System and method for realizing three-party service dynamic access control and forwarding
By introducing intermediate-layer services to centrally manage permission verification and interface forwarding, the compatibility problem during third-party service updates is solved, flexible service access control and interface forwarding is realized, and the system maintainability and scalability is improved.
Patent Information
- Application Number
- CN202510145308.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-05-13
AI Technical Summary
The prior art is prone to compatibility problems when third-party services are updated, resulting in increased maintenance complexity, and common permission management systems are prone to compatibility problems when upgrading.
By introducing intermediate-layer services, centralized management of permission verification and interface forwarding, third-party services can be upgraded independently of upper-layer applications. The specific plan includes creating an intermediate-layer service, receiving service requests initiated by the client, obtaining authentication information, verifying permissions, and converting the request into a format adapted to the third-party service interface and forwarding it to the third-party service, and finally returning the response to the client according to the preset permission rules.
It realizes a flexible service access control and interface forwarding mechanism, effectively solves the data permission control problem caused by service updates, and improves the maintainability and scalability of the system.
Smart Images

Figure CN119995987A_ABST
Abstract
Description
Technical Field
[0001] The invention discloses a system and method for realizing dynamic access control and forwarding of three-party services, and relates to the field of computer network service access control. Background Art
[0002] With the popularity of cloud computing and microservice architecture, many services rely on open source software to implement specific functions. These open source services may frequently update versions to fix vulnerabilities, optimize performance, or add new features. However, each update may affect the interface definition and data permission control logic of the upper-level applications integrated with it, resulting in increased maintenance complexity. The current common solution is to deploy a complete permission management system in each application that relies on third-party services for permission maintenance, but this approach not only increases the development workload, but is also prone to compatibility issues when third-party services are upgraded. Summary of the invention
[0003] In view of the problems of the prior art, the present invention provides a system and method for realizing dynamic access control and forwarding of third-party services, which centrally manages authority verification and interface forwarding by introducing middle-layer services, so that third-party services can be upgraded independently of upper-layer applications.
[0004] The specific scheme proposed by the present invention is:
[0005] The present invention provides a method for implementing dynamic access control and forwarding of a three-party service, comprising:
[0006] Create a middle-tier service, receive service requests initiated by the client through the middle-tier service, and obtain authentication information based on the service request.
[0007] The middle-tier service verifies the authority of the service request based on the authentication information. After the verification is passed, the service request is converted into a format suitable for the third-party service interface and forwarded to the third-party service.
[0008] Receive the response of the third-party service to the service request through the middle-tier service, and return the response to the client according to the preset permission rules.
[0009] Furthermore, the method for implementing dynamic access control and forwarding of a third-party service includes:
[0010] Initialize the permission management file of the middle-tier service, including loading the permission configuration file, or connecting to the remote permission database to receive the permission configuration file.
[0011] Furthermore, the method for implementing dynamic access control and forwarding of third-party services describes verifying the authority of the service request based on the identity authentication information through the middle-layer service, including: first performing a basic security check through the middle-layer service, including TLS encryption and signature verification, and then extracting the identity authentication information in the service request, querying the authority database based on the authentication information, and determining whether the client has the right to access a specific third-party service interface. If the verification fails, the middle-layer service returns an error message to the client; if the verification passes, the service request is forwarded to the third-party service based on the authority.
[0012] Furthermore, in the method for implementing dynamic access control and forwarding of third-party services, a response to a service request from a third-party service is received through an intermediate layer service, the response content is checked according to the permissions of the service request, and sensitive information in the response is filtered or the response format is adjusted according to preset permission rules, and then the response is returned to the client.
[0013] The present invention also provides a device for implementing dynamic access control and forwarding of three-party services, including a service management module, a verification module and a forwarding module.
[0014] The service management module creates a middle-tier service, receives service requests initiated by the client through the middle-tier service, and obtains authentication information based on the service request.
[0015] The verification module verifies the authority of the service request based on the authentication information through the middle-layer service. After the verification is passed, the forwarding module converts the service request into a format that is suitable for the third-party service interface and forwards it to the third-party service.
