Method, system and storage medium for securely acquiring enterprise WeChat open interface data
By introducing the enterprise WeChat service platform between the application and the open interface of enterprise WeChat, and performing permission checks and data forwarding, the risk of data leakage of enterprise WeChat open interface is solved and the security of data access is improved.
Patent Information
- Application Number
- CN202211443156.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-11-17
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-11-17
AI Technical Summary
In the prior art, once the key request parameters SECRET and CORPID of the enterprise WeChat open interface are leaked, it is easy to lead to information leakage risks and is difficult to track.
A layer of enterprise WeChat service platform is added between the application and the open interface of enterprise WeChat. Through this platform, the application side is subject to permission verification, and the open interface data is obtained and forwarded only after passing the verification.
It effectively avoids the risk of information leakage and improves the security of data access to the open interface of the enterprise WeChat backend.
Smart Images

Figure CN115834514B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data information security technology, and in particular to a method, system and storage medium for securely acquiring enterprise WeChat open interface data. Background Art
[0002] API (Application Programming Interface, also known as open interface) has the advantages of easy calling and strong versatility. It has gradually become the main way to provide Internet network services. Therefore, API calling has also become a key area of focus in preventing data leakage.
[0003] WeChat for Business has opened up various APIs to facilitate enterprise application development. SECRET and CORPID are two key request parameters necessary for application development. They are provided by the WeChat for Business backend management system and are permanently effective with the application and the enterprise. In the actual development process, the two key parameters SECRET and CORPID are generally provided directly to developers, who then directly call WeChat for Business' open APIs. At this point, if these two key parameters are leaked, even through the open platform provided by WeChat, the complete company address book and organizational structure information can be easily obtained, and it is difficult to track, which poses a risk of information leakage. Summary of the invention
[0004] The embodiments of the present invention provide a method, system and storage medium for securely acquiring enterprise WeChat open interface data, which can effectively avoid information leakage and improve the security of enterprise WeChat backend open interface data access.
[0005] In a first aspect, an embodiment of the present invention provides a method for securely obtaining enterprise WeChat open interface data, comprising:
[0006] The enterprise WeChat service platform performs permission verification on the application end according to the open interface call request sent by the application end;
[0007] When the permission verification is passed, the enterprise WeChat service platform obtains the open interface data of the corresponding open interface of the enterprise WeChat according to the configuration information of the enterprise WeChat;
[0008] The enterprise WeChat service platform forwards the open interface data to the application end.
[0009] As an improvement to the above solution, the enterprise WeChat service platform performs permission verification on the application end according to the open interface call request sent by the application end, including:
[0010] The application terminal generates an open interface call request according to its own application identification and application key, and sends the open interface call request to the enterprise WeChat service platform;
[0011] The enterprise WeChat service platform performs a first verification on the application identifier and the application key in the open interface call request;
[0012] When the first verification is passed, the enterprise WeChat service platform performs a second verification on the open interface access rights of the application end.
[0013] As an improvement to the above solution, the enterprise WeChat service platform performs a second verification on the open interface access rights of the application end, including:
[0014] The enterprise WeChat service platform queries the access rights currently applied for by the application end;
[0015] The enterprise WeChat service platform determines whether the application end has access rights to the open interface specified by the open interface call request based on the queried applied access rights;
[0016] If yes, determining that the application terminal passes the second verification;
[0017] If not, it is determined that the application terminal has not passed the second verification.
[0018] As an improvement to the above solution, the method for securely obtaining enterprise WeChat open interface data also includes:
[0019] The application sends a registration request to the enterprise WeChat service platform;
[0020] In response to the registration request, the enterprise WeChat service platform configures the application end with an application identifier, an application key, and access rights to basic interfaces;
[0021] The enterprise WeChat service platform generates registration response information according to the application identifier, the application key and the access rights of the basic interface, and sends the registration response information to the application end so that the application end completes the registration.
