Authorization method and device, electronic device, and computer-readable storage medium

The authorization of application services is dynamically managed through the authorization server, and the number of authorizations is automatically allocated according to the time period type and version information, which solves the problems of inconvenience of manual deployment and waste of resources, and realizes flexible and efficient authorization management.

CN116155526BActive Publication Date: 2025-09-23MASHANG CONSUMER FINANCE CO LTD
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202211412206.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-11
Publication Date
2025-09-23
Estimated Expiration
2042-11-11

AI Technical Summary

Technical Problem

In the prior art, the authorization method for application services relies on manual deployment, which is inconvenient and cannot be flexibly adjusted, resulting in resource waste and inconvenient management.

Method used

The authorization server receives authorization requests from application services, dynamically obtains the number of available authorizations based on the current authorization period type and application version information, and generates a response message to automatically manage the authorization status of the application service.

Benefits of technology

It achieves flexible and efficient authorization management, avoids resource waste, improves user experience and reduces manual intervention.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116155526B_ABST
    Figure CN116155526B_ABST
Patent Text Reader

Abstract

The present disclosure provides an authorization method and apparatus, an electronic device, and a computer-readable storage medium, the method comprising: receiving an authorization request sent by an application service to be authorized, the authorization request including an application identifier, application version information, and a requested authorization number of the application service; determining, in response to the authorization request, an authorization period type at the current moment, the authorization period type indicating whether the current moment is in a busy period of the application service; obtaining, based on the authorization period type and the application version information, the number of allocable authorizations, wherein the number of allocable authorizations is the number of authorizations remaining in the authorization service at the current moment and that can be allocable to the application service; generating, based on the application identifier, the requested authorization number, and the number of allocable authorizations, a response message corresponding to the authorization request, and sending the response message to the application service, wherein the response message is at least used to indicate whether the authorization request was successful. According to the embodiments of the present disclosure, the number of authorizations can be conveniently and flexibly allocable to the application service.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, and in particular to an authorization method and device, an electronic device, and a computer-readable storage medium. Background Art

[0002] In related technologies, after a customer purchases an application service, an operation and maintenance personnel usually generates an authorization code based on the number of licenses purchased by the customer and the length of use; then, the operation and maintenance personnel deploys the application service locally at the customer and configures the authorization code in the application service.

[0003] This authorization method for application services often has problems of being inconvenient and inflexible because it relies on manual deployment. Summary of the Invention

[0004] The present disclosure provides an authorization method and apparatus, an electronic device, and a computer-readable storage medium for conveniently and flexibly allocating authorization numbers to application services.

[0005] In a first aspect, the present disclosure provides an authorization method, the method comprising:

[0006] Receive an authorization request sent by an application service to be authorized, wherein the authorization request includes an application identifier, application version information, and a requested authorization number of the application service;

[0007] In response to the authorization request, determining an authorization period type at a current moment, wherein the authorization period type indicates whether the current moment is in a busy period of the application service;

[0008] According to the authorization period type and the application version information, the number of allocable authorizations is obtained, wherein the number of allocable authorizations is the number of authorizations remaining in the authorization service at the current moment and that can be allocated to the application service;

[0009] A response message corresponding to the authorization request is generated according to the application identifier, the requested authorization number, and the distributable authorization number, and the response message is sent to the application service, wherein the response message is at least used to indicate whether the authorization request is successful.

[0010] In a second aspect, the present disclosure provides an authorization device, the device comprising:

[0011] A receiving unit, configured to receive an authorization request sent by an application service to be authorized, wherein the authorization request includes an application identifier, application version information, and a requested authorization number of the application service;

[0012] a determining unit, configured to determine, in response to the authorization request, an authorization period type at a current moment, wherein the authorization period type indicates whether the current moment is in a busy period of the application service;

[0013] an acquiring unit, configured to acquire the number of allocable authorizations according to the authorization period type and the application version information, wherein the number of allocable authorizations is the number of authorizations remaining in the authorization service at the current moment and that can be allocated to the application service;

[0014] A response unit is used to generate a response message corresponding to the authorization request based on the application identifier, the requested authorization number and the distributable authorization number, and send the response message to the application service, wherein the response message is at least used to indicate whether the authorization request is successful.

[0015] In a third aspect, the present disclosure provides an electronic device comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores one or more computer programs executable by the at least one processor, and the one or more computer programs are executed by the at least one processor to enable the at least one processor to execute the above-mentioned authorization method.

[0016] In a fourth aspect, the present disclosure provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the above-mentioned authorization method when executed by a processor.

[0017] In the embodiments provided by the present disclosure, by setting up an authorization server, it is unnecessary for operation and maintenance personnel to manually configure the number of authorizations in the application service. Instead, after receiving the authorization request sent by the application service to be authorized, the authorization server can determine the authorization period type at the current moment, and obtain the number of allocable authorizations that can be allocated to the application service at the current moment based on the authorization period type and application version information; then, based on the application identifier of the application service, the requested number of authorizations requested by the application service, and the allocable number of authorizations, the authorization server can determine whether the requested authorization request can be allocated to the application service, and send a response message to the application service indicating whether the request is successful.

[0018] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] The accompanying drawings are used to provide a further understanding of the present disclosure and constitute a part of the specification. Together with the embodiments of the present disclosure, they are used to explain the present disclosure and do not constitute a limitation of the present disclosure. The above and other features and advantages will become more apparent to those skilled in the art by describing detailed example embodiments with reference to the accompanying drawings. In the accompanying drawings:

[0020] Figure 1 A schematic diagram of an implementation environment of the authorization method provided in an embodiment of the present disclosure;

[0021] Figure 2 A flowchart of an authorization method provided in an embodiment of the present disclosure;

[0022] Figure 3 A flowchart of the authorization process provided in an embodiment of the present disclosure;

[0023] Figure 4 A flow chart of generating a response message provided in an embodiment of the present disclosure;

[0024] Figure 5 A flowchart for verifying an authorization request provided in an embodiment of the present disclosure;

[0025] Figure 6 Another flow chart for generating a response message provided by an embodiment of the present disclosure;

[0026] Figure 7 A block diagram of an authorization device provided in an embodiment of the present disclosure;

[0027] Figure 8 A block diagram of an electronic device provided in an embodiment of the present disclosure. DETAILED DESCRIPTION

[0028] To enable those skilled in the art to better understand the technical solutions of the present disclosure, exemplary embodiments of the present disclosure are described below in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding. These details should be considered merely exemplary. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0029] In the absence of conflict, the various embodiments of the present disclosure and the various features therein may be combined with each other.

