Access method and apparatus of client device, electronic device and storage medium
By introducing a universal access interface between the business server and customer devices, and establishing a connection by calling this interface based on the authentication result, the problem of high difficulty in customer device access is solved, and low-cost device access and scalability are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- APOLLO INTELLIGENT CONNECTIVITY (BEIJING) TECH CO LTD
- Filing Date
- 2021-10-20
- Publication Date
- 2026-07-24
AI Technical Summary
Due to the diverse types, formats, and storage methods of business data, the development of customer devices connecting to business servers in existing technologies is difficult and costly.
By introducing a common access interface between the business server and the client device, and establishing a connection by calling this interface based on the authentication result, the client device can access the system.
It reduces the development difficulty and cost of device access, has good scalability, and is suitable for access scenarios of different customer devices.
Smart Images

Figure CN114117439B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of computer technology, and in particular to a method, apparatus, electronic device, storage medium, and computer program product for accessing a client device. Background Technology
[0002] Currently, with the continuous development of internet technology, there are many types of business data. For example, in the field of intelligent transportation, business data includes vehicle driving data, map data, pedestrian data, road construction data, weather data, etc. The formats of business data are also diverse, including text, images, audio, and video. Correspondingly, there are also many ways to store business data. In existing technologies, due to the variety of business data types, formats, and storage methods, business servers often need to connect to multiple client devices, resulting in high development difficulty and cost for device integration. Summary of the Invention
[0003] This disclosure provides a method, apparatus, electronic device, storage medium, and computer program product for accessing a customer device.
[0004] According to one aspect of this disclosure, a method for accessing a client device is provided, applied to a business server. The method includes: obtaining the authentication result of an authenticated object, wherein the authenticated object is a client device or a business server; in response to the authentication result indicating that the authenticated object has passed authentication, invoking a general access interface; and establishing a connection between the business server and the client device based on the general access interface.
[0005] According to another aspect of this disclosure, another access method for a client device is provided, applied to a client device, the method comprising: obtaining device identification information and a first authentication policy of the client device itself; sending the device identification information and the first authentication policy to a service server, wherein the device identification information is used to obtain a second authentication policy, the first authentication policy and the second authentication policy are used to generate an authentication result of the client device, and the authentication result is used to indicate whether to invoke a general access interface.
[0006] According to another aspect of this disclosure, another access method for a client device is provided, applied to a client device, the method comprising: receiving a second authentication policy sent by a service server; obtaining a first authentication policy of the client device itself; generating an authentication result of the service server based on the first authentication policy and the second authentication policy; and sending the authentication result to the service server.
[0007] According to another aspect of this disclosure, an access device for a client device is provided, comprising: a first acquisition module, configured to acquire the authentication result of an authenticated object, wherein the authenticated object is a client device or a service server; an invocation module, configured to invoke a general access interface in response to the authentication result indicating that the authenticated object has passed authentication; and an access module, configured to establish a connection between the service server and the client device based on the general access interface.
[0008] According to another aspect of this disclosure, another access device for a client device is provided, comprising: an acquisition module for acquiring device identification information and a first authentication policy of the client device itself; and a sending module for sending the device identification information and the first authentication policy to a service server, wherein the device identification information is used to acquire a second authentication policy, the first authentication policy and the second authentication policy are used to generate an authentication result of the client device, and the authentication result is used to indicate whether to invoke a general access interface.
[0009] According to another aspect of this disclosure, another access device for a client device is provided, comprising: a receiving module for receiving a second authentication policy sent by a service server; an obtaining module for obtaining a first authentication policy of the client device itself; a generating module for generating an authentication result of the service server based on the first authentication policy and the second authentication policy; and a sending module for sending the authentication result to the service server.
[0010] According to another aspect of this disclosure, a service server is provided, including an access device for a client device.
[0011] According to another aspect of this disclosure, a client equipment is provided, including an access device for the client equipment.
[0012] According to another aspect of this disclosure, another client device is provided, including an access device for the client device.
[0013] According to another aspect of this disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform a client device access method.
[0014] According to another aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are used to cause the computer to perform an access method for a client device.
[0015] According to another aspect of this disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps of a client device access method.
[0016] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description
[0017] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein:
[0018] Figure 1 This is a flowchart illustrating a method for accessing a client device according to a first embodiment of the present disclosure;
[0019] Figure 2 This is a schematic flowchart of a client equipment access method according to a second embodiment of the present disclosure;
[0020] Figure 3 This is a flowchart illustrating a method for accessing a client device according to a third embodiment of the present disclosure;
[0021] Figure 4 This is a flowchart illustrating a method for accessing a client device according to the fourth embodiment of this disclosure;
[0022] Figure 5 This is a schematic flowchart of a client equipment access method according to the fifth embodiment of this disclosure;
[0023] Figure 6 This is a flowchart illustrating a method for accessing a client device according to the sixth embodiment of this disclosure;
[0024] Figure 7 This is a schematic flowchart of a data access method according to a first embodiment of the present disclosure;
[0025] Figure 8 This is a block diagram of an access device for a client equipment according to a first embodiment of the present disclosure;
[0026] Figure 9 This is a block diagram of an access device for a client equipment according to a second embodiment of the present disclosure;
[0027] Figure 10 This is a block diagram of an access device for a client equipment according to a third embodiment of the present disclosure;
[0028] Figure 11 This is a block diagram of a service server according to a first embodiment of the present disclosure;
[0029] Figure 12This is a block diagram of a client device according to a first embodiment of the present disclosure;
[0030] Figure 13 This is a block diagram of a client device according to a second embodiment of the present disclosure;
[0031] Figure 14 This is a block diagram of an electronic device used to implement the access method of a client device according to embodiments of the present disclosure. Detailed Implementation
[0032] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0033] Artificial intelligence (AI) is a technical science that studies and develops theories, methods, technologies, and application systems to simulate, extend, and expand human intelligence. Currently, AI technology has the advantages of high automation, high accuracy, and low cost, and has been widely applied.
