System access method, apparatus, and electronic device

CN115664670BActive Publication Date: 2026-08-07CHINA CONSTRUCTION BANK +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA CONSTRUCTION BANK
Filing Date
2022-10-08
Publication Date
2026-08-07

AI Technical Summary

Technical Problem

[0003]本公开提供一种系统接入方法、装置、电子设备、计算机可读存储介质和计算机程序产品,以至少解决相关技术中系统接入稳定性低的问题

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115664670B_ABST
    Figure CN115664670B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a system access method and device and electronic equipment, and belongs to the technical field of artificial intelligence identification and classification. The method comprises the following steps: screening a target network interface from at least two general network interfaces, calling the target network interface, and obtaining identity authentication information of a client system from an authentication device through the target network interface; generating an identity authentication request of the client system based on the identity authentication information, and sending the identity authentication request to a bank system; in response to an identity authentication result indicating that the client system passes the identity authentication sent by the bank system, establishing a connection between the client and the bank system, and establishing a connection between the client system and the client. Thus, data transmission between the client and the authentication device can be realized through the target network interface only, the stability of data transmission between the client and the authentication device is improved, and the stability of system access is improved. Furthermore, the client can be deployed in a virtual machine, and the deployment environment of the client is widened.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of artificial intelligence recognition and classification technology, and in particular to a system access method, apparatus, electronic device, computer-readable storage medium, and computer program product. Background Technology

[0002] Direct bank-enterprise connection refers to the connection between a bank's system and an enterprise's system, allowing direct handling of banking transactions such as account management and fund transfers through the enterprise system. It offers advantages such as convenience, speed, and customization, and has been widely adopted. However, in related direct bank-enterprise connection technologies, to improve convenience and security, authentication devices can be used for enterprise system identity verification. However, most authentication devices require insertion into interfaces on physical machines, which are prone to loosening or damage, leading to low system connection stability. Summary of the Invention

[0003] This disclosure provides a system access method, apparatus, electronic device, computer-readable storage medium, and computer program product to at least solve the problem of low system access stability in related technologies. The technical solution of this disclosure is as follows:

[0004] According to a first aspect of the present disclosure, a system access method is provided, applicable to a client, comprising: filtering a target network port from at least two general network ports; invoking the target network port and obtaining the client system's identity authentication information from an authentication device through the target network port; generating an identity authentication request for the client system based on the identity authentication information and sending the identity authentication request to a bank system; and, in response to an identity authentication result sent by the bank system, instructing the client system to pass identity authentication, establishing a connection between the client and the bank system, and establishing a connection between the client system and the client.

[0005] In one embodiment of this disclosure, the method further includes: in response to a first business request sent by the customer system, converting the first business request into a second business request according to a set conversion rule, and sending the second business request to the bank system.

[0006] In one embodiment of this disclosure, sending the second service request to the bank system includes: sending a signature request for the second service request to the authentication device through the target network port; receiving the signed second service request sent by the authentication device through the target network port; and sending the signed second service request to the bank system.

[0007] In one embodiment of this disclosure, sending a signature request for the second service request to the authentication device through the target network port includes: identifying whether the transaction category corresponding to the second service request is a set transaction category; and in response to the transaction category corresponding to the second service request being a set transaction category, sending the signature request to the authentication device through the target network port.

[0008] In one embodiment of this disclosure, the method further includes: receiving the processing result of the second business request sent by the banking system, and sending the processing result of the second business request to the customer system.

[0009] In one embodiment of this disclosure, the step of filtering out a target network port from at least two general-purpose network ports includes: obtaining the transmission parameters and / or operating status of each of the general-purpose network ports; and filtering out the target network port from at least two of the general-purpose network ports based on the transmission parameters and / or the operating status.

[0010] In one embodiment of this disclosure, the transmission parameters include transmission speed, and the step of filtering the target network port from at least two general network ports based on the transmission parameters and / or the operating status includes: filtering the general network port with the highest transmission speed from at least two general network ports, and determining the general network port with the highest transmission speed as the target network port.

[0011] In one embodiment of this disclosure, the operating state includes an occupied state and an idle state. The step of filtering the target network port from at least two general network ports based on the transmission parameters and / or the operating state includes: filtering the general network ports whose operating state is idle from at least two general network ports, and determining the general network port whose operating state is idle as the target network port.

[0012] According to a second aspect of the present disclosure, a system access device is provided, applicable to a client, comprising: a filtering module configured to filter a target network port from at least two general network ports; an acquisition module configured to invoke the target network port and acquire the client system's identity authentication information from an authentication device through the target network port; a sending module configured to generate an identity authentication request for the client system based on the identity authentication information and send the identity authentication request to a bank system; and a connection module configured to, in response to an identity authentication result sent by the bank system, instruct the client system to pass identity authentication, establish a connection between the client and the bank system, and establish a connection between the client system and the client.

