Access request processing method and device
By obtaining access request parameters and querying configuration information, and adding global unique number value, the cumbersome configuration information problem when the access entry information of the business system is changed, and the access efficiency is improved and dynamic switching is achieved.
Patent Information
- Application Number
- CN202211716354.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-29
- Publication Date
- 2025-08-26
- Estimated Expiration
- 2042-12-29
AI Technical Summary
In the prior art, when the access entry information of the business system is changed, the configuration information change process is complicated, resulting in low access efficiency.
By obtaining access parameters in the access request, querying the corresponding configuration information, and sending access requests based on the access address parameters, adding a global unique number value to identify the uniqueness of the request, simplifying the configuration information change process.
When the access address of the business system changes, access can be completed by simply changing the configuration information, which improves access efficiency, reduces the transformation content, and realizes dynamic switching and security control of access requests.
Smart Images

Figure CN115988091B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet technology, and in particular to a method and device for processing access requests. Background Art
[0002] With the continuous development of internet technology, information dissemination has become more convenient and the speed of information updates has also been accelerating. Taking banks as an example, the amount of information that needs to be released across their online systems and offline branches is increasing, and banks are also placing increasing demands on the frequency and timeliness of information updates.
[0003] When information changes, such as the URL link, published information content, information validity, etc., it is necessary to republish the entrance to access the information, or jump the link at the originally published access entrance to jump to the updated information access link.
[0004] When information changes, whether it is re-publishing the access information entrance or jumping the link to the originally published access entrance, the configuration information change process is cumbersome, resulting in inefficient access to the business system. Summary of the Invention
[0005] In view of this, an embodiment of the present application provides an access request processing method and device, which aims to solve the problem in the prior art that when the access entry information of the business system is changed, the configuration information change process is cumbersome, resulting in low access efficiency to the business system.
[0006] In a first aspect, an embodiment of the present application provides a method for processing an access request, the method comprising:
[0007] In response to an access request to a business system, obtaining access parameters in the access request;
[0008] Querying configuration information corresponding to the access parameter; the configuration information at least includes an access address parameter and access parameter authority of the business system corresponding to the access parameter;
[0009] According to the access address parameters of the business system included in the configuration information, the access request is sent to the business system, so as to access the business system.
[0010] Optionally, the method further includes:
[0011] The access parameters in the access request, configuration information corresponding to the access parameters, and a history record of access to the business system are stored.
[0012] Optionally, before sending the access request to the business system, the method further includes:
[0013] A globally unique number value is added to the access address parameter of the business system corresponding to the access parameter, where the globally unique number value is used to characterize the uniqueness of the access request to the business system.
[0014] Optionally, before accessing the business system, the method further includes:
[0015] The access parameter in the access request is verified using the globally unique number value.
[0016] Optionally, before obtaining access parameters in the access request in response to the access request to the business system, the method further includes:
[0017] Parameter configuration is performed on the access medium used to access the business system, and the parameters include at least the validity period of the access medium, the target address for accessing the business system, the number of access restrictions, the access channel restrictions, the access user authority settings, the access IP address settings, the encryption method, the encryption key, the decryption key, the channel number, the message format and the request forwarding mode.
[0018] In a second aspect, an embodiment of the present application provides an access request processing device, the device comprising: an access request processing module, a parameter configuration module, and a request forwarding module;
[0019] The access request processing module is configured to respond to an access request to a business system and obtain access parameters in the access request;
[0020] The parameter configuration module is used to query the configuration information corresponding to the access parameter; the configuration information at least includes the access address parameter and access parameter authority of the business system corresponding to the access parameter;
[0021] The request forwarding module is configured to send the access request to the business system according to the access address parameter of the business system included in the configuration information, so as to access the business system.
[0022] Optionally, the device further includes a data storage module, wherein the data storage module is specifically configured to:
[0023] The access parameters in the access request, configuration information corresponding to the access parameters, and a history record of access to the business system are stored.
