A method and system for authentication control processing based on a gateway
Authentication control is performed through the gateway, and user signatures and identity token information are used for authentication and encrypted transmission, which solves the problems of cumbersome configuration and security risks in multi-business systems, and realizes the refinement of permission control and the improvement of data security.
Patent Information
- Application Number
- CN202311839956.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-28
- Publication Date
- 2025-10-24
- Estimated Expiration
- 2043-12-28
AI Technical Summary
In the authentication control management of multi-business systems, the access requirements of the same user lead to cumbersome configuration operations, low resource utilization, and the risk of data leakage.
Authentication control is performed through the gateway, using user signature and identity token information for authentication, and compared with the pre-configured information in the database and cache to achieve refined permission control and encrypted transmission, providing a unified access portal.
It simplifies permission configuration operations, improves system resource utilization, reduces the risk of configuration errors, and enhances data security.
Smart Images

Figure CN117978445B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of data security, and more particularly, to a method and system for authentication control processing based on a gateway. BACKGROUND
[0002] In existing service platforms, many are unified management platforms supporting individualized configuration of various service systems. The configuration in the system supports configuration of requirements according to user publishing permissions. When the configuration of a user takes effect, the user makes a request for access to a specified interface of a service system in the subsequent stage, and authentication control processing is performed according to the configured permission information. The request meeting the permission configuration is released, and the request not meeting the permission configuration is intercepted and returned.
[0003] At present, with the expansion of services and the increase in the number of users, the number of external interfaces of various service systems that need to be subjected to authentication control management gradually increases, and the configuration operation of user permission information gradually becomes more complex, requiring more configuration operations, which can easily cause configuration errors of operation personnel, thereby affecting the access request of the user, and more seriously, causing data leakage and security problems.
[0004] There are many traditional configuration and authentication methods for request permission control, such as using a database or using cache technology to maintain a black and white list information table, and performing identity token verification on a request. However, the above application scenarios have the problems of resource waste caused by overlapping of multiple user configuration information, complicated configuration operation, and coarse-grained permission control. Specifically, the permission of different users cannot be fully configured and identified; since it is necessary to meet the individualized permission control requirements published by specific users, user rights can only be created according to various service systems, and black and white lists are maintained. However, the same user has request access requirements in multiple service systems, resulting in repeated and complicated configuration and authentication operations, and low resource utilization. SUMMARY
[0005] In order to solve the technical problem in the prior art that when the same user has request access requirements in multiple service systems, rights are configured for each service system, which can easily lead to repeated and complicated configuration and authentication operations, and low resource utilization, the present application provides a method and system for authentication control processing based on a gateway.
[0006] According to an aspect of the present application, the present application provides a method for authentication control processing based on a gateway, the method comprising:
[0007] The gateway obtains an access request sent by a user, wherein the access request includes a user signature, identity token information, a service system to be accessed, and a service data packet corresponding to the service system to be accessed and encrypted;
[0008] The gateway parses the access request, obtains user signature, identity token information, a business system to be accessed, and a business data packet corresponding to the business system to be accessed and encrypted;
[0009] The gateway queries a request routing, authenticates the user according to the user signature and the identity token information when the business system to be accessed exists, and generates an authentication result, wherein the authentication result includes authentication pass and authentication fail;
[0010] When the authentication result is authentication pass, user information and right configuration information bound with the identity token information are obtained.
[0011] The right configuration information is compared with preconfigured information in a database and a cache to generate a comparison result, wherein the comparison result includes comparison consistent and comparison inconsistent.
[0012] When the comparison result is comparison consistent, the gateway receives response information returned by the business system to be accessed based on the business data packet, and returns an access result generated according to the response information to the user.
[0013] According to another aspect of the present application, the present application provides a system for performing authentication control processing based on a gateway, the system comprising:
[0014] A client for generating an access request of a user and sending the access request to a gateway, wherein the access request includes user signature, identity token information, a business system to be accessed, and a business data packet corresponding to the business system to be accessed and encrypted;
[0015] The gateway receives and parses the access request, obtains user signature, identity token information, a business system to be accessed, and a business data packet corresponding to the business system to be accessed and encrypted, queries a request routing, authenticates the user according to the user signature and the identity token information when the business system to be accessed exists, generates an authentication result, obtains user information and right configuration information bound with the identity token information when the authentication result is authentication pass, compares the right configuration information with preconfigured information in a database and a cache to generate a comparison result, and receives response information returned by the business system to be accessed based on the business data packet when the comparison result is comparison consistent, and returns an access result generated according to the response information to the client, wherein the authentication result includes authentication pass and authentication fail, and the comparison result includes comparison consistent and comparison inconsistent.
