Access Permission Authentication Method, Device, Unified Authentication System, and Program Product

The user information and interface request information are obtained through a unified authentication method, and a complete request path is generated, which solves the problems of subsystem security risks and maintenance costs, and realizes efficient unity of security authentication and interface management.

CN115550018BActive Publication Date: 2025-07-22HANGZHOU ANHENG INFORMATION SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211169501.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-09-22
Publication Date
2025-07-22
Estimated Expiration
2042-09-22

AI Technical Summary

Technical Problem

In the prior art, the subsystem lacks unified user authentication and interface access verification, resulting in security risks and increases system maintenance costs.

Method used

It provides an access permission authentication method, which can obtain user information and interface request information by receiving a request carrying a valid identity token and web page request path tag, determine its existence, and analyze and generate a complete request path, so as to realize unified authentication and interface access to the subsystem.

Benefits of technology

The security authentication of the subsystem is realized, the cost of resource development is reduced, and the security of the interface is improved through automatic interface registration and custom security policies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115550018B_ABST
    Figure CN115550018B_ABST
Patent Text Reader

Abstract

The present application relates to an access permission authentication method, device, unified authentication system, and computer program product. The method includes: receiving a first request carrying a valid identity token and a web request path label, obtaining user information from the valid identity token, thereby obtaining a list of web path labels, and determining whether the web request path label exists in the list; if it exists, obtaining the uniform resource locator of the interface request, and obtaining a list of uniform resource locators from the web request path label and user information, and determining whether the uniform resource locator exists in this list; if it exists, the authentication is passed, the uniform resource locator is parsed, the complete interface information is obtained and the complete request path is spliced, and finally the first request is forwarded to the corresponding subsystem. By using this method, user authentication for the interaction between the front-end page of the platform and multiple sub-backend system services is realized, and the security problem of the subsystem is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of interface registration, and particularly to an access permission authentication method, an access permission authentication device, a unified authentication system, and a computer program product. Background Art

[0002] With the development of the computer industry, especially the multi-functionalization of platform applications, many platform application products have multiple associated subsystems. Most of the functions of these subsystems are to provide data services for users. However, since the subsystems do not require user authentication and interface access verification, when exposed to the Internet, many security risks will be brought. Therefore, it is necessary to connect user authentication and interface access verification to the subsystems.

[0003] If a set of independent user authentication and interface verification systems are developed for each subsystem separately, it will bring huge human and resource costs. Moreover, the actual functions of the subsystems only need to provide data services for users, which have nothing to do with user authentication and interface verification. If an authentication and verification link is added to each subsystem, the system maintenance cost will increase. Summary of the Invention

[0004] Based on this, in view of the above technical problems, it is necessary to provide an access permission authentication method, an access permission authentication device, a unified authentication system, and a computer program product that can perform unified authentication on each subsystem.

[0005] In a first aspect, the present application provides an access permission authentication method, and the method includes:

[0006] Receiving a first request carrying a valid identity token and a web page request path label, where the first request includes an interface request and service parameters;

[0007] Obtaining user information based on the valid identity token, and obtaining a list of web page path labels based on the user information;

[0008] Judging whether the web page request path label exists in the list of web page path labels;

[0009] If it exists, obtaining the uniform resource locator and the interface request type of the interface request; and obtaining a list of uniform resource locators based on the web page request path label and the user information;

[0010] Judging whether the uniform resource locator of the interface request exists in the list of uniform resource locators;

[0011] If it exists, parse the uniform resource locator of the interface request to obtain the interface request protocol and the request relative path of the uniform resource locator of the interface request; based on the interface request protocol, the interface request type, and the request relative path, obtain the complete interface information;

[0012] Generate a complete request path based on the complete interface information, and forward the first request to the corresponding subsystem according to the interface request type and the complete request path.

[0013] In one embodiment, before receiving the first request carrying the valid identity token and the web request path label, it further includes:

[0014] Receive a login authentication request sent by the client;

[0015] After successful authentication, generate the valid identity token;

[0016] Associate the valid identity token with the user information and store it in the data storage system.

[0017] In one embodiment, before receiving the first request carrying the valid identity token and the web request path label, it further includes:

[0018] Obtain a request processor mapping instance through the container context, and obtain a network processing method result set based on the request processor mapping instance;

[0019] Traverse the network processing method result set and determine whether each result in the network processing method result set is annotated;

[0020] If it is annotated, receive an interface registration request initiated by the subsystem, and register the interface based on the interface registration request.

