Authorization processing method and device, system, electronic device and storage medium

By receiving and parsing authorization requests in the service mesh and generating and loading the authorization policy model, the problem that the service mesh cannot dynamically load new authorization services is solved, and flexible and efficient authorization functions are achieved.

CN115396221BActive Publication Date: 2025-05-13ALIBABA (CHINA) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211049147.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-08-30
Publication Date
2025-05-13
Estimated Expiration
2042-08-30

AI Technical Summary

Technical Problem

The existing service mesh cannot dynamically load new authorization services, resulting in limited authorization functions.

Method used

By receiving the authorization request, parsing the request to obtain the corresponding authorization service, determining the authorization policy model that matches the authorization service, and using the open rule definition interface to generate the authorization policy model to achieve dynamic loading of the authorization service.

Benefits of technology

It realizes dynamic loading of authorization services, improves the flexibility and scalability of authorization functions, and can dynamically match or control authorization requests according to authorization rules defined by users or administrators.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115396221B_ABST
    Figure CN115396221B_ABST
Patent Text Reader

Abstract

The present application provides an authorization processing method and device, system, electronic device and storage medium. According to the embodiments of the present application, the authorization request for the application service is first parsed to obtain the authorization service corresponding to the authorization request; then the authorization policy model matching the authorization service is determined; finally, the authorization result of the authorization request is determined by running the authorization policy model. Among them, the above-mentioned authorization policy model is generated according to the authorization rules defined by calling the rule definition interface. The rule definition interface is open to users or administrators of the service grid. By calling the interface, the authorization rules can be flexibly defined, so that the corresponding authorization policy model can be generated. The generated authorization policy model can be run to match or control the authorization request according to the authorization rules defined by the user or administrator, realizing the dynamic loading of new authorization services and the flexible definition of the authorization function of the service grid.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the fields of cloud computing and data processing technology, and in particular to an authorization processing method and device, system, electronic device and storage medium. Background Art

[0002] In related technologies, a relatively complex application service can be divided into multiple microservices. Each microservice focuses on completing a task. Each task represents a small business capability. Each microservice can be independently deployed on different clusters or machines. A service grid is a distributed, interconnected proxy network deployed with application services. Its responsibility is to ensure reliable information transmission between microservices.

[0003] The current service grid supports the authorization function, matching the authorization request with the pre-defined authorization conditions, and executing the corresponding action after a successful match, such as releasing the authorization request or rejecting the authorization request. However, the service grid cannot dynamically load new authorization services. Summary of the invention

[0004] The embodiments of the present application provide an authorization processing method and device, system, electronic device and storage medium to realize dynamic loading of new authorization services.

[0005] In a first aspect, an embodiment of the present application provides an authorization processing method, which is applied to a service grid, wherein the service grid is communicatively connected with an application service to implement an authorization function of the application service, and the method includes:

[0006] Receiving an authorization request for the application service;

[0007] Parsing the authorization request to obtain the authorization service corresponding to the authorization request;

[0008] Determine an authorization policy model that matches the authorization service; wherein the authorization policy model is generated according to authorization rules, and the authorization rules are defined by calling an open rule definition interface;

[0009] An authorization result of the authorization request is determined according to the authorization request and the authorization policy model.

[0010] In a possible implementation manner, the authorization policy model is generated in advance, and the generation process of the authorization policy model includes:

[0011] Obtaining the authorization rules defined for the authorization service through the rule definition interface;

[0012] Determine the service grid context of the authorization service; wherein the service grid context includes execution environment information of the authorization service, which is obtained according to information defined by calling an open service definition interface;

[0013] Generate proxy configuration information of the authorization service according to the authorization rule and the service grid context; the proxy configuration information is used to configure the corresponding service grid proxy in the service grid;

[0014] An authorization policy model corresponding to the authorization service is constructed according to the proxy configuration information.

[0015] In a possible implementation, the service grid context includes a workload context; the application service includes at least one workload instance;

[0016] The determining the service grid context of the authorization service includes:

[0017] Determine a workload instance corresponding to the authorization service; the workload instance corresponds to a service grid agent in the service grid; the service grid agent is used to implement a preset function to be implemented by the corresponding workload instance;

[0018] A workload context corresponding to the workload instance is acquired from a workload context set; wherein the workload context set stores a matching relationship between at least one workload instance and a workload context.

[0019] In a possible implementation manner, the workload context set is generated in advance, and the workload context set is generated according to the following steps:

[0020] Obtain resource information of the physical nodes where each workload instance is located;

[0021] Based on the resource information, workload contexts matching each workload instance are generated respectively, and matching relationships between each workload instance and the workload context are stored in the workload context set.

[0022] In a possible implementation, the service grid context includes an authorization service context;

[0023] The determining the service grid context of the authorization service includes:

[0024] An authorization service context matching the authorization service is acquired from the authorization service context set; wherein the authorization service context set stores a matching relationship between at least one authorization service and the authorization service context.