[0016] A plurality of business systems for generating response information according to a business data packet sent by the gateway, and returning the response information to the gateway.
[0017] According to still another aspect of the present application, the present application provides a computer readable storage medium storing a computer program for executing the method according to any one of the above aspects of the present application.
[0018] According to still another aspect of the present application, an electronic device is provided, comprising: a processor; a memory for storing executable instructions for the processor; the processor is configured to read the executable instructions from the memory and execute the instructions to implement the method according to any one of the above aspects of the present application.
[0019] The method and system for authentication control processing based on a gateway according to the present application, wherein the method comprises: a gateway obtaining an access request sent by a user; the gateway parsing the access request to obtain a user signature, identity token information, a service system to be accessed, and an encrypted service data packet corresponding to the service system to be accessed; the gateway querying a request route, and when the service system to be accessed exists, authenticating the user according to the user signature and the identity token information to generate an authentication result; when the authentication result is authentication passed, obtaining user information and right configuration information bound to the identity token information; comparing the right configuration information with preconfigured information in a database and a cache to generate a comparison result; when the comparison result is consistent, the gateway receiving response information returned by the service system to be accessed based on the service data packet, and returning an access result generated according to the response information to the user. The method and system bind user information and right configuration information by using identity token information, solve the control problem of individualized demand of permission control, reduce the occupation of system resources, provide a standard and unified external channel by taking the gateway as a unified entrance for access of various service systems, improve the efficiency of service processing, and solve the data security problem in communication through the signing and encryption operation on the access request and the response information. BRIEF DESCRIPTION OF DRAWINGS
[0020] The exemplary embodiments of the present application can be more fully understood with reference to the following drawings:
[0021] Figure 1 A flowchart of the method for authentication control processing based on a gateway according to the preferred embodiment of the present application;
[0022] Figure 2 A structural schematic diagram of the system for authentication control processing based on a gateway according to the preferred embodiment of the present application;
[0023] Figure 3 A structural schematic diagram of the electronic device according to the preferred embodiment of the present application. DETAILED DESCRIPTION
[0024] For a better understanding of the present application, reference will be made to the preferred embodiments, examples of which are illustrated in the accompanying drawings. The application can be implemented in numerous ways, including the described embodiments, and not limited to the embodiments described herein, which are presented as examples of the application and to fully and effectively disclose the application and to convey its scope to those skilled in the art. The terminology used in the description presented herein is not intended to be limiting. Rather, the terminology is used solely by way of reference to assist in comprehension of the teachings. Throughout the specification, like reference numerals will be understood to refer to like parts throughout the specification and the drawings.
[0025] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the relevant art and will not be interpreted in an idealized or overly formal sense unless expressly so defined herein.
[0026] Exemplary method
[0027] Figure 1 A flow chart of a method for gateway-based authentication control processing according to a preferred embodiment of the present application. As shown in FIG. 1, the method for gateway-based authentication control processing according to the preferred embodiment of the present application starts from step 101. Figure 1
[0028] In step 101, the gateway obtains an access request sent by a user, wherein the access request includes a user signature, identity token information, a service system to be accessed, and a service data packet corresponding to the service system to be accessed and encrypted.
[0029] Preferably, the gateway obtaining the access request sent by the user further includes:
[0030] The service system sets a service code for a service function provided by the service system and sets an interface ID for an interface calling the service function;
[0031] The user code is configured according to the identity information of the user, and user information including the user code, key data, and registration code is generated;
[0032] When the user makes a right configuration request based on the user code, the right configuration is performed according to the right configuration request, and right configuration information is generated, wherein the right configuration information includes a service code of a service function configured for the user, an interface ID of an interface called, and corresponding permission information;
[0033] When the user makes a request for an identity token based on the user code, the identity token information is generated, and the identity token information is bound to the user token and the right configuration information.
