A data verification method, device, server, and storage medium

Through the methods of cache queries and hierarchical index queries, the time-consuming and resource utilization of permission verification is solved, and the rapid and accurate acquisition of permission verification results is achieved, which improves verification efficiency and accuracy.

CN114398619BActive Publication Date: 2025-07-04BEIJING DAJIA INTERNET INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111506046.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-10
Publication Date
2025-07-04
Estimated Expiration
2041-12-10

AI Technical Summary

Technical Problem

In the prior art, the permission verification process consumes a lot of time and occupies more computing resources. Especially when key operations and permission rules are complex, performance consumption is serious, which becomes a performance bottleneck for business services.

Method used

By receiving permission verification requests, parsing the request field, determining the identity of the main caller and querying the cache resources, obtaining the verification result if there is a cache keyword, otherwise the results will be obtained through the index query permission verification rule set, and the hash function is used to generate cache keywords and build cache records. The hierarchical index query permission verification rule sets are queried.

Benefits of technology

Reduces permission verification time, improves verification efficiency, saves computing resources, shortens retrieval time, and improves verification accuracy and speed.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114398619B_ABST
    Figure CN114398619B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a data verification method, apparatus, server, and storage medium. The method includes: receiving a permission verification request and obtaining request information from the permission verification request; determining a cache keyword according to the request information; querying in a cache resource using the cache keyword; when the cache keyword is found in the cache resource, obtaining the verification result of the permission verification request through the cache keyword; when the cache keyword is not found in the cache resource, using the request information as a query keyword and obtaining the verification result of the permission verification request from a preset permission verification rule set through index query. The above solution reduces the time consumed by permission verification, improves the verification efficiency, and saves computing resources.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of data security, and in particular, to a data verification method, apparatus, server, and storage medium. Background Art

[0002] In the process of service calls such as remote procedure calls and application programming interface calls, permission verification is involved to improve data security. In each permission verification, it is necessary to perform permission verification on the calling identity of the requestor, the requested service, the target service resource operation, and the request parameters, etc.

[0003] When there are key operations in permission verification, a large number of callee permission groups, and complex permission rules, it will cause non-negligible time consumption in the permission verification process; in addition, when the request concurrency is high, the permission verification server needs to perform a large number of operations, resulting in obvious performance consumption. Seriously, permission verification will become a performance bottleneck of business services.

[0004] Therefore, there are still problems of more time consumption and more computing resources occupied in the current permission verification process. Summary of the Invention

[0005] The present disclosure provides a data verification method, apparatus, server, and storage medium to at least solve the problems of more time consumption and more computing resources occupied in the permission verification process in the related art. The technical solution of the present disclosure is as follows:

[0006] According to the first aspect of the embodiments of the present disclosure, a data verification method is provided, including:

[0007] Receiving a permission verification request, and parsing the fields to be verified in the permission verification request to obtain corresponding field values;

[0008] Obtaining the identity identifier of the calling party from the field values, and determining whether it is the first time to receive the permission verification request of the calling party;

[0009] If it is determined that it is not the first time to receive the permission verification request of the calling party, determining a cache keyword according to the field values, and querying whether the cache keyword exists in the cache resource;

[0010] If the cache keyword exists, obtaining the cache value corresponding to the cache keyword, and determining the verification result of the permission verification request according to the cache value;

[0011] If the cache keyword does not exist, using the field values as query keywords, and obtaining the verification result of the permission verification request from a preset permission verification rule set through index query.

[0012] Optionally, the field values include a first field value for representing the identity identifier of the calling party, a second field value for representing the called service, a third field value for representing the operation method of the called party, and a fourth field value for representing the request parameter. Taking the field values as query keywords and obtaining the corresponding verification result from a preset permission verification rule set through index query includes:

[0013] Determine the permission verification results of the second field value, the third field value, and the fourth field value according to the first index set and the second index set in the permission verification rule set; the first index set and the second index set include the indexes of all called services, called party operation methods, and request parameters;

[0014] Determine the permission verification result of the first field value according to the authorized calling party list in the permission verification rule set;

[0015] Determine the verification result of the permission verification request based on the permission verification results of the second field value, the third field value, the fourth field value, and the first field value..

[0016] Optionally, the determining the permission verification results of the second field value, the third field value, and the fourth field value according to the first index set and the second index set in the permission verification rule set includes:

[0017] Query the first index set with the second field value and the third field value as query keywords;

[0018] If a first target index with the second field value and the third field value as index names is found in the first index set, obtain the second index set corresponding to the first target index; the second index set is the index set of all request parameters corresponding to the first target index;

[0019] Query the second index set with the request parameter name in the fourth field value as the query keyword;

[0020] If a second target index with the request parameter name as the index name is found in the second index set, obtain the index content of the second target index;

[0021] Determine whether the request parameter value in the fourth field value is in the index content of the second target index;

[0022] If so, determine that the second field value, the third field value, and the fourth field value pass the verification.