[0025] In a possible implementation manner, the authorization service context set is generated in advance, and the authorization service context set is generated according to the following steps:

[0026] Obtaining authorization metadata for each authorization service definition in at least one authorization service through the service definition interface;

[0027] According to the authorization metadata of each authorization service, an authorization service context matching each authorization service is generated respectively, and the matching relationship between each authorization service and the authorization service context is stored in the authorization service context set.

[0028] In a possible implementation, the authorization metadata includes at least one of the following:

[0029] The access address of the authorization service, the access path of the authorization service, the access port of the authorization service, the access timeout constraint of the authorization service, the request header information of the authorization service, the request body information of the authorization service, the response header information corresponding to the authorization service, and the response body information corresponding to the authorization service.

[0030] In a possible implementation, constructing the authorization policy model corresponding to the authorization service according to the proxy configuration information includes:

[0031] Determine the service grid proxy corresponding to the authorized service according to the proxy configuration information; wherein the service grid includes at least one service grid proxy; the service grid proxy corresponds to the workload instance and is used to implement the preset function to be implemented by the workload instance;

[0032] The service grid agent is utilized to construct an authorization policy model corresponding to the authorization service according to the agent configuration information.

[0033] In a possible implementation manner, determining the authorization result of the authorization request according to the authorization request and the authorization policy model includes:

[0034] Using the authorization plug-in in the service grid, at least part of the information in the authorization request and information of the authorization policy model are sent to the authorization execution engine, so that the authorization execution engine runs the authorization policy model to obtain the authorization result of the authorization request;

[0035] The authorization result fed back by the authorization execution engine is received by utilizing the authorization plug-in.

[0036] In a second aspect, an embodiment of the present application provides an authorization processing device, which is applied to a service grid, and the device includes:

[0037] An information interface module, used for receiving an authorization request;

[0038] A request parsing module, used to parse the authorization request and obtain the authorization service corresponding to the authorization request;

[0039] A model determination module, used to determine an authorization policy model that matches the authorization service; wherein the authorization policy model is generated according to authorization rules, and the authorization rules are defined by calling an open rule definition interface;

[0040] The authorization module is used to determine the authorization result of the authorization request according to the authorization request and the authorization policy model.

[0041] In a third aspect, an embodiment of the present application provides an authorization system, including a service grid that executes the above method, and an application service that is communicatively connected to the service grid;

[0042] The service grid is used to obtain an authorization request for the application service and execute the above method to determine the authorization result of the authorization request.

[0043] In a fourth aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory, wherein the processor implements any of the above methods when executing the computer program.

[0044] In a fifth aspect, an embodiment of the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method described in any one of the above is implemented.

[0045] Compared with the prior art, this application has the following advantages:

[0046] According to the embodiment of the present application, the obtained authorization request is first parsed to obtain the authorization service corresponding to the authorization request; then the authorization policy model matching the authorization service is determined; finally, the authorization result of the authorization request is determined by running the authorization policy model. Among them, the above-mentioned authorization policy model is generated according to the authorization rules defined by calling the rule definition interface. The rule definition interface is open to users or administrators of the service grid. By calling the interface, the authorization rules can be flexibly defined, so that the corresponding authorization policy model can be generated. Running the authorization policy model can match or control the authorization request according to the authorization rules defined by the user or administrator, realizing dynamic loading of the authorization service and flexible definition of the authorization function of the service grid.

[0047] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] In the accompanying drawings, unless otherwise specified, the same reference numerals throughout the multiple drawings represent the same or similar parts or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings only depict some embodiments according to the present application and should not be regarded as limiting the scope of the present application.

[0049] Figure 1 This is a schematic diagram of the structure of the service grid in this application;

[0050] Figure 2 A flowchart of an authorization processing method according to an embodiment of the present application;

[0051] Figure 3 is a schematic diagram of an authorization processing method according to another embodiment of the present application;

[0052] Figure 4 This is a scene diagram corresponding to the authorization processing method of yet another embodiment of the present application;

[0053] Figure 5 is a structural block diagram of an authorization processing device according to an embodiment of the present application;

[0054] Figure 6 is a structural block diagram of an authorization system according to an embodiment of the present application;

[0055] Figure 7 A block diagram of an electronic device used to implement an embodiment of the present application. DETAILED DESCRIPTION

[0056] In the following, only some exemplary embodiments are briefly described. As those skilled in the art will appreciate, the described embodiments may be modified in various ways without departing from the concept or scope of the present application. Therefore, the drawings and descriptions are considered to be exemplary in nature and not restrictive.

[0057] To facilitate understanding of the technical solutions of the embodiments of the present application, the following describes the related technologies of the embodiments of the present application. The following related technologies can be combined with the technical solutions of the embodiments of the present application as optional solutions, and they all belong to the protection scope of the embodiments of the present application.

[0058] A service mesh is a distributed network of interconnected proxies deployed with application services, such as Figure 1As shown, specifically, the service grid includes some user agents (or service grid agents) 102 deployed with each microservice 101, and management components 103, which are also called control layers or control planes, and are used to communicate with the service grid agents 102 and issue configuration information for the microservices 101. Each service grid agent 102 constitutes the data layer or data plane of the service grid, which is used to perform traffic routing, load balancing, authentication, authorization, production monitoring data, etc. for the microservices 101. The microservice 101 includes a workload instance, which is an instance that implements the functions of the microservice.