[0030] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.

[0031] The terms used herein are only used to describe specific embodiments and are not intended to limit the present disclosure. As used herein, the singular forms "a" and "the" are also intended to include the plural forms, unless the context clearly indicates otherwise. It will also be understood that when the terms "comprising" and / or "made of" are used in this specification, the presence of the features, wholes, steps, operations, elements and / or components is specified, but the presence or addition of one or more other features, wholes, steps, operations, elements, components and / or groups thereof is not excluded. Similar words such as "connected" or "connected" are not limited to physical or mechanical connections, but can include electrical connections, whether direct or indirect.

[0032] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and the present disclosure, and will not be interpreted as having an idealized or overly formal meaning unless expressly defined as such herein.

[0033] In related technologies, after a customer purchases an application service, an operation and maintenance personnel usually generates an authorization code based on the number of licenses purchased by the customer and the length of use; then, the operation and maintenance personnel deploys the application service locally at the customer and configures the authorization code in the application service.

[0034] This authorization method in the related art often has the problem of inconvenience because it relies on manual deployment and authorization at the customer's local site. In addition, in practice, when customers use application services, the number of authorizations they need to use during off-peak hours is often much smaller than the number of authorizations during busy hours. For example, customers rarely or even do not need to use application services during holidays. However, since this authorization method in the related art can only allow operation and maintenance personnel to configure the number of authorizations to the application service at one time, and cannot flexibly and dynamically adjust the number of authorizations for the application service, there may be a problem of resource waste during off-peak hours.

[0035] Please see Figure 1 , which is a schematic diagram of the implementation environment of the authorization method provided by the embodiment of the present disclosure. Figure 1 As shown, the implementation environment may include an authorization server 101 , an application server 102 , and a network 103 .

[0036] Authorization server 101 can be, for example, a physical server, such as a blade server, a rack-mounted server, or a virtual server, such as a server cluster deployed in the cloud, without limitation. In embodiments of the present disclosure, authorization server 101 can be used to deploy and run authorization services to implement the authorization method of any embodiment of the present disclosure and to distribute authorizations to at least one application service deployed in application server 102.

[0037] The application server 102 may be, for example, a physical server, such as a blade server or a rack-mounted server, and the authorization server 101 may also be a virtual server, such as a server cluster deployed in the cloud, without limitation. In the disclosed embodiments, an application service may be deployed in the application server 102. During startup, the application service may send an authorization request containing its own application identifier, application version information, and a requested authorization number to the authorization service running in the authorization server 101, requesting that the authorization server 101 grant the requested authorization number.

[0038] In the embodiment of the present disclosure, the application service deployed in the application server 102 can be any application, for example, it can be an automatic speech recognition (ASR) service, an optical character recognition (OCR) service, and other services; of course, the application service can also be one or more different versions of the same service, for example, the application service can be version 1.1, version 1.2, and other versions of the ASR service.

[0039] In the embodiment of the present disclosure, unless otherwise specified, different services of the same version can share the total number of authorizations, that is, in the authorization server 101, application information of the application services that the authorization service can authorize can be pre-configured. The application information may include application type, application version information, authorization expiration time, and the total number of authorizations corresponding to busy periods and non-busy periods, respectively.

[0040] The network 103 can be a wireless network or a wired network, a local area network or a wide area network. The authorization server 101 and the application server 102 can communicate with each other through the network 103.

[0041] In an embodiment of the present disclosure, the authorization server 101 can be used to deploy and run an authorization service, which can be used to participate in implementing the authorization method according to any embodiment of the present disclosure. For example, it can be used to: receive an authorization request sent by an application service to be authorized deployed in the application server 102, wherein the authorization request includes the application identifier, application version information, and requested authorization number of the application service; in response to the authorization request, determine the authorization period type at the current moment, wherein the authorization period type indicates whether the current moment is in a busy period of the application service; obtain the number of allocable authorizations based on the authorization period type and application version information, wherein the number of allocable authorizations is the number of authorizations remaining in the authorization service at the current moment and that can be allocable to the application service; generate a response message corresponding to the authorization request based on the application identifier, requested authorization number, and allocable authorization number, and send the response message to the application service in the application server 102, wherein the response message is at least used to indicate whether the authorization request is successful.

[0042] In the embodiment of the present disclosure, the application service in the application server 102 can be used to: during the application service startup process, send an authorization request containing its own application identification, application version information and requested authorization number to the authorization service running in the authorization server 101; when receiving a response message sent by the application server 102, if the response message indicates that the request is successful, then start normally and provide services to the user; if the response message indicates that the request fails, then the application service startup fails.

[0043] It is understandable that Figure 1 The implementation environment shown is illustrative only and is in no way intended to limit the present disclosure, its application, or uses. Figure 1 Only one authorization server 101 and one application server 102 are shown, but this does not mean to limit their respective numbers. The implementation environment may include multiple authorization servers 101 and multiple application servers 102.

[0044] In order to authorize application services conveniently and flexibly, the present disclosure provides an authorization method. Figure 2 , which is a flowchart of an authorization method provided by an embodiment of the present disclosure. The method can be applied to an authorization server, more specifically, can be applied to an authorization service deployed on the authorization server, for example, can be applied to Figure 1 In the authorization service of the authorization server 101 shown.

[0045] like Figure 2 As shown, the authorization method provided by the embodiment of the present disclosure includes the following steps S201-S204, which are described in detail below.

[0046] Step S201: receiving an authorization request sent by an application service to be authorized, wherein the authorization request includes an application identifier of the application service, application version information, and a requested authorization number.

[0047] The application identifier is used to uniquely identify the service process of the application service. The application identifier can be a universally unique identifier (UUID) or a unique identifier generated based on other algorithms, and is not specifically limited here.

[0048] In actual implementation, the application identifier may be generated by the application service based on a preset identification algorithm after startup, and the application identifier is used to uniquely identify the current application service.

[0049] It should be noted that for the same application, the application identifiers of different application processes are different. For example, for version 1.1 of the automatic speech recognition service, i.e. ASR1.1, after running ASR1.1 in application server 1, its application identifier may be "application identifier 1". If another ASR1.1 service process is started in the application server 1, the application identifier of the newly started ASR1.1 service is "application identifier 2" which is different from "application identifier 1".

