Data access method, node and hub
Patent Information
- Application Number
- CN202110750165.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-07-02
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2041-07-02
AI Technical Summary
[0004]在现有技术中,当某一层级的用户想要访问另一层级的应用时,必须在该另一层级注册一个新账号,并通过登录新账号的方式访问该另一层级的应用,用户需要二次登陆才能够访问到跨层级的应用,且在注册账号和登录节点的过程中均需要用户进行人工操作,存在繁琐复杂、低效耗时的问题
[0105]第九方面,本发明实施例提供一种计算机程序,该计算机程序包括计算机指令,该计算机指令存储在计算机可读存储介质中,当计算机设备的处理器从计算机可读存储介质读取该计算机指令,处理器执行该计算机指令,使得该计算机设备执行实现如第一、第二或第三方面所提供的方法的步骤。
Smart Images

Figure CN115563591B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of distributed access technology, and more specifically, to a data access method, a node, and a cascading center. Background Technology
[0002] The innovation of information technology has transformed people's traditional ways of working, learning, living, and entertaining, while also posing challenges to how organizational systems (such as enterprises or governments) provide information services and facilitate user participation in decision-making. Utilizing information technology to improve the efficiency of organizational work and services, and to create new ways of working, has become a concern for all types of organizational systems.
[0003] Many organizational systems have multiple levels. Taking a government system as an example, there are five levels: province, city, county, and township. Each level wants to deploy an independent application, but they also need to be interconnected to ensure cross-level collaboration when users at different levels access applications at other levels within their authorized access permissions.
[0004] In existing technologies, when a user at one level wants to access an application at another level, they must register a new account at that other level and log in to the application by logging in to the new account. Users need to log in twice to access cross-level applications, and both the account registration and login processes require manual operation by the user, which is cumbersome, inefficient, and time-consuming. Summary of the Invention
[0005] This invention provides a data access method, node, and cascading center that overcomes or at least partially solves the above-mentioned problems.
[0006] Firstly, a distributed system data access method is provided, wherein the distributed system includes at least two nodes, and the data access method is executed by the first node among the at least two nodes, the method comprising:
[0007] Determine the second node identifier of the second node where the target data is located; the target data is the data that the target user on the first node needs to access.
[0008] If it is determined that there is target authentication information in the first-level concatenation information that corresponds to the target user identifier and the second node identifier of the target user, a data access request is generated, which includes the target user identifier and the target authentication information.
[0009] Send a data access request to the second node to instruct the second node to authenticate the target user identifier and target authentication information based on the second concatenation information, and grant the first node access to the target data after successful authentication.
[0010] In one possible implementation, the first concatenation information is used to store the user identifiers of each local user in the first node, the authentication information of the corresponding local user accessing data across nodes, and the correspondence between the node identifiers of the cross nodes; the second concatenation information is used to store the user identifiers of each cross-node user accessing the target data, and the authentication information of the corresponding cross-node user accessing the target data.
[0011] In one possible implementation, the distributed system also includes a cascading center, which is used to store the first cascading information and the second cascading information.
[0012] If it is determined that the first-level concatenation information contains target authentication information that corresponds to the target user identifier and the second node identifier of the target user, including:
[0013] Send the target user identifier and the second node identifier of the target user to the cascading center to instruct the cascading center to determine in the cascading center whether there is target authentication information that corresponds to the target user identifier and the second node identifier of the target user.
[0014] This instructs the second node to authenticate the target user identifier and target authentication information based on the second concatenation information, including:
[0015] This instructs the second node to send the target user identifier and target authentication information to the cascading center, which then authenticates the target user identifier and target authentication information based on the second cascading information.
[0016] In one possible implementation, if it is determined that there is target authentication information in the first concatenation information that corresponds to the target user identifier and the second node identifier of the target user, the following steps are also included beforehand:
[0017] Generate an access request, which includes the first node identifier of the first node and the target user identifier;
[0018] Send an access request to the second node to instruct the second node to configure the target user's role, determine the target user's role information on the second node, and the role information has the permission to access the target data;
[0019] Target authentication information is generated based on the returned role information. The correspondence between the target user identifier, the second node identifier and the target authentication information is stored in the first concatenation information.
[0020] In one possible implementation, the target authentication information is generated, followed by:
[0021] The target authentication information is synchronized to the second node, instructing the second node to store the correspondence between the target user identifier, role information, and target authentication information in the second cascade information.
[0022] In one possible implementation, an access request is sent to the second node to instruct the second node to configure the target user's role and determine the target user's role information on the second node, including:
[0023] An access request is sent to the second node to instruct the second node to determine the interface address for user authentication of the first node based on the second concatenation information; the second concatenation information is also used to store the correspondence between the node identifier of the node in the distributed system and the interface address for user authentication of the corresponding node.
[0024] Receive the call request from the second node's API address and perform user authentication on the target user identifier included in the call request;
[0025] If the target user identifier is verified, a response indicating successful user authentication is sent to the second node, instructing the second node to generate role information based on the target user identifier.
[0026] In one possible implementation, determining the second node identifier of the second node where the target data resides includes, before:
[0027] Receive the data address information broadcast by the second node after storing the target data. The data address information includes the access address of the target data and the identifier of the second node.
[0028] The first concatenation information stores the correspondence between the access address of the target data and the identifier of the second node.
[0029] The second node identifier for determining the second node where the target data is located includes:
[0030] Determine the access address of the target data, and identify the second node identifier that corresponds to the access address from the first cascade information.
[0031] Secondly, a data access method is provided in a distributed system, wherein the distributed system includes at least two nodes, and the data access method is executed by the second node of the at least two nodes, the method including:
[0032] Receive a data access request for target data sent by the first node. The target data is the data to be accessed by the target user of the first node. The data access request includes the target user identifier and the target authentication information determined by the first node based on the first concatenation information, which corresponds to the target user identifier and the second node identifier of the second node.
[0033] The target user identifier and target authentication information are authenticated based on the second-level information, and the first node is granted access to the target data after successful authentication.
[0034] In one possible implementation, the first concatenation information is used to store the user identifiers of each local user in the first node, the authentication information of the corresponding local user accessing data across nodes, and the correspondence between the node identifiers of the cross nodes; the second concatenation information is used to store the user identifiers of each cross-node user accessing the target data, and the authentication information of the corresponding cross-node user accessing the target data.
[0035] In one possible implementation, the distributed system also includes a cascading center, which is used to store the first cascading information and the second cascading information.
[0036] Authentication is performed on the target user identifier and target authentication information based on the second-level concatenation information, including:
[0037] The target user identifier and target authentication information are sent to the cascading center, which then authenticates the target user identifier and target authentication information based on the second-level cascading information.
[0038] In one possible implementation, receiving the data access request sent by the first node, before that includes:
[0039] Receive an access request sent by the first node when it determines that no target authentication information exists. The access request includes the first node's first node identifier and the target user identifier.
[0040] Based on the first node identifier and the target user identifier, the target user is assigned a role, and the target user's role information in the second node is determined. The role information grants the user the permission to access the target data.
[0041] Send the role information to the first node to instruct the first node to generate and return authentication information based on the role information;
[0042] The second-level information stores the correspondence between the target user identifier, role information, and target authentication information.
[0043] In one possible implementation, authentication of the target user identifier and target authentication information is performed based on pre-stored second-level concatenation information, including:
[0044] Search the second-level information for role information corresponding to the target user identifier and target authentication information;
[0045] If corresponding role information exists, authentication is successful based on the role information's permission to access the target data.
[0046] If no corresponding role information exists, authentication will fail.
[0047] In one possible implementation, the target user's role is configured based on the first node identifier and the target user identifier, including:
[0048] Based on the first node identifier, the interface address for user authentication of the first node is determined in the second concatenation information. The second concatenation information is also used to store the correspondence between the node identifier of the node in the distributed system and the interface address for user authentication of the corresponding node.
[0049] Send a call request to the first node, which includes the target user identifier, to instruct the first node to perform user authentication based on the target user identifier;
[0050] If a response indicating successful user authentication is received from the first node, role information is generated based on the target user identifier.