[0034] Intelligent Traffic (IT) is a comprehensive transportation system that effectively integrates advanced science and technology (information technology, computer technology, data communication technology, sensor technology, electronic control technology, automatic control theory, operations research, artificial intelligence, etc.) into transportation, service control, and vehicle manufacturing. It strengthens the connection between vehicles, roads, and users, thereby forming a comprehensive transportation system that ensures safety, improves efficiency, improves the environment, and saves energy.
[0035] The basic purpose of data processing is to extract and derive valuable and meaningful data from large amounts of potentially messy and incomprehensible data. This includes data collection, storage, retrieval, processing, transformation, and transmission.
[0036] Figure 1 This is a flowchart illustrating a method for accessing a client device according to a first embodiment of the present disclosure.
[0037] like Figure 1 As shown, the access method for a client device according to the first embodiment of this disclosure includes:
[0038] S101, obtain the authentication result of the authenticated object, where the authenticated object is a client device or a business server.
[0039] It should be noted that the execution entity of the client device access method in this embodiment is a service server. It is understood that a service server refers to a server capable of providing service to the client device. It should be noted that there are no excessive limitations on the types of service servers, client devices, and service providers. For example, client devices include, but are not limited to, APPs (Applications), web pages, terminals, etc., wherein terminals include, but are not limited to, mobile phones, computers, smart voice interaction devices, smart home appliances, and in-vehicle terminals. Service providers include, but are not limited to, data access, data transmission, and data storage.
[0040] In the embodiments of this disclosure, the service server can obtain the authentication result of the authenticated object, wherein the authenticated object is a client device or a service server.
[0041] In one implementation, the object to be authenticated is a client device. The client device can initiate an authentication request to the service server, and the service server can obtain the authentication result of the client device.
[0042] In one implementation, the object to be authenticated is a service server. The service server can initiate an authentication request to the client device, and the client device can obtain the authentication result from the service server and send the authentication result back to the service server. Correspondingly, the service server can receive the authentication result sent by the client device.
[0043] It should be noted that the specific authentication method can be set according to the actual situation, and no further restrictions are imposed here.
[0044] S102, in response to the authentication result indicating that the authenticated object has passed authentication, the general access interface is invoked.
[0045] In the embodiments of this disclosure, the service server can respond to the authentication result indicating that the authenticated object has passed authentication, signifying that the authenticated object has access permissions, and can then call the general access interface. It should be noted that the general access interface can be configured according to actual conditions, and is not limited here; the general access interface is applicable to different client devices.
[0046] In one implementation, in intelligent transportation application scenarios, a general access interface can be set according to the national standard GAT1400 view library specification.
[0047] In one implementation, the object being authenticated is a client device. The service server can respond to the authentication result by instructing the client device to pass the authentication, indicating that the client device has the permission to access the service server, and can then call the general access interface.
[0048] In one implementation, the object being authenticated is a business server. The business server can respond to the authentication result indicating that it has the right to access the client device, and can then call the general access interface.
[0049] S103 establishes a connection between the business server and the customer equipment based on the general access interface.
[0050] In the embodiments of this disclosure, the service server can establish a connection between the service server and the client equipment based on a general access interface, that is, the service server can access the client equipment based on a general access interface.
[0051] In summary, the client device access method according to the embodiments of this disclosure can obtain the authentication result of the authenticated object, which can be a client device or a service server. In response to the authentication result indicating that the authenticated object has passed authentication, a general access interface is invoked, and a connection is established between the service server and the client device based on the general access interface. Therefore, the service server can access the client device through the general access interface, which is applicable to access scenarios of different client devices, has good scalability, and greatly reduces the development difficulty and cost of device access.
[0052] Figure 2 This is a flowchart illustrating a method for accessing a client device according to a second embodiment of the present disclosure.
[0053] like Figure 2 As shown, the access method for a client device according to the second embodiment of this disclosure includes:
[0054] S201, Receive the device identification information and first authentication policy of the customer device sent by the customer device.
[0055] In the embodiments of this disclosure, the object to be authenticated is a client device. The service server can receive the client device's device identification information and a first authentication policy sent by the client device.
[0056] In the embodiments of this disclosure, device identification information can be pre-set for customer devices to distinguish different customer devices. It should be noted that the type of device identification information is not limited in many ways; for example, device identification information includes, but is not limited to, characters, text, etc.
[0057] In the embodiments of this disclosure, a first authentication policy can be pre-set for the client equipment, and different client equipment can correspond to different first authentication policies.
