Interface access verification method, device, electronic device and readable storage medium
By performing interface access verification processing on the received access request in the cloud computing platform, whether access is allowed is determined based on the user's target account identification and account type, the risk of illegal access to cloud platform resources after ordinary key leakage is solved, and higher security is achieved.
Patent Information
- Application Number
- CN202111473196.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-02
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2041-12-02
AI Technical Summary
In cloud computing platforms, after ordinary keys are leaked, there is a risk of illegal access to cloud platform resources, resulting in security risks.
When receiving an access request for the target application interface, the user's target account identification is obtained, and the interface access verification process is performed according to the account type and target account identification to determine whether access is allowed.
It effectively improves the security of the cloud platform and prevents potential risks to the cloud platform when the access keys corresponding to the user account (especially internal accounts) are leaked.
Smart Images

Figure CN114357426B_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present disclosure relate to the technical field of permission control, and more specifically, to an interface access verification method, device, electronic device, and readable storage medium. Background Art
[0002] With the continuous development of cloud computing technology, the functions of cloud resources are becoming more and more. Usually, cloud platforms will encapsulate the services provided by the platform into a series of open application programming interfaces (OpenAPI, Open Application Programming Interface) to facilitate user development and use.
[0003] In related technologies, applications developed by users can access open application programming interfaces by mounting super keys (SuperAK, SuperAccessKey) and common keys (AK, AccessKey), where super keys are generally provided to services registered by lines of business (LOB), and common keys are generally provided to users or roles. For example, services registered by a certain line of business can access open application programming interfaces provided by the cloud platform based on the mounted super keys.
[0004] Usually, because the super key has greater permissions and the ordinary key has relatively smaller permissions, the cloud platform will generally only verify access requests initiated by the super key mounted on the service registered by the business line. This means that under certain working conditions, if the ordinary key is leaked, there is a possibility of security risks to the cloud platform. Summary of the invention
[0005] An object of the present disclosure is to provide a new technical solution for interface access verification to improve the security of a cloud platform.
[0006] According to a first aspect of the present disclosure, an embodiment of an interface access verification method is provided, comprising:
[0007] Upon receiving an access request for a target application program interface, obtaining a target account identifier of a user initiating the access request, wherein the target account identifier indicates a target user account of the user;
[0008] According to the target account identifier, obtaining the account type of the target user account;
[0009] According to the account type and the target account identifier, interface access verification processing is performed on the target user account.
[0010] Optionally, performing interface access verification processing on the target user account according to the account type and the target account identifier includes:
[0011] When the account type is a first preset type, obtaining address information of a requesting end that initiates the access request, and determining an address type of the address information;
[0012] When the address type is a first preset address type, the interface access verification process is performed on the target user account.
[0013] Optionally, performing the interface access verification process on the target user account includes:
[0014] Obtaining a preset whitelist, wherein the whitelist includes configuration information for limiting whether to perform the interface access verification process on the user account;
[0015] In the case that the content in the whitelist is not empty, obtaining a first configuration item from the whitelist, wherein the first configuration item indicates whether to perform the interface access verification process on the user account whose account type is the first preset type;
[0016] The interface access verification process is performed on the target user account according to the first configuration item and the target account identifier.
[0017] Optionally, performing the interface access verification process on the target user account according to the first configuration item and the target account identifier includes:
[0018] When the first configuration item indicates that the interface access verification process is not performed on the user account whose account type is the first preset type, access to the target application interface is allowed based on the target access key corresponding to the target user account.
[0019] Optionally, performing the interface access verification process on the target user account according to the first configuration item and the target account identifier further includes:
[0020] In a case where the first configuration item indicates that the interface access verification process is performed on a user account whose account type is the first preset type, obtaining an account identifier set and / or an access key set from the whitelist;
[0021] In a case where the target account identifier exists in the account identifier set and / or the target access key exists in the access key set, the target application program interface is allowed based on the target access key.
[0022] Optionally, the method further comprises:
[0023] In the case where the address type is the second preset address type, the interface access verification process is not performed on the target user account, and access to the target application program interface is allowed based on the target access key corresponding to the user account.