[0059] In the related art, the service grid supports the authorization function, but it cannot realize the dynamic loading of new authorization services. In order to solve this technical problem, the present application provides an authorization processing method and device based on the service grid, and the authorization processing method and device are described below.

[0060] like Figure 2 The flowchart of the authorization processing method of an embodiment of the present application is shown, and the method is applied to a service grid, and the service grid is connected to the application service for communication to implement the authorization function of the application service. The authorization processing method may specifically include:

[0061] S201. Obtain an authorization request for the application service; S202. Parse the authorization request to obtain the authorization service corresponding to the authorization request; S203. Determine an authorization policy model that matches the authorization service; wherein the authorization policy model is generated based on authorization rules, and the authorization rules are defined by calling an open rule definition interface; S204. Determine the authorization result of the authorization request based on the authorization request and the authorization policy model.

[0062] The above authorization request is a request to obtain a certain operation permission, such as a request to obtain payment permission, a request to obtain login permission, etc. When a user has an authorization requirement, he will send the corresponding authorization request to the workload instance, and then the service grid agent in the service grid will actively or passively obtain the authorization request from the workload instance. One workload instance corresponds to one service grid agent, and the service grid agent is used to implement the preset functions to be implemented by the corresponding workload instance. Exemplarily, the preset functions may include service discovery, health checking, traffic routing, load balancing, and observability in addition to the authorization function.

[0063] The service grid proxy parses the received authorization request, obtains the authorization service corresponding to the authorization request, and determines the authorization policy model that matches the authorization service; then the service grid proxy calls the authorization plug-in in the service grid, and uses the authorization plug-in to send the information of the authorization policy model and at least part of the information in the authorization request to the authorization execution engine, which runs the authorization policy model to determine the authorization result of the authorization request. The authorization result here includes authorization or rejection.

[0064] At least part of the information in the authorization request sent to the authorization execution engine may include information required to authenticate the authorization request, such as user identity information, password information, etc.

[0065] The above authorization request may also include type information of the authorization service or an identifier of the authorization service. The service grid proxy parses the authorization request to obtain the type information or identifier of the authorization service, that is, determines the authorization service corresponding to the authorization request.

[0066] The service grid proxy maintains a mapping relationship between at least one authorization service and an authorization policy model, and there is at least one authorization policy model corresponding to one authorization service. After determining the authorization service corresponding to the authorization request, the service grid proxy can determine at least one authorization policy model corresponding to the authorization service using the above mapping relationship. The authorization policy model includes information about the authorization rules corresponding to the authorization service, and the authorization rules are used to define the conditions for passing authorization and / or the conditions for rejecting authorization. Therefore, running the authorization policy model can determine the authorization result of the authorization request.

[0067] The above authorization policy model is pre-generated based on the authorization rules defined by the user or service grid administrator calling the rule definition interface, so that new authorization services can be dynamically loaded. Specifically, the authorization policy model of a certain authorization service can be generated using the following steps:

[0068] First, the service grid obtains the authorization rules defined by the user or the administrator of the service grid for the authorization service through the rule definition interface. Then, the service grid determines the service grid context of the authorization service; wherein the service grid context includes the execution environment information of the authorization service, and is obtained according to the information defined by calling the open service definition interface. Then, the service grid generates the proxy configuration information of the authorization service according to the authorization rules and the service grid context; finally, the service grid constructs the authorization policy model corresponding to the authorization service according to the proxy configuration information.

[0069] The user or service grid administrator calls the rule definition interface to enter the authorization rule. The authorization rule here is the description of the authorization policy defined by the user or administrator for the authorization service. Figure 3 As shown, the authorization policy controller 302 in the service grid obtains the authorization rule through the rule definition interface, rewrites the received authorization rule, and obtains information that can be processed by the authorization policy configuration generator 303 in the service grid, and then the authorization policy controller 302 sends the processed information to the authorization policy configuration generator 303. In addition, the authorization policy controller 302 also sends the service grid context of the authorization service to the authorization policy configuration generator 303.

[0070] like Figure 3 As shown, the authorization policy configuration generator 303 generates proxy configuration information of the authorization service according to the information rewritten by the authorization rule and the service grid context, and sends the generated proxy configuration information to the corresponding service grid proxy, for example, the generated proxy configuration information is sent to the service grid proxy 312 or the service grid proxy 322. The service grid proxy constructs the authorization policy model corresponding to the authorization service according to the received proxy configuration information.

[0071] In some embodiments, the service network context in the service grid is pre-generated and may include the execution environment information of at least one authorization service, where the execution environment information may include the authorization metadata defined by the user or the administrator of the service grid for each authorization service or the information obtained by rewriting the authorization metadata in a format, and may also include the workload instances corresponding to each authorization service, such as the resource information of the physical node where the workload instances such as workload instance 311 and workload instance 321 are located or the resource information in a format rewritten. The authorization policy model can be run based on the execution environment information of the authorization service to obtain the authorization result.

