a structural block diagram of a system for processing digital certificates according to the present disclosure.
[0024] FIG2 is a flowchart of a method for processing a digital certificate according to the present disclosure.
[0025] FIG3 is a structural block diagram of a device for processing digital certificates disclosed herein.
[0026] FIG4 is a structural block diagram of a device for processing digital certificates according to the present disclosure.
[0027] FIG5 is a structural block diagram of a device disclosed herein. DETAILED DESCRIPTION
[0028] In order to make the above-mentioned objects, features and advantages of the present disclosure more obvious and easy to understand, the present disclosure is further described in detail below with reference to the accompanying drawings and specific embodiments.
[0029] In one approach, each service node in a service provider's service cluster applies for a digital certificate from a certificate issuing center, and the certificate issuing center issues a digital certificate to each service node. That is, the certificate issuing center needs to issue as many digital certificates to the service provider's service cluster as there are service nodes in the service provider's service cluster.
[0030] It can be seen that, on the one hand, the large number of digital certificates issued by the certificate issuance center to the service cluster of the service provider will consume a lot of certificate resources.
[0031] On the other hand, the process of the certificate issuing center issuing digital certificates to each service node in the service cluster of the service provider will consume a lot of network resources of the certificate issuing center.
[0032] To this end, in order to save certificate resources and save network resources of the certificate issuing center, the present disclosure is proposed. Referring to FIG1 , a system for processing digital certificates of the present disclosure is shown, which includes: a certificate management node, a service cluster, and a certificate issuing center.
[0033] The certificate management node and the certificate issuing center can be connected (for example, communication connection, etc.), and data can be exchanged between the certificate management node and the certificate issuing center.
[0034] The certificate issuing authority may include a CA certification authority, etc.
[0035] The certificate management node and the service cluster can be connected (for example, communication connection, etc.), and data can be exchanged between the certificate management node and the service cluster.
[0036] The service cluster may include one service node or multiple service nodes, and the multiple service nodes are used to provide at least data services (data services may include multiple types of data services, such as video type data services, music type data services or instant messaging type data services, etc.).
[0037] In one embodiment, multiple service nodes in the service cluster can be connected to the certificate management node respectively.
[0038] Secondly, in another embodiment, any two service nodes among the multiple service nodes in the service cluster can be connected to each other, and any two service nodes among the multiple service nodes in the service cluster can exchange data.
[0039] In the present disclosure, the service nodes in the service cluster may include cloud service nodes (e.g., service nodes in a cloud computing scenario), such as virtual machines, etc. The virtual machines may include ECS (Elastic Compute Service, cloud servers), etc., and the service nodes may also include cloud service nodes, etc.
[0040] Each service node in the service cluster may belong to the same service provider.
[0041] Alternatively, the service providers to which the service nodes in the service cluster belong may not all be the same or completely different. For example, the service providers to which some service nodes in the service cluster belong may be different from those to which other service nodes belong. The service provider to which the service node belongs may be the provider that rents the service node, and the provider that rents the service node may use the service node to provide services related to the provider that rented the service node.
[0042] In one embodiment, the data services that the service node can provide include: CDN (Content Delivery Network) service, SLB (Server Load Balancing) service and WAF (Web Application Firewall) service, etc. Of course, it is understandable that other types of services can also be included, which are not detailed here.
[0043] For off-cloud service nodes, auxiliary scripts can be installed on the off-cloud service nodes. The auxiliary scripts may include Agent scripts, etc. The auxiliary scripts may have multiple functions, such as heartbeat reporting function, certificate update function, node restart function, certificate backup function, path scanning function, file verification function and service detection function, etc.
[0044] The heartbeat reporting function is used to regularly report the heartbeat information of the service node where the auxiliary script is located to the certificate control node.
[0045] The certificate update function is used to request the certificate control node to update the digital certificate deployed on the service node where the auxiliary script is located, receive the digital certificate distributed by the certificate control node, and deploy the digital certificate on the service node.
[0046] The node restart function is used to control the restart of the service node where the auxiliary script is located after deploying the digital certificate on the service node where the auxiliary script is located.
[0047] The certificate backup function is used to back up the digital certificate deployed on the service node where the auxiliary script is located for subsequent tracing.
[0048] The path scanning function is used to scan the path / location of the digital certificate deployed on the service node where the auxiliary script is located on the service node where the auxiliary script is located.
[0049] The file verification function is used to respond to the certificate issuing center's verification of the service node's identity when the certificate control node applies for a digital certificate from the certificate issuing center for the service node in the service cluster.
[0050] The service detection function is used to detect whether the service node where the auxiliary script is located has provided data services within a period of time, for example, whether it has received data requests sent from the outside (for example, the service node provides data services based on data requests), and report the detection results to the certificate control node.
[0051] In addition, the certificate management node can have multiple functions, such as certificate management function, certificate application function, monitoring service function, DNS (Domain Name System) management function, alarm service function, certificate distribution function, node management function, deployment detection function, multi-vendor cloud product management function and cloud data resource management function.
[0052] The certificate management function is used to manage digital certificates applied for from a certificate issuing center, for example, to store / back up digital certificates applied for from a certificate issuing center.
[0053] The certificate application function is used to apply for a digital certificate from a certificate authority.
[0054] The monitoring service function is used to receive detection status reported by the service node, including whether the service node has provided data services within a period of time, for example, whether it has received data requests sent from the outside (for example, the service node provides data services based on data requests).
[0055] DNS management function is used to set DNS information of service nodes in the service cluster, etc.
[0056] The alarm service function is used to output alarm information when the digital certificate is about to expire or has expired.
[0057] The certificate distribution function is used to distribute the applied digital certificates to the service nodes in the service cluster.
[0058] The node management function is used to manage the service nodes in the service cluster and to connect to the service nodes in the service cluster.
[0059] The deployment detection function is used to detect whether the digital certificate distributed to the service node is effective or deployed successfully in the service node.
[0060] Multi-vendor cloud product management function is used to connect and manage cloud products of multiple service providers.
[0061] Cloud data resource management function is used to manage cloud data resources in service nodes.
[0062] Referring to FIG2 , a method for processing a digital certificate according to the present disclosure is shown, which can be applied to the system for processing a digital certificate shown in FIG1 . The method may include:
[0063] In step S101, the certificate control node sends an application request to a certificate issuing center. The application request is used to apply for a first digital certificate. The first digital certificate is used to authorize or permit a service node to provide data services.
[0064] The service nodes in the service cluster may provide data services based on the first digital certificate, for example, providing the aforementioned types of data services.