[0024] Optionally, obtaining a target account identifier of a user corresponding to the access request includes:
[0025] Obtaining a target access key from the access request;
[0026] The target account identifier is obtained from preset mapping data according to the target access key, wherein the preset mapping data reflects the corresponding relationship between the access key and the user's account identifier.
[0027] According to a second aspect of the present disclosure, an embodiment of an interface access verification device is provided, comprising:
[0028] A receiving response module, configured to obtain a target account identifier of a user initiating the access request when receiving an access request for a target application program interface, wherein the target account identifier indicates a target user account of the user;
[0029] An account type obtaining module, used to obtain the account type of the target user account according to the target account identifier;
[0030] The interface access verification module is used to perform interface access verification processing on the target user account according to the account type and the target account identifier.
[0031] According to a third aspect of the present disclosure, an embodiment of an electronic device is provided, such as the device described in the second aspect of this specification; or,
[0032] The electronic device comprises:
[0033] A memory for storing executable instructions;
[0034] A processor is used to operate the electronic device to execute the method described in the first aspect of this specification under the control of the instruction.
[0035] According to a fourth aspect of the present disclosure, an embodiment of a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program that can be read and executed by a computer, and the computer program is used to execute the method described in the first aspect of this specification when read and executed by the computer.
[0036] One beneficial effect of the embodiments of the present disclosure is that, according to the embodiments of the present disclosure, when an electronic device receives an access request for a target application program interface, in order to improve the security of the cloud platform, the embodiment obtains the target account identifier of the user account to obtain the account type of the user account based on the target account identifier, and then performs interface access verification on the user account based on the account type and the target account identifier to avoid the risks that may be brought to the cloud platform when the access key corresponding to the user account, especially the internal account, is leaked.
[0037] Other features and advantages of the present specification will become apparent from the following detailed description of exemplary embodiments of the present specification with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The accompanying drawings, which are incorporated in and constitute a part of the specification, illustrate embodiments of the specification and, together with the description, serve to explain the principles of the specification.
[0039] Figure 1 It is a schematic diagram of the structure of an electronic device that can be used to implement the embodiments of the present disclosure.
[0040] Figure 2 It is a flowchart of an interface access verification method provided by an embodiment of the present disclosure.
[0041] Figure 3 It is a principle block diagram of the interface access verification device provided by an embodiment of the present disclosure.
[0042] Figure 4 It is a schematic diagram of the hardware structure of an electronic device provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0043] Various exemplary embodiments of the present disclosure will now be described in detail with reference to the accompanying drawings. It should be noted that the relative arrangement of components and steps, numerical expressions and numerical values set forth in these embodiments do not limit the scope of the present invention unless otherwise specifically stated.
[0044] The following description of at least one exemplary embodiment is merely illustrative in nature and is in no way intended to limit the invention, its application, or uses.
[0045] Technologies, methods, and equipment known to ordinary technicians in the relevant art may not be discussed in detail, but where appropriate, the technologies, methods, and equipment should be considered as part of the specification.
[0046] In all examples shown and discussed herein, any specific values should be interpreted as merely exemplary and not limiting. Therefore, other examples of the exemplary embodiments may have different values.
[0047] It should be noted that like reference numerals and letters refer to similar items in the following figures, and therefore, once an item is defined in one figure, it need not be further discussed in subsequent figures.
[0048] <Hardware Configuration>
[0049] Figure 1 It is a schematic diagram of the structure of an electronic device that can be used to implement the embodiments of the present disclosure.
[0050] The electronic device 1000 may be a server, and the server may be a physical server or a cloud server, without any special limitation. In the embodiments of the present disclosure, unless otherwise specified, the electronic device 1000 is taken as a server for illustration.