[0022] As an improvement to the above solution, the method for securely obtaining enterprise WeChat open interface data includes:
[0023] When the application completes registration, the application sends an open interface permission application request to the enterprise WeChat service platform; wherein the open interface permission application request is used to indicate the access rights of at least one open interface in the enterprise WeChat applied for;
[0024] The enterprise WeChat service platform responds to the open interface permission application request and determines whether the application terminal has access requirements for the corresponding open interface;
[0025] If yes, then configure the access rights of the corresponding open interface for the application end;
[0026] If not, the access permission for configuring the corresponding open interface on the application side is denied.
[0027] As an improvement to the above solution, the method for securely obtaining enterprise WeChat open interface data includes:
[0028] The enterprise WeChat service platform registers the enterprise WeChat according to the received enterprise WeChat configuration information.
[0029] As an improvement to the above solution, the method for securely obtaining enterprise WeChat open interface data also includes:
[0030] When the permission check fails, the enterprise WeChat service platform rejects the open interface call request.
[0031] As an improvement of the above solution, the configuration information includes: the enterprise WeChat key and the enterprise WeChat corporate account.
[0032] In a second aspect, an embodiment of the present invention provides a system for securely acquiring enterprise WeChat open interface data, including: an application end, an enterprise WeChat service platform, and an open interface of enterprise WeChat;
[0033] The application end is used to send an open interface call request to the enterprise WeChat service platform;
[0034] The enterprise WeChat service platform is used to perform permission verification on the application end according to the open interface call request;
[0035] When the permission check is passed, the enterprise WeChat service platform is used to obtain the open interface data of the corresponding open interface of the enterprise WeChat according to the configuration information of the enterprise WeChat;
[0036] The enterprise WeChat service platform is used to forward the open interface data to the application end.
[0037] In a third aspect, an embodiment of the present invention provides a computer-readable storage medium, which stores a computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute a method for securely obtaining enterprise WeChat open interface data as described in any one of Embodiment 1.
[0038] Compared with the prior art, the beneficial effects of the embodiments of the present invention are: by adding a layer of enterprise WeChat service platform between the application and the open interface of Enterprise WeChat, the Enterprise WeChat service platform performs permission verification on the application end according to the open interface call request sent by the application end; when the permission verification is passed, the Enterprise WeChat service platform obtains the open interface data of the corresponding open interface of the Enterprise WeChat according to the configuration information of the Enterprise WeChat; the Enterprise WeChat service platform forwards the open interface data to the application end, so that the application end needs to obtain the open interface data from the Enterprise WeChat service platform, which can effectively avoid information leakage and improve the security of access to the open interface data of the Enterprise WeChat background. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] In order to more clearly illustrate the technical solution of the present invention, the drawings used in the implementation mode will be briefly introduced below. Obviously, the drawings described below are only some implementation modes of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0040] Figure 1 It is a flow chart of a method for securely obtaining enterprise WeChat open interface data provided by an embodiment of the present invention;
[0041] Figure 2 It is a schematic diagram of the interaction between the application end, the enterprise WeChat service platform, and the enterprise WeChat open interface provided by an embodiment of the present invention;
[0042] Figure 3 It is a schematic diagram of a system for securely acquiring enterprise WeChat open interface data provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0043] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0044] Embodiment 1
[0045] See also Figure 1 , which is a flow chart of a method for securely obtaining enterprise WeChat open interface data provided by an embodiment of the present invention, the method for securely obtaining enterprise WeChat open interface data includes:
[0046] S1: The enterprise WeChat service platform performs permission verification on the application according to the open interface call request sent by the application;
[0047] S2: When the permission check is passed, the enterprise WeChat service platform obtains the open interface data of the corresponding open interface of the enterprise WeChat according to the configuration information of the enterprise WeChat;
[0048] The configuration information includes: the enterprise WeChat key (ie, SECRET) and the enterprise WeChat corporate ID (ie, CORPID). These two parameters can be used to call the corresponding enterprise WeChat open interface.
