Unified gateway-based horizontal unauthorized verification method, apparatus and device, and medium

By performing token verification, user information acquisition and sectional annotation on the unified gateway, the problem of insufficient service-level security authentication and level overreach in the existing technology is solved, and higher system security and reliability are achieved.

CN119966671APending Publication Date: 2025-05-09HUNAN SANXIANG BANK CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510009026.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-03
Publication Date
2025-05-09

AI Technical Summary

Technical Problem

The existing unified gateway technical solutions have weak support for business-level security certification and level overreach.

Method used

By implementing token verification, user information acquisition and facet annotation on the unified gateway, the level of service traffic is overright verification.

Benefits of technology

It improves the security and reliability of the system, provides efficient traffic management and security guarantees, and supports business-level security certification and level overreach.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966671A_ABST
    Figure CN119966671A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of micro-service system clusters, and discloses a horizontal unauthorized verification method and device based on a unified gateway, equipment and a medium, and the method comprises the steps: setting an entrance of service flow at a pre-constructed gateway; performing token verification on the service flow on a pre-constructed gateway, and judging whether the service flow has an effective token or not; when the service traffic has the effective token, acquiring user information requesting the token from the cache; transferring the user information to the request; and performing section annotation on the request by using the identification field so as to perform horizontal unauthorized verification on the request to obtain a verification result. According to the method, the gateway pair with the unified flow inlet is utilized, horizontal unauthorized verification is achieved, service flow is managed in a unified mode through the gateways, the safety and reliability of the system are improved, and an efficient flow management and safety guarantee method is provided for a micro-service system cluster; and support for service-level security authentication and level unauthorized is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of microservice system clusters, and in particular to a horizontal over-authorization verification method, device, equipment and medium based on a unified gateway. Background Art

[0002] As the entrance to microservices, the gateway needs to verify whether the user is eligible to make a request, and intercept it if not. All requests must first pass through the gateway, but the gateway does not process the business. Instead, it forwards the request to a microservice according to certain rules. This process is called routing. Of course, when there are multiple target services for the route, load balancing is also required. When the request traffic is too high, the gateway releases the request at a speed that the downstream microservice can accept to avoid excessive service pressure.

[0003] Among the related technologies, the existing unified gateway technology solutions mainly realize functions such as service routing, traffic control, fuse protection, and load balancing, but their support for business-level security authentication and horizontal unauthorized access is relatively weak. Summary of the invention

[0004] In view of this, the present invention provides a horizontal override verification method, device, equipment and medium based on a unified gateway to solve the problem that the existing unified gateway technical solution has weak support for business-level security authentication and horizontal override.

[0005] In a first aspect, the present invention provides a horizontal overriding verification method based on a unified gateway, which is applied to a service cluster, and the method includes:

[0006] Set the entrance of service traffic to the pre-built gateway;

[0007] Perform token verification on service traffic on the pre-built gateway to determine whether the service traffic has a valid token;

[0008] When the service traffic has a valid token, the user information requesting the token is obtained from the cache through the token;

[0009] Transfer user information to the request and generate identification fields;

[0010] Use the identification field to annotate the request to implement horizontal unauthorized verification of the request and obtain the verification result.

[0011] In the present invention, a gateway with a unified traffic entrance is established to achieve unified entry and exit of service traffic. By utilizing the gateway pair with a unified traffic entrance, while realizing horizontal unauthorized verification, the service traffic is uniformly managed through the gateway, thereby improving the security and reliability of the system, providing a method of efficient traffic management and security assurance for microservice system clusters, and realizing support for business-level security authentication and horizontal unauthorized verification.

[0012] In an optional implementation, a pre-built gateway is established by the following steps:

[0013] Create the initial gateway;

[0014] Configure routing rules and configure the initial gateway based on the routing rules;

[0015] Perform verification tests on the initial gateway until the initial gateway's message is consistent with the original transaction network message, and establish a pre-built gateway.