[0021] In one embodiment, the step of if it is annotated, receive an interface registration request initiated by the subsystem, and register the interface based on the interface registration request includes:

[0022] If it is annotated, obtain the interface annotation attribute value; the interface annotation attribute value includes the interface name, interface description, interface request protocol, interface request platform address, whether the interface is enabled, the uniform resource locator of the interface request, the interface access type, and the interface request type.

[0023] In one embodiment, the interface access type includes: the first access type, the second access type, the third access type, and the fourth access type;

[0024] When the interface access type is the first access type, access the corresponding subsystem through login authentication;

[0025] When the interface access type is the second access type, access the corresponding subsystem through access permission authentication;

[0026] When the interface access type is the third access type, access the corresponding subsystem after user login authentication and access permission authentication;

[0027] When the interface access type is the fourth access type, directly access the corresponding subsystem.

[0028] In one embodiment, the step of receiving an interface registration request initiated by a subsystem and registering the interface based on the interface registration request if annotated further includes:

[0029] Perform an interface warehousing operation based on an interface warehousing identifier, where the interface warehousing identifier is composed of a platform unique identifier, a uniform resource locator of the interface request, and an interface request type, and the platform unique identifier is composed of an interface request protocol and an interface request platform address;

[0030] After successful warehousing, if there is no identical interface, regard the registered successful interface as a new interface; if there is the identical interface, overwrite the original interface with the registered successful interface.

[0031] In one embodiment, after receiving an interface registration request initiated by a subsystem and registering the interface based on the interface registration request if annotated, it further includes:

[0032] Determine whether the page associated with the interface exists;

[0033] If the associated page exists, directly associate the interface with the associated page;

[0034] If the associated page does not exist, add a new associated page and then associate the interface with the associated page.

[0035] In a second aspect, the present application further provides an access permission authentication device, and the device includes:

[0036] A request receiving module, configured to receive a first request carrying a valid identity token and a web page request path label, where the first request includes an interface request and service parameters;

[0037] A first obtaining module, configured to obtain user information based on the valid identity token and obtain a list of web page path labels based on the user information;

[0038] A first judgment module, configured to judge whether the web page request path label exists in the list of web page path labels;

[0039] A second acquisition module, configured to, if existent, acquire the uniform resource locator of the interface request and the interface request type; and acquire a list of uniform resource locators based on the web request path label and the user information;

[0040] A second determination module, configured to determine whether the uniform resource locator of the interface request exists in the list of uniform resource locators;

[0041] A third acquisition module, configured to, if existent, parse the uniform resource locator of the interface request to acquire the interface request protocol and the request relative path of the uniform resource locator of the interface request; and acquire complete interface information based on the interface request protocol, the interface request type, and the request relative path;

[0042] An authentication forwarding module, configured to splice and generate a complete request path based on the complete interface information, and forward the first request to the corresponding subsystem according to the interface request type and the complete request path.

[0043] In a third aspect, the present application further provides a unified authentication system, including the access permission authentication device in the second aspect, multiple subsystems, and a data storage system, and the unified authentication system is configured to implement the steps of the method described in any one of the first aspects when executed.

[0044] In a fourth aspect, the present application further provides a computer program product, including a computer program, and the computer program implements the method steps of the first aspect when executed by a processor.

[0045] The above access permission authentication method, access permission authentication device, unified authentication system, and computer program product receive a first request carrying a valid identity token and a web request path label, acquire user information based on the valid identity token, and acquire a list of web path labels based on the user information, and determine whether the web request path label exists in the list of web path labels; if existent, acquire the uniform resource locator of the interface request and the interface request type; and acquire a list of uniform resource locators based on the web request path label and the user information, and determine whether the uniform resource locator of the interface request exists in the list of uniform resource locators; if existent, parse the uniform resource locator of the interface request to acquire the interface request protocol and the request relative path of the uniform resource locator of the interface request; acquire complete interface information based on the interface request protocol, the interface request type, and the request relative path; splice and generate a complete request path based on the complete interface information, and forward the first request to the corresponding subsystem according to the interface request type and the complete request path, thereby implementing unified platform authentication for subsystems and solving the security problem of subsystems.

