Task data processing method and device, equipment and medium
By deploying task interceptors on the process engine components of the process processing equipment to verify IT workflow tasks, the problem of difficult task execution security and reliability in the prior art is solved, and a safer and more reliable automated task execution is achieved.
Patent Information
- Application Number
- CN202311531720.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-15
- Publication Date
- 2025-05-16
AI Technical Summary
The prior art is difficult to ensure the security and reliability of task execution when automating IT workflow tasks, especially when there are risky operations in the task.
Task verification is performed before task execution by deploying a task interceptor on the process engine component of the process processing device. The specific steps include obtaining tasks in the business process, finding interception identifiers related to tasks and process, calling the task interceptor for verification, and notifying the business server to perform tasks after the verification is successful.
Improve the security and reliability of task execution, prevent potential risks through task verification mechanism, and ensure that automated tasks are executed under the premise of safety.
Smart Images

Figure CN120011113A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a task data processing method, device, equipment and medium. Background Art
[0002] As business becomes more complex, workflows are widely used in various fields. The so-called workflow is an abstract and general description of the business rules between the workflow and its various operation steps. In simple terms, it is a process-based abstraction of business. The main problem that workflows solve is: to achieve a certain business goal, use computer equipment to automatically transfer documents, information or tasks between multiple participants according to certain predetermined rules.
[0003] For example, in the field of IT (Information Technology) workflow, tasks within IT workflows can be automatically executed, and the operation object of the task is a machine. The inventor found in practice that the prior art combines multiple operations into one task for execution, and after all operations in the task are completed, further triggers risk detection for the task, which means that once an operation in the task has a risk, it will be difficult to ensure the safety and reliability of the task execution during the task execution because the task has been automatically executed. Summary of the invention
[0004] The embodiments of the present application provide a task data processing method, apparatus, device and medium, which can improve the security and reliability of task execution.
[0005] On the one hand, an embodiment of the present application provides a task data processing method, which is executed by a process processing device, and a task interceptor is deployed on a process engine component in the process processing device; the method includes:
[0006] Obtain a business process associated with the business operation device, and create a task i to be executed through M tasks associated with the business operation device in the business process; M is a positive integer; i is a positive integer less than or equal to M;
[0007] Before executing task i, searching the task auxiliary parameters of task i for a task interception identifier associated with the task interceptor to obtain a first identifier search result;
[0008] When the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, the task interceptor is called through the process engine component, and the process interception identifier associated with the task interceptor is searched in the process auxiliary parameters corresponding to the business process to obtain a second identifier search result;
[0009] When the second identifier search result indicates that the process intercept identifier is found in the process auxiliary parameters, task verification is performed on task i in the business process. When the task verification is successful, the business server associated with the process engine component is notified to execute task i for the business operation device.
[0010] On the one hand, an embodiment of the present application provides a task data processing device, which runs on a process processing device, and a task interceptor is deployed on a process engine component in the process processing device; the device includes:
[0011] The task creation module is used to obtain the business process associated with the business operation device, and create a task i to be executed through M tasks associated with the business operation device in the business process; M is a positive integer; i is a positive integer less than or equal to M;
[0012] A first search module is used to search for a task interception identifier associated with a task interceptor in task auxiliary parameters of task i before executing task i, and obtain a first identifier search result;
[0013] A second search module is used to call the task interceptor through the process engine component when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, and search the process interception identifier associated with the task interceptor in the process auxiliary parameters corresponding to the business process to obtain a second identifier search result;
[0014] The verification success module is used to perform task verification on task i in the business process when the second identifier search result indicates that the process interception identifier is found in the process auxiliary parameters. When the task verification is successful, the business server associated with the process engine component is notified to execute task i for the business operation device.
[0015] Among them, the task creation module includes:
[0016] The process startup unit is used to obtain a process startup request sent by a business client associated with the process engine component through the process engine component; the process startup request is used to start a business process associated with a business operation device; based on the process startup request, the process template data associated with the business process is obtained, and the business process is generated through the process template data.