[0050] The application version information may include both the application type and the application version. For example, the application version information "ASR1.1" may indicate that the application type of the application service is an automatic speech recognition service and the version is 1.1. Of course, this disclosure uses the example of the application version information including both the application type and the application version as an example. In actual implementation, the "application type" parameter may also be directly included in the authorization request.

[0051] For example, the request parameters in the authorization request may include: [application identifier: "application identifier 1", application version information: "ASR1.1", requested authorization number: 20]; or, it may also include: [application identifier: "application identifier 1", application type: "ASR", application version information: "ASR1.1", requested authorization number: 20].

[0052] The number of authorization requests, also known as the number of authorized users, is the number of users allowed to use the application service simultaneously within a unit of time.

[0053] In the embodiment of the present disclosure, the authorization request may be sent by the application service to the authorization service in the authorization server during the startup process to request the authorization service to allocate an authorization number to it.

[0054] It should be noted that, in actual implementation, the application service may send the authorization request to the authorization service each time it is started; or, the application service may send the authorization request to the authorization service when it detects that its authorization status meets the preset request conditions during the startup process.

[0055] The authorization status of the application service may include: an unauthorized state and an authorized state; in this case, the application service may send an authorization request to the authorization service when detecting that the authorization status is an unauthorized state.

[0056] In addition, the authorized status can be further divided into: idle authorized status and busy authorized status. The idle authorized status indicates that the number of authorizations currently allocated to the application service is the number of authorizations requested when it is idle, that is, the non-busy period. The busy authorized status indicates that the number of authorizations currently allocated to the application service is the number of authorizations requested when it is busy, that is, the busy period. In this case, since the authorization service in the embodiment of the present disclosure will reclaim part of the authorizations allocated to the application service when the application service is idle, the number of authorizations allocated to the application service when the application service is in the idle authorized status will usually be less than the number of authorizations in the busy period. If the application service detects that the authorization status is the idle authorized status and the current time is a busy period during the startup process, it can send an authorization request to the authorization service to request more authorizations, thereby meeting the user's demand for the application service during the busy period and improving the user experience.

[0057] Step S202: In response to the authorization request, determine the authorization period type at the current moment, wherein the authorization period type indicates whether the current moment is in a busy period of the application service.

[0058] It should be noted that the current moment described in the embodiments of the present disclosure may be the moment represented by the system time of the authorization server where the authorization service is located; or, it may be the network time, that is, the moment represented by the real real time.

[0059] It is understandable that in an implementation method where the current moment is represented by the system time of the authorization server, in order to avoid errors in the operation of the authorization service, a clock synchronization application can be set in the authorization server. The clock synchronization application can obtain the Internet time at a preset time interval and calibrate the local system time of the authorization server to ensure the accuracy of the system time of the authorization server and avoid abnormalities in the authorization service due to errors in the system time of the authorization server.

[0060] The authorized time period type may include a busy period and a non-busy period, wherein the busy period indicates that the application service may be in a time range with a high usage frequency at the current moment, and the non-busy period indicates that the application service may be in a time range with a low usage frequency at the current moment.

[0061] For example, for an application service used locally by an enterprise, the frequency of use of the application service is often low during holidays. At this time, if a large number of authorizations are allocated to the application service, there may be a problem of waste of resources.

[0062] Therefore, in the embodiment of the present disclosure, after receiving the authorization request sent by the application service, the authorization service can flexibly and accurately allocate the authorization number to the application service by determining the authorization period type at the current moment, thereby avoiding the problem of resource waste.

[0063] In the embodiment of the present disclosure, when the authorization service determines the authorization period type according to the current time, it can obtain the type by querying whether the preset non-busy period table corresponding to the application service includes the current time.

[0064] For example, the application type of the application service is "ASR" and the current time is "April 1st". If the non-busy periods preset for the application service in the authorization service are ["April / 5th to August / 5th", "October / 5th to October / 15th", "November / 5th to December / 5th"], then the current authorization period type can be obtained as a busy period.

[0065] Step S203: acquiring the number of allocable authorizations according to the authorization period type and the application version information, wherein the number of allocable authorizations is the number of authorizations remaining in the authorization service at the current moment and that can be allocated to the application service.

[0066] In the embodiment of the present disclosure, in the authorization service, different authorization numbers can be configured for the application service according to different authorization period types.

[0067] For example, you can add the following configuration to the configuration file of the authorization service: {"serviceTypeArray":[{"serviceType":"asr","typeVersions":["ASR1.1","ASR1.2","ASR1.3"],"expirationDate":"2030-01-01","busyProcesser":15,"unbusyProcesser":5,"unbusyDate":["April / 5th to August / 5th","October / 5th to October / 5th","November / 5th to December / 5th"]},…]}, so that the authorization service When an authorization request is received, the application type and version information of the application service can be parsed according to the application version information in the authorization request, and the number of distributable authorizations currently corresponding to the application service can be obtained according to the current authorization period type. Among them, serviceTypeArray indicates that this configuration item is used to configure the authorization data of different application types, serviceType indicates the application type, typeVersions indicates the application version information, expirationDate indicates the authorization expiration time of the authorization number, that is, the validity period, busyProcesser indicates the first total authorization number in the busy period, and unbusyProcesser indicates the second total authorization number in the non-busy period.

[0068] In addition, in the above description, the authorization expiration time of the authorization number is used as a moment, for example, in the form of "2030-01-01"; in some embodiments, the authorization expiration time can also be a duration, for example, in the form of "1440 hours". In this implementation, the authorization service can determine whether the authorization number of the application service meets the preset expiration condition by counting the usage time of the application service after allocating the requested authorization number to the application service.

[0069] Step S204: Generate a response message corresponding to the authorization request according to the application identifier, the requested authorization number, and the allocable authorization number, and send the response message to the application service, wherein the response message is at least used to indicate whether the authorization request is successful.

[0070] After obtaining the application identifier, requested authorization number, and allocable authorization number corresponding to the application service according to the above steps, the authorization service can determine whether to allocate the requested authorization number to the application service by comparing the requested authorization number with the allocable authorization number, and generate a response message indicating whether the request is successful.