[0051] The electronic device 1000 may include, but is not limited to, a processor 1100, a memory 1200, an interface device 1300, a communication device 1400, a display device 1500, an input device 1600, a speaker 1700, a microphone 1800, and the like. Among them, the processor 1100 may be a central processing unit CPU, a graphics processing unit GPU, a microprocessor MCU, and the like, and is used to execute a computer program, and the computer program may be written in an instruction set of an architecture such as x86, Arm, RISC, MIPS, SSE, and the like. The memory 1200 may include, for example, a ROM (read-only memory), a RAM (random access memory), a non-volatile memory such as a hard disk, and the like. The interface device 1300 may include, for example, a USB interface, a serial interface, a parallel interface, and the like. The communication device 1400 may, for example, be capable of wired communication using an optical fiber or a cable, or wireless communication, and may specifically include WiFi communication, Bluetooth communication, 2G / 3G / 4G / 5G communication, and the like. The display device 1500 may be, for example, a liquid crystal display screen, a touch display screen, and the like. The input device 1600 may include, for example, a touch screen, a keyboard, a somatosensory input, and the like. The speaker 1700 is used to output audio signals. The microphone 1800 is used to collect audio signals.
[0052] As used in the embodiments of the present disclosure, the memory 1200 of the electronic device 1000 is used to store a computer program, which is used to control the processor 1100 to operate to implement the method according to the embodiments of the present disclosure. A technician can design the computer program according to the scheme disclosed in the present disclosure. How the computer program controls the processor to operate is well known in the art, so it will not be described in detail here. The electronic device 1000 can be installed with an intelligent operating system (such as Windows, Linux, Android, IOS, etc.) and application software.
[0053] It should be understood by those skilled in the art that although Figure 1, multiple devices of the electronic device 1000 are shown; however, the electronic device 1000 of the embodiment of the present disclosure may only involve some of the devices, for example, only the processor 1100 and the memory 1200.
[0054] <Method Example>
[0055] Please see Figure 2 , which is a flowchart of an interface access verification method provided by an embodiment of the present disclosure, and the embodiment can be implemented by an electronic device, for example, Figure 1 The electronic device 1000 shown is implemented, and the electronic device is used to receive an application program interface provided for a cloud platform, for example, an access request for an open application program interface, and perform interface access verification processing on the access request to improve the security of the cloud platform.
[0056] like Figure 2 As shown, the interface access verification method of this embodiment may include the following steps S2100-S2300, which are described in detail below.
[0057] Step S2100, when receiving an access request for a target application program interface, obtaining a target account identifier of a user who initiates the access request, wherein the target account identifier represents a target user account of the user.
[0058] In the embodiments of the present disclosure, the target application program interface may be an open application program interface provided by the cloud platform to facilitate users to develop and use the services it provides, namely, OpenAPI. Of course, in the specific implementation, the target application program interface may also be other types of application program interfaces, which are not specifically limited here.
[0059] Specifically, users can create ordinary access keys, i.e., ordinary keys, in the cloud platform in advance; then, by mounting the access key corresponding to their own user account on the application they develop, the application can access the open application interface provided by the cloud platform based on the access key during its operation; or, the cloud platform operator can also create a super access key with relatively large permissions in advance, i.e., a super key, and mount the super key on a service registered by a certain business line, so that the service can easily access the resources provided by the cloud platform.
[0060] In the related art, since the super key usually has greater authority, the core resources and data in the cloud platform can be easily viewed and operated based on the super key, so the cloud platform usually restricts the access request to the open application interface based on the super key to the intranet access, and does not usually impose any restrictions on the access request to the open application interface based on the ordinary key created by ordinary users. However, in the case where the ordinary user is an internal employee of the enterprise, the ordinary key created by the ordinary user has the possibility of accessing and operating the core resources and data of the cloud platform. If such a key is leaked, for example, because the employee resigns and fails to cancel the account in time, there is a risk that the resources of the cloud platform will be illegally accessed by other users on the external network based on the key.
[0061] To solve this problem, in an embodiment of the present disclosure, when an electronic device implementing the method of this embodiment receives an access request for a target application program interface, it can first obtain the user's target account identifier based on the access request, and determine whether it is necessary to perform interface access verification processing on the user's target user account according to the target account identifier, so as to solve this problem. It should be noted that for the convenience of description, in the following description, unless otherwise specified, the ordinary key corresponding to the user account is referred to as the access key for description.