[0058] S202, Based on the device identification information, obtain the matching second authentication policy from the authentication policy database.
[0059] In the embodiments of this disclosure, an authentication policy database can be pre-configured according to actual conditions. This database stores second authentication policies for at least one client device. It is understood that different client devices may correspond to different second authentication policies. Furthermore, the service server can retrieve a matching second authentication policy from the authentication policy database based on device identification information.
[0060] In one implementation, a mapping relationship or mapping table between the second authentication policy and device identification information can be pre-established. After obtaining the device identification information, the mapping relationship or mapping table is queried to determine the second authentication policy mapped to the device identification information, and this second authentication policy is used as the matching second authentication policy. It should be noted that the mapping relationship or mapping table can be set according to the actual situation, and no further limitations are imposed here. The mapping relationship or mapping table can be set in the storage space of the business server.
[0061] S203, based on the first authentication strategy and the second authentication strategy, obtain the authentication result of the customer's device.
[0062] In the embodiments of this disclosure, the service server can obtain the authentication result of the client device based on the first authentication strategy and the second authentication strategy.
[0063] In one implementation, obtaining the authentication result of the client device based on the first authentication strategy and the second authentication strategy may include comparing the first authentication strategy and the second authentication strategy. If the first authentication strategy and the second authentication strategy are consistent, the authentication result of the client device can be obtained as the client device has passed authentication; or, if the first authentication strategy and the second authentication strategy are inconsistent, the authentication result of the client device can be obtained as the client device has failed authentication.
[0064] In one implementation, obtaining the authentication result of the client device based on the first authentication strategy and the second authentication strategy may include executing the corresponding authentication process based on the first authentication strategy and the second authentication strategy to obtain the authentication result of the client device. It should be noted that the authentication process can be set according to the actual situation, and no further limitations are imposed here.
[0065] S204, in response to the authentication result indicating that the client equipment has passed authentication, invokes the general access interface.
[0066] S205 establishes a connection between the business server and customer equipment based on a general access interface.
[0067] The details of steps S204-S205 can be found in the above embodiments and will not be repeated here.
[0068] In summary, according to the client device access method of this disclosure, the client device receives device identification information and a first authentication policy sent by the client device; based on the device identification information, a matching second authentication policy is obtained from the authentication policy database; and based on the first and second authentication policies, the authentication result of the client device is obtained. Therefore, when the object to be authenticated is a client device, the service server can automatically obtain the authentication result of the client device based on the first and second authentication policies.
[0069] Figure 3 This is a flowchart illustrating a method for accessing a client device according to a third embodiment of the present disclosure.
[0070] like Figure 3 As shown, the access method for a client device according to the third embodiment of this disclosure includes:
[0071] S301, Obtain the device identification information of the customer's equipment.
[0072] In the embodiments of this disclosure, the object being authenticated is a service server. The service server can obtain the device identification information of the client device. It should be noted that the aforementioned client device refers to the client device that the service server needs to access.
[0073] In the embodiments of this disclosure, the device identification information of the customer device can be pre-set in the storage space of the business server so that the business server can obtain the device identification information of the customer device from its own storage space.
[0074] S302, based on the device identification information, retrieve the matching second authentication policy from the authentication policy database, wherein the second authentication policy is used by the customer device to obtain the authentication result of the business server.
[0075] The details of step S302 can be found in the above embodiments and will not be repeated here.
[0076] S303 sends a second authentication policy to the client equipment.
[0077] S304: Receive the authentication result from the service server sent by the client equipment.
[0078] In the embodiments of this disclosure, the service server may send a second authentication policy to the client device. The second authentication policy is used by the client device to obtain the authentication result of the service server and to receive the authentication result of the service server sent by the client device.
[0079] S305: In response to the authentication result indicating that the business server has passed authentication, the general access interface is invoked.
[0080] S306 establishes a connection between the business server and customer equipment based on a general access interface.
[0081] The details of steps S305-S306 can be found in the above embodiments and will not be repeated here.
[0082] In summary, the client device access method according to the embodiments of this disclosure can obtain a matching second authentication policy from the authentication policy database based on the client device's device identification information, send the second authentication policy to the client device, and receive the authentication result from the service server sent by the client device. Therefore, when the object to be authenticated is a service server, the service server can send the second authentication policy to the client device and receive the authentication result from the service server sent by the client device, thus enabling automatic acquisition of the service server's authentication result.
[0083] Figure 4 This is a flowchart illustrating a method for accessing a client device according to a fourth embodiment of the present disclosure.
[0084] like Figure 4 As shown, the access method for a client device according to the fourth embodiment of this disclosure includes:
[0085] S401, obtain the authentication result of the authenticated object, where the authenticated object is a client device or a business server.
[0086] S402, in response to the authentication result indicating that the authenticated object has passed authentication, the general access interface is invoked.
[0087] S403 establishes a connection between the business server and the customer equipment based on a general access interface.
[0088] The details of steps S401-S403 can be found in the above embodiments and will not be repeated here.
[0089] S404 sends the first data identification information of the data to be stored to the client equipment.
[0090] In the embodiments of this disclosure, the service server may send first data identification information of the data to be stored to the client device. It should be noted that the data to be stored is stored in the client device's storage space, and the data to be stored refers to the data that the service server needs to store.