[0051] In one possible implementation, the method also includes:
[0052] Store the target data and broadcast the data address information in the distributed system. The data address information includes the access address of the target data and the identifier of the second node.
[0053] Thirdly, a data access method is provided in a distributed system, the distributed system including a cascaded center and at least two nodes, the at least two nodes including a first node and a second node, the data access method being executed by the cascaded center, the method including:
[0054] Save the first cascade information of the first node and the cascade information of the second node;
[0055] If the target user identifier and target authentication information are received from the second node, the target user identifier and target authentication information are authenticated according to the second concatenation information, and the authentication result is sent back to the second node.
[0056] The first cascade information is used to store the user identifiers of each local user in the first node, the authentication information of the corresponding local user accessing data across nodes, and the correspondence between node identifiers across nodes.
[0057] The second-level concatenation information is used to store the user identifiers of each cross-node user accessing the target data, as well as the authentication information for the corresponding cross-node user accessing the target data.
[0058] Fourthly, a first node in a distributed system is provided, comprising:
[0059] The second node identifier determination module is used to determine the second node identifier of the second node where the target data is located. The target data is the data to be accessed by the target user in the first node.
[0060] The access request generation module is used to generate a data access request if it is determined that there is target authentication information in the first concatenation information that corresponds to the target user identifier and the second node identifier of the target user. The data access request includes the target user identifier and the target authentication information.
[0061] The access request generation module is used to send a data access request to the second node, instructing the second node to authenticate the target user identifier and target authentication information based on the second concatenation information, and grant the first node access to the target data after successful authentication.
[0062] In one possible implementation, the distributed system also includes a cascading center, which is used to store the first cascading information and the second cascading information.
[0063] The access request generation module is specifically used to: send the target user identifier and the second node identifier of the target user to the cascading center, so as to instruct the cascading center to determine in the cascading center whether there is target authentication information that corresponds to the target user identifier and the second node identifier of the target user;
[0064] The access request generation module is specifically used to instruct the second node to send the target user identifier and target authentication information to the cascading center, which then authenticates the target user identifier and target authentication information based on the second cascading information.
[0065] In one possible implementation, the first node also includes:
[0066] The access request generation module is used to generate access requests, which include the first node identifier of the first node and the target user identifier.
[0067] The access request sending module is used to send an access request to the second node to instruct the second node to configure the target user's role and determine the target user's role information on the second node. The role information has the permission to access the target data.
[0068] The first correspondence generation module is used to generate target authentication information based on the returned role information, and stores the correspondence between the target user identifier, the second node identifier and the target authentication information in the first concatenation information.
[0069] In one possible implementation, the first node also includes:
[0070] The target authentication sending information module is used to synchronize the target authentication information to the second node, so as to instruct the second node to store the correspondence between the target user identifier, role information and target authentication information in the second concatenation information.
[0071] In one possible implementation, the access request sending module includes:
[0072] The access request sending unit is used to send an access request to the second node, instructing the second node to determine the interface address for user authentication of the first node based on the second concatenation information; the second concatenation information is also used to store the correspondence between the node identifier of the node in the distributed system and the interface address for user authentication of the corresponding node.
[0073] The authentication unit is used to receive the call request from the second node's call interface address and perform user authentication on the target user identifier included in the call request;
[0074] The authentication response unit is used to send a response message indicating that the user authentication has been passed to the second node if the target user identifier is successfully verified, so as to instruct the second node to generate role information based on the target user identifier.
[0075] In one possible implementation, the first node also includes:
[0076] The broadcast receiving module is used to receive the data address information broadcast by the second node after storing the target data. The data address information includes the access address of the target data and the identifier of the second node.
[0077] The mapping relationship storage module is used to store the mapping relationship between the access address of the target data and the second node identifier in the first concatenation information;
[0078] The second node identifier determination module is specifically used to: determine the access address of the target data, and determine the second node identifier that corresponds to the access address from the first cascade information.
[0079] Fifthly, a second node in a distributed system is provided, comprising:
[0080] The access request receiving module is used to receive a data access request for target data sent by the first node. The target data is the data to be accessed by the target user of the first node. The data access request includes the target user identifier and the target authentication information determined by the first node based on the first concatenation information, which corresponds to the target user identifier and the second node identifier of the second node.
[0081] The authentication module is used to authenticate the target user identifier and target authentication information based on the pre-stored second-level concatenation information, and grant the first node access to the target data after successful authentication.
[0082] In one possible implementation, the distributed system also includes a cascading center, which is used to store the first cascading information and the second cascading information.
[0083] The authentication module is specifically used to send the target user identifier and target authentication information to the cascading center, which then authenticates the target user identifier and target authentication information based on the second-level cascading information.
[0084] In one possible implementation, the first node also includes:
[0085] The access request receiving module is used to receive the access request sent by the first node when it determines that there is no target authentication information. The access request includes the first node identifier and the target user identifier of the first node.
[0086] The role configuration module is used to configure the role of the target user based on the first node identifier and the target user identifier, and to determine the role information of the target user in the second node. The role information has the permission to access the target data.
[0087] The role feedback module is used to send role information to the first node, so that the first node can generate and return authentication information based on the role information;
[0088] The second correspondence generation module is used to store the correspondence between the target user identifier, role information and target authentication information in the second concatenation information.
[0089] In one possible implementation, the authentication module includes:
[0090] The search unit is used to search for role information corresponding to the target user identifier and target authentication information in the second-level information;
[0091] The judgment unit is used to determine whether authentication is successful if the corresponding role information exists and the role information has the permission to access the target data; otherwise, it determines that authentication is unsuccessful.
[0092] In one possible implementation, the role configuration module includes:
[0093] The interface address acquisition unit is used to determine the interface address of the first node for user authentication based on the first node identifier in the second concatenation information. The second concatenation information is also used to store the correspondence between the node identifier of the node in the distributed system and the interface address of the corresponding node for user authentication.
[0094] The interface invocation unit is used to send an invocation request to the first node to call the interface address. The invocation request includes the target user identifier to instruct the first node to perform user authentication based on the target user identifier.
[0095] The role generation unit is used to generate role information based on the target user identifier if it receives a response message from the first node indicating that the user authentication has passed.
[0096] In one possible implementation, the second node also includes:
[0097] The broadcast module is used to store target data and broadcast data address information in the distributed system. The data address information includes the access address of the target data and the identifier of the second node.
[0098] Sixthly, a cascading center is provided in a distributed system, the distributed system comprising at least two nodes, the at least two nodes including a first node and a second node, and the cascading center comprising:
[0099] The cascading information storage module is used to store the first cascading information of the first node and the cascading information of the second node.
[0100] The cascaded authentication module is used to authenticate the target user identifier and target authentication information according to the second cascade information if it receives the target user identifier and target authentication information sent by the second node, and to send the authentication result back to the second node.
[0101] The first cascade information is used to store the user identifiers of each local user in the first node, the authentication information of the corresponding local user accessing data across nodes, and the correspondence between node identifiers across nodes.
[0102] The second-level concatenation information is used to store the user identifiers of each cross-node user accessing the target data, as well as the authentication information for the corresponding cross-node user accessing the target data.
[0103] In a seventh aspect, embodiments of the present invention provide an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the steps of the methods provided in the first, second, or third aspects.
[0104] Eighthly, embodiments of the present invention provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the methods provided in the first, second, or third aspects.
[0105] In a ninth aspect, embodiments of the present invention provide a computer program including computer instructions stored in a computer-readable storage medium. When a processor of a computer device reads the computer instructions from the computer-readable storage medium, the processor executes the computer instructions, causing the computer device to perform steps implementing the methods provided in the first, second, or third aspects.