[0046] In the third embodiment of the first aspect, interface automatic registration based on annotations is implemented, which reduces the cost of interface management, adds a custom security control policy for interfaces, improves the security of individual interfaces, and realizes user authentication for the interaction between the platform front-end page and multiple sub-backend system services in the unified authentication system, as well as access permission authentication for the platform front-end page access interface. BRIEF DESCRIPTION OF THE DRAWINGS

[0047] Figure 1 It is an application environment diagram of the access permission authentication method in an embodiment;

[0048] Figure 2 It is a schematic flowchart of the access permission authentication method in an embodiment;

[0049] Figure 3 It is a schematic flowchart of user login authentication before access permission authentication in an embodiment;

[0050] Figure 4 It is a schematic flowchart of the interface automatic registration method based on annotations in an embodiment;

[0051] Figure 5 It is a schematic diagram of the access permission authentication method of the exemplary embodiment;

[0052] Figure 6 It is a structural block diagram of the access permission authentication device in an embodiment;

[0053] Figure 7 It is an internal structure diagram of the unified authentication system in an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0054] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0055] The access permission authentication method provided by the embodiments of the present application can be applied to, for example Figure 1In the application environment shown. Among them, the client 102 communicates with the unified authentication system 104 through the network, and the unified authentication system 104 communicates with multiple subsystems 105 through the network. The data storage system 106 can store the data that the unified authentication system 104 needs to process. The data storage system 106 can be integrated on the unified authentication system 104, or can be placed on the cloud or other network servers. The client 102 sends a first request carrying a valid identity token and a web request path label to the unified authentication system 104. The unified authentication system 104 obtains user information based on the valid identity token, and obtains a list of web path labels based on the user information, and determines whether the web request path label exists in the list of web path labels; if it exists, obtains the uniform resource locator of the interface request and the interface request type; and obtains a list of uniform resource locators based on the web request path label and the user information, and determines whether the uniform resource locator of the interface request exists in the list of uniform resource locators; if it exists, parses the uniform resource locator of the interface request to obtain the interface request protocol and the request relative path of the uniform resource locator of the interface request; based on the interface request protocol. The interface request type and the request relative path are used to obtain the complete interface information; based on the complete interface information, a complete request path is spliced, and according to the interface request type and the complete request path, the first request is forwarded to the corresponding subsystem. Among them, the client 102 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The unified authentication system 104 can be implemented by an independent server or a server cluster composed of multiple servers.

[0056] The subsystem 105 includes a Bigdata supervision business system, which includes functions such as holographic archives, major security, notification and early warning, inspection and supervision, situation awareness, and assessment; a Baas data analysis system, which includes functions such as analysis and research, intelligence analysis, traceability, and security think tank; an App extended business function development system; a Portainer portable computer system; a Patrol patrol monitoring system for monitoring the platform status.

[0057] The unified authentication system 104 includes a page management unit, a user management unit, a role management unit, an access permission authentication device, and a data storage system. Among them, the access permission authentication device includes a subsystem interface management unit and an interface authentication forwarder.

[0058] Among them, the page management unit mainly manages the unique page identifier, which is the web page path label. The page management source can be generated by the subsystem registration or a new page can be added in the page management. An access interface can be associated with each page. Its main attributes include the web page path label code and the page-associated access interface interfaceId. The user management unit can mainly create users, and can assign corresponding roles, accounts, and passwords to each user. The account and password are used for user login authentication to obtain a valid identity token token. Its main attributes include the user ID userId, the user name nameId, the password pwd, and the role roleId. The role management unit is mainly used to create roles and can assign specified access pages to the role. Its main attributes include the web page path label code and the role roleId. The access permission authentication device is mainly used to authenticate the user's access permission to the subsystem and manage each subsystem interface. The interface source can be generated by the product subsystem interface registration or a new interface can be added in the interface management. Its main attributes include the page-associated access interface interfaceId, the interface name name, the interface description desc, the interface access type type, whether the interface is enabled, the interface request protocol prefix, the interface request platform address, whether the interface is enabled, the request relative path url, the interface access page webpage, the interface request type httpMethod, the interface request whitelist ip, and the uniform resource locator URL of the interface request.

[0059] The communication method between the client 102 and the unified authentication system 104 can be a post request or a get request.

[0060] In one embodiment, as Figure 2 shown, an access permission authentication method is provided. Taking the application environment in Figure 1 as an example, the method includes the following steps:

[0061] S202, receive a first request carrying a valid identity token and a web page request path label.

[0062] Among them, the first request includes an interface request instruction and a service access instruction.

[0063] Specifically, the first request sent by the client is sent to the unified authentication system. After receiving the first request, the unified authentication system performs login authentication through the user management unit and returns the valid identity token to the user end. At this time, the user resends the first request carrying the valid identity token and the web page request path label to the unified authentication system.

[0064] S204. Obtain user information based on the valid identity token, obtain the list of web page path tags based on the user information, and determine whether the web page request path tag exists in the list of web page path tags.

[0065] Specifically, in the unified authentication system, each user is associated with a role. Therefore, after obtaining the user information, the associated role information can naturally be obtained from the user information. And each role is assigned a specified subsystem access page, so the list of web page path tags can be obtained from the user's role information. Among them, the list of web page path tags is the sum of all subsystem pages that a role can access.