[0024] Optionally, the parameter configuration module is further used to:
[0025] Before sending the access request to the business system, a globally unique number value is added to the access address parameter of the business system corresponding to the access parameter, where the globally unique number value is used to characterize the uniqueness of the access request to the business system.
[0026] Optionally, before accessing the business system, the data storage module is further configured to:
[0027] The access parameter in the access request is verified using the globally unique number value.
[0028] Optionally, before obtaining access parameters in the access request in response to the access request to the business system, the parameter configuration module is further configured to:
[0029] Parameter configuration is performed on the access medium used to access the business system, and the parameters include at least the validity period of the access medium, the target address for accessing the business system, the number of access restrictions, the access channel restrictions, the access user authority settings, the access IP address settings, the encryption method, the encryption key, the decryption key, the channel number, the message format and the request forwarding mode.
[0030] The present application provides an access request processing method and device. When executing the method, in response to an access request to a business system, the access parameters in the access request are obtained; then the configuration information corresponding to the access parameters is queried; the configuration information at least includes the access address parameters and access parameter permissions of the business system corresponding to the access parameters; then, based on the access address parameters of the business system contained in the configuration information, the access request is sent to the business system in order to access the business system. By obtaining the access parameters in the access request, querying the access address parameters of the business system corresponding to the access parameters based on the access parameters, and then sending the access request to the business system, it is achieved that when the access address of the business system changes, only the configuration information needs to be changed to complete the access to the business system, which simplifies the configuration information change process and improves the efficiency of access to the business system. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the technical solutions in this embodiment or the prior art, the following briefly introduces the drawings required for use in the embodiment or the prior art description. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0032] Figure 1 A schematic diagram of the interaction between a user terminal and a business system provided in an embodiment of the present application;
[0033] Figure 2 A method for processing access requests provided in an embodiment of the present application;
[0034] Figure 3 A method for forwarding access requests provided in an embodiment of the present application;
[0035] Figure 4 A method for forwarding access requests provided in an embodiment of the present application;
[0036] Figure 5 A schematic diagram of the structure of an access request forwarding device provided in an embodiment of the present application;
[0037] Figure 6 A schematic structural diagram of another access request forwarding device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0038] With the continuous development of internet technology, information dissemination has become more convenient and the speed of information updates has also been accelerating. Taking banks as an example, the amount of information that needs to be released across their online systems and offline branches is increasing, and banks are also placing increasing demands on the frequency and timeliness of information updates.
[0039] When information changes, such as the URL link, published information content, information validity, etc., it is necessary to republish the entrance to access the information, or jump the link at the originally published access entrance to jump to the updated information access link.
[0040] When information changes, whether it is re-publishing the access information entrance or jumping the link to the originally published access entrance, the configuration information change process is cumbersome, resulting in inefficient access to the business system.
[0041] In view of this, the present application proposes an access request processing method and device, which converts and encapsulates the target access address and then forwards it to the target business system. On the one hand, when the access target system changes, the modification content required for the target business system due to the change is reduced, and dynamic switching of access requests is realized; on the other hand, by forwarding access control, the access request forwarding system can undertake the security control, message encryption and decryption processing, access permission verification, access data statistics and other public functions of each business system, reduce the processing pressure of the business system, and realize centralized control of access request security and access entrances.
[0042] The following will be combined with the accompanying drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of this application, not all of the embodiments. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0043] See also Figure 1 , Figure 1 A schematic diagram of the interaction between a user terminal and a business system provided in an embodiment of the present application.
[0044] Figure 1 The process of interaction between multiple user terminals and multiple business systems is shown. This application supports request forwarding modes between user terminals and business systems, including sending messages and page jumps.
[0045] Taking the request forwarding mode between the user terminal and the business system as page jump as an example, when the user terminal needs to send the request mode of page jump to the corresponding business system, the access request forwarding system will perform operations such as message encryption and decryption, user authority verification, data message format and message parameter conversion, and assemble the page request to jump to the corresponding business system according to the requirements of the business system.
