A Distributed Resource Discovery and Unified Management Method

By adopting a distributed resource discovery and unified management method, the problem of cross-service resource management is solved, and the automatic discovery and unified management of heterogeneous resources are realized. It supports cross-service resource opening, authorization and authentication, and enables seamless access and management of resources.

CN115277196BActive Publication Date: 2025-10-31CHENGDU FENGSHUN TECH CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202210891704.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-07-27
Publication Date
2025-10-31
Estimated Expiration
2042-07-27

AI Technical Summary

Technical Problem

Existing information resource management methods cannot effectively manage cross-service resources, especially data analysis results resources and external system data resources, and existing resource authorization and authentication technology frameworks cannot achieve cross-service management.

Method used

A distributed resource discovery and unified management approach is adopted. Through the collaborative work of the registry center and the resource management center, resource providers are automatically discovered, resource information is obtained, and resource authorization and access authentication are performed. Resource open protocols are used to achieve unified management and cross-service access of resources.

Benefits of technology

It enables comprehensive management of heterogeneous resources, allowing for resource opening, authorization, and authentication without unified storage, and supports resource sharing and access between services with different technical architectures.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115277196B_ABST
    Figure CN115277196B_ABST
Patent Text Reader

Abstract

This invention discloses a distributed resource discovery and unified management method, which discovers resource providers; obtains resource information; and performs resource authorization and user access authentication. In this invention, resource providers open resource information according to resource open protocols. The resource management center automatically discovers currently online resource providers and obtains resource information according to the resource open protocols for viewing, previewing, and authorizing management operations. Resource users obtain resource authentication and access resources through authentication. The resource management center performs authentication. Resources in this invention can be distributed across different services, which can have different technical architectures, and resource information is opened through a unified network protocol. This invention can autonomously discover currently online resources. This invention integrates heterogeneous resources into a unified format for unified opening, authorization, and authentication according to resource open protocols. Resource data in this invention does not require unified storage.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of data processing technology, and in particular relates to a unified management method for distributed resource discovery. Background Technology

[0002] Information resource management (IRM) is an applied theory that first developed in the United States in the late 1970s and early 1980s and then gradually spread globally. It is a new type of information management theory born from the application of modern information technology, particularly information technology centered on computers and modern communication technologies. IRM can be divided into narrow and broad definitions. In a narrow sense, IRM refers to the process of managing information itself, i.e., information content. In a broad sense, IRM refers to the process of managing information content and related resources such as equipment, facilities, technology, investment, and information personnel.

[0003] Enterprise information resources are the collection of various information activity elements (information technology, equipment, information producers, etc.) accumulated by an enterprise in its information activities. The task of enterprise information resource management is to effectively collect, acquire, and process internal and external information, maximize the quality, availability, and value of enterprise information resources, and enable all parts of the enterprise to share these information resources.

[0004] The explosive development of information technology and the overheated demand for informatization applications from governments, enterprises, and society have transformed information resources from technological applications into ubiquitous and vital economic resources. Information resources drive economic growth, institutional reforms, social changes, and development. Information resource management technology is also evolving from a singular approach to a comprehensive one, forming large-scale platforms that integrate various software components.

[0005] However, existing information resource management methods have the following problems: Data warehouses and data marts require ETL for unified storage before unified management; and they can only manage raw data resources, such as data analysis results resources like BI dashboards, reports, and large screens. Data platforms include data warehouses, data marts, and data analysis-related resources; however, external system data resources still require ETL for unified storage before unified management, and non-pure data resources from external systems (such as AI model prediction interfaces) cannot be managed. Resource authorization and authentication frameworks (such as Spring Security and Shiro in Java) can only manage resources within a single service and cannot manage resources across services. Summary of the Invention

[0006] To address the aforementioned issues, this invention proposes a distributed resource discovery and unified management method that enables comprehensive management of information resources.

[0007] To achieve the above objectives, the technical solution adopted by this invention is: a distributed resource discovery and unified management method, comprising the following steps:

[0008] S10, Discover resource providers;

[0009] S20, Obtain resource information;

[0010] S30 is used for resource authorization and access authentication for resource users.

[0011] Furthermore, in step S10, the resource provider is identified, including the following steps:

[0012] S11, the resource provider initiates the sending of service information to the registration center; the registration center sends a notification to the resource management center that the service information has changed; and the resource provider then opens the resource information according to the resource open protocol.

[0013] S12, in the resource management center, notify the gateway to change the route, obtain all resource provider information in the registration center and cache it, regenerate the resource provider gateway route, and obtain the resource provider information from the cache;

[0014] S13, during the process of retrieving resource provider information from the cache, the resource administrator sends an instruction to the resource management center to retrieve the resource provider information set, and the resource management center returns the resource provider information set to the resource administrator.