[0106] The data access method, node, cascading center, electronic device, and storage medium provided in this invention allow a user of a first node to access data on a second node across nodes. By determining the second node identifier of the second node where the target data is located, and if authentication information corresponding to the second node identifier is found in the first cascading information, a data access request is sent to the second node. This instructs the second node to authenticate the user identifier and authentication information based on the second cascading information. Upon successful authentication, the user's access to the target data is granted. This embodiment does not require the user to re-register an account on the second node. Instead, it determines whether to grant access based on the user identifier and authentication information stored in the cascading information of each node on the first node. This achieves cross-node information integration, allowing users to access data across nodes without obstacles, while also ensuring data independence. Users do not need to log in twice or register additional accounts across nodes, significantly improving data access efficiency. Attached Figure Description
[0107] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments of this application will be briefly introduced below.
[0108] Figure 1 A schematic diagram illustrating an optional scenario of a distributed system applied to a blockchain system, as provided in the embodiments of the application.
[0109] Figure 2 An optional schematic diagram of the block structure provided in the embodiments of this application;
[0110] Figure 3 A system architecture diagram of a distributed system provided in this application embodiment;
[0111] Figure 4 This is a flowchart illustrating the data access method applied to the first node according to an embodiment of this application;
[0112] Figure 5 This is a schematic diagram illustrating the deployment of an application on a provincial open platform according to an embodiment of this application;
[0113] Figure 6 This is a flowchart illustrating the data method executed by the first node in an embodiment of this application;
[0114] Figure 7 This is a flowchart illustrating the data method executed by the second node in an embodiment of this application;
[0115] Figure 8 This is a system architecture diagram for applying the data methods of this application to a government affairs system;
[0116] Figure 9 This is a schematic diagram illustrating the cascading of identity information in a government affairs system according to an embodiment of this application;
[0117] Figure 10 This is a flowchart illustrating the data method applied to a government system according to an embodiment of this application;
[0118] Figure 11 This application provides a schematic diagram of the structure of a first node according to an embodiment of the present application;
[0119] Figure 12 This is a schematic diagram of the structure of a second node provided in an embodiment of this application;
[0120] Figure 13 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation
[0121] The embodiments of this application are described in detail below. Examples of the embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting the invention.
[0122] Those skilled in the art will understand that, unless explicitly stated otherwise, the singular forms “a,” “an,” and “the” used herein may also include the plural forms. It should be further understood that the term “comprising” as used in the specification of this application means the presence of features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or groups thereof. It should be understood that when we say an element is “connected” or “coupled” to another element, it can be directly connected or coupled to the other element, or there may be intermediate elements. Furthermore, “connected” or “coupled” as used herein can include wireless connections or wireless coupling. The term “and / or” as used herein includes all or any units and all combinations of one or more associated listed items.
[0123] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0124] The data access method, apparatus, electronic device, and computer-readable storage medium for cross-nodes in a distributed system provided in this application are intended to solve the above-mentioned technical problems of the prior art.
[0125] The technical solution of this application and how the technical solution of this application solves the above-mentioned technical problems are described in detail below with specific embodiments. These specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described again in some embodiments. The embodiments of this application will now be described with reference to the accompanying drawings.
[0126] The following will combine Figure 1 and Figure 2 The following describes specific implementation scenarios provided in the embodiments of this application. The blockchain network involved in the embodiments of this application can be a distributed system formed by connecting clients and multiple nodes (any form of computing device in the network, such as servers and user terminals) through network communication.
[0127] Taking a distributed system as an example, see blockchain system. Figure 1 , Figure 1 This is a schematic diagram of an optional scenario where the distributed system 100 provided in this application is applied to a blockchain system. It consists of multiple nodes 200 (any form of computing device connected to the network, such as servers or user terminals) and clients 300. The nodes form a peer-to-peer (P2P) network. The P2P protocol is an application layer protocol running on top of the Transmission Control Protocol (TCP). In the distributed system, any machine, such as a server or terminal, can join and become a node. A node includes a hardware layer, a middleware layer, an operating system layer, and an application layer.
[0128] See Figure 1 The functions of each node in the blockchain system shown include:
[0129] 1) Routing: A basic function of nodes used to support communication between nodes.
[0130] In addition to routing capabilities, nodes can also have the following functions:
[0131] 2) Applications are deployed in the blockchain to implement specific business needs. They record data related to the implementation of functions to form record data, carry digital signatures in the record data to indicate the source of the task data, and send the record data to other nodes in the blockchain system. When other nodes successfully verify the source and integrity of the record data, they add the record data to a temporary block.
[0132] 3) A blockchain consists of a series of blocks that are sequentially generated. Once a new block is added to the blockchain, it will not be removed. The blocks record the data submitted by the nodes in the blockchain system.
[0133] See Figure 2 , Figure 2This is an optional schematic diagram of the block structure provided in the embodiments of this application. Each block includes the hash value of the transaction records stored in this block (the hash value of this block) and the hash value of the previous block. The blocks are connected through the hash values to form a blockchain.
[0134] Figure 3 A system architecture diagram of a distributed system provided in this application embodiment is shown below. Figure 3 The blockchain network 10 includes nodes 101, 102, ..., 10n. Each node stores exclusive data and public data. Exclusive data refers to data accessible only to user terminals connected to the node itself, while public data refers to data accessible to authorized user terminals not connected to the node. By cascading the nodes, user terminals can gain access to the public data on other nodes. The data in this embodiment can be applications, mini-programs, audio, video, images, web pages, etc.
[0135] The blockchain network 10 establishes a link with the user terminal cluster 30 through the communication bus 20. Each terminal in the user terminal cluster establishes a link with a corresponding node. For example, user terminal 301 and user terminal 302 establish a link with node 101, user terminal 303 establishes a link with node 102, ..., user terminals 30m and 30n establish a link with node 10n. By establishing a link with the corresponding node, the user terminal can access the exclusive data stored by the corresponding node, and through the data access method of this application embodiment, realize the access to public data across nodes.
[0136] Please see Figure 4 The figure illustrates an exemplary flowchart of a data access method applied to a first node according to an embodiment of this application, as shown in the figure, including:
[0137] S101. Determine the second node identifier of the second node where the target data is located.
[0138] Depend on Figure 3 As can be seen, the node in this application embodiment can be linked to multiple user terminals, and each user terminal can be understood as corresponding to a unique user. The target data in this application embodiment is the data to be accessed by the target user of the first node, and the data is stored across nodes.
[0139] When a first node wants to access public data, i.e., target data, on other nodes (such as the second node), it first needs to know the node identifier of the node where the target data is located. Taking the second node as an example, the node identifier of the second node is called the second node identifier, and the corresponding node identifier of the first node itself is called the first node identifier. In this embodiment, the information obtained by each node during its interaction with other nodes is stored in the cascading information stored within the node itself, such as the user's user identifier, authentication information required for the user to access information normally on other nodes, etc.
[0140] In the government affairs system, the platforms developed by provinces, cities, and districts are not located on different server clusters, forming a typical distributed system. Each platform is called a node. Provincial users, such as civil servants of provincial units, can access data within their authorized scope on the provincial platform. When a provincial user wants to access target data (which could be an application) on a city platform, the organizational domain of that city platform is first determined. The organizational domain uniquely represents the hierarchical information of a platform and can serve as the node identifier for the city-level open platform. The platform's gateway address, data storage address, and authentication address are all identified through the node identifier. For example, if the storage address of certain data is http: / / www.province.com / app2 / , the "province" in the storage address indicates that the data (app2) belongs to the provincial platform. If the data is public data, the node will broadcast this address to other nodes in the distributed system, allowing other nodes to access the data through this address. Therefore, when a user of the first node wants to access data stored on the second node, they can obtain the second node identifier of the second node where the data is located through the storage address of the target data.
[0141] It should be understood that the embodiments of this application can be applied not only to the organizational systems with hierarchical administrative relationships (provinces, cities, and districts) mentioned above, but also to organizational systems with non-local hierarchical relationships. For example, the Municipal Public Security Bureau, the Municipal Education Bureau, and the Municipal Agriculture Bureau are three organizations at the same administrative level. The nodes of these three organizations can also act as nodes in a distributed system and interact using the data access method of the embodiments of this application.