[0091] In the embodiments of this disclosure, the type of data to be stored can be set according to the actual situation, and no further limitations are imposed here. For example, in intelligent transportation application scenarios, the types of data to be stored include, but are not limited to, text, images, audio, and video.
[0092] In embodiments of this disclosure, a first data identification information can be pre-set for the data to be stored to distinguish different data to be stored. It should be noted that the type of the first data identification information is not overly limited; for example, the first data identification information includes, but is not limited to, characters, text, etc. In one embodiment, the first data identification information is the identification information of the storage location of the data to be stored in the client device.
[0093] The S405 receives the data to be stored identified by the first data identification information sent by the client equipment through the general access interface, and stores the received data to be stored locally.
[0094] In the embodiments of this disclosure, the service server can receive the data to be stored identified by the first data identification information sent by the client equipment through a general access interface, and store the received data to be stored locally for subsequent service provision.
[0095] In one implementation, storage space for the data to be stored can be pre-configured in the business server. It should be noted that the type of storage space for the data to be stored can be set according to actual needs, and is not limited here. For example, the type of storage space for the data to be stored includes, but is not limited to, relational databases, distributed file databases, etc.
[0096] S406, in response to not receiving the data to be stored from the client equipment, adds the first data identification information of the data to be stored to the data compensation list.
[0097] S407, perform compensation storage on the data to be stored corresponding to the first data identifier information in the data compensation list.
[0098] In the embodiments of this disclosure, a data compensation list can be preset, which is used to store the first data identification information of the data to be stored that failed to be stored.
[0099] In embodiments of this disclosure, the service server may, in response to not receiving data to be stored sent by the client device, add the first data identifier information of the data to be stored to the data compensation list, update the data compensation list in real time, and perform compensation storage on the data to be stored corresponding to the first data identifier information in the data compensation list, so as to compensate for the data to be stored that failed to be stored.
[0100] In one implementation, compensating and storing the data to be stored corresponding to the first data identifier information in the data compensation list may include obtaining the first data identifier information in the data compensation list, sending the first data identifier information to the client device, and if the data to be stored sent by the client device is received, it indicates that the compensation and storage is successful at this time; if the data to be stored is not received from the client device, it indicates that the compensation and storage has failed at this time.
[0101] In one implementation, the service server may also obtain compensation storage results, wherein the compensation storage results include the number of successful compensation storage attempts and / or the number of failed compensation storage attempts.
[0102] Once a data compensation storage is successfully identified, the first data identifier information of the data to be stored is removed from the data compensation list. This allows for timely removal of the first data identifier information of successfully compensated data from the data compensation list, thus updating the data compensation list in real time.
[0103] The system identifies when the number of failed data storage attempts reaches a first preset threshold and sends an alert message to notify the user of the abnormal data storage. It should be noted that the first preset threshold can be set according to actual conditions; no specific limitations are imposed here, but it could be set to three times. Therefore, when the number of failed data storage attempts reaches a high threshold, an alert message can be sent to promptly notify the user of the abnormal data storage.
[0104] In one implementation, the service server can detect network parameters, where the values of these parameters are positively correlated with the service server's network bandwidth. If a network parameter value is greater than or equal to a second preset threshold, it indicates a large network parameter value, meaning the service server's network bandwidth is large. The service server can then adjust the network parameter value until it falls below the second preset threshold. It should be noted that the type of network parameter and the second preset threshold can be set according to actual conditions, and are not limited here. Similarly, the specific method for adjusting the network parameter value can be set according to actual conditions, and is not limited here. Therefore, in this method, the service server can detect network parameters in real time and adjust them when the values are large until they are small, automatically adjusting the network bandwidth to ensure the stability and reliability of the service server's operation.
[0105] In one implementation, the service server can also receive second data identification information of the data to be accessed sent by the access device. Based on the second data identification information, the service server retrieves the data to be accessed identified by the second data identification information from local storage, calls the general access interface, and sends the data to be accessed to the access device through the general access interface. Therefore, the service server can send the data to be accessed to the access device through the general access interface, which is applicable to access scenarios of different access devices, has good scalability, and greatly reduces the development difficulty and cost of data access.
[0106] It should be noted that there are no restrictions on the type of access device. For example, access devices include, but are not limited to, apps, web pages, and terminals. Terminals include, but are not limited to, mobile phones, computers, smart voice interaction devices, smart home appliances, and in-vehicle terminals.
[0107] It should be noted that the data to be accessed is stored in the storage space of the business server, and the data to be accessed refers to the data that the accessing device needs to obtain. In the embodiments of this disclosure, the type of data to be accessed can be set according to the actual situation, and no further limitations are imposed here. For example, in intelligent transportation application scenarios, the types of data to be accessed include, but are not limited to, text, images, audio, and video.
[0108] In the embodiments of this disclosure, second data identification information can be pre-set for the data to be accessed to distinguish different data to be accessed. It should be noted that the type of the second data identification information is not limited in many ways; for example, the second data identification information includes, but is not limited to, characters, text, etc. In one embodiment, the second data identification information is the identification information of the storage location of the data to be accessed in the business server.