[0023] Optionally, the determining the permission verification result of the first field value according to the authorized calling party list in the permission verification rule set includes:

[0024] Obtain multiple authorized caller lists corresponding to the second target index;

[0025] From the multiple authorized caller lists, obtain the target list corresponding to the request parameter value in the fourth field value;

[0026] Query whether the first field value is in the target list;

[0027] If so, determine that the verification of the first field value passes.

[0028] Optionally, after determining whether it is the first time to receive the permission verification request of the caller, it further includes:

[0029] If it is determined that it is the first time to receive the permission verification request of the caller, calculate the permission verification result according to the field value;

[0030] If the permission verification result is passed, add the field value to a preset permission verification rule set.

[0031] Optionally, the adding the field value to the permission verification rule set includes:

[0032] Set a rule name for the permission verification request;

[0033] Create a new first index with the combination of the second field value and the third field value as the index name and the rule name as the index content;

[0034] Add the new first index to the first index set;

[0035] Create a new second index with the parameter name of the fourth field value as the index name and the parameter value of the fourth field value as the index content;

[0036] Add the new second index to the second index set corresponding to the new first index;

[0037] Add the first field value to the authorized caller list corresponding to the new second index.

[0038] Optionally, the determining the cache key word according to the field value includes:

[0039] Calculate the corresponding hash value according to the field value and a preset hash function;

[0040] Use the hash value as the cache key word.

[0041] Optionally, after obtaining the verification result of the permission verification request from a preset permission verification rule set through index query, it further includes:

[0042] Construct a cache record with the keyword as the cache keyword and the second verification result as the cache value;

[0043] Store the cache record in the cache resource and set the expiration time of the cache record.

[0044] According to a second aspect of the embodiments of the present disclosure, there is provided a data verification device, including:

[0045] A parsing module, configured to receive an authorization verification request and parse the fields to be verified in the authorization verification request to obtain corresponding field values;

[0046] An identity determination module, configured to obtain the identity identifier of the calling party from the field values and determine whether it is the first time to receive the authorization verification request of the calling party;

[0047] A cache query module, configured to, if it is determined that it is not the first time to receive the authorization verification request of the calling party, determine a cache keyword according to the field values and query whether the cache keyword exists in the cache resource;

[0048] A first verification module, configured to, if the cache keyword exists, obtain the cache value corresponding to the cache keyword and determine the verification result of the authorization verification request according to the cache value;

[0049] A second verification module, configured to, if the cache keyword does not exist, use the field values as query keywords and obtain the verification result of the authorization verification request from a preset authorization verification rule set through index query.

[0050] Optionally, the field values include a first field value for representing the identity identifier of the calling party, a second field value for representing the called service, a third field value for representing the operation method of the called party, and a fourth field value for representing the request parameters. The second verification module is specifically configured to perform:

[0051] Determine the authorization verification results of the second field value, the third field value, and the fourth field value according to the first index set and the second index set in the authorization verification rule set; the first index set and the second index set include indexes of all called services, operation methods of the called party, and request parameters;

[0052] Determine the authorization verification result of the first field value according to the authorized calling party list in the authorization verification rule set;

[0053] Determine the verification result of the permission verification request based on the permission verification results of the second field value, the third field value, the fourth field value, and the permission verification result of the first field value.

[0054] Optionally, the second verification module is specifically configured to execute:

[0055] Query the first index set with the second field value and the third field value as query keywords.

[0056] If a first target index with the second field value and the third field value as index names is found in the first index set, obtain the second index set corresponding to the first target index; the second index set is the index set of all request parameters corresponding to the first target index.

[0057] Query the second index set with the request parameter name in the fourth field value as the query keyword.

[0058] If a second target index with the request parameter name as the index name is found in the second index set, obtain the index content of the second target index.

[0059] Determine whether the request parameter value in the fourth field value is in the index content of the second target index.

[0060] If so, determine that the second field value, the third field value, and the fourth field value pass the verification.

[0061] Optionally, the second verification module is specifically configured to execute:

[0062] Obtain multiple authorized calling party lists corresponding to the second target index.

[0063] From the multiple authorized calling party lists, obtain the target list corresponding to the request parameter value in the fourth field value.

[0064] Query whether the first field value is in the target list.

[0065] If so, determine that the first field value passes the verification.

[0066] Optionally, the device further includes:

[0067] A calculation module, configured to execute: if it is determined that the permission verification request from the calling party is received for the first time, calculate the permission verification result according to the field value.

[0068] An addition module, configured to execute: if the permission verification result is passed, add the field value to a preset permission verification rule set.

[0069] Optionally, the newly added module is specifically configured to execute:

[0070] Set a rule name for the permission verification request;

[0071] Using the combination of the second field value and the third field value as the index name and the rule name as the index content, create a newly added first index;

[0072] Add the first newly added index to the first index set;

[0073] Using the parameter name of the fourth field value as the index name and the parameter value of the fourth field value as the index content, create a newly added second index;

[0074] Add the newly added second index to the second index set corresponding to the first newly added index;

[0075] Add the first field value to the authorized calling party list corresponding to the newly added second index.

