Incremental synchronization and verification method and system for access control authorization list
By pushing incremental data blocks from the server and combining them with multi-factor authentication, the issues of real-time performance and transmission efficiency of access control authorization lists were resolved. This enabled efficient and reliable data synchronization and verification, ensuring data consistency and security.
Patent Information
- Application Number
- CN202511769523.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-28
- Publication Date
- 2026-03-17
AI Technical Summary
In existing technologies, access control authorization lists suffer from low real-time performance, low transmission efficiency, and insufficient data consistency guarantees, failing to meet the requirements for millisecond-level response and large-volume data transmission, and also posing security risks such as data leakage and mis-sending.
The method of pushing incremental data blocks from the server and performing multi-factor data verification on the terminal is adopted. This includes version number increment, WebSocket long connection, rpcx framework and proto encoding, combined with list quantity, version continuity and hash signature verification to ensure data integrity and consistency.
It achieves millisecond-level response speed, improves data transmission efficiency, reduces data loss and error rates, and ensures the real-time performance and integrity of data transmission.
Smart Images

Figure CN121686618A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data synchronization technology, and in particular to an incremental synchronization and verification method and system for access control authorization lists. Background Technology
[0002] As intelligent access control systems increasingly demand real-time performance, security, and reliability, the need for millisecond-level authorization change response, efficient large-scale data transmission, and strong data consistency has become indispensable.
[0003] The widely used existing technology employs a "terminal-periodic polling" method to retrieve change lists. Specifically, the terminal proactively queries the server at fixed time intervals to check for data updates. This is supplemented by an asynchronous notification mechanism based on message queues to improve real-time performance, management of data changes based on version numbers / incremental identifiers, and data transmission using HTTP protocol + JSON format. This solution meets the basic requirements for managing and transmitting data updates, making the distribution of access control authorization lists possible.
[0004] However, existing technologies still have the following drawbacks:
[0005] Poor real-time performance: The timed polling mechanism relied upon by the terminal results in a significant delay in the reception of incremental data, which cannot truly meet the critical requirement of millisecond-level real-time response.
[0006] Low transmission efficiency: The HTTP protocol has high overhead in the header, and the JSON format serialization / deserialization is inefficient. In the case of large data volume (especially full list) transmission scenarios, it takes a long time and has low bandwidth utilization.
[0007] Insufficient data consistency assurance: It mainly relies on simple incremental identifiers or version numbers for verification, lacks an effective strong data integrity verification mechanism, and is difficult to reliably detect security risks such as missing or incorrect distribution of lists. Summary of the Invention
[0008] To overcome the aforementioned problems in the existing technology, this application provides an incremental synchronization and verification method and system for access control authorization lists, which adopts the following technical solution:
[0009] Firstly, this application provides a method for incremental synchronization and verification of access control authorization lists, including:
[0010] Initialize the terminal and server;
[0011] The server retrieves the list change data, increments the version number, and pushes it to the terminal device;
[0012] The terminal initiates an incremental request to the server based on the notification message and obtains the incremental data block in response from the server.
[0013] The terminal performs multi-factor data verification on incremental data blocks;
[0014] Perform cyclical synchronization of incremental data;
[0015] The terminal performs full consistency verification on incremental data.
[0016] Furthermore, the initialization terminal and server include:
[0017] Server initialization: Start list management, version number generator, and message push engine. The version number generator has a built-in Snowflake algorithm to ensure that the generated version number is globally unique and strictly monotonically increasing.
[0018] Terminal initialization: The data synchronization module initializes local_max_ver (local maximum version number) to 0;
[0019] The terminal establishes a long connection with the server: The terminal establishes a WebSocket long connection with the server's message push engine. The terminal will periodically send heartbeat packets to the server and automatically reconnect using an exponential backoff strategy when the connection is abnormally disconnected.