[0049] Furthermore, the enterprise WeChat service platform registers the enterprise WeChat according to the received enterprise WeChat configuration information.
[0050] The administrator may configure the configuration information of the enterprise WeChat in the enterprise WeChat service platform in advance, so that the enterprise WeChat service platform can subsequently access the open interface data of the corresponding enterprise WeChat according to the configuration information stored locally.
[0051] S3: The enterprise WeChat service platform forwards the open interface data to the application end.
[0052] Furthermore, when the permission check fails, the enterprise WeChat service platform rejects the open interface call request.
[0053] Exemplarily, a user can create an application end in Enterprise WeChat, and the user sends an open interface call request to the Enterprise WeChat service through the application end to request access to the open interface of the corresponding Enterprise WeChat; then the Enterprise WeChat service platform performs a permission check on the application end to determine whether the application end has the access permission to the open interface of the Enterprise WeChat described in the method, if not, the open interface call request is rejected; if so, it means that the permission check has passed. At this time, the Enterprise WeChat service platform obtains the open interface data from the Enterprise WeChat according to the configuration information of the Enterprise WeChat, and returns the obtained open interface data to the application end; the embodiment of the present invention adds a layer of Enterprise WeChat service platform between the application and the open interface of Enterprise WeChat. The application end needs to obtain the open interface data from the Enterprise WeChat service platform, and no longer directly calls Enterprise WeChat, which can effectively avoid information leakage and improve the security of access to the open interface data of the Enterprise WeChat background.
[0054] In an optional embodiment, the enterprise WeChat service platform performs permission verification on the application end according to the open interface call request sent by the application end, including:
[0055] The application terminal generates an open interface call request according to its own application identification and application key, and sends the open interface call request to the enterprise WeChat service platform;
[0056] The enterprise WeChat service platform performs a first verification on the application identifier and the application key in the open interface call request;
[0057] The application identifier is the application ID of the application terminal.
[0058] When the first verification is passed, the enterprise WeChat service platform performs a second verification on the open interface access rights of the application end.
[0059] Further, the enterprise WeChat service platform performs a second verification on the open interface access rights of the application end, including:
[0060] The enterprise WeChat service platform queries the access rights currently applied for by the application end;
[0061] The enterprise WeChat service platform determines whether the application end has access rights to the open interface specified by the open interface call request based on the queried applied access rights;
[0062] If yes, determining that the application terminal passes the second verification;
[0063] If not, it is determined that the application terminal has not passed the second verification.
[0064] When the enterprise WeChat service platform receives an open interface call request from the application end, it first verifies the application identifier and application key in the open interface call request to determine whether the application identifier and application key of a registered application that are consistent with the application identifier and application key are stored in the database of the enterprise WeChat service platform. If not, the open interface call request is rejected; if so, the access rights of the application end are further verified to determine whether the application end has the access rights to the open interface specified by the open interface call request. If not, the open interface call request is rejected; if so, through the permission verification, the enterprise WeChat service platform obtains the open interface data of the enterprise WeChat according to the configuration information of the enterprise WeChat, and returns the obtained open interface data to the application end.
[0065] In an optional embodiment, the method for securely obtaining enterprise WeChat open interface data further includes:
[0066] The application sends a registration request to the enterprise WeChat service platform;
[0067] In response to the registration request, the enterprise WeChat service platform configures the application end with an application identifier, an application key, and access rights to basic interfaces;
[0068] The enterprise WeChat service platform generates registration response information according to the application identifier, the application key and the access rights of the basic interface, and sends the registration response information to the application end so that the application end completes the registration.
[0069] Furthermore, the method for securely obtaining enterprise WeChat open interface data includes:
[0070] When the application completes registration, the application sends an open interface permission application request to the enterprise WeChat service platform; wherein the open interface permission application request is used to indicate the access rights of at least one open interface in the enterprise WeChat applied for;
[0071] The enterprise WeChat service platform responds to the open interface permission application request and determines whether the application terminal has access requirements for the corresponding open interface;
[0072] If yes, then configure the access rights of the corresponding open interface for the application end;
[0073] If not, the access permission for configuring the corresponding open interface on the application side is denied.