[0065] In one embodiment, multiple service nodes in a service cluster may respectively provide data services, for example, respectively provide the aforementioned types of data services, and the types of data services that each service node may provide may be the same.
[0066] For any type of data service that can be provided by the multiple service nodes, the multiple service nodes need to have a digital certificate for authorizing or permitting the service node to provide that type of data service. In this way, the service node can provide that type of data service based on the digital certificate for authorizing or permitting the service node to provide that type of data service. The same applies to each other type of data service that can be provided by the multiple service nodes.
[0067] The present disclosure is illustrated by taking the example that multiple service nodes in a service cluster can respectively provide one type of data service among multiple types of data services, but this is not intended to limit the scope of protection of the present disclosure.
[0068] If the service nodes in the service cluster need to provide this type of data service, the service nodes in the service cluster need to have a digital certificate for authorizing or permitting the service nodes to provide this type of data service. In this way, this type of data service can be provided based on the digital certificate for authorizing or permitting the service nodes to provide this type of data service.
[0069] The present disclosure is that a certificate management node uniformly schedules digital certificates for service nodes in a service cluster. In this way, the certificate management node can send an application request to a certificate issuing center to obtain a first digital certificate from the certificate issuing center for authorizing or permitting the service node to provide data services.
[0070] In step S102, the certificate control node receives the first digital certificate returned by the certificate issuing center according to the application request.
[0071] In step S103, the certificate control node distributes the first digital certificate to the service nodes in the service cluster.
[0072] For example, after the certificate management node applies for the first digital certificate for authorizing or permitting the service node to provide data services from the certificate issuing center, the first digital certificate can be distributed to the service nodes in the service cluster so that the service nodes in the service cluster can deploy the first digital certificate, and then the service nodes in the service cluster can provide data services based on the first digital certificate.
[0073] For a service node in a service cluster, the following process S104 to S105 may be executed:
[0074] In step S104, a first digital certificate distributed by a certificate control node is received.
[0075] In step S105 , a first digital certificate is deployed in the service node.
[0076] To provide data services based on the first digital certificate.
[0077] In the present disclosure, a certificate control node may send an application request to a certificate issuing center, the application request being used to apply for a first digital certificate, which is used to authorize or permit a service node to provide data services. The certificate issuing center may then return the first digital certificate based on the application request and distribute the first digital certificate to the service node. The service node may receive the first digital certificate distributed by the certificate control node and deploy the first digital certificate in the service node to provide data services based on the first digital certificate.
[0078] Through the present disclosure, it is possible to achieve unified application, unified management and unified distribution of digital certificates by certificate management nodes. For example, service nodes do not apply to a certificate issuing center for a digital certificate used to authorize or permit service nodes to provide data services. Instead, the certificate management nodes uniformly apply to the certificate issuing center for a digital certificate and can distribute the applied digital certificates to the service nodes so that the service nodes can provide data services based on the digital certificates distributed by the certificate management nodes.
[0079] In one example, when there are multiple service nodes, each of the multiple service nodes does not apply to the certificate issuing center for a digital certificate for authorizing or permitting the service node to provide data services. Instead, the certificate management node applies to the certificate issuing center for a digital certificate and can distribute the applied digital certificate to each of the multiple service nodes, so that each of the multiple service nodes can provide data services based on the digital certificate distributed by the certificate management node.
[0080] Secondly, in the present disclosure, when there are multiple service nodes, the digital certificates that the certificate management node uniformly applies for from the certificate issuing center can be reused in multiple service nodes. In this way, each service node in the multiple service nodes does not need to apply for a digital certificate from the certificate issuing center separately, which can reduce the number of digital certificates applied for from the certificate issuing center and save certificate resources.
[0081] In addition, through the present disclosure, when there are multiple service nodes, the certificate issuing center can only connect with the certificate control node, and does not need to connect with each of the multiple service nodes separately. In this way, the certificate issuing center can only issue digital certificates to the certificate control node, and does not need to issue digital certificates to each of the multiple service nodes separately, thereby saving network resources of the certificate issuing center.
[0082] In one embodiment of the present disclosure, the service nodes in the service cluster may periodically send heartbeat information to the certificate control node.
[0083] Accordingly, after the certificate control node receives the heartbeat information sent by a service node, it can be determined that this service node is running (not down).
[0084] Alternatively, when the certificate control node does not receive the heartbeat information sent by a certain service node for a long time, it can be assumed that the certain service node is not running (has crashed).
[0085] A service node that is not running (has crashed) often does not have the ability to provide data services. Therefore, when distributing digital certificates, the certificate management node may not distribute digital certificates to the service node that is not running (has crashed) to save network resources involved in the scenario of distributing digital certificates (for example, saving network resources within the system that processes digital certificates, etc.).
[0086] In this way, before the certificate management node distributes the first digital certificate to the service nodes in the service cluster, for any service node in the service cluster, the certificate management node can determine whether the heartbeat information sent by the service node is received within the first preset time period before the current moment.
[0087] Among them, when the certificate control node receives the heartbeat information sent by the service node for the first time, the certificate control node can record the reception time when the certificate control node receives the heartbeat information sent by the service node in the certificate control node. Later, when the certificate control node receives the heartbeat information sent by the service node for the Nth time, N is greater than or equal to 2, the certificate control node can use the reception time when the heartbeat information sent by the service node is received for the Nth time in the certificate control node to replace the recorded reception time when the heartbeat information sent by the service node was received for the last time.
[0088] In this way, when determining whether the heartbeat information sent by the service node is received within the first preset time period before the current moment, the time period between the current moment of the certificate control node and the receiving time recorded in the certificate control node can be calculated. If the time period is less than or equal to the first preset time period, it can be determined that the heartbeat information sent by the service node is received within the first preset time period before the current moment, or if the time period is greater than the first preset time period, it can be determined that the heartbeat information sent by the service node is not received within the first preset time period before the current moment.
[0089] If the heartbeat information sent by the service node is received within the first preset time period before the current moment, it means that the service node is running and the first digital certificate can be distributed to the service node.
[0090] Alternatively, if no heartbeat information sent by the service node is received within a first preset time period before the current moment, it indicates that the service node is not running, and the first digital certificate may not be distributed to the service node.
[0091] The current time may be the current time of the certificate control node.
[0092] The first preset duration may include 1s (second), 2s, 3s or 4s, etc., and may be determined according to actual conditions, and is not limited in this disclosure.
[0093] In another embodiment of the present disclosure, after the first digital certificate is deployed in the service node, the service node may send first deployment information to the certificate control node. The first deployment information is used to indicate that the first digital certificate has been deployed in the service node. Accordingly, the certificate control node may receive the first deployment information and, based on the first deployment information, learn that the first digital certificate has been deployed in the service node.