[0015] Furthermore, in step S11, the resource provider initiates the sending of service information to the registration center; the registration center sends a notification to the resource management center regarding the change in service information, including the following steps:

[0016] The resource provider configures service metadata, indicating that the current service is provided by a resource provider;

[0017] The resource provider initiates the process, discovers the registry center, and sends its own service information to the registry center;

[0018] The registration center receives the service launch notification and then notifies the resource management center.

[0019] Furthermore, in step S12, in the resource management center, the gateway is notified to change the route, all resource provider information in the registration center is obtained and cached, the resource provider gateway route is regenerated, and the resource provider information is retrieved from the cache, including the following steps:

[0020] S121, after receiving the service change notification, the resource management center updates the online service information set and notifies the refreshable route locator within the resource management center service to update the gateway route;

[0021] S122, the refreshable route locator can obtain and cache all resource provider information in the registry center after receiving an online service change event;

[0022] S123, the refreshable route locator generates a new set of resource provider routing rules based on the cached object provider and provides them to the gateway for use;

[0023] S214, the registry center listens for the service offline message and notifies the resource management center; then the resource management center executes steps S121-S123 to refresh the cache object provider and gateway route.

[0024] Furthermore, in step S122, the refreshable route locator, upon receiving an online service change event, obtains and caches information on all resource providers in the registry center, including the following steps:

[0025] S1221, Obtain a collection of online service information;

[0026] S1222, Traverse the online service information set, find services whose service type value is resource provider; and generate resource provider information for services that meet the conditions;

[0027] S1223, store the resource provider information in the cache object provider.

[0028] Furthermore, in step S123, the refreshable route locator generates a new set of resource provider routing rules based on the cached object provider and provides it to the gateway for use, including the following steps:

[0029] S1231, Traverse all values ​​of the cached object provider to obtain information about a single resource provider;

[0030] S1232, Generate a routing object based on the resource provider information;

[0031] S1233, add the route object to the resource provider's route rule set.

[0032] Furthermore, the resource provider, according to the resource open access agreement, includes:

[0033] Resource providers can access a collection of open resource category information; enable paginated resource information queries; allow queries of resource information under hierarchical nodes; enable queries of paginated resource information under hierarchical nodes; allow queries of individual resource information; allow queries of the number of resources within a resource category; obtain authentication and authorization from the resource management center; and verify resource management center authentication.

[0034] Furthermore, in step S20, obtaining resource information includes the following steps:

[0035] S21, After obtaining authentication and authorization from the resource management center on the management client, the resource administrator sends a request to the resource management center to obtain a set of information on resource providers, carrying the authorization.

[0036] S22, after receiving the request to obtain the resource provider information set, the resource management center retrieves the cached object provider and returns it to the management client; after receiving the resource provider information set, the management client renders it as a drop-down list for resource administrators to select;

[0037] S23, after the resource administrator selects a resource provider, an event is triggered to send a request to the resource management center to obtain the resource category information provided by the resource provider, carrying the authorization and the service name of the resource provider;

[0038] S24. After receiving the request to obtain resource category information provided by the resource provider, the resource management center obtains the interface calling tool according to the service name of the resource provider, uses the interface calling tool to access the open interface of the resource provider, and carries the authorization.

[0039] S25. After receiving the interface request, the resource provider verifies whether the authorization is valid. If valid, it continues to execute and returns a set of resource category information.

[0040] S26, after receiving the set of resource category information from the resource provider, the resource management center returns it to the management client; after receiving the set of resource category information, the management client renders it as a drop-down list for resource administrators to select from;

[0041] S27, After the resource administrator selects a resource category, the event management client is triggered to determine the value of the data structure in the resource category information, initiate a request, and render the interface; including the following steps:

[0042] S271, if the data structure value is a list structure, then the management client initiates a paginated query request for resource information, carrying the authorization, resource provider service name, resource category code and pagination object;

[0043] S272, if the data structure is a tree hierarchy, then the management client initiates a request to query resource information under the hierarchy node, carrying the authorization, resource provider service name, resource category code and resource parent node ID;

[0044] S273, the data structure value is tree_list hierarchical structure + list structure, then the management client first executes step S272 to load the tree structure, and all tree nodes are directories.