[0071] It can be seen that in the embodiment of the present disclosure, by setting up an authorization server, it is unnecessary for the operation and maintenance personnel to manually configure the number of authorizations in the application service. Instead, after the authorization server receives the authorization request sent by the application service to be authorized, it can determine the authorization period type at the current moment, and obtain the number of allocable authorizations that can be allocated to the application service at the current moment based on the authorization period type and the application version information; thereafter, the authorization server can determine whether the requested authorization request can be allocated to the application service based on the application identifier of the application service, the requested number of authorizations requested by the application service, and the allocable number of authorizations, and send a response message to the application service indicating whether the request is successful.

[0072] In some embodiments, the obtaining of the number of allocable authorizations based on the authorization period type and the application version information as described in the above step S203 includes: obtaining the number of allocable authorizations corresponding to the application service based on the application version information; in the case where the authorization period type is the first type, obtaining the first total number of authorizations corresponding to the application service, and obtaining the number of allocable authorizations based on the first total number of authorizations and the number of allocable authorizations; in the case where the authorization period type is the second type, obtaining the second total number of authorizations corresponding to the application service, and obtaining the number of allocable authorizations based on the second total number of authorizations and the number of allocable authorizations; wherein the first type indicates that the current moment is in the busy period of the application service, and the second type indicates that the current moment is not in the busy period of the application service.

[0073] Since the application version information in the embodiment of the present disclosure includes the application type and the version information of the application service, after obtaining the application version information, the application version information can be parsed to determine the application type and version information of the application service; then, according to the current authorization period type, the current number of distributable authorizations can be determined by querying in the preset configuration.

[0074] It is understandable that, in the case where the application version information only includes the version information of the application service, the request parameters of the authorization request also need to include the application type of the application service.

[0075] It can be seen that in the embodiment of the present disclosure, in order to avoid waste of resources, by setting the authorization period type, the authorization service can select the total number of authorizations corresponding to the authorization period according to the current authorization period type when allocating authorization numbers to the application service to determine the currently allocable number of allocable authorizations, so as to avoid the problem of resource waste.

[0076] It should be noted that, in the embodiments of the present disclosure, considering that the authorization service may make a judgment based on the system time of the authorization server where it is located when judging the type of the authorization period at the current moment, if the system time of the authorization server is inaccurate, it may lead to inaccurate judgment of the type of the authorization period; for this reason, in some embodiments, the authorization method also includes: during the startup of the authorization service, obtaining the server fingerprint information of the authorization server where the authorization service is located, wherein the server fingerprint information is generated by encrypting the MAC address and system time of the authorization server; based on the server fingerprint information, verifying whether the system time of the authorization server at the current moment is accurate, and if the verified system time of the authorization server is inaccurate, stopping the startup.

[0077] The server fingerprint information is generated by the user after verifying the MAC address and system time of the authorization server offline and configured in the configuration file of the authorization service. During the startup process, the authorization service can verify whether the server system time is correct based on the server fingerprint information. If it is incorrect, the startup can be stopped.

[0078] Please see Figure 3 , which is a flowchart of the authorization process provided by the embodiment of the present disclosure. Figure 3 As shown, in the embodiment of the present disclosure, the step S204 described above, generating a response message corresponding to the authorization request according to the application identifier, the requested authorization number and the distributable authorization number, may include the following steps S301-S302.

[0079] Step S301: When the requested authorization number is less than or equal to the allocable authorization number, the requested authorization number is allocated to the application service, and a first response message indicating that the request is successful is generated according to the application identifier.

[0080] That is, when the application service requests the number of authorizations to be allocated, that is, the requested number of authorizations is less than or equal to the number of authorizations that can be allocated, the authorization service can allocate the requested number of authorizations to the application service. In this case, the authorization service can generate authorization information corresponding to the application service based on the application identifier of the application service and the requested number of authorizations, and store the authorization information in a database, such as a Redis database, to manage the authorization status of the application service based on the authorization information; at the same time, a first response message indicating that the request is successful can be generated and sent to the application service.

[0081] For example, if the application ID of the application service is "application ID 1", the requested authorization number is 3, and the available authorization number is "15", the authorization service can generate a key-value pair <application ID 1, 3> in the form of <application ID, requested authorization number> as the authorization information of the application service, and store the key-value pair in the Redis database; at the same time, it can also generate a first response message {"msg":"Request successful","code":200,"data":{"clientid":"application ID 1"}} and send the first response message to the application service.

[0082] Step S302: When the number of requested authorizations is greater than the number of allocable authorizations, a second response message indicating that the request has failed is generated according to the application identifier.

[0083] It is understandable that if the number of requested authorizations is greater than the number of allocable authorizations, the request fails. At this time, the authorization service can generate a second response message of {"msg":"Request failed","code":40004,"data":{"clientid":"Application ID 1","processes":3}} and send the second response message to the application service, where processes represents the number of requested authorizations in the authorization request. If the application service request fails, the authorization service can include the requested authorization number in the returned response message to prompt the application service that it can make the request again with a reduced number of requested authorizations.

[0084] Please continue to see Figure 3 In some embodiments, when the response message indicates that the request is successful, the method may further include: step S303, when the preset conditions are met, performing authorization number recovery processing on the request authorization number allocated to the application service according to the application identifier, wherein the authorization number recovery processing is used to recover all or part of the authorization number allocated to the application service.

[0085] Among them, the preset conditions may include at least one of the following: the application service is in an abnormal operating state, the authorization period type changes from the first type to the second type, and the number of requested authorizations meets the preset expiration conditions; the first type indicates that the current moment is in the busy period of the application service, and the second type indicates that the current moment is not in the busy period of the application service.

[0086] That is, in order to be able to flexibly manage the number of authorizations for application services, in some embodiments, after the authorization service allocates the number of authorizations to the application service, it can also continuously detect the operating status of the application service, detect whether the current authorization period type has changed, and whether the number of authorizations meets the preset expiration conditions, etc., to determine whether the number of authorizations granted to the application service needs to be adjusted, for example, to perform full or partial recycling processing.

[0087] In this embodiment, the abnormal state of the application service can be obtained by the following steps: receiving a heartbeat detection packet sent by the application service at a preset time interval, and determining that the application service is in an abnormal state if the heartbeat detection packet is not received within the preset time period.

[0088] That is, after receiving a response message indicating a successful request, i.e., the above-mentioned first response message, the application service can, during operation, continuously send heartbeat detection packets to the authorization service at preset time intervals based on a heartbeat mechanism; the authorization service can determine the operating status of the application service based on the received heartbeat detection packets. If the heartbeat detection packet sent by the application service is not received within a preset time period, for example, half an hour, it can be determined that the application service is in an abnormal state.