[0020] Furthermore, the terminal initiates an incremental request to the server based on the notification message and obtains the server's response incremental data block, specifically as follows:
[0021] After receiving the notification message, the terminal sends an incremental request to the server using the RPCX framework and proto encoding.
[0022] The incremental request includes:
[0023] last_sync_ver: The maximum version number on the terminal's local machine;
[0024] chunk_size: The size of the requested fixed data block.
[0025] Furthermore, the terminal performs multi-factor data verification on the incremental data block, including:
[0026] Perform list count and version continuity checks on incremental data blocks: Determine if the number of data entries in the incremental data block is the preset number of chunk_size. If the number of data entries in the incremental data block is the preset number, then perform a version continuity check to determine if the current version number is higher than the initial version number. If the current version number is higher than the initial version number, it proves that the version number conforms to monotonically increasing and the next step of verification can be performed. If the number of data entries in the incremental data block is not the preset number, or the current version number is not higher than the initial version number, then a retry mechanism needs to be entered to retry.
[0027] Furthermore, the terminal's multi-factor data verification of incremental data blocks also includes:
[0028] Hash signature verification of incremental data blocks: The server calculates the SHA-256 hash value of the incremental data block and sends it to the terminal as a chunk_signature protocol; after receiving the chunk_signature protocol, the terminal calculates the SHA-256 hash value of the received incremental data block and outputs it as a client_signature protocol. The hash values of the chunk_signature protocol and the client_signature protocol are compared. If they are different, it is considered that the transmission has failed. The terminal discards the currently received incremental data block and triggers the retry mechanism to retry.
[0029] Furthermore, the cyclic synchronization of incremental data specifically involves:
[0030] The incremental data block is requested repeatedly until the local version number local_max_ver on the terminal is equal to the maximum version number total_max_ver of the current full data on the server. Then the incremental loop synchronization is completed.
[0031] Furthermore, the terminal performs full consistency verification on the incremental data as follows:
[0032] The terminal requests the full hash from the server, along with the synchronization version number final_sync_ver;
[0033] After receiving the synchronization version number, the server calculates the overall hash value of all data with version numbers within the synchronization version number and returns it as the variable name server_full_hash;
[0034] The terminal calculates the overall hash value of all data within the same version number range as the variable name server_full_hash in local storage and outputs it as the variable name client_full_hash;
[0035] If the client_full_hash and server_full_hash match, the synchronization is successful; otherwise, the difference comparison and repair process is initiated to perform the repair.
[0036] Secondly, this application also provides an incremental synchronization and verification system for access control authorization lists, including:
[0037] Initialization module: Used to initialize the terminal and server;
[0038] Change information push module: The server retrieves the list change data, increments the version number, and pushes it to the terminal device;
[0039] Incremental Request Module: Used to initiate incremental requests to the server based on notification messages and obtain incremental data blocks from the server's response;
[0040] Multi-factor validation module: The terminal performs multi-factor data validation on incremental data blocks;
[0041] Circular synchronization module: performs cyclic synchronization of incremental data;
[0042] Full consistency verification module: Used to perform full consistency verification.
[0043] Thirdly, this application provides an electronic device, comprising:
[0044] One or more processors; a memory; and one or more computer programs, wherein the one or more computer programs are stored in the memory, and the one or more computer programs include instructions that, when executed by the device, cause the device to perform the method as described in the first aspect.
[0045] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when run on a computer, causes the computer to perform the method described in the first aspect.