[0045] Furthermore, in step S30, a resource authorization process is performed, including the following steps:

[0046] Authorization from the resource user;

[0047] User resource authorization;

[0048] Generate a unified resource access address;

[0049] In step S30, the resource user access authentication and authorization process includes the following steps:

[0050] Resource users obtain resource authentication;

[0051] Resource users access the resource management center gateway using the unified resource access address, carrying resource authentication;

[0052] The resource management center gateway receives the request and obtains the resource authentication and request path;

[0053] The resource management center gateway verifies whether the request path is compliant and whether the path rules meet the unified resource access address; if not, it terminates the request and returns an error message.

[0054] The resource management center gateway obtains the resource provider's service gateway route, resource category code, and business ID based on the request path; and uses unified resource access address resolution.

[0055] The resource management center gateway obtains the resource provider service name based on the resource provider service gateway routing;

[0056] Use the source provider service gateway route as the key to retrieve resource provider information from the cached object provider, and then retrieve the resource provider service name from the resource provider information;

[0057] The resource management center gateway verifies the validity of resource authentication; if invalid, it terminates the request and returns an error message; the validity of resource authentication includes whether it can be decrypted correctly and whether it has expired.

[0058] The authentication information contained in the resource authentication is obtained, that is, the decrypted and recognizable authentication information;

[0059] Determine whether the authentication information contains user information; if not, retrieve the resource user's service name from the authentication information.

[0060] The authentication information does not include user information. The query permission is based on the resource user's service name, provider's service name, resource category code, and business ID. The query is based on the resource user's authorization. The system checks whether the resource user's authorized query result exists. If it does not exist, the request ends and an error message is returned. If it exists, the resource access continues.

[0061] The authentication information includes user information. The resource user's service name and user ID are obtained from the authentication information. The query permissions are based on the resource user's service name, provider's service name, resource category code, business ID, and user ID. The query is based on the user's resource authorization. It is determined whether the user's resource authorization query result exists. If it does not exist, the request is terminated and an error message is returned. If it exists, the resource access continues.

[0062] Furthermore, resource users obtain resource authentication, including two resource authentication modes:

[0063] Resource users access the resource management center client credential interface to obtain resource authentication. This resource authentication information includes the resource user's service name and the Chinese name of the resource user's service, but does not include user information.

[0064] Resource users access the password-protected interface of the resource management center to obtain resource authentication. This authentication information includes the resource user's service name and user information. This type of resource authentication access can be controlled down to the user level, but resource users need to integrate with the resource management center's single sign-on feature.

[0065] The beneficial effects of adopting this technical solution are:

[0066] In this invention, resource providers openly share resource information according to resource openness protocols. The resource management center automatically discovers currently online resource providers and obtains resource information for viewing, previewing, and authorizing management operations based on the resource openness protocols. Resource users obtain resource authentication and access resources through authentication. The resource management center performs authentication. Resources in this invention can be distributed across different services (resource providers), and these services (resource providers) can have different technical architectures, all sharing resource information through a unified network protocol. This invention can autonomously discover currently online resources. This invention integrates heterogeneous resources into a unified format for unified opening, authorization, and authentication based on resource openness protocols. Resource data in this invention does not require unified storage. Attached Figure Description

[0067] Figure 1 This is a schematic diagram of a distributed resource discovery and unified management method according to the present invention;

[0068] Figure 2 This is a schematic diagram illustrating the process by which a resource administrator sends a set of information about resource providers to the resource management center in an embodiment of the present invention.

[0069] Figure 3 This is a schematic diagram illustrating the process by which a resource user obtains resource authentication in an embodiment of the present invention. Detailed Implementation

[0070] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described below with reference to the accompanying drawings.

[0071] In this embodiment, see Figure 1 As shown, this invention proposes a unified management method for distributed resource discovery, including the following steps:

[0072] S10, Discover resource providers;

[0073] S20, Obtain resource information;

[0074] S30 is used for resource authorization and access authentication for resource users.

[0075] As an optimization of the above embodiment, step S10, which involves finding the resource provider, includes the following steps:

[0076] S11, the resource provider initiates the sending of service information to the registration center; the registration center sends a notification to the resource management center regarding the change in service information; and the resource provider then opens the resource information according to the resource open protocol; including the following steps:

[0077] The resource provider configures service metadata, indicating that the current service is provided by a resource provider;

[0078] The service metadata specifically includes the service name (usually in English), the Chinese name of the service, the service type (the value is resource-provider, indicating that the current service is a resource provider), the service gateway route (if empty, the service name is used), and whether temporary resource authentication is used.

[0079] The resource provider initiates the process, discovers the registry center, and sends its own service information (including the resource provider's IP, port, service metadata, etc.) to the registry center.

[0080] Once the registration center receives the service launch notification, it will notify the resource management center of the message (including the resource provider's IP, port, service metadata, etc.).