[0016] In this way, under the existing microservice cluster system, all traffic entrances of external transactions are unified to the gateway, which realizes unified management of service traffic and improves the security and reliability of the system.

[0017] In an optional implementation, the token includes a generation validity period, and token verification is performed on the service traffic on a pre-built gateway to determine whether the service traffic has a valid token, including:

[0018] On the pre-built gateway, determine whether the service traffic generates a token that is valid at the current moment;

[0019] When there is no token generated with a validity period valid at the current moment, the request is determined to be an illegal request, and the request is intercepted using a pre-built gateway;

[0020] When there is a token generated with a validity period valid at the current moment, it is determined that the service traffic has a valid token.

[0021] In this method, a token is generated with a fixed validity period during the user authentication phase, and the gateway queries whether the token is valid. If the token does not exist, the current operation is an illegal request, and the transaction is intercepted at the gateway layer to implement a validity check on the token.

[0022] In an optional implementation, obtaining user information of a request token from a cache through a token includes:

[0023] According to the preset design rules, the token is stored in the header of the HTTP request, and the HTTP request is cached in the client cache;

[0024] Get the user information of the request token from the client cache based on the key value of the token.

[0025] In this method, the corresponding user information is found in the Redis cache by requesting the token, and the user information of the request token is obtained from the client cache according to the key value of the token, thereby determining the user information and facilitating subsequent verification using the user information.

[0026] In an optional implementation, the request is annotated with a section using an identification field to implement horizontal unauthorized verification of the request, including:

[0027] Filter the user information in the identification field to obtain the corresponding value of the preset verification field, parse the header of the HTTP request, and obtain the identification field object;

[0028] Verify the identification field object with the user information field passed in the request to obtain the verification result.

[0029] In this way, the verification field specified in the annotation application finds the corresponding value in the custom user information in the identification field, thereby realizing AOP (aspect-oriented programming) aspect annotation and applying it in the cluster system, thereby realizing horizontal unauthorized verification before the interface request logic processing.

[0030] In an optional embodiment, the method further includes:

[0031] When the verification result is passed, the subsequent business is executed;

[0032] When the check parameter of the verification result is illegal, the current request is determined to be an illegal request, and the response is transaction failure.

[0033] In this way, when the verification fails, it is determined that the current request message has been intercepted and tampered, and the transaction is an illegal request, so it is intercepted and verified; when the verification passes, the subsequent business logic is executed, which further improves the security of horizontal unauthorized verification and ensures the security of the verification results.

[0034] In a second aspect, the present invention provides a horizontal overriding verification device based on a unified gateway, the device comprising:

[0035] A gateway building module is used to set the entrance of service traffic to a pre-built gateway;

[0036] The token verification module is used to perform token verification on the service traffic on the pre-built gateway to determine whether the service traffic has a valid token;

[0037] The information acquisition module is used to obtain the user information of the request token from the cache through the token when the service traffic has a valid token;

[0038] The identification generation module is used to transfer the user information to the request and generate the identification field;

[0039] The aspect annotation module is used to use the identification field to annotate the request to achieve horizontal unauthorized verification of the request and obtain the verification result.

[0040] In a third aspect, the present invention provides a computer device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the horizontal unauthorized verification method based on a unified gateway according to the first aspect or any corresponding embodiment thereof by executing the computer instructions.

[0041] In a fourth aspect, the present invention provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the horizontal overriding verification method based on a unified gateway according to the first aspect or any corresponding embodiment thereof.

[0042] In a fifth aspect, the present invention provides a computer program product, including computer instructions, which are used to enable a computer to execute the horizontal overriding verification method based on a unified gateway according to the first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] In order to more clearly illustrate the specific implementation methods of the present invention or the technical solutions in the prior art, the drawings required for use in the specific implementation methods or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some implementation methods of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0044] Figure 1 The figure is a flow chart of a horizontal overriding verification method based on a unified gateway according to an embodiment of the present invention.