[0089] In addition, in this embodiment, whether the number of authorizations meets the preset expiration condition can be determined based on the authorization expiration time configured for the application service in the authorization service. For example, if the authorization expiration time of the number of authorizations of the application service is "2030-01-01", which is in the form of a moment, then whether the number of authorizations of the application service meets the preset expiration condition can be determined by determining whether the system time of the authorization server is greater than or equal to the authorization expiration time. For another example, if the authorization expiration time is "1440 hours", which is in the form of a length of time, then when allocating the number of authorizations requested by the application service, the authorization service can record and store the allocation time of the number of authorizations, and calculate the statistical time between the allocation time and the current system time, and determine whether the number of authorizations meets the preset expiration condition by comparing the statistical time with the authorization expiration time. Of course, in actual implementation, other methods can also be used to determine whether the number of authorizations meets the preset expiration condition, which is not specifically limited here.

[0090] In addition, when a change in the current authorization period type is detected, the frequency of use of the application service will be greatly reduced when it switches from a busy period to a non-busy period. Therefore, if there are still authorizations for the busy period remaining, there may be a problem of resource waste. In this case, the authorization service can partially recycle the authorizations of the application service to avoid resource waste.

[0091] Please continue to see Figure 3In the embodiment of the present disclosure, the authorization number recovery processing of the request authorization number allocated to the application service according to the application identifier as described in the above step S303 may include: step S303-1, obtaining the authorization information corresponding to the application service from the database according to the application identifier, wherein the authorization information is generated and stored in the database in the process of allocating the request authorization number to the application service, and the authorization information includes at least the application identifier and the request authorization number; step S303-2, clearing the authorization information in the database, or reducing the value of the request authorization number in the authorization information to complete the authorization number recovery processing.

[0092] That is, since the authorization service manages the number of authorizations for the application service based on the authorization information stored in the database, when it is necessary to reclaim the number of authorizations for the application service, the authorization information in the database can be directly cleared to fully reclaim the number of authorizations allocated to the application service, or the number of authorizations can be partially reclaimed through numerical reduction processing, such as geometric reduction processing.

[0093] The processing of recovering all authorization numbers will not be described in detail here; the reduction processing of the value of the requested authorization number in the authorization information to complete the authorization number recovery processing can be: obtaining the ratio of the second total authorization number to the first total authorization number, and according to the ratio, performing a geometric reduction processing on the value of the requested authorization number.

[0094] For example, if the second total authorization is 5, the first total authorization number is 15, and the requested authorization number is 3, the requested authorization number can be reduced to 1 by geometrically reducing the requested authorization number based on the ratio of the second total authorization number to the first total authorization number and rounding it off.

[0095] It can be seen that in the embodiments of the present disclosure, by setting up an authorization server running an authorization service, the problem of inconvenience in authorization number management caused by manual deployment of application services and manual configuration of authorization numbers can be solved; and after the authorization numbers are allocated to the application services, authorization information for managing their authorization numbers is generated based on the application identifier of the application services, so that the authorization service can also flexibly manage the authorization numbers allocated to the application services when preset conditions are met, so as to avoid resource waste.

[0096] Please see Figure 4 , which is a flow chart of generating a response message provided by an embodiment of the present disclosure. Figure 4 As shown, in some embodiments, the authorization request also includes the request time of the authorization request; the step S204 above generates a response message corresponding to the authorization request based on the application identifier, the requested authorization number, and the allocable authorization number, including:

[0097] Step S401: Generate a response identifier including a request time, wherein the request time in the response identifier is used by the application service to verify whether the response message is a simulated response.

[0098] Step S402: Generate a response message according to the applied identifier, the response identifier, the requested authorization number and the distributable authorization number.

[0099] Considering that the authorization service distributes authorization numbers to the application service through remote communication, there is a possibility that the data interaction between the authorization service and the application service will be simulated during the actual implementation process, which may bring security risks to the application service and may also affect the commercial rights enjoyed by the developers of the authorization service.

[0100] To solve this problem, in some embodiments, the authorization request sent by the application service to the authorization service may further include the request time; in response to the authorization request, the authorization service may generate a response identifier, i.e., responseId, based on the request time when sending a response message to the application service; after receiving the response message including the response identifier, the application service may parse the response identifier, obtain the request time, and calculate the difference between the current time and the request time. If the difference is greater than a preset threshold, for example, greater than 10 minutes, it can be determined that the response message may be simulated by a simulation service and there is a certain security risk. The response message may be discarded and the authorization request may be resent to the authorization service.

[0101] The step S401 of generating a response identifier including the request time may include generating a random character string, and concatenating the random character string and the request time to obtain the response identifier.

[0102] In the embodiment of the present disclosure, unless otherwise specified, the request time may be in the form of a timestamp.

[0103] For example, the request time can be "1651823169170", and the responseId in the response message can be "c5ece10860634dc8b2a95a068d5e2f90-1651823169170" obtained by concatenating a random string and the request time; the response message can be, for example: {"msg":"Request successful","code":200,"data":{"clientid":"Application ID 1","respo After receiving the response message, the application service obtains the current timestamp and parses the responseId to obtain the timestamp of the request time, which is 1651823169170. If the absolute value of the difference between the two timestamps is greater than a preset threshold, for example, greater than 10 minutes, the response message can be discarded and the authorization request can be resent to the authorization service.

[0104] It can be seen that the method provided by the embodiment of the present disclosure configures the request time in the authorization request, and generates a response identifier based on the request time when sending a response message to the application service, so that the application service can verify whether the authorization service is subjected to a simulated attack based on the request time, thereby improving the security of the application service side.

[0105] Please see Figure 5 , which is a flow chart for verifying authorization request provided by an embodiment of the present disclosure. Figure 5 As shown, in some embodiments, the authorization request may further include a request identifier and first signature information of the authorization request, wherein the first signature information is generated by the application service after signing the request identifier based on a preset signature algorithm; after receiving the authorization request based on the above step S201, the method further includes:

[0106] Step S501: Use a preset signature algorithm to sign the request identifier to obtain first verification signature information.

[0107] The preset signature algorithm may refer to any algorithm used for digital signature.