[0072] Exemplarily, the authorization metadata includes the access address of the authorization service, the access path of the authorization service, the access port of the authorization service, the access timeout constraint of the authorization service, the request header information of the authorization service, the request body information of the authorization service, the response header information of the authorization service, the response body information of the authorization service, the processing method information for the status code returned by calling the authorization service, etc.

[0073] Authorization metadata is the definition information of the authorization service. This information can be input into the service grid by users or service grid administrators by calling the service definition interface of the service grid. Using this open service definition interface can ensure that the service grid can dynamically load the definition information of new authorization services.

[0074] Exemplarily, the resource information of the physical node where the workload instance is located may include information of the central processor of the physical node, information of a memory, and the like.

[0075] like Figure 3 As shown, the service grid controller 301 in the service grid obtains the authorization metadata of each authorization service through the service definition interface of the service grid, and the service grid controller 301 communicates with multiple workload instances and obtains the resource information of the physical node where each workload instance is located through these communication connections. The service grid controller 301 then parses and rewrites the obtained authorization metadata to obtain the authorization service context corresponding to each authorization service that can be processed by the service grid; the service grid controller 301 parses and rewrites the resource information of the physical node where each workload instance is located to obtain the workload context corresponding to each workload instance that can be processed by the service grid.

[0076] Before the service grid controller 301 generates the authorization service context, the registration process of the authorization metadata of each authorization service can also be completed first, that is, the service grid controller 301 rewrites the received authorization metadata according to the preset registration format. After that, the service grid controller 301 continues to parse and rewrite the format of the rewritten authorization metadata to obtain the authorization service context corresponding to each authorization service that can be processed by the service grid.

[0077] The authorization service context and workload context form the service grid context of each authorization service, and the authorization service context and workload context can be stored in a service grid set. Exemplarily, the authorization service context of each authorization service can be stored in an authorization service context set, and the workload context corresponding to each workload instance can be stored in a workload context set.

[0078] When determining the service grid context of a certain authorization service, the authorization service context matching the authorization service can be obtained from the authorization service context set, and the workload instance corresponding to the authorization service can be determined, and the workload context corresponding to the workload instance can be obtained from the workload context set. The obtained authorization service context and workload context are then used as the service grid context of the authorization service.

[0079] Exemplarily, the authorization rule includes information about the workload instance to which the authorization rule applies, or the workload instance on which the authorization service depends. Therefore, by parsing the authorization rule, the workload instance corresponding to the authorization service can be determined.

[0080] The proxy configuration information of the above-mentioned authorization service is generated based on the information rewritten from the authorization rules of the authorization service and the service grid context of the authorization service. Specifically, the authorization rules are defined through the rule definition interface, and the service grid cannot understand or process such authorization rules. Therefore, it is necessary to use the authorization policy controller 302 to rewrite the authorization rules. The rewritten authorization rules, that is, the information rewritten from the above-mentioned authorization rules, are understood and processed by the service grid. Afterwards, the authorization policy configuration generator 303 extracts the corresponding information from the information rewritten from the authorization rules and the service grid context of the authorization service according to the pre-defined name or identifier of the information required to generate the proxy configuration information. Afterwards, the authorization policy configuration generator 303 rewrites the extracted information according to the pre-defined format to obtain the proxy configuration information of the authorization service.

[0081] According to the above description, the service grid controller 301 obtains the authorization metadata defined by the user or the administrator of the service grid for each authorization service, and generates the authorization service context corresponding to each authorization service based on the obtained authorization metadata; the service grid controller 301 obtains the resource information of the physical node where each workload instance is located, and generates the workload context corresponding to each workload instance based on the obtained resource information. The above authorization service context and workload context provide the implementation environment information for the implementation of the authorization function. Without such environment information, the authorization function cannot be implemented. The authorization policy controller 302 obtains the authorization rules defined by the user or the administrator of the service grid for one or more authorization services, and rewrites the obtained authorization rules and sends them to the authorization policy configuration generator 303. At the same time, the authorization policy controller 302 sends the service grid context of the authorization service corresponding to the authorization rule to the authorization policy configuration generator 303. The authorization policy configuration generator 303 generates the proxy configuration information of the authorization service based on the received information.

[0082] like Figure 3 As shown, the service grid controller 301, the authorization policy controller 302 and the authorization policy configuration generator 303 together constitute the management component of the service grid, that is, the control layer or control plane 30 of the service grid. The authorization policy configuration generator 303 in the control layer or control plane of the service grid sends the generated proxy configuration information to the service grid proxy corresponding to the authorized service in the data plane of the service grid.

[0083] The control layer of the service mesh can run in a hosted mode, that is, the control layer of the service mesh runs independently in an operating environment. Running the control layer of the service mesh in a hosted mode can reduce the complexity and cost of operation and maintenance.

[0084] In some embodiments, the authorization policy configuration generator 303 can generate proxy configuration information for one or more authorization services according to the methods in the above embodiments. When issuing the proxy configuration information, it can first determine the authorization service corresponding to the proxy configuration information based on the information such as the identifier of the authorization service included in the proxy configuration information, then determine the service grid proxy that matches the authorization service, and finally issue the proxy configuration information to the corresponding service grid proxy.