[0076] Optionally, the cache query module is specifically configured to execute:

[0077] Calculate a corresponding hash value according to the field value and a preset hash function;

[0078] Use the hash value as the cache key.

[0079] Optionally, the device further includes:

[0080] A cache record construction module, configured to execute constructing a cache record with the keyword as the cache key and the second verification result as the cache value;

[0081] A storage module, configured to execute storing the cache record in the cache resource and setting an expiration time for the cache record.

[0082] According to a third aspect of the embodiments of the present disclosure, there is provided a server, including:

[0083] A processor;

[0084] A memory for storing executable instructions of the processor;

[0085] Wherein, the processor is configured to execute the instructions to implement the data verification method as described in the first aspect.

[0086] According to a fourth aspect of the embodiments of the present disclosure, there is provided a computer-readable storage medium, when instructions in the computer-readable storage medium are executed by a processor of a server, enabling the server to execute the data verification method as described in the first aspect.

[0087] According to a fifth aspect of the embodiments of the present disclosure, there is provided a computer program product, including a computer program / instructions, characterized in that when the computer program / instructions are executed by a processor, the data verification method described in the first aspect is implemented.

[0088] The technical solutions provided by the embodiments of the present disclosure at least bring the following beneficial effects:

[0089] In the embodiments of the present invention, a permission verification request is received, and the fields to be verified in the permission verification request are parsed to obtain corresponding field values; the identity identifier of the calling party is obtained from the field values, and it is determined whether it is the first time to receive the permission verification request of the calling party; if it is determined that it is not the first time to receive the permission verification request of the calling party, a cache keyword is determined according to the field values, and it is queried whether there is a cache keyword in the cache resource; if there is a cache keyword, the cache value corresponding to the cache keyword is obtained, and the verification result of the permission verification request is determined according to the cache value; if there is no cache keyword, the field values are used as query keywords, and the verification result of the permission verification request is obtained from a preset permission verification rule set through index query. In the above solution, a quick verification result feedback can be obtained by querying the verification result from the cache resource. In the case of no corresponding cache resource, only a simple index query operation is required to quickly match the verification result by using the permission verification rule set, which reduces the time consumed by permission verification, improves the verification efficiency, and saves computing resources.

[0090] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS

[0091] The accompanying drawings herein are incorporated into the specification and constitute a part of the specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure, and do not constitute an improper limitation to the present disclosure.

[0092] Figure 1 is a flowchart of steps of a data verification method shown according to an exemplary embodiment;

[0093] Figure 2 is a schematic diagram of a permission verification rule set shown according to an exemplary embodiment;

[0094] Figure 3 is a flowchart of steps of another data verification method shown according to an exemplary embodiment;

[0095] Figure 4 is a block diagram of the structure of a data verification device shown according to an exemplary embodiment;

[0096] Figure 5A block diagram of a server for data verification according to an exemplary embodiment is shown. Detailed implementation

[0097] In order to enable ordinary technicians in the field to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the accompanying drawings.

[0098] It should be noted that the terms "first", "second", etc. in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments of the present disclosure described here can be implemented in an order other than those illustrated or described here. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0099] Figure 1 A step flowchart of a data verification method according to an exemplary embodiment is shown. As Figure 1 shown, the data verification method includes the following steps.

[0100] In step S11, a permission verification request is received, and request information is obtained from the permission verification request.

[0101] This method is applied to a server that receives a permission verification request.

[0102] A permission verification request is a request used to trigger a permission verification operation. In scenarios such as remote procedure calls and application programming interface calls, when the calling party requests to call the program or interface of the called party, a permission verification request will be sent to the called party server. For example, in a business system, there are Service A and Service B. If the data or resources in Service B are business-critical and have very high security requirements, when Service A calls Service B, Service B needs to perform a permission verification on the call request from Service A.

[0103] The server receives the permission verification request and parses the permission verification request. The permission verification request generally includes fields such as the identity identifier of the calling party, the called service, the operation method of the called party, and request parameters. After the server parses the permission verification request, the field values of the above fields can be obtained, and the request information of the calling party can be obtained from the field values.

[0104] In step S12, a cache key is determined according to the request information.

[0105] In order to improve the efficiency of permission verification, the previous verification results can be searched first by querying the cache resources.

[0106] The data in the cache is stored in a Key-value database, which is a database that stores data in key-value pairs. Specifically, the cache keyword (key) for querying cache resources can be determined according to the request information. If the request information includes multiple field values, the cache keyword can be a combination of these multiple field values to uniquely identify the request.

[0107] Optionally, determining the cache keyword according to the request information includes the following steps A1 - A2:

[0108] A1. Calculate the corresponding hash value according to the request information and a preset hash function;

[0109] A2. Use the hash value as the keyword.

[0110] In steps A1 - A2, the request information includes the caller identity, the called service, the called party operation method, request parameters, etc. The above request information is mapped to a unique and highly specific hash value through the hash function, so as to facilitate using this unique hash value as the cache keyword to search for the cache value.