[0108] A digital signature is a string of digits that can only be generated by the sender and cannot be forged. This string of digits also effectively proves the authenticity of the message. A digital signature is an alphanumeric string generated by processing the message through a one-way function. It authenticates the source and verifies whether the message has been altered during transmission.

[0109] The preset signature algorithm may be any algorithm used to sign data, for example, it may be an Advanced Encryption Standard (AES) symmetric encryption algorithm.

[0110] Step S502 , verifying whether the first verification signature information and the first signature information are consistent; and step S503 , executing the step of determining the authorization period type at the current moment in response to the authorization request if the verification is consistent.

[0111] That is, in order to prevent the authorization request sent by the application service to the authorization service from being simulated, thereby causing the authorization service to respond unnecessary, the authorization request sent by the application service to the authorization service may also include a request identifier and a first signature information generated after signing the request identifier using a preset signature algorithm; after the authorization service receives the authorization request, it can use a preset signature algorithm consistent with the application service to sign the request identifier in the authorization request to obtain first verification signature information. Thereafter, by comparing the first verification signature information with the first signature information configured by the application service in the authorization request for consistency, it can be determined whether the authorization request is simulated, that is, whether it is indeed made by the application service and has not been tampered with.

[0112] For example, the authorization request sent by the application service may include a request identifier: requestId1, and the signature information Sign1(requestId1) corresponding to the request identifier; after receiving the authorization request, the authorization service may sign the request identifier in the authorization request to obtain Sign2(requestId1); thereafter, by verifying whether Sign1(requestId1) and Sign2(requestId1) are consistent, it can be verified whether the authorization request is a simulated request or whether it has been tampered with.

[0113] It should be noted that the above is to sign the request identifier and verify its signature information to determine whether the authorization request is a simulated request or whether it has been tampered with; in actual implementation, other parameters in the authorization request can also be signed at the same time. For example, the string obtained by splicing the request identifier, application identifier and request time can be signed. There is no special limitation here.

[0114] It can be seen that the embodiment of the present disclosure can avoid the security risks that may be caused by unnecessary responses when the authorization service is subjected to simulated attacks by configuring signature information in the authorization request based on the signature algorithm, thereby improving the security of the authorization service.

[0115] Please see Figure 6 , which is another flow chart of generating a response message provided by an embodiment of the present disclosure. Figure 6 As shown, in some embodiments, the authorization request may include the request time, the request identifier and the above-mentioned first signature information at the same time; after the authorization service receives the authorization request and verifies the authorization request based on the first signature information, the response message corresponding to the authorization request is generated according to the application identifier, the requested authorization number and the distributable authorization number, including: S601, generating a response identifier including the request time; S602, using a preset signature algorithm to sign the response identifier to obtain the second signature information; S603, generating a response message according to the response identifier, the second signature information, the application identifier, the requested authorization number and the distributable authorization number.

[0116] That is, in order to further improve the security of the authorization method provided by the embodiment of the present disclosure, in actual implementation, while verifying that the authorization request received by the authorization service has not been tampered with based on the signature algorithm, it is also possible to at least sign the response identifier in the response message sent to the application service based on the signature algorithm; after receiving such a response message, the application service can use the signature algorithm to sign the response identifier in the response message to obtain second verification signature information, and verify whether the second verification signature information and the second signature information are consistent. If they are consistent, it means that the response message has not been tampered with. Otherwise, the response message can be discarded and the authorization request can be resent.

[0117] For example, the request time may be "1651823169170", and the responseId in the response message may be "c5ece10860634dc8b2a95a068d5e2f90-1651823169170". When the number of requested authorizations is less than the number of available authorizations, the response message may be, for example: {"msg":"Request successful","code":200,"data":{"clientid":"Application ID 1","responseId":"c5ece10860634dc8b2a95a068d5e2f90-1651823169170","responseSign":"Sign3 ”}}, wherein Sign3 is obtained by signing “c5ece10860634dc8b2a95a068d5e2f90-1651823169170” using a preset signature algorithm; after the application service receives the response message, it can use the preset signature algorithm to sign the response identifier to obtain the second verification signature information Sign4. Thereafter, by verifying whether Sign3 and Sign4 are consistent, it can be verified whether the response message has been tampered with. If not, the request time in the response identifier can also be parsed to calculate the absolute value of the difference between the request time and the current time, and compare it with the preset threshold, so as to further verify whether the response message is a simulated response sent by the simulated service.

[0118] It can be seen that the authorization method provided by the embodiment of the present disclosure can further improve the security of the application service side and the authorization service side by signing the transmitted data in the authorization request and response message based on the digital signature technology.

[0119] It is understood that the above-mentioned various method embodiments mentioned in this disclosure can be combined with each other to form combined embodiments without violating the principle logic. Due to space limitations, this disclosure will not go into details. It is understood by those skilled in the art that in the above-mentioned methods of specific implementation, the specific execution order of each step should be determined by its function and possible internal logic.

[0120] In addition, the present disclosure also provides an authorization device, an electronic device, and a computer-readable storage medium, all of which can be used to implement any authorization method provided by the present disclosure. The corresponding technical solutions and descriptions are referred to the corresponding records in the method section and will not be repeated here.

[0121] Figure 7 A block diagram of an authorization device provided in an embodiment of the present disclosure.

[0122] Reference Figure 7The embodiment of the present disclosure provides an authorization device, which includes a receiving unit 701, a determining unit 702, an acquiring unit 703 and a responding unit 704.

[0123] The receiving unit 701 is configured to receive an authorization request sent by an application service to be authorized, wherein the authorization request includes an application identifier of the application service, application version information, and a requested authorization number.

[0124] The determining unit 702 is configured to determine the authorization period type at the current moment in response to the authorization request, wherein the authorization period type indicates whether the current moment is in a busy period of the application service.

[0125] The acquiring unit 703 is configured to acquire the number of allocable authorizations according to the authorization period type and the application version information, wherein the number of allocable authorizations is the number of authorizations remaining in the authorization service at the current moment and that can be allocated to the application service.

[0126] The response unit 704 is used to generate a response message corresponding to the authorization request according to the application identifier, the requested authorization number and the allocable authorization number, and send the response message to the application service, wherein the response message is used to at least indicate whether the authorization request is successful.