[0034] In the preferred embodiment, the business system usually provides a certain service function for the user through the external interface, and therefore different service codes are set according to different service functions, and different interface IDs are defined for the interface under the service function to identify the specific interface. The user of the business system includes not only the enterprise platform but also the customer, and correspondingly, when setting the user code, the platform code is set for the platform, and for the customer, the corresponding code is set according to the nature of the customer, for example, if it is a taxpaying enterprise, the user code can be the enterprise tax number. In summary, on the one hand, the business system is maintained and managed through the service code and the interface ID, and on the other hand, the user of the business system is managed through the user number.
[0035] When configuring the rights and interests according to the personalized needs of the user, the corresponding relationship between the user code, the service code, and the interface ID is established, and the corresponding permission information is configured, and a complete rights and interests configuration information is generated. For example, the interface with the interface ID TEST.001 under the service code 001 is configured for the user with the platform code A0000001, and the corresponding permission information such as the validity period, the enable state, the number of calls, the amount of money, and the like is configured, and the information including all the above contents is a complete rights and interests configuration information.
[0036] As can be seen, in the method, the corresponding relationship between the service code, the interface ID, and the user code is established, the rights and interests configuration information is verified under the premise that the corresponding relationship can be correctly obtained, the granularity range of the permission control is refined, and the operation of the configuration is simplified.
[0037] In step 102, the gateway parses the access request, obtains the user signature, the identity token information, the business system to be accessed, and the encrypted business data packet corresponding to the business system to be accessed.
[0038] In step 103, the gateway queries the request route, authenticates the user according to the user signature and the identity token information when the business system to be accessed exists, and generates an authentication result, wherein the authentication result includes authentication pass and authentication fail.
[0039] Preferably, the authentication of the user according to the user signature and the identity token information to generate the authentication result includes:
[0040] verifying the user signature of the user to generate a verification result, wherein the verification result includes verification pass and verification fail;
[0041] When the verification result is verification pass, the gateway calls the identity token verification interface according to the identity token information to authenticate the user identity, and generates an authentication result.
[0042] In the preferred embodiment, the method of identity token authentication binds the benefit allocation token with the identity token, simplifies the request message, and reduces resource consumption.
[0043] In step 104, when the authentication result is authentication pass, the user information and the benefit allocation information bound with the identity token information are obtained.
[0044] In step 105, the benefit allocation information is compared with the preconfigured information in the database and the cache to generate a comparison result, wherein the comparison result includes comparison consistent and comparison inconsistent.
[0045] In step 106, when the comparison result is comparison consistent, the gateway receives the response information returned by the business system based on the business data packet, and returns the access result generated according to the response information to the user.
[0046] Preferably, when the comparison result is comparison consistent, the gateway receives the response information returned by the business system based on the business data packet, and returns the access result generated according to the response information to the user, including:
[0047] When the comparison result is comparison consistent, the business data packet is decrypted by calling the CA encryption and decryption service according to the key data in the user information;
[0048] The decrypted business data is forwarded to the business system to be accessed for processing;
[0049] The response information returned by the business system to be accessed is received, and the CA encryption and decryption service is called to encrypt the response information;
[0050] The encrypted response information is signed according to the registration code in the user information;
[0051] The encrypted and signed response information is returned to the user as the access result.
[0052] In the preferred embodiment, the encryption and signature operation on the access request and the response information returned by the business system effectively solves the data security problem in communication.
[0053] In summary, the method of authentication control processing based on the gateway in the preferred embodiment of the application realizes authentication control processing with the help of the gateway, meets the personalized needs of users, solves possible security problems, and greatly improves the stability of the system.
[0054] Exemplary system
[0055] Figure 2 The structure of the system for authentication control processing based on the gateway according to the preferred embodiment of the application is shown in the schematic diagram. As shown inFigure 2 As shown, the system for authentication control processing based on the gateway in the preferred embodiment includes:
[0056] The client 201 is configured to generate an access request of a user and send the access request to the gateway, wherein the access request includes a user signature, identity token information, a service system to be accessed, and a service data packet corresponding to the service system to be accessed and encrypted;
[0057] The gateway 202 is configured to receive and parse the access request, obtain the user signature, the identity token information, the service system to be accessed, and the service data packet corresponding to the service system to be accessed and encrypted, query a request route, authenticate the user according to the user signature and the identity token information when the service system to be accessed exists, generate an authentication result, obtain user information and right configuration information bound to the identity token information when the authentication result is authentication passed, compare the right configuration information with preconfigured information in a database and a cache, generate a comparison result, receive response information returned by the service system to be accessed based on the service data packet when the comparison result is consistent, and return an access result generated according to the response information to the client, wherein the authentication result includes authentication passed and authentication failed, and the comparison result includes consistent and inconsistent.