[0081] S12, in the resource management center, notify the gateway to change the route, obtain and cache all resource provider information from the registry center, regenerate the resource provider gateway route, and retrieve the resource provider information from the cache; including the following steps:

[0082] S121, after receiving the service change notification, the resource management center updates the online service information set (including resource provider IP, port, service metadata, etc.) and notifies the refreshable route locator within the resource management center service to update the gateway route.

[0083] S122, the refreshable route locator receives an online service change event, retrieves and caches information on all resource providers in the registry center; including the following steps:

[0084] S1221, Obtain a collection of online service information;

[0085] S1222, Traverse the online service information set, find services whose service type value is resource provider; and generate resource provider information (service name, Chinese name of service, service gateway route, whether temporary resource authentication is used) for services that meet the conditions;

[0086] S1223, store the resource provider information in the cache object provider providers (key-value pair type, the key is the service gateway route, and the value is the resource provider information).

[0087] S123, the refreshable route locator generates a new set of resource provider routing rules (key-value pairs, where the key is the path rule and the value is the route object) based on the cached provider object and provides it to the gateway; including the following steps:

[0088] S1231, iterate through all values ​​of the cached object provider to obtain information about a single resource provider;

[0089] S1232, Generate a routing object based on the resource provider information;

[0090] S1233, add the route object to the resource provider's route rule set.

[0091] Table 1. Main resource provider information and routing object mapping rules

[0092] route object Resource provider information Router ID Service Name Service ID Service Name Path rules / Service Gateway Routing / **

[0093] S124, the registry center listens for the service offline message and notifies the resource management center; then the resource management center executes steps S121-S123 to refresh the cached object providers and gateway routes.

[0094] S13, during the process of retrieving resource provider information from the cache, the resource administrator sends an instruction to the resource management center to retrieve the resource provider information set, and the resource management center returns the resource provider information set to the resource administrator.

[0095] As an embodiment of the above, the resource provider according to the resource open protocol includes:

[0096] Resource providers can access a collection of open resource category information; enable paginated resource information queries; allow queries of resource information under hierarchical nodes; enable queries of paginated resource information under hierarchical nodes; allow queries of individual resource information; allow queries of the number of resources within a resource category; obtain authentication and authorization from the resource management center; and verify resource management center authentication.

[0097] Resource sharing protocols, using JSON as an example:

[0098] 1. Resource providers open resource category information collections.

[0099] Address: resource provider address / providerClient / getResourceCategorys.

[0100] Request method: GET.

[0101] parameter:

[0102]

[0103] Return value: A collection of resource category information provided by the resource provider.

[0104] Format for single resource category information:

[0105] {

[0106] "resourceCategoryName":"Dashboard", / / Resource category name;

[0107] "resourceCategoryCode":"panel", / / Resource category code;

[0108] "resourceCategoryDesc":null, / / Description of resource category;

[0109] "dataStructure":"tree_list", / / Resource structure, list structure, tree hierarchy structure, tree_list hierarchy structure + list structure;

[0110] "manifestation":"html" / / Resource presentation format: HTML or API;

[0111] }

[0112] 2. Resource providers can enable paginated querying of resource information (for dataStructure value list).

[0113] Address: Resource provider address / providerClient / page / {resourceCategoryCode}.

[0114] Request method: POST.

[0115] parameter:

[0116]

[0117]

[0118] Return value: A collection of paginated resource information for the specified resource category.

[0119] Single resource information format

[0120] {

[0121] "businessId":"", / / A unique business ID for the resource among the resource providers;

[0122] "resourceName":"", / / Resource name;

[0123] "resourceCode":null, / / Resource code;

[0124] "resourceDesc":null, / / Resource description;

[0125] "resourceCategoryCode":"panel", / / Resource category information;

[0126] "resourceCategoryName":"Dashboard", / / Resource category name;

[0127] "resourceAddress":"", / / Resource browser address, for resources presented in HTML format;

[0128] "resourceApi":null, / / Resource interface address, for resource representation API;

[0129] "requestMethod":"GET", / / Resource request method;

[0130] "parentId": null, / / Resource parent node ID, for resource structures of tree or tree_list;

[0131] "hasAddress":true, / / Whether there is a request address; false for directories.

[0132] "createUser":"", / / Name of the resource creator;

[0133] "createTime":"2022-03-30 18:00:44", / / Resource creation time;

[0134] "updateUser":"", / / Name of the person who modified the resource

[0135] "updateTime":null, / / Resource modification time;

[0136] "dir":false, / / Whether it is a directory;

[0137] "otherInfos":[{ / / A collection of other descriptive information about the resource, which can include multiple entries;

[0138] "name":"Original Data", / / Other Information Name;

[0139] "code":"originalInfo", / / Encoding of other information;

[0140] "info": null / / Other information value, allowing any data structure (single value, set, or object).