[0127] In some embodiments, when the response unit 704 generates a response message corresponding to the authorization request based on the application identifier, the requested authorization number and the allocable authorization number, it can be used to: when the requested authorization number is less than or equal to the allocable authorization number, allocate the requested authorization number to the application service, and generate a first response message indicating that the request is successful based on the application identifier; when the requested authorization number is greater than the allocable authorization number, generate a second response message indicating that the request failed based on the application identifier.

[0128] In some embodiments, the device 700 also includes a recovery unit, which is used to: when preset conditions are met, perform authorization number recovery processing on the number of request authorizations allocated to the application service according to the application identifier, wherein the authorization number recovery processing is used to fully or partially recover the number of authorizations allocated to the application service; wherein the preset conditions include at least one of the following: the application service is in an abnormal operating state, the authorization period type is changed from the first type to the second type, and the number of request authorizations meets the preset expiration condition; the first type indicates that the current moment is in the busy period of the application service, and the second type indicates that the current moment is not in the busy period of the application service.

[0129] In some embodiments, when the recovery unit performs authorization number recovery processing on the request authorization number allocated to the application service based on the application identifier, it can be used to: obtain authorization information corresponding to the application service from the database based on the application identifier, wherein the authorization information is generated and stored in the database in the process of allocating the request authorization number to the application service, and the authorization information includes at least the application identifier and the request authorization number; clear the authorization information in the database, or reduce the value of the request authorization number in the authorization information to complete the authorization number recovery processing.

[0130] In some embodiments, the authorization request also includes the request time of the authorization request; when the response unit 704 generates a response message corresponding to the authorization request based on the application identifier, the requested authorization number and the distributable authorization number, it can be used to: generate a response identifier including the request time, wherein the request time in the response identifier is used by the application service to verify whether the response message is a simulated response; generate a response message based on the application identifier, the response identifier, the requested authorization number and the distributable authorization number.

[0131] In some embodiments, the authorization request also includes a request identifier and a first signature information of the authorization request, wherein the first signature information is generated by the application service after signing the request identifier based on a preset signature algorithm; the device 700 also includes a verification unit, which is used to: after receiving the authorization request, use the preset signature algorithm to sign the request identifier to obtain the first verification signature information; verify whether the first verification signature information and the first signature information are consistent; if the verification is consistent, execute the step of responding to the authorization request to determine the authorization period type at the current moment.

[0132] In some embodiments, when the determination unit 702 obtains the number of distributable authorizations based on the authorization period type and application version information, it can be used to: obtain the number of distributed authorizations corresponding to the application service based on the application version information; when the authorization period type is the first type, obtain the first total number of authorizations corresponding to the application service, and obtain the number of distributable authorizations based on the first total number of authorizations and the number of distributed authorizations; when the authorization period type is the second type, obtain the second total number of authorizations corresponding to the application service, and obtain the number of distributable authorizations based on the second total number of authorizations and the number of distributed authorizations; wherein the first type indicates that the current moment is in a busy period of the application service, and the second type indicates that the current moment is not in a busy period of the application service.

[0133] Figure 8 A block diagram of an electronic device provided in an embodiment of the present disclosure.

[0134] Reference Figure 8An embodiment of the present disclosure provides an electronic device, which includes: at least one processor 801; at least one memory 802, and one or more I / O interfaces 803, connected between the processor 801 and the memory 802; wherein the memory 802 stores one or more computer programs that can be executed by the at least one processor 801, and the one or more computer programs are executed by the at least one processor 801 to enable the at least one processor 801 to perform the above-mentioned authorization method.

[0135] The present disclosure also provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the above-mentioned authorization method when executed by a processor. The computer-readable storage medium may be a volatile or non-volatile computer-readable storage medium.

[0136] An embodiment of the present disclosure also provides a computer program product, including a computer-readable code, or a non-volatile computer-readable storage medium carrying the computer-readable code. When the computer-readable code runs in a processor of an electronic device, the processor in the electronic device executes the above-mentioned authorization method.

[0137] It will be understood by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In a hardware implementation, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or may be implemented as hardware, or may be implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable storage medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium).

[0138] As is well known to those skilled in the art, the term computer storage media includes volatile and nonvolatile, removable and non-removable media implemented in any method or technology for storage of information (such as computer-readable program instructions, data structures, program modules or other data). Computer storage media includes, but is not limited to, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM), static random access memory (SRAM), flash memory or other memory technology, portable compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical disc storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, as is well known to those skilled in the art, communication media typically contains computer-readable program instructions, data structures, program modules or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0139] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, fiber optic transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions to be stored in the computer-readable storage medium in each computing / processing device.

[0140] The computer program instructions for performing the operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Smalltalk, C++, and conventional procedural programming languages ​​such as "C" language or similar programming languages. Computer-readable program instructions may be executed entirely on a user's computer, partially on a user's computer, as an independent software package, partially on a user's computer, partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., utilizing an Internet service provider to connect via the Internet). In some embodiments, an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may be personalized by utilizing the state information of the computer-readable program instructions. The electronic circuit may execute the computer-readable program instructions, thereby realizing various aspects of the present disclosure.

[0141] The computer program product described herein may be implemented in hardware, software, or a combination thereof. In one embodiment, the computer program product is implemented as a computer storage medium. In another embodiment, the computer program product is implemented as a software product, such as a software development kit (SDK).

[0142] Various aspects of the present disclosure are described herein with reference to flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.

[0143] These computer-readable program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, thereby producing a machine, so that when these instructions are executed by the processor of the computer or other programmable data processing device, a device is generated that implements the functions / actions specified in one or more blocks in the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium, where these instructions cause the computer, programmable data processing device, and / or other device to operate in a specific manner. Thus, the computer-readable medium storing the instructions comprises an article of manufacture that includes instructions for implementing various aspects of the functions / actions specified in one or more blocks in the flowchart and / or block diagram.

[0144] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device so that a series of operational steps are performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process, thereby causing the instructions executed on the computer, other programmable data processing apparatus, or other device to implement the functions / actions specified in one or more blocks in the flowchart and / or block diagram.

[0145] The flow charts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the systems, methods and computer program products according to multiple embodiments of the present disclosure. In this regard, each box in the flow chart or block diagram can represent a part of a module, program segment or instruction, and the part of the module, program segment or instruction contains one or more executable instructions for realizing the prescribed logical function. In some alternative implementations, the functions marked in the box can also occur in a sequence different from that marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the prescribed function or action, or can be implemented by a combination of dedicated hardware and computer instructions.