[0046] This application has the following beneficial effects:
[0047] This application provides an incremental synchronization and verification method and system for access control authorization lists, including: initializing a terminal and a server; the server obtaining list change data, incrementing the version number, and pushing it to the terminal device; the terminal initiating an incremental request to the server based on a notification message and obtaining the server's response incremental data block; the terminal performing multi-factor data verification on the incremental data block; performing cyclic synchronization of the incremental data; and the terminal performing full consistency verification on the incremental data. It adopts real-time message notification and long-connection transmission from the server to replace the traditional polling mechanism, achieving millisecond-level response speed; it uses the RPCX protocol in conjunction with the proto binary format for data transmission, reducing protocol header overhead and improving serialization efficiency; and it introduces a multi-factor data verification mechanism, combining list quantity verification, incremental version number continuity verification, and full-text hash verification to construct a multi-layered data consistency guarantee system, avoiding data loss and mis-sending issues. Attached Figure Description
[0048] To more clearly illustrate the solutions in this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0049] Figure 1 This is an exemplary system architecture diagram to which embodiments of this application can be applied;
[0050] Figure 2 This is a flowchart illustrating the incremental synchronization and verification method for the access control authorization list in an embodiment of this application;
[0051] Figure 3 This is a flowchart illustrating the incremental synchronization and verification method for the access control authorization list in an embodiment of this application.
[0052] Figure 4 This is a flowchart illustrating multi-factor data validation of incremental data blocks in an embodiment of this application;
[0053] Figure 5 This is an experimental diagram comparing the performance gap between the technical solutions of this application and the prior art;
[0054] Figure 6 This is a schematic diagram of the incremental synchronization and verification system for the access control authorization list in an embodiment of this application;
[0055] Figure 7 This is a flowchart illustrating the incremental synchronization and verification system for the access control authorization list in an embodiment of this application.
[0056] Figure 8 This is a schematic diagram of a computer device according to an embodiment of this application. Detailed Implementation
[0057] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein in the specification of the application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application; the terms "comprising" and "having," and any variations thereof, in the specification, claims, and foregoing drawings of this application, are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification, claims, or foregoing drawings of this application are used to distinguish different objects, not to describe a particular order.
[0058] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0059] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.
[0060] like Figure 1 As shown, system architecture 100 may include terminal devices 101, 102, and 103, a network 104, and a server 105. Network 104 serves as the medium for providing communication links between terminal devices 101, 102, and 103 and server 105. Network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.
[0061] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Various communication client applications can be installed on terminal devices 101, 102, and 103, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social media platform software, etc.
[0062] Terminal devices 101, 102, and 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, e-book readers, MP3 players (Moving Picture Experts Group Audio Layer III), MP4 players (Moving Picture Experts Group Audio Layer IV), laptops, and desktop computers, etc.
[0063] Server 105 can be a server that provides various services, such as a backend server that supports the pages displayed on terminal devices 101, 102, and 103.
[0064] It should be noted that the incremental synchronization and verification method for access control authorization lists provided in this application is generally executed by a server / terminal device, and correspondingly, an incremental synchronization and verification system for access control authorization lists is generally set up in the server / terminal device.
[0065] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0066] Example 1
[0067] Continue to refer to Figure 2The figure shows a flowchart of an incremental synchronization and verification method for an access control authorization list according to this application. The method includes the following steps:
[0068] 201. Initialize the terminal and server;
[0069] Specifically, server initialization includes starting the list management, version number generator, and message push engine.
[0070] It should be noted that the version number generator has a built-in Snowflake algorithm to ensure that the generated version number is globally unique and strictly monotonically increasing.
[0071] Terminal initialization: The data synchronization module initializes local_max_ver (local maximum version number) to 0;
[0072] Establish a long connection between the terminal and the server: The terminal establishes a WebSocket long connection with the server's message push engine;
[0073] It should be noted that the terminal will send heartbeat packets to the server periodically (e.g., every 30 seconds) and automatically reconnect using an exponential backoff strategy when the connection is abnormally disconnected.
[0074] 202. The server retrieves the list change data, increments the version number, and pushes it to the terminal device.
[0075] Continue to refer to Figure 3 Specifically, the server performs list data change detection, obtains the changed list data, generates a version number identifier based on the changed list, and then the server's message push engine pushes a notification message to the terminal device through the established long connection channel.