[0094] However, in another case, the service node does not send the first deployment information to the certificate control node. Accordingly, the certificate control node does not receive the first deployment information sent by the service node.
[0095] Among them, "the service node did not send the first deployment information to the certificate management node" may be because: the service node did not receive the digital certificate distributed by the certificate management node, or, it may also be because: the service node received the digital certificate distributed by the certificate management node but the service node failed to successfully deploy the first digital certificate in the service node, etc.
[0096] To this end, within a second preset time period after the certificate control node distributes the first digital certificate to the service node, the certificate control node may detect whether the first deployment information sent by the service node is received.
[0097] If the certificate control node does not receive the first deployment information sent by the service node within a second preset time period after the certificate control node distributes the first digital certificate to the service node, the certificate control node may distribute the first digital certificate to the service node again.
[0098] On the one hand, the service node can be enabled to obtain the first digital certificate as much as possible, and on the other hand, the service node can be enabled to try to deploy the first digital certificate in the service node again as much as possible to increase the possibility of successfully deploying the first digital certificate in the service node.
[0099] Alternatively, within a second preset period of time after distributing the first digital certificate to the service node, if the certificate control node receives the first deployment information sent by the service node, the certificate control node may no longer distribute the first digital certificate to the service node.
[0100] The second preset duration may include 1s (second), 2s, 3s or 4s, etc., which may be determined according to actual conditions and is not limited in this disclosure.
[0101] In addition, in another embodiment of the present disclosure, if the first deployment information sent by the service node is not received within the second preset time period after distributing the first digital certificate to the service node multiple times, it often indicates that the service node is abnormal (although the service node may be running and not down, the service node has an abnormality in receiving the digital certificate, or the service node can receive the digital certificate, but has an abnormality in deploying the digital certificate), and a first alarm message can be output. The first alarm message is used to prompt that the first digital certificate cannot be deployed in the service node.
[0102] In one embodiment, the first alarm information can be output to relevant staff so that the staff can intervene as soon as possible and eliminate the abnormality of the service node as soon as possible, so that the digital certificate can be successfully deployed in the service node as soon as possible, and thus the service node can provide data services as soon as possible.
[0103] The same is true for every other service node in the service cluster.
[0104] In the present disclosure, digital certificates often have a validity period. If the digital certificate deployed in the service node has not expired, the service node can provide data services based on the digital certificate that has not expired. However, if the digital certificate deployed in the service node has expired, the service node cannot provide data services based on the expired digital certificate.
[0105] In this way, in order to avoid the interruption of data services provided by the service node as much as possible or shorten the duration of the interruption of data services provided by the service node as much as possible, in another embodiment of the present disclosure, the certificate management node can detect whether the remaining effective time of the first digital certificate is less than a third preset time.
[0106] When the remaining validity period of the first digital certificate is less than the third preset period, the certificate control node may output a second warning message. The second warning message is used to prompt that the first digital certificate is about to expire or has expired.
[0107] In one embodiment, the second alarm information can be output to relevant staff so that the staff can intervene as soon as possible and renew the first digital certificate as soon as possible to improve the continuity of data services provided by the service node.
[0108] The third preset duration may include 10s (seconds), 12s, 15s or 18s, etc., which may be determined according to actual conditions and is not limited in this disclosure.
[0109] Furthermore, in order to improve the level of automation, reduce labor costs, and improve the efficiency of renewal of the first digital certificate, in another embodiment of the present disclosure, when the remaining effective period of the first digital certificate is less than the third preset period, the certificate management node can send a renewal request for the first digital certificate to the certificate issuing center.
[0110] The certificate issuing center may receive the renewal request and then issue a second digital certificate to the certificate control node based on the renewal request. The second digital certificate is used to authorize or permit the service node to provide data services. The second digital certificate expires later than the first digital certificate.
[0111] Afterwards, the certificate management and control node may receive the second digital certificate returned by the certificate issuing center according to the renewal request, and distribute the second digital certificate to the service nodes in the service cluster.
[0112] Then, the service nodes in the service cluster can receive the second digital certificate distributed by the certificate management node and deploy the second digital certificate in the service nodes in the service cluster. For example, the second digital certificate can be used to replace the deployed first digital certificate in the service nodes in the service cluster to provide data services based on the second digital certificate.
[0113] The second digital certificate can be regarded as a digital certificate obtained after the first digital certificate is renewed.
[0114] For example, the second digital certificate can be a certificate different from the first digital certificate. The common point between the two is that they are both used to authorize or permit the service node to provide data services. However, the valid expiration time of the second digital certificate is later than the valid expiration time of the first digital certificate. That is, starting from the current moment, the validity period of the second digital certificate is longer. After that, the service node can provide data services based on the second digital certificate, and can no longer provide data services based on the first digital certificate, thereby achieving the purpose of renewing the first digital certificate.
[0115] In another embodiment of the present disclosure, the sharing of digital certificates between service nodes is illustrated by taking the first service node and the second service node as an example, but it is not intended to limit the scope of protection of the present disclosure. The first service node is one of the multiple service nodes in the service cluster, and the second service node is one of the multiple service nodes in the service cluster. The first service node is different from the second service node.
[0116] Normally, the certificate control node distributes digital certificates to the service nodes in the service cluster at the same time. Therefore, normally, if the service nodes in the service cluster can receive the digital certificates distributed by the certificate control node, they will often receive the digital certificates distributed by the certificate control node at the same time.
[0117] However, sometimes the following situation may occur: after some service nodes receive the digital certificates distributed by the certificate control node, other service nodes have not received the digital certificates distributed by the certificate control node for a period of time.
[0118] If the above situation occurs, it may sometimes be due to a temporary communication failure between other service nodes and the certificate control node, such as a sudden increase in delay, etc. For example, the amount of data interacting between other service nodes and the certificate control node surges at this time, resulting in very few idle network resources between other service nodes and the certificate control node at this time, affecting the transmission of digital certificates, and then causing other service nodes to not receive the digital certificates distributed by the certificate control node, and often may not be able to receive the digital certificates distributed by the certificate control node for a period of time.
[0119] In view of this, based on the above situation, when some service nodes have not received the digital certificates distributed by the certificate management node for a period of time after some service nodes have received the digital certificates distributed by the certificate management node, in order to enable other service nodes to obtain the digital certificates distributed by the certificate management node as soon as possible, and then enable other service nodes to provide data services based on the digital certificates as soon as possible, in another embodiment of the present disclosure, other service nodes can obtain the digital certificates distributed by the certificate management node through these certain service nodes.