[0017] The process start request carries the process identifier corresponding to the business process;
[0018] The process startup unit includes:
[0019] The template acquisition subunit is used to obtain the process identifier corresponding to the business process from the process start request, obtain the business process diagram of the business process configuration from the template database associated with the process engine component according to the process identifier corresponding to the business process, and use the business process diagram as the process template data associated with the business process;
[0020] The instantiation subunit is used to initialize the process template data through the process engine component to obtain the initialized process template data, and perform process instantiation processing according to the initialized process template data to obtain the business process.
[0021] Among them, the task creation module includes:
[0022] The first creating unit is used to create M tasks associated with the business operation device through a business process, and obtain a task i to be executed from the M tasks.
[0023] Among them, the task creation module includes:
[0024] The second creating unit is used to obtain the task execution order of M tasks associated with the business operation device in the business process, and create a task i to be executed according to the task execution order.
[0025] Wherein, the first search module includes:
[0026] The first search unit is used to obtain the task function header of task i through the process engine component before executing task i, and use the task function header of task i as the task auxiliary parameter of task i; search for the task interception annotation information associated with the task interceptor in the task auxiliary parameters of task i, and when the task interception annotation information is found, determine that the task interception identifier associated with the task interceptor is found in the task auxiliary parameters of task i; and use the result of finding the task interception identifier in the task auxiliary parameters of task i as the first identifier search result.
[0027] Wherein, the first search module includes:
[0028] The second search unit is used to obtain the task interception list configured by the task interceptor through the process engine component before executing task i, and use the task interception list as the task auxiliary parameter of task i; the task interception list contains a task identifier for triggering the task interceptor; the task identifier of task i is searched in the task auxiliary parameters of task i, and when the task identifier of task i is found, it is determined that the task interception identifier associated with the task interceptor is found in the task auxiliary parameters of task i; the result of finding the task interception identifier in the task auxiliary parameters of task i is used as the first identifier search result.
[0029] Wherein, the first search module includes:
[0030] The third search unit is used to obtain the task switch list configured by the task interceptor through the process engine component before executing task i, and use the task switch list as the task auxiliary parameter of task i; search for the task switch state of task i in the task auxiliary parameters of task i, and when the found task switch state is the task interception state, determine that the task interception identifier associated with the task interceptor is found in the task auxiliary parameters of task i; and use the result of finding the task interception identifier in the task auxiliary parameters of task i as the first identifier search result.
[0031] Wherein, the second search module includes:
[0032] The fourth search unit is used to call the task interceptor through the process engine component when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, obtain the process function header of the business process, and use the process function header of the business process as the process auxiliary parameter corresponding to the business process; search for the process interception annotation information associated with the task interceptor in the process auxiliary parameters, and when the process interception annotation information is found, determine that the process interception identifier associated with the task interceptor is found in the process auxiliary parameters; and use the result of finding the process interception identifier in the process auxiliary parameters as the second identifier search result.
[0033] Wherein, the second search module includes:
[0034] The fifth search unit is used to call the task interceptor through the process engine component when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, obtain the process interception list configured by the task interceptor, and use the process interception list as the process auxiliary parameter corresponding to the business process; the process interception list contains a process identifier used to instruct the task interceptor to perform task interception; search for the process identifier corresponding to the business process in the process auxiliary parameters, and when the process identifier corresponding to the business process is found, determine that the process interception identifier associated with the task interceptor is found in the process auxiliary parameters; and use the result of finding the process interception identifier in the process auxiliary parameters as the second identifier search result.
[0035] Wherein, the second search module includes:
[0036] The sixth search unit is used to call the task interceptor through the process engine component when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, obtain the process switch list configured by the task interceptor, and use the process switch list as the process auxiliary parameters corresponding to the business process; search the process switch state of the business process in the process auxiliary parameters, and when the found process switch state is the process interception state, determine that the process interception identifier associated with the task interceptor is found in the process auxiliary parameters; and use the result of finding the process interception identifier in the process auxiliary parameters as the second identifier search result.
[0037] Among them, the verification success module includes:
[0038] The task verification unit is used to call the verification service component in the process processing device through the task interceptor to perform task verification on the task i in the business process and obtain the task verification result when the second identifier search result indicates that the process interception identifier is found in the process auxiliary parameters;
[0039] The task execution unit is used to send a task execution request to the business server associated with the process engine component based on task i when the task verification result indicates that the task verification is successful, so that the business server executes task i for the business operation device based on the task execution request.