[0045] Figure 2 The diagram is an interactive diagram of a horizontal overriding verification method based on a unified gateway according to an embodiment of the present invention.

[0046] Figure 3 The figure is a flow chart of another horizontal override verification method based on a unified gateway according to an embodiment of the present invention.

[0047] Figure 4 The figure is a flow chart of another horizontal override verification method based on a unified gateway according to an embodiment of the present invention.

[0048] Figure 5 It is a structural block diagram of a horizontal unauthorized verification device based on a unified gateway according to an embodiment of the present invention.

[0049] Figure 6 It is a schematic diagram of the hardware structure of a computer device according to an embodiment of the present invention. DETAILED DESCRIPTION

[0050] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of the present invention.

[0051] Among the related technologies, the existing unified gateway technology solutions mainly realize functions such as service routing, traffic control, fuse protection, and load balancing, but their support for business-level security authentication and horizontal unauthorized access is relatively weak.

[0052] In order to solve the above problems, a horizontal unauthorized access verification method based on a unified gateway is provided in an embodiment of the present invention, which is used in a computer device. It should be noted that its execution subject can be a horizontal unauthorized access verification device based on a unified gateway, and the device can be implemented as part or all of the computer device through software, hardware, or a combination of software and hardware. The computer device can be a terminal, a client, or a server. The server can be a single server or a server cluster composed of multiple servers. The terminal in the embodiment of the present application can be a smart phone, a personal computer, a tablet computer, or other intelligent hardware devices. In the following method embodiments, the execution subject is taken as an example of a computer device for explanation.

[0053] The computer device in this embodiment is suitable for a microservice system cluster, and is intended to achieve unified management of service traffic, as well as unified horizontal unauthorized verification of the internal system of the cluster, to ensure the use scenario of system security. The present invention provides a horizontal unauthorized verification method based on a unified gateway, and achieves unified access to service traffic by establishing a gateway with a unified traffic entrance. By utilizing a gateway pair with a unified traffic entrance, while achieving horizontal unauthorized verification, the service traffic is also uniformly managed through the gateway, thereby improving the security and reliability of the system, providing a method of efficient traffic management and security assurance for a microservice system cluster, and achieving support for business-level security authentication and horizontal unauthorized verification.

[0054] According to an embodiment of the present invention, an embodiment of a horizontal unauthorized verification method based on a unified gateway is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.

[0055] In this embodiment, a horizontal overriding verification method based on a unified gateway is provided, which can be used for the above-mentioned service cluster. Figure 1is a flow chart of a horizontal over-authorization verification method based on a unified gateway according to an embodiment of the present invention. Figure 1 As shown, the process includes the following steps:

[0056] Step S101, setting the entrance of service traffic to a pre-built gateway.

[0057] In one example, in the existing microservice cluster system, all external transaction traffic entrances are unified to the gateway to achieve unified entry and exit of service traffic. The gateway can be implemented using tools such as Gateway, Nacos, Nginx, and Zuul. The implementation method of the gateway is not limited in the present invention.

[0058] Step S102, performing token verification on the service traffic on the pre-built gateway to determine whether the service traffic has a valid token.

[0059] In one example, the token verification is implemented on the gateway, and the traffic without the token is intercepted. Functions such as dynamic configuration and wildcard matching can be customized, and the functions are not limited in the present invention.

[0060] Step S103, when the service traffic has a valid token, obtain the user information requesting the token from the cache through the token.

[0061] In one example, the corresponding custom user information is found in the Redis cache by requesting a Token, and the user information is uniformly agreed upon by multiple systems within multiple clusters.

[0062] Step S104: transfer the user information to the request and generate an identification field.