[0120] For example, after the first digital certificate is deployed in the first service node, the first service node may broadcast first deployment information in the service cluster, where the first deployment information is used to indicate that the first digital certificate has been deployed in the first service node.
[0121] Other service nodes in the service cluster except the first service node may receive the first deployment information broadcast by the first service node. For example, the second service node may receive the first deployment information broadcast by the first service node.
[0122] Afterwards, the second service node may learn, based on the first deployment information, that the first digital certificate has been deployed in the first service node.
[0123] Since the second service node and the first service node are both service nodes in the service cluster and can both provide data services, the second service node will believe, based on the first deployment information, that the second service node should also have the first digital certificate. For example, the second service node should receive the first digital certificate distributed by the certificate control node, otherwise it will affect the second service node's provision of data services.
[0124] To this end, in this embodiment, within a fourth preset time period after the second service node receives the first deployment information broadcast by the first service node, the second service node can detect whether it has received the first digital certificate distributed by the certificate control node.
[0125] In one example, within a fourth preset time period after the second service node receives the first deployment information, if the second service node receives the first digital certificate distributed by the certificate management node, the second service node can deploy the first digital certificate in the second service node to provide data services based on the first digital certificate.
[0126] Alternatively, in another example, if the second service node does not receive the first digital certificate distributed by the certificate control node within a fourth preset period of time after receiving the first deployment information, it indicates that the second service node may not be able to receive the first digital certificate distributed by the certificate control node in a short period of time. However, in order to enable the second service node to obtain the first digital certificate as soon as possible and thus provide data services based on the first digital certificate, the second service node may send a first acquisition request to the first service node. The first acquisition request is used to obtain the first digital certificate.
[0127] The first service node may receive a first acquisition request sent by a second service node, where the second service node is one of multiple service nodes in the service cluster, and the second service node is different from the first service node. The first service node may then distribute the first digital certificate to the second service node based on the first acquisition request.
[0128] In this way, the second service node can receive the first digital certificate returned by the first service node according to the first acquisition request, and then the second service node can deploy the first digital certificate in the second service node to provide data services based on the first digital certificate.
[0129] The fourth preset duration may include 0.5s (seconds), 1s, 1.5s, 2s or 2.5s, etc., and may be determined according to actual circumstances, and this disclosure does not impose any limitation on this.
[0130] Through the present disclosure, if the second service node has not received the first digital certificate distributed by the certificate control node within a period of time after the first service node received the first digital certificate distributed by the certificate control node, the second service node can obtain the first digital certificate distributed by the certificate control node through the first service node, so that the second service node can obtain the first digital certificate distributed by the certificate control node as soon as possible, and then enable the second service node to provide data services based on the first digital certificate as soon as possible.
[0131] In the present disclosure, generally, the digital certificates of the service nodes in the service cluster are directly distributed by the certificate management node, and the certificate management node can directly manage and control the digital certificates of the service nodes in the service cluster.
[0132] There are many service nodes in the service cluster. Sometimes, some service nodes in the service cluster are qualified to provide data services, while other service nodes in the service cluster may temporarily be unqualified to provide data services due to some reasons (but may be restored to be qualified to provide data services later).
[0133] If a service node does not have the qualifications to provide data services at this time, the service node should not obtain a digital certificate.
[0134] The certificate control node can accurately know which service nodes in the service cluster are qualified to provide data services at any time.
[0135] In a scenario where a certificate control node distributes data certificates to service nodes in a service cluster, the certificate control node may distribute digital certificates to service nodes in the service cluster that are currently qualified to provide data services, but not to service nodes in the service cluster that are currently unqualified to provide data services. This prevents service nodes that are currently unqualified to provide data services from obtaining digital certificates used to authorize or permit service nodes to provide data services. For example, this prevents a service node that is currently unqualified to provide data services from being hacked into and becoming an illegal node, preventing the illegal node from obtaining the digital certificate and engaging in illegal activities, thereby ensuring data security in the service cluster.
[0136] Thus, in another embodiment of the present disclosure, in a scenario where the first service node distributes the first digital certificate to the second service node based on the first acquisition request, the first service node may ask the certificate control node whether the first digital certificate can be shared with the second service node. For example, the first service node may send a first sharing request to the certificate control node based on the first acquisition request, and the first sharing request is used to request to share the first digital certificate with the second service node.
[0137] The certificate management node receives the first sharing request sent by the first service node according to the first acquisition request, and then the certificate management node can decide whether to allow the first service node to share the first digital certificate with the second service node according to the first acquisition request.
[0138] For example, the certificate management node can determine whether the second service node meets the following conditions at the same time: the second service node is located in the service cluster, the second service node has the objective ability to provide data services, the second service node has the service qualifications to provide data services, and the second service node has not been invaded, etc.
[0139] If the second service node meets the above conditions at the same time, the first service node may be allowed to share the first digital certificate with the second service node; alternatively, if the second service node does not meet the above conditions at the same time, the first service node may not be allowed to share the first digital certificate with the second service node.
[0140] If the certificate control node allows the first service node to share the first digital certificate with the second service node, the certificate control node may send a first sharing response to the first service node based on the first sharing request. The first sharing response indicates permission to share the first digital certificate with the second service node. The first service node then receives the first sharing response returned by the certificate control node based on the first sharing request and distributes the first digital certificate to the second service node based on the first sharing response.
[0141] Alternatively, if the certificate control node does not allow the first service node to share the first digital certificate with the second service node, the certificate control node may send a first rejection response to the first service node based on the first sharing request, where the first rejection response is used to indicate that the first digital certificate is not allowed to be shared with the second service node. The first service node may then receive the first rejection response returned by the certificate control node based on the first sharing request and then not distribute the first digital certificate to the second service node.
[0142] In another embodiment of the present disclosure, after the first digital certificate is deployed in the second service node, the second service node may send second deployment information to the first service node, where the second deployment information is used to indicate that the first digital certificate has been deployed in the second service node, so that the first service node sends the second deployment information to the certificate management node.
[0143] Afterwards, the first service node may receive the second deployment information sent by the second service node, and then may send the second deployment information to the certificate control node.
[0144] Thereafter, the certificate control node may receive the second deployment information sent by the first service node, and then determine, based on the second deployment information, that the first digital certificate has been deployed in the second service node.
[0145] In this embodiment, after the first digital certificate is deployed on the second service node, the second service node can send second deployment information to the certificate control node via the first service node to notify the certificate control node that the first digital certificate has been deployed on the second service node, thereby increasing the likelihood that the certificate control node will receive the second deployment information. Furthermore, if the certificate control node knows that the first digital certificate has been deployed on the second service node, it can avoid repeatedly distributing the first digital certificate to the second service node, thereby avoiding wasting system and network resources of the certificate control node.