[0076] It should be noted that, in this embodiment of the application, the notification message includes an identifier of the data version range involved in the change;
[0077] 203. The terminal initiates an incremental request to the server based on the notification message and obtains the incremental data block in response from the server.
[0078] Specifically, after receiving the notification message, the terminal sends an incremental request to the server using the RPCX framework and proto encoding.
[0079] The incremental request includes:
[0080] last_sync_ver: The maximum version number on the terminal's local machine;
[0081] chunk_size: The size of the requested fixed data block (e.g., 500 data blocks).
[0082] It should be noted that both incremental request data and server response data are transmitted through the rpcx framework and are serialized into binary format using Protocol Buffers (proto).
[0083] Compared to the traditional HTTP+JSON encoding method, the above encoding method reduces data volume and CPU overhead for serialization / deserialization; in addition, the rpcx framework compresses the protocol header and supports multiplexing requests on long connections, avoiding the overhead of frequently establishing connections.
[0084] 204. The terminal performs multi-factor data verification on the incremental data block;
[0085] like Figure 4 As shown, in Embodiment 204 of this application, the terminal performs multi-factor data verification on incremental data blocks, including:
[0086] Perform list count and version continuity checks on incremental data blocks: Determine if the number of data entries in the incremental data block is the preset number of chunk_size. If the number of data entries in the incremental data block is the preset number, then perform version continuity checks to determine if the current version number is higher than the initial version number. If the current version number is higher than the initial version number, it proves that the version number conforms to monotonically increasing and can proceed to the next step of verification. If the number of data entries in the incremental data block is not the preset number, or the current version number is not higher than the initial version number, then the retry mechanism needs to be entered for retry.
[0087] Hash signature verification of incremental data blocks: The server calculates the SHA-256 hash value of the incremental data block and sends it to the terminal as a chunk_signature protocol; After receiving the chunk_signature protocol, the terminal calculates the SHA-256 hash value of the received incremental data block and outputs it as a client_signature protocol. The hash values of the chunk_signature protocol and the client_signature protocol are compared. If they are different, it is considered that the transmission has failed. The terminal discards the currently received incremental data block and triggers the retry mechanism to retry.
[0088] For incremental data blocks that pass the verification of list quantity, version continuity, and hash signature, the incremental data blocks are deduplicated and persisted to local storage with the version number as the primary key, and the local_max_ver variable name of the terminal is updated to the data pointed to by the batch_max_ver variable name of the received data.
[0089] In this embodiment, multi-factor data verification is used. First, the basic integrity of the data is initially verified. Then, hash signature verification is used to verify whether the data has been tampered with during transmission. Finally, the data block is deduplicated and persisted to local storage with the version number as the primary key to prevent data loss.
[0090] 205. Perform cyclical synchronization of incremental data;
[0091] Specifically, repeat steps 203 and 204 to request incremental data blocks in a loop until the terminal's local version number local_max_ver is equal to the server's current maximum version number total_max_ver of the full data. Then, the incremental loop synchronization is complete.
[0092] 206. The terminal performs a full consistency verification on the incremental data;
[0093] Specifically, the terminal requests the full hash from the server, carrying the synchronization version number final_sync_ver;
[0094] After receiving the synchronization version number, the server calculates the overall hash value of all data with version numbers within and including the synchronization version number, and returns it as the variable name server_full_hash;
[0095] The terminal calculates the overall hash value of all data within the same version number range as the variable name server_full_hash in local storage and outputs it as the variable name client_full_hash;
[0096] If the client_full_hash and server_full_hash match, the synchronization is successful; otherwise, the difference comparison and repair process is initiated to perform the repair.
[0097] like Figure 5 As shown in the embodiments of this application, the long connection established between the terminal and the server is used to transmit message notification response speed to the millisecond level, and the data transmission efficiency is also improved. Furthermore, the use of a multi-factor verification mechanism for multiple verifications ensures data integrity; the data loss and missending rate is reduced by more than 99%.