[0141] }]

[0142] }

[0143] 3. Resource providers can open the query hierarchy to access resource information (for dataStructure values ​​tree and tree_list).

[0144] Address: Resource provider's address

[0145] / providerClient / getDirsByParent / {resourceCategoryCode} / {parentId}.

[0146] Request method: POST.

[0147] parameter:

[0148]

[0149] Return value: A collection of resource or directory information for the specified resource category and its parent node.

[0150] For the format of a single resource information, refer to 2.

[0151] 4. Resource providers can access the pagination information of resources under the query hierarchy nodes (for the dataStructure value tree_list).

[0152] Address: Resource provider's address

[0153] / providerClient / getResourcesByParent / {resourceCategoryCode} / {parentId}.

[0154] Request method: POST.

[0155] parameter:

[0156]

[0157]

[0158] Return value: The set of paginated resource information for the specified resource category and the parent node.

[0159] For the format of a single resource information, refer to 2.

[0160] 5. Resource providers can query individual resource information.

[0161] Address: Resource provider's address

[0162] / providerClient / getResourceInfo / {resourceCategoryCode} / {businessId}.

[0163] Request method: GET.

[0164] parameter:

[0165]

[0166] Return value: See reference 2 for the format of a single resource.

[0167] 6. Resource providers can query the number of resources in a resource category.

[0168] Address: Resource provider's address

[0169] / providerClient / countResourceCategory / {resourceCategoryCode}.

[0170] Request method: GET.

[0171] parameter:

[0172]

[0173] Return value: The number of resources in the specified resource category.

[0174] 7. Obtain Authorization from Resource Management Center.

[0175] (1) The Resource Management Center service's scheduled task automatically generates a Resource Management Center authentication (OAuth 2.0 client credential). This Resource Management Center authentication includes the Resource Management Center service name (OAuth 2.0 client ID) and the Chinese name of the Resource Management Center service (OAuth 2.0 client name), but does not contain user information. This type of Resource Management Center authentication can be used in scenarios where scheduled tasks retrieve resource quantities without user information.

[0176] (2) Resource Management Center users (resource administrators) log in to the Resource Management Center to obtain Resource Management Center authentication (OAuth 2.0 password-based). This Resource Management Center authentication includes the Resource Management Center service name (OAuth 2.0 client ID), the Resource Management Center service name in Chinese (OAuth 2.0 client name), and user information. This type of Resource Management Center authentication is valid when resource administrators manage resources online.

[0177] (3) Both resource management center authentications are generated using OAuth 2.0 jwt encryption.

[0178] 8. The resource provider verifies the resource management center's certification.

[0179] (1) When the resource provider receives a request from the resource management center to obtain resource information, it first retrieves the value of Authorization from the request.

[0180] (2) Decrypt the Authorization value using JWT and verify its validity period.

[0181] (3) Verify whether the client ID in the JWT is consistent with the known resource management center service name.

[0182] If they match, continue with the interface access.

[0183] If there is a discrepancy, the interface access will not be executed further, and a permission error will be returned.

[0184] As an optimization of the above embodiment, in step S20, such as Figure 2 As shown, obtaining resource information includes the following steps:

[0185] S21, After obtaining authentication and authorization from the resource management center on the management client, the resource administrator sends a request to the resource management center to obtain a set of information on resource providers, carrying the authorization.

[0186] S22, after receiving the request to obtain the resource provider information set, the resource management center retrieves the cached object provider and returns it to the management client; after receiving the resource provider information set, the management client renders it as a drop-down list for resource administrators to select;

[0187] S23, after the resource administrator selects a resource provider, an event is triggered to send a request to the resource management center to obtain the resource category information provided by the resource provider, carrying the authorization and the service name of the resource provider;

[0188] S24. After receiving the request to obtain resource category information provided by the resource provider, the resource management center obtains the interface calling tool according to the service name of the resource provider, uses the interface calling tool to access the open interface of the resource provider, and carries the authorization.

[0189] S25. After receiving the interface request, the resource provider verifies whether the authorization is valid. If valid, it continues to execute and returns a set of resource category information.