[0146] Normally, the certificate control node distributes digital certificates to the service nodes in the service cluster at the same time. Therefore, normally, if the service nodes in the service cluster can receive the digital certificates distributed by the certificate control node, they will often receive the digital certificates distributed by the certificate control node at the same time.
[0147] However, sometimes the following situation may occur: after some service nodes receive the digital certificates distributed by the certificate control node, other service nodes have not received the digital certificates distributed by the certificate control node for a period of time.
[0148] If the above situation occurs, it may sometimes be due to a temporary communication failure between other service nodes and the certificate control node, such as a sudden increase in delay, etc. For example, the amount of data interacting between other service nodes and the certificate control node surges at this time, resulting in very few idle network resources between other service nodes and the certificate control node at this time, affecting the transmission of digital certificates, and then causing other service nodes to not receive the digital certificates distributed by the certificate control node, and often may not be able to receive the digital certificates distributed by the certificate control node for a period of time.
[0149] In view of this, based on the above situation, when some service nodes have not received the digital certificates distributed by the certificate management node for a period of time after some service nodes have received the digital certificates distributed by the certificate management node, in order to enable other service nodes to obtain the digital certificates distributed by the certificate management node as soon as possible, and then enable other service nodes to provide data services based on the digital certificates as soon as possible, in another embodiment of the present disclosure, other service nodes can obtain the digital certificates distributed by the certificate management node through these certain service nodes.
[0150] For example, when the first service node obtains the second digital certificate distributed by the certificate control node, other service nodes in the service cluster except the first service node can obtain the second digital certificate from the first service node.
[0151] For example, when the remaining valid period of the first digital certificate is less than the fifth preset period, the second service node can detect whether it has received the second digital certificate distributed by the certificate management node; the second digital certificate is applied for by the certificate management node to the certificate issuing center when the remaining valid period of the first digital certificate is less than the third preset period, and is distributed by the certificate management node to the first service node, and the second digital certificate is used to authorize or permit the service node to provide data services; the valid expiration time of the second digital certificate is later than the valid expiration time of the first digital certificate; the first service node is one of the multiple service nodes in the service cluster, and the first service node is different from the second service node; the fifth preset period is less than the third preset period.
[0152] In one example, upon receiving the second digital certificate distributed by the certificate control node, the second service node may deploy the second digital certificate in the second service node to provide data services based on the second digital certificate.
[0153] Alternatively, in another example, if the second digital certificate distributed by the certificate control node is not received, it means that the second service node may not be able to receive the second digital certificate distributed by the certificate control node in a short period of time. However, in order to enable the second service node to obtain the second digital certificate as soon as possible and then provide data services based on the second digital certificate, the second service node can broadcast a second acquisition request in the service cluster; the second acquisition request is used to obtain the second digital certificate.
[0154] The first service node receives the second acquisition request broadcast by the second service node, and then distributes the second digital certificate to the second service node according to the second acquisition request.
[0155] In this way, the second service node can receive the second digital certificate returned by the first service node according to the second acquisition request; then the second service node can deploy the second digital certificate in the second service node to provide data services based on the second digital certificate.
[0156] The fifth preset duration may include 1s (second), 2s, 3s, 4s or 5s, etc., which can be determined according to actual conditions and is not limited in this disclosure.
[0157] Through the present disclosure, if the second service node has not received the second digital certificate distributed by the certificate control node within a period of time after the first service node received the second digital certificate distributed by the certificate control node, the second service node can obtain the second digital certificate distributed by the certificate control node via the first service node, so that the second service node can obtain the second digital certificate distributed by the certificate control node as soon as possible, and then enable the second service node to provide data services based on the second digital certificate as soon as possible.
[0158] In the present disclosure, generally, the digital certificates of the service nodes in the service cluster are directly distributed by the certificate management node, and the certificate management node can directly manage and control the digital certificates of the service nodes in the service cluster.
[0159] There are many service nodes in the service cluster. Sometimes, some service nodes in the service cluster are qualified to provide data services, while other service nodes in the service cluster may temporarily be unqualified to provide data services due to some reasons (but may be restored to be qualified to provide data services later).
[0160] If a service node does not have the qualifications to provide data services at this time, the service node should not obtain a digital certificate.
[0161] The certificate control node can accurately know which service nodes in the service cluster are qualified to provide data services at any time.
[0162] In scenarios where a certificate control node distributes data certificates to service nodes in a service cluster, the certificate control node can distribute digital certificates to service nodes in the service cluster that are currently eligible to provide data services, while refraining from distributing digital certificates to service nodes in the service cluster that are currently ineligible to provide data services. This prevents service nodes that are currently ineligible from obtaining digital certificates used to authorize or permit service nodes to provide data services. For example, this prevents an illegal node from obtaining a digital certificate and engaging in illegal activities if a service node that is currently ineligible to provide data services is compromised and rendered illegal, thereby ensuring data security in the service cluster.
[0163] Thus, in another embodiment of the present disclosure, in a scenario where the first service node distributes the second digital certificate to the second service node based on the second acquisition request, the first service node may ask the certificate control node whether the second digital certificate can be shared with the second service node. For example, the first service node may send a second sharing request to the certificate control node based on the second acquisition request, and the second sharing request is used to request sharing the second digital certificate with the second service node.
[0164] The certificate control node receives the second sharing request sent by the first service node according to the second acquisition request, and then the certificate control node may decide whether to allow the first service node to share the second digital certificate with the second service node according to the second acquisition request.
[0165] For example, the certificate management node can determine whether the second service node meets the following conditions at the same time: the second service node is located in the service cluster, the second service node has the objective ability to provide data services, the second service node has the service qualifications to provide data services, and the second service node has not been invaded, etc.
[0166] If the second service node meets the above conditions at the same time, the first service node may be allowed to share the second digital certificate with the second service node; alternatively, if the second service node does not meet the above conditions at the same time, the first service node may not be allowed to share the second digital certificate with the second service node.
[0167] If the certificate control node allows the first service node to share the second digital certificate with the second service node, the certificate control node may send a second sharing response to the first service node based on the second sharing request. The second sharing response indicates permission to share the second digital certificate with the second service node. The first service node then receives the second sharing response returned by the certificate control node based on the second sharing request and sends the second digital certificate to the second service node based on the second sharing response.
[0168] Alternatively, if the certificate control node does not allow the first service node to share the second digital certificate with the second service node, the certificate control node may send a second rejection response to the first service node based on the second sharing request, where the second rejection response is used to indicate that the second digital certificate is not allowed to be shared with the second service node. The first service node may then receive the second rejection response returned by the certificate control node based on the second sharing request and then not distribute the second digital certificate to the second service node.