[0109] It should be noted that the general access interface can be configured according to the actual situation, and no further limitations are imposed here. The general access interface is applicable to different access devices. In one implementation, the type of general access interface includes, but is not limited to, SDK (Software Development Kit), AWS S3 (Amazon Simple Storage Service), etc.
[0110] In summary, according to the client device access method of this disclosure, after establishing a connection between the service server and the client device, a first data identification information of the data to be stored can be sent to the client device. The data to be stored identified by the first data identification information sent by the client device can be received through a general access interface, and the received data to be stored can be stored locally. Alternatively, in response to not receiving the data to be stored sent by the client device, the first data identification information of the data to be stored can be added to the data compensation list, and the data to be stored corresponding to the first data identification information in the data compensation list can be compensated and stored, thus ensuring the reliability of data transmission between the service server and the client device.
[0111] Figure 5 This is a flowchart illustrating a method for accessing a client device according to a fifth embodiment of the present disclosure.
[0112] like Figure 5 As shown, the client equipment access method of the fifth embodiment of this disclosure includes:
[0113] S501 obtains the customer's own device identification information and primary authentication policy.
[0114] S502, send device identification information and first authentication policy to the service server. The device identification information is used to obtain the second authentication policy. The first authentication policy and the second authentication policy are used to generate the authentication result of the customer device. The authentication result is used to indicate whether to call the general access interface.
[0115] It should be noted that the client device access method in this embodiment is executed by the client device. It is understood that a service server refers to a server capable of providing service to the client device. It should be noted that there are no excessive limitations on the types of service servers, client devices, and service providers. For example, client devices include, but are not limited to, apps, web pages, and terminals, where terminals include, but are not limited to, mobile phones, computers, smart voice interaction devices, smart home appliances, and in-vehicle terminals. Service providers include, but are not limited to, data access, data transmission, and data storage.
[0116] In the embodiments of this disclosure, the client equipment can obtain its own device identification information and a first authentication policy, and send the device identification information and the first authentication policy to the service server. The device identification information is used to obtain a second authentication policy, and the first authentication policy and the second authentication policy are used to generate the authentication result of the client equipment. The authentication result is used to indicate whether to call the general access interface.
[0117] The details of steps S501-S502 can be found in the above embodiments and will not be repeated here.
[0118] In summary, according to the access method of the client device in the embodiments of this disclosure, the client device can obtain its own device identification information and first authentication policy, and send the device identification information and first authentication policy to the service server. At this time, the object to be authenticated is the client device, so that the service server can automatically obtain the authentication result of the client device.
[0119] Figure 6 This is a flowchart illustrating a method for accessing a client device according to a sixth embodiment of the present disclosure.
[0120] like Figure 6 As shown, the access method for a client device according to the sixth embodiment of this disclosure includes:
[0121] S601 receives the second authentication policy sent by the service server.
[0122] S602, obtain the customer's own primary authentication strategy.
[0123] S603 generates the authentication result of the business server based on the first authentication strategy and the second authentication strategy.
[0124] S604 sends the authentication result to the business server.
[0125] It should be noted that the client device access method in this embodiment is executed by the client device. It is understood that a service server refers to a server capable of providing service to the client device. It should be noted that there are no excessive limitations on the types of service servers, client devices, and service providers. For example, client devices include, but are not limited to, apps, web pages, and terminals, where terminals include, but are not limited to, mobile phones, computers, smart voice interaction devices, smart home appliances, and in-vehicle terminals. Service providers include, but are not limited to, data access, data transmission, and data storage.
[0126] In the embodiments of this disclosure, the client equipment can receive a second authentication policy sent by the service server, obtain its own first authentication policy, generate the authentication result of the service server based on the first authentication policy and the second authentication policy, and send the authentication result to the service server.
[0127] The relevant content of steps S601-S604 can be found in the above embodiments, and will not be repeated here.
[0128] In summary, according to the access method of the client equipment in the embodiments of this disclosure, the client equipment can receive the second authentication policy sent by the service server and obtain its own first authentication policy. Based on the first authentication policy and the second authentication policy, it generates the authentication result of the service server and sends the authentication result to the service server. At this time, the authenticated object is the service server, and the client equipment can automatically obtain the authentication result of the service server based on the first authentication policy and the second authentication policy.
[0129] Figure 7 This is a flowchart illustrating a data access method according to a first embodiment of the present disclosure.
[0130] like Figure 7 As shown, the data access method of the first embodiment of this disclosure includes:
[0131] S701 sends the second data identification information of the data to be accessed to the business server.
[0132] S702 calls the general access interface of the business server and receives the data to be accessed identified by the second data identification information sent by the business server through the general access interface.
[0133] It should be noted that the execution subject of the client device access method in this embodiment is the access device. It is understood that a service server refers to a server capable of providing service to the access device. It should be noted that there are no excessive limitations on the types of service servers, access devices, and service providers. For example, access devices include, but are not limited to, apps, web pages, and terminals, where terminals include, but are not limited to, mobile phones, computers, smart voice interaction devices, smart home appliances, and in-vehicle terminals. Service providers include, but are not limited to, data access, data transmission, and data storage.
