Server-oriented communication methods, communication systems, communication devices and electronic equipment

By using session identification and authentication information through an intermediate server, a communication connection between the client and the target server is indirectly established, which solves the problem that the client cannot communicate directly with the target server, reduces operation and maintenance costs, and improves communication efficiency and security.

CN116015770BActive Publication Date: 2025-12-02BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211589163.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-09
Publication Date
2025-12-02
Estimated Expiration
2042-12-09

AI Technical Summary

Technical Problem

In existing technologies, clients cannot directly establish communication connections with target servers, especially when the target server has not granted communication permissions, resulting in a large workload for network maintenance and high communication costs.

Method used

By using an intermediate server as a medium, and utilizing session identification information and authentication information, a communication connection between the client and the target server is indirectly established. This includes determining the session identification information and generating authentication information, using Kerberos authentication for authentication, and adapting the database connection protocol to the target server's computing engine.

Benefits of technology

It reduces network maintenance workload and communication costs, improves communication efficiency and security between clients and target servers, and expands the application scope of clients.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116015770B_ABST
    Figure CN116015770B_ABST
Patent Text Reader

Abstract

This disclosure provides a server-oriented communication method, communication system, communication device, electronic device, and storage medium, relating to the field of artificial intelligence technology, particularly cloud computing, big data, and public cloud technologies, and applicable to intelligent cloud scenarios. The specific implementation scheme is as follows: In response to receiving a first access request from a client, session identification information and access information are determined based on the first access request, wherein the first access request is used to request access to the target server; based on the session identification information, authentication information for accessing the target server is determined; and based on the authentication information and access information, a second access request is sent to the target server.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This disclosure relates to the field of artificial intelligence technology, and in particular to cloud computing, big data, and public cloud technologies, applicable to intelligent cloud scenarios. Specifically, it relates to server-oriented communication methods, communication systems, communication devices, electronic devices, storage media, and program products. Background Technology

[0002] With the development of information technology, network communication has attracted increasing attention due to its advantages such as service interconnection and data openness and sharing. The synergistic improvement of the intelligence, efficiency, and security of network communication has become a key research focus. Summary of the Invention

[0003] This disclosure provides a server-oriented communication method, communication system, apparatus, electronic device, storage medium, and program product.

[0004] According to one aspect of this disclosure, a communication method is provided, comprising: responding to receiving a first access request from a client, determining session identification information and access information based on the first access request, wherein the first access request is used to request access to a target server; determining authentication information for accessing the target server based on the session identification information; and sending a second access request to the target server based on the authentication information and the access information.

[0005] According to another aspect of this disclosure, a communication method is provided, comprising: sending a first access request to an intermediate server, wherein the first access request is used to request access to a target server, so that the intermediate server determines session identification information and access information based on the first access request, determines authentication information for accessing the target server based on the session identification information, and generates a second access request for accessing the target server based on the authentication information and the access information.

[0006] According to another aspect of this disclosure, a communication system is provided, comprising: a client for sending a first access request to an intermediate server, wherein the first access request is for requesting access to a target server; and an intermediate server for receiving the first access request from the client, determining session identification information and access information based on the first access request, determining authentication information for accessing the target server based on the session identification information, and sending a second access request to the target server based on the authentication information and the access information.

[0007] According to another aspect of this disclosure, a communication apparatus is provided, comprising: a first access module, configured to, in response to receiving a first access request from a client, determine session identification information and access information based on the first access request, wherein the first access request is used to request access to a target server; a first determination module, configured to, based on the session identification information, determine authentication information for accessing the target server; and a second access module, configured to, based on the authentication information and the access information, send a second access request to the target server.

[0008] According to another aspect of this disclosure, a communication apparatus is provided, comprising: a second sending module, configured to send a first access request to an intermediate server, wherein the first access request is used to request access to a target server, so that the intermediate server determines session identification information and access information based on the first access request, determines authentication information for accessing the target server based on the session identification information, and generates a second access request for accessing the target server based on the authentication information and the access information.

[0009] According to another aspect of this disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the method as disclosed herein.

[0010] According to another aspect of this disclosure, a non-transitory computer-readable storage medium is provided storing computer instructions, wherein the computer instructions are used to cause the computer to perform the methods as disclosed herein.

[0011] According to another aspect of this disclosure, a computer program product is provided, including a computer program that, when executed by a processor, implements the method as disclosed herein.

[0012] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of this disclosure, nor is it intended to limit the scope of this disclosure. Other features of this disclosure will become readily apparent from the following description. Attached Figure Description

[0013] The accompanying drawings are provided to better understand this solution and do not constitute a limitation of this disclosure. Wherein:

[0014] Figure 1 This illustration schematically shows an exemplary system architecture to which communication methods and apparatus can be applied according to embodiments of the present disclosure;

[0015] Figure 2A flowchart illustrating a communication method according to an embodiment of the present disclosure, applied to an intermediate server, is shown schematically.

[0016] Figure 3 A schematic flowchart of a communication method according to an embodiment of the present disclosure is shown.

[0017] Figure 4 A signaling diagram of a communication method according to an embodiment of the present disclosure is illustrated schematically;

[0018] Figure 5 A flowchart illustrating a communication method according to an embodiment of the present disclosure, applied to a client, is shown schematically.

[0019] Figure 6 A block diagram of a communication device according to an embodiment of the present disclosure is illustrated, applied to an intermediate server;

[0020] Figure 7 A block diagram of a communication device according to an embodiment of the present disclosure is illustrated, applied to a client; and

[0021] Figure 8 A block diagram of an electronic device suitable for implementing a communication method according to an embodiment of the present disclosure is shown schematically. Detailed Implementation

[0022] The exemplary embodiments of this disclosure are described below with reference to the accompanying drawings, including various details of the embodiments to aid understanding, and should be considered merely exemplary. Therefore, those skilled in the art will recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Similarly, for clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.