[0066] If the web page request path tag exists in the list of web page path tags, it indicates that the subsystem page requested by the user interface can be accessed.

[0067] S206. If it exists, obtain the uniform resource locator (URL) requested by the interface and the interface request type; and obtain the list of uniform resource locators based on the web page request path tag and the user information, and determine whether the uniform resource locator requested by the interface exists in the list of uniform resource locators.

[0068] S208. If it exists, resolve the uniform resource locator requested by the interface to obtain the interface request protocol and the request relative path of the uniform resource locator requested by the interface, and obtain the complete interface information based on the interface request protocol, the interface request type, and the request relative path.

[0069] Specifically, in S206 and S208, the interface request protocol and the request relative path of each subsystem are unique, and the interface request protocol and the request relative path are obtained from the uniform resource locator. Therefore, determining whether the uniform resource locator requested by the interface exists in the list of uniform resource locators can determine the subsystem to be accessed in the user interface request. If it exists, it means that the interface authentication is completed, and at this time, the access permission authentication passes, and the complete interface information of the interface request can be obtained.

[0070] S210. Generate a complete request path by splicing based on the complete interface information, and forward the first request to the corresponding subsystem according to the interface request type and the complete request path.

[0071] Specifically, after receiving the first request, the subsystem processes the service according to the service parameters in the first request, and returns the processing result to the unified authentication system, which then returns the user.

[0072] In the above access permission authentication method, interface authentication is performed by determining whether the web page request path label exists in the web page path label list and whether the uniform resource locator of the interface request exists in the uniform resource locator list in the unified authentication system, which solves the problem of subsystem security authentication. Moreover, the entire authentication process is implemented on the unified authentication platform, enabling the subsystem to only focus on business functions and reducing the cost of resource development.

[0073] In one embodiment, as Figure 3 shown, before receiving the first request carrying a valid identity token and a web page request path label, it further includes:

[0074] S302, receiving a login authentication request sent by the client.

[0075] Specifically, the login authentication request carries a username and a password, and password authentication is completed in the user management unit of the unified authentication system.

[0076] S304, after authentication passes, generating a valid identity token.

[0077] S306, associating the valid identity token with user information and storing it in the data storage system.

[0078] Specifically, after password authentication passes, the generated valid identity token token is associated with user information and stored in the data storage system.

[0079] Among them, the data storage system includes MySQL, Redis, and es.

[0080] In the above steps, through user login authentication before interface authentication, a valid identity token is obtained, providing a valid token and user information for interface authentication, further improving the security of accessing the subsystem through the unified authentication system's interface.

[0081] In one embodiment, as Figure 4 shown, before receiving the first request carrying a valid identity token and a web page request path label, it further includes:

[0082] S402, obtaining a request handler mapping instance through the container context, and obtaining a network processing method result set based on the request handler mapping instance.

[0083] Among them, the container is a spring container.

[0084] Specifically, obtain the requestMappingHandlerMapp instance through the spring container context, and then obtain the handlerMethods method result set based on the requestMappingHandlerMapp instance.

[0085] S404, traverse the result set of the network processing method, and determine whether each result in the result set of the network processing method is annotated;

[0086] Specifically, traverse the handlerMethods result set, and determine whether each result in the result set is annotated with the ApiPermissionInteface annotation.

[0087] S406, if it is annotated, receive the interface registration request initiated by the subsystem, and register the interface based on the interface registration request.

[0088] Specifically, all results in the result set are annotated with the ApiPermissionInteface annotation, and the interfaces of the subsystem are registered to the unified authentication system through interface registration. If there are results in the result set that are not annotated, the interface will not be registered.

[0089] In the above steps, the request processor mapping instance is obtained through the container, and the result set of the network processing method is obtained based on the request processor mapping instance. The result set is traversed, and each result in the result set is annotated to achieve automatic registration of the interface, reducing the cost of interface management.

[0090] In one embodiment, if it is annotated, receiving the interface registration request initiated by the subsystem and registering the interface based on the interface registration request includes:

[0091] If it is annotated, obtain the interface annotation attribute value; the interface annotation attribute value includes the interface name, interface description, interface request protocol, interface request platform address, whether the interface is enabled, the uniform resource locator requested by the interface, the interface access type, and the interface request type.

[0092] In one embodiment, the interface access type includes: the first access type, the second access type, the third access type, and the fourth access type;

[0093] When the interface access type is the first access type, access the corresponding subsystem through login authentication.

[0094] When the interface access type is the second access type, access the corresponding subsystem through access permission authentication.

[0095] When the interface access type is the third access type, access the corresponding subsystem after user login authentication and access permission authentication.

[0096] When the interface access type is the fourth access type, directly access the corresponding subsystem.