[0111] The hash value has high specificity, can uniquely identify the cache keyword, and regardless of the length of the value input to the hash function, the hash value calculated by the hash function is a fixed-length bit value, which facilitates the recording and management of the cache keyword, and the calculation speed of the hash value is relatively fast, improving the efficiency of permission verification.

[0112] In step S13, use the cache keyword to query in the cache resources.

[0113] After determining the cache keyword, use this cache keyword as the search keyword to query whether there is a corresponding cache record in the cache resources.

[0114] In step S14, when the cache keyword is found in the cache resources, obtain the verification result of the permission verification request through the cache keyword.

[0115] Each key in the Key-value database corresponds to a unique value. When the above cache keyword is found in the cache resources, the corresponding cache value (value) can be obtained according to the cache keyword. This cache value is the verification result.

[0116] In step S15, when the cache keyword is not found in the cache resources, use the request information as the query keyword and obtain the verification result of the permission verification request from a preset permission verification rule set through index query.

[0117] When the verification result of the permission verification request cannot be obtained from the cached resources, the verification result of the permission verification request can be obtained from the preset permission verification rule set through index query.

[0118] The permission verification rule set is a set of verification rules compiled according to the previously received permission verification requests and verification results. The permission verification rule set includes indexes at multiple different levels and with different contents. Using the request information as the query keyword and querying in the indexes at different levels can quickly obtain the corresponding verification result.

[0119] Different from the existing permission verification that requires a large number of key operations, permission group selections, and cross-verifications, this solution can quickly match the verification result only by a simple index query operation using the permission verification rule set.

[0120] Optionally, the request information includes a first field value for indicating the identity identifier of the calling party, a second field value for indicating the called service, a third field value for indicating the operation method of the called party, and a fourth field value for indicating the request parameters. The steps of using the request information as the query keyword and obtaining the verification result of the permission verification request from the preset permission verification rule set through index query include the following steps B1 - B3:

[0121] B1. According to the first index set and the second index set in the permission verification rule set, determine the permission verification results of the second field value, the third field value, and the fourth field value; the first index set and the second index set include indexes of all called services, operation methods of the called party, and request parameters;

[0122] B2. According to the authorized calling party list in the permission verification rule set, determine the permission verification result of the first field value;

[0123] B3. Based on the permission verification results of the second field value, the third field value, the fourth field value, and the permission verification result of the first field value, determine the verification result of the permission verification request..

[0124] In steps B1 - B3, through the index query method, according to the first index set, determine the permission verification results of the second field value and the third field value, and then according to the second index set, determine the permission verification result of the fourth field value.

[0125] The first field value is the identity identifier of the calling party. According to the authorized calling party list, it can be known whether the calling party corresponding to the first field value is an authorized calling party, and thus the permission verification result of the first field value can be determined.

[0126] In this way, by querying and retrieving the first index set, the second index set, and the authorized caller list, the verification result of the permission verification request can be obtained. The first index set and the second index set respectively verify the called service, the called party operation method, and the request parameters, and the authorized caller list verifies the caller, improving the verification accuracy and speed.

[0127] Optionally, step B1 includes the following steps B11 - B16:

[0128] B11. Query the first index set using the second field value and the third field value as query keywords.

[0129] B12. If a first target index with the second field value and the third field value as index names is found in the first index set, obtain the second index set corresponding to the first target index; the second index set is the index set of all request parameters corresponding to the first target index.

[0130] B13. Query the second index set using the request parameter name in the fourth field value as the query keyword.

[0131] B14. If a second target index with the request parameter name as the index name is found in the second index set, obtain the index content of the second target index.

[0132] B15. Determine whether the request parameter value in the fourth field value is in the index content of the second target index.

[0133] B16. If so, determine that the second field value, the third field value, and the fourth field value pass the verification.

[0134] In steps B11 - B16, a permission verification rule database is maintained in the system's permission configuration center. The permission verification rule database stores all permission verification requests with permissions. Each record consists of a permission verification request with permissions, and each record includes the field values of each permission verification request. Each permission verification request serves as a permission verification rule.

[0135] The permission verification rule set stores the data in the permission verification rule database in the form of indexes to facilitate the server to quickly determine the verification result by querying the indexes.

[0136] The permission verification rule set includes multi-level indexes. The highest-level index is the first index set, which includes the index sets of all called services and the operation methods of the callee. Among them, each first index consists of a combination of a called service and an operation method of the callee as the index name, and the index content is the name of the permission verification rule that hits this combination.

[0137] The second index set is the index set of request parameters, which is the next level of the first index set. The index content of each second index is the parameter names of all request parameters corresponding to the above first index.

[0138] Figure 2 It is a schematic diagram of a permission verification rule set shown according to an exemplary embodiment.

[0139] Refer to Figure 2 , rule1 and rule2 are the names of two permission verification rules in the permission verification rule database. Each permission verification rule consists of fields and field values.