[0023] In the technical solution disclosed herein, the collection, storage, use, processing, transmission, provision, disclosure, and application of user personal information comply with the provisions of relevant laws and regulations, necessary confidentiality measures have been taken, and there is no violation of public order and good morals.

[0024] In the technical solution disclosed herein, the user's authorization or consent is obtained before acquiring or collecting the user's personal information.

[0025] This disclosure provides a server-oriented communication method, communication system, apparatus, electronic device, storage medium, and program product.

[0026] According to embodiments of this disclosure, a communication method is provided, comprising: responding to receiving a first access request from a client, determining session identification information and access information based on the first access request, wherein the first access request is used to request access to a target server; determining authentication information for accessing the target server based on the session identification information; and sending a second access request to the target server based on the authentication information and the access information.

[0027] According to another embodiment of this disclosure, a communication system is provided, comprising: a client, configured to send a first access request to an intermediate server, wherein the first access request is used to request access to a target server; and an intermediate server, configured to receive the first access request from the client, determine session identification information and access information based on the first access request, determine authentication information for accessing the target server based on the session identification information, and send a second access request to the target server based on the authentication information and access information.

[0028] Figure 1 The illustration schematically depicts an exemplary system architecture to which communication methods and apparatus can be applied according to embodiments of the present disclosure.

[0029] It is important to note that Figure 1 The examples shown are merely examples of system architectures that can be applied to the embodiments of this disclosure, in order to help those skilled in the art understand the technical content of this disclosure, but do not mean that the embodiments of this disclosure cannot be used in other devices, systems, environments or scenarios.

[0030] like Figure 1 As shown, the system architecture 100 according to this embodiment may include a communication system 101, a network 102, an authentication service center 103, and a server cluster 104. The network 102 serves as a medium for providing communication links between the communication system 101, the authentication service center 103, and the server cluster 104. The network 103 may include various connection types, such as wired and / or wireless communication links, etc.

[0031] The communication system 101 includes a client 1011 and an intermediate server 1012. Users can send a first access request to the intermediate server 1012 through the client 1011, and can also receive target data from the intermediate server 1012 through the client 1011.

[0032] Various communication client applications can be installed on the 1011 client, such as knowledge reading applications, web browser applications, search applications, instant messaging tools, email clients and / or social platform software, etc. (for example only).

[0033] Client 1011 can be any electronic device with a display screen and web browsing support, including but not limited to smartphones, tablets, laptops, and desktop computers.

[0034] Intermediate server 1012 can be used to receive a first access request from client 1011, determine session identification information and access information based on the first access request, determine authentication information for accessing any server cluster node in server cluster 104, such as target server 1041, based on the session identification information, and send a second access request to target server 1041 based on the authentication information and access information, receive target data from target server 1041 for the second access request, and send the target data to client 1011.

[0035] The authentication service center 103 can be a KDC (Key Distribution Center). The authentication service center may include two independent servers, such as an authentication server (AS) and a ticket granting server (TGS). Communication authentication between client 1011 and target server 1041 can be completed through the authentication service center 103.

[0036] The target server 1041 may be a server that provides various services, such as a backend management server that supports the second access request sent by the intermediate server 1012 (for example only).

[0037] The target server 1041 can be a node in the server cluster 104. The server cluster can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system. It solves the shortcomings of traditional physical hosts and VPS services ("Virtual Private Server", or simply "VPS"), such as high management difficulty and weak business scalability. The server can also be a server in a distributed system, or a server combined with blockchain.

[0038] It should be understood that Figure 1 The number of clients, intermediate servers, network nodes, and server cluster nodes shown in the diagram is merely illustrative. Depending on implementation requirements, there can be any number of clients, network nodes, and server cluster nodes.

[0039] It should be noted that the sequence numbers of the operations in the following methods are for descriptive purposes only and should not be considered as indicating the execution order of the operations. Unless explicitly stated otherwise, the method does not need to be executed in the exact order shown.

[0040] Figure 2 A flowchart illustrating a communication method according to an embodiment of the present disclosure is shown schematically.

[0041] like Figure 2 As shown, the method includes operations S210 to S230.

[0042] In operation S210, in response to receiving a first access request from the client, session identification information and access information are determined based on the first access request.

[0043] In operation S220, authentication information for accessing the target server is determined based on session identification information.

[0044] In operation S230, a second access request is sent to the target server based on authentication and access information.

[0045] According to embodiments of this disclosure, such as Figure 2 The communication method shown can be applied to an intermediate server. For the client, the intermediate server grants the client communication permissions, while the target server does not. The client uses the intermediate server to establish a communication connection with the target server.

[0046] According to embodiments of this disclosure, the first access request may be a request sent to an intermediate server, and the first access request is used to request access to the target server.

[0047] According to embodiments of this disclosure, the target server can be a server requested for access by a client. The target server can be a node in a server cluster. The server cluster can be, for example, a Hadoop data cluster. For core business information, client access operations can generally be managed through internet isolation. For example, if a client does not have the communication permissions granted by the target server, network isolation can prevent the client from accessing the target server.

[0048] According to embodiments of this disclosure, an intermediate server can determine session identification information and access information based on a first access request. For example, field matching rules can be used to determine the session identification information and access information based on the first access request. Taking session identification information as an example, the session identification information may be located in a fixed field position in the first access request, and the session identification information can be determined from the first access request based on field position matching rules. Alternatively, the session identification information may include predetermined field information, such as client identity identifiers like ID information or QR code identifiers, etc. The predetermined field information can be matched with the content in the first access request, and the field in the first access request that matches the predetermined field information is determined as the session identification information.

[0049] According to embodiments of this disclosure, the session identification information can be client identification information used to identify the client. For example, the session identification information is identification information that an intermediate server can recognize and authenticate. However, it is not limited to this. The session identification information may also include client identification information and communication key information. This communication key information can be used to implement encrypted transmission of information between the client and the target server, thereby ensuring the security of information transmission.