[0058] The plurality of service systems 203 are configured to generate response information according to the service data packet sent by the gateway and return the response information to the gateway.
[0059] Preferably, the service system 203 is further configured to:
[0060] set a service code for a service function provided thereby and set an interface ID for an interface calling the service function;
[0061] configure a user code according to identity information of the user and generate user information including the user code, key data, and a registration code;
[0062] configure rights according to the right configuration request when the user proposes a right configuration request based on the user code, generate right configuration information, and wherein the right configuration information includes a service code of a service function configured for the user, an interface ID of an interface called, and corresponding permission information;
[0063] generate identity token information when the user proposes a request for an identity token based on the user code, and bind the identity token information to the user token and the right configuration information.
[0064] Preferably, the gateway 202 authenticates the user according to the user signature and identity token information, generates an authentication result, including:
[0065] The gateway verifies the user signature of the user, generates a verification result, and the verification result includes verification pass and verification fail;
[0066] When the verification result is verification pass, the gateway calls an identity token verification interface according to the identity token information to perform user identity authentication, and generates an authentication result.
[0067] Preferably, when the comparison result is consistent, the gateway 202 receives response information returned by the business system to be accessed based on the business data packet, and returns an access result generated according to the response information to the client, including:
[0068] When the comparison result is consistent, the gateway decrypts the business data packet according to the key data in the user information by calling the CA encryption and decryption service;
[0069] The gateway forwards the decrypted business data to the business system to be accessed for processing;
[0070] The gateway receives the response information returned by the business system to be accessed, and calls the CA encryption and decryption service to encrypt the response information;
[0071] The gateway signs the encrypted response information according to the registration code in the user information;
[0072] The gateway returns the encrypted and signed response information as an access result to the client.
[0073] The system for performing authentication control processing based on the gateway according to the preferred embodiment of the present application has the same steps of performing authentication control processing on the access request sent by the user through the client by the gateway as the steps of the method for performing authentication control processing based on the gateway, and achieves the same technical effects, which will not be repeated here.
[0074] Exemplary electronic device
[0075] Figure 3 A structural schematic diagram of an electronic device according to the preferred embodiment of the present application. The electronic device can be either one or both of the first device and the second device, or a single device independent of them, which can communicate with the first device and the second device to receive the collected input signals therefrom. Figure 3 A block diagram of an electronic device according to an embodiment of the present disclosure is shown. As shown in Figure 3 The electronic device includes one or more processors 301 and a memory 302.
[0076] The processor 301 can be a central processing unit (CPU) or other form of processing unit having data processing and / or instruction execution capabilities and can control other components in the electronic device to perform desired functions.
[0077] The memory 302 can include one or more computer program products that can include various forms of computer-readable storage media, such as volatile memory and / or non-volatile memory. The volatile memory, for example, can include random access memory (RAM), cache memory, and / or the like. The non-volatile memory, for example, can include read-only memory (ROM), hard disk, flash memory, and / or the like. One or more computer program instructions can be stored on the computer-readable storage media, and the processor 301 can execute the program instructions to implement the enterprise energy-consuming space-based energy anomaly diagnosis method and / or other desired functions of the various embodiments disclosed above. In one example, the electronic device can further include an input device 303 and an output device 304, which are interconnected through a bus system and / or other forms of connection mechanisms (not shown).
[0078] In addition, the input device 303 can further include, for example, a keyboard, a mouse, and / or the like.
[0079] The output device 304 can output various information to the outside. The output device 304 can include, for example, a display, a speaker, a printer, a communication network and a remote output device connected thereto, and / or the like.
[0080] Of course, in order to simplify, Figure 3 Only some of the components in the electronic device related to the present disclosure are shown in FIG. 3, and components such as buses, input / output interfaces, and / or the like are omitted. In addition, the electronic device can further include any other appropriate components according to specific application cases.
[0081] Exemplary computer program product and computer readable storage medium
[0082] In addition to the above-described method and device, embodiments of the present disclosure can be a computer program product including computer program instructions that, when executed by a processor, cause the processor to perform the steps of the method of gateway-based authentication control processing according to various embodiments of the present disclosure described in the above "Exemplary Method" section of the specification.