[0085] like Figure 3 As shown, the service grid includes at least one service grid agent; the service grid agent corresponds to a workload instance. The authorization rule may include information about the workload instance to which the authorization rule applies, or information about the workload instance on which the authorization service depends, and the agent configuration information generated using the authorization rule may also include information about the corresponding workload instance. Therefore, when sending the agent configuration information, it can also be done in the following manner: the information about the workload instance can be determined by parsing the agent configuration information, and then the service grid agent to which the agent configuration information is to be sent can be determined based on the correspondence between the workload instance and the service grid agent; finally, the agent configuration information is sent to the corresponding service grid agent.

[0086] like Figure 3 As shown, the service grid proxy receives the proxy configuration information and generates an authorization policy model according to a predefined model generation method. Exemplarily, the above-mentioned model generation method defines the usage of each information in the proxy configuration information. The service grid proxy encodes the usage of each information in the proxy configuration information in combination with the corresponding information in the proxy configuration information to obtain the judgment logic for implementing the authorization function. The judgment logic includes at least one judgment link, each of which is used to implement the preset discrimination function. The judgment links are combined according to a certain logic to obtain the overall judgment logic for implementing the authorization function. The overall judgment logic can be considered as the authorization policy model. The authorization policy model generated according to the model generation method includes the proxy configuration information and the usage of each information in the proxy configuration information. Running the authorization policy model can use the authorization rules in the proxy configuration information to determine the authorization result of the authorization request.

[0087] like Figure 3 As shown, the service grid agent is connected to the workload instance in communication. By using the communication connection, the service grid agent can obtain the authorization request initiated by the user, or feedback the authorization result and other information to the workload instance.

[0088] In some embodiments, Figure 3As shown, the service grid may also include authorization plug-ins, such as authorization plug-ins 313 and authorization plug-ins 323. The service grid uses the authorization plug-in to send at least part of the information in the authorization request and the information of the authorization policy model to the authorization execution engine 304. The authorization execution engine 304 runs the authorization policy model to obtain the authorization result of the authorization request, and feeds back the authorization result to the corresponding authorization plug-in. The authorization plug-in receives the authorization result fed back by the authorization execution engine 304, and feeds back the authorization result to the corresponding service grid agent. The service grid agent performs corresponding operations according to the received authorization result, such as performing traffic routing operations. The above-mentioned service grid agents, authorization plug-ins, etc. form the data plane 31 of the service grid. The present application uses the authorization plug-in to realize the dynamic loading of the authorization service customized by the user or the administrator of the service grid, and uses the plug-in method to call the authorization execution engine, which can improve the flexibility of the calling function in updating or expanding. In addition, instead of using the service grid to perform the authorization judgment, the authorization execution engine is used to perform the authorization judgment, which not only reduces the workload of the service grid, but also realizes the functional decoupling, avoids the interference between different functional modules, and improves the reliability of the authorization function.

[0089] like Figure 3 As shown, the authorization plug-in and the service mesh proxy can form a data plane cluster of a service mesh, which can be a Kubernetes cluster or other types of clusters.

[0090] The above authorization rules can be defined in a cloud-native manner, and the authorization rules may include rules for workload instances to which the authorization rules apply, rules for the scope of the authorization rules in the service grid, and rules for the relationship between multiple authorization sub-rules of the authorized service. Among them, the scope of the authorization rules in the service grid may specifically include the scope within the service grid, the scope between the service grid and other service grids; in a specific embodiment, the scope of the authorization rules in the service grid may select the scope within the service grid and / or the scope between the service grid and other service grids. The authorization rules may include one or more authorization sub-rules, and the relationship between multiple authorization sub-rules may specifically include that authorization can be passed by any one of the authorization sub-rules, or that all the authorization sub-rules must pass before authorization can be passed. The authorization policy model generated according to the authorization rules may include an authorization policy sub-model corresponding to each authorization sub-rule.

[0091] The authorization processing method of the present application is described below through a specific embodiment.

[0092] like Figure 4As shown, the application service is a service for online shopping, which includes microservice A and microservice B. Microservice A includes a workload instance 1, and microservice B includes a workload instance 2. Microservice A is used to verify the user's identity information, and after the verification is passed, authorize the user to enter the payment details page, that is, control the user end to display the payment details page. Microservice A is deployed together with the service grid agent 1 in the service grid; microservice B is deployed together with the service grid agent 2 in the service grid. In addition, the service grid also includes a control plane, where the control plane is used to send proxy configuration information for the service of authorizing users to enter the payment details page to the service grid agent 1, so that the service grid agent 1 generates an authorization policy model for the service of authorizing users to enter the payment details page according to the received proxy configuration information.

[0093] When a user pays for a product, he sends an authorization request to workload instance 1 of microservice A. Service grid proxy 1 intercepts the authorization request and parses it. Then, service grid proxy 1 uses the parsing results to locate the authorization policy model for the service that authorizes users to enter the payment details page.

[0094] Afterwards, the service grid proxy 1 calls the authorization plug-in and sends at least part of the information in the authorization request and the information of the located authorization policy model to the authorization execution engine. The authorization execution engine runs the authorization policy model, obtains and feeds back the authorization result. The service grid proxy 1 uses the authorization plug-in to receive the authorization result fed back by the authorization execution engine, and determines whether to control the user end to display the payment details page based on the authorization result.