[0050] According to embodiments of this disclosure, access information is related to accessing a target server. Access information can be information related to reading data, but is not limited to this; it can also be information related to writing data, or information related to processing data. For example, access information can be one or more of the following: data extraction, transformation, loading, storage, and querying. Any information related to accessing data is acceptable.

[0051] According to embodiments of this disclosure, authentication information can refer to authentication information used to identify a client. For example, authentication information can be identification information that the target server can recognize and authenticate. However, it is not limited to this. Authentication information may also include client identification information and authentication key information. The information type of the client identification information in the authentication information can be the same as or different from the information type of the client identification information in the session identification information, as long as it is identification information that can be recognized and authenticated by the target server. The authentication key information can be used to implement encrypted transmission of information between the intermediate server and the target server, thereby ensuring the security of information transmission. The encryption type of the authentication key information can be the same as or different from the encryption type of the communication key information, as long as it can encrypt the information and ensure secure transmission of the information.

[0052] According to embodiments of this disclosure, a second access request is sent to the target server based on authentication information and access information. This allows the target server to authenticate the legitimacy of the second access request based on the authentication information. If the authentication information is deemed legitimate, the legitimacy of the second access request is determined, and further processing can be determined based on the access information, utilizing an intermediate server to complete the communication operation between the client and the target server.

[0053] Based on relevant examples, if it is determined that the target server does not have communication permissions granted to the client, network maintenance personnel can implement network maintenance engineering to open the communication connection between the client and the target server.

[0054] Compared with directly establishing a communication connection between the client and the target server, the communication method provided in this disclosure can indirectly establish a communication connection between the client and the target server using an intermediate server, thereby avoiding network maintenance and reducing workload and communication costs.

[0055] According to embodiments of this disclosure, when performing such Figure 2 Prior to the operation S210 shown, the communication method may also include the following communication authentication operation between the client and the target server.

[0056] For example, the system receives an authentication request from the client. This request, which requests authentication for establishing communication between the client and the target server, includes the client's identification information and authentication file. The authentication request is then sent to the authentication service center, which authenticates the client based on the client's identification information and authentication file. The system also receives authentication information from the authentication service center. Finally, session identification information matching the authentication information is sent to the client, completing the communication authentication between the client and the target server.

[0057] It should be noted that the aforementioned communication authentication operation between the client and the target server can be performed before the client first accesses the target server using the intermediate server. After communication authentication is completed, the client can directly use the authentication information to access the target server through the intermediate server within a predetermined time period. If the predetermined time period is exceeded, the communication authentication operation needs to be performed again.

[0058] According to embodiments of this disclosure, communication authentication between the client and the target server can be Kerberos (Computer Network Authorization Protocol) authentication. An authentication service center can be used to complete the communication authentication between the client and the target server. The authentication service center can be a KDC (Key Distribution Center). The authentication service center may include two independent servers, such as an authentication server (AS) and a ticket granting server (TGS).

[0059] According to embodiments of this disclosure, sending an authentication request to an authentication service center so that the authentication service center can authenticate the client based on the client's client identification information and authentication file may include: an intermediate server sending the authentication request to the authentication server of the authentication service center, so that the authentication server sends a Tick Granting Ticket (TGT) to the intermediate server based on the client's client identification information and authentication file; and the intermediate server sending the received TGT to the Tick Granting Server, so that the TGT sends a Service Ticket (ST) to the intermediate server.

[0060] According to embodiments of this disclosure, client identification information may include an authentication principal identifier (Principa1). The authentication file may be a key file (e.g., a Keytab file) generated based on the client identification information.

[0061] According to embodiments of this disclosure, the authentication information received by the intermediate server from the authentication service center may be a service ticket. This authentication information can be used as a security key to access the target server.

[0062] According to relevant examples, a client can generate a direct authentication request to be sent to the authentication service center based on its client identification information and authentication file. The authentication service center then uses this direct authentication request to determine the client identification information and authentication file. Based on the client identification information and authentication file, it authenticates the client. If the authentication result is correct, it sends authentication information to the client.

[0063] Compared to the client directly sending a direct authentication request to the authentication service center to complete the authentication, the communication authentication between the client and the target server through an intermediate server provided in this embodiment of the disclosure can be completed indirectly by using an intermediate server to achieve a communication connection between the client and the authentication service center even when the client does not have the communication permissions granted by the authentication service center. This breaks down network isolation and permission isolation through the intermediate server, avoids additional network configuration, and thus improves the application scope of the client.

[0064] According to embodiments of this disclosure, a database connection protocol, such as Java Database Connectivity, can be deployed on the client. A database connection protocol can also be deployed on an intermediate server.

[0065] According to embodiments of this disclosure, the target server can be a server cluster node. The server cluster may be, for example, a Hadoop data cluster. Multiple computing engines of different types can be deployed on the server cluster node. All of these different computing engines support access via database connection protocols.

[0066] According to embodiments of this disclosure, deploying a database connection protocol on the client can be adapted to the computing engine deployed in the target server, thereby reducing access difficulty.

[0067] According to embodiments of this disclosure, for application scenarios where the target server is a server cluster node, Kerberos authentication can be used to establish communication authentication between the target server and the client. Kerberos authentication offers high versatility and wide applicability.

[0068] Figure 3 A schematic flowchart of a communication method according to an embodiment of the present disclosure is shown.

[0069] like Figure 3 As shown, if client 310 does not have communication permissions with authentication access center 320, such as the operation indicated by mark 1, client 310 can send an authentication request to intermediate server 330. The authentication request includes client identification information and an authentication file, such as a Keytab file.

[0070] like Figure 3 As shown in Figure 2, the intermediate server 330 sends the authentication request to the authentication service center 320.

[0071] like Figure 3 As shown, in response to receiving the authentication request, the authentication service center 320 performs identity authentication on the client 310 based on the client identification information and authentication file in the authentication request.

[0072] like Figure 3 As shown in Figure 3, if the authentication of the client 310 is confirmed to be successful, the authentication service center 320 will send the authentication information to the intermediate server 330.