[0013] In one embodiment of this disclosure, the sending module is further configured to: in response to a first business request sent by the customer system, convert the first business request into a second business request according to a set conversion rule, and send the second business request to the bank system.

[0014] In one embodiment of this disclosure, the sending module is further configured to: send a signature request for the second service request to the authentication device through the target network port; receive the signed second service request sent by the authentication device through the target network port; and send the signed second service request to the banking system.

[0015] In one embodiment of this disclosure, the sending module is further configured to: identify whether the transaction category corresponding to the second service request is a set transaction category; and in response to the transaction category corresponding to the second service request being a set transaction category, send the signature request to the authentication device through the target network port.

[0016] In one embodiment of this disclosure, the sending module is further configured to: receive the processing result of the second business request sent by the bank system, and send the processing result of the second business request to the customer system.

[0017] In one embodiment of this disclosure, the filtering module is further configured to: obtain the transmission parameters and / or operating status of each of the general network ports; and filter out the target network port from at least two of the general network ports based on the transmission parameters and / or the operating status.

[0018] In one embodiment of this disclosure, the transmission parameters include transmission speed, and the filtering module is further configured to: filter out the general network port with the highest transmission speed from at least two general network ports, and determine the general network port with the highest transmission speed as the target network port.

[0019] In one embodiment of this disclosure, the operating state includes an occupied state and an idle state. The filtering module is further configured to: filter out the general network ports whose operating state is idle from at least two general network ports, and determine the general network ports whose operating state is idle as the target network port.

[0020] According to a third aspect of the present disclosure, an electronic device is provided, comprising: a processor; and a memory for storing processor-executable instructions; wherein the processor is configured to execute the instructions to implement the system access method as described above.

[0021] According to a fourth aspect of the present disclosure, a computer-readable storage medium is provided that, when instructions in the computer-readable storage medium are executed by a processor of an electronic device, enables the electronic device to perform the system access method as described above.

[0022] According to a fifth aspect of the present disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the system access method as described above.

[0023] The technical solution provided by the embodiments of this disclosure brings at least the following beneficial effects: The client selects a target network port from at least two general network ports, calls the target network port, and obtains the client system's identity authentication information from the authentication device through the target network port. Compared with the related technologies where the authentication device mostly needs to be plugged into the interface of the physical machine and the client needs to be deployed on the physical machine, the client can select a target network port from at least two general network ports. The determined target network port has higher flexibility and reliability, and data transmission between the client and the authentication device can be realized only through the target network port, which improves the stability of data transmission between the client and the authentication device, thereby improving the stability of system access. Moreover, the client can be deployed on a virtual machine, which broadens the client's deployment environment. Based on the identity authentication information, the client generates an identity authentication request for the client system and sends the identity authentication request to the bank system. In response to the identity authentication result sent by the bank system, the client system is instructed to pass the identity authentication and establish a connection between the client and the bank system, and establish a connection between the client system and the client. That is, the client interfaces with the bank system and the client system respectively, and the bank system and the client system can be interfaced through the client.

[0024] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description

[0025] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure, and are not intended to unduly limit this disclosure.

[0026] Figure 1 This is a flowchart illustrating the system access method according to the first embodiment of this disclosure.

[0027] Figure 2 This is a flowchart illustrating the system access method according to the second embodiment of this disclosure.

[0028] Figure 3 This is a flowchart illustrating the system access method according to the third embodiment of this disclosure.

[0029] Figure 4This is a flowchart illustrating the system access method according to the fourth embodiment of this disclosure.

[0030] Figure 5 This is a block diagram of a system access device according to a first embodiment of the present disclosure.

[0031] Figure 6 This is a block diagram illustrating an electronic device according to an exemplary embodiment. Detailed Implementation

[0032] To enable those skilled in the art to better understand the technical solutions of this disclosure, the technical solutions in the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings.

[0033] It should be noted that the terms "first," "second," etc., used in the specification, claims, and accompanying drawings of this disclosure are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this disclosure described herein can be implemented in orders other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this disclosure. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this disclosure as detailed in the appended claims.

[0034] The acquisition, storage, use, and processing of data in this disclosed technical solution all comply with the relevant provisions of national laws and regulations.

[0035] Figure 1 This is a flowchart illustrating the system access method according to the first embodiment of this disclosure.