[0083] The computer program product can be written in any combination of one or more programming languages, including an object oriented programming language such as Java, C++ or the like, and conventional procedural programming languages, such as the "C" programming language or similar programming languages. The program code can execute entirely on the user's computing device, partly on the user's device, as a stand-alone software package, partly on the user's computing device and partly on a remote computing device or entirely on the remote computing device or server.
[0084] Furthermore, embodiments of the present disclosure can also be a computer readable storage medium, having stored thereon computer program instructions which, when executed by a processor, cause the processor to perform the steps of the method described in the above “Exemplary Method” section of the present specification for performing gateway-based authentication control processing according to various embodiments of the present disclosure.
[0085] The computer readable storage medium can be any combination of one or more computer readable media. The computer readable medium can be a computer readable signal medium or a computer readable storage medium. A computer readable storage medium can be, for example, but not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer readable storage medium include an electrical connection having one or more wires, a portable disc, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0086] The above describes the basic principles of the present disclosure in combination with specific embodiments, but it should be noted that the advantages, benefits, effects and the like mentioned in the present disclosure are only examples and are not limiting, and these advantages, benefits, effects and the like cannot be considered as necessary for each embodiment of the present disclosure. In addition, the above specific details are only for the purpose of example and understanding, and the above details do not limit the present disclosure to the above specific details.
[0087] Each embodiment in the present specification is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between each embodiment can be understood by mutual reference. For system embodiments, since they are basically corresponding to method embodiments, the description is relatively simple, and the relevant parts can be understood by referring to the part of the method embodiment.
[0088] The block diagrams of devices, apparatuses, equipment, systems referred to in this disclosure are merely illustrative examples and are not intended to require or imply that the connection, arrangement, configuration must be as shown in the block diagrams. These devices, apparatuses, equipment, systems can be connected, arranged, configured in any manner as will be appreciated by those skilled in the art. Words such as "include," "contain," "have," and the like are open-ended words that are to be interpreted to mean "including but not limited to," and are not to be interpreted as limiting the described embodiment to features, elements, and / or steps disclosed herein. The words "or" and "and" as used herein are to be interpreted as the word "and / or," and are not to be interpreted as requiring both features, elements, and / or steps disclosed herein. The word "such as" as used herein is to be interpreted as the phrase "such as but not limited to," and is not to be interpreted as limiting the described embodiment to features, elements, and / or steps disclosed herein.
[0089] The methods and apparatuses of this disclosure can be implemented in a number of ways. For example, the methods and apparatuses of this disclosure can be implemented using software, hardware, firmware, or any combination of these. The above described order of steps for the methods is merely illustrative, and the steps of the methods of this disclosure are not limited to the order specifically described above unless otherwise specifically stated. Furthermore, in some embodiments, the disclosure can also be implemented as a program recorded in a recording medium, which includes machine readable instructions for implementing the methods according to the disclosure. Thus, the disclosure also covers a recording medium storing a program for executing the methods according to the disclosure.
[0090] It is also important to note that the devices, equipment, and methods of this disclosure can be embodied in a variety of ways. These variations are contemplated as being within the scope of the present disclosure. The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use the disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the generic principles defined herein can be applied to other aspects without departing from the scope of the disclosure. Thus, the present disclosure is not intended to be limited to the aspects shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
[0091] The above description has been given for the purpose of illustration and description. Furthermore, this description does not purport to be exhaustive or to limit the embodiments of the disclosure to the precise forms disclosed. Although various example aspects and embodiments have been discussed above, those of ordinary skill in the art will readily appreciate that some variations, modifications, changes, additions, and sub-combinations of the aspects discussed above can be made without departing from the scope of the disclosure.