[0134] In the embodiments of this disclosure, the access device may send second data identification information of the data to be accessed to the service server, call the general access interface of the service server, and receive the data to be accessed identified by the second data identification information sent by the service server through the general access interface.
[0135] The relevant content of steps S701-S702 can be found in the above embodiments, and will not be repeated here.
[0136] In summary, according to the data access method of this disclosure, the access device can send second data identification information of the data to be accessed to the business server, invoke the general access interface of the business server, and receive the data to be accessed identified by the second data identification information sent by the business server through the general access interface. Therefore, the access device can obtain data from the business server through the general access interface, which is applicable to access scenarios of different access devices, has good scalability, and greatly reduces the development difficulty and cost of data access.
[0137] The collection, storage, use, processing, transmission, provision, and disclosure of user personal information involved in the technical solution disclosed herein comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0138] Figure 8 This is a block diagram of an access device for a client equipment according to a first embodiment of the present disclosure.
[0139] like Figure 8 As shown, the access device 800 of the client equipment in this embodiment of the present disclosure includes: a first acquisition module 801, a calling module 802 and an access module 803.
[0140] The first acquisition module 801 is used to acquire the authentication result of the authenticated object, wherein the authenticated object is a client device or a business server.
[0141] Module 802 is invoked in response to the authentication result indicating that the authenticated object has passed authentication, by invoking the general access interface.
[0142] Access module 803 is used to establish a connection between the service server and the client equipment based on the general access interface.
[0143] In one embodiment of this disclosure, the object to be authenticated is the client device, and the first acquisition module 801 is further configured to: receive device identification information and a first authentication policy sent by the client device; obtain a matching second authentication policy from the authentication policy database based on the device identification information; and obtain the authentication result of the client device based on the first authentication policy and the second authentication policy.
[0144] In one embodiment of this disclosure, the object to be authenticated is the service server, and the first acquisition module 801 is further configured to: receive the authentication result of the service server sent by the client equipment.
[0145] In one embodiment of this disclosure, before receiving the authentication result from the service server sent by the client device, the first acquisition module 801 is further configured to: acquire device identification information of the client device; acquire a matching second authentication strategy from the authentication strategy database based on the device identification information, wherein the second authentication strategy is used by the client device to acquire the authentication result from the service server; and send the second authentication strategy to the client device.
[0146] In one embodiment of this disclosure, the access device 800 of the client equipment further includes: a first sending module, configured to send first data identification information of data to be stored to the client equipment; and a first receiving module, configured to receive the data to be stored identified by the first data identification information sent by the client equipment through the general access interface, and store the received data to be stored locally.
[0147] In one embodiment of this disclosure, the access device 800 of the client equipment further includes: a compensation module, the compensation module being configured to: in response to not receiving the data to be stored sent by the client equipment, add the first data identification information of the data to be stored to a data compensation list; and perform compensation storage on the data to be stored corresponding to the first data identification information in the data compensation list.
[0148] In one embodiment of this disclosure, the compensation module is further configured to: obtain compensation storage results, wherein the compensation storage results include the number of successful compensation storage times and / or the number of failed compensation storage times; identify that the data to be stored has been successfully compensated once, and delete the first data identification information of the data to be stored from the data compensation list; or, identify that the number of failed compensation storage times of the data to be stored has reached a first preset threshold, and send a reminder message, wherein the reminder message is used to remind the user that the data to be stored is abnormal.
[0149] In one embodiment of this disclosure, the access device 800 of the client equipment further includes: an adjustment module, the adjustment module being configured to: detect network parameters of the service server, wherein the value of the network parameters is positively correlated with the network bandwidth of the service server; identify that the value of the network parameters is greater than or equal to a second preset threshold, and adjust the value of the network parameters until the value of the network parameters is less than the second preset threshold.
[0150] In one embodiment of this disclosure, the access device 800 of the client equipment further includes: a second receiving module, configured to receive second data identification information of data to be accessed sent by the access device; a second obtaining module, configured to obtain the data to be accessed identified by the second data identification information from local storage according to the second data identification information; and a second sending module, configured to invoke a general access interface and send the data to be accessed to the access device through the general access interface.
[0151] In summary, the access device for client equipment in this embodiment of the present disclosure can obtain the authentication result of the authenticated object, which may be a client equipment or a service server. In response to the authentication result indicating that the authenticated object has passed authentication, it calls the general access interface and establishes a connection between the service server and the client equipment based on the general access interface. Therefore, client equipment can be accessed through the general access interface, making it suitable for access scenarios of different client equipment, with good scalability, and greatly reducing the development difficulty and cost of device access.
[0152] Figure 9 This is a block diagram of an access device for a client equipment according to a second embodiment of the present disclosure.
[0153] like Figure 9 As shown, the access device 900 of the client equipment in this embodiment of the present disclosure includes: an acquisition module 901 and a transmission module 902.
[0154] Module 901 is used to obtain the customer's own device identification information and first authentication policy;
[0155] The sending module 902 is used to send the device identification information and the first authentication policy to the service server, wherein the device identification information is used to obtain the second authentication policy, the first authentication policy and the second authentication policy are used to generate the authentication result of the client device, and the authentication result is used to indicate whether to call the general access interface.