[0140] In Figure 2 , query indexes are established using rule1 and rule2 to obtain the permission verification rule set. Among them, the called service values of rule1 and rule2 are serviceA, and the called operation method values are method1. Therefore, the index name of the obtained first index is serviceA-method1, and the index content is rule1, rule2, that is, the index content is the name of the permission verification rule that hits the combination of serviceA-method1. The index content of the second index serviceA-method1 is the parameter names of rule1 and rule2: app, userid. Among them, app is the parameter name of the request parameter field of rule1, and userid is the parameter name of the request parameter field of rule2. The index content of the parameter name app is: google, apple, and the index content of the parameter name userid is: 123, 111.

[0141] When a permission verification request is received, first parse the request to obtain the first field value representing the identity identifier of the calling party, the second field value representing the called service, the third field value representing the operation method of the callee, and the fourth field value representing the request parameters, and obtain the request parameter values corresponding to the request parameters.

[0142] Then query in the first index of the permission verification rule set whether there is an index name named with the above second field value + third field value. If it exists, it means that the called service + called operation method exists in the permission verification rule database. Take the first index with the second field value and the third field value as the index name as the first target index.

[0143] Then obtain the second index corresponding to the first target index. The fourth field value consists of a request parameter name and a request parameter value. Query whether the request parameter name in the fourth field value exists in the index content of the second index. If the request parameter name exists, use the index name named after the request parameter name as the second target index. Further obtain the index content corresponding to the second target index, and this index content is a list of request parameter values. Query whether the request parameter value in the fourth field value exists in the index content. If it exists, it indicates that the fourth field value passes the verification. Furthermore, it indicates that the second field value, the third field value, and the fourth field value of this permission verification request all pass the verification.

[0144] In the above step B12, if the first target index named after the second field value and the third field value cannot be found in the first index set, it is determined that the permission verification fails, and there is no need to execute the next step; similarly, if in step B14, the second target index cannot be found in the second index set, it is determined that the permission verification fails and there is no need to execute the next step; if in step B15, the request parameter value of the fourth field value is not in the index content of the second target index, it is determined that the permission verification fails and there is no need to execute the next step.

[0145] Optionally, step B2 includes the following steps B21 - B24:

[0146] B21. Obtain multiple authorized calling party lists corresponding to the second target index;

[0147] B22. From the multiple authorized calling party lists, obtain the target list corresponding to the request parameter value of the fourth field value;

[0148] B23. Query whether the first field value is in the target list;

[0149] B24. If so, determine that the first field value passes the verification.

[0150] Steps B21 - B24 are used to verify whether the identity of the calling party is an authorized identity. At this time, query whether the calling party is in the authorized calling party list corresponding to the request parameter value in the fourth field value. If it is in this list, the first field value passes the verification.

[0151] Refer to Figure 2, when receiving an authentication request from clint1, parse the request, calculate the necessary field values, and obtain the request information. Among them, the first field value, i.e., the caller identity identifier value, is client1, the second field value, i.e., the called service value, is serviceA, the third field value, i.e., the called party operation method value, is method1, the fourth field value, i.e., the request parameter names, are app, userid, version, and the request parameter values are: app = google, userid = 123, version = 100.

[0152] Use Figure 2 the permission verification rule set in

[0153] to perform permission verification. First, query whether there is a first index of serviceA - method1 in the permission verification rule set, and the result is that there is; then query whether there are request parameter names such as app and userid in the request second index corresponding to the first index of serviceA - method1, and determine whether the request parameter names and request parameter values in this permission verification request are in the request parameter value lists corresponding to app and userid, and the result is that there is; finally, query whether the caller identity identifier value client1 is in the authorized caller list corresponding to the target request parameter value, and the result is that there is, so the final verification result is verification passed.

[0154] Optionally, after step S15, the following steps C1 - C2 are further included:

[0155] C1. Construct a cache record with the keyword as the cache keyword and the second verification result as the cache value;

[0156] C2. Store the cache record in the cache resource and set the expiration time of the cache record.

[0157] In steps C1 - C2, the data in the cache is stored in a Key - value (keyword - value) database. Map the field values to hash values, use this unique hash value as the cache keyword key, and use the verification result of step S15 as the cache value value to construct a Key - value cache record and store it in the cache resource to facilitate directly calling the cache record to verify the permission request next time and improve the speed of permission verification.

[0158] In addition, the expiration time of the cache record can be set, so that the expired data can be cleared after a certain period of time, which is beneficial to memory decompression and improves the response time and throughput of the cache.

[0159] In summary, in the embodiment of the present invention, a permission verification request is received, and request information is obtained from the permission verification request; a cache keyword is determined according to the request information; the cache keyword is used to query in the cache resource; when the cache keyword is found in the cache resource, the verification result of the permission verification request is obtained through the cache keyword; when the cache keyword is not found in the cache resource, the request information is used as the query keyword, and the verification result of the permission verification request is obtained from a preset permission verification rule set through index query.

[0160] In the above solution, querying the verification result from the cache resource can obtain a quick verification result feedback. In the case of no corresponding cache resource, using the permission verification rule set only requires a simple index query operation to quickly match the verification result, reducing the time consumed by permission verification, improving the verification efficiency, and saving computing resources.