[0036] like Figure 1 As shown, the system access method of the first embodiment of this disclosure includes the following steps:

[0037] In step S101, the target network port is selected from at least two general network ports.

[0038] It should be noted that the system access method of this disclosure is executed by the client. The system access method of this disclosure embodiment can be executed by the system access device of this disclosure embodiment, and the system access device of this disclosure embodiment can be configured in any client to execute the system access method of this disclosure embodiment.

[0039] It should be noted that "client" refers to a client that provides banking services (such as mobile banking, bank web pages, and direct bank-enterprise connection clients). These banking services include at least the connection services between the bank's system and the customer's system (such as direct bank-enterprise connection services). "Bank system" refers to a system that can provide banking services to the client (such as workstations, servers, and computers), and "customer system" refers to the customer's own system (such as workstations, servers, and computers). In some examples, the customer system may include the company's financial system. "Authentication device" refers to a device that can provide identity authentication services to the customer's system (such as a security token). In some examples, the authentication device may include a high-speed security token.

[0040] It should be noted that there are no major restrictions on the client's deployment environment. For example, the client can be deployed on a physical machine or a virtual machine (such as a cloud virtual machine or cloud platform).

[0041] In the embodiments of this disclosure, the number of general-purpose network ports is at least two, and the client can select the target network port from at least two general-purpose network ports.

[0042] In one implementation, selecting a target network port from at least two general network ports includes randomly selecting one general network port from the at least two general network ports and determining the randomly selected general network port as the target network port.

[0043] In one implementation, the general-purpose network interface includes a primary general-purpose network interface and a secondary general-purpose network interface. Selecting a target network interface from at least two general-purpose network interfaces includes identifying whether the primary general-purpose network interface is faulty; if the primary general-purpose network interface is not faulty, the primary general-purpose network interface is designated as the target network interface; or, if the primary general-purpose network interface is faulty, the secondary general-purpose network interface is designated as the target network interface. Therefore, in this method, the client can designate the primary general-purpose network interface as the target network interface when the primary general-purpose network interface is not faulty, and designate the secondary general-purpose network interface as the target network interface when the primary general-purpose network interface is faulty. This ensures that the target network interface is not faulty, thereby improving the stability of data transmission between the client and the authentication device, and thus improving the stability of system access.

[0044] In step S102, the target network port is invoked, and the identity authentication information of the customer system is obtained from the authentication device through the target network port.

[0045] In the embodiments of this disclosure, the client can invoke the target network port and obtain the client system's identity authentication information from the authentication device through the target network port. It should be noted that the authentication device stores the client system's identity authentication information, and the identity authentication information is not subject to numerous limitations; for example, the identity authentication information may include a pre-built certificate. In some examples, the pre-built certificate may be generated by a third-party organization and pre-stored in the authentication device; for example, the third-party organization may include CFCA (China Financial Certification Authority). The target network port is not subject to numerous limitations; for example, the target network port may include a general-purpose network port. For example, the target network port may include a Gigabit Ethernet interface.

[0046] In one implementation, the authentication device is deployed in at least one of the customer's intranet, local area network, or virtual private network where the customer system resides. For example, an IP address (Internet Protocol Address) can be pre-assigned to the authentication device within the customer's intranet.

[0047] In one implementation, the client system's identity authentication information is obtained from the authentication device via the target network port, including receiving the identity authentication information sent by the authentication device via the target network port.

[0048] In one implementation, the client has operational permissions to the authentication device, including at least obtaining the client system's identity authentication information from the authentication device. In this case, the client can obtain the client system's identity authentication information from the authentication device through the target network port.

[0049] In step S103, based on the identity authentication information, an identity authentication request is generated for the customer system and sent to the bank system.

[0050] In this embodiment of the disclosure, the client can generate an identity authentication request for the customer system based on the identity authentication information, and send the identity authentication request to the bank system. It should be noted that the bank system can perform identity authentication on the customer system based on the identity authentication request and generate an identity authentication result for the customer system.

[0051] In one implementation, the method further includes receiving a first business request from the customer system before sending the authentication request to the bank system. Therefore, the client can receive the first business request from the customer system before sending the authentication request to the bank system, thus avoiding initiating the authentication request before the customer system sends the first business request. This reduces the number of authentication requests sent and helps save computational resources.

[0052] In one implementation, the authentication request carries authentication information. In some examples, the authentication request carries a pre-made certificate.

[0053] In step S104, in response to the authentication result sent by the bank system instructing the customer system to pass authentication, a connection is established between the client and the bank system, and a connection is established between the customer system and the client.