[0095] The control plane in this embodiment can obtain the authorization rules defined by the administrator for the service of authorizing users to enter the payment details page through the rule definition interface, and obtain the authorization metadata defined by the administrator for the service of authorizing users to enter the payment details page through the service definition interface. The control plane uses the authorization metadata to form an authorization service context, and uses the resource information of the physical node where the workload instance 1 is located to form a workload context. Of course, these contexts can also be pre-generated by the control plane, and here only these contexts need to be read. Afterwards, the control plane combines the authorization rules, the authorization service context, and the workload context to generate the proxy configuration information for the service of authorizing users to enter the payment details page, and sends the proxy configuration information to the service grid proxy 1. The service grid proxy 1 can generate the corresponding authorization policy model using the received proxy configuration information.

[0096] Through the method of the above embodiment, the authorization function can be offloaded from the application code to the service grid, supporting dynamic configuration of authorization rules and authorization metadata, and being able to efficiently update the authorization policy model to realize dynamic loading of authorization services.

[0097] Corresponding to the application scenario and method of the method provided in the embodiment of the present application, the embodiment of the present application also provides an authorization processing device. Figure 5 The figure is a structural block diagram of an authorization processing device according to an embodiment of the present application, and the authorization processing device may include:

[0098] The information acquisition module 510 is used to obtain an authorization request for the application service.

[0099] The request parsing module 520 is used to parse the authorization request to obtain the authorization service corresponding to the authorization request.

[0100] The model determination module 530 is used to determine the authorization policy model that matches the authorization service; wherein the authorization policy model is generated according to the authorization rules, and the authorization rules are defined by calling an open rule definition interface.

[0101] The authorization module 540 is used to determine the authorization result of the authorization request according to the authorization request and the authorization policy model.

[0102] In some embodiments, a model generation module 550 is further included for:

[0103] Obtaining the authorization rules defined for the authorization service through the rule definition interface;

[0104] Determine the service grid context of the authorization service; wherein the service grid context includes execution environment information of the authorization service, which is obtained according to information defined by calling an open service definition interface;

[0105] Generate proxy configuration information of the authorization service according to the authorization rule and the service grid context; the proxy configuration information is used to configure the corresponding service grid proxy in the service grid;

[0106] An authorization policy model corresponding to the authorization service is constructed according to the proxy configuration information.

[0107] In some embodiments, the service grid context includes a workload context; the application service includes at least one workload instance; and the model generation module 550, when determining the service grid context of the authorization service, is used to:

[0108] Determine a workload instance corresponding to the authorization service; the workload instance corresponds to a service grid agent in the service grid; the service grid agent is used to implement a preset function to be implemented by the corresponding workload instance;

[0109] A workload context corresponding to the workload instance is acquired from a workload context set; wherein the workload context set stores a matching relationship between at least one workload instance and a workload context.

[0110] In some embodiments, the model generation module 550 is further configured to pre-generate the workload context set:

[0111] Obtain resource information of the physical nodes where each workload instance is located;

[0112] Based on the resource information, workload contexts matching each workload instance are generated respectively, and matching relationships between each workload instance and the workload context are stored in the workload context set.

[0113] In some embodiments, the service grid context includes an authorization service context; when determining the service grid context of the authorization service, the model generation module 550 is used to:

[0114] An authorization service context matching the authorization service is acquired from the authorization service context set; wherein the authorization service context set stores a matching relationship between at least one authorization service and the authorization service context.

[0115] In some embodiments, the model generation module 550 is further used to pre-generate the authorization service context set:

[0116] Obtaining authorization metadata for each authorization service in at least one authorization service through the service definition interface;

[0117] According to the authorization metadata of each authorization service, an authorization service context matching each authorization service is generated respectively, and the matching relationship between each authorization service and the authorization service context is stored in the authorization service context set.

[0118] In some embodiments, the authorization metadata includes at least one of the following:

[0119] The access address of the authorization service, the access path of the authorization service, the access port of the authorization service, the timeout constraint of the authorized access, the request header information of the authorization service access, the request body information of the authorization service access, the response header information returned by the authorization service, and the response body information returned by the authorization service.

[0120] In some embodiments, when constructing the authorization policy model corresponding to the authorization service according to the proxy configuration information, the model generation module 550 is used to:

[0121] Determine the service grid proxy corresponding to the authorized service according to the proxy configuration information; wherein the service grid includes at least one service grid proxy; the service grid proxy corresponds to the workload instance and is used to implement the preset function to be implemented by the workload instance;

[0122] The service grid agent is utilized to construct an authorization policy model corresponding to the authorization service according to the agent configuration information.

[0123] In some embodiments, when determining the authorization result of the authorization request according to the authorization request and the authorization policy model, the authorization module 540 is used to:

[0124] Using the authorization plug-in in the service grid, at least part of the information in the authorization request and information of the authorization policy model are sent to the authorization execution engine, so that the authorization execution engine runs the authorization policy model to obtain the authorization result of the authorization request;

[0125] The authorization result fed back by the authorization execution engine is received by utilizing the authorization plug-in.