[0156] In summary, the access device for the client equipment in this embodiment of the present disclosure can obtain the device identification information and the first authentication policy of the client equipment itself, and send the device identification information and the first authentication policy to the service server. At this time, the object being authenticated is the client equipment, so that the service server can automatically obtain the authentication result of the client equipment.
[0157] Figure 10 This is a block diagram of an access device for a client equipment according to a third embodiment of the present disclosure.
[0158] like Figure 10 The access device 1000 for a client device according to this embodiment includes: a receiving module 1001, an acquisition module 1002, a generation module 1003, and a sending module 1004.
[0159] The receiving module 1001 is used to receive the second authentication policy sent by the service server;
[0160] Module 1002 is used to obtain the first authentication policy of the customer device itself.
[0161] The generation module 1003 is used to generate the authentication result of the business server based on the first authentication strategy and the second authentication strategy.
[0162] The sending module 1004 is used to send the authentication result to the service server.
[0163] In summary, the access device of the client equipment in this embodiment of the present disclosure can receive the second authentication policy sent by the service server and obtain its own first authentication policy. Based on the first authentication policy and the second authentication policy, it generates the authentication result of the service server and sends the authentication result to the service server. At this time, the authentication object is the service server, and the client equipment can automatically obtain the authentication result of the service server based on the first authentication policy and the second authentication policy.
[0164] Figure 11 This is a block diagram of a service server according to a first embodiment of the present disclosure.
[0165] like Figure 11 The service server 1100 of this embodiment includes an access device 800 for a client device.
[0166] The service server in this embodiment can obtain the authentication result of the authenticated object, which can be a client device or a service server. In response to the authentication result indicating that the authenticated object has passed authentication, the server calls a general access interface and establishes a connection between the service server and the client device based on the general access interface. Therefore, the service server can access the client device through the general access interface, making it suitable for access scenarios of different client devices, with good scalability, and greatly reducing the development difficulty and cost of device access.
[0167] Figure 12 This is a block diagram of a client device according to a first embodiment of the present disclosure.
[0168] like Figure 12 The client equipment 1200 of this disclosure includes a client equipment access device 900.
[0169] The client device in this embodiment of the disclosure can obtain its own device identification information and first authentication policy, and send the device identification information and first authentication policy to the service server. At this time, the object to be authenticated is the client device, so that the service server can automatically obtain the authentication result of the client device.
[0170] Figure 13 This is a block diagram of a client device according to a second embodiment of the present disclosure.
[0171] like Figure 13 The client equipment 1300 of this embodiment includes a client equipment access device 1000.
[0172] The client equipment in this embodiment of the present disclosure can receive a second authentication policy sent by a service server and obtain its own first authentication policy. Based on the first authentication policy and the second authentication policy, it generates the authentication result of the service server and sends the authentication result to the service server. At this time, the object being authenticated is the service server. The client equipment can automatically obtain the authentication result of the service server based on the first authentication policy and the second authentication policy.
[0173] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.
[0174] Figure 14A schematic block diagram of an example electronic device 1400 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.
[0175] like Figure 14 As shown, device 1400 includes a computing unit 1401, which can perform various appropriate actions and processes according to a computer program stored in read-only memory (ROM) 1402 or a computer program loaded from storage unit 1408 into random access memory (RAM) 1403. The RAM 1403 may also store various programs and data required for the operation of device 1400. The computing unit 1401, ROM 1402, and RAM 1403 are interconnected via bus 1404. Input / output (I / O) interface 1405 is also connected to bus 1404.
[0176] Multiple components in device 1400 are connected to I / O interface 1405, including: input unit 1406, such as a keyboard, mouse, etc.; output unit 1407, such as various types of displays, speakers, etc.; storage unit 1408, such as a disk, optical disk, etc.; and communication unit 1409, such as a network card, modem, wireless transceiver, etc. Communication unit 1409 allows device 1400 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0177] The computing unit 1401 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 1401 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 1401 performs the various methods and processes described above, such as client device access methods. For example, in some embodiments, the client device access method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 1408. In some embodiments, part or all of the computer program may be loaded and / or installed on device 1400 via ROM 1402 and / or communication unit 1409. When the computer program is loaded into RAM 1403 and executed by the computing unit 1401, one or more steps of the client device access method described above may be performed. Alternatively, in other embodiments, the computing unit 1401 may be configured to perform the client equipment access method by any other suitable means (e.g., by means of firmware).
[0178] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0179] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0180] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0181] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0182] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with embodiments of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.
[0183] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, servers in distributed systems, or servers incorporating blockchain technology.
[0184] According to embodiments of this disclosure, this disclosure also provides a computer program product, including a computer program, wherein the computer program, when executed by a processor, implements the steps of the client device access method described in the above embodiments of this disclosure.
[0185] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.
[0186] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.
Claims
1. A method for accessing a client device, applied to a business server, the method comprising: Obtain the authentication result of the authenticated object, wherein the authenticated object is a client device or a business server; If the authentication result indicates that the authenticated object has passed the authentication, then the general access interface is invoked; Based on the general access interface, a connection is established between the business server and the client device; The object being authenticated is the business server, and obtaining the authentication result of the object being authenticated includes: Receive the authentication result from the service server sent by the client device; Before receiving the authentication result from the service server sent by the client equipment, the method further includes: Obtain the device identification information of the customer device; Based on the device identification information, a matching second authentication policy is obtained from the authentication policy database, wherein the second authentication policy is used by the client device to obtain the authentication result of the business server; Send the second authentication policy to the client equipment; The method further includes: The network parameters of the service server are detected, wherein the values of the network parameters are positively correlated with the network bandwidth of the service server. If the value of the network parameter is greater than or equal to a second preset threshold, the value of the network parameter is adjusted until the value of the network parameter is less than the second preset threshold.