[0062] In one embodiment, obtaining the target account identifier of the user corresponding to the access request includes: obtaining a target access key from the access request; and obtaining the target account identifier from preset mapping data based on the target access key, wherein the preset mapping data reflects the correspondence between the access key and the user's account identifier.
[0063] Step S2200, obtaining the account type of the target user account according to the target account identifier; and executing step S2300, performing interface access verification processing on the target user account according to the account type and the target account identifier.
[0064] In an embodiment of the present disclosure, the account type of the user account may be set by an operator corresponding to the cloud platform when creating the user account. The account type may specifically be an attribute information of the user account.
[0065] For example, when a user account "user01" is created for an internal employee of an enterprise, the account type of the user account may be automatically set to information indicating that it is of the first preset type, that is, an internal account.
[0066] It should be noted that, in the specific implementation, in order to enable the electronic device to accurately obtain the account type of the user account, after the operator sets the account type of the user account, it can be synchronized to the cache database used by the cloud platform through an asynchronous message queue, for example, a Redis database.
[0067] In one embodiment, the interface access verification process is performed on the target user account based on the account type and the target account identifier, including: when the account type is a first preset type, obtaining the address information of the requesting end that initiates the access request, and determining the address type of the address information; when the address type is the first preset address type, performing the interface access verification process on the user account.
[0068] Specifically, the account type in the embodiments of the present disclosure includes at least a first preset type and a second preset type, wherein the first preset type indicates that the user account is an internal account, that is, a user account used by internal users of the enterprise to which the cloud platform belongs; the second preset type indicates that the user account is an external account, that is, a user account used by external users outside the enterprise to which the cloud platform belongs.
[0069] In the specific implementation, if the account type is the second preset type, it means that the user corresponding to the access request is an external user. Since restrictions have been made on their usage permissions when providing user keys to external users, that is, access and operation permissions to the core resources and data of the cloud platform will not be involved. Therefore, when the account type is the second preset type, there is no need to perform interface access verification on the access request initiated by the user key of this type of user account, and access to the target application interface can be directly allowed based on the access key corresponding to the user account.
[0070] If the account type is the first preset type, it means that the user corresponding to the access request is an internal user. In order to ensure the security of the cloud platform, it is necessary to first determine the address type of the requesting end that initiates the access request to determine whether it is necessary to perform interface access verification processing on the access request initiated by the user key based on this type of user account.
[0071] The request end may be the IP address of the electronic device that initiates the access request. The address type may include a first preset address type and a second preset address type, the first preset address type is used to indicate that the corresponding address is an external network IP address, and the second preset address type is used to indicate that the corresponding address is an intranet IP address. In one optional implementation, the address type of the request end may be determined by the network segment to which the IP address belongs. If the IP address that initiates the access request belongs to an IP network segment specific to the intranet, it may be determined that the address type of the IP address is the second preset address type (i.e., the intranet IP address).
[0072] Specifically, in an embodiment of the present disclosure, when the target user account that initiates an access request for a target application interface is an internal account, and the address type of the requesting end that initiates the access request is an external network address, in order to avoid the access key corresponding to the internal account being leaked and possible security risks to the cloud platform, it is necessary to perform interface access verification processing on the access request received in this case to ensure the security of the cloud platform.
[0073] In one embodiment, the interface access verification process for the target user account includes: obtaining a preset whitelist, wherein the whitelist includes configuration information for limiting whether the interface access verification process is performed on the user account; when the content in the whitelist is not empty, obtaining a first configuration item from the whitelist, wherein the first configuration item indicates whether to perform the interface access verification process on the user account whose account type is the first preset type; and performing the interface access verification process on the target user account according to the first configuration item and the target account identifier.