[0126] The functions of each module in each device in the embodiments of the present application can be found in the corresponding description in the above method, and have corresponding beneficial effects, which will not be repeated here.

[0127] Corresponding to the application scenario and method of the method provided in the embodiment of the present application, the embodiment of the present application also provides an authorization system. Figure 6 The figure is a structural block diagram of an authorization system according to an embodiment of the present application, and the authorization system may include:

[0128] A service grid 610 that executes the above authorization processing method, and an application service 620 that is in communication with the service grid 610. The service grid 610 is used to obtain an authorization request for the application service 620, and execute the authorization processing method of the above embodiment to determine the authorization result of the authorization request.

[0129] The way in which the authorization system generates an authorization policy model and processes an authorization request is the same as in the above embodiment and will not be described again here.

[0130] Figure 7 FIG. 1 is a block diagram of an electronic device used to implement an embodiment of the present application. Figure 7 As shown, the electronic device includes: a memory 710 and a processor 720. The memory 710 stores a computer program that can be run on the processor 720. When the processor 720 executes the computer program, the method in the above embodiment is implemented. The number of the memory 710 and the processor 720 can be one or more.

[0131] The electronic device also includes:

[0132] The communication interface 730 is used to communicate with external devices and perform data exchange transmission.

[0133] If the memory 710, the processor 720 and the communication interface 730 are implemented independently, the memory 710, the processor 720 and the communication interface 730 can be connected to each other through a bus and communicate with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 7 Only one thick line is used in the diagram, but this does not mean that there is only one bus or only one type of bus.

[0134] Optionally, in a specific implementation, if the memory 710, the processor 720 and the communication interface 730 are integrated on a chip, the memory 710, the processor 720 and the communication interface 730 can communicate with each other through an internal interface.

[0135] An embodiment of the present application provides a computer-readable storage medium storing a computer program, which implements the method provided in the embodiment of the present application when the program is executed by a processor.

[0136] An embodiment of the present application also provides a chip, which includes a processor for calling and executing instructions stored in the memory from the memory, so that a communication device equipped with the chip executes the method provided in the embodiment of the present application.

[0137] An embodiment of the present application also provides a chip, including: an input interface, an output interface, a processor and a memory, wherein the input interface, the output interface, the processor and the memory are connected via an internal connection path, and the processor is used to execute the code in the memory. When the code is executed, the processor is used to execute the method provided in the embodiment of the application.

[0138] It should be understood that the processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor supporting the Advanced RISC Machines (ARM) architecture.

[0139] Further, optionally, the above-mentioned memory may include a read-only memory and a random access memory. The memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memory. Among them, the non-volatile memory may include a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may include a random access memory (RAM), which is used as an external cache. By way of exemplary but not limiting description, many forms of RAM are available. For example, static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM) and direct memory bus random access memory (DR RAM).

[0140] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function according to the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium.

[0141] In the description of this specification, the description with reference to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. Moreover, the specific features, structures, materials or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, those skilled in the art may combine and combine different embodiments or examples described in this specification and the features of different embodiments or examples, unless they are contradictory.

[0142] In addition, the terms "first" and "second" are used for descriptive purposes only and should not be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include at least one of the features. In the description of this application, the meaning of "plurality" is two or more, unless otherwise clearly and specifically defined.

[0143] Any process or method described in the flow chart or otherwise described herein can be understood as a module, fragment or portion of a code representing one or more executable instructions for implementing the steps of a specific logical function or process. And the scope of the preferred embodiment of the present application includes other implementations, in which the functions may not be performed in the order shown or discussed, including in a substantially simultaneous manner or in a reverse order according to the functions involved.

[0144] The logic and / or steps described in the flowchart or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing logical functions, which can be specifically implemented in any computer-readable medium for use by an instruction execution system, device or apparatus (such as a computer-based system, a system including a processor, or other system that can fetch instructions from an instruction execution system, device or apparatus and execute instructions), or used in combination with these instruction execution systems, devices or apparatuses.

[0145] It should be understood that the various parts of the present application can be implemented with hardware, software, firmware or a combination thereof. In the above embodiments, multiple steps or methods can be implemented with software or firmware stored in a memory and executed by a suitable instruction execution system. All or part of the steps of the above embodiment method can be completed by instructing the relevant hardware through a program, which can be stored in a computer-readable storage medium, and when the program is executed, it includes one of the steps of the method embodiment or a combination thereof.

[0146] In addition, each functional unit in each embodiment of the present application can be integrated into a processing module, or each unit can exist physically separately, or two or more units can be integrated into one module. The above-mentioned integrated module can be implemented in the form of hardware or in the form of a software functional module. If the above-mentioned integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. The storage medium can be a read-only memory, a disk or an optical disk, etc.

[0147] The above is only an exemplary embodiment of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of various changes or substitutions within the technical scope recorded in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be based on the protection scope of the claims.