[0169] In another embodiment of the present disclosure, after the second digital certificate is deployed in the second service node, the second service node may send third deployment information to the first service node, where the third deployment information is used to indicate that the second digital certificate has been deployed in the second service node, so that the first service node sends the third deployment information to the certificate management node.
[0170] Afterwards, the first service node may receive the third deployment information sent by the second service node, and then may send the third deployment information to the certificate control node.
[0171] Thereafter, the certificate control node may receive the third deployment information sent by the first service node, and then determine, based on the third deployment information, that the second digital certificate has been deployed in the second service node.
[0172] In this embodiment, after the second digital certificate is deployed on the second service node, the second service node can send third deployment information to the certificate control node via the first service node to notify the certificate control node that the second digital certificate has been deployed on the second service node, thereby increasing the likelihood that the certificate control node will receive the third deployment information. Furthermore, if the certificate control node knows that the second digital certificate has been deployed on the second service node, it can avoid repeatedly distributing the second digital certificate to the second service node, thereby avoiding wasting system and network resources of the certificate control node.
[0173] It should be noted that for the method embodiments, for simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present disclosure is not limited by the order of the actions described, because according to the present disclosure, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all optional embodiments, and the actions involved are not necessarily required by the present disclosure.
[0174] 3 , there is shown a structural block diagram of a device for processing digital certificates disclosed herein, which is applied to a certificate management node and includes: a first sending module 11, for sending an application request to a certificate issuing center, wherein the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit a service node to provide data services; a first receiving module 12, for receiving the first digital certificate returned by the certificate issuing center according to the application request; and a first distribution module 13, for distributing the first digital certificate to the service node.
[0175] In an optional implementation, the device also includes: a determination module, which is used to determine whether the heartbeat information sent by the service node is received within a first preset time period before the current moment after receiving the first digital certificate returned by the certificate issuing center according to the application request; the distribution module is also used to distribute the first digital certificate to the service node if the heartbeat information sent by the service node is received within the first preset time period before the current moment.
[0176] In an optional implementation, the device further includes: a detection module, configured to detect whether first deployment information sent by the service node is received within a second preset time period after distributing the first digital certificate to the service node, the first deployment information being used to indicate that the first digital certificate has been deployed in the service node; the distribution module is further configured to distribute the first digital certificate to the service node again if the first deployment information sent by the service node is not received.
[0177] In an optional implementation, the device also includes: a first output module, which is used to output a first alarm message when the first deployment information sent by the service node is not received within a second preset time period after distributing the first digital certificate to the service node multiple times, and the first alarm message is used to prompt that the first digital certificate cannot be deployed in the service node.
[0178] In an optional implementation, the device also includes: a second sending module, used to send a renewal request for the first digital certificate to the certificate issuing center when the remaining valid period of the first digital certificate is less than a third preset period; a second receiving module, used to receive a second digital certificate returned by the certificate issuing center according to the renewal request; the second digital certificate is used to authorize or permit the service node to provide data services; the valid expiration time of the second digital certificate is later than the valid expiration time of the first digital certificate; and a second distribution module, used to distribute the second digital certificate to the service node.
[0179] In an optional implementation, the device also includes: a second output module, used to output a second alarm message when the remaining valid period of the first digital certificate is less than a third preset period; the second alarm message is used to prompt that the first digital certificate is about to expire or has expired.
[0180] In the present disclosure, a certificate control node may send an application request to a certificate issuing center, the application request being used to apply for a first digital certificate, which is used to authorize or permit a service node to provide data services. The certificate issuing center may then return the first digital certificate based on the application request and distribute the first digital certificate to the service node. The service node may receive the first digital certificate distributed by the certificate control node and deploy the first digital certificate in the service node to provide data services based on the first digital certificate.
[0181] Through the present disclosure, it is possible to achieve unified application, unified management and unified distribution of digital certificates by certificate management nodes. For example, service nodes do not apply to a certificate issuing center for a digital certificate used to authorize or permit service nodes to provide data services. Instead, the certificate management nodes uniformly apply to the certificate issuing center for a digital certificate and can distribute the applied digital certificates to the service nodes so that the service nodes can provide data services based on the digital certificates distributed by the certificate management nodes.
[0182] In one example, when there are multiple service nodes, each of the multiple service nodes does not apply to the certificate issuing center for a digital certificate for authorizing or permitting the service node to provide data services. Instead, the certificate management node applies to the certificate issuing center for a digital certificate and can distribute the applied digital certificate to each of the multiple service nodes, so that each of the multiple service nodes can provide data services based on the digital certificate distributed by the certificate management node.
[0183] Secondly, in the present disclosure, when there are multiple service nodes, the digital certificates that the certificate management node uniformly applies for from the certificate issuing center can be reused in multiple service nodes. In this way, each service node in the multiple service nodes does not need to apply for a digital certificate from the certificate issuing center separately, which can reduce the number of digital certificates applied for from the certificate issuing center and save certificate resources.
[0184] In addition, through the present disclosure, when there are multiple service nodes, the certificate issuing center can only connect with the certificate control node, and does not need to connect with each of the multiple service nodes separately. In this way, the certificate issuing center can only issue digital certificates to the certificate control node, and does not need to issue digital certificates to each of the multiple service nodes separately, thereby saving network resources of the certificate issuing center.
[0185] 4 , there is shown a structural block diagram of a device for processing digital certificates disclosed herein, which is applied to a service node and includes: a third receiving module 21, for receiving a first digital certificate distributed by a certificate control node, wherein the first digital certificate is returned by the certificate issuing center to the certificate control node according to the application request after the certificate control node sends an application request to the certificate issuing center, wherein the application request is used to apply for the first digital certificate, and the first digital certificate is used to authorize or permit the service node to provide data services; and a first deployment module 22, for deploying the first digital certificate in the service node.
[0186] In an optional implementation, the apparatus further includes: a third sending module, configured to periodically send heartbeat information to the certificate control node.
[0187] In an optional implementation, the device also includes: a fourth sending module, used to send first deployment information to the certificate management node after deploying the first digital certificate in the service node, and the first deployment information is used to indicate that the first digital certificate has been deployed in the service node.
[0188] In an optional implementation, the device also includes: a fourth receiving module, used to receive a second digital certificate distributed by the certificate control node, the second digital certificate is applied for by the certificate control node to the certificate issuing center when the remaining validity period of the first digital certificate is less than a third preset period, and the second digital certificate is used to authorize or permit the service node to provide data services; the validity expiration time of the second digital certificate is later than the validity expiration time of the first digital certificate; and a second deployment module, used to deploy the second digital certificate in the service node.