[0074] A whitelist refers to configuration information that is pre-set and can be maintained based on an automatic update mechanism, and is used to limit whether interface access verification processing is required for user accounts. The whitelist may include a first configuration item that identifies whether the verification processing is performed on user accounts of a first preset type, that is, enable_all; in an embodiment of the present disclosure, the value of the first configuration item enable_all can be set to identify whether interface access verification processing is required for internal accounts. For example, when enable_all is "1", it indicates that interface access verification processing is not required for internal accounts, and when enable_all is "0" or no specific value is set, it indicates that interface access verification processing is required for internal accounts.
[0075] That is, in one embodiment, the interface access verification processing for the user account based on the first configuration item and the target account identifier includes: when the first configuration item indicates that the interface access verification processing will not be performed on the user account whose account type is the first preset type, access to the target application interface based on the access key corresponding to the target user account is allowed.
[0076] In addition, in one embodiment, the interface access verification processing for the target user account based on the first configuration item and the target account identifier also includes: when the first configuration item indicates that interface access verification processing is to be performed on a user account with an account type of a first preset type, obtaining an account identifier set and / or an access key set from the whitelist; and when the target account identifier exists in the account identifier set and / or the target access key exists in the access key set, allowing access to the target application interface based on the target access key.
[0077] Specifically, when the first configuration item is empty or the set value indicates that interface access verification processing needs to be performed on the internal account, the account identifier set account_list and / or the access key set ak_list can be obtained in the whitelist; and the account_list is queried to see whether the target account identifier exists, and the ak_list is queried to see whether the target access key in the access request exists; if any of the above items is met, the requesting end is allowed to access the target application interface based on the target access key.
[0078] To summarize, the method provided by the embodiment of the present disclosure, when an electronic device receives an access request for a target application program interface, in order to improve the security of the cloud platform, this embodiment obtains the target account identifier of the user account to obtain the account type of the user account based on the target account identifier. Thereafter, the user account can be subjected to interface access verification processing based on the account type and the target account identifier to avoid the risks that may be brought to the cloud platform when the access key corresponding to the user account, especially the internal account, is leaked.
[0079] <Device Example>
[0080] Corresponding to the above method embodiment, Figure 3 1 is a principle block diagram of an interface access verification device provided by an embodiment of the present disclosure. Figure 3 As shown, the interface access verification device 3000 may include: a response receiving module 3100 , an account type obtaining module 3200 and an interface access verification module 3300 .
[0081] The receiving response module 3100 is used to obtain the target account identifier of the user who initiated the access request when receiving the access request for the target application program interface, wherein the target account identifier represents the target user account of the user.
[0082] In one embodiment, when obtaining the target account identifier of the user corresponding to the access request, the receiving response module 3100 can be used to: obtain the target access key from the access request; obtain the target account identifier from preset mapping data according to the target access key, wherein the preset mapping data reflects the corresponding relationship between the access key and the user's account identifier. The account type obtaining module 3200 is used to obtain the account type of the target user account according to the target account identifier.
[0083] The interface access verification module 3300 is used to perform interface access verification processing on the target user account according to the account type and the target account identifier.
[0084] In one embodiment, when the interface access verification module 3300 performs interface access verification on the target user account based on the account type and the target account identifier, it can be used to: when the account type is a first preset type, obtain the address information of the requesting end that initiates the access request, and determine the address type of the address information; when the address type is the first preset address type, perform the interface access verification on the target user account.
[0085] In one embodiment, the interface access verification module 3300, when performing the interface access verification on the target user account, can be used to: obtain a preset whitelist, wherein the whitelist includes configuration information for limiting whether to perform the interface access verification on the user account; when the content in the whitelist is not empty, obtain a first configuration item from the whitelist, wherein the first configuration item indicates whether to perform the interface access verification on the user account whose account type is the first preset type; and perform the interface access verification on the target user account according to the first configuration item and the target account identifier.
[0086] In one embodiment, the interface access verification module 3300, when performing the interface access verification processing on the target user account according to the first configuration item and the target account identifier, can be used to: when the first configuration item indicates that the interface access verification processing will not be performed on the user account with the account type of the first preset type, allow access to the target application interface based on the target access key corresponding to the target user account.