[0046] Taking the request forwarding mode between the user terminal and the business system as sending messages as an example, when the user terminal sends the request mode of sending messages to the corresponding business system, it sends a request to the access request forwarding system. After the access request forwarding system performs operations such as message encryption and decryption, user authority verification, data message format and message parameter conversion, it assembles the message request according to the requirements of the business system and forwards it to the corresponding business system.
[0047] See also Figure 2 , Figure 2 An access request processing method provided in an embodiment of the present application includes the following steps:
[0048] S201: In response to an access request to a business system, obtain access parameters in the access request.
[0049] When a user terminal initiates an access request to a business system, the access request processing module obtains access parameters in the access request, where the access parameters include a unique access primary key.
[0050] Parameter configuration is required for the link to be released. The link to be released is the access medium for accessing the business system. When configuring the parameters of the link to be released, a unique access master key will be generated. The configured parameters include but are not limited to the unique access master key, validity period, target address for accessing the business system, access count limit, access channel limit, access user permission settings, access IP address settings, encryption method, encryption and decryption keys, channel number, message format, forwarding mode, etc.; the unique access master key can correspond to different valid time periods, each time period can be associated with a different access target address, and each access address has parameters such as access count limit, access channel limit, access user permission settings, access IP address settings, encryption method, encryption and decryption keys, channel number, message format, forwarding mode, etc.
[0051] S202: Query configuration information corresponding to the access parameter; the configuration information at least includes an access address parameter and access parameter authority of the business system corresponding to the access parameter.
[0052] After receiving the request, the access request processing module queries the corresponding configuration parameters in the parameter configuration module based on the unique access primary key in the access request. The parameter configuration module verifies the access permission of the access request, searches for the valid request configuration information corresponding to the access parameters in the access request based on the current time, and sends the processing result to the request forwarding module. The processing result includes request failure or success, prompt information, and target jump address; the target jump address parameter adds a globally unique number Token value parameter to mark the uniqueness of this request.
[0053] S203: Send the access request to the business system according to the access address parameter of the business system included in the configuration information, so as to access the business system.
[0054] The request forwarding module performs corresponding processing based on the processing result of the access request processing module: if the access request processing fails, relevant failure information is prompted and the process ends; if the access request processing is successful, it is forwarded to the business system according to the jump address in the processing result so as to access the business system.
[0055] An embodiment of the present application provides an access request processing method. When executing the method, in response to an access request to a business system, the access parameters in the access request are obtained; then the configuration information corresponding to the access parameters is queried; the configuration information at least includes the access address parameters and access parameter permissions of the business system corresponding to the access parameters; then, based on the access address parameters of the business system contained in the configuration information, the access request is sent to the business system in order to access the business system. By obtaining the access parameters in the access request, querying the access address parameters of the business system corresponding to the access parameters based on the access parameters, and then sending the access request to the business system, it is achieved that when the access address of the business system changes, only the configuration information needs to be changed to complete the access to the business system, which simplifies the configuration information change process and improves the efficiency of access to the business system.
[0056] Furthermore, an optional embodiment of the present application may also store the access parameters in the access request, the configuration information corresponding to the access parameters, and the historical record of accesses to the business system. For example, the request forwarding module may feed back the request redirection result to the data storage module, which will record the success and failure data of the access request and notify the parameter configuration module; the parameter configuration module will record the globally unique token value of the current request, as well as information such as whether the corresponding access request data is encrypted or decrypted, user identity information, access rights, number of access verifications, number of successful accesses, and number of failed accesses.
[0057] Furthermore, in an optional embodiment of the present application, before accessing the business system, the business system may also use the globally unique identifier to verify the access parameters in the access request. For example, the business system may query the data storage module in real time via an API interface by sending the globally unique identifier Token value of the target redirect address. The query includes but is not limited to user identity, access rights, access uniqueness, and anti-tampering verification. After the redirect is successful, the user terminal can access the business system.