[0189] In the present disclosure, a certificate control node may send an application request to a certificate issuing center, the application request being used to apply for a first digital certificate, which is used to authorize or permit a service node to provide data services. The certificate issuing center may then return the first digital certificate based on the application request and distribute the first digital certificate to the service node. The service node may receive the first digital certificate distributed by the certificate control node and deploy the first digital certificate in the service node to provide data services based on the first digital certificate.
[0190] Through the present disclosure, it is possible to achieve unified application, unified management and unified distribution of digital certificates by certificate management nodes. For example, service nodes do not apply to a certificate issuing center for a digital certificate used to authorize or permit service nodes to provide data services. Instead, the certificate management nodes uniformly apply to the certificate issuing center for a digital certificate and can distribute the applied digital certificates to the service nodes so that the service nodes can provide data services based on the digital certificates distributed by the certificate management nodes.
[0191] In one example, when there are multiple service nodes, each of the multiple service nodes does not apply to the certificate issuing center for a digital certificate for authorizing or permitting the service node to provide data services. Instead, the certificate management node applies to the certificate issuing center for a digital certificate and can distribute the applied digital certificate to each of the multiple service nodes, so that each of the multiple service nodes can provide data services based on the digital certificate distributed by the certificate management node.
[0192] Secondly, in the present disclosure, when there are multiple service nodes, the digital certificates that the certificate management node uniformly applies for from the certificate issuing center can be reused in multiple service nodes. In this way, each service node in the multiple service nodes does not need to apply for a digital certificate from the certificate issuing center separately, which can reduce the number of digital certificates applied for from the certificate issuing center and save certificate resources.
[0193] In addition, through the present disclosure, when there are multiple service nodes, the certificate issuing center can only connect with the certificate control node, and does not need to connect with each of the multiple service nodes separately. In this way, the certificate issuing center can only issue digital certificates to the certificate control node, and does not need to issue digital certificates to each of the multiple service nodes separately, thereby saving network resources of the certificate issuing center.
[0194] The embodiments of the present disclosure further provide a non-volatile readable storage medium, which stores one or more modules (programs). When the one or more modules are applied to a device, the device can execute instructions (instructions) of each method step in the embodiments of the present disclosure.
[0195] The present disclosure provides one or more machine-readable media having instructions stored thereon that, when executed by one or more processors, cause an electronic device to perform one or more of the methods described in the above embodiments. In the present disclosure, the electronic device includes a server, a gateway, a sub-device, and the like, wherein the sub-device is an IoT device or other device.
[0196] The embodiments of the present disclosure may be implemented as an apparatus configured as desired using any appropriate hardware, firmware, software, or any combination thereof, which may include a server (cluster), terminal devices such as IoT devices, and other electronic devices.
[0197] FIG5 schematically illustrates an exemplary apparatus 1300 that may be used to implement various embodiments of the present disclosure.
[0198] For one embodiment, Figure 5 shows an exemplary apparatus 1300 having one or more processors 1302, a control module (chip set) 1304 coupled to at least one of the processor(s) 1302, a memory 1306 coupled to the control module 1304, a non-volatile memory (NVM) / storage device 1308 coupled to the control module 1304, one or more input / output devices 1310 coupled to the control module 1304, and a network interface 1312 coupled to the control module 1304.
[0199] Processor 1302 may include one or more single-core or multi-core processors, and may include any combination of general-purpose processors or specialized processors (e.g., graphics processors, application processors, baseband processors, etc.). In some embodiments, apparatus 1300 may serve as a server device such as a gateway in the embodiments of the present disclosure.
[0200] In some embodiments, the apparatus 1300 may include one or more computer-readable media (e.g., memory 1306 or NVM / storage 1308) having instructions 1314 and one or more processors 1302 configured in conjunction with the one or more computer-readable media to execute the instructions 1314 to implement a module to perform the actions of the present disclosure.
[0201] For one embodiment, the control module 1304 may include any suitable interface controller to provide any suitable interface to at least one of the processor(s) 1302 and / or any suitable device or component in communication with the control module 1304 .
[0202] The control module 1304 may include a memory controller module to provide an interface to the memory 1306. The memory controller module may be a hardware module, a software module, and / or a firmware module.
[0203] The memory 1306 can be used, for example, to load and store data and / or instructions 1314 for the device 1300. For one embodiment, the memory 1306 can include any suitable volatile memory, such as a suitable DRAM. In some embodiments, the memory 1306 can include double data rate quad synchronous dynamic random access memory (DDR4 SDRAM).
[0204] For one embodiment, control module 1304 may include one or more input / output controllers to provide interfaces to NVM / storage device 1308 and input / output device(s) 1310 .
[0205] For example, NVM / storage 1308 may be used to store data and / or instructions 1314. NVM / storage 1308 may include any suitable non-volatile memory (e.g., flash memory) and / or may include any suitable non-volatile storage device(s) (e.g., one or more hard disk drives (HDDs), one or more compact disk (CD) drives, and / or one or more digital versatile disk (DVD) drives).
[0206] NVM / storage device 1308 may include storage resources that are physically part of the device on which apparatus 1300 is installed, or it may be accessible to the device without being part of the device. For example, NVM / storage device 1308 may be accessible over a network via input / output device(s) 1310.
[0207] (One or more) input / output devices 1310 may provide an interface for apparatus 1300 to communicate with any other appropriate device. Input / output devices 1310 may include a communication component, a phonetic component, a sensor component, etc. Network interface 1312 may provide an interface for apparatus 1300 to communicate via one or more networks. Apparatus 1300 may wirelessly communicate with one or more components of a wireless network according to any of one or more wireless network standards and / or protocols, for example, accessing a wireless network based on a communication standard, such as WiFi, 2G, 3G, 4G, 5G, etc., or a combination thereof for wireless communication.
[0208] For one embodiment, at least one of the processor(s) 1302 may be packaged together with the logic of one or more controllers of the control module 1304 (e.g., a memory controller module). For one embodiment, at least one of the processor(s) 1302 may be packaged together with the logic of one or more controllers of the control module 1304 to form a system-in-package (SiP). For one embodiment, at least one of the processor(s) 1302 may be integrated on the same die with the logic of one or more controllers of the control module 1304. For one embodiment, at least one of the processor(s) 1302 may be integrated on the same die with the logic of one or more controllers of the control module 1304 to form a system-on-chip (SoC).