[0087] In one embodiment, the interface access verification module 3300, when performing the interface access verification processing on the target user account according to the first configuration item and the target account identifier, can also be used to: when the first configuration item indicates that the interface access verification processing is to be performed on a user account with an account type of the first preset type, obtain an account identifier set and / or an access key set from the whitelist; when the target account identifier exists in the account identifier set and / or the target access key exists in the access key set, allow the target application interface based on the target access key.
[0088] In one embodiment, the interface access verification module 3300 can also be used for: when the address type is a second preset address type, not performing the interface access verification process on the target user account, and allowing access to the target application interface based on the target access key corresponding to the user account.
[0089] <Equipment Embodiment>
[0090] Corresponding to the above embodiment, Figure 4 It is a schematic diagram of the hardware structure of an electronic device provided by an embodiment of the present disclosure.
[0091] like Figure 4 As shown, the electronic device 400 includes a processor 410 and a memory 420, wherein the memory 420 is used to store an executable computer program, and the processor 410 is used to execute a method such as any of the above method embodiments under the control of the computer program.
[0092] Each module of the above interface access verification device 3000 may be implemented by the processor 410 in this embodiment executing a computer program stored in the memory 420, or may be implemented by other circuit structures, which is not limited here.
[0093] <Computer Readable Storage Medium Embodiment>
[0094] This embodiment provides a computer-readable storage medium, in which executable commands are stored. When the executable commands are executed by a processor, the method described in any method embodiment of this specification is executed.
[0095] One or more embodiments of the present specification may be a system, method and / or computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for causing a processor to implement various aspects of the present specification.
[0096] A computer-readable storage medium may be a tangible device that can hold and store instructions used by an instruction execution device. A computer-readable storage medium may be, for example, but not limited to, an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples of computer-readable storage media (a non-exhaustive list) include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disk read-only memory (CD-ROM), a digital versatile disk (DVD), a memory stick, a floppy disk, a mechanical encoding device, such as a punch card or a raised structure in a groove on which instructions are stored, and any suitable combination of the foregoing. As used herein, a computer-readable storage medium is not to be interpreted as a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., a light pulse through a fiber optic cable), or an electrical signal transmitted through a wire.
[0097] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in the computer-readable storage medium in each computing / processing device.
[0098] The computer program instructions for performing the operation of the embodiments of this specification may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as "C" language or similar programming languages. Computer-readable program instructions may be executed completely on a user's computer, partially on a user's computer, executed as an independent software package, partially on a user's computer, partially on a remote computer, or completely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., using an Internet service provider to connect via the Internet). In certain embodiments, by utilizing the state information of a computer-readable program instruction to customize an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA) or a programmable logic array (PLA), the electronic circuit may execute a computer-readable program instruction, thereby realizing various aspects of this specification.
[0099] Various aspects of this specification are described herein with reference to flowcharts and / or block diagrams of methods, devices (systems) and computer program products according to embodiments of this specification. It should be understood that each box in the flowchart and / or block diagram and the combination of boxes in the flowchart and / or block diagram can be implemented by computer-readable program instructions.
[0100] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine, so that when these instructions are executed by the processor of the computer or other programmable data processing device, a device that implements the functions / actions specified in one or more boxes in the flowchart and / or block diagram is generated. These computer-readable program instructions can also be stored in a computer-readable storage medium, and these instructions cause the computer, programmable data processing device, and / or other equipment to work in a specific manner, so that the computer-readable medium storing the instructions includes a manufactured product, which includes instructions for implementing various aspects of the functions / actions specified in one or more boxes in the flowchart and / or block diagram.
[0101] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operating steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to implement the functions / actions specified in one or more boxes in the flowchart and / or block diagram.