[0040] Among them, the task verification unit includes:
[0041] A rule search subunit is used to generate a task verification request for task i in the business process through a task interceptor, and send the task verification request to the verification service interface of the verification service component; the task verification request carries the process identifier corresponding to the business process and the device identifier of the business operation device; based on the task verification request, the verification service interface is called to search for a verification rule that matches the process identifier corresponding to the business process in the verification rule table configured by the verification service component, and when a verification rule that matches the process identifier corresponding to the business process is found in the verification rule table, the found verification rule is used as the task verification rule associated with task i;
[0042] The comparison and verification subunit is used to obtain the first device configuration information associated with the device identification of the business operation device from the device configuration system associated with the business operation device based on the task verification rule, and compare the first device configuration information with the task verification rule through the verification service component to obtain the task verification result.
[0043] Among them, the comparison and verification sub-unit is specifically used to compare the first device configuration information with the task verification rules through the verification service component. If the first device configuration information is consistent with the task verification rules, the task verification is determined to be successful; if the first device configuration information is inconsistent with the task verification rules, the task verification is determined to have failed; the result of the successful task verification or the result of the failed task verification is used as the task verification result.
[0044] Among them, the task verification rules are used to specify the target device department to which the business operation device belongs, the target device status of the business operation device, and the target network status; the first device configuration information includes one or more information of the first device configuration department to which the business operation device belongs, the first device configuration status of the business operation device, and the first network configuration status.
[0045] Among them, the task execution unit is specifically used to obtain the task identifier of task i and the process variables associated with task i through the process engine component when the task verification result indicates that the task verification is successful, generate a task execution request based on the task identifier and process variables of task i, and send the task execution request to the business server associated with the process engine component, so that the business server obtains the business logic corresponding to task i for the business operation device based on the task identifier of task i, and executes the business logic corresponding to task i when logging in to the business operation device through the process variables.
[0046] The device further comprises:
[0047] The verification failure module is used to not execute task i and (Mi) tasks after task i in the business process when the task verification fails, and send a first verification failure prompt message to the business client associated with the process engine component.
[0048] The device further comprises:
[0049] A process inspection module is used to obtain a process status table configured by a process engine component; the process status table records the process status of N processes; N is a positive integer; the N processes include business processes associated with business operation devices; the process status table is scanned, and when it is detected in the process status table that the process status of the business process is a process running state, the business operation device is verified by the verification service component in the process processing device, and when the device verification fails, a second verification failure prompt message is sent to the business client associated with the process engine component.
[0050] The process inspection module includes:
[0051] A rule search unit is used to send a device verification request to the verification service interface of the verification service component in the process processing device when it is detected in the process status table that the process state of the business process is the process running state; the device verification request carries the process identifier corresponding to the business process and the device identifier of the business operation device; based on the device verification request, the verification service interface is called to search for a verification rule matching the process identifier corresponding to the business process in the verification rule table configured by the verification service component, and when a verification rule matching the process identifier corresponding to the business process is found in the verification rule table, the found verification rule is used as the device verification rule associated with the business operation device;
[0052] A comparison and verification unit, configured to obtain, based on a device verification rule, second device configuration information associated with a device identifier of the business operation device from a device configuration system associated with the business operation device, and compare the second device configuration information with the device verification rule through a verification service component to obtain a device verification result;
[0053] The failure prompt unit is used to send second verification failure prompt information to the business client associated with the process engine component when the device verification result indicates that the device verification has failed.
[0054] An embodiment of the present application provides a computer device, including: a processor and a memory;
[0055] The processor is connected to the memory, wherein the memory is used to store a computer program. When the computer program is executed by the processor, the computer device executes the method provided in the embodiment of the present application.
[0056] On the one hand, an embodiment of the present application provides a computer-readable storage medium, which stores a computer program. The computer program is suitable for being loaded and executed by a processor so that a computer device having the processor executes the method provided by the embodiment of the present application.
[0057] In one aspect, the present application provides a computer program product or a computer program, which includes a computer instruction stored in a computer-readable storage medium. A processor of a computer device reads the computer instruction from the computer-readable storage medium, and the processor executes the computer instruction, so that the computer device executes the method provided in the present application.