[0016] The forwarding module receives the response of the third-party service to the service request through the middle-layer service, and returns the response to the client according to the preset permission rules.
[0017] Furthermore, the device for implementing dynamic access control and forwarding of third-party services also includes a rights management module, which initializes the rights management file of the middle-layer service, including loading a rights configuration file, or connecting to a remote rights database to receive the rights configuration file.
[0018] Furthermore, the verification module of the device for implementing dynamic access control and forwarding of third-party services verifies the authority of the service request based on the identity verification information through the middle-layer service, including: first performing a basic security check through the middle-layer service, including TLS encryption and signature verification, and then extracting the identity verification information in the service request, querying the authority database based on the authentication information, and determining whether the client has the right to access a specific third-party service interface. If the verification fails, the middle-layer service returns an error message to the client; if the verification passes, the service request is forwarded to the third-party service based on the authority.
[0019] Furthermore, the forwarding module of the device for implementing dynamic access control and forwarding of third-party services receives the response of the third-party service to the service request through the middle layer service, checks the response content according to the authority of the service request, filters the sensitive information in the response or adjusts the response format according to preset authority rules, and then returns the response to the client.
[0020] The benefits of the present invention are:
[0021] It provides a flexible service access control and interface forwarding mechanism, which can effectively solve the data permission control problem caused by service updates and improve the maintainability and scalability of the system. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] Figure 1 It is a schematic diagram of the application process of the method of the present invention. DETAILED DESCRIPTION
[0023] The present invention is further described below in conjunction with the accompanying drawings and specific embodiments so that those skilled in the art can better understand the present invention and implement it, but the embodiments are not intended to limit the present invention.
[0024] Example 1
[0025] The present invention provides a method for implementing dynamic access control and forwarding of a three-party service, comprising:
[0026] Create a middle-tier service, receive service requests initiated by the client through the middle-tier service, and obtain authentication information based on the service request.
[0027] The middle-tier service verifies the authority of the service request based on the authentication information. After the verification is passed, the service request is converted into a format suitable for the third-party service interface and forwarded to the third-party service.
[0028] Receive the response of the third-party service to the service request through the middle-tier service, and return the response to the client according to the preset permission rules.
[0029] The specific process can be found as follows:
[0030] There is a service request from client A service, third-party service C,
[0031] Create middle-tier service B and perform the initialization phase:
[0032] Service B initializes the permission management file, loads the permission configuration file or connects to the remote permission database.
[0033] Service B starts listening on the port, ready to receive requests from service A.
[0034] Request processing phase:
[0035] When service A needs to access the functions of service C, it constructs an HTTP request with authentication information and sends it to service B.
[0036] After receiving the request, Service B first performs basic security checks, including TLS encryption and signature verification, and then extracts the authentication information in the request.
[0037] Service B queries the permission database based on the authentication information to determine whether service A has the right to access the specific C service interface.
[0038] If the verification fails, service B returns an error message to service A; if the verification succeeds, it proceeds to the next step.
[0039] Request forwarding stage:
[0040] Service B forwards the request to service C, converts the request format to adapt to the API specification of service C, and service C performs the corresponding operation and returns the result to service B.
[0041] Response processing phase:
[0042] After service B receives the response from service C, it checks the response content according to the permissions of service A.
[0043] Filter sensitive information in responses or adjust the response format based on preset permission rules.
[0044] The final processed response is returned to Service A.
[0045] Example 2
[0046] The present invention also provides a device for implementing dynamic access control and forwarding of three-party services, including a service management module, a verification module and a forwarding module.
[0047] The service management module creates a middle-tier service, receives service requests initiated by the client through the middle-tier service, and obtains authentication information based on the service request.
[0048] The verification module verifies the authority of the service request based on the authentication information through the middle-layer service. After the verification is passed, the forwarding module converts the service request into a format that is suitable for the third-party service interface and forwards it to the third-party service.
[0049] The forwarding module receives the response of the third-party service to the service request through the middle-layer service, and returns the response to the client according to the preset permission rules.
[0050] As the information interaction and execution process between the modules in the above-mentioned device are based on the same concept as the embodiment of the method of the present invention, the specific contents can be found in the description of the embodiment of the method of the present invention and will not be repeated here.