[0074] Before the application end requests the open interface data of WeChat for Enterprise from the WeChat for Enterprise service platform, the application end is required to complete registration and access permission application to the WeChat for Enterprise service platform in advance; wherein, the registration process is: the application end applies for registration to the WeChat for Enterprise service platform, and the WeChat for Enterprise service platform configures the application identifier, application key and basic interface access permission for the application end applying for registration; wherein, the basic interface connects to the basic data of WeChat for Enterprise, and this part of data can be understood as that the application end applying for registration can access it, which is generally the open information of WeChat for Enterprise. After completing the registration, the application end also needs to apply for access permission of individual open interfaces according to business needs. For example, developer A and developer B belong to two different R&D departments and need to apply for access permission of different open interfaces. The specific permission application process is: the application end sends an open interface permission application request to the WeChat for Enterprise service platform, and the WeChat for Enterprise service platform determines whether the application end has the access requirement of the corresponding open interface according to the corresponding business needs. If so, the open interface permission application request is passed and the access permission of the corresponding open interface is configured on the WeChat for Enterprise service platform; if not, the open interface permission application request is rejected.
[0075] Combine the following Figure 2 , the workflow of the enterprise WeChat service platform is described, and the workflow of the enterprise WeChat service platform specifically includes:
[0076] Step 1: The application registers the application on the enterprise WeChat service platform;
[0077] Step 2: The enterprise WeChat service platform configures the application ID, application key, and access rights to the basic interface, and returns them to the application end;
[0078] Step 3: The application side applies to the enterprise WeChat service platform for access rights to the open interface;
[0079] Step 4: The WeChat Enterprise service platform determines whether to approve the access permission application in step 3 based on the business needs of the application, and returns a response message of approval or rejection to the application.
[0080] Step 5: The application sends an open interface call request to the enterprise WeChat service platform; wherein the request header of the open interface call request carries the application ID and application key;
[0081] Step 6: The enterprise WeChat service platform verifies the application, including: application ID and application key verification, and whether the application has access rights to query the corresponding open interface data; if it fails the verification, jump to step 7; if it passes the verification, jump to step 8;
[0082] Step 7: The WeChat for Enterprise service platform rejects the open interface call request; For example, developer A registers application A through the WeChat for Enterprise service platform and obtains access rights to basic data. When accessing an open interface for which he has not applied for access rights, he is rejected by the WeChat for Enterprise service platform;
[0083] Step 8: The enterprise WeChat service platform sends SECRET and CORPID to the open interface of enterprise WeChat to query the corresponding open interface data;
[0084] Step 9: The WeChat for Enterprise service platform forwards the queried open interface data to the application end. For example, developer B obtains access to basic data through the WeChat for Enterprise service platform. Due to business needs, he applies for access to the employee department information interface, and the WeChat for Enterprise service platform approves the application after review. When accessing the employee department information interface later, the WeChat for Enterprise service platform successfully requests data from the WeChat for Enterprise employee department information interface, and then returns the corresponding open interface data to application end B.
[0085] Compared with the prior art, the beneficial effect of the embodiments of the present invention is that by adding a layer of enterprise WeChat service platform between the application and the open interface of enterprise WeChat, the application side only needs to provide the application ID, application key and the open interface information that needs to be requested, and the enterprise WeChat service platform carries SECRET and CORPID to initiate a request to the enterprise WeChat backend, and then returns the corresponding open interface data to the application side. At this time, when the application side needs to obtain the open interface of enterprise WeChat, it no longer directly calls enterprise WeChat, but obtains it through the enterprise WeChat service platform, which can reduce the number of key transfers, reduce the risk of information leakage, and improve the security of access to the open interface data of the enterprise WeChat background.