[0054] In the embodiments of this disclosure, the client can respond to the authentication result sent by the bank system, instructing the client to authenticate and establish a connection between the client and the bank system, and establish a connection between the client and the customer system. That is, the client interfaces with the bank system and the customer system respectively, and the bank system and the customer system can be interfaced through the client.

[0055] It should be noted that there are no restrictions on the connection methods between the client and the bank system, or between the client system and the client. For example, the connection between the client and the bank system includes a two-way HTTPS (Hypertext Transfer Protocol Secure) connection, and the connection between the client system and the client includes a target network port connection.

[0056] In one implementation, the client includes a bank-enterprise direct connection service module, which establishes a connection between the client system and the client, including establishing a connection between the client system and the bank-enterprise direct connection service module in the client.

[0057] As another possible implementation, the client may also respond to the authentication result sent by the bank system indicating that the client system has failed authentication by sending the authentication result to the client system in order to promptly inform the client system that the authentication has failed.

[0058] In summary, according to the system access method provided in this disclosure, the client selects a target network port from at least two general network ports, calls the target network port, and obtains the client system's identity authentication information from the authentication device through the target network port. Compared with related technologies where the authentication device mostly needs to be plugged into an interface on a physical machine, and the client needs to be deployed on a physical machine, the client can select a target network port from at least two general network ports. The determined target network port has higher flexibility and reliability, and data transmission between the client and the authentication device can be achieved only through the target network port, which improves the stability of data transmission between the client and the authentication device, thereby improving the stability of system access. Moreover, the client can be deployed on a virtual machine, broadening the client's deployment environment. Based on the identity authentication information, the client generates an identity authentication request for the client system and sends the identity authentication request to the bank system. In response to the identity authentication result sent by the bank system, the client system is instructed to pass the identity authentication, establish a connection between the client and the bank system, and establish a connection between the client system and the client. That is, the client interfaces with both the bank system and the client system, and the bank system and the client system can interface through the client.

[0059] Figure 2 This is a flowchart illustrating the system access method according to the second embodiment of this disclosure.

[0060] like Figure 2 As shown, the system access method of the second embodiment of this disclosure includes the following steps:

[0061] In step S201, the target network port is selected from at least two general network ports.

[0062] In step S202, the target network port is invoked, and the identity authentication information of the customer system is obtained from the authentication device through the target network port.

[0063] In step S203, based on the identity authentication information, an identity authentication request is generated for the customer system and sent to the bank system.

[0064] In step S204, in response to the authentication result sent by the bank system instructing the customer system to authenticate its identity, a connection is established between the client and the bank system, and a connection is established between the customer system and the client.

[0065] The details of steps S202-S204 can be found in the above embodiments and will not be repeated here.

[0066] In step S205, in response to the first business request sent by the customer system, the first business request is converted into a second business request according to the set conversion rules, and the second business request is sent to the bank system.

[0067] It is understandable that the first business request may not conform to the business rules of the bank system (such as data format, message format, etc.). In the embodiments of this disclosure, the client can respond to the first business request sent by the client system, convert the first business request into a second business request according to the set conversion rules, and send the second business request to the bank system. It should be noted that the second business request conforms to the business rules of the bank system. The set conversion rules are not subject to excessive limitations; for example, the set conversion rules include message format conversion rules, data format conversion rules, etc.

[0068] In one implementation, a first business request is converted into a second business request according to a set conversion rule. This includes identifying the first transaction category corresponding to the first business request and converting the first business request into a second business request according to the set conversion rule corresponding to the first transaction category. It should be noted that the first transaction category is not overly limited. For example, the first transaction category includes, but is not limited to, query transactions (such as querying balances or historical transaction data), fund transactions (such as transferring funds, paying social security, or paying housing provident fund), and file upload / download transactions (such as uploading invoices or vouchers). It is understood that different first transaction categories can correspond to different set conversion rules. Therefore, this method can determine the set conversion rule based on the first transaction category corresponding to the first business request, improving the flexibility and accuracy of setting the conversion rule, and thus improving the flexibility and accuracy of the second business request.

[0069] In one implementation, the method further includes receiving the processing result of a second business request sent by the bank system and sending the processing result of the second business request to the customer system. It is understood that the processing result of the second business request is the same as the processing result of the first business request sent by the customer system. Therefore, in this method, the client can receive the processing result of the second business request sent by the bank system and send the processing result to the customer system, so as to promptly inform the customer system of the processing result of the first business request.

[0070] In summary, according to the system access method provided in this embodiment, the client responds to the first business request sent by the client system, converts the first business request into a second business request according to the set conversion rules, and sends the second business request to the bank system. That is, the client can realize the conversion of the business request so that the second business request conforms to the business rules of the bank system, so that the bank system can perform business processing according to the second business request.