[0142] S102. If it is determined that there is target authentication information in the first cascade information that corresponds to the target user identifier and the second node identifier of the target user, a data access request is generated. The data access request includes the target user identifier and the target authentication information.
[0143] When a user has previously accessed target data on a second node through a first node, the first cascade information stored on the first node will record the user's authentication information on the second node, thus enabling quick access to the target data through the authentication information and user identifier.
[0144] The user identifier in this application is information that uniquely identifies a user. In government systems, the user identifier can be a user's WeChat ID for government affairs, ID card number, mobile phone number, employee ID of an administrative unit, etc. This application does not impose specific limitations. Within government systems, each open platform can set user identifiers for each user in the address book storage. For example, a provincial open platform can set user identifiers for employees of provincial-level units in the provincial address book, and a municipal open platform can set user identifiers for employees of municipal-level units in the municipal address book.
[0145] The first-level concatenation information in this application is used to store the user identifiers of each local user in the first node, the authentication information for the corresponding local user accessing data across nodes, and the correspondence between node identifiers across nodes. For example, the first-level concatenation information stores the following correspondence:
[0146] User01-jqxx1-jiedian02;
[0147] User01-jqxx2-jiedian03;
[0148] User02-jqxx3-jiedian03;
[0149] User03-jqxx4-jiedian02;
[0150] In this context, User01, User02, and User03 are the user identifiers for users 1, 2, and 3 in the first node; jiedian02 and jiedian03 are the node identifiers for nodes 2 and 3; jqxx1 is the authentication information for user 1 accessing data in node 2; qxx2 is the authentication information for user 1 accessing data in node 3; qxx3 is the authentication information for user 2 accessing data in node 3; and qxx4 is the authentication information for user 3 accessing data in node 2. Through this correspondence, once the node identifiers and user identifiers are determined, the corresponding authentication information can be quickly retrieved.
[0151] S103. Send a data access request to the second node to instruct the second node to authenticate the target user identifier and target authentication information based on the second concatenation information, and grant the first node access to the target data after successful authentication.
[0152] The second-level concatenation information is used to store the user identifiers of each cross-node user accessing the target data, as well as the corresponding authentication information for cross-node users accessing the target data. In this embodiment, to achieve cross-node data access, the user's authentication information and user identifier are stored not only in the first node but also in the second node. When the first node sends the user identifier and authentication information to the second node, the second node checks its own stored second-level concatenation information to see if it contains the user identifier and authentication information from the data access request, thus achieving rapid authentication. This embodiment will further explain the generation process of the concatenation information for each node through subsequent embodiments. Successful authentication means that the user can access the target data through the first node, and the second node grants access permission to the target data.
[0153] Once the second node grants access permissions, the user can access the target data through the first node.
[0154] The cross-node data access method in the distributed system of this application embodiment, when a user of the first node accesses data of the second node across nodes, determines the second node identifier of the second node where the target data is located. If it is determined that there is authentication information in the first concatenation information that corresponds to the second node identifier, a data access request is sent to the second node to instruct the second node to authenticate the user identifier and authentication information according to the second concatenation information. After successful authentication, the user's access permission to the target data is granted. This application embodiment does not require the user to re-register an account on the second node. Instead, it determines whether to grant access permission by using the user identifier and authentication information of the user on the first node stored in the concatenation information of each of the two nodes. This achieves cross-node information integration, allowing users to access cross-node data without obstacles. At the same time, it also ensures the independence of the data. Users do not need to log in twice or register additional accounts across nodes, which greatly improves data access efficiency.
[0155] Based on the above embodiments, as an optional embodiment, the distributed system also includes a cascading center, which is used to store the first cascading information and the second cascading information.
[0156] In other words, by adding a cascading center to the distributed system to store the cascading information of each node, the cascading center performs authentication when accessing data across nodes, thereby reducing data coupling and improving the security and stability of the system.
[0157] Specifically, if it is determined that there is target authentication information in the first-level concatenation information that corresponds to the target user identifier and the second node identifier of the target user, including:
[0158] The first node sends the target user identifier and the second node identifier of the target user to the cascading center, instructing the cascading center to determine whether there is target authentication information in the cascading center that corresponds to the target user identifier and the second node identifier of the target user.
[0159] This instructs the second node to authenticate the target user identifier and target authentication information based on the second concatenation information, including:
[0160] The first node instructs the second node to send the target user identifier and target authentication information to the cascading center, which then authenticates the target user identifier and target authentication information based on the second cascading information. Based on the above embodiments, as an optional embodiment, if it is determined that the first cascading information contains target authentication information that corresponds to both the target user identifier and the second node identifier, the following further steps are included:
[0161] S201. Generate an access request, which includes the first node identifier of the first node and the target user identifier.
[0162] It is understandable that if the cascading information is stored locally on the node, the first node directly queries the correspondence between the second node identifier and the authentication information of the user accessing the target data on the second node based on the first cascading information stored locally. If the cascading information is stored in the cascading center, the cascading center queries the above relationship in the first cascading information.
[0163] If the first concatenation information does not find a correspondence between the second node identifier and the authentication information for the user accessing the target data on the second node, it indicates that a concatenation with the second node is needed to generate the corresponding correspondence, which is then stored in the concatenation information between the two nodes. Specifically, the first node first generates an access request, which includes the first node identifier and the user identifier. This allows the second node to know which node the access request originated from and which user on that node is being associated with the corresponding correspondence.
[0164] S202. Send an access request to the second node to instruct the second node to configure the target user's role, determine the target user's role information on the second node, and the role information has the permission to access the target data.
[0165] By sending an access request to the second node, the second node can generate role information based on the first node identifier and the user identifier. In this embodiment, the second node can achieve data access through a Role-Based Access Control (RBAC) method. The basic idea is that access permissions are not directly granted to specific users, but rather a set of roles is established between the user set and the permission set. Each role corresponds to a set of permissions. Once a user is assigned an appropriate role, that user has all the operational permissions for that role. The advantage of this approach is that it eliminates the need to assign permissions every time a user is created; only the corresponding role needs to be assigned. Furthermore, changes to role permissions are far less frequent than changes to user permissions, thus simplifying user permission management and reducing system overhead.
[0166] S203. Generate target authentication information based on the returned role information, and store the correspondence between the target user identifier, the second node identifier and the target authentication information in the first concatenation information.
[0167] The target authentication information in this application embodiment can be used to indicate that the first node and the second node have reached a consensus on the authenticity of the target user and the target user's permission to access the target data.
[0168] Based on the above embodiments, as an optional embodiment, the first node generates target authentication information, and then further includes:
[0169] The target authentication information is synchronized to the second node, instructing the second node to store the correspondence between the target user identifier, role information, and target authentication information in the second cascade information.
[0170] Based on the above embodiments, as an optional embodiment, the first node sends an access request to the second node to instruct the second node to configure the target user's role and determine the target user's role information on the second node, including:
[0171] S301. Send an access request to the second node to instruct the second node to determine the interface address for user authentication by the first node based on the second concatenation information.
[0172] The second concatenation information in this embodiment is also used to store the correspondence between the node identifier of a node in the distributed system and the interface address for user authentication of the corresponding node. Each node in the distributed system of this embodiment has an interface address for authentication, enabling authentication when other nodes need to verify the identity of users on their own nodes. Taking a government affairs system as an example, each open platform can set up an identity authentication platform to complete user authentication. Nodes achieve concatenation of identity authentication by storing the interface addresses for user authentication of other nodes in the concatenation information. In a government affairs system, each open platform can establish a concatenation relationship between identity authentication platforms.
[0173] S302. Receive the call request from the second node's call interface address and perform user authentication on the target user identifier included in the call request.
[0174] The first node can authenticate users by verifying whether the target user identifier has been stored in advance. If the target user identifier has not been stored in advance, the authentication will pass; otherwise, the authentication will fail.
[0175] S303. If the target user identifier is verified, a response message indicating that the user identity verification has been passed is sent to the second node to instruct the second node to generate role information based on the target user identifier.