[0063] In one example, the custom user information corresponding to the Token is transferred to the newly added identification field userInfo in the request Header, and the obtained user information is converted into a JSON object, including mobile phone number, name and other information, and sent to the userInfo object in the Header. This can be achieved using technologies such as custom filters, which is not limited in the present invention.

[0064] Step S105, using the identification field, annotating the request to implement horizontal unauthorized verification of the request and obtaining a verification result.

[0065] In one example, an AOP (Aspect Oriented Programming) aspect annotation is implemented and applied in a cluster system. Its purpose is to perform horizontal overriding verification before the interface request logic is processed. This can be achieved using technologies such as Spring AOP.

[0066] In one implementation scenario, Figure 2is an interactive schematic diagram of a horizontal overriding verification method based on a unified gateway according to an embodiment of the present invention, such as Figure 2 As shown in the figure, firstly, a gateway with unified traffic entrance is established to uniformly manage service traffic. Secondly, the corresponding custom user information is found in the Redis cache by requesting the Token. The user information is uniformly agreed upon by multiple systems within multiple clusters. The custom user information corresponding to the Token is transferred to the newly added identification field userInfo in the request Header. Finally, an AOP aspect annotation is implemented and applied in the cluster system. Its purpose is to perform horizontal unauthorized verification before the interface request logic is processed. The annotation mainly finds the corresponding value in the custom user information in userInfo by specifying the verification field when the annotation is applied, and compares it with the field value passed in the request Body or Param. If the verification fails, the request is intercepted, otherwise the horizontal unauthorized verification passes. In the figure, Nginx is a high-performance HTTP and reverse proxy web server; Gateway is a gateway used to carry horizontal unauthorized Token inspection and userInfo object splicing; Peer is a node in the service cluster, including the application microservice cluster, the registration center cluster, and the cache node cluster; Token is a token, which is the unique authentication identifier obtained when the user logs in.

[0067] The horizontal unauthorized access verification method based on a unified gateway provided in this embodiment realizes unified access to and from service traffic by establishing a gateway with a unified traffic entrance. By utilizing the gateway pair with a unified traffic entrance, while realizing horizontal unauthorized access verification, it also uniformly manages service traffic through the gateway, thereby improving the security and reliability of the system, providing a method of efficient traffic management and security assurance for microservice system clusters, and realizing support for business-level security authentication and horizontal unauthorized access.

[0068] In this embodiment, a horizontal overriding verification method based on a unified gateway is provided, which can be used for the above-mentioned service cluster. Figure 3 FIG. 4 is a flowchart of another horizontal over-authorization verification method based on a unified gateway according to an embodiment of the present invention. Figure 3 As shown, the process includes the following steps:

[0069] Step S301, setting the entrance of service traffic to a pre-built gateway.

[0070] Specifically, the pre-built gateway is established through the following steps:

[0071] Step a1: Create an initial gateway.

[0072] Step a2: configure routing rules, and configure the initial gateway based on the routing rules.

[0073] Step a3, verify the initial gateway until the message of the initial gateway is consistent with the original transaction network message, and establish the pre-built gateway.

[0074] In one example, the steps to create a gateway are as follows:

[0075] 1. To create a gateway application, it is recommended to use an existing open source solution.

[0076] 2. Configure routing rules, sort out routing rules according to the existing microservice modules, and complete the configuration at the gateway layer.

[0077] 3. Perform verification test on the created gateway service and ensure that it is consistent with the original transaction network message through the gateway layer.

[0078] In this way, under the existing microservice cluster system, all traffic entrances of external transactions are unified to the gateway, which realizes unified management of service traffic and improves the security and reliability of the system.

[0079] Step S302: Perform token verification on the service traffic on the pre-built gateway to determine whether the service traffic has a valid token.

[0080] Specifically, the token includes a generated validity period, and the above step S302 includes:

[0081] Step S3021, on the pre-built gateway, determine whether the service traffic has generated a token that is valid at the current moment.