[0071] Figure 3 This is a flowchart illustrating the system access method according to the third embodiment of this disclosure.

[0072] like Figure 3 As shown, the system access method of the third embodiment of this disclosure includes the following steps:

[0073] In step S301, the target network port is selected from at least two general network ports.

[0074] In step S302, the target network port is invoked, and the identity authentication information of the customer system is obtained from the authentication device through the target network port.

[0075] In step S303, an identity authentication request is generated for the customer system based on the identity authentication information, and the identity authentication request is sent to the bank system.

[0076] In step S304, in response to the authentication result sent by the bank system instructing the customer system to pass authentication, a connection is established between the client and the bank system, and a connection is established between the customer system and the client.

[0077] In step S305, in response to the first service request sent by the customer system, the first service request is converted into a second service request according to the set conversion rules.

[0078] The relevant content of steps S301-S305 can be found in the above embodiments, and will not be repeated here.

[0079] In step S306, a signature request for the second service request is sent to the authentication device through the target network port.

[0080] In step S307, the second service request with signature sent by the authentication device is received through the target network port.

[0081] In step S308, the signed second business request is sent to the bank system.

[0082] In the embodiments of this disclosure, the client can send a signature request for the second service request to the authentication device through the target network port. It should be noted that the authentication device can perform signature processing on the second service request to generate a signed second service request. The client can receive the signed second service request sent by the authentication device through the target network port and send the signed second service request to the banking system.

[0083] In one implementation, a signature request for the second service request is sent to the authentication device via the target network port. This includes identifying whether the transaction category corresponding to the second service request is a set transaction category. If the transaction category is indeed a set transaction category, a signature request is sent to the authentication device via the target network port. It should be noted that the set transaction category is not overly limited; for example, it may include financial transactions. Therefore, in this method, before sending the signature request to the authentication device, the client can identify the transaction category corresponding to the second service request as a set transaction category, thus avoiding signature processing for second service requests that do not fall under the set transaction category. This reduces the number of signature request transmissions and helps save computational resources.

[0084] In summary, according to the system access method provided in this disclosure, the client sends a signature request for the second service request to the authentication device through the target network port, receives the signed second service request from the authentication device through the target network port, and then sends the signed second service request to the bank system. Therefore, compared to related technologies where the authentication device mostly needs to be plugged into an interface on a physical machine, and the client needs to be deployed on a physical machine, the client can send a signature request to the authentication device through the target network port and receive the signed second service request from the authentication device, improving the stability and efficiency of signatures in business processing, thereby improving the stability and efficiency of business processing.

[0085] Figure 4 This is a flowchart illustrating the system access method according to the fourth embodiment of this disclosure.

[0086] like Figure 4 As shown, the system access method of the fourth embodiment of this disclosure includes the following steps:

[0087] In step S401, the transmission parameters and / or operating status of each general network port are obtained.

[0088] In step S402, the target network port is selected from at least two general network ports based on transmission parameters and / or operating status.

[0089] It should be noted that there are no restrictions on transmission parameters or operating status. For example, transmission parameters include, but are not limited to, transmission speed, transmission bandwidth, throughput, number of connected clients, etc., and operating status includes, but is not limited to, occupied status, idle status, etc. Occupied status means that the general network port is currently transmitting data, and idle status means that the general network port is not currently transmitting data.

[0090] In one implementation, a target network interface is selected from at least two general-purpose network interfaces based on transmission parameters and / or operating status, including the following possible implementation methods:

[0091] Method 1: Select the general network port with the highest transmission speed from at least two general network ports, and determine the general network port with the highest transmission speed as the target network port.

[0092] In the embodiments of this disclosure, the transmission parameters include transmission speed. The target network port can be determined by the general network port with the highest transmission speed, which can ensure that the transmission speed of the target network port is relatively high.

[0093] Method 2: Select the general network interface that is in an idle state from at least two general network interfaces, and determine the general network interface that is in an idle state as the target network interface.

[0094] In the embodiments of this disclosure, the operating state includes an occupied state and an idle state. The general network port in the idle state can be identified as the target network port, which helps to improve the efficiency of data transmission between the client and the authentication device, and can effectively and reasonably utilize the resources of the general network port.

[0095] In one implementation, a general-purpose network interface (WAN) in an idle state is identified as the target WAN. This involves selecting the target WAN from at least two idle WANs based on their transmission parameters. For example, a candidate WAN with the highest transmission speed and currently in an idle state can be selected from at least two idle WANs and then identified as the target WAN. Therefore, this method can identify the WAN with optimal transmission parameters and currently in an idle state as the target WAN, which helps improve the efficiency of data transmission between the client and the authentication device and effectively utilizes the resources of the general-purpose WAN.