[0058] See also Figure 3 , Figure 3 A method for forwarding an access request provided in an embodiment of the present application is implemented by redirecting a page access request, and mainly includes the following steps:
[0059] Step 1. The access parameter configuration module configures the parameters of the link to be published to form a unique access primary key. The configured parameters include but are not limited to the unique access primary key, validity period, access target address, access number limit, access channel limit, access user authority setting, access IP address setting, encryption method, encryption and decryption keys, channel number, message format, forwarding mode, etc.; the unique access primary key can correspond to different valid time periods, each time period can correspond to a different access target address, and each access address has parameters such as access number limit, access channel limit, access user authority setting, access IP address setting, encryption method, encryption and decryption keys, channel number, message format, forwarding mode, etc.
[0060] Step 2: The user requests access to the request processing module, wherein the request link or request parameter carries a unique access primary key.
[0061] Step 3. After receiving the request, the access request processing module queries the corresponding configuration parameters in the parameter configuration module based on the unique access primary key of the request. The parameter configuration module verifies the access permission of the request, searches for the valid request configuration information corresponding to the access request based on the current time, and sends the processing result to the request forwarding module. The processing result includes request failure or success, prompt information, and target jump address; the target jump address parameter adds a globally unique number Token value parameter to mark the uniqueness of this request.
[0062] Step 4. The request forwarding module performs corresponding processing according to the processing result of the access request processing module: if the access request processing fails, the relevant failure information is prompted and the process ends; if the access request processing is successful, it is forwarded to the business system according to the jump address in the processing result; the request forwarding module feeds back the request jump result to the data storage module, the data storage module records the data of successful and failed access requests, and notifies the parameter configuration module; the parameter configuration module records the globally unique number Token value of the current request and whether the corresponding access request data is encrypted or decrypted, user identity information, access rights, number of access verifications, number of successful accesses, number of access failures, and other information.
[0063] Step 5. The business system can query in real time through the API interface by sending the globally unique number Token value of the target jump address to the data storage module. The query includes but is not limited to user identity, access rights, access uniqueness, and anti-tampering verification; after the jump is successful, the user end performs operations and feedback on the results through the interactive page of the business system.
[0064] See also Figure 4 , Figure 4An access request forwarding method provided in an embodiment of the present application is implemented by forwarding a request message and processing a message return, and mainly includes the following steps:
[0065] Step 1. The access parameter configuration module configures the parameters of the link to be published to form a unique access primary key. The configured parameters include but are not limited to the unique access primary key, validity period, access target address, access number limit, access channel limit, access user authority setting, access IP address setting, encryption method, encryption and decryption keys, channel number, message format, forwarding mode, etc.; the unique access primary key can correspond to different valid time periods, each time period can correspond to a different access target address, and each access address has parameters such as access number limit, access channel limit, access user authority setting, access IP address setting, encryption method, encryption and decryption keys, channel number, message format, forwarding mode, etc.
[0066] Step 2: The user requests access to the request processing module, wherein the request link or request parameter carries a unique access primary key.
[0067] Step 3. After receiving the request, the access request processing module queries the corresponding configuration parameters in the parameter configuration module based on the unique access primary key of the request. The parameter configuration module verifies the access permission of the request, searches for the valid request configuration information corresponding to the access request based on the current time, and sends the processing result to the request forwarding module. The processing result includes request failure or success, prompt information, and target jump address; the target jump address parameter adds a globally unique number Token value parameter to mark the uniqueness of this request.
[0068] Step 4. The request forwarding module performs corresponding processing according to the processing result of the access request processing module: if the access request processing fails, the relevant failure information is prompted and the process ends; if the access request processing is successful, it is forwarded to the business system according to the jump address in the processing result; the request forwarding module feeds back the request jump result to the data storage module, the data storage module records and stores the data of successful and failed access requests, and notifies the parameter configuration module; the parameter configuration module records the global unique number Token value of the current request and whether the corresponding access request data is encrypted or decrypted, user identity information, access rights, number of access verifications, number of successful accesses, number of access failures, and other information.