[0161] Moreover, the permission verification rule set stores the data in the permission verification rule database in the form of a hierarchical index such as a first index and a second index, which can strengthen the link between data structures and clarify the hierarchical relationship between data; and verifies the permission verification request by means of a hierarchical query index, shortening the retrieval time of permission verification and improving the efficiency and accuracy of permission verification.

[0162] In addition, after obtaining the verification result of the permission verification request from a preset permission verification rule set through index query, the verification result is stored in the cache resource, which can facilitate directly calling the cache record to verify the permission request next time, further improving the speed of permission verification.

[0163] Figure 3 is a step flowchart of another data verification method shown according to an exemplary embodiment, as Figure 3 shown, and this data verification method includes the following steps.

[0164] In step S21, a permission verification request is received, and request information is obtained from the permission verification request.

[0165] In the embodiment of the present invention, step S21 can refer to step S11, which will not be elaborated here.

[0166] In step S22, a cache keyword is determined according to the request information.

[0167] In an embodiment of the present invention, step S22 may refer to step S12, which will not be elaborated here.

[0168] In step S23, query in the cache resources using the cache keyword.

[0169] In an embodiment of the present invention, step S23 may refer to step S13, which will not be elaborated here.

[0170] In step S24, when the cache keyword is found in the cache resources, obtain the verification result of the permission verification request through the cache keyword.

[0171] In an embodiment of the present invention, step S24 may refer to step S14, which will not be elaborated here.

[0172] In step S25, when the cache keyword is not found in the cache resources, use the request information as the query keyword, and obtain the verification result of the permission verification request from a preset permission verification rule set through index query.

[0173] In an embodiment of the present invention, step S25 may refer to step S15, which will not be elaborated here.

[0174] In step S26, when the verification result of the permission verification request is not obtained from the preset permission verification rule set through index query, calculate the permission verification result according to the request information.

[0175] If the server receives the permission verification request from the calling party for the first time, there is no corresponding record available for query in the permission verification rule set. Then, the verification result of the permission verification request cannot be obtained through index query either. In this case, the traditional method can be used to calculate the permission verification result.

[0176] In step S27, if the permission verification result is passed, add the field value corresponding to the request information to the preset permission verification rule set.

[0177] If the verification is passed, the field value corresponding to the request information of this permission verification request can be added to the permission verification rule set according to the corresponding index structure.

[0178] Optionally, step S27 includes the following steps C1 - C6:

[0179] C1. Set a rule name for the permission verification request;

[0180] C2. Create a new added first index with the combination of the second field value and the third field value in the request information as the index name, and the rule name as the index content;

[0181] C3. Add the first newly added index to the first index set;

[0182] C4. Use the parameter name of the fourth field value in the request information as the index name, and the parameter value of the fourth field value as the index content to create a newly added second index;

[0183] C5. Add the newly added second index to the second index set corresponding to the first newly added index;

[0184] C6. Add the first field value to the authorized caller list corresponding to the newly added second index.

[0185] In steps C1 - C6, according to the data structure of the permission verification rule set, use the second field value + the third field value as the index name, and the rule name of the permission verification request as the index content to construct a newly added first index and add it to the first index set of the permission verification rule set.

[0186] If an index name like the second field value + the third field value already exists in the permission verification rule set, just add the new rule name to the index content of this index name. For example, for Figure 2 the permission verification request from client1, if the rule name of this permission verification request is set to rule3 and it is added to the first index of the original permission verification rule set, the updated first index is obtained: serviceA - method1: [rule1, rule2, rule3].

[0187] The fourth field value is the request parameter name and the request parameter value. Add the request parameter name to the index content of the second index corresponding to the newly added first index. For example, for Figure 2 the permission verification request from client1, add the fourth field value: app, userid, version to the original second index, and the updated second index is obtained: serviceA - method1: [app, userid, version], app: [google, apple], userid: [123, 111], version:

[100] .

[0188] Finally, add the caller identity identifier to the authorized caller list corresponding to the newly added second index. For example, in the authorized caller list corresponding to the index information serviceA - method1: [rule1, rule2, rule3], serviceA - method1: [app, userid, version], app: [google, apple], userid: [123, 111], version:

[100] , add client1.

[0189] In summary, in the embodiments of the present invention, when the verification result of the permission verification request cannot be obtained from the preset permission verification rule set through index query, the permission verification result is calculated according to the request information, and after the verification is passed, the field values of the permission verification request are newly added to the permission verification rule set according to the data structure and index level requirements of the permission verification rule set. Then, when the calling party subsequently sends a permission verification request, the permission verification can be directly performed by querying the permission verification rule set, improving the permission verification efficiency.

[0190] Figure 4 It is a structural block diagram of a data verification device shown according to an exemplary embodiment.