[0098] Core code
[0099] (a) Server-side message notification
[0100] / / Real-time message notification implementation
[0101] func (s *Server) NotifyDataChange(deviceID string, changeRangeVersionRange) error {
[0102] if conn, ok := s.connections[deviceID]; ok {
[0103] return conn.SendMessage(Message{
[0104] Type: "data_change",
[0105] Range: changeRange,
[0106] Timestamp: time.Now().UnixMilli(),
[0107] })
[0108] }
[0109] return errors.New("device not connected")
[0110] }
[0111] (ii) Multi-factor validation logic
[0112] / / Core logic for data validation
[0113] func (c *Client) validateDataChunk(chunk *DataChunk) error {
[0114] / / Factor 1: List Quantity Verification
[0115] if len(chunk.Records) == 0 && chunk.HasMore {
[0116] return errors.New("empty chunk but has more data")
[0117] }
[0118] if len(chunk.Records) != chunk_size {
[0119] return errors.New("unexpected chunk data size")
[0120] }
[0121] / / Factor 2: Version Number Continuity Verification
[0122] if chunk.BatchMaxVer <= c.localMaxVer {
[0123] return errors.New("version regression detected")
[0124] }
[0125] / / Factor 3: Hash Signature Verification
[0126] expectedHash := c.calculateChunkHash(chunk.Records)
[0127] if !bytes.Equal(expectedHash, chunk.Signature) {
[0128] return errors.New("hash mismatch")
[0129] }
[0130] return nil
[0131] }
[0132] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This computer program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the methods described above. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, optical disk, or read-only memory (ROM), or random access memory (RAM).
[0133] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0134] Continue to refer to Figure 6 , 7 The incremental synchronization and verification system for access control authorization lists described in this embodiment includes:
[0135] Initialization module 101: Used to initialize the terminal and server;
[0136] Change information push module 102: The server obtains the list change data, increments the version number, and pushes it to the terminal device;
[0137] Incremental request module 103: used to initiate an incremental request to the server based on the notification message and obtain the incremental data block in response from the server;
[0138] Multi-factor verification module 104: The terminal performs multi-factor data verification on the incremental data block;
[0139] Circular synchronization module 105: performs cyclic synchronization of incremental data;
[0140] Full consistency verification module 106: Used for performing full consistency verification;
[0141] In this embodiment of the application, the initialization module includes:
[0142] Server-side initialization unit: used to start the list management, version number generator, and message push engine;
[0143] Terminal initialization unit: used to initialize local_max_ver (local maximum version number) to 0 using the data synchronization module;
[0144] Long connection establishment unit: Used for establishing a WebSocket long connection between the terminal and the server's message push engine.
[0145] It should be noted that the version number generator has a built-in Snowflake algorithm to ensure that the generated version number is globally unique and strictly monotonically increasing;
[0146] In this embodiment of the application, the incremental request module includes:
[0147] Incremental Request Unit: Sends incremental requests to the server using the rpcx framework and proto encoding.
[0148] It should be noted that both incremental request data and server response data are transmitted through the rpcx framework and are serialized into binary format using Protocol Buffers (proto).
[0149] In this embodiment of the application, the multi-factor verification module includes:
[0150] List Quantity and Version Continuity Verification Unit: Performs list quantity and version continuity verification on incremental data blocks: Determines whether the number of data entries in the incremental data block is the preset number of chunk_size. If the number of data entries in the incremental data block is the preset number, then performs version continuity verification, determining whether the current version number is higher than the initial version number. If the current version number is higher than the initial version number, it proves that the version number conforms to monotonically increasing and can proceed to the next step of verification. If the number of data entries in the incremental data block is not the preset number, or the current version number is not higher than the initial version number, then the retry mechanism needs to be entered for retry.