[0096] Method 3: Select the general network interface with the fewest connected clients from at least two general network interfaces, and determine the general network interface with the fewest connected clients as the target network interface.

[0097] In the embodiments of this disclosure, the transmission parameters include the number of connected clients. The general network port with the fewest connected clients can be determined as the target network port, which can effectively and rationally utilize the resources of the general network port.

[0098] In one implementation, the target network interface is determined by selecting the general-purpose network interface with the fewest connected clients. This involves filtering from at least two general-purpose network interfaces with the fewest connected clients to identify the candidate network interface with the highest transmission speed and the fewest connected clients, and then determining the candidate network interface as the target network interface. Therefore, this method can identify the general-purpose network interface with the highest transmission speed and the fewest connected clients as the target network interface, which helps improve the efficiency of data transmission between the client and the authentication device, and effectively and rationally utilizes the resources of the general-purpose network interface.

[0099] In step S403, the target network port is invoked, and the identity authentication information of the customer system is obtained from the authentication device through the target network port.

[0100] In step S404, an identity authentication request is generated for the customer system based on the identity authentication information, and the identity authentication request is sent to the bank system.

[0101] In step S405, in response to the authentication result sent by the bank system instructing the customer system to pass authentication, a connection is established between the client and the bank system, and a connection is established between the customer system and the client.

[0102] The details of steps S403-S405 can be found in the above embodiments and will not be repeated here.

[0103] In summary, according to the system access method provided in this disclosure, the client obtains the transmission parameters and / or operating status of each general-purpose network port, and selects a target network port from at least two general-purpose network ports based on the transmission parameters and / or operating status. Therefore, the client can consider the transmission parameters and / or operating status of the general-purpose network ports to select the target network port, resulting in greater flexibility and reliability in the determined target network port. This improves the stability of data transmission between the client and the authentication device, thereby enhancing the stability of system access.

[0104] Figure 5 This is a block diagram of a system access device according to a first embodiment of the present disclosure.

[0105] like Figure 5 As shown, the system access device 500 of this embodiment is applicable to a client. The system access device 500 includes: a filtering module 501, an acquisition module 502, a sending module 503, and a connection module 504.

[0106] The filtering module 501 is configured to filter the target network port from at least two general network ports;

[0107] The acquisition module 502 is configured to call the target network port and obtain the customer system's identity authentication information from the authentication device through the target network port;

[0108] The sending module 503 is configured to generate an identity authentication request for the customer system based on the identity authentication information, and send the identity authentication request to the bank system;

[0109] The connection module 504 is configured to, in response to the authentication result sent by the bank system instructing the customer system to pass authentication, establish a connection between the client and the bank system, and establish a connection between the customer system and the client.

[0110] In one embodiment of this disclosure, the sending module 503 is further configured to: in response to a first business request sent by the customer system, convert the first business request into a second business request according to a set conversion rule, and send the second business request to the bank system.

[0111] In one embodiment of this disclosure, the sending module 503 is further configured to: send a signature request for the second service request to the authentication device through the target network port; receive the signed second service request sent by the authentication device through the target network port; and send the signed second service request to the bank system.

[0112] In one embodiment of this disclosure, the sending module 503 is further configured to: identify whether the transaction category corresponding to the second service request is a set transaction category; and in response to the transaction category corresponding to the second service request being a set transaction category, send the signature request to the authentication device through the target network port.

[0113] In one embodiment of this disclosure, the sending module 503 is further configured to: receive the processing result of the second business request sent by the bank system, and send the processing result of the second business request to the customer system.

[0114] In one embodiment of this disclosure, the filtering module 501 is further configured to: obtain the transmission parameters and / or operating status of each of the general network ports; and filter out the target network port from at least two of the general network ports based on the transmission parameters and / or the operating status.

[0115] In one embodiment of this disclosure, the transmission parameters include transmission speed, and the filtering module 501 is further configured to: filter out the general network port with the highest transmission speed from at least two general network ports, and determine the general network port with the highest transmission speed as the target network port.

[0116] In one embodiment of this disclosure, the operating state includes an occupied state and an idle state, and the filtering module 501 is further configured to: filter out the general network ports whose operating state is idle from at least two general network ports, and determine the general network ports whose operating state is idle as the target network port.

[0117] Regarding the apparatus in the above embodiments, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.