[0097] Among them, the fourth access type is IP whitelist access. IP users in the whitelist can access the subsystem without performing login authentication and interface authentication on the unified authentication system. When the interface access type is the fourth access type, it is necessary to mark the attribute value interface request whitelist ip in the interface access type type.

[0098] In this embodiment, different interface access types are set, and the subsystem access type of the user can be determined according to the role of the user, which improves the convenience for the user to log in to the subsystem through the unified authentication system, and adds a custom interface custom security control policy, improving the security of a single interface.

[0099] In one embodiment, if annotated, receiving an interface registration request initiated by the subsystem, and based on the interface registration request, registering the interface further includes:

[0100] Performing an interface warehousing operation based on the interface warehousing identifier, where the interface warehousing identifier is composed of a platform unique identifier, a uniform resource locator of the interface request, and an interface request type, and the platform unique identifier is composed of an interface request protocol and an interface request platform address.

[0101] After the warehousing is successful, if there is no same interface, the registered successful interface is used as a new interface; if there is a same interface, the registered successful interface overwrites the original interface.

[0102] In one embodiment, if annotated, after receiving an interface registration request initiated by the subsystem and registering the interface based on the interface registration request, it further includes:

[0103] Determining whether the page associated with the interface exists;

[0104] If the associated page exists, directly associate the interface to the associated page;

[0105] If the associated page does not exist, a new associated page is added, and then the interface is associated to the associated page.

[0106] In an exemplary embodiment, as Figure 5 shown, an access right authentication for a unified authentication system based on annotation is provided.

[0107] The user of the client carries the username and password and requests login authentication from the user management unit of the unified authentication system. This authentication process verifies the correctness of the password. After the login authentication passes, a valid identity token token is generated in the user management unit, and the valid identity token token is associated with the user information and stored in the storage module Redis of the data storage system, and then the valid identity token token is returned to the user.

[0108] The user sends a first request carrying a valid identity token and a web page request path label code to the access permission authentication device of the unified authentication system for interface authentication. After receiving the first request, the access permission authentication device obtains the user information from the Redis storage module based on the valid identity token, obtains the web page path label list according to the role information in the user information, and determines whether the web page request path label code is in the web page path label list. If it exists, it means that the user has passed the page verification in the access permission authentication, and the user is allowed to access the requested subsystem.

[0109] After the page verification is passed, obtain the Uniform Resource Locator (URL) of the interface request and the interface request type httpMethod, and obtain the Uniform Resource Locator list according to the web page request path label code and the user information. Determine whether the Uniform Resource Locator URL of the interface request exists in the Uniform Resource Locator list. If it exists, it means that the user has passed the interface verification in the access permission authentication, and the user can jump to the corresponding subsystem through the interface. Therefore, it is necessary to parse the Uniform Resource Locator URL of the interface request to obtain the interface request protocol prefix and the request relative path url of the URL, and based on the interface request protocol prefix, the interface request type httpMethod, and the request relative path url, obtain the complete interface information.

[0110] The complete interface information includes the interface name name, interface description desc, interface access type type, whether the interface is enabled, interface request protocol prefix, interface request platform address, whether the interface is enabled, request relative path url, interface access page webpage, interface request type httpMethod, and the Uniform Resource Locator URL of the interface request.

[0111] After the access permission authentication is passed, generate a complete request path based on the complete interface information: address + prefix + url. Forward the first request to the corresponding subsystem according to the interface request type httpMethod and the complete request path.

[0112] The subsystem processes the business according to the first request, and then returns the processing result to the access permission authentication device of the unified authentication system, which is forwarded by the access permission authentication device and returns the processing result to the user.

[0113] To implement the access permission authentication of the user on the unified authentication system, it is also necessary to register each interface on the subsystem to the unified authentication system before this:

[0114] First, obtain the request handler mapping instance requestMappingHandlerMapp through the spring container context. Then, obtain the set of network processing method results handlerMethods through the request handler mapping instance requestMappingHandleMapp. Traverse the set of network processing method results handlerMethods and determine whether each result in the set is annotated with the ApiPermissionInteface annotation. If it is annotated, obtain the ApiPermissionInteface annotation attribute value, where the ApiPermissionInteface annotation attribute value is the interface name name, interface description desc, interface access type type, whether the interface is enabled, interface request protocol prefix, interface request platform address, whether the interface is enabled, request relative path url, interface access page webpage, interface request type httpMethod, and the uniform resource locator URL of the interface request.