[0058] In an embodiment of the present application, a process processing device can obtain a business process associated with a business operation device, and create a task i to be executed through M tasks associated with the business operation device in the business process; wherein M is a positive integer; i is a positive integer less than or equal to M; before executing task i, a task interception identifier associated with a task interceptor can be searched in the task auxiliary parameters of task i to obtain a first identifier search result; further, when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, the task interceptor can be called through the process engine component, and the process interception identifier associated with the task interceptor can be searched in the process auxiliary parameters corresponding to the business process to obtain a second identifier search result; it can be understood that when the second identifier search result indicates that the process interception identifier is found in the process auxiliary parameters, a task verification can be performed on task i in the business process, and when the task verification is successful, the business server associated with the process engine component can be notified to execute task i for the business operation device. It can be seen that the embodiment of the present application provides a solution for task operation security detection based on the process engine. In the field of IT workflow, the process engine (i.e., the aforementioned process engine component) is used as the scheduling core, and task interception is implemented inside the process engine through a task pre-interceptor (i.e., the aforementioned task interceptor). Before the process engine drives the scheduling of atomic tasks in the business process (tasks that only implement one operation, such as the aforementioned task i), it searches for an interception identifier associated with the task interceptor (i.e., the aforementioned task interception identifier and the process interception identifier) to achieve precise interception on demand from the two dimensions of task + process, and then triggers task verification of the intercepted atomic task, and executes the atomic task after the verification is successful. In other words, task operations can be performed under the premise of ensuring safety, thereby improving the safety and reliability of task execution. BRIEF DESCRIPTION OF THE DRAWINGS
[0059] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0060] Figure 1 It is a schematic diagram of a system architecture provided by an embodiment of the present application;
[0061] Figure 2 It is a schematic diagram of a scenario of task data processing provided by an embodiment of the present application;
[0062] Figure 3 This is a flowchart of a task data processing provided by an embodiment of the present application. Figure 1 ;
[0063] Figure 4 is a schematic diagram of a task function header provided in an embodiment of the present application;
[0064] Figure 5 is a schematic diagram of a task interception list provided in an embodiment of the present application;
[0065] Figure 6 is a schematic diagram of a task switch list provided in an embodiment of the present application;
[0066] Figure 7 It is a schematic diagram of a process function header provided in an embodiment of the present application;
[0067] Figure 8 is a schematic diagram of a process interception list provided in an embodiment of the present application;
[0068] Fig. 9 is a schematic diagram of a process switch list provided in an embodiment of the present application;
[0069] Fig.10 is a schematic diagram of a task interception scenario provided in an embodiment of the present application;
[0070] Fig.11 It is a schematic diagram of a process variable provided in an embodiment of the present application;
[0071] Fig.12 is a schematic diagram of a verification rule table provided in an embodiment of the present application;
[0072] Fig.13 This is a flowchart of a task data processing provided by an embodiment of the present application. Figure 2 ;
[0073] Fig.14 This is a schematic diagram of the architecture of a process engine-based automatic task operation safety detection system provided in an embodiment of the present application;
[0074] Fig.15 It is a structural diagram of a task data processing device provided in an embodiment of the present application;
[0075] Fig.16 It is a structural diagram of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0076] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0077] See also Figure 1 , Figure 1 Schematic diagram of a system architecture provided by an embodiment of the present application. Figure 1 As shown, the system architecture may include a server 100 and a terminal cluster, and the terminal cluster may include multiple terminal devices. The embodiment of the present application does not limit the number of terminal devices contained in the terminal cluster. For example, the terminal cluster may specifically include: terminal device 200a, terminal device 200b, terminal device 200c, ..., terminal device 200n, wherein there may be a communication connection between the terminal clusters, for example, there is a communication connection between terminal device 200a and terminal device 200b, and there is a communication connection between terminal device 200a and terminal device 200c. At the same time, any terminal device in the terminal cluster may be in communication connection with the server 100, for example, there is a communication connection between terminal device 200a and server 100. Among them, the above-mentioned communication connection does not limit the connection method, and may be directly or indirectly connected by wired communication, or directly or indirectly connected by wireless communication, or by other methods, which are not limited by the present application.