[0086] Embodiment 2
[0087] See also Figure 3 , an embodiment of the present invention provides a system for securely acquiring enterprise WeChat open interface data, comprising: an application end 1, an enterprise WeChat service platform 2, and an enterprise WeChat open interface 3;
[0088] The application end 1 is used to send an open interface call request to the enterprise WeChat service platform 2;
[0089] Further, the application end 1 is used to generate an open interface call request according to its own application identification and application key, and send the open interface call request to the enterprise WeChat service platform 2;
[0090] The enterprise WeChat service platform 2 is used to perform a first verification on the application identifier and the application key in the open interface call request;
[0091] When the first verification is passed, the enterprise WeChat service platform 2 is used to perform a second verification on the open interface access rights of the application end.
[0092] Specifically, the enterprise WeChat service platform 2 is used to query the access rights currently applied for by the application end;
[0093] The enterprise WeChat service platform 2 is used to determine whether the application end has the access rights to the open interface specified by the open interface call request based on the queried access rights applied for; if so, it is determined that the application end has passed the second verification; if not, it is determined that the application end has not passed the second verification.
[0094] The enterprise WeChat service platform 2 is used to perform permission verification on the application terminal 1 according to the open interface call request;
[0095] When the permission check is passed, the enterprise WeChat service platform 2 is used to obtain the open interface data of the enterprise WeChat corresponding open interface 3 according to the configuration information of the enterprise WeChat;
[0096] The enterprise WeChat service platform 2 is used to forward the open interface data to the application end.
[0097] Furthermore, when the permission verification fails, the enterprise WeChat service platform 2 is used to reject the open interface call request.
[0098] In an optional embodiment, the application end is further used to send a registration request to the enterprise WeChat service platform;
[0099] In response to the registration request, the enterprise WeChat service platform is further used to configure an application identifier, an application key, and access permissions for the basic interface for the application end;
[0100] The enterprise WeChat service platform is further used to generate registration response information according to the application identifier, the application key, and the access permissions for the basic interface, and send the registration response information to the application end so that the application end completes the registration.
[0101] In an optional embodiment, the method for securely obtaining enterprise WeChat open interface data includes:
[0102] After the application end completes the registration, the application end is further used to send an open interface permission application request to the enterprise WeChat service platform; wherein, the open interface permission application request is used to indicate the access permissions for at least one open interface in the enterprise WeChat to be applied for;
[0103] The enterprise WeChat service platform is further used to, in response to the open interface permission application request, determine whether the application end has the access requirement for the corresponding open interface; if so, configure the access permissions for the corresponding open interface for the application end; if not, refuse to configure the access permissions for the corresponding open interface for the application end.
[0104] In an optional embodiment, the enterprise WeChat service platform is further used to register the enterprise WeChat according to the received configuration information of the enterprise WeChat.
[0105] As an improvement to the above solution, the method for securely obtaining enterprise WeChat open interface data further includes:
[0106] As an improvement to the above solution, the configuration information includes: the key of the enterprise WeChat and the enterprise number of the enterprise WeChat.
[0107] It should be noted that the technical principle and technical effect of the embodiments of the present invention are the same as those of Embodiment 1, and will not be elaborated here.
[0108] Embodiment 3
[0109] An embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method for securely obtaining enterprise WeChat open interface data as described in any one of the first embodiments, for example Figure 1 The steps S1-S3 shown in the figure can achieve the same technical effect and will not be described again here to avoid repetition.
[0110] It should be noted that the device embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. In addition, in the accompanying drawings of the device embodiments provided by the present invention, the connection relationship between the modules indicates that there is a communication connection between them, which may be specifically implemented as one or more communication buses or signal lines. A person of ordinary skill in the art may understand and implement it without paying any creative effort.