[0115] Next, perform interface registration. Send an interface registration request to the unified authentication system with the obtained ApiPermissionInteface annotation attribute value. After successful registration, perform an interface storage operation. The interface storage identifier is the platform-unique identifier (interface request protocol prefix + interface request platform address address) + request relative path + interface request type, that is, address + prefix + url + httpMethod. This interface storage identifier is unique. At this time, if the original interface does not exist, a new interface is added. If it exists, the latest interface information is updated. If it does not exist, a new one is added.

[0116] Finally, perform page registration. After successful interface registration, the interface needs to be associated with the corresponding page. If the original page does not exist, a new page is added and the interface is associated with this page. If the page originally exists, the interface is directly associated with this page.

[0117] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are shown in sequence according to the arrows, these steps do not necessarily have to be executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily have to be executed at the same time, but can be executed at different times. The execution order of these steps or stages does not necessarily have to be sequential, but can be executed alternately or alternately with at least a part of the steps or stages in other steps or other steps.

[0118] Based on the same inventive concept, an embodiment of the present application further provides an access right authentication device for implementing the access right authentication method involved above. The solution for solving the problem provided by this device is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the access right authentication device provided below can refer to the limitations on the access right authentication method in the above text, and will not be elaborated here.

[0119] In one embodiment, as Figure 6 shown, an access right authentication device is provided, including: a request receiving module 60, a first obtaining module 61, a first judging module 62, a second obtaining module 63, a second judging module 64, a third obtaining module 65, and an authentication forwarding module 66, where:

[0120] The request receiving module 60 is configured to receive a first request carrying a valid identity token and a web page request path label, where the first request includes an interface request and service parameters;

[0121] The first obtaining module 61 is configured to obtain user information based on the valid identity token, and obtain a list of web page path labels based on the user information;

[0122] The first judging module 62 is configured to judge whether the web page request path label exists in the list of web page path labels;

[0123] The second obtaining module 63 is configured to, if it exists, obtain the uniform resource locator and interface request type of the interface request; and obtain a list of uniform resource locators based on the web page request path label and user information;

[0124] The second judging module 64 is configured to judge whether the uniform resource locator of the interface request exists in the list of uniform resource locators;

[0125] The third obtaining module 65 is configured to, if it exists, parse the uniform resource locator of the interface request to obtain the interface request protocol and request relative path of the uniform resource locator of the interface request; and obtain complete interface information based on the interface request protocol, interface request type, and the request relative path;

[0126] The authentication forwarding module 66 is configured to splice and generate a complete request path based on the complete interface information, and forward the first request to the corresponding subsystem according to the interface request type and the complete request path.

[0127] Each module in the above access permission authentication device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0128] In one embodiment, as Figure 7 shown, a unified authentication system is provided, including an access permission authentication device 72, a plurality of subsystems 74, and a data storage system 76. When the unified authentication system is executed, the following steps are implemented:

[0129] S202: Receive a first request carrying a valid identity token and a web request path label.

[0130] S204: Obtain user information based on the valid identity token, and obtain a list of web path labels based on the user information; determine whether the web request path label exists in the list of web path labels.

[0131] S206: If it exists, obtain the uniform resource locator (URL) of the interface request and the interface request type; and obtain a list of uniform resource locators based on the web request path label and the user information; determine whether the uniform resource locator of the interface request exists in the list of uniform resource locators.

[0132] S208: If it exists, parse the uniform resource locator of the interface request to obtain the interface request protocol and the request relative path of the uniform resource locator of the interface request; obtain the complete interface information based on the interface request protocol, the interface request type, and the request relative path.

[0133] S210: Generate a complete request path based on the complete interface information, and forward the first request to the corresponding subsystem according to the interface request type and the complete request path.

[0134] In one of the embodiments, the user management module of the unified authentication system includes:

[0135] Receive a login authentication request sent by the client;

[0136] After successful authentication, generate a valid identity token;

[0137] Associate the valid identity token with the user information and store it in the data storage system.

[0138] In one of the embodiments, the access permission authentication device 72 further includes:

[0139] Obtain a request processor mapping instance through the container context, and obtain a set of network processing method results based on the request processor mapping instance;

[0140] Traverse the result set of the network processing method, and determine whether each result in the result set of the network processing method is annotated;

[0141] If it is annotated, receive the interface registration request initiated by the subsystem, and register the interface based on the interface registration request.

[0142] In one embodiment, the access permission authentication device 72 includes:

[0143] If it is annotated, obtain the interface annotation attribute value; the interface annotation attribute value includes the interface name, interface description, interface request protocol, interface request platform address, whether the interface is enabled, the uniform resource locator requested by the interface, the interface access type, and the interface request type.