Claims

1. An authorization processing method, characterized in that: Applied to a service grid, the service grid is communicatively connected with an application service to implement an authorization function of the application service, the method comprising: Obtaining an authorization request for the application service; Parsing the authorization request to obtain the authorization service corresponding to the authorization request; Determine an authorization policy model that matches the authorization service; wherein the authorization policy model is generated based on authorization rules, and the authorization rules are defined by calling an open rule definition interface; pre-generate the authorization policy model, and the generation process of the authorization policy model includes: obtaining the authorization rules defined for the authorization service through the rule definition interface; determine the service grid context of the authorization service; wherein the service grid context includes the execution environment information of the authorization service, which is obtained based on the information defined by calling the open service definition interface; generate the proxy configuration information of the authorization service based on the authorization rules and the service grid context; the proxy configuration information is used to configure the corresponding service grid proxy in the service grid; according to the proxy configuration information, construct the authorization policy model corresponding to the authorization service; An authorization result of the authorization request is determined according to the authorization request and the authorization policy model.

2. The method according to claim 1, characterized in that The service grid context includes a workload context; the application service includes at least one workload instance; The determining the service grid context of the authorization service includes: Determine a workload instance corresponding to the authorization service; the workload instance corresponds to a service grid agent in the service grid; the service grid agent is used to implement a preset function to be implemented by the corresponding workload instance; A workload context corresponding to the workload instance is acquired from a workload context set; wherein the workload context set stores a matching relationship between at least one workload instance and a workload context.

3. The method according to claim 2, characterized in that The workload context set is generated in advance, and the workload context set is generated according to the following steps: Obtain resource information of the physical node where each workload instance is located; Based on the resource information, workload contexts matching each workload instance are generated respectively, and matching relationships between each workload instance and the workload context are stored in the workload context set.

4. The method according to any one of claims 1 to 3, characterized in that: The service grid context includes an authorization service context; The determining the service grid context of the authorization service includes: An authorization service context matching the authorization service is acquired from the authorization service context set; wherein the authorization service context set stores a matching relationship between at least one authorization service and the authorization service context.

5. The method according to claim 4, characterized in that The authorization service context set is generated in advance, and the authorization service context set is generated according to the following steps: Obtaining authorization metadata for each authorization service definition in at least one authorization service through the service definition interface; According to the authorization metadata of each authorization service, an authorization service context matching each authorization service is generated respectively, and the matching relationship between each authorization service and the authorization service context is stored in the authorization service context set.

6. The method according to claim 5, characterized in that The authorization metadata includes at least one of the following: The access address of the authorization service, the access path of the authorization service, the access port of the authorization service, the access timeout constraint of the authorization service, the request header information of the authorization service, the request body information of the authorization service, the response header information corresponding to the authorization service, and the response body information corresponding to the authorization service.

7. The method according to any one of claims 1 to 3, characterized in that: The step of constructing an authorization policy model corresponding to the authorization service according to the proxy configuration information includes: Determine the service grid proxy corresponding to the authorized service according to the proxy configuration information; wherein the service grid includes at least one service grid proxy; the service grid proxy corresponds to the workload instance and is used to implement the preset function to be implemented by the workload instance; The service grid agent is utilized to construct an authorization policy model corresponding to the authorization service according to the agent configuration information.

8. The method according to claim 1, characterized in that The step of determining the authorization result of the authorization request according to the authorization request and the authorization policy model includes: Using the authorization plug-in in the service grid, at least part of the information in the authorization request and information of the authorization policy model are sent to the authorization execution engine, so that the authorization execution engine runs the authorization policy model to obtain the authorization result of the authorization request; The authorization result fed back by the authorization execution engine is received by utilizing the authorization plug-in.

9. An authorization processing device, characterized in that: Applied to a service grid, the device comprises: An information acquisition module, used to obtain authorization requests; A request parsing module, used to parse the authorization request and obtain the authorization service corresponding to the authorization request; A model determination module is used to determine an authorization policy model that matches the authorization service; wherein the authorization policy model is generated according to authorization rules, and the authorization rules are defined by calling an open rule definition interface; the authorization policy model is generated in advance, and the model determination module is also used to: obtain the authorization rules defined for the authorization service through the rule definition interface; determine the service grid context of the authorization service; wherein the service grid context includes the execution environment information of the authorization service, which is obtained according to the information defined by calling the open service definition interface; generate the proxy configuration information of the authorization service according to the authorization rules and the service grid context; the proxy configuration information is used to configure the corresponding service grid proxy in the service grid; according to the proxy configuration information, construct the authorization policy model corresponding to the authorization service; The authorization module is used to determine the authorization result of the authorization request according to the authorization request and the authorization policy model.

10. An authorization system, characterized in that: A service grid comprising the method according to any one of claims 1 to 8, and an application service in communication connection with the service grid; The service grid is used to obtain an authorization request for the application service and execute the method described in any one of claims 1 to 8 to determine an authorization result of the authorization request.

11. An electronic device comprising a memory, a processor and a computer program stored in the memory, wherein the processor implements the method according to any one of claims 1 to 8 when executing the computer program.

12. A computer-readable storage medium, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.

Citation Information

Patent Citations

  • Computing cluster system, security authentication method, node equipment and storage medium

    CN113886794A