[0176] Based on the above embodiments, as an optional embodiment, determining the second node identifier of the second node where the target data is located further includes:
[0177] Receive the data address information broadcast by the second node after storing the target data. The data address information includes the access address of the target data and the identifier of the second node.
[0178] The first cascade information stores the correspondence between the access address of the target data and the identifier of the second node.
[0179] In this embodiment of the application, when new data is stored in a node, the node will broadcast data address information to other nodes in the distributed system. The data address information includes the access address of the target data and the second node identifier, so that other nodes know which node the target data is stored on and the access address of the data.
[0180] Taking the government affairs system as an example, the provincial, municipal, and district platforms all have some common public applications that require access, such as attendance tracking, leave application and cancellation, and work-related social networking. These public applications all hope to be accessible to users at the provincial, municipal, and district levels. Therefore, by simply deploying a unified set of applications on the provincial platform and registering them with the provincial platform's access gateway, users at all levels can access the application through the same address. Please see [link to relevant documentation]. Figure 5The illustration shows a schematic diagram of deploying an application on a provincial platform according to an embodiment of this application. As shown in the figure, after the provincial user deploys the application, the application's access address will be broadcast: http: / / www.province.com / app / , so that both city users and provincial users can access the application through the same address.
[0181] Correspondingly, the first node determines the second node identifier of the second node where the target data is located, including: determining the access address of the target data, and determining the second node identifier that corresponds to the access address from the first cascade information.
[0182] Please see Figure 6 The figure illustrates, by way of example, a flowchart of a data method executed by a first node according to an embodiment of this application, as shown in the figure, including:
[0183] S401. Receive data address information broadcast by the second node after storing the target data. The data address information includes the access address of the target data and the identifier of the second node.
[0184] S402. Store the correspondence between the access address of the target data and the identifier of the second node in the first concatenation information;
[0185] S403. Determine the access address of the target data, and determine the second node identifier that corresponds to the access address from the first cascade information;
[0186] S404. Determine if there is target authentication information in the first cascade information that corresponds to the target user identifier and the second node identifier of the target user. If not, proceed to step S405. If it exists, proceed to step S409.
[0187] S405. Generate an access request, which includes the first node identifier of the first node and the target user identifier.
[0188] S406. Send an access request to the second node to instruct the second node to configure the target user's role and determine the target user's role information on the second node.
[0189] S407. Generate target authentication information based on the returned role information, and store the correspondence between the target user identifier, the second node identifier and the target authentication information in the first concatenation information;
[0190] S408. Synchronize the target authentication information to the second node to instruct the second node to store the correspondence between the target user identifier, role information and target authentication information in the second concatenation information;
[0191] S409. If it is determined that there is target authentication information in the first cascade information that corresponds to both the target user identifier and the second node identifier of the target user, then a data access request is generated. The data access request includes the target user identifier and the target authentication information.
[0192] S410. Send a data access request to the second node to instruct the second node to authenticate the target user identifier and target authentication information according to the second concatenation information, and grant the first user the right to access the target data after successful authentication, and send an authentication success message back to the first node.
[0193] S411. Access the target data via the received authentication message.
[0194] Please see Figure 7 The figure illustrates, by way of example, a flowchart of a data method executed by a second node according to an embodiment of this application, as shown in the figure, including:
[0195] S501. Receive a data access request for target data sent by the first node. The target data is the data to be accessed by the target user of the first node. The data access request includes the target user identifier and the target authentication information determined by the first node based on the first concatenation information, which corresponds to the target user identifier and the second node identifier of the second node.
[0196] The first concatenation information in this application embodiment is used to store the user identifiers of each local user in the first node, the authentication information of the corresponding local user accessing data across nodes, and the correspondence between the node identifiers across nodes. Therefore, if the first node determines the second node identifier of the second node where the target data is located, it can search for whether there is corresponding target authentication information in the first concatenation information based on the second node identifier and the target user identifier. If it exists, it means that the first node has stored the user and the second node have concatenation information.
[0197] S502. Authenticate the target user identifier and target authentication information according to the pre-stored second concatenation information, and grant the first node access to the target data after successful authentication.
[0198] The second concatenation information in this application embodiment is used to store the user identifiers of each cross-node user accessing the target data and the authentication information of the corresponding cross-node user accessing the target data. If the second concatenation information stores the target user identifier and the target authentication information, then the authentication is determined to be successful.
[0199] The data access method of this application embodiment receives a data access request for target data sent by a first node. The target data is the data to be accessed by the target user of the first node. The data access request includes a target user identifier and target authentication information determined by the first node based on first concatenation information, which corresponds to the target user identifier and the second node identifier of the second node. The target user identifier and target authentication information are authenticated according to the pre-stored second concatenation information, and an authentication pass message is sent back to the first node after successful authentication, instructing the first node to access the target data based on the received authentication pass message. This achieves cross-node information integration, allowing users to access cross-node data without obstacles, while also ensuring data independence. Users do not need to log in twice or register additional accounts across nodes, greatly improving data access efficiency.
[0200] Based on the above embodiments, as an optional embodiment, the first concatenation information is used to store the user identifiers of each local user in the first node, the authentication information of the corresponding local user accessing data across nodes, and the correspondence between the node identifiers of the cross nodes; the second concatenation information is used to store the user identifiers of each cross-node user accessing the target data and the authentication information of the corresponding cross-node user accessing the target data.
[0201] In one possible implementation, the distributed system also includes a cascading center, which is used to store the first cascading information and the second cascading information.
[0202] Authentication is performed on the target user identifier and target authentication information based on the second-level concatenation information, including:
[0203] The target user identifier and target authentication information are sent to the cascading center, which then authenticates the target user identifier and target authentication information based on the second-level cascading information.
[0204] Based on the above embodiments, as an optional embodiment, the second node receives the data access request sent by the first node, and further includes:
[0205] S601. Receive an access request sent by the first node when it determines that there is no target authentication information. The access request includes the first node identifier and the target user identifier of the first node.
[0206] S602. Configure the target user's role based on the first node identifier and the target user identifier, and determine the target user's role information in the second node. The role information has the permission to access the target data.
[0207] S603. Send the role information to the first node to instruct the first node to generate and return authentication information based on the role information;
[0208] S604. Store the correspondence between the target user identifier, role information, and target authentication information in the second-level concatenation information.
[0209] Based on the above embodiments, as an optional embodiment, authentication of the target user identifier and target authentication information is performed according to the pre-stored second concatenation information, including:
[0210] Search the second-level information for role information corresponding to the target user identifier and target authentication information;
[0211] If the corresponding role information exists, the authentication is successful based on the role information's permission to access the target data; if the corresponding role information does not exist, the authentication fails.
[0212] Based on the above embodiments, as an optional embodiment, role information is generated according to the first node identifier and the target user identifier, including:
[0213] S701. Based on the first node identifier, determine the interface address for user authentication of the first node in the second concatenation information. The second concatenation information is also used to store the correspondence between the node identifier of the node in the distributed system and the interface address for user authentication of the corresponding node.
[0214] S702. Send a call request for the interface address to the first node. The call request includes the target user identifier to instruct the first node to perform user authentication based on the target user identifier.
[0215] S703. If a response indicating successful user authentication is received from the first node, role information is generated based on the target user identifier.
[0216] Based on the above embodiments, as an optional embodiment, the data access method further includes: the second node storing the target data and broadcasting data address information in the distributed system, wherein the data address information includes the access address of the target data and the identifier of the second node.
[0217] This application also provides a data access method in a distributed system. The distributed system includes a cascaded center and at least two nodes, including a first node and a second node. The data access method is executed by the cascaded center and includes:
[0218] Save the first cascade information of the first node and the cascade information of the second node;
[0219] If the target user identifier and target authentication information are received from the second node, the target user identifier and target authentication information are authenticated according to the second concatenation information, and the authentication result is sent back to the second node.
[0220] The first cascade information is used to store the user identifiers of each local user in the first node, the authentication information of the corresponding local user accessing data across nodes, and the correspondence between node identifiers across nodes.