2. The method according to claim 1, wherein, The object to be authenticated is the client device, and obtaining the authentication result of the object to be authenticated includes: Receive the device identification information and first authentication policy of the client device sent by the client device; Based on the device identification information, a matching second authentication policy is obtained from the authentication policy database; Based on the first authentication strategy and the second authentication strategy, the authentication result of the client device is obtained.
3. The method according to claim 1, wherein, After establishing the connection between the service server and the client device, the method further includes: Send the first data identification information of the data to be stored to the client equipment; The system receives the data to be stored identified by the first data identification information sent by the client equipment through the general access interface, and stores the received data to be stored locally.
4. The method according to claim 3, wherein, The method further includes: In response to not receiving the data to be stored from the client device, the first data identification information of the data to be stored is added to the data compensation list; The data to be stored corresponding to the first data identifier information in the data compensation list is compensated and stored.
5. The method according to claim 4, wherein, The method further includes: Obtain the compensation storage result, wherein the compensation storage result includes the number of successful compensation storage and / or the number of failed compensation storage; If the data to be stored is successfully compensated once, the first data identifier information of the data to be stored is deleted from the data compensation list; or... If the number of failed data storage attempts to be stored reaches a first preset threshold, a reminder message is sent, wherein the reminder message is used to notify the user that the data storage to be stored is abnormal.
6. The method according to claim 1, wherein, The method further includes: Receive the second data identification information of the data to be accessed sent by the accessing device; Based on the second data identification information, retrieve the data to be accessed identified by the second data identification information from local storage; Invoke the general access interface and send the data to be accessed to the access device through the general access interface.
7. An access device for a client equipment, comprising: The first acquisition module is used to acquire the authentication result of the object being authenticated, wherein the object being authenticated is a client device or a business server. The calling module is used to call the general access interface in response to the authentication result indicating that the authenticated object has passed the authentication. An access module is used to establish a connection between the service server and the client device based on the general access interface; The object to be authenticated is the business server, and the first acquisition module is further configured to: Receive the authentication result from the service server sent by the client device; Before receiving the authentication result from the service server sent by the client equipment, the first acquisition module is further configured to: Obtain the device identification information of the customer device; Based on the device identification information, a matching second authentication policy is obtained from the authentication policy database, wherein the second authentication policy is used by the client device to obtain the authentication result of the business server; Send the second authentication policy to the client equipment; The device further includes: an adjustment module, the adjustment module being used for: The network parameters of the service server are detected, wherein the values of the network parameters are positively correlated with the network bandwidth of the service server. If the value of the network parameter is greater than or equal to a second preset threshold, the value of the network parameter is adjusted until the value of the network parameter is less than the second preset threshold.
8. The apparatus according to claim 7, wherein, The object to be authenticated is the client device, and the first acquisition module is further configured to: Receive the device identification information and first authentication policy of the client device sent by the client device; Based on the device identification information, a matching second authentication policy is obtained from the authentication policy database; Based on the first authentication strategy and the second authentication strategy, the authentication result of the client device is obtained.
9. The apparatus according to claim 7, wherein, The device further includes: The first sending module is used to send the first data identification information of the data to be stored to the client equipment; The first receiving module is configured to receive the data to be stored identified by the first data identification information sent by the client equipment through the general access interface, and store the received data to be stored locally.
10. The apparatus according to claim 9, wherein, The device further includes: a compensation module, the compensation module being used for: In response to not receiving the data to be stored from the client device, the first data identification information of the data to be stored is added to the data compensation list; The data to be stored corresponding to the first data identifier information in the data compensation list is compensated and stored.
11. The apparatus according to claim 10, wherein, The compensation module is also used for: Obtain the compensation storage result, wherein the compensation storage result includes the number of successful compensation storage and / or the number of failed compensation storage; If the data to be stored is successfully compensated once, the first data identifier information of the data to be stored is deleted from the data compensation list; or... If the number of failed data storage attempts to be stored reaches a first preset threshold, a reminder message is sent, wherein the reminder message is used to notify the user that the data storage to be stored is abnormal.
12. The apparatus according to claim 7, wherein, The device further includes: The second receiving module is used to receive the second data identification information of the data to be accessed sent by the access device; The second acquisition module is used to acquire the data to be accessed identified by the second data identification information from local storage according to the second data identification information; The second sending module is used to call the general access interface and send the data to be accessed to the access device through the general access interface.
13. A business server, comprising: The access device for the customer equipment as described in any one of claims 7-12.
14. An electronic device comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the access method of the client equipment as described in any one of claims 1-6.
15. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to execute the access method for the client equipment as described in any one of claims 1-6.
16. A computer program product comprising a computer program that, when executed by a processor, implements the steps of the access method for a client device as described in any one of claims 1-6.