[0078] Wherein, the server 100 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud database, cloud service, cloud computing, cloud function, cloud storage, network service, cloud communication, middleware service, domain name service, security service, CDN, and big data and artificial intelligence platform. Wherein, the number of servers indicated by the server 100 can be one or more, a terminal device can be connected to a server, and each server can obtain the data uploaded by the terminal device connected thereto. Wherein, the terminal device can be a smart phone, a tablet computer, a laptop computer, a desktop computer, a PDA, a mobile Internet device (mobile internet device, MID), a wearable device (such as a smart watch, a smart helmet, etc.), a smart computer, a smart home, a smart car and other smart terminals. Wherein, the terminal device and the server can be directly or indirectly connected by wire or wireless means, and the embodiments of the present application are not limited here.
[0079] It should be understood that Figure 1Each terminal device in the terminal cluster shown in the figure may be installed with a client. When the client runs in each terminal device, it can communicate with the above-mentioned Figure 1 Data is exchanged between the servers 100 shown. The client may be an instant messaging client, a social client, an entertainment client (e.g., a game client, a live broadcast client, a novel client), a multimedia client (e.g., a short video client, a music client), a shopping client, a tool client (e.g., a payment client, a document editing client), a car client, a smart home client, a browser, or other application programs that have the function of displaying data information such as text, images, videos, and audio. The client may be an independent client or an embedded sub-client integrated in a client (e.g., an instant messaging client, a social client, etc.), which is not limited here.
[0080] Among them, terminal devices can be roughly divided into two terminal types according to their operation methods. For the convenience of distinction, they can be referred to as the first terminal type and the second terminal type respectively. Among them, terminal devices with the first terminal type (also referred to as desktop devices or desktop-oriented terminal devices) refer to terminal devices that mainly use interactive operations such as mouse clicks and keyboard input, and any client running on such terminal devices can usually support opening one or more windows at the same time (that is, supporting multi-page display). Therefore, such terminal devices have the characteristics of interacting with windows as the dimension. Terminal devices with the first terminal type may include laptops, desktop computers, smart computers, some tablet computers (such as Microsoft's Surface Pro, which can be operated with an external keyboard and mouse), etc.; terminal devices with the second terminal type (also referred to as non-desktop devices) refer to terminal devices that mainly use interactive operations such as user hand clicks or slides, and any client running on such terminal devices can usually only open one window (that is, supporting single-page display). Terminal devices with the second terminal type may include smart phones, some tablet computers (such as iPads), mobile Internet devices, wearable devices (such as smart watches, smart bracelets, etc.), smart cars, etc. It can be understood that based on this, the embodiments of the present application can also divide the clients installed and running on different terminal types into two client types, wherein the client type of the client installed and running on the terminal device having the first terminal type can be referred to as the first client type (i.e., a desktop-oriented client, also referred to as a non-mobile terminal, such as a computer terminal), and the client type of the client installed and running on the terminal device having the second terminal type can be referred to as the second client type (i.e., a mobile terminal, such as a mobile phone terminal). For the two different client types of the same application, there may also be certain differences in their page layout and interaction methods. The method provided in the present application is applicable to all client types. Therefore, all embodiments of the present application do not limit the terminal type of the terminal device involved, and do not limit the client type of the client involved, and the differences in the page layout and interaction methods of different client types will not be distinguished and described later.
[0081] It is understandable that IT departments face tedious and complex daily work every day, such as handling service requests, managing and testing hardware and software, implementing new technologies and finding errors, testing compliance and security, performing maintenance, etc. In order to free up resources and manpower for other work, IT process automation can be reused. IT Process Automation (ITPA) here refers to the use of technology and tools to automatically execute, coordinate and control various repetitive and tedious tasks, processes and operations within the IT department. Its purpose is to improve work efficiency, reduce human errors, speed up task completion, and free up IT personnel's time so that they can focus on more strategic and creative work. IT process automation can be achieved by writing scripts, using automation tools and platforms, and implementing workflows. It accelerates the delivery of IT infrastructure and applications by automating manual processes that originally required human intervention. This can reduce repetitive work, reduce human errors, improve efficiency, save costs, and also help ensure the consistency and repeatability of work. After determining the task to be automated, you can create a workflow (including specified processes) for the function of the task. These workflows can be pre-scheduled or automatically activated when a specific situation occurs or relevant trigger conditions are met; based on relevant configurations, you can also set up notifications or prompts as needed for further action. With the rise of virtualized networks and cloud services that require fast and complex provisioning, IT process automation has become an indispensable strategy to help IT departments improve the speed, consistency and security of service delivery. For example, IT process automation can enable IT departments to operate efficiently in environments where thousands of servers often need to be set up and configured.