[0069] Step 5. The business system can query in real time by sending the globally unique number Token value of the target jump address to the data storage module through the API interface. The query includes but is not limited to user identity, access rights, access uniqueness, and anti-tampering verification; after forming the business processing result, the business system returns the request processing result message to the request forwarding module.
[0070] Step 6: After receiving the request message returned by the business system, the request forwarding module decrypts the message format, parses the message format, assembles application parameters, verifies data, and then returns the message processing result to the access request processing module.
[0071] Step 7: The access request processing module desensitizes the message parameters, performs data dictionary verification, assembles the message format, securely encrypts, and encapsulates the processing results according to the parameters configured by the parameter configuration module to form a message processing result.
[0072] Step 8: The request processing module returns the message processing result to the requesting user.
[0073] The above are some specific implementations of a method for processing an access request provided by the embodiment of the present application. Based on this, the present application also provides a corresponding device. The device provided by the embodiment of the present application will be introduced below from the perspective of functional modularization.
[0074] See also Figure 5 , Figure 5 A schematic diagram of the structure of an access request forwarding device provided in an embodiment of the present application, the device comprising: an access request processing module 501, a parameter configuration module 502, and a request forwarding module 503;
[0075] The access request processing module 501 is used to respond to an access request to a business system and obtain access parameters in the access request;
[0076] The parameter configuration module 502 is used to query the configuration information corresponding to the access parameter; the configuration information at least includes the access address parameter and access parameter authority of the business system corresponding to the access parameter;
[0077] The request forwarding module 503 is configured to send the access request to the business system according to the access address parameter of the business system included in the configuration information, so as to access the business system.
[0078] An embodiment of the present application provides an access request processing device for executing a corresponding method. When executing the method, in response to an access request to a business system, the access parameters in the access request are obtained; then the configuration information corresponding to the access parameters is queried; the configuration information at least includes the access address parameters and access parameter permissions of the business system corresponding to the access parameters; and then, based on the access address parameters of the business system contained in the configuration information, the access request is sent to the business system in order to access the business system. By obtaining the access parameters in the access request, querying the access address parameters of the business system corresponding to the access parameters based on the access parameters, and then sending the access request to the business system, it is achieved that when the access address of the business system changes, only the configuration information needs to be changed to complete the access to the business system, which simplifies the configuration information change process and improves the efficiency of access to the business system.
[0079] See also Figure 6 , Figure 6 This is a schematic diagram of the structure of an access request forwarding device provided in an embodiment of the present application. The device also includes a data storage module 504. The data storage module 504 is specifically configured to:
[0080] The access parameters in the access request, configuration information corresponding to the access parameters, and a history record of access to the business system are stored.
[0081] Furthermore, in an optional embodiment of the present application, the parameter configuration module 502 is further configured to:
[0082] Before sending the access request to the business system, a globally unique number value is added to the access address parameter of the business system corresponding to the access parameter, where the globally unique number value is used to characterize the uniqueness of the access request to the business system.
[0083] Furthermore, in an optional embodiment of the present application, before accessing the business system, the data storage module 504 is further configured to:
[0084] The access parameter in the access request is verified using the globally unique number value.
[0085] Furthermore, in an optional embodiment of the present application, before obtaining access parameters in the access request in response to the access request to the business system, the parameter configuration module 502 is further configured to:
[0086] Parameter configuration is performed on the access medium used to access the business system, and the parameters include at least the validity period of the access medium, the target address for accessing the business system, the number of access restrictions, the access channel restrictions, the access user authority settings, the access IP address settings, the encryption method, the encryption key, the decryption key, the channel number, the message format and the request forwarding mode.
[0087] Through the description of the above embodiments, it can be known that those skilled in the art can clearly understand that all or part of the steps in the above embodiment methods can be implemented by means of software plus a general hardware platform. Based on this understanding, the technical solution of the present application can be embodied in the form of a software product, which can be stored in a storage medium, such as a read-only memory (ROM) / RAM, a magnetic disk, an optical disk, etc., and includes a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network communication device such as a router) to execute the methods described in each embodiment or certain parts of the embodiments of the present application.