[0221] The second-level concatenation information is used to store the user identifiers of each cross-node user accessing the target data, as well as the authentication information for the corresponding cross-node user accessing the target data.
[0222] The process of the data access method of this application embodiment is described below with reference to a specific example.
[0223] When a user at the first node wants to access target data on the second node, the first node first sends the target user's identifier and the second node's identifier to the cascading center. The cascading center then searches its first-level cascading information for a matching authentication information. If a match is found, the authentication information is sent to the first node, which generates a data access request containing the target user's identifier and the authentication information. This request is then sent to the second node. The second node parses the request and sends the target user's identifier and authentication information to the cascading center. The cascading center authenticates the target user's identifier and authentication information based on the second-level cascading information. Upon successful authentication, the center sends an authentication pass response to the second node. The second node then grants the first node permission to access the target data.
[0224] If the cascading center does not find any target authentication information corresponding to the target user identifier and the second node identifier in the first cascading information corresponding to the first node, it sends a response message indicating that the information was not found to the first node. In this case, after the first node and the second node interact to obtain role information as described in the above embodiment, the first node stores the correspondence between the target user identifier, the second node identifier, and the target authentication information in the first cascading information. Alternatively, the first node can send the relevant information to the cascading center, which then stores the correspondence in the first cascading information. Similarly, after the second node receives the authentication information returned by the first node, it can store the correspondence between the target user identifier, the role information, and the target authentication information in the second cascading information, or the cascading center can store it.
[0225] Please see Figure 8The figure exemplifies the system architecture diagram of the data method of this application applied to a government affairs system. As shown, provinces, municipalities, and districts deploy their own dedicated applications according to their respective needs, as well as some province-wide public applications. These applications synchronize agentid (application identifier) and secret (the "key" used to ensure data security) to the open platform, and publish and manage the applications through the open platform, and through their respective identity authentication platforms (…). Figure 8 The authentication platform (represented in the image) reports user data to the cascading center for storing corresponding cascading information. The open platform supports sharing applications to various platforms within the cascading center, which records the relationships between platform cascading and application cascading. For example, the cascading of provincial, municipal, and district government WeChat accounts indicates that WeChat accounts at different levels can interconnect and send messages. Similarly, the cascading of provincial, municipal, and district identity authentication indicates that identity authentication can be performed on platforms at different levels.
[0226] Please see Figure 9 The illustration shows a schematic diagram of identity information cascading in the government affairs system of this application embodiment. As shown in the figure, city users manage and maintain user information (including user identifiers) through the city identity authentication platform, and synchronize users that need to be cascaded to the provincial identity authentication platform; provincial users manage and maintain user information cascaded on other platforms through the provincial identity authentication platform, and distribute it to the address book of the provincial government WeChat account; a provincial connection center is deployed at the provincial level to maintain user cascading relationships, including all user information reported in identity authentication platforms at all levels, and record the government WeChat account to which each user belongs.
[0227] Please see Figure 10 The figure illustrates a flowchart of a data method applied to a government system according to an embodiment of this application, as shown in the figure, including:
[0228] S1.1. City users logging into the government WeChat account can see the public application provided by provincial users: Provincial Public Document Processing. In addition to including the application's organizational domain to identify the node where the application resides (the provincial platform), the access request sent by the user also records the organizational domain of the requesting city platform. When a city user accesses the application, the provincial access gateway will point to the address of the Provincial Public Document Processing application along with the city platform's organizational domain.
[0229] S1.2 The provincial access gateway sends the user identifier to the municipal platform access gateway based on the municipal platform's organizational domain.
[0230] S1.3 The city access gateway sends the user's identifier to the city platform's identity authentication address for authentication.
[0231] S1.4 After authentication is successful, the municipal access gateway will report the target user's government WeChat account, gateway address, and identity authentication result stored in the municipal platform to the provincial joint center and save them in the provincial joint information.
[0232] S1.5 The provincial joint center generates the role information of the city users from the information reported by the city platform, configures the corresponding permissions, and then sends the role information to the city access gateway in the form of a cascading code (password).
[0233] S1.6 The city access gateway sends the cascade code to the city identity authentication platform for further improvement of user information;
[0234] S1.7 The city's identity authentication platform generates authentication information, which, while being saved to the municipal government's WeChat account, also needs to be synchronized to the provincial joint center.
[0235] S1.8 The provincial joint center sends the authentication information to the provincial access gateway. At this point, the city user has completed identity verification on the provincial access gateway and can start accessing the provincial document application.
[0236] S1.9 When a city user accesses the provincial document application through the provincial access gateway, the request header parameters will include the user's user identifier and corresponding authentication information.
[0237] This application provides a first node in a distributed system, such as... Figure 11 As shown, the device may include: a second node identifier determination module 111, an access request generation module 112, and an access request generation module 113, specifically:
[0238] The second node identifier determination module 111 is used to determine the second node identifier of the second node where the target data is located. The target data is the data to be accessed by the target user of the first node.
[0239] The access request generation module 112 is used to generate a data access request if it is determined that there is target authentication information in the first concatenation information that corresponds to both the target user identifier and the second node identifier of the target user. The data access request includes the target user identifier and the target authentication information.
[0240] The access request generation module 113 is used to send a data access request to the second node, instructing the second node to authenticate the target user identifier and target authentication information according to the second concatenation information, and grant the first node access to the target data after successful authentication.
[0241] The first node provided in this embodiment of the invention specifically executes the process described in the above method embodiment. For details, please refer to the content of the above data method embodiment executed on the first node, which will not be repeated here. When a user of the first node accesses data on a second node across nodes, the first node provided in this embodiment of the invention determines the second node identifier of the second node where the target data is located. If it is determined that there is authentication information in the first cascading information that corresponds to the second node identifier, a data access request is sent to the second node. This instructs the second node to authenticate the user identifier and authentication information according to the second cascading information, and grants the user access to the target data after successful authentication. This embodiment of the application does not require the user to re-register an account on the second node. Instead, it determines whether to grant access based on the user identifier and authentication information stored in the cascading information of each of the two nodes on the first node. This achieves cross-node information integration, allowing users to access data across nodes without obstacles, while also ensuring data independence. Users do not need to log in twice or register additional accounts across nodes, greatly improving data access efficiency.
[0242] Based on the above embodiments, as an optional embodiment, the distributed system also includes a cascading center, which is used to store the first cascading information and the second cascading information.
[0243] The access request generation module is specifically used to: send the target user identifier and the second node identifier of the target user to the cascading center, so as to instruct the cascading center to determine in the cascading center whether there is target authentication information that corresponds to the target user identifier and the second node identifier of the target user;
[0244] The access request generation module is specifically used to instruct the second node to send the target user identifier and target authentication information to the cascading center, which then authenticates the target user identifier and target authentication information based on the second cascading information.
[0245] Based on the above embodiments, as an optional embodiment, the first node further includes:
[0246] The access request generation module is used to generate access requests, which include the first node identifier of the first node and the target user identifier.
[0247] The access request sending module is used to send an access request to the second node to instruct the second node to configure the target user's role and determine the target user's role information on the second node. The role information has the permission to access the target data.
[0248] The first correspondence generation module is used to generate target authentication information based on the returned role information, and stores the correspondence between the target user identifier, the second node identifier and the target authentication information in the first concatenation information.
[0249] Based on the above embodiments, as an optional embodiment, the first node further includes:
[0250] The target authentication sending information module is used to synchronize the target authentication information to the second node, so as to instruct the second node to store the correspondence between the target user identifier, role information and target authentication information in the second concatenation information.
[0251] Based on the above embodiments, as an optional embodiment, the access request sending module includes:
[0252] The access request sending unit is used to send an access request to the second node, instructing the second node to determine the interface address for user authentication of the first node based on the second concatenation information; the second concatenation information is also used to store the correspondence between the node identifier of the node in the distributed system and the interface address for user authentication of the corresponding node.