[0051] Likewise, the device of the present invention provides a flexible service access control and interface forwarding mechanism, which can effectively solve the data authority control problem caused by service updates and improve the maintainability and scalability of the system.
[0052] It should be noted that not all steps and modules in the above-mentioned processes and device structures are necessary, and some steps or modules can be ignored according to actual needs. The execution order of each step is not fixed and can be adjusted as needed. The system structure described in the above-mentioned embodiments can be a physical structure or a logical structure, that is, some modules may be implemented by the same physical entity, or some modules may be implemented by multiple physical entities, or some components in multiple independent devices may be implemented together.
[0053] The above-described embodiments are only preferred embodiments for fully illustrating the present invention, and the protection scope of the present invention is not limited thereto. Equivalent substitutions or changes made by those skilled in the art based on the present invention are within the protection scope of the present invention. The protection scope of the present invention shall be subject to the claims.
Claims
1. A method for implementing dynamic access control and forwarding of a third-party service, characterized in that include: Create a middle-tier service, receive service requests initiated by the client through the middle-tier service, and obtain authentication information based on the service request. The middle-tier service verifies the authority of the service request based on the authentication information. After the verification is passed, the service request is converted into a format suitable for the third-party service interface and forwarded to the third-party service. Receive the response of the third-party service to the service request through the middle-tier service, and return the response to the client according to the preset permission rules.
2. A method for implementing dynamic access control and forwarding of a third-party service according to claim 1, characterized in that The creation of the middle layer service includes: Initialize the permission management file of the middle-tier service, including loading the permission configuration file, or connecting to the remote permission database to receive the permission configuration file.
3. A method for implementing dynamic access control and forwarding of a third-party service according to claim 1, characterized in that The method of verifying the authority of the service request based on the identity verification information through the middle-layer service includes: first performing a basic security check through the middle-layer service, including TLS encryption and signature verification, and then extracting the identity verification information in the service request, querying the authority database based on the authentication information, and determining whether the client has the right to access a specific third-party service interface. If the verification fails, the middle-layer service returns an error message to the client. If the verification passes, the service request is forwarded to the third-party service based on the authority.
4. A method for implementing dynamic access control and forwarding of a third-party service according to claim 1, characterized in that Receive the response of the third-party service to the service request through the middle-tier service, check the response content according to the permissions of the service request, filter sensitive information in the response or adjust the response format according to the preset permission rules, and then return the response to the client.
5. A device for implementing dynamic access control and forwarding of a third-party service, characterized in that Including service management module, verification module and forwarding module, The service management module creates a middle-tier service, receives service requests initiated by the client through the middle-tier service, and obtains authentication information based on the service request. The verification module verifies the authority of the service request based on the authentication information through the middle-layer service. After the verification is passed, the forwarding module converts the service request into a format that is suitable for the third-party service interface and forwards it to the third-party service. The forwarding module receives the response of the third-party service to the service request through the middle-layer service, and returns the response to the client according to the preset permission rules.
6. The device for implementing dynamic access control and forwarding of a third-party service according to claim 5, characterized in that It also includes a rights management module, which initializes the rights management file of the middle-layer service, including loading the rights configuration file, or connecting to a remote rights database to receive the rights configuration file.
7. The device for implementing dynamic access control and forwarding of a third-party service according to claim 5, characterized in that The verification module verifies the authority of the service request based on the authentication information through the middle-layer service, including: first performing basic security checks through the middle-layer service, including TLS encryption and signature verification, and then extracting the authentication information in the service request, querying the authority database based on the authentication information, and determining whether the client has the right to access a specific third-party service interface. If the verification fails, the middle-layer service returns an error message to the client. If the verification passes, the service request is forwarded to the third-party service based on the authority.
8. The device for implementing dynamic access control and forwarding of a third-party service according to claim 5, characterized in that The forwarding module receives the response of the third-party service to the service request through the middle-layer service, checks the response content according to the permissions of the service request, filters the sensitive information in the response or adjusts the response format according to the preset permission rules, and then returns the response to the client.