You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何验证AWS4-HMAC-SHA256签名?代理场景下IAM临时凭证验证难题

验证使用IAM角色临时凭证的AWS4签名请求

可行解决方案(无需修改ServiceA代码)

核心思路

利用AWS STS的GetCallerIdentity API结合AWS4签名验证,确认请求的调用者身份为RoleA(即ServiceA所扮演的角色)。临时凭证的会话token(x-amz-security-token)绑定特定身份,通过验证签名有效性+校验调用者ARN,即可完成身份确认。

具体步骤

  1. 提取请求中的AWS4签名相关信息
    从ServiceA的请求头中提取以下字段:

    • Authorization:包含签名、Access Key ID、签名算法等核心信息
    • x-amz-date:请求时间戳
    • x-amz-security-token:临时凭证的会话token
    • x-amz-content-sha256:请求体的哈希值(若请求带body则需提取)
  2. 验证AWS4签名的有效性
    使用AWS SDK提供的签名验证工具,直接基于请求中的签名信息完成合法性校验。以Python为例,借助botocore库实现:

    from botocore.auth import SigV4Auth
    from botocore.awsrequest import AWSRequest
    
    # 构造请求对象
    request = AWSRequest(
        method=request.method,
        url=request.url,
        headers=request.headers,
        body=request.body
    )
    
    # 从Authorization头解析Access Key ID
    auth_header = request.headers.get('Authorization')
    access_key_id = auth_header.split('Credential=')[1].split('/')[0]
    
    # 初始化SigV4验证器(服务类型和区域需与ServiceA签名时一致)
    sigv4 = SigV4Auth(
        {'access_key': access_key_id, 'secret_key': '', 'token': request.headers.get('x-amz-security-token')},
        'execute-api',  # 按ProxyService实际服务类型填写,如自定义服务可填任意匹配值
        'us-east-1'
    )
    
    # 执行签名验证
    try:
        sigv4.verify(request)
        signature_valid = True
    except Exception:
        signature_valid = False
    

    注:此步骤无需知晓ServiceA的临时Secret Key,verify方法会直接基于请求签名完成校验。

  3. 校验调用者身份
    签名验证通过后,调用STS的GetCallerIdentity API,传入提取到的会话token,获取调用者ARN并校验是否匹配RoleA:

    import boto3
    
    sts_client = boto3.client('sts')
    try:
        caller_identity = sts_client.get_caller_identity(
            Token=request.headers.get('x-amz-security-token')
        )
        caller_arn = caller_identity['Arn']
        # 检查ARN是否符合RoleA的假设角色格式
        if caller_arn.startswith('arn:aws:sts::YOUR_ACCOUNT_ID:assumed-role/RoleA/'):
            identity_valid = True
        else:
            identity_valid = False
    except Exception:
        identity_valid = False
    
  4. 最终准入判断
    仅当signature_valid和identity_valid均为True时,允许请求通过ProxyService。

权限配置要求

  • ProxyService的角色需拥有sts:GetCallerIdentity权限
  • RoleA的信任策略需明确限定仅ServiceA能扮演该角色,确保临时凭证的唯一性

内容的提问来源于stack exchange,提问作者Shelef

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.13 19:50:07