[0082] Among them, the above-mentioned client can be an application that supports IT process automation, and the server 100 can include multiple servers such as business servers, data processing servers, data storage servers, etc. corresponding to the client. Therefore, each terminal device can transmit data with the server 100 through the client. For example, each terminal device can initiate a request to the server 100 to start a specified process (such as a deployment process) through the client it runs. After receiving the request, the server 100 can use the relevant configuration to start the specified process and create corresponding task nodes so as to drive the relevant business modules to perform tasks for the specified device (such as restarting a server).
[0083] It should be noted that in the field of IT workflow, there are certain risks in executing automated tasks. For example, assuming that a restart task needs to be executed on server A, when server A is running under the designated department B1 (such as the operations department), since department B1 can perform any operation on server A, it is safe to restart server A at this time; and when server A is running under another department B2 (such as the business department), restarting server A may cause business interruption or data loss, which is high risk. In order to achieve the purpose of performing security checks before executing automatic atomic tasks and preventing the execution of automated tasks, the embodiment of the present application proposes a solution based on process engine task operation security detection. Before executing automated tasks, a task pre-interceptor can be implemented inside the process engine. The interceptor performs multi-dimensional environment and status checks on the objects of task operations, and executes automated tasks after checking safety, thereby improving the security and reliability of task execution and realizing IT workflow task operation security detection.
[0084] To facilitate subsequent understanding and explanation, the client used to initiate the IT workflow can be collectively referred to as a business client. The business client can run on a terminal device (which can be called a business terminal). The implementation (such as page layout and interaction mode) and functions of the business client are related to specific businesses (such as instant messaging, games, live broadcasts, shopping, etc.), and are not limited here. In addition, depending on the different operating modes, the business client may include but is not limited to client applications, applets running as subroutines in the client, and web applications opened through a browser, etc. The operating mode of the business client is not limited here. Similarly, IT personnel associated with the business client can also be referred to as business objects, and business objects can interact with the business client to trigger the operation of the IT workflow. At the same time, computer devices used to process IT workflows (such as security verification, task interception, etc.) can be collectively referred to as process processing devices. The process processing device can be a terminal device or a server. The specific form of the process processing device is not limited in the embodiments of the present application. The process processing device may include a process engine component and a verification service component, wherein the process engine component may be referred to as a process engine or a workflow engine, which is a set of tools for implementing and driving IT workflows, and may be used to generate process instances, schedule / process the status of tasks, process variables, etc. The embodiment of the present application does not limit the type of process engine component used, for example, jBPM5, Activiti, Workflow Server or other process engines may be used. It is understandable that a task interceptor is deployed on the process engine component, which is mainly used to intercept the execution of high-risk tasks within the process engine component, thereby avoiding the occurrence of operational accidents. Among them, the verification service component refers to an implementation tool that provides a multi-dimensional security verification service (or is called a multi-dimensional task security microservice, a multi-dimensional security microservice), which is responsible for specific security verification.
[0085] It should be noted that the process engine component and the verification service component can be deployed on the same device or on different devices. For example, when the process engine component and the verification service component are deployed on the same device, optionally, the process engine component and the verification service component can be different components independently deployed on the same device; optionally, the verification service component can also be deployed inside the process engine component, but independent of the task interceptor; optionally, the verification service component can also be directly deployed inside the task interceptor. For another example, when the process engine component and the verification service component are deployed on different devices, for ease of distinction, the device on which the process engine component is deployed can be referred to as a first process processing device, and similarly, the device on which the verification service component is deployed can be referred to as a second process processing device, and the first process processing device and the second process processing device can be collectively referred to as the aforementioned process processing devices. The embodiments of the present application do not limit the deployment method of the process engine component, the verification service component, and the task interceptor.