[0190] S26, after receiving the set of resource category information from the resource provider, the resource management center returns it to the management client; after receiving the set of resource category information, the management client renders it as a drop-down list for resource administrators to select from;

[0191] S27, after the resource administrator selects a resource category, the event management client is triggered to determine the value of the dataStructure data structure in the resource category information, initiate a request, and render the interface, including the following steps:

[0192] S271, if the data structure value dataStructure is a list structure, then the management client initiates a paginated query request for resource information, carrying the authorization, resource provider service name, resource category code and pagination object;

[0193] The resource management center receives a request to query resource information in pagination mode, obtains the interface calling tool based on the resource provider's service name, and uses the interface calling tool to access the resource provider's open interface, carrying the authorization, resource category code, and pagination object.

[0194] After receiving the interface request, the resource provider verifies whether the authorization is valid. If valid, it continues to execute and returns a set of paginated resource information for the specified resource category.

[0195] After receiving a set of paginated resource information for a specified resource category from the resource provider, the resource management center returns it to the management client; the management client then renders the paginated list; resource administrators can select resources from the list for subsequent management operations (view details, browse, authorize).

[0196] S272, if the data structure is a tree hierarchy, then the management client initiates a request to query resource information under the hierarchy node, carrying the authorization, resource provider service name, resource category code and resource parent node ID;

[0197] When the resource management center receives a request to query resource information under a hierarchical node, it obtains the interface calling tool based on the resource provider's service name, and uses the interface calling tool to access the resource provider's open interface, carrying the authorization, resource category code, and resource parent node ID.

[0198] After receiving the interface request, the resource provider verifies whether the authorization is valid. If valid, it continues to execute and returns a set of resource or directory information under the specified resource category and parent node.

[0199] After receiving the specified resource category and the set of resource or directory information under the parent node from the resource provider, the resource management center returns it to the management client. The management client then renders this set of information into a tree structure.

[0200] Resource administrators can select resources in the tree node for subsequent management operations (view details, browse, authorize).

[0201] Resource administrators can expand directories in the tree node to perform operations similar to S272 to load sub-nodes under the directory, except that the resource parent node ID is the businessId of the current directory node.

[0202] S273, the data structure value is tree_list hierarchical structure + list structure, then the management client first executes step S272 to load the tree structure, and all tree nodes are directories.

[0203] Resource administrators can select directories in the tree node, and the management client can initiate a request to query resource pagination information under the hierarchical node, carrying authorization, resource provider service name, resource category code, resource parent node ID, and the businessId and pagination object of the current directory node.

[0204] The resource management center receives a request to query resource pagination information under the query hierarchy node, obtains the interface calling tool based on the resource provider's service name, and uses the interface calling tool to access the resource provider's open interface, carrying authorization, resourceCategoryCode, and page.

[0205] After receiving the interface request, the resource provider verifies whether the authorization is valid. If valid, it continues to execute and returns the set of paginated resource information under the specified resource category and parent node.

[0206] After receiving the specified resource category and a set of paginated resource information under the parent node from the resource provider, the resource management center returns it to the management client. The management client then renders the paginated list. Resource administrators can select resources from the list for subsequent management operations (view details, browse, authorize).

[0207] As an optimization of the above embodiment, in step S30, a resource authorization process is performed, including the following steps:

[0208] Authorization from the resource user;

[0209] After authorization, the system saves the following records: the resource user's service name (OAuth 2.0 client ID), the resource provider's service name, the resource category code, and the resource's business ID.

[0210] User resource authorization;

[0211] The authorized resource and role relationship record includes the role ID, resource provider service name, resource category code, and resource business ID.

[0212] The authorized user and role relationship is stored in the user ID and role ID records.

[0213] Generate a unified resource access address.

[0214] Unified Resource Access Address: Resource Management Center Address / Gateway Prefix / Resource Provider Service Gateway Route / Resource Category Code / Business ID / Resource Representation Format.

[0215] In step S30, as Figure 3 As shown, the resource user access authentication and authorization process includes the following steps:

[0216] Resource users obtain resource authentication tokens; resource users obtain resource authentication, which includes two resource authentication modes:

[0217] Resource users access the OAuth 2.0 client credential interface of the resource management center to obtain a ResourceToken. This resource authentication information includes the resource user's service name (OAuth 2.0 client ID) and the resource user's service name in Chinese (OAuth 2.0 client name), but does not include user information. This resource authentication permission can only be controlled at the resource user service level, and cannot be controlled at the user level.

[0218] Resource users access the resource management center's OAuth 2.0 password-based interface. They obtain a ResourceToken, which contains the resource user's service name (OAuth 2.0 client ID), the resource user's Chinese service name (OAuth 2.0 client name), and user information. This type of resource authentication access can be controlled down to the user level, but resource users need to integrate with the resource management center's single sign-on feature.