[0253] The authentication unit is used to receive the call request from the second node's call interface address and perform user authentication on the target user identifier included in the call request;
[0254] The authentication response unit is used to send a response message indicating that the user authentication has been passed to the second node if the target user identifier is successfully verified, so as to instruct the second node to generate role information based on the target user identifier.
[0255] Based on the above embodiments, as an optional embodiment, the first node further includes:
[0256] The broadcast receiving module is used to receive the data address information broadcast by the second node after storing the target data. The data address information includes the access address of the target data and the identifier of the second node.
[0257] The mapping relationship storage module is used to store the mapping relationship between the access address of the target data and the second node identifier in the first concatenation information;
[0258] The second node identifier determination module is specifically used to: determine the access address of the target data, and determine the second node identifier that corresponds to the access address from the first cascade information.
[0259] This application provides a second node in a distributed system, such as... Figure 12 As shown, the device may include: an access request receiving module 211 and an authentication module 212, specifically:
[0260] The access request receiving module 211 is used to receive a data access request for target data sent by the first node. The target data is the data to be accessed by the target user of the first node. The data access request includes a target user identifier and target authentication information determined by the first node based on the first concatenation information, which corresponds to the target user identifier and the second node identifier of the second node.
[0261] The authentication module 212 is used to authenticate the target user identifier and target authentication information based on the pre-stored second-level concatenation information, and grant the first node access to the target data after successful authentication.
[0262] The second node provided in this embodiment of the invention specifically executes the process described in the above method embodiment. For details, please refer to the content of the above data method embodiment executed on the second node, which will not be repeated here. When a user of the first node accesses data on the second node across nodes, the second node provided in this embodiment of the invention determines the second node identifier of the second node where the target data is located. If it is determined that there is authentication information in the first cascading information that corresponds to the second node identifier, a data access request is sent to the second node. This instructs the second node to authenticate the user identifier and authentication information according to the second cascading information, and grants the user access to the target data after successful authentication. This embodiment of the application does not require the user to re-register an account on the second node. Instead, it determines whether to grant access based on the user identifier and authentication information stored in the cascading information of each of the two nodes on the first node. This achieves cross-node information integration, allowing users to access data across nodes without obstacles, while also ensuring data independence. Users do not need to log in twice or register additional accounts across nodes, greatly improving data access efficiency.
[0263] Based on the above embodiments, as an optional embodiment, the distributed system also includes a cascading center, which is used to store the first cascading information and the second cascading information.
[0264] The authentication module is specifically used to send the target user identifier and target authentication information to the cascading center, which then authenticates the target user identifier and target authentication information based on the second-level cascading information.
[0265] Based on the above embodiments, as an optional embodiment, the first node further includes:
[0266] The access request receiving module is used to receive the access request sent by the first node when it determines that there is no target authentication information. The access request includes the first node identifier and the target user identifier of the first node.
[0267] The role configuration module is used to configure the role of the target user based on the first node identifier and the target user identifier, and to determine the role information of the target user in the second node. The role information has the permission to access the target data.
[0268] The role feedback module is used to send role information to the first node, so that the first node can generate and return authentication information based on the role information;
[0269] The second correspondence generation module is used to store the correspondence between the target user identifier, role information and target authentication information in the second concatenation information.
[0270] Based on the above embodiments, as an optional embodiment, the authentication module includes:
[0271] The search unit is used to search for role information corresponding to the target user identifier and target authentication information in the second-level information;
[0272] The judgment unit is used to determine whether authentication is successful if the corresponding role information exists and the role information has the permission to access the target data; otherwise, it determines that authentication is unsuccessful.
[0273] Based on the above embodiments, as an optional embodiment, the role configuration module includes:
[0274] The interface address acquisition unit is used to determine the interface address of the first node for user authentication based on the first node identifier in the second concatenation information. The second concatenation information is also used to store the correspondence between the node identifier of the node in the distributed system and the interface address of the corresponding node for user authentication.
[0275] The interface invocation unit is used to send an invocation request to the first node to call the interface address. The invocation request includes the target user identifier to instruct the first node to perform user authentication based on the target user identifier.
[0276] The role generation unit is used to generate role information based on the target user identifier if it receives a response message from the first node indicating that the user authentication has passed.
[0277] Based on the above embodiments, as an optional embodiment, the second node further includes:
[0278] The broadcast module is used to store target data and broadcast data address information in the distributed system. The data address information includes the access address of the target data and the identifier of the second node.
[0279] This application provides a cascading center in a distributed system. The distributed system includes at least two nodes, including a first node and a second node. The cascading center includes:
[0280] The cascading information storage module is used to store the first cascading information of the first node and the cascading information of the second node.
[0281] The cascaded authentication module is used to authenticate the target user identifier and target authentication information according to the second cascade information if it receives the target user identifier and target authentication information sent by the second node, and to send the authentication result back to the second node.
[0282] The first cascade information is used to store the user identifiers of each local user in the first node, the authentication information of the corresponding local user accessing data across nodes, and the correspondence between node identifiers across nodes.
[0283] The second-level concatenation information is used to store the user identifiers of each cross-node user accessing the target data, as well as the authentication information for the corresponding cross-node user accessing the target data.
[0284] This application provides an electronic device comprising: a memory and a processor; at least one program stored in the memory, which, when executed by the processor, can achieve the following compared to the prior art: when a user of a first node accesses data of a second node across nodes, by determining the second node identifier of the second node where the target data is located, if it is determined that there is authentication information in the first concatenation information corresponding to the second node identifier, a data access request is sent to the second node to instruct the second node to authenticate the user identifier and authentication information according to the second concatenation information, and to grant the user access to the target data after successful authentication. This application embodiment does not require the user to re-register an account on the second node, but determines whether to grant access based on the user identifier and authentication information of the user on the first node stored in the concatenation information of each of the two nodes, thereby realizing cross-node information integration. Users can access cross-node data without obstacles, while also ensuring data independence. Users do not need to log in twice or register additional accounts across nodes, greatly improving data access efficiency.
[0285] In one alternative embodiment, an electronic device is provided, such as Figure 13 As shown, Figure 13 The illustrated electronic device 4000 includes a processor 4001 and a memory 4003. The processor 4001 and the memory 4003 are connected, for example, via a bus 4002. Optionally, the electronic device 4000 may also include a transceiver 4004. It should be noted that in practical applications, the transceiver 4004 is not limited to one type, and the structure of this electronic device 4000 does not constitute a limitation on the embodiments of this application.
[0286] Processor 4001 may be a CPU (Central Processing Unit), a general-purpose processor, a DSP (Digital Signal Processor), an ASIC (Application Specific Integrated Circuit), an FPGA (Field Programmable Gate Array), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. It can implement or execute the various exemplary logic blocks, modules, and circuits described in conjunction with the disclosure of this application. Processor 4001 may also be a combination that implements computational functions, such as including one or more microprocessor combinations, a combination of a DSP and a microprocessor, etc.
[0287] Bus 4002 may include a pathway for transmitting information between the aforementioned components. Bus 4002 may be a PCI (Peripheral Component Interconnect) bus or an EISA (Extended Industry Standard Architecture) bus, etc. Bus 4002 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 13 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.
[0288] The memory 4003 may be ROM (Read Only Memory) or other types of static storage devices capable of storing static information and instructions, RAM (Random Access Memory) or other types of dynamic storage devices capable of storing information and instructions, or EEPROM (Electrically Erasable Programmable Read Only Memory), CD-ROM (Compact Disc Read Only Memory) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital universal optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto.
[0289] The memory 4003 stores application code that executes the scheme of this application, and its execution is controlled by the processor 4001. The processor 4001 executes the application code stored in the memory 4003 to implement the content shown in the foregoing method embodiments.