[0073] like Figure 3 As shown in Figure 4, the intermediate server 330 sends the session identifier information that matches the authentication information to the client 310, thus completing the communication authentication between the client 310 and the target server 340.

[0074] like Figure 3 As shown in Figure 5, when the client 310 receives the session identifier information, it can send a first access request to the intermediate server 330.

[0075] like Figure 3 As shown, intermediate server 330 receives a first access request from client 310. In response to receiving the first access request, it determines session identification information and access information based on the access request. Based on the session identification information, it determines authentication information for accessing target server 340. As shown in operation 7, based on the authentication information and access information, it sends a second access request to target server 340.

[0076] like Figure 3 As shown in Figure 7, the intermediate server 330 receives target data from the target server 340 in response to the second access request.

[0077] like Figure 3 As shown in Figure 5, the intermediate server 330 sends the target data to the client 310.

[0078] According to embodiments of this disclosure, an intermediate server can be used to indirectly connect the communication permissions between the client and the authentication service center, enabling communication authentication between the client and the target server, and also enabling data transmission between the client and the target server, thereby improving the scope of business processing while ensuring the security of data transmission.

[0079] According to embodiments of this disclosure, before receiving a first access request from a client, the communication method of the intermediate server may include: receiving encrypted information from the client; and decoding the encrypted information according to a secure transmission protocol to obtain the first access request.

[0080] According to embodiments of this disclosure, the secure transport protocol may be Transport Layer Security (TLS), but it is not limited to this; it may also be Transmission Control Protocol (TCP) or User Datagram Protocol (UDP), etc. Any protocol capable of enabling encrypted transmission between the intermediate server and the client is acceptable.

[0081] like Figure 3 As shown, the authentication file can be obtained in the following ways. For example, client 310 obtains the authentication file from shared database 350. This authentication file may be stored in shared database 350 by other clients 360 in the same area network that can communicate with authentication service center 320.

[0082] According to embodiments of this disclosure, the authentication file, such as a Keytab file, can be a file issued by an authentication service center that serves as a regional identifier. It can be an authentication file shared by multiple clients.

[0083] According to embodiments of this disclosure, the intermediate server can directly send a second access request to the target server based on authentication information and access information. However, it is not limited to this. Figure 3As shown in Figure 6, the intermediate server 330 can also send a temporary authentication request to the authentication service center 320 based on authentication information and access information. The access type can be determined based on the access information in the temporary authentication request. For example, the access type related to querying data or the access type related to storing data. This allows the authentication service center 320 to send temporary authentication information indicating the access type to the intermediate server 330 based on the authentication information and access information in the temporary authentication request. The intermediate server 330 can then selectively access the target server 340 based on the temporary authentication information and access information.

[0084] Based on relevant examples, the intermediate server can directly send authentication information to the client to complete the communication authentication between the client and the target server. This allows the client to generate an initial access request based on the authentication and access information.

[0085] Compared to the method of directly including authentication information in the first access request, the method provided in this disclosure sends session identification information that matches the authentication information to the client. This enables the client to generate the first access request based on the session identification information and access information, thereby avoiding the use of large amounts of authentication information for information transmission between the client and the intermediate server. This allows for the use of small amounts of session identification information for transmission, ensuring information transmission security while improving transmission efficiency.

[0086] According to embodiments of this disclosure, before sending session identification information that matches the authentication information to the client, the communication method may further include the following operations.

[0087] For example, generate session identifier information that matches the authentication information. Based on the authentication information, session identifier information, and the client's client identifier information, update the authentication identifier mapping table.

[0088] According to embodiments of this disclosure, an authentication identifier mapping table is used to represent the mapping relationship between authentication information, session identifier information, and client identifier information of the client.

[0089] According to embodiments of this disclosure, the intermediate server can directly store information representing the mapping relationship between authentication information, session identification information, and client identification information in a cache. However, it is not limited to this. An authentication identification mapping table can also be established and stored in the cache. Updating the authentication identification mapping table can include adding information representing the mapping relationship between authentication information, session identification information, and client identification information to the authentication identification mapping table.

[0090] According to embodiments of this disclosure, determining authentication information for accessing a target server based on session identifier information may include: determining authentication information for accessing the target server that matches the session identifier information from an authentication information mapping table.

[0091] According to embodiments of this disclosure, an authentication identifier mapping table can be used to quickly match authentication information based on session identifier information. This ensures both transmission security and speed, while also guaranteeing the transmission quality of the intermediate server as a medium, avoiding matching errors caused by information disorder.

[0092] According to embodiments of this disclosure, session identification information can be valid for a long period, but is not limited to this; an expiration period can also be set for the session identification information. If the session identification information is determined to be valid, the operation of determining authentication information for accessing the target server is performed. If the session identification information is determined to be invalid, subsequent operations are stopped to improve processing efficiency. Furthermore, determining authentication information for accessing the target server based on the session identification information may include the following operations.

[0093] For example, based on the generation time of the session identifier information, it can be determined whether the session identifier information is compliant. If the session identifier information is determined to be compliant, the authentication information used to access the target server can be determined based on the session identifier information.

[0094] According to embodiments of this disclosure, determining whether session identification information is compliant based on the generation time information of the session identification information may include: determining whether the session identification information is compliant, for example, whether it is valid, based on the current time information, the generation time information, and the predetermined valid duration. The session duration can be determined based on the current time information and the generation time information. If the session duration is less than or equal to the predetermined valid duration, the session identification information is determined to be compliant. If the session duration is greater than the predetermined valid duration, the session identification information is determined to be non-compliant. A timestamp can be set for the session identification information. For example, the generation time information of the session identification information can be recorded. A session timestamp can be set based on the generation time information. The session duration can be determined using the session timestamp.