[0086] In the embodiment of the present application, the IT workflow is automatically executed without manual intervention, and can be applied to a variety of scenarios that require IT automated process operations, such as shopping, social networking, entertainment, and education. It can be understood that each time an IT workflow is started, a process instance (also referred to as an IT process, or simply a process) is actually started. The process instance here can be understood as an executable process object instantiated according to a pre-configured process template (such as a flowchart), and the execution of different process instances does not affect each other. Among them, a process instance can contain one or more tasks, and the number of tasks contained in the process instance is not limited here. The operation object (i.e., the object of the task operation) targeted by each task in the same process instance is the same computer device (or machine). For the convenience of distinction, the operation object can be referred to as a business operation device, and the business operation device can be a server or a terminal device. The specific form of the business operation device is not limited in the embodiment of the present application. In the embodiment of the present application, the tasks in the process instance are not executed by the aforementioned process processing device, but by the business module to execute specific business logic and log in to the business operation device to execute the corresponding operation / command (such as power on, power off, restart, etc.). Relative to the process processing equipment, the business module here can be understood as the business system of a third-party business (including but not limited to instant messaging, shopping, social networking, entertainment, and education), which can be driven by relevant codes. Its specific implementation is determined by the third party according to its own business needs. Different businesses can deploy different business modules, and the number of business modules deployed by the same business can be one or more. Therefore, multiple tasks in a process instance can be executed by the same business module, or they can be distributed to multiple business modules for execution, which is not limited here. For the sake of distinction, the server used to execute specific business logic can be called a business server, and the business server is deployed with relevant business modules. Among them, the business server and business operation equipment in the embodiment of the present application can be deployed in different places, such as the business server is deployed in A, and the business operation equipment is deployed in B (B can be deployed with a large number of operational devices), so it is possible to remotely log in to the business operation equipment through the business server for operation.
[0087] It can be understood that the business client belongs to the business front desk (also known as the business front end, or simply the front desk, front end), and the process processing equipment, business server and business operation equipment all belong to the business back end (also known as the business back end, or simply the back end, back end) corresponding to the business front desk. Data can be exchanged between the business front desk and the business back end so that the business back end can provide computing and application service support for the business front desk.
[0088] Among them, the business client and the process processing device (the process engine component therein), the process processing device (the process engine component therein) and the business server, the business server and the business operation device, and the components / modules inside the process processing device (such as the aforementioned process engine component, verification service component and task interceptor) can all be directly or indirectly connected to each other through wired or wireless means, and the embodiments of the present application are not limited to this.
[0089] It is understandable that for the same operation object, different process instances can be started to meet different automation requirements. For example, when server 1 needs to reinstall the system and redeploy, a reinstallation process instance and a deployment process instance can be started for server 1 respectively. If different operation objects are targeted, different process instances also need to be started. For example, when both server 1 and server 2 need to reinstall the system, a reinstallation process instance C1 for server 1 and a reinstallation process instance C2 for server 2 can be started respectively. For ease of distinction, the embodiment of the present application can use any process instance started for the aforementioned business operation device as a business process associated with the business operation device. For example, when the aforementioned server 1 is used as a business operation device, the aforementioned reinstallation process instance C1 can be used as a business process associated with server 1. After the business process is acquired, the process processing device can perform relevant processing on the business process.
[0090] Based on this, in an embodiment of the present application, the process processing device can obtain the business process associated with the business operation device, and create a task i to be executed through M tasks associated with the business operation device in the business process; wherein M is a positive integer; i is a positive integer less than or equal to M; before executing task i, the task interception identifier associated with the task interceptor can be searched in the task auxiliary parameters of task i to obtain a first identifier search result; when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, the task interceptor can be called through the process engine component, and the process interception identifier associated with the task interceptor can be searched in the process auxiliary parameters corresponding to the business process to obtain a second identifier search result; it can be understood that when the second identifier search result indicates that the process interception identifier is found in the process auxiliary parameters, the task i in the business process can be checked, and when the task check is successful, the business server associated with the process engine component can be notified to execute task i for the business operation device.