[0144] In one embodiment, the interface access types of the access permission authentication device 72 include: the first access type, the second access type, the third access type, and the fourth access type;

[0145] When the interface access type is the first access type, access the corresponding subsystem through login authentication;

[0146] When the interface access type is the second access type, access the corresponding subsystem through access permission authentication;

[0147] When the interface access type is the third access type, access the corresponding subsystem after user login authentication and access permission authentication;

[0148] When the interface access type is the fourth access type, directly access the corresponding subsystem.

[0149] In one embodiment, the access permission authentication device 72 further includes:

[0150] Perform an interface warehousing operation based on the interface warehousing identifier, which is composed of the platform unique identifier, the uniform resource locator requested by the interface, and the interface request type, and the platform unique identifier is composed of the interface request protocol and the interface request platform address;

[0151] After the warehousing is successful, if there is no same interface, use the registered successful interface as a new interface; if there is a same interface, overwrite the original interface with the registered successful interface.

[0152] In one embodiment, the access permission authentication device 72 further includes:

[0153] Determine whether the page associated with the interface exists;

[0154] If the associated page exists, directly associate the interface to the associated page;

[0155] If the associated page does not exist, a new associated page is added, and then the interface is associated with the associated page.

[0156] In one embodiment, a computer program product is provided, including a computer program which, when executed by a processor, implements the following steps:

[0157] S202, receive a first request carrying a valid identity token and a web request path label.

[0158] S204, obtain user information based on the valid identity token, and obtain a list of web path labels based on the user information; determine whether the web request path label exists in the list of web path labels.

[0159] S206, if it exists, obtain the uniform resource locator of the interface request and the interface request type; and obtain a list of uniform resource locators based on the web request path label and the user information; determine whether the uniform resource locator of the interface request exists in the list of uniform resource locators.

[0160] S208, if it exists, parse the uniform resource locator of the interface request to obtain the interface request protocol and the request relative path of the uniform resource locator of the interface request; based on the interface request protocol, the interface request type, and the request relative path, obtain the complete interface information.

[0161] S210, splice and generate a complete request path based on the complete interface information, and forward the first request to the corresponding subsystem according to the interface request type and the complete request path.

[0162] In one of the embodiments, when the computer program is executed by a processor, the following steps are further implemented:

[0163] Receive a login authentication request sent by the client;

[0164] After successful authentication, generate a valid identity token;

[0165] Associate the valid identity token with the user information and store it in the data storage system.

[0166] In one of the embodiments, when the computer program is executed by a processor, the following steps are further implemented:

[0167] Obtain a request processor mapping instance through the container context, and obtain a network processing method result set based on the request processor mapping instance;

[0168] Traverse the network processing method result set, and determine whether each result in the network processing method result set is annotated;

[0169] If annotated, receive the interface registration request initiated by the receiving subsystem and register the interface based on the interface registration request.

[0170] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0171] If annotated, obtain the interface annotation attribute value; the interface annotation attribute value includes the interface name, interface description, interface request protocol, interface request platform address, whether the interface is enabled, the uniform resource locator of the interface request, interface access type, and interface request type.

[0172] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0173] When the interface access type is the first access type, access the corresponding subsystem through login authentication.

[0174] When the interface access type is the second access type, access the corresponding subsystem through access permission authentication.

[0175] When the interface access type is the third access type, access the corresponding subsystem after user login authentication and access permission authentication.

[0176] When the interface access type is the fourth access type, directly access the corresponding subsystem.

[0177] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0178] Perform interface warehousing operation based on the interface warehousing identifier, where the interface warehousing identifier is composed of the platform unique identifier, the uniform resource locator of the interface request, and the interface request type, and the platform unique identifier is composed of the interface request protocol and the interface request platform address;

[0179] After successful warehousing, if there is no identical interface, regard the registered successful interface as a new interface; if there is an identical interface, overwrite the original interface with the registered successful interface.

[0180] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented:

[0181] Determine whether the page associated with the interface exists;

[0182] If the associated page exists, directly associate the interface with the associated page;

[0183] If the associated page does not exist, add a new associated page and then associate the interface with the associated page.

[0184] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties.

[0185] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAM), magnetoresistive random access memories (MRAM), ferroelectric random access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logics, data processing logics based on quantum computing, etc., without limitation.

[0186] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.

[0187] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.