[0191] As Figure 4 shown, the data verification device 30 includes:

[0192] A request information acquisition module 31, configured to receive a permission verification request and acquire request information from the permission verification request;

[0193] A keyword determination module 32, configured to determine a cache keyword according to the request information;

[0194] A query module 33, configured to perform a query in a cache resource using the cache keyword;

[0195] A first verification module 34, configured to, when the cache keyword is found in the cache resource, obtain the verification result of the permission verification request through the cache keyword;

[0196] A second verification module 35, configured to, when the cache keyword is not found in the cache resource, use the request information as a query keyword and obtain the verification result of the permission verification request from a preset permission verification rule set through index query.

[0197] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.

[0198] Figure 5 It is a block diagram of a server for data verification shown according to an exemplary embodiment, and its internal structure diagram can be as Figure 5As shown. The server includes a processor, a memory, and a network interface connected by a system bus. Among them, the processor of the server is used to provide computing and control capabilities. The memory of the server includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and computer programs. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The network interface of the server is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a data verification method.

[0199] Those skilled in the art can understand that Figure 5 the structure shown in is only a block diagram of some structures related to the solution of the present disclosure, and does not constitute a limitation on the server to which the solution of the present disclosure is applied. A specific server may include more or fewer components than those shown in the figure, or combine certain components, or have a different component layout.

[0200] In an exemplary embodiment, a server is further provided, including: a processor; a memory for storing executable instructions of the processor; wherein, the processor is configured to execute the instructions to implement the data verification method in the embodiments of the present disclosure.

[0201] In an exemplary embodiment, a computer-readable storage medium is further provided. When the instructions in the computer-readable storage medium are executed by the processor of the server, the server can execute the data verification method in the embodiments of the present disclosure. The computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.

[0202] In an exemplary embodiment, a computer program product containing instructions is further provided. When it runs on a computer, the computer executes the data verification method in the embodiments of the present disclosure.

[0203] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. This computer program can be stored in a non-volatile computer-readable storage medium. When this computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0204] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. This application is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include well-known knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and examples are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the following claims.

[0205] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

[0206] After considering the specification and practicing the invention disclosed herein, those skilled in the art will readily conceive of other embodiments of the present disclosure. This application is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include well-known knowledge or conventional technical means in the technical field not disclosed in the present disclosure. The specification and examples are only regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the following claims.

[0207] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is limited only by the appended claims.

Claims

1. A data verification method, characterized in that, Including: Receiving a permission verification request and obtaining request information from the permission verification request; Determining a cache keyword according to the request information; Querying in a cache resource using the cache keyword; When the cache keyword is found in the cache resource, obtaining the verification result of the permission verification request through the cache keyword; When the cache keyword is not found in the cache resource, using the request information as a query keyword and obtaining the verification result of the permission verification request from a preset permission verification rule set through index query; the permission verification rule set includes multi-level indexes, the highest-level index is a first index set, and the first index set includes an index set of all called services and called party operation methods; a second index set is an index set of request parameters and is the next level of the first index set; The request information includes a first field value for representing the identity identifier of the calling party, a second field value for representing the called service, a third field value for representing the operation method of the called party, and a fourth field value for representing the request parameters. The using the request information as a query keyword and obtaining the verification result of the permission verification request from a preset permission verification rule set through index query includes: Determining the permission verification results of the second field value, the third field value, and the fourth field value according to the first index set and the second index set in the permission verification rule set; the first index set and the second index set include indexes of all called services, called party operation methods, and request parameters; Determining the permission verification result of the first field value according to the authorized calling party list in the permission verification rule set; Determining the verification result of the permission verification request according to the permission verification results of the second field value, the third field value, the fourth field value, and the permission verification result of the first field value.

2. The method according to claim 1, characterized in that The determining the permission verification results of the second field value, the third field value, and the fourth field value according to the first index set and the second index set in the permission verification rule set includes: Querying the first index set with the second field value and the third field value as query keywords; If a first target index with the second field value and the third field value as index names is found in the first index set, obtaining the second index set corresponding to the first target index; the second index set is an index set of all request parameters corresponding to the first target index; Querying the second index set with the request parameter name in the fourth field value as a query keyword; If a second target index with the request parameter name as the index name is found in the second index set, obtaining the index content of the second target index; Determining whether the request parameter value in the fourth field value is in the index content of the second target index; If so, determining that the second field value, the third field value, and the fourth field value pass the verification.

3. The method according to claim 2, wherein The determining the permission verification result of the first field value according to the authorized calling party list in the permission verification rule set includes: Obtain multiple authorized caller lists corresponding to the second target index; From the multiple authorized caller lists, obtain the target list corresponding to the request parameter value in the fourth field value; Query whether the first field value is in the target list; If so, determine that the verification of the first field value has passed.

4. The method according to claim 1, characterized in that, The method further includes: When the verification result of the permission verification request cannot be obtained from the preset permission verification rule set through index query, calculate the permission verification result according to the request information; If the permission verification result is passed, add the field value corresponding to the request information to the preset permission verification rule set.