[0082] Step S3022: When there is no token generated with a validity period valid at the current moment, the request is determined to be an illegal request, and the request is intercepted using a pre-built gateway.

[0083] Step S3023, when there is a token generated with a validity period valid at the current moment, it is determined that the service traffic has a valid token.

[0084] In one example, the gateway layer implements Token verification. The Token is generated during the user authentication phase (account and password login, verification code login, and other login operations) and has a fixed validity period. It is generally recommended to be within 30 minutes. The gateway queries whether the Token is valid. If the Token does not exist, the current operation is an illegal request and the transaction is intercepted at the gateway layer. The custom interceptor intercepts the key value of the existing design Token and performs a Token validity check on this part.

[0085] In this method, a token is generated with a fixed validity period during the user authentication phase, and the gateway queries whether the token is valid. If the token does not exist, the current operation is an illegal request, and the transaction is intercepted at the gateway layer to implement a validity check on the token.

[0086] Step S303, when the service traffic has a valid token, obtain the user information requesting the token from the cache through the token.

[0087] Specifically, the above step S303 includes:

[0088] Step S3031, according to the preset design rules, the token is stored in the header of the HTTP request, and the HTTP request is cached in the client cache.

[0089] Step S3032: Obtain the user information of the token request from the client cache according to the key value of the token.

[0090] In one example, the request token is returned in the transaction to obtain the token according to the preset design rules. The HTTP request stores the token in the HTTP header and caches it in sessionStorage in the web client. All gateway transactions require the token to be obtained in the WEB client and the transaction message is spliced ​​to request the gateway. After the gateway layer recognizes that the token is valid, it obtains the user information (logged in) when requesting the token from the cache according to the key value.

[0091] In this method, the corresponding user information is found in the Redis cache by requesting the token, and the user information of the request token is obtained from the client cache according to the key value of the token, thereby determining the user information and facilitating subsequent verification using the user information.

[0092] Step S304: transfer the user information to the request and generate an identification field. Figure 1 Step S104 of the illustrated embodiment will not be described in detail here.

[0093] Step S305, using the identification field, annotating the request to implement horizontal unauthorized verification of the request and obtaining a verification result.

[0094] Specifically, the above step S305 includes:

[0095] Step S3051, filter the user information in the identification field to obtain the corresponding value of the preset verification field, parse the header of the HTTP request, and obtain the identification field object.

[0096] In an example, this step is explained in detail.

[0097] Step S3052: Verify the identification field object with the user information field passed in the request to obtain a verification result.

[0098] In one example, an AOP (Aspect Oriented Programming) aspect annotation is implemented and applied in a cluster system. Its purpose is to perform horizontal overriding verification before the interface request logic is processed. This can be achieved using technologies such as Spring AOP.

[0099] The annotation mainly finds the corresponding value in the custom user information in userInfo by specifying the "verification field" of the verification when the annotation is applied. The userInfo object is requested by the gateway to the target microservice, and the HTTP header is parsed. The userInfo object is stored in the memory of the current microservice. This object is compared with the user information field (such as mobile phone number, name, etc.) passed in the request Body or Param. If the verification fails, the request is intercepted, otherwise the horizontal unauthorized verification passes.

[0100] In this way, the corresponding value is found in the custom user information in the identification field by specifying the verification field of the verification when the annotation is applied, thereby realizing AOP (Aspect Oriented Programming) aspect annotation and applying it in the cluster system, thereby realizing horizontal unauthorized verification before the logic processing of the interface request.