[0095] According to embodiments of this disclosure, if the session identification information is determined to be compliant, authentication information for accessing the target server is determined based on the session identification information. If the session identification information is determined to be non-compliant, subsequent operations can be stopped. However, this is not the only option. Feedback information can also be sent to the client so that the client responds to the feedback information and resends the authentication request.

[0096] According to embodiments of this disclosure, the operation of determining whether session identification information is compliant information can be used to achieve verification-free operation within a predetermined session validity period, thereby improving processing efficiency while ensuring security in communication between the client and the intermediate server.

[0097] According to exemplary embodiments of this disclosure, authentication information can be valid indefinitely or set to be valid for a predetermined authentication validity period. The method for determining the compliance of authentication information is similar to the method for determining the compliance of session identifier information. The compliance of authentication information can be determined based on the predetermined authentication validity period. For example, if it is determined that an intermediate server has received authentication information from an authentication service center, the time of receipt is recorded. Based on the current time information and the time of receipt information, the authentication duration is determined. Based on the authentication duration and the predetermined authentication validity period, it is determined whether the authentication information is compliant. If the authentication duration is less than or equal to the predetermined authentication validity period, the authentication information is determined to be compliant. If the authentication duration is determined to be longer than the predetermined authentication validity period, the authentication information is determined to be non-compliant.

[0098] According to embodiments of this disclosure, sending a second access request to a target server based on authentication information and access information may include: if the authentication information is determined to be compliant, sending a second access request to the target server based on the authentication information and identification information; if the authentication information is determined to be non-compliant, stopping the operation or sending feedback information to the client, so that the client responds to the feedback information and sends an authentication request.

[0099] According to embodiments of this disclosure, the operation of determining whether authentication information is compliant information can be used to achieve verification-free operation within a predetermined time period, thereby improving processing efficiency for both intermediate and target servers while ensuring security.

[0100] According to exemplary embodiments of this disclosure, the communication method provided in these embodiments may further include the operation of updating an authentication information mapping table based on the session duration. For example, if the session duration exceeds a predetermined session validity period, the session identifier information is determined to be non-compliant. The authentication information mapping table is then updated by deleting the session identifier information from the authentication information mapping table.

[0101] It should be noted that deleting session identifier information in the authentication information mapping table can refer to deleting session identifier information, authentication information that has a mapping relationship with session identifier information, and client identifier information from the authentication information mapping table.

[0102] According to embodiments of this disclosure, by utilizing the above processing method, it is possible to determine whether the session identifier information is compliant information simultaneously with the operation of determining whether the authentication information is compliant information. This simplifies the process and improves communication efficiency while ensuring the communication security between the client and the intermediate server, and between the intermediate server and the target server.

[0103] Figure 4 A signaling diagram of a communication method according to an embodiment of the present disclosure is illustrated schematically.

[0104] like Figure 4 As shown, the method includes operations S401 to S412.

[0105] When operating S401, the client sends the first access request to the intermediate server.

[0106] In operation S402, the intermediate server responds to receiving the first access request from the client and determines the session identification information and access information based on the first access request.

[0107] In operation S403, the intermediate server determines whether the session identifier information is compliant based on the generation time information of the session identifier information. If the session identifier information is compliant, operations S409 to S412 are executed. If the session identifier information is non-compliant, operations S404 to S408 are executed.

[0108] When operating S404, the intermediate server sends feedback information to the client.

[0109] When operating S405, the client sends an authentication request to the intermediate server.

[0110] When operating S406, the intermediate server sends the authentication request to the authentication service center.

[0111] When operating S407, the authentication service center sends authentication information to the intermediate server.

[0112] When operating S408, session identification information that matches the authentication information is sent to the client.

[0113] According to embodiments of this disclosure, the session identifier information matching the authentication information in operation S408, relative to historical session identifier information (e.g., the session identifier information in operation S402), can refer to new session identifier information. This new session identifier information can refer to information different from historical session identifier information, but is not limited to this; it can also be the same information but with different generation times. The key is that the session identifier information is compliant.

[0114] According to embodiments of this disclosure, if the client holds compliant session identification information, the client can re-execute operation S401 to achieve the task of accessing the target server using an intermediate server.

[0115] When operating S409, the intermediate server determines the authentication information based on the session identifier information.

[0116] When operating S410, the intermediate server sends a second access request to the target server based on access information and authentication information.

[0117] In operation S411, the target server sends target data to the intermediate server.

[0118] When operating S412, the intermediate server sends the target data to the client.

[0119] Figure 5 A flowchart illustrating a communication method according to an embodiment of the present disclosure is shown schematically.

[0120] like Figure 5 As shown, the method includes operations S510 to S520.

[0121] In operation S510, a first access request is sent to the intermediate server. The first access request is used to request access to the target server. The first access request includes session identification information and access information, so that the intermediate server can determine the authentication information for accessing the target server based on the session identification information, and generate a second access request for accessing the target server based on the authentication information and access information.

[0122] In operation S520, target data matching the first access request is received from the intermediate server.

[0123] According to embodiments of this disclosure, the target data is data obtained by the intermediate server from the target server using a second access request.

[0124] It should be noted that, as Figure 5 The communication method shown can be applied to the client. For example... Figure 5 The communication method shown may include only operation S510, but is not limited to this. It may also include operation S510 and operation S520, which can be determined according to the actual situation, and will not be elaborated here.

[0125] According to embodiments of this disclosure, before performing operation S510, the communication method may further include the following operations.

[0126] For example, the client sends an authentication request to the intermediate server. The authentication request is used to request the establishment of communication authentication between the client and the target server. The authentication request includes the client's client identification information and authentication file, so that the intermediate server can send the authentication request to the authentication service center and receive authentication information from the authentication service center. The intermediate server also receives session identification information, which matches the authentication information. The session identification information is generated by the intermediate server based on the authentication information.

[0127] According to embodiments of this disclosure, when a client first establishes communication authentication between itself and the target server through an intermediate server, the client can directly send an authentication request to the intermediate server. However, this is not the limitation. As long as the authentication information and session identification information have an expiration date, the client can establish communication authentication between itself and the target server multiple times through the intermediate server. For example, in response to receiving feedback information from the intermediate server, an authentication request can be sent to the intermediate server. The feedback information is used to indicate that the session identification information is non-compliant.