5. The method according to claim 4, wherein The adding the field value corresponding to the request information to the permission verification rule set includes: Set a rule name for the permission verification request; Using the combination of the second field value and the third field value in the request information as the index name and the rule name as the index content, create a new first index; Add the new first index to the first index set; Using the parameter name of the fourth field value in the request information as the index name and the parameter value of the fourth field value as the index content, create a new second index; Add the new second index to the second index set corresponding to the new first index; Add the first field value to the authorized caller list corresponding to the new second index.

6. The method according to any one of claims 1-5, characterized in that The determining the cache key according to the request information includes: Calculate the corresponding hash value according to the request information and a preset hash function; Use the hash value as the cache key.

7. According to the method according to any one of claims 1-5, characterized in that, After obtaining the verification result of the permission verification request from the preset permission verification rule set through index query, it further includes: Construct a cache record with the request information as the cache key and the verification result as the cache value; Store the cache record in the cache resource and set the expiration time of the cache record.

8. A data verification device, characterized in that, It includes: A request information acquisition module, configured to receive a permission verification request and obtain request information from the permission verification request; A keyword determination module, configured to determine a cache key according to the request information; A query module, configured to perform a query in the cache resource using the cache key; A first verification module, configured to obtain the verification result of the permission verification request through the cache key when the cache key is found in the cache resource; A second verification module, configured to, when the cache key is not found in the cache resource, use the request information as a query keyword and obtain the verification result of the permission verification request from the preset permission verification rule set through index query; the permission verification rule set includes multi-level indexes, the highest-level index is the first index set, and the first index set includes an index set of all called services and called party operation methods; the second index set is an index set of request parameters and is the next level of the first index set; The request information includes a first field value for indicating the identity identifier of the calling party, a second field value for indicating the called service, a third field value for indicating the operation method of the called party, and a fourth field value for indicating the request parameters. The second verification module is specifically configured to execute: Determine the permission verification results of the second field value, the third field value, and the fourth field value according to the first index set and the second index set in the permission verification rule set; the first index set and the second index set include the indexes of all called services, the operation methods of the called party, and the request parameters; Determine the permission verification result of the first field value according to the authorized calling party list in the permission verification rule set; Determine the verification result of the permission verification request based on the permission verification results of the second field value, the third field value, the fourth field value, and the permission verification result of the first field value.

9. The device according to claim 8, characterized in that, The second verification module is specifically configured to execute: Use the second field value and the third field value as query keywords to query the first index set; If a first target index with the second field value and the third field value as the index name is found in the first index set, obtain the second index set corresponding to the first target index; the second index set is the index set of all request parameters corresponding to the first target index; Use the request parameter name in the fourth field value as the query keyword to query the second index set; If a second target index with the request parameter name as the index name is found in the second index set, obtain the index content of the second target index; Determine whether the request parameter value in the fourth field value is in the index content of the second target index; If so, determine that the second field value, the third field value, and the fourth field value pass the verification.

10. The device according to claim 9, characterized in that, The second verification module is specifically configured to execute: Obtain multiple authorized calling party lists corresponding to the second target index; From the multiple authorized calling party lists, obtain the target list corresponding to the request parameter value in the fourth field value; Query whether the first field value is in the target list; If so, determine that the first field value passes the verification.

11. The device according to claim 8, characterized in that, The device further includes: A calculation module, configured to execute when the verification result of the permission verification request is not obtained from the preset permission verification rule set through index query, calculate the permission verification result according to the request information; An addition module, configured to execute if the permission verification result is passed, add the field values corresponding to the request information into the preset permission verification rule set.

12. The device according to claim 11, characterized in that, The addition module is specifically configured to execute: Set a rule name for the permission verification request; Use the combination of the second field value and the third field value as the index name and the rule name as the index content to create a new first index; Add the new first index to the first index set; Use the parameter name of the fourth field value as the index name and the parameter value of the fourth field value as the index content to create a new second index; Add the new second index to the second index set corresponding to the new first index; Add the first field value to the authorized caller list corresponding to the newly added second index.

13. The device according to any one of claims 8-12, characterized in that, The keyword determination module is specifically configured to execute: Calculate a corresponding hash value according to the request information and a preset hash function; Use the hash value as the cache keyword.

14. The device according to any one of claims 8 - 12, characterized in that, The apparatus further includes: A cache record construction module, configured to execute constructing a cache record with the keyword as the cache keyword and the verification result as the cache value; A storage module, configured to execute storing the cache record in the cache resource and setting an expiration time for the cache record.

15. A server, characterized in that, Comprising: A processor; A memory for storing executable instructions of the processor; Wherein, the processor is configured to execute the instructions to implement the data verification method according to any one of claims 1 to 7.

16. A computer-readable storage medium, when the instructions in the computer-readable storage medium are executed by a processor of a server, enabling the server to execute the data verification method according to any one of claims 1 to 7.

17. A computer program product, comprising a computer program / instructions, characterized in that, The computer program / instructions, when executed by a processor, implement the data verification method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Permission data validation method, device and system

    CN103490886A

  • Block chain access authentication method and device, storage medium and electronic device

    CN110602050A