[0101] The horizontal unauthorized access verification method based on a unified gateway provided in this embodiment unifies the traffic entrances of all external transactions to the gateway under the existing microservice cluster system, realizes unified management of service traffic, and improves the security and reliability of the system. The token is generated in the user confirmation stage and the validity period is set to a fixed time. The gateway queries whether the token is valid. If the token does not exist, the current operation is an illegal request. The transaction is intercepted at the gateway layer to check the validity of the token. The corresponding user information is found in the Redis cache by requesting the token, and the user information of the request token is obtained from the client cache according to the key value of the token, so as to determine the user information and facilitate the subsequent use of the user information for verification. By specifying the verification field for verification during the annotation application, the corresponding value is found in the custom user information in the identification field, and the AOP (aspect-oriented programming) aspect annotation is realized. It is applied in the cluster system, and then the horizontal unauthorized access verification is realized before the logic processing of the interface request.

[0102] In this embodiment, a horizontal overriding verification method based on a unified gateway is provided, which can be used for the above-mentioned service cluster. Figure 4 is a flowchart of another horizontal overriding verification method based on a unified gateway according to an embodiment of the present invention. Figure 4 As shown, the process includes the following steps:

[0103] Step S401: Set the service traffic entrance to the pre-built gateway. Figure 3 Step S302 of the illustrated embodiment will not be described in detail here.

[0104] Step S402: Token verification is performed on the service traffic on the pre-built gateway to determine whether the service traffic has a valid token. Figure 3 Step S302 of the illustrated embodiment will not be described in detail here.

[0105] Step S403: When the service flow has a valid token, the user information requesting the token is obtained from the cache through the token. Figure 3 Step S303 of the illustrated embodiment will not be described in detail here.

[0106] Step S404: transfer the user information to the request and generate an identification field. Figure 3 Step S304 of the illustrated embodiment will not be described in detail here.

[0107] Step S405: Use the identification field to perform aspect annotation on the request to implement horizontal unauthorized verification of the request and obtain the verification result. Figure 3 Step S305 of the illustrated embodiment will not be described in detail here.

[0108] Step S406: When the verification result is passed, subsequent business is executed.

[0109] Step S407: when the check parameter of the verification result is illegal, the current request is determined to be an illegal request, and the response is transaction failure.

[0110] In one example, corresponding processing is performed according to the verification result, such as returning error information or continuing to execute the request logic. This can be implemented using technologies such as Spring MVC.

[0111] According to the interception result of the aspect, if the check passes, the subsequent business logic can be directly executed. If the check parameters are illegal (the mobile phone number is tampered with, the name is tampered with, etc.), it means that the current request message has been intercepted and tampered with, the current transaction is an illegal request, the microservice blocks the transaction, and the HTTP response is a transaction failure.

[0112] In this way, when the verification fails, it is determined that the current request message has been intercepted and tampered, and the transaction is an illegal request, so it is intercepted and verified; when the verification passes, the subsequent business logic is executed, which further improves the security of horizontal unauthorized verification and ensures the security of the verification results.

[0113] The horizontal unauthorized access verification method based on a unified gateway provided in this embodiment determines that the current request message has been intercepted and tampered with when the verification fails, and the transaction is an illegal request, and intercepts the verification; when the verification passes, the subsequent business logic is executed, which further improves the security of the horizontal unauthorized access verification and ensures the security of the verification results.

[0114] In this embodiment, a horizontal unauthorized verification device based on a unified gateway is also provided, which is used to implement the above-mentioned embodiments and preferred implementation modes, and the descriptions that have been made will not be repeated. As used below, the term "module" can implement a combination of software and / or hardware for a predetermined function. Although the device described in the following embodiments is preferably implemented in software, the implementation of hardware, or a combination of software and hardware, is also possible and conceivable.

[0115] This embodiment provides a horizontal over-authorization verification device based on a unified gateway, such as Figure 5 As shown, including:

[0116] The gateway construction module 501 is used to set the entrance of the service traffic to the pre-constructed gateway. Figure 1 Step S101 of the illustrated embodiment will not be described in detail here.

[0117] The token verification module 502 is used to perform token verification on the service traffic on the pre-built gateway to determine whether the service traffic has a valid token. Figure 1 Step S102 of the illustrated embodiment will not be described in detail here.