[0128] Figure 6 A block diagram of a communication device according to an embodiment of the present disclosure is illustrated, applied to an intermediate server.

[0129] like Figure 6 As shown, the communication device 600 includes: a first access module 610, a first determination module 620, and a second access module 630.

[0130] The first access module 610 is used to respond to a first access request received from a client and determine session identification information and access information based on the first access request. The first access request is used to request access to the target server.

[0131] The first determining module 620 is used to determine the authentication information for accessing the target server based on the session identification information.

[0132] The second access module 630 is used to send a second access request to the target server based on authentication information and access information.

[0133] According to embodiments of this disclosure, the communication device further includes: a first authentication module, a second authentication module, a third authentication module, and a fourth authentication module.

[0134] The first authentication module is used to receive authentication requests from clients. The authentication request is used to request the establishment of communication authentication between the client and the target server. The authentication request includes the client's client identification information and authentication file.

[0135] The second authentication module is used to send authentication requests to the authentication service center, so that the authentication service center can authenticate the client's identity based on the client's identification information and authentication documents.

[0136] The third authentication module is used to receive authentication information from the authentication service center.

[0137] The fourth authentication module is used to send session identification information that matches the authentication information to the client, thereby completing the communication authentication between the client and the target server.

[0138] According to embodiments of this disclosure, the communication device further includes, prior to the fourth authentication module: a session generation module and a table update module.

[0139] The session generation module is used to generate session identification information that matches the authentication information.

[0140] The table update module is used to update the authentication identifier mapping table based on authentication information, session identifier information, and client identifier information. The authentication identifier mapping table represents the mapping relationship between authentication information, session identifier information, and client identifier information.

[0141] According to embodiments of this disclosure, the first determining module includes: a first determining submodule, a second determining submodule, and a first feedback submodule.

[0142] The first determination submodule is used to determine whether the session identifier information is compliant based on the generation time information of the session identifier information.

[0143] The second determination submodule is used to determine the authentication information for accessing the target server based on the session identifier information, provided that the session identifier information is deemed compliant.

[0144] The first feedback submodule is used to send feedback information to the client when it is determined that the session identification information is non-compliant, so that the client responds to the feedback information and sends an authentication request.

[0145] According to embodiments of this disclosure, the first determining module includes a third determining submodule.

[0146] The third determination submodule is used to determine the authentication information for accessing the target server that matches the session identification information from the authentication information mapping table.

[0147] According to embodiments of this disclosure, the communication device further includes a first receiving module and a first transmitting module.

[0148] The first receiving module is used to receive target data from the target server in response to the second access request.

[0149] The first sending module is used to send the target data to the client.

[0150] According to embodiments of this disclosure, the communication device further includes a second receiving module and a second determining module.

[0151] The second receiving module is used to receive encrypted information from the client.

[0152] The second determining module is used to decode the encrypted information according to the secure transmission protocol to obtain the first access request.

[0153] According to embodiments of this disclosure, a database connection protocol is deployed on the client. The target server is a server cluster node.

[0154] Figure 7 A block diagram of a communication device according to an embodiment of the present disclosure is illustrated, applied to a client.

[0155] like Figure 7 As shown, the communication device 700 includes a second transmitting module 710 and a third receiving module 720.

[0156] The second sending module 710 is used to send a first access request to an intermediate server. The first access request is used to request access to the target server, so that the intermediate server determines session identification information and access information based on the first access request, determines authentication information for accessing the target server based on the session identification information, and generates a second access request for accessing the target server based on the authentication information and access information.

[0157] The third receiving module 720 is used to receive target data from the intermediate server that matches the first access request, wherein the target data is data obtained by the intermediate server from the target server using the second access request.

[0158] According to embodiments of this disclosure, the communication device 700 may include only the second transmitting module 710, but is not limited thereto. The communication device 700 may also include the second transmitting module 710 and the third receiving module 720.

[0159] According to embodiments of this disclosure, the communication device further includes a third transmitting module and a fourth receiving module.

[0160] The third sending module is used to send authentication requests to the intermediate server. The authentication request is used to request the establishment of communication authentication between the client and the target server. The authentication request includes the client's client identification information and authentication file, so that the intermediate server can send the authentication request to the authentication service center and receive authentication information from the authentication service center.

[0161] The fourth receiving module is used to receive session identification information from the intermediate server. The session identification information is matched with the authentication information, and the session identification information is generated by the intermediate server based on the authentication information.

[0162] According to embodiments of this disclosure, the third sending module includes a sending submodule.

[0163] The sending submodule is used to "send an authentication request to the intermediate server upon receiving feedback information from the intermediate server, wherein the feedback information is used to indicate that the session identification information is non-compliant information".

[0164] According to embodiments of this disclosure, this disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0165] According to an embodiment of the present disclosure, an electronic device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform a method as described in the embodiments of the present disclosure.

[0166] According to embodiments of the present disclosure, a non-transitory computer-readable storage medium stores computer instructions, wherein the computer instructions are used to cause a computer to perform methods as described in embodiments of the present disclosure.

[0167] According to embodiments of the present disclosure, a computer program product includes a computer program that, when executed by a processor, implements the methods as described in embodiments of the present disclosure.

[0168] Figure 8 A schematic block diagram of an example electronic device 800 that can be used to implement embodiments of the present disclosure is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0169] like Figure 8As shown, device 800 includes a computing unit 801, which can perform various appropriate actions and processes based on a computer program stored in read-only memory (ROM) 802 or a computer program loaded from storage unit 808 into random access memory (RAM) 803. RAM 803 may also store various programs and data required for the operation of device 800. The computing unit 801, ROM 802, and RAM 803 are interconnected via bus 804. Input / output (I / O) interface 805 is also connected to bus 804.