Claims

1. An access permission authentication method, characterized in that The method includes: Receiving a first request carrying a valid identity token and a web request path label, where the first request includes an interface request and service parameters; Obtaining user information based on the valid identity token, and obtaining a list of web path labels based on the user information; Determining whether the web request path label exists in the list of web path labels; If it exists, obtaining the uniform resource locator (URL) of the interface request and the interface request type; and obtaining a list of uniform resource locators based on the web request path label and the user information; Determining whether the uniform resource locator of the interface request exists in the list of uniform resource locators; If it exists, parsing the uniform resource locator of the interface request to obtain the interface request protocol and the request relative path of the uniform resource locator of the interface request; and obtaining complete interface information based on the interface request protocol, the interface request type, and the request relative path; Generating a complete request path by splicing based on the complete interface information, and forwarding the first request to the corresponding subsystem according to the interface request type and the complete request path; Before receiving the first request carrying a valid identity token and a web request path label, it further includes: Obtaining a request processor mapping instance through the container context, and obtaining a set of network processing method results based on the request processor mapping instance; Traversing the set of network processing method results, and determining whether each result in the set of network processing method results is annotated; If it is annotated, receiving an interface registration request initiated by the subsystem, and registering the interface based on the interface registration request.

2. The access permission authentication method according to claim 1, characterized in that, Before receiving the first request carrying a valid identity token and a web request path label, it further includes: Receiving a login authentication request sent by the client; After successful authentication, generating the valid identity token; Associating the valid identity token with the user information and storing it in the data storage system.

3. The access permission authentication method according to claim 1, characterized in that The step of, if it is annotated, receiving an interface registration request initiated by the subsystem and registering the interface based on the interface registration request includes: If it is annotated, obtaining the interface annotation attribute value; the interface annotation attribute value includes the interface name, interface description, interface request protocol, interface request platform address, whether the interface is enabled, the uniform resource locator of the interface request, the interface access type, and the interface request type.

4. The access permission authentication method according to claim 3, characterized in that The interface access type includes: a first access type, a second access type, a third access type, and a fourth access type; When the interface access type is the first access type, accessing the corresponding subsystem through login authentication; When the interface access type is the second access type, accessing the corresponding subsystem through access permission authentication; When the interface access type is the third access type, accessing the corresponding subsystem after user login authentication and access permission authentication; When the interface access type is the fourth access type, directly accessing the corresponding subsystem.

5. The access permission authentication method according to claim 1, wherein The step of, if it is annotated, receiving an interface registration request initiated by the subsystem and registering the interface based on the interface registration request further includes: Perform interface warehousing operation based on the interface warehousing identifier, where the interface warehousing identifier consists of a platform unique identifier, a uniform resource locator of the interface request, and an interface request type, and the platform unique identifier consists of an interface request protocol and an interface request platform address; After successful warehousing, if there is no identical interface, the registered successful interface is taken as a newly added interface; if there is the identical interface, the registered successful interface overwrites the original interface.

6. The access permission authentication method according to claim 1, characterized in that If annotated, after receiving an interface registration request initiated by a subsystem and registering the interface based on the interface registration request, it further includes: Determine whether the page associated with the interface exists; If the associated page exists, directly associate the interface with the associated page; If the associated page does not exist, add a new associated page and then associate the interface with the associated page.

7. An access right authentication device, characterized in that The device includes: A request receiving module, configured to receive a first request carrying a valid identity token and a web request path label, where the first request includes an interface request instruction and a service access instruction; A first obtaining module, configured to obtain user information based on the valid identity token and obtain a list of web path labels based on the user information; A first judging module, configured to judge whether the web request path label exists in the list of web path labels; A second obtaining module, configured to, if it exists, obtain a uniform resource locator of the interface request and an interface request type; and obtain a list of uniform resource locators based on the web request path label and the user information; A second judging module, configured to judge whether the uniform resource locator of the interface request exists in the list of uniform resource locators; A third obtaining module, configured to, if it exists, parse the uniform resource locator of the interface request to obtain an interface request protocol and a request relative path of the uniform resource locator of the interface request; and obtain complete interface information based on the interface request protocol, the interface request type, and the request relative path; An authentication forwarding module, configured to splice a complete request path based on the complete interface information and forward the first request to the corresponding subsystem according to the interface request type and the complete request path; Before receiving the first request carrying a valid identity token and a web request path label, it further includes: obtaining a request processor mapping instance through a container context, obtaining a network processing method result set based on the request processor mapping instance; traversing the network processing method result set to judge whether each result in the network processing method result set is annotated; if annotated, receive an interface registration request initiated by a subsystem and register the interface based on the interface registration request.

8. A unified authentication system, comprising the access right authentication device described in claim 7, a plurality of subsystems, and a data storage system, characterized in that, This unified authentication system is used to implement the steps of the method described in any one of claims 1 to 6 when executed.

9. A computer program product, comprising a computer program, characterized in that, This computer program implements the steps of the method described in any one of claims 1 to 6 when executed by a processor.

Citation Information

Patent Citations

  • Multi-user authentication method, device and system and storage medium

    CN113518091A

  • Security management system based on micro-service

    CN113839966A