[0118] The information acquisition module 503 is used to obtain the user information of the request token from the cache through the token when the service flow has a valid token. Figure 1 Step S103 of the illustrated embodiment will not be described in detail here.

[0119] The identification generation module 504 is used to transfer the user information to the request and generate an identification field. Figure 1 Step S104 of the illustrated embodiment will not be described in detail here.

[0120] The aspect annotation module 505 is used to use the identification field to perform aspect annotation on the request to implement horizontal unauthorized verification of the request and obtain the verification result. Figure 1 Step S105 of the illustrated embodiment will not be described in detail here.

[0121] In some optional implementations, the horizontal overriding verification device based on the unified gateway includes:

[0122] The initial gateway creation unit is used to create an initial gateway.

[0123] The gateway configuration unit is used to configure routing rules and configure the initial gateway based on the routing rules.

[0124] The gateway construction unit is used to perform verification tests on the initial gateway until the message of the initial gateway is consistent with the original transaction network message, and a pre-built gateway is established.

[0125] In some optional implementations, the token verification module 502 includes:

[0126] The token judgment unit is used to judge whether the service traffic has generated a token that is valid at the current moment on the pre-built gateway.

[0127] The first illegal request determination unit is used to determine that a request is an illegal request when there is no token generated with a valid validity period at the current moment, and intercept the request by using a pre-built gateway.

[0128] The valid token determination unit is used to determine that the service traffic has a valid token when there is a token generated with a validity period valid at the current moment.

[0129] In some optional implementations, the information acquisition module 503 includes:

[0130] The token cache unit is used to store the token in the header of the HTTP request according to the preset design rules, and cache the HTTP request in the client cache.

[0131] The user information acquisition unit is used to acquire the user information of the request token from the client cache according to the key value of the token.

[0132] In some optional implementations, the section annotation module 505 includes:

[0133] The identification field parsing unit is used to filter the user information in the identification field to obtain the corresponding value of the preset verification field, parse the header of the HTTP request, and obtain the identification field object.

[0134] The field verification unit is used to verify the identification field object with the user information field passed in the request to obtain a verification result.

[0135] In some optional implementations, the horizontal overriding verification device based on the unified gateway further includes:

[0136] The verification pass unit is used to execute subsequent business when the verification result is passed.

[0137] The illegality verification unit is used to determine that the current request is an illegal request when the check parameter of the verification result is illegal, and the response is transaction failure.

[0138] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.

[0139] The horizontal unauthorized verification device based on the unified gateway in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.

[0140] The embodiment of the present invention also provides a computer device having the above Figure 5 The horizontal unauthorized verification device based on the unified gateway is shown.

[0141] See also Figure 6 , Figure 6 is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present invention, such as Figure 6 As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components are connected to each other using different buses for communication, and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Similarly, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 6 A processor 10 is taken as an example.

[0142] The processor 10 may be a central processing unit, a network processor or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be a dedicated integrated circuit, a programmable logic device or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic or any combination thereof.

[0143] The memory 20 stores instructions executable by at least one processor 10, so that the at least one processor 10 executes the method shown in the above embodiment.

[0144] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.

[0145] The memory 20 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid state drive; the memory 20 may also include a combination of the above types of memory.

[0146] The computer device also includes an input device 30 and an output device 40. The processor 10, the memory 20, the input device 30 and the output device 40 may be connected via a bus or other means. Figure 6 The example of connecting through bus is taken in the following.

[0147] The input device 30 can receive input digital or character information, and generate key signal input related to the user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a track pad, a touch pad, an indicator bar, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 may include a display device, an auxiliary lighting device (e.g., an LED) and a tactile feedback device (e.g., a vibration motor), etc. The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display and a plasma display. In some optional embodiments, the display device can be a touch screen.