[0219] Resource users access the resource management center gateway using the unified resource access address, carrying the resource authentication ResourceToken.

[0220] The resource management center gateway receives the request and obtains the resource authentication ResourceToken and the request path URI;

[0221] The resource management center gateway verifies whether the request path URI is compliant and whether the path rule meets the unified resource access address; if not, it terminates the request and returns an error message.

[0222] The resource management center gateway obtains the resource provider's service gateway route, resource category code, and business ID based on the request path URI; and uses unified resource access address resolution.

[0223] The resource management center gateway obtains the resource provider service name based on the resource provider service gateway routing;

[0224] Use the source provider service gateway route as the key to retrieve resource provider information from the cached object provider, and then retrieve the resource provider service name from the resource provider information;

[0225] The resource management center gateway verifies whether the resource authentication token is valid; if invalid, it terminates the request and returns an error message; the validity of the resource authentication token includes whether it can be decrypted correctly and whether it has expired.

[0226] The authentication information jwtInfo contained in the ResourceToken is obtained, which is the decrypted and recognizable authentication information jwtInfo.

[0227] For the first resource authentication mode, jwtInfo includes the resource user service name and the Chinese name of the resource user service; for the second resource authentication mode, jwtInfo includes the resource user service name, the Chinese name of the resource user service, and user information (including user ID).

[0228] Determine if the authentication information jwtInfo contains user information; if not, retrieve the resource user's service name from the authentication information jwtInfo.

[0229] The authentication information jwtInfo does not contain user information. It queries the resource user's service name, provider's service name, resource category code, and business ID based on the resource user's authorization. It checks whether the resource user's authorized query result exists. If it does not exist, the request ends and returns an error message. If it exists, the resource access continues.

[0230] The authentication information jwtInfo contains user information. The resource user service name and user ID are obtained from the authentication information jwtInfo. The query permissions are based on the resource user service name, provider service name, resource category code, business ID, and user ID. The query is based on the user's resource authorization. It is determined whether the user's resource authorization query result exists. If it does not exist, the request is terminated and an error message is returned. If it exists, the resource access continues.

[0231] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of this invention is defined by the appended claims and their equivalents.

Claims

1. A unified management method for distributed resource discovery, characterized in that, Including the following steps: S10, Discovering resource providers, including the following steps: S11, the resource provider initiates the sending of service information to the registration center; the registration center sends a notification to the resource management center that the service information has changed. The resource provider shall disclose the resource information in accordance with the resource disclosure agreement; The resource providers, according to the resource sharing agreement, include: Resource providers can access resource category information sets, paginated resource information queries, and query resource information under hierarchical nodes. They can also query paginated resource information under hierarchical nodes, query individual resource information, and query the number of resources within a resource category. Resource providers can also obtain authentication and authorization from the resource management center and verify their authentication with the resource management center. S12, in the resource management center, notify the gateway to change the route, obtain and cache all resource provider information in the registry center, regenerate the resource provider gateway route, and retrieve the resource provider information from the cache, including the following steps: S121, after receiving the service change notification, the resource management center updates the online service information set and notifies the refreshable route locator within the resource management center service to update the gateway route; S122, the refreshable route locator can obtain and cache all resource provider information in the registry center after receiving an online service change event; S123, the refreshable route locator generates a new set of resource provider routing rules based on the cached object provider and provides them to the gateway for use; S124, the registry center listens for the service offline message and notifies the resource management center; then the resource management center executes steps S121-S123 to refresh the cache object provider and gateway route; S13, during the process of retrieving resource provider information from the cache, the resource administrator sends an instruction to the resource management center to retrieve the set of resource provider information, and the resource management center returns the set of resource provider information to the resource administrator; S20, Obtain resource information; S30 is used for resource authorization and access authentication for resource users. In step S30, the resource user access authentication and authorization process includes the following steps: Resource users obtain resource authentication; Resource users access the resource management center gateway using the unified resource access address, carrying resource authentication; The resource management center gateway receives the request and obtains the resource authentication and request path; The resource management center gateway verifies whether the request path is compliant and whether the path rules meet the unified resource access address; if not, it terminates the request and returns an error message. The resource management center gateway obtains the resource provider's service gateway route, resource category code, and business ID based on the request path; and uses unified resource access address resolution. The resource management center gateway obtains the resource provider service name based on the resource provider service gateway routing; Use the resource provider service gateway route as the key to retrieve resource provider information from the cached object provider, and then retrieve the resource provider service name from the resource provider information; The resource management center gateway verifies the validity of resource authentication; if invalid, it terminates the request and returns an error message; the validity of resource authentication includes whether it can be decrypted correctly and whether it has expired. The authentication information contained in the resource authentication is obtained, that is, the decrypted and recognizable authentication information; Determine whether the authentication information contains user information; if not, retrieve the resource user's service name from the authentication information. The authentication information does not include user information. The query permission is based on the resource user's service name, provider's service name, resource category code, and business ID. The query is based on the resource user's authorization. The system checks whether the resource user's authorized query result exists. If it does not exist, the request ends and an error message is returned. If it exists, the resource access continues. The authentication information includes user information. The resource user's service name and user ID are obtained from the authentication information. The query permissions are based on the resource user's service name, provider's service name, resource category code, business ID, and user ID. The query is based on the user's resource authorization. The query results are checked to see if the user's resource authorization query results exist. If they do not exist, the request is terminated and an error message is returned. If they exist, the resource access continues. Resource users obtain resource authentication, which includes two resource authentication modes: Resource users access the resource management center client credential interface to obtain resource authentication. The resource authentication information includes the resource user's service name and the Chinese name of the resource user's service, but does not include user information. Resource users access the password-protected interface of the resource management center to obtain resource authentication. The resource authentication information includes the resource user's service name and user information. This type of resource authentication permission can be controlled down to the user level, but the resource user needs to access the resource management center's single sign-on.