[0088] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For the relevant parts, refer to the partial description of the method embodiment. Some or all of the modules can be selected according to actual needs to achieve the purpose of the embodiment. Those of ordinary skill in the art can understand and implement it without paying any creative work.
[0089] The above description is merely an exemplary embodiment of the present application and is not intended to limit the scope of protection of the present application.
Claims
1. A method for processing an access request, characterized in that: The method comprises: In response to an access request to a business system, obtaining access parameters in the access request; the access parameters are obtained by configuring parameters of an access medium used to access the business system; the access parameters include a unique access primary key, the unique access primary key corresponds to different valid time periods, and each valid time period is associated with a different access target address; Based on the current time, query the configuration information corresponding to the unique access primary key; the configuration information at least includes the access address parameter and access parameter authority of the business system corresponding to the access parameter; According to the access address parameters of the business system included in the configuration information, the access request is sent to the business system, so as to access the business system.
2. The method according to claim 1, characterized in that The method further comprises: The access parameters in the access request, the configuration information corresponding to the unique access primary key, and the historical records of access to the business system are stored.
3. The method according to claim 1, characterized in that Before sending the access request to the business system, the method further includes: A globally unique number value is added to the access address parameter of the business system corresponding to the access parameter, where the globally unique number value is used to characterize the uniqueness of the access request to the business system.
4. The method according to claim 3, characterized in that Before accessing the business system, the method further includes: The access parameter in the access request is verified using the globally unique number value.
5. The method according to claim 1, wherein Before obtaining the access parameters in the access request in response to the access request to the business system, the method further includes: Parameter configuration is performed on the access medium used to access the business system, and the parameters include at least the validity period of the access medium, the target address for accessing the business system, the number of access restrictions, the access channel restrictions, the access user authority settings, the access IP address settings, the encryption method, the encryption key, the decryption key, the channel number, the message format and the request forwarding mode.
6. An access request processing device, characterized in that: The device includes: an access request processing module, a parameter configuration module, and a request forwarding module; The access request processing module is configured to respond to an access request to a business system and obtain access parameters in the access request; the access parameters are obtained by configuring parameters of an access medium used to access the business system; the access parameters include a unique access primary key, the unique access primary key corresponding to different valid time periods, and each valid time period is associated with a different access target address; The parameter configuration module is used to query the configuration information corresponding to the unique access primary key based on the current time; the configuration information at least includes the access address parameter and access parameter authority of the business system corresponding to the access parameter; The request forwarding module is configured to send the access request to the business system according to the access address parameter of the business system included in the configuration information, so as to access the business system.
7. The device according to claim 6, characterized in that The device further includes a data storage module, which is specifically configured to: The access parameters in the access request, the configuration information corresponding to the unique access primary key, and the historical records of access to the business system are stored.
8. The device according to claim 7, characterized in that The parameter configuration module is also used for: Before sending the access request to the business system, a globally unique number value is added to the access address parameter of the business system corresponding to the access parameter, where the globally unique number value is used to characterize the uniqueness of the access request to the business system.
9. The device according to claim 8, characterized in that Before accessing the business system, the data storage module is further used to: The access parameter in the access request is verified using the globally unique number value.
10. The device according to claim 6, characterized in that Before obtaining the access parameters in the access request in response to the access request to the business system, the parameter configuration module is further configured to: Parameter configuration is performed on the access medium used to access the business system, and the parameters include at least the validity period of the access medium, the target address for accessing the business system, the number of access restrictions, the access channel restrictions, the access user authority settings, the access IP address settings, the encryption method, the encryption key, the decryption key, the channel number, the message format and the request forwarding mode.
Citation Information
Patent Citations
Service addressing access method, device and system, equipment and medium
CN112261172A