[0118] In summary, the system access device provided in this embodiment allows the client to select a target network port from at least two general-purpose network ports, invoke the target network port, and obtain the client system's identity authentication information from the authentication device through the target network port. Compared to related technologies where authentication devices mostly need to be plugged into interfaces on physical machines and the client needs to be deployed on a physical machine, the client can select a target network port from at least two general-purpose network ports. The determined target network port is more flexible and reliable, and data transmission between the client and the authentication device can be achieved solely through the target network port, improving the stability of data transmission between the client and the authentication device, thereby improving the stability of system access. Furthermore, the client can be deployed on a virtual machine, broadening the client's deployment environment. Based on the identity authentication information, the client generates an identity authentication request for the client system and sends the identity authentication request to the bank system. In response to the identity authentication result sent by the bank system, the client system is instructed to pass identity authentication, establishing a connection between the client and the bank system, and establishing a connection between the client system and the client. That is, the client interfaces with both the bank system and the client system, and the bank system and the client system can interface through the client.

[0119] Figure 6 This is a block diagram illustrating an electronic device according to an exemplary embodiment. It should be noted that the electronic device may be a client.

[0120] like Figure 6 As shown, the electronic device 600 includes a processor 601 and a memory 602 for storing executable instructions of the processor 601. The processor 601 is configured to execute instructions to implement the system access method described in this embodiment. It should be noted that the implementation process and technical principles of the electronic device in this embodiment are explained in the foregoing description of the system access method in this embodiment, and will not be repeated here.

[0121] In summary, the electronic device provided in this embodiment can execute the system access method described above. The client selects a target network port from at least two general network ports, calls the target network port, and obtains the client system's identity authentication information from the authentication device through the target network port. Compared with related technologies where the authentication device mostly needs to be plugged into an interface on a physical machine and the client needs to be deployed on a physical machine, the client can select a target network port from at least two general network ports. The determined target network port is more flexible and reliable, and data transmission between the client and the authentication device can be achieved only through the target network port, improving the stability of data transmission between the client and the authentication device, thereby improving the stability of system access. Moreover, the client can be deployed on a virtual machine, broadening the client's deployment environment. Based on the identity authentication information, the client generates an identity authentication request for the client system and sends the identity authentication request to the bank system. In response to the identity authentication result sent by the bank system, the client system is instructed to pass the identity authentication, establish a connection between the client and the bank system, and establish a connection between the client system and the client. That is, the client interfaces with both the bank system and the client system, and the bank system and the client system can interface through the client.

[0122] To implement the above embodiments, this disclosure also proposes a computer-readable storage medium.

[0123] When the instructions in the computer-readable storage medium are executed by the processor of the service server, the service server is able to perform the system access method as described above. Optionally, the computer-readable storage medium may be a ROM, random access memory (RAM), CD-ROM, magnetic tape, floppy disk, or optical data storage device, etc.

[0124] To implement the above embodiments, this disclosure also provides a computer program product, including a computer program, characterized in that the computer program, when executed by a processor, implements the system access method as described above.

[0125] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and spirit of this disclosure are indicated by the following claims.

[0126] It should be understood that this disclosure is not limited to the precise structures described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from its scope. The scope of this disclosure is limited only by the appended claims.

Claims

1. A system access method, characterized in that, Applicable to a client deployed in a virtual machine, the method includes: Obtain the transmission parameters of each general-purpose network port, including the transmission speed; select the general-purpose network port with the highest transmission speed from at least two general-purpose network ports, and determine the general-purpose network port with the highest transmission speed as the target network port; The target network port is invoked, and the identity authentication information of the customer system is obtained from the authentication device through the target network port; Based on the identity authentication information, an identity authentication request is generated for the customer system, and the identity authentication request is sent to the bank system; In response to the authentication result sent by the bank system, the customer system establishes a connection between the client and the bank system after authentication, and establishes a connection between the customer system and the client. The method further includes: In response to a first service request sent by the customer system, the first service request is converted into a second service request according to a set conversion rule; A signature request for the second service request is sent to the authentication device through the target network port; The target network port receives the signed second service request sent by the authentication device. The signed second business request is sent to the bank system.

2. The method according to claim 1, characterized in that, Sending a signature request for the second service request to the authentication device through the target network port includes: Identify whether the transaction category corresponding to the second business request is a set transaction category; In response to the second service request corresponding to the transaction category being the set transaction category, the signature request is sent to the authentication device through the target network port.

3. The method according to claim 2, characterized in that, Also includes: The system receives the processing result of the second business request sent by the bank system and sends the processing result of the second business request to the customer system.