[0170] Multiple components in device 800 are connected to I / O interface 805, including: input unit 806, such as keyboard, mouse, etc.; output unit 807, such as various types of monitors, speakers, etc.; storage unit 808, such as disk, optical disk, etc.; and communication unit 809, such as network card, modem, wireless transceiver, etc. Communication unit 809 allows device 800 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.

[0171] The computing unit 801 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 801 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 801 performs the various methods and processes described above, such as communication methods. For example, in some embodiments, the communication method may be implemented as a computer software program tangibly contained in a machine-readable medium, such as storage unit 808. In some embodiments, part or all of the computer program may be loaded and / or installed on device 800 via ROM 802 and / or communication unit 809. When the computer program is loaded into RAM 803 and executed by the computing unit 801, one or more steps of the communication method described above may be performed. Alternatively, in other embodiments, the computing unit 801 may be configured to perform the communication method by any other suitable means (e.g., by means of firmware).

[0172] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.

[0173] The program code used to implement the methods of this disclosure may be written in any combination of one or more programming languages. This program code may be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that when executed by the processor or controller, the program code causes the functions / operations specified in the flowcharts and / or block diagrams to be implemented. The program code may be executed entirely on a machine, partially on a machine, as a standalone software package partially on a machine and partially on a remote machine, or entirely on a remote machine or server.

[0174] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0175] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor); and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the computer. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).

[0176] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as a data server), or computing systems that include middleware components (e.g., an application server), or computing systems that include frontend components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with embodiments of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., a communication network). Examples of communication networks include local area networks (LANs), wide area networks (WANs), and the Internet.

[0177] Computer systems can include clients and servers. Clients and servers are generally located far apart and typically interact via communication networks. Client-server relationships are created by computer programs running on the respective computers and having a client-server relationship with each other. Servers can be cloud servers, distributed system servers, or servers incorporating blockchain technology.

[0178] It should be understood that the various forms of processes shown above can be used to rearrange, add, or delete steps. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution disclosed in this disclosure can be achieved, and this is not limited herein.

[0179] The specific embodiments described above do not constitute a limitation on the scope of protection of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure should be included within the scope of protection of this disclosure.

Claims

1. A communication method, comprising: Receive encrypted information from the client; The encrypted information is decoded according to the secure transmission protocol to obtain the first access request; In response to receiving the first access request from the client, session identification information and access information are determined based on the first access request, wherein the first access request is used to request access to the target server, the client has a database connection protocol deployed on it, and the computing engine deployed on the target server supports access via the database connection protocol. Based on the session identifier information, the authentication information used to access the target server is determined; A second access request is generated based on the authentication information and the access information, and the second access request is sent to the target server so that the target server can determine the legitimacy of the second access request based on the authentication information in the second access request. The authentication information includes authentication key information for encrypted transmission of information between the intermediate server and the target server. Receive target data from the target server in response to the second access request, wherein the target data is obtained by processing the access information after the target server determines that the second access request is legitimate; and The target data is sent to the client.

2. The method according to claim 1, further comprising: Receive an authentication request from the client, wherein the authentication request is used to request the establishment of communication authentication between the client and the target server, the authentication request includes the client's client identification information and authentication file, the client and the target server are network isolated, and the client and the authentication service center are network isolated; The authentication request is sent to the authentication service center so that the authentication service center can authenticate the client based on the client's client identification information and the authentication file; Receive authentication information from the authentication service center, the authentication information including a service ticket for accessing the target server; Session identification information matching the authentication information is sent to the client to complete the communication authentication between the client and the target server.

3. The method according to claim 2, further comprising, before sending the session identification information matching the authentication information to the client: Generate session identification information that matches the authentication information; and Based on the authentication information, the session identifier information, and the client's client identifier information, the authentication identifier mapping table is updated, wherein, The authentication identifier mapping table is used to represent the mapping relationship between authentication information, session identifier information, and client identifier information.

4. The method according to claim 2, wherein, The step of determining the authentication information for accessing the target server based on the session identifier information includes: Based on the generation time information of the session identifier information, determine whether the session identifier information is compliant information; If the session identification information is determined to be compliant, the authentication information used to access the target server is determined based on the session identification information; and If the session identification information is determined to be non-compliant, a feedback message is sent to the client so that the client responds to the feedback message and sends the authentication request.

5. The method according to claim 3, wherein, The step of determining the authentication information for accessing the target server based on the session identifier information includes: From the authentication information mapping table, determine the authentication information for accessing the target server that matches the session identification information.

6. The method according to any one of claims 1 to 5, wherein, The target server is a node in a server cluster.

7. A communication method, comprising: A first access request is sent to an intermediate server. This first access request is obtained by decoding encrypted information according to a secure transmission protocol and is used to request access to the target server. The intermediate server determines session identification information and access information based on the first access request. Based on the session identification information, it determines authentication information for accessing the target server. Based on the authentication information and the access information, it generates a second access request for accessing the target server and sends the second access request to the target server. A database connection protocol is deployed on the client, and the computing engine deployed on the target server supports access via the database connection protocol. The intermediate server receives target data matching the first access request from the intermediate server. The target data is data obtained by the intermediate server from the target server using the second access request. The target server determines the legitimacy of the second access request based on the authentication information in the second access request. The target data is obtained by processing the access information based on the access information when the target server determines that the second access request is legitimate. The authentication information includes authentication key information for encrypted transmission of information between the intermediate server and the target server.

8. The method according to claim 7, further comprising: An authentication request is sent to the intermediate server, wherein the authentication request is used to request the establishment of communication authentication between the client and the target server, and the authentication request includes the client's client identification information and authentication file, so that the intermediate server sends the authentication request to the authentication service center and receives the authentication information from the authentication service center. The client and the target server are isolated from each other on the network, and the client and the authentication service center are also isolated from each other on the network. Receive session identification information from the intermediate server, wherein the session identification information matches the authentication information, the session identification information is information generated by the intermediate server based on the authentication information, and the authentication information includes a service ticket for accessing the target server.