[0146] Example embodiments have been disclosed herein, and although specific terms are employed, they are used and should be interpreted only in a general illustrative sense and not for purposes of limitation. In some instances, it will be apparent to those skilled in the art that, unless otherwise expressly indicated, features, characteristics, and / or elements described in conjunction with a particular embodiment may be used alone or in combination with features, characteristics, and / or elements described in conjunction with other embodiments. Therefore, it will be understood by those skilled in the art that various changes in form and detail may be made without departing from the scope of the present disclosure as set forth in the appended claims.

Claims

1. An authorization method, characterized in that: include: Receive an authorization request sent by an application service to be authorized, wherein the authorization request includes an application identifier of the application service, application version information, and a requested authorization number, where the requested authorization number is the number of users requesting authorization; In response to the authorization request, determining an authorization period type at a current moment, wherein the authorization period type indicates whether the current moment is in a busy period of the application service; According to the authorization period type and the application version information, the number of allocable authorizations is obtained, wherein the number of allocable authorizations is the number of authorizations remaining in the authorization service at the current moment and that can be allocated to the application service; Generate a response message corresponding to the authorization request according to the application identifier, the requested authorization number, and the allocable authorization number, and send the response message to the application service, wherein the response message is used to at least indicate whether the authorization request is successful; The obtaining of the number of allocable authorizations according to the authorization period type and the application version information includes: According to the application version information, obtain the number of allocated authorizations corresponding to the application service, The total number of authorizations for the authorization period corresponding to the application service is obtained according to the authorization period type, and the number of allocable authorizations is obtained according to the total number of authorizations and the number of allocable authorizations.

2. The method according to claim 1, characterized in that The generating, according to the application identifier, the requested authorization number, and the allocable authorization number, a response message corresponding to the authorization request includes: In a case where the requested authorization number is less than or equal to the allocable authorization number, allocating the requested authorization number to the application service, and generating a first response message indicating a successful request according to the application identifier; In a case where the number of requested authorizations is greater than the number of allocable authorizations, a second response message indicating that the request has failed is generated according to the application identifier.

3. The method according to claim 1 or 2, characterized in that If the response message indicates that the request is successful, the method further includes: When a preset condition is met, performing authorization number recovery processing on the request authorization number allocated to the application service according to the application identifier, wherein the authorization number recovery processing is used to recover all or part of the authorization number allocated to the application service; Among them, the preset conditions include at least one of the following: the application service is in an abnormal operating state, the authorization period type is changed from the first type to the second type, and the number of requested authorizations meets the preset expiration conditions; the first type indicates that the current moment is in a busy period of the application service, and the second type indicates that the current moment is not in a busy period of the application service.

4. The method according to claim 3, characterized in that The step of recovering the number of request authorizations allocated to the application service according to the application identifier includes: Obtaining authorization information corresponding to the application service from a database based on the application identifier, wherein the authorization information is generated and stored in the database during the process of allocating the requested authorization number to the application service, and the authorization information includes at least the application identifier and the requested authorization number; The authorization information in the database is cleared, or the value of the requested authorization number in the authorization information is reduced to complete the authorization number recovery process.

5. The method according to claim 1, wherein The authorization request also includes the request time of the authorization request; The generating, according to the application identifier, the requested authorization number, and the allocable authorization number, a response message corresponding to the authorization request includes: generating a response identifier including the request time, wherein the request time in the response identifier is used by the application service to verify whether the response message is a simulated response; The response message is generated according to the application identifier, the response identifier, the requested authorization number and the distributable authorization number.

6. The method according to claim 1, characterized in that The authorization request also includes a request identifier and first signature information of the authorization request, wherein the first signature information is generated by the application service after signing the request identifier based on a preset signature algorithm; After receiving the authorization request, the method further includes: Use the preset signature algorithm to sign the request identifier to obtain first verification signature information; If the first verification signature information and the first signature information are verified to be consistent, the step of determining the authorization period type at the current moment in response to the authorization request is performed.

7. The method according to claim 1, characterized in that The obtaining, according to the authorization period type, the total number of authorizations for the application service corresponding to the authorization period includes: In the case where the authorization period type is the first type, the total number of authorizations corresponding to the application service is obtained as the first total number of authorizations; In the case where the authorization period type is the second type, the total number of authorizations corresponding to the application service is obtained as the second total number of authorizations; The acquiring the number of allocable authorizations according to the total number of authorizations and the number of allocable authorizations includes: Obtaining the number of allocable authorizations according to the first total number of authorizations and the number of allocable authorizations; or Obtaining the allocable number of authorizations according to the second total number of authorizations and the number of allocable authorizations; The first type indicates that the current moment is in a busy period of the application service, and the second type indicates that the current moment is not in a busy period of the application service.

8. An authorization device, characterized in that: include: a receiving unit, configured to receive an authorization request sent by an application service to be authorized, wherein the authorization request includes an application identifier of the application service, application version information, and a requested authorization number, where the requested authorization number is the number of users requesting authorization; a determining unit, configured to determine, in response to the authorization request, an authorization period type at a current moment, wherein the authorization period type indicates whether the current moment is in a busy period of the application service; an acquiring unit, configured to acquire the number of allocable authorizations according to the authorization period type and the application version information, wherein the number of allocable authorizations is the number of authorizations remaining in the authorization service at the current moment and that can be allocated to the application service; a response unit, configured to generate a response message corresponding to the authorization request according to the application identifier, the requested authorization number, and the allocable authorization number, and send the response message to the application service, wherein the response message is used to at least indicate whether the authorization request is successful; Among them, when the acquisition unit obtains the number of distributable authorizations based on the authorization period type and the application version information, it is used to: obtain the number of distributed authorizations corresponding to the application service based on the application version information, obtain the total number of authorizations for the authorization period corresponding to the application service based on the authorization period type, and obtain the distributable authorizations based on the total number of authorizations and the number of distributed authorizations.

9. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores one or more computer programs executable by the at least one processor, and the one or more computer programs are executed by the at least one processor to enable the at least one processor to perform the authorization method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the computer program implements the authorization method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Software starting method, software authorization verification method, equipment and storage medium

    CN109684790A

  • Authorization management method and device

    CN111597545A

  • Software authorization method and device based on container cluster and storage medium

    CN115248907A

  • Software use monitoring system and method

    CN1635437A