2. The distributed resource discovery and unified management method according to claim 1, characterized in that, In step S11, the resource provider initiates the sending of service information to the registration center; the registration center sends a notification to the resource management center regarding the change in service information, including the following steps: The resource provider configures service metadata, indicating that the current service is provided by a resource provider; The resource provider initiates the process, discovers the registry center, and sends its own service information to the registry center; The registration center receives the service launch notification and then notifies the resource management center.

3. The distributed resource discovery and unified management method according to claim 2, characterized in that, In step S122, the refreshable route locator receives an online service change event, retrieves and caches information on all resource providers in the registry center, including the following steps: S1221, Obtain a collection of online service information; S1222, Traverse the set of online service information and find services whose service type value is resource provider; And generate resource provider information for services that meet the criteria; S1223, store the resource provider information in the cache object provider.

4. The distributed resource discovery and unified management method according to claim 3, characterized in that, In step S123, the refreshable route locator generates a new set of resource provider routing rules based on the cached object provider and provides it to the gateway, including the following steps: S1231, Traverse all values ​​of the cached object provider to obtain information about a single resource provider; S1232, Generate a routing object based on the resource provider information; S1233, add the route object to the resource provider's route rule set.

5. The distributed resource discovery and unified management method according to claim 1, characterized in that, In step S20, obtaining resource information includes the following steps: S21, After obtaining authentication and authorization from the resource management center on the management client, the resource administrator sends a request to the resource management center to obtain a set of information on resource providers, carrying the authorization. S22, after receiving the request to obtain the resource provider information set, the resource management center retrieves the cached object provider and returns it to the management client; after receiving the resource provider information set, the management client renders it as a drop-down list for resource administrators to select; S23, after the resource administrator selects a resource provider, an event is triggered to send a request to the resource management center to obtain the resource category information provided by the resource provider, carrying the authorization and the service name of the resource provider; S24. After receiving the request to obtain resource category information provided by the resource provider, the resource management center obtains the interface calling tool according to the service name of the resource provider, uses the interface calling tool to access the open interface of the resource provider, and carries the authorization. S25. After receiving the interface request, the resource provider verifies whether the authorization is valid. If valid, it continues to execute and returns a set of resource category information. S26, the resource management center receives the set of resource category information from the resource provider and returns it to the management client; After receiving the resource category information set, the management client renders it as a drop-down list for resource administrators to select from. S27, after the resource administrator selects a resource category, the event management client is triggered to determine the value of the data structure in the resource category information, initiate a request, and render the interface; Including the following steps: S271, if the data structure value is a list structure, then the management client initiates a paginated query request for resource information, carrying the authorization, resource provider service name, resource category code and pagination object; S272, if the data structure is a tree hierarchy, then the management client initiates a request to query resource information under the hierarchy node, carrying the authorization, resource provider service name, resource category code and resource parent node ID; S273, the data structure value is tree_list hierarchical structure + list structure, then the management client first executes step S272 to load the tree structure, and all tree nodes are directories.

Citation Information

Patent Citations

  • Cluster framework capable of realizing cloud computing flexible service

    CN105025095A

  • Method for forwarding service request by gateway node and gateway node

    CN110381163A

  • Data interaction method, system and device based on multiple data platforms and storage medium

    CN112148679A

  • High-performance gateway authentication method and system oriented to credential field

    CN114039759A