[0148] The embodiment of the present invention also provides a computer-readable storage medium. The method according to the embodiment of the present invention can be implemented in hardware, firmware, or can be implemented as a computer code that can be recorded in a storage medium, or can be implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium through a network download, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state hard disk, etc.; further, the storage medium can also include a combination of the above types of memories. It can be understood that a computer, a processor, a microprocessor controller, or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor, or hardware, the method shown in the above embodiment is implemented.

[0149] A part of the present invention may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present invention through the operation of the computer. Those skilled in the art should understand that the existence of the computer program instruction in a computer-readable medium includes, but is not limited to, a source file, an executable file, an installation package file, etc., and accordingly, the way in which the computer program instruction is executed by the computer includes, but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium may be any available computer-readable storage medium or communication medium accessible to the computer.

[0150] Although the embodiments of the present invention have been described in conjunction with the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present invention, and such modifications and variations are all within the scope defined by the appended claims.

Claims

1. A horizontal overriding verification method based on a unified gateway, characterized in that: Applied to a service cluster, the method includes: Set the entrance of service traffic to the pre-built gateway; Performing token verification on the service traffic on the pre-built gateway to determine whether the service traffic has a valid token; When the service traffic has a valid token, obtaining user information requesting the token from a cache through the token; Transferring the user information to the request and generating an identification field; The identification field is used to perform aspect annotation on the request to implement horizontal unauthorized verification of the request and obtain a verification result.

2. The method according to claim 1, characterized in that To build the pre-built gateway, follow these steps: Create the initial gateway; Configure routing rules, and configure the initial gateway based on the routing rules; The initial gateway is subjected to a verification test until the message of the initial gateway is consistent with the original transaction network message, and the pre-built gateway is established.

3. The method according to claim 1, characterized in that The token includes a generation validity period, and the token verification is performed on the pre-built gateway to determine whether the service traffic has a valid token, including: On the pre-built gateway, determining whether the service traffic has a token generated with a validity period valid at the current moment; When there is no token generated with a validity period valid at the current moment, determining that the request is an illegal request, and intercepting the request using the pre-built gateway; When there is a token generated with a validity period valid at the current moment, it is determined that the service traffic has a valid token.

4. The method according to claim 1, characterized in that: The obtaining, from the cache, the user information requesting the token by using the token includes: According to preset design rules, the token is stored in the header of the HTTP request, and the HTTP request is cached in the client cache; According to the key value of the token, the user information requesting the token is obtained from the client cache.

5. The method according to claim 4, characterized in that The utilizing the identification field to perform aspect annotation on the request to implement horizontal unauthorized verification on the request includes: Filtering the user information in the identification field to obtain a corresponding value of a preset verification field, parsing the header of the HTTP request to obtain an identification field object; The identification field object is verified with the user information field passed in the request to obtain the verification result.

6. The method according to claim 5, characterized in that The method further comprises: When the verification result is passed, executing subsequent business; When the check parameter of the verification result is illegal, the current request is determined to be an illegal request, and the response is transaction failure.

7. A horizontal unauthorized verification device based on a unified gateway, characterized in that: The device comprises: A gateway building module is used to set the entrance of service traffic to a pre-built gateway; A token verification module, used to perform token verification on the service traffic on the pre-built gateway to determine whether the service traffic has a valid token; An information acquisition module, used for acquiring user information requesting the token from a cache through the token when the service flow has a valid token; An identification generation module, used to transfer the user information to the request and generate an identification field; The aspect annotation module is used to use the identification field to perform aspect annotation on the request to implement horizontal unauthorized verification of the request and obtain a verification result.

8. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the horizontal unauthorized verification method based on a unified gateway as described in any one of claims 1 to 6 by executing the computer instructions.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the horizontal overauthorization verification method based on a unified gateway according to any one of claims 1 to 6.

10. A computer program product, characterized in that It includes computer instructions, and the computer instructions are used to enable a computer to execute the horizontal overauthorization verification method based on a unified gateway as described in any one of claims 1 to 6.