[0111] The above is a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, many improvements and modifications can be made without departing from the principle of the present invention. These improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A method for securely obtaining enterprise WeChat open interface data, It is characterized in that include: The application sends a registration request to the enterprise WeChat service platform; In response to the registration request, the enterprise WeChat service platform configures the application end with an application identifier, an application key, and access rights to basic interfaces; The enterprise WeChat service platform generates registration response information according to the application identifier, the application key and the access rights of the basic interface, and sends the registration response information to the application end, so that the application end completes the registration; The application terminal generates an open interface call request according to its own application identification and application key, and sends the open interface call request to the enterprise WeChat service platform; The enterprise WeChat service platform performs permission verification on the application end according to the open interface call request sent by the application end; When the permission verification is passed, the enterprise WeChat service platform obtains the open interface data of the corresponding open interface of the enterprise WeChat according to the configuration information of the enterprise WeChat; The enterprise WeChat service platform forwards the open interface data to the application end.
2. The method for securely obtaining enterprise WeChat open interface data as claimed in claim 1, It is characterized in that The enterprise WeChat service platform performs permission verification on the application end according to the open interface call request sent by the application end, including: The enterprise WeChat service platform performs a first verification on the application identifier and the application key in the open interface call request; When the first verification is passed, the enterprise WeChat service platform performs a second verification on the open interface access rights of the application end.
3. The method for securely obtaining enterprise WeChat open interface data as claimed in claim 2, It is characterized in that The enterprise WeChat service platform performs a second verification on the open interface access rights of the application end, including: The enterprise WeChat service platform queries the access rights currently applied for by the application end; The enterprise WeChat service platform determines whether the application end has access rights to the open interface specified by the open interface call request based on the queried applied access rights; If yes, determining that the application terminal passes the second verification; If not, it is determined that the application terminal has not passed the second verification.
4. The method for securely obtaining enterprise WeChat open interface data as claimed in claim 1, It is characterized in that Also includes: When the application completes registration, the application sends an open interface permission application request to the enterprise WeChat service platform; The open interface permission application request is used to indicate the access rights to at least one open interface in the enterprise WeChat; The enterprise WeChat service platform responds to the open interface permission application request and determines whether the application terminal has access requirements for the corresponding open interface; If yes, then configure the access rights of the corresponding open interface for the application end; If not, the access permission for configuring the corresponding open interface on the application side is denied.
5. The method for securely obtaining enterprise WeChat open interface data as claimed in claim 1, It is characterized in that Also includes: The enterprise WeChat service platform registers the enterprise WeChat according to the received enterprise WeChat configuration information.
6. The method for securely obtaining enterprise WeChat open interface data as claimed in claim 3, It is characterized in that Also includes: When the permission check fails, the enterprise WeChat service platform rejects the open interface call request.
7. The method for securely obtaining enterprise WeChat open interface data as described in claim 1 or 5, It is characterized in that The configuration information includes: The WeChat Work key and WeChat Work corporate account.
8. A system for securely acquiring enterprise WeChat open interface data, It is characterized in that include: Application end, WeChat for Business service platform and WeChat for Business open interface; The application end is used to send a registration request to the enterprise WeChat service platform; After the application is registered, an open interface call request is generated according to the application identifier and application key fed back by the enterprise WeChat service platform, and the open interface call request is sent to the enterprise WeChat service platform; The enterprise WeChat service platform is used to respond to the registration request of the application end and configure the application identification, application key and basic interface access rights for the application end; Generate registration response information according to the application identifier, the application key and the access right of the basic interface, and send the registration response information to the application end, so that the application end completes the registration; And according to the open interface call request, the application end is checked for permissions; When the permission check is passed, the enterprise WeChat service platform is used to obtain the open interface data of the corresponding open interface of the enterprise WeChat according to the configuration information of the enterprise WeChat; The enterprise WeChat service platform is used to forward the open interface data to the application end.
9. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores a computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the method for securely obtaining enterprise WeChat open interface data as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Method for analyzing data authority control based on Handle identification
CN112417511A