9. The method according to claim 8, wherein, Send an authentication request to the intermediate server, including: In response to receiving feedback information from the intermediate server, an authentication request is sent to the intermediate server, wherein the feedback information is used to indicate that the session identification information is non-compliant.

10. A communication system, comprising: A client, used to send encrypted information to an intermediate server, wherein a database connection protocol is deployed on the client; and An intermediate server is configured to receive the encrypted information from the client, decode the encrypted information according to a secure transmission protocol to obtain a first access request; determine session identification information and access information based on the first access request; determine authentication information for accessing the target server based on the session identification information; generate a second access request based on the authentication information and the access information; and send the second access request to the target server so that the target server can determine the legitimacy of the second access request based on the authentication information in the second access request. The authentication information includes authentication key information for encrypted information transmission between the intermediate server and the target server. The intermediate server is further configured to receive target data from the target server in response to the second access request, wherein the computing engine deployed on the target server supports access to the database connection protocol, the target data is obtained by processing the access information based on the access information when the target server determines that the second access request is legitimate, and to send the target data to the client.

11. A communication device, comprising: The second receiving module is used to receive encrypted information from the client; The second determining module is used to decode the encrypted information according to the secure transmission protocol to obtain the first access request; The first access module is configured to respond to receiving the first access request from the client, and determine session identification information and access information based on the first access request, wherein the first access request is used to request access to the target server, the client is equipped with a database connection protocol, and the computing engine deployed on the target server supports access via the database connection protocol. The first determining module is used to determine authentication information for accessing the target server based on the session identifier information; The second access module is used to generate a second access request based on the authentication information and the access information, and send the second access request to the target server so that the target server can determine the legitimacy of the second access request based on the authentication information in the second access request. The authentication information includes authentication key information for encrypted transmission of information between the intermediate server and the target server. A first receiving module is configured to receive target data from the target server in response to the second access request, wherein the target data is obtained by processing the access information after the target server determines that the second access request is legitimate; and The first sending module is used to send the target data to the client.

12. The apparatus of claim 11, further comprising: The first authentication module is used to receive an authentication request from the client, wherein the authentication request is used to request the establishment of communication authentication between the client and the target server, the authentication request includes the client's client identification information and authentication file, the client and the target server are network isolated, and the client and the authentication service center are network isolated; The second authentication module is used to send the authentication request to the authentication service center, so that the authentication service center can authenticate the client based on the client's client identification information and the authentication file; The third authentication module is configured to receive the authentication information from the authentication service center, the authentication information including a service ticket for accessing the target server; and The fourth authentication module is used to send session identification information that matches the authentication information to the client to complete the communication authentication between the client and the target server.

13. The apparatus of claim 12, further comprising, prior to the fourth authentication module: A session generation module is used to generate session identification information that matches the authentication information; and The table update module is used to update the authentication identifier mapping table based on the authentication information, the session identifier information, and the client's identifier information, wherein... The authentication identifier mapping table is used to represent the mapping relationship between authentication information, session identifier information, and client identifier information.

14. The apparatus according to claim 12, wherein, The first determining module includes: The first determining submodule is used to determine whether the session identifier information is compliant information based on the generation time information of the session identifier information; The second determining submodule is used to, if the session identifier information is determined to be compliant information, determine the authentication information used to access the target server based on the session identifier information; and The first feedback submodule is used to send feedback information to the client when it is determined that the session identification information is non-compliant, so that the client responds to the feedback information and sends the authentication request.

15. The apparatus according to claim 11, wherein, The first determining module includes: The third determining submodule is used to determine, from the authentication information mapping table, the authentication information used to access the target server that matches the session identifier information.

16. The apparatus according to any one of claims 11 to 15, wherein, The target server is a node in a server cluster.

17. A communication device, comprising: The second sending module is used to send a first access request to an intermediate server for accessing a target server. The intermediate server decodes encrypted information according to a secure transmission protocol to obtain the first access request. Based on the first access request, the intermediate server determines session identification information and access information. Based on the session identification information, it determines authentication information for accessing the target server. Based on the authentication information and the access information, it generates a second access request for accessing the target server and sends the second access request to the target server. A database connection protocol is deployed on the client, and the computing engine deployed on the target server supports access via the database connection protocol. The third receiving module is used to receive target data from the intermediate server that matches the first access request. The target data is data obtained by the intermediate server from the target server using the second access request. The target server determines the legitimacy of the second access request based on the authentication information in the second access request. The target data is obtained by processing the access information based on the access information when the target server determines that the second access request is legitimate. The authentication information includes authentication key information for encrypted transmission of information between the intermediate server and the target server.

18. The apparatus of claim 17, further comprising: The third sending module is used to send an authentication request to the intermediate server. The authentication request is used to request the establishment of communication authentication between the client and the target server. The authentication request includes the client's client identification information and authentication file, so that the intermediate server sends the authentication request to the authentication service center and receives the authentication information from the authentication service center. The client and the target server are network isolated, and the client and the authentication service center are network isolated. The fourth receiving module is used to receive session identification information from the intermediate server, wherein the session identification information matches the authentication information, the session identification information is information generated by the intermediate server based on the authentication information, and the authentication information includes a service ticket for accessing the target server.

19. The apparatus according to claim 18, wherein, The third sending module includes: The sending submodule is used to send an authentication request to the intermediate server in response to receiving feedback information from the intermediate server, wherein the feedback information is used to indicate that the session identification information is non-compliant information.

20. An electronic device, comprising: At least one processor; as well as A memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor to enable the at least one processor to perform the method of any one of claims 1 to 9.

21. A non-transitory computer-readable storage medium storing computer instructions, wherein, The computer instructions are used to cause the computer to perform the method according to any one of claims 1 to 9.

22. A computer program product comprising a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Access method and device

    CN112491890A

  • Access control method and electronic equipment

    CN115277207A