[0209] In various embodiments, the apparatus 1300 may be, but is not limited to, a terminal device such as a server, a desktop computing device, or a mobile computing device (e.g., a laptop computing device, a handheld computing device, a tablet computer, a netbook, etc.). In various embodiments, the apparatus 1300 may have more or fewer components and / or a different architecture. For example, in some embodiments, the apparatus 1300 includes one or more cameras, a keyboard, a liquid crystal display (LCD) screen (including a touchscreen display), a non-volatile memory port, multiple antennas, a graphics chip, an application-specific integrated circuit (ASIC), and a speaker.
[0210] An embodiment of the present disclosure provides an electronic device, comprising: one or more processors; and one or more machine-readable media having instructions stored thereon, which, when executed by the one or more processors, enable the electronic device to perform one or more methods as disclosed herein.
[0211] As for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0212] The various embodiments in this specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referenced to each other.
[0213] The embodiments of the present disclosure are described with reference to the flowcharts and / or block diagrams of the methods, terminal devices (systems), and computer program products according to the embodiments of the present disclosure. It should be understood that each process and / or box in the flowchart and / or block diagram, and the combination of the processes and / or boxes in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable terminal device to produce a machine, so that the instructions executed by the processor of the computer or other programmable terminal device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0214] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable terminal device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0215] These computer program instructions can also be loaded onto a computer or other programmable terminal device so that a series of operating steps are executed on the computer or other programmable terminal device to produce a computer-implemented process, whereby the instructions executed on the computer or other programmable terminal device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0216] Although the preferred embodiments of the present disclosure have been described, those skilled in the art may make additional changes and modifications to these embodiments once they are aware of the basic creative concepts. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present disclosure.
[0217] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or terminal device that includes a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or terminal device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or terminal device that includes the element.
[0218] The above is a detailed introduction to the method and device for processing digital certificates provided by the present disclosure. Specific examples are used herein to illustrate the principles and implementation methods of the present disclosure. The description of the above embodiments is only used to help understand the method and core ideas of the present disclosure. At the same time, for those skilled in the art, according to the ideas of the present disclosure, there may be changes in the specific implementation methods and application scopes. In summary, the content of this specification should not be understood as a limitation on the present disclosure.
Claims
1. A method for processing digital certificates, wherein, Applied to a certificate control node, the method includes: Sending an application request to a certificate authority, where the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit a service node to provide data services; Receiving the first digital certificate returned by the certificate authority according to the application request; Distributing the first digital certificate to the service node.
2. The method according to claim 1, wherein, The method further includes: After receiving the first digital certificate returned by the certificate authority according to the application request, determining whether heartbeat information sent by the service node is received within a first preset duration before the current moment; When the heartbeat information sent by the service node is received within the first preset duration before the current moment, then distributing the first digital certificate to the service node.
3. The method according to claim 1 or 2, wherein The method further includes: Within a second preset duration after distributing the first digital certificate to the service node, detecting whether first deployment information sent by the service node is received, where the first deployment information is used to indicate that the first digital certificate has been deployed in the service node; When the first deployment information sent by the service node is not received, distributing the first digital certificate to the service node again.
4. The method according to claim 3, wherein The method further includes: When the first deployment information sent by the service node is not received within the second preset duration after distributing the first digital certificate to the service node multiple times, outputting a first warning message, where the first warning message is used to prompt that the first digital certificate cannot be deployed in the service node.
5. The method according to any one of claims 1 to 4, wherein The method further includes: When the remaining valid duration of the first digital certificate is less than a third preset duration, sending a renewal request for the first digital certificate to the certificate authority; Receiving a second digital certificate returned by the certificate authority according to the renewal request; the second digital certificate is used to authorize or permit the service node to provide data services; the effective expiration moment of the second digital certificate is later than that of the first digital certificate; Distributing the second digital certificate to the service node.
6. The method according to any one of claims 1 to 5, wherein The method further includes; When the remaining valid duration of the first digital certificate is less than a third preset duration, outputting a second warning message; The second warning message is used to prompt that the first digital certificate is about to expire or has expired.
7. A method for processing digital certificates, wherein, Applied to a service node, the method includes: Receiving the first digital certificate distributed by the certificate control node, where the first digital certificate is returned by the certificate authority to the certificate control node according to an application request after the certificate control node sends the application request to the certificate authority, the application request is used to apply for the first digital certificate, and the first digital certificate is used to authorize or permit the service node to provide data services; Deploying the first digital certificate in the service node.
8. The method according to claim 7, wherein The method further includes: Regularly sending heartbeat information to the certificate control node.
9. The method according to claim 7 or 8, wherein The method further includes: After deploying the first digital certificate in the service node, send first deployment information to the certificate control node, where the first deployment information is used to indicate that the first digital certificate has been deployed in the service node.
10. The method according to any one of claims 7 to 9, wherein The method further includes: Receiving a second digital certificate distributed by the certificate control node, where the second digital certificate is applied for by the certificate control node from the certificate authority when the remaining valid duration of the first digital certificate is less than a third preset duration, and the second digital certificate is used to authorize or permit the service node to provide data services; the effective expiration time of the second digital certificate is later than that of the first digital certificate; Deploying the second digital certificate in the service node.
11. A device for processing digital certificates, wherein, Applied to a certificate control node, the apparatus includes: A first sending module, configured to send an application request to a certificate authority, where the application request is used to apply for a first digital certificate, and the first digital certificate is used to authorize or permit a service node to provide data services; A first receiving module, configured to receive the first digital certificate returned by the certificate authority according to the application request; A first distributing module, configured to distribute the first digital certificate to the service node.
12. A device for processing digital certificates, wherein, Applied to a service node, the apparatus includes: A third receiving module, configured to receive the first digital certificate distributed by the certificate control node, where the first digital certificate is returned by the certificate authority to the certificate control node according to the application request after the certificate control node sends the application request to the certificate authority, the application request is used to apply for the first digital certificate, and the first digital certificate is used to authorize or permit the service node to provide data services; A first deployment module, configured to deploy the first digital certificate in the service node.
13. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, When the processor executes the program, it implements the method according to any one of claims 1 to 10.
14. A computer-readable storage medium, wherein, A computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the method according to any one of claims 1 to 10.
15. A computer program product, wherein, Including a computer program, and when the computer program is executed by a processor of a computer, it implements the method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Digital certificate managing method, device and system
CN105553671A
Certificate renewal and deployment
CN108370374A
Certificate processing method, certificate processing device and electronic equipment
CN110493234A
Digital certificate management method and device based on multiple CAs, equipment and storage medium
CN110932861A
Block chain certificate management method and device, electronic equipment and storage medium
CN116722989A