[0151] Hash Signature Verification Unit: Performs hash signature verification on incremental data blocks: The server calculates the SHA-256 hash value of the incremental data block and sends it to the terminal as a chunk_signature protocol; After receiving the chunk_signature protocol, the terminal performs SHA-256 hashing on the received incremental data block and outputs it as a client_signature protocol. It compares whether the hash values of the chunk_signature protocol and the client_signature protocol are the same. If they are different, it is considered that the transmission has failed, the terminal discards the currently received incremental data block, and triggers the retry mechanism to retry.
[0152] Storage unit: Used to deduplicatize incremental data blocks that have passed the list count, version continuity, and hash signature verification, persist the incremental data blocks to local storage with the version number as the primary key, and update the local variable name of the terminal to the data pointed to by the batch_max_ver variable name of the received data.
[0153] In this embodiment of the application, the full consistency verification module includes:
[0154] Server-wide hash acquisition unit: After receiving the synchronization version number, calculate the overall hash value of all data with version numbers within the synchronization version number (inclusive), and return it as the variable name server_full_hash;
[0155] Terminal overall hash acquisition unit: Calculates the overall hash value of all data in the same version number range as the variable name server_full_hash in local storage and outputs it as the variable name client_full_hash;
[0156] Hash value comparison unit: Compare client_full_hash and server_full_hash. If they match, the synchronization is successful; if they do not match, the difference comparison and repair process is initiated to perform the repair.
[0157] To address the aforementioned technical problems, embodiments of this application also provide a computer device. Please refer to [link / reference needed]. Figure 8 , Figure 8 This is a basic structural block diagram of the computer device in this embodiment.
[0158] The computer device 8 includes a memory 8a, a processor 8b, and a network interface 8c that are interconnected via a system bus. It should be noted that only the computer device 8 with components 8a-8c is shown in the figure; however, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Those skilled in the art will understand that the computer device described here is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.
[0159] The computer device can be a desktop computer, laptop, handheld computer, or cloud server, etc. The computer device can interact with the user via a keyboard, mouse, remote control, touchpad, or voice control.
[0160] The memory 8a includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the memory 8a may be an internal storage unit of the computer device 8, such as the hard disk or memory of the computer device 8. In other embodiments, the memory 8a may also be an external storage device of the computer device 8, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the computer device 8. Of course, the memory 8a may include both the internal storage unit and its external storage device of the computer device 8. In this embodiment, the memory 8a is typically used to store the operating system and various application software installed on the computer device 8, such as the program code of an incremental synchronization and verification method for an access control authorization list. In addition, the memory 8a can also be used to temporarily store various types of data that have been output or will be output.
[0161] In some embodiments, the processor 8b may be a central processing unit (CPU), controller, microcontroller, microprocessor, or other data processing chip. The processor 8b is typically used to control the overall operation of the computer device 8. In this embodiment, the processor 8b is used to run program code stored in the memory 8a or process data, for example, to run the program code for the incremental synchronization and verification method of the access control authorization list.
[0162] The network interface 8c may include a wireless network interface or a wired network interface, which is typically used to establish communication connections between the computer device 8 and other electronic devices.
Claims
1. A method for incremental synchronization and verification of an access authorization list, characterized by the steps of The method comprises the following steps: initializing the terminal and the server; the server acquires the list change data to increase the version number and pushes it to the terminal device; the terminal initiates an incremental request to the server according to a notification message and acquires an incremental data block responded by the server; the terminal performs multi-factor data verification on the incremental data block; cyclic synchronization is performed on the incremental data; the terminal performs full-amount consistency verification on the incremental data.
2. The method of claim 1, wherein the method further comprises: The initialization of the terminal and the server comprises the following steps: server initialization: starting the list management, the version number generator and the message pushing engine, the version number generator is internally provided with a Snowflake algorithm to ensure that the generated version number is globally unique and strictly monotonically increasing; terminal initialization: the data synchronization module initializes the local_max_ver (local maximum version number) to 0; establishing a long connection between the terminal and the server: the terminal establishes a WebSocket long connection with the message pushing engine of the server, the terminal will periodically send a heartbeat packet to the server, and when the connection is abnormally disconnected, the exponential backoff strategy is used to automatically reconnect.