[0290] This application provides a computer-readable storage medium storing a computer program that, when run on a computer, enables the computer to execute the corresponding content in the aforementioned method embodiments. Compared with the prior art, when a user of a first node accesses data on a second node across nodes, by determining the second node identifier of the second node where the target data is located, and if it is determined that there is authentication information in the first concatenation information corresponding to the second node identifier, a data access request is sent to the second node to instruct the second node to authenticate the user identifier and authentication information according to the second concatenation information, and to grant the user access to the target data after successful authentication. This application embodiment does not require the user to re-register an account on the second node, but instead determines whether to grant access based on the user identifier and authentication information stored in the concatenation information of each of the two nodes on the first node. This achieves cross-node information integration, allowing users to access data across nodes without obstacles, while also ensuring data independence. Users do not need to log in twice or register additional accounts across nodes, greatly improving data access efficiency.
[0291] This application provides a computer program including computer instructions stored in a computer-readable storage medium. When a processor of a computer device reads the computer instructions from the computer-readable storage medium, the processor executes the computer instructions, causing the computer device to perform the content shown in the foregoing method embodiments. Compared with the prior art, when a user of a first node accesses data of a second node across nodes, by determining the second node identifier of the second node where the target data is located, if it is determined that there is authentication information in the first concatenation information corresponding to the second node identifier, a data access request is sent to the second node to instruct the second node to authenticate the user identifier and authentication information according to the second concatenation information, and to grant the user access to the target data after successful authentication. This application embodiment does not require the user to re-register an account on the second node, but determines whether to grant access based on the user identifier and authentication information of the user on the first node stored in the concatenation information of each of the two nodes. This achieves cross-node information integration, allowing users to access data across nodes without obstacles, while also ensuring data independence. Users do not need to log in twice or register additional accounts across nodes, greatly improving data access efficiency.
[0292] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.
[0293] The above are only some embodiments of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A data access method for a distributed system, wherein the distributed system includes at least two nodes, characterized in that, The data access method is executed by the first node of the at least two nodes, and the method includes: Determine the second node identifier of the second node where the target data is located, where the target data is the data to be accessed by the target user of the first node; If it is determined that there is target authentication information in the first concatenation information that corresponds to the target user identifier and the second node identifier of the target user, a data access request is generated, and the data access request includes the target user identifier and the target authentication information; Send the data access request to the second node to instruct the second node to authenticate the target user identifier and target authentication information according to the second concatenation information, and grant the first node permission to access the target data after successful authentication; The first concatenation information is used to store the user identifier of each local user in the first node, the authentication information of the corresponding local user accessing data across nodes, and the correspondence between node identifiers across nodes. The second concatenation information is used to store the user identifiers of each cross-node user accessing the target data, as well as the authentication information for the corresponding cross-node user accessing the target data.
2. The data access method according to claim 1, characterized in that, The distributed system also includes a cascading center, which is used to store the first cascading information and the second cascading information. If it is determined that there is target authentication information in the first concatenation information that corresponds to the target user identifier and the second node identifier of the target user, including: The target user identifier and the second node identifier of the target user are sent to the cascading center to instruct the cascading center to determine in the cascading center that there is target authentication information that corresponds to the target user identifier and the second node identifier of the target user; The step of instructing the second node to authenticate the target user identifier and target authentication information based on the second concatenation information includes: This instructs the second node to send the target user identifier and target authentication information to the cascading center, whereby the cascading center authenticates the target user identifier and target authentication information based on the second cascading information.
3. The data access method according to claim 1, characterized in that, If it is determined that there is target authentication information in the first concatenation information that corresponds to the target user identifier and the second node identifier of the target user, the process further includes: Generate an access request, the access request including the first node identifier of the first node and the target user identifier; The access request is sent to the second node to instruct the second node to configure the target user's role and determine the target user's role information on the second node, wherein the role information has the permission to access the target data; The target authentication information is generated based on the returned role information, and the correspondence between the target user identifier, the second node identifier and the target authentication information is stored in the first concatenated information.
4. The data access method according to claim 3, characterized in that, After generating the target authentication information, the process further includes: The target authentication information is synchronized to the second node to instruct the second node to store the correspondence between the target user identifier, the role information and the target authentication information in the second concatenation information.
5. The data access method according to claim 4, characterized in that, Sending the access request to the second node to instruct the second node to configure the target user's role and determine the target user's role information on the second node includes: The access request is sent to the second node to instruct the second node to determine the interface address for user authentication of the first node based on the second concatenation information; the second concatenation information is also used to store the correspondence between the node identifier of the node in the distributed system and the interface address for user authentication of the corresponding node. Receive the call request from the second node to call the interface address, and perform user authentication on the target user identifier included in the call request; If the target user identifier is verified, a response indicating successful user authentication is sent to the second node, instructing the second node to generate the role information based on the target user identifier.
6. The data access method according to any one of claims 1-5, characterized in that, The second node identifier for determining the second node where the target data is located also includes: Receive data address information broadcast by the second node after storing target data, wherein the data address information includes the access address of the target data and the identifier of the second node; The first concatenation information stores the correspondence between the access address of the target data and the second node identifier; The second node identifier for determining the second node where the target data is located includes: Determine the access address of the target data, and identify the second node identifier that corresponds to the access address from the first cascading information.
7. A data access method in a distributed system, characterized in that, The distributed system includes a cascaded center and at least two nodes, the at least two nodes including a first node and a second node, and the data access method is executed by the cascaded center, the method including: Save the first concatenation information of the first node and the second concatenation information of the second node; If the target user identifier and target authentication information sent by the second node are received, the target user identifier and target authentication information are authenticated according to the second concatenation information, and the authentication result is fed back to the second node. The target user identifier and target authentication information are sent by the second node upon receiving the data access request; the data access request includes the target user identifier and target authentication information. The data access request is generated when the first node determines the second node identifier of the second node where the target data is located and determines that there is target authentication information in the first concatenation information that corresponds to the target user identifier and the second node identifier of the target user. The first concatenation information is used to store the user identifier of each local user in the first node, the authentication information of the corresponding local user accessing data across nodes, and the correspondence between node identifiers across nodes; The second concatenation information is used to store the user identifiers of each cross-node user accessing the target data, as well as the authentication information for the corresponding cross-node user accessing the target data.
8. A first node in a distributed system, characterized in that, include: The second node identifier determination module is used to determine the second node identifier of the second node where the target data is located, wherein the target data is the data to be accessed by the target user of the first node. An access request generation module is used to generate a data access request if it is determined that there is target authentication information in the first concatenation information that corresponds to both the target user identifier and the second node identifier of the target user. The data access request includes the target user identifier and the target authentication information. The access request sending module is used to send a data access request to the second node, instructing the second node to authenticate the target user identifier and target authentication information according to the second concatenation information, and grant the first node permission to access the target data after the authentication is successful. The first concatenation information is used to store the user identifier of each local user in the first node, the authentication information of the corresponding local user accessing data across nodes, and the correspondence between node identifiers across nodes. The second concatenation information is used to store the user identifiers of each cross-node user accessing the target data, as well as the authentication information for the corresponding cross-node user accessing the target data.
9. A cascading center in a distributed system, characterized in that, The distributed system includes at least two nodes, the at least two nodes including a first node and a second node, and the cascading center includes: A cascade information storage module is used to store the first cascade information of the first node and the second cascade information of the second node. The cascaded authentication module is used to authenticate the target user identifier and target authentication information according to the second cascade information if it receives the target user identifier and target authentication information sent by the second node, and to feed back the authentication result to the second node. The target user identifier and target authentication information are sent by the second node upon receiving the data access request; the data access request includes the target user identifier and target authentication information. The data access request is generated when the first node determines the second node identifier of the second node where the target data is located and determines that there is target authentication information in the first concatenation information that corresponds to the target user identifier and the second node identifier of the target user. The first concatenation information is used to store the user identifier of each local user in the first node, the authentication information of the corresponding local user accessing data across nodes, and the correspondence between node identifiers across nodes; The second concatenation information is used to store the user identifiers of each cross-node user accessing the target data, as well as the authentication information for the corresponding cross-node user accessing the target data.
Citation Information
Patent Citations
A cross-domain access control system for realizing role and group mapping based on cross-domain authorization
CN101262474A
Identity authentication method and system
CN110309636A