Claims
1. A method for authentication control processing based on a gateway, characterized by, The method comprises: The gateway obtains an access request sent by a user, wherein the access request comprises a user signature, identity token information, a service system to be accessed, and an encrypted service data packet corresponding to the service system to be accessed; The gateway parses the access request to obtain the user signature, the identity token information, the service system to be accessed, and the encrypted service data packet corresponding to the service system to be accessed; The gateway queries a request route, authenticates the user according to the user signature and the identity token information when the service system to be accessed exists, and generates an authentication result, wherein the authentication result comprises authentication pass and authentication fail; When the authentication result is authentication pass, user information and right configuration information bound to the identity token information are obtained; The right configuration information is compared with preconfigured information in a database and a cache to generate a comparison result, wherein the comparison result comprises comparison consistent and comparison inconsistent; When the comparison result is comparison consistent, the gateway receives response information returned by the service system to be accessed based on the service data packet, and returns an access result generated according to the response information to the user, comprising: When the comparison result is comparison consistent, the CA encryption and decryption service is called to decrypt the service data packet according to key data in the user information; The decrypted service data is forwarded to the service system to be accessed for processing; The response information returned by the service system to be accessed is received, and the CA encryption and decryption service is called to encrypt the response information; The encrypted response information is signed according to a registration code in the user information; The encrypted and signed response information is returned to the user as the access result.
2. The method of claim 1, wherein, Before the gateway obtains the access request sent by the user, the method further comprises: A service system sets a service code for a service function provided by the service system, and sets an interface ID for an interface calling the service function; User information comprising a user code, key data, and a registration code is generated according to the identity information of the user; When the user proposes a right configuration request based on the user code, right configuration is performed according to the right configuration request to generate right configuration information, wherein the right configuration information comprises a service code of a service function configured for the user, an interface ID of an interface called, and corresponding permission information; When the user proposes a request for applying for an identity token based on the user code, identity token information is generated, and the identity token information is bound to the user information and the right configuration information.
3. The method of claim 1, wherein, The authentication of the user according to the user signature and the identity token information to generate an authentication result comprises: The user signature of the user is verified to generate a verification result, wherein the verification result comprises verification pass and verification fail; When the verification result is verification pass, the gateway calls an identity token verification interface according to the identity token information to perform user identity authentication to generate an authentication result.
4. A system for authentication control processing based on a gateway, characterized by, The system comprises: A client generates an access request of a user and sends the access request to a gateway, wherein the access request includes a user signature, identity token information, a service system to be accessed, and a service data packet corresponding to the service system to be accessed and encrypted; The gateway receives and parses the access request, obtains the user signature, the identity token information, the service system to be accessed, and the service data packet corresponding to the service system to be accessed and encrypted, queries a request route, authenticates the user according to the user signature and the identity token information when the service system to be accessed exists, generates an authentication result, compares the benefit configuration information with preconfigured information in a database and a cache when the authentication result is authentication passed, generates a comparison result, wherein the authentication result includes authentication passed and authentication not passed, and the comparison result includes comparison consistent and comparison inconsistent, receives response information returned by the service system to be accessed based on the service data packet when the comparison result is comparison consistent, and returns an access result generated according to the response information to the client, including: decrypting the service data packet according to key data in the user information when the comparison result is comparison consistent; forwarding the decrypted service data to the service system to be accessed for processing; receiving the response information returned by the service system to be accessed and calling a CA encryption and decryption service to encrypt the response information; signing the encrypted response information according to a registration code in the user information; returning the encrypted and signed response information as the access result to the user; A plurality of service systems generate response information according to the service data packet sent by the gateway and return the response information to the gateway.
5. The system of claim 4, wherein, The service system is further configured to: set a service code for a service function provided by the service system and set an interface ID for an interface calling the service function; configure a user code according to user identity information and generate user information including the user code, key data, and a registration code; configure benefits according to a benefit configuration request of the user based on the user code, generate benefit configuration information, wherein the benefit configuration information includes a service code of a service function configured for the user, an interface ID of a calling interface, and corresponding permission information; generate identity token information when the user requests an identity token based on the user code, and bind the identity token information with the user information and the benefit configuration information.
6. The system of claim 4, wherein, The gateway authenticates the user according to the user signature and the identity token information, and generates an authentication result, including: The gateway verifies the user signature of the user, generates a verification result, and the verification result includes verification passed and verification not passed; The gateway calls an identity token verification interface to authenticate the user identity according to the identity token information when the verification result is verification passed, and generates an authentication result.
7. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, and the computer program is used to execute the method in any one of claims 1-3.
8. An electronic device, comprising: The electronic device comprises: a processor; a memory for storing executable instructions for the processor; the processor is configured to read the executable instructions from the memory and execute the instructions to implement the method of any one of claims 1-3.
Citation Information
Patent Citations
Method and system for realizing micro-service gateway authentication
CN113055367A
Microservice gateway authentication method, device, equipment and medium
CN115643061A