3. The method of claim 2, wherein the method further comprises: The terminal initiates an incremental request to the server according to a notification message and acquires an incremental data block responded by the server, specifically as follows: after receiving the notification message, the terminal sends an incremental request to the server through the rpcx framework and the proto encoding mode; the incremental request comprises: last_sync_ver: the maximum version number of the terminal locally; chunk_size: the fixed data block size of the request.
4. The method of claim 3, wherein the method further comprises: The multi-factor data verification of the terminal on the incremental data block comprises the following steps: list quantity and version continuity verification on the incremental data block: it is judged whether the data quantity of the incremental data block is the preset quantity of chunk_size, if the data quantity of the incremental data block is the preset quantity, the version continuity is judged, it is judged whether the current version number is higher than the initial version number, if the current version number is higher than the initial version number, it is proved that the version number meets the monotonic increasing requirement and the next step of verification is performed, if the data quantity of the incremental data block is not the preset quantity or the current version number is not higher than the initial version number, a retry mechanism needs to be entered for retry.
5. The method of claim 4, wherein the method further comprises: The multi-factor data verification of the terminal on the incremental data block further comprises the following steps: hash signature verification on the incremental data block: the server calculates the SHA-256 hash value of the incremental data block and sends it to the terminal as a chunk_signature protocol; after receiving the chunk_signature protocol, the terminal calculates the SHA-256 hash value of the received incremental data block and outputs it as a client_signature protocol, and compares the hash values of the chunk_signature protocol and the client_signature protocol, if they are not the same, it is considered that an error occurs, the terminal discards the currently received incremental data block and triggers a retry mechanism for retry.
6. The method of claim 5, wherein the method further comprises: The cyclic synchronization of the incremental data comprises the following steps: The terminal requests the incremental data in a loop until the local version number local_max_ver is equal to the current total data maximum version number total_max_ver of the server, and then the loop synchronization is completed.
7. The method of claim 6, wherein the method further comprises: The terminal performs total consistency verification on the incremental data, and the total consistency verification specifically comprises: The terminal requests the total hash from the server and carries the synchronization version number final_sync_ver. After the server receives the synchronization version number, the server calculates the overall hash value of the data with all version numbers within the synchronization version number, and returns the overall hash value in the form of a variable server_full_hash. The terminal calculates the overall hash value of all data within the same version number range as the variable server_full_hash, and outputs the overall hash value in the form of a variable client_full_hash. The terminal compares the client_full_hash with the server_full_hash, and if the two are consistent, the synchronization is successful; if the two are inconsistent, the difference comparison and repair process is started to perform repair.
8. A system for incremental synchronization and verification of an access authorization list, characterized in that, The method comprises the following steps: An initialization module is configured to initialize the terminal and the server; A change information pushing module is configured to obtain the name change data from the server, increment the version number, and push the name change data to the terminal device; An incremental request module is configured to initiate an incremental request to the server according to a notification message, and obtain the incremental data block from the server; A multi-factor verification module is configured to perform multi-factor data verification on the incremental data block; A loop synchronization module is configured to perform loop synchronization on the incremental data; A total consistency verification module is configured to perform total consistency verification.
9. An electronic device, comprising: The device comprises: one or more processors; a memory; and one or more computer programs, wherein the one or more computer programs are stored in the memory, and the one or more computer programs comprise instructions, which, when executed by the device, cause the device to perform the steps of the incremental synchronization and verification method of the access control authorization list according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer readable storage medium stores a computer program, which, when executed on a computer, causes the computer to perform the steps of the incremental synchronization and verification method of the access control authorization list according to any one of claims 1 to 7.
Citation Information
Cited By
Smart community visitor reservation and dynamic authorization management method and system
CN121938073A