[0102] The flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the systems, methods and computer program products according to the multiple embodiments of this specification. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of an instruction, and a part of a module, a program segment or an instruction contains one or more executable instructions for realizing the specified logical function. In some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or the flowchart, and the combination of the boxes in the block diagram and / or the flowchart can be implemented by a dedicated hardware-based system that performs the specified function or action, or can be implemented by a combination of dedicated hardware and computer instructions. It is well known to those skilled in the art that it is equivalent to implement it by hardware, implement it by software, and implement it by combining software and hardware.
[0103] The embodiments of the present specification have been described above, and the above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and changes will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described embodiments. The choice of terms used herein is intended to best explain the principles of the embodiments, practical applications, or technical improvements in the marketplace, or to enable other persons of ordinary skill in the art to understand the embodiments disclosed herein. The scope of this application is defined by the appended claims.
Claims
1. An interface access verification method, It is characterized in that include: Upon receiving an access request for a target application program interface, obtaining a target account identifier of a user initiating the access request, wherein the target account identifier indicates a target user account of the user; According to the target account identifier, obtaining the account type of the target user account; In the case where the account type is a first preset type, obtaining address information of a requesting end that initiates the access request, and determining an address type of the address information, wherein the first preset type indicates that the user account is an internal account; In the case where the address type is a first preset address type, interface access verification processing is performed on the target user account, wherein the first preset address type is used to indicate that the corresponding address is an external network IP address.
2. The method according to claim 1, It is characterized in that The performing the interface access verification process on the target user account includes: Obtaining a preset whitelist, wherein the whitelist includes configuration information for limiting whether to perform the interface access verification process on the user account; In the case that the content in the whitelist is not empty, obtaining a first configuration item from the whitelist, wherein the first configuration item indicates whether to perform the interface access verification process on the user account whose account type is the first preset type; The interface access verification process is performed on the target user account according to the first configuration item and the target account identifier.
3. The method according to claim 2, It is characterized in that The performing the interface access verification process on the target user account according to the first configuration item and the target account identifier includes: When the first configuration item indicates that the interface access verification process is not performed on the user account whose account type is the first preset type, access to the target application interface is allowed based on the target access key corresponding to the target user account.
4. The method according to claim 3, It is characterized in that The performing the interface access verification process on the target user account according to the first configuration item and the target account identifier further includes: In a case where the first configuration item indicates that the interface access verification process is performed on a user account whose account type is the first preset type, obtaining an account identifier set and / or an access key set from the whitelist; In a case where the target account identifier exists in the account identifier set and / or the target access key exists in the access key set, the target application program interface is allowed based on the target access key.
5. The method according to claim 1, It is characterized in that The method further comprises: In the case where the address type is the second preset address type, the interface access verification process is not performed on the target user account, and access to the target application program interface is allowed based on the target access key corresponding to the user account.
6. The method according to claim 1, It is characterized in that The obtaining of a target account identifier of a user corresponding to the access request includes: Obtaining a target access key from the access request; The target account identifier is obtained from preset mapping data according to the target access key, wherein the preset mapping data reflects the corresponding relationship between the access key and the user's account identifier.
7. An interface access verification device, It is characterized in that include: A receiving response module, configured to obtain a target account identifier of a user initiating the access request when receiving an access request for a target application program interface, wherein the target account identifier indicates a target user account of the user; An account type obtaining module, used to obtain the account type of the target user account according to the target account identifier; An interface access verification module is used to obtain the address information of the requesting end that initiates the access request and determine the address type of the address information when the account type is a first preset type, wherein the first preset type indicates that the user account is an internal account; and to perform interface access verification on the target user account when the address type is the first preset address type, wherein the first preset address type is used to indicate that the corresponding address is an external network IP address.
8. An electronic device comprising the device according to claim 7 ; or, The electronic device comprises: A memory for storing executable instructions; A processor is used to operate the electronic device to execute the method according to any one of claims 1 to 6 under the control of the instruction.
9. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores a computer program that can be read and executed by a computer, and the computer program is used to execute the method according to any one of claims 1 to 6 when being read and executed by the computer.
Citation Information
Patent Citations
Access control method and device, gateway and console
CN112165454A
Interface calling method, device and equipment and computer readable storage medium
CN113609520A