4. A system access method, characterized in that, Applicable to a client deployed in a virtual machine, the method includes: Obtain the operating status of each general network port, including occupied status and idle status; filter out the general network ports whose operating status is idle from at least two general network ports; and determine the general network ports whose operating status is idle as the target network port. The target network port is invoked, and the identity authentication information of the customer system is obtained from the authentication device through the target network port; Based on the identity authentication information, an identity authentication request is generated for the customer system, and the identity authentication request is sent to the bank system; In response to the authentication result sent by the bank system, the customer system establishes a connection between the client and the bank system after authentication, and establishes a connection between the customer system and the client. The method further includes: In response to a first service request sent by the customer system, the first service request is converted into a second service request according to a set conversion rule; A signature request for the second service request is sent to the authentication device through the target network port; The target network port receives the signed second service request sent by the authentication device. The signed second business request is sent to the bank system.

5. The method according to claim 4, characterized in that, Sending a signature request for the second service request to the authentication device through the target network port includes: Identify whether the transaction category corresponding to the second business request is a set transaction category; In response to the second service request corresponding to the transaction category being the set transaction category, the signature request is sent to the authentication device through the target network port.

6. The method according to claim 5, characterized in that, Also includes: The system receives the processing result of the second business request sent by the bank system and sends the processing result of the second business request to the customer system.

7. A system access device, characterized in that, For a client deployed in a virtual machine, the device includes: The filtering module is configured to obtain the transmission parameters of each general network port, including the transmission speed, and to filter out the general network port with the highest transmission speed from at least two general network ports, and to determine the general network port with the highest transmission speed as the target network port. The acquisition module is configured to call the target network port and obtain the client system's identity authentication information from the authentication device through the target network port; The sending module is configured to generate an identity authentication request for the customer system based on the identity authentication information, and send the identity authentication request to the bank system; The connection module is configured to, in response to the authentication result sent by the bank system instructing the customer system to pass authentication, establish a connection between the client and the bank system, and establish a connection between the customer system and the client; The sending module is further configured to: In response to a first service request sent by the customer system, the first service request is converted into a second service request according to a set conversion rule; A signature request for the second service request is sent to the authentication device through the target network port; The target network port receives the signed second service request sent by the authentication device. The signed second business request is sent to the bank system.

8. The apparatus according to claim 7, characterized in that, The sending module is further configured to: Identify whether the transaction category corresponding to the second business request is a set transaction category; In response to the second service request corresponding to the transaction category being the set transaction category, the signature request is sent to the authentication device through the target network port.

9. The apparatus according to claim 8, characterized in that, The sending module is further configured to: The system receives the processing result of the second business request sent by the bank system and sends the processing result of the second business request to the customer system.

10. A system access device, characterized in that, For a client deployed in a virtual machine, the device includes: The filtering module is configured to obtain the running status of each general network port, including occupied status and idle status, filter out the general network ports whose running status is idle from at least two general network ports, and determine the general network ports whose running status is idle as target network ports; The acquisition module is configured to call the target network port and obtain the client system's identity authentication information from the authentication device through the target network port; The sending module is configured to generate an identity authentication request for the customer system based on the identity authentication information, and send the identity authentication request to the bank system; The connection module is configured to, in response to the authentication result sent by the bank system instructing the customer system to pass authentication, establish a connection between the client and the bank system, and establish a connection between the customer system and the client; The sending module is further configured to: In response to a first service request sent by the customer system, the first service request is converted into a second service request according to a set conversion rule; A signature request for the second service request is sent to the authentication device through the target network port; The target network port receives the signed second service request sent by the authentication device. The signed second business request is sent to the bank system.

11. The apparatus according to claim 10, characterized in that, The sending module is further configured to: Identify whether the transaction category corresponding to the second business request is a set transaction category; In response to the second service request corresponding to the transaction category being the set transaction category, the signature request is sent to the authentication device through the target network port.

12. The apparatus according to claim 11, characterized in that, The sending module is further configured to: The system receives the processing result of the second business request sent by the bank system and sends the processing result of the second business request to the customer system.

13. An electronic device, characterized in that, include: processor; Memory used to store the processor's executable instructions; The processor is configured to execute the instructions to implement the system access method as described in any one of claims 1-6.

14. A computer-readable storage medium, wherein instructions in the computer-readable storage medium, when executed by a processor of an electronic device, enable the electronic device to perform the system access method as described in any one of claims 1-6.

15. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the system access method according to any one of claims 1-6.

Citation Information

Patent Citations

  • Computer and transmitting method of security information for authentication

    CN101459513A

  • Processing system between enterprise and bank service abutting joint

    CN1681260A