[0091] For easier understanding, please refer to Figure 2 , Figure 220A, 20B, 20C, and 20D are used as examples to illustrate the implementation of the present application. The present application embodiment takes device 20A, device 20B, server 20C, and device 20D as examples. The device 20A here can be used as the aforementioned service terminal. The device 20A can be used as the aforementioned service terminal. Figure 1 Any terminal device in the terminal cluster shown (for example, terminal device 200a). Device 20B can be used as the aforementioned process processing device. Device 20B can be a terminal device or a server, which is not limited here. The embodiment of the present application takes device 20B as an example to illustrate the server. For example, the device 20B can be the aforementioned Figure 1 The server 100 shown in FIG. 20C can be used as the aforementioned service server. The device 20D can be used as the aforementioned service operation device. The device 20D can be a terminal device or a server, which is not limited here. The embodiment of the present application takes the device 20D as a server as an example for explanation.
[0092] like Figure 2 As shown, user 21a can be used as the aforementioned business object and has a binding relationship with device 20A. Multiple clients (e.g., instant messaging client, game client, audio and video client, etc.) can be installed and run on device 20A for use by user 21a, wherein the multiple clients can include client 21b with IT process initiation function, and the client 21b can be used as the aforementioned business client (e.g., in the game scenario, it can be a game client). In this way, when user 21a wants to initiate an IT process, it can use its IT process initiation function by starting client 21b, thereby starting a process instance for a certain device. For example, when user 21a wants to initiate a process instance for device 20D through client 21b, client 21b can respond to the process initiation operation of user 21a for device 20D and send a process initiation request 21c to device 20B to start the process instance associated with device 20D.
[0093] like Figure 2As shown, the device 20B includes a process engine component 21d and a verification service component 21o, and a task interceptor 21j is deployed on the process engine component 21d. The deployment method of the process engine component 21d, the verification service component 21o and the task interceptor 21j on the device 20B is not limited here. It can be understood that when the device 20B obtains the aforementioned process start request 21c through the process engine component 21d, it can obtain the process template data associated with the process instance requested to be started based on the process start request 21c. The process template data is used to describe a process model, which can be understood as a basic template required to start a process instance, including but not limited to a flowchart and a process definition file pre-configured for the process engine component 21d, wherein the flowchart here refers to a configuration file that uses a graphical method to abstractly express IT processes and related operations, and the process definition file refers to a configuration file that uses a special modeling language (such as BPMN (Business Process Model And Notation)) to define IT processes and related operations, rules, parameters, etc. The process template data may be represented in a specified data format as required, such as XML (Extensible Markup Language) format, JSON (JavaScript Object Notation) format, etc. There is no limitation on the data format used by the process template data.
[0094] For example, assuming that the process template data obtained by the process engine component 21d based on the process start request 21c is a flowchart 21e, a corresponding process instance, such as process 21f, can be generated according to the flowchart 21e as the aforementioned business process associated with the business operation device. Among them, the flowchart 21e can be used to describe M operations for the device 20D, for example, the M operations can specifically include operation 1, operation 2, operation 3, ..., operation M, and the specific content of each operation is not limited here; accordingly, the process 21f instantiated according to the flowchart 21e can include M tasks associated with the device 20D, and the M tasks here can specifically include task 1, task 2, task 3, ..., task M. It can be understood that the M tasks in the process 21f can be created by the process engine component 21d in a parallel or serial manner, and the task creation method is not limited here.
[0095] It should be noted that in order to ensure that each operation can be executed safely, the solution provided in the embodiment of the present application is to intercept and verify each atomic task in the IT process on demand. For example, the M tasks in the above process 21f are all atomic tasks. The atomic task here can be understood as the smallest execution unit of the task. The process engine component will schedule one or more related task nodes in sequence after generating the process instance. Each task node corresponds to an atomic task, and each atomic task only implements an operation for the business operation device. For example, assuming that M=4, the four operations described in the above flowchart 21e are server restart operation, server disk RAID (Redundant Array of IndependentDisks, that is, independent disk redundant array, which can be referred to as disk array, used to improve data storage capacity and read and write speed) operation, server hard disk formatting operation, server OS (Operation System, that is, operating system, such as Windows) installation operation, then the four tasks included in process 21f are server restart-task, server disk RAID-task, server hard disk formatting-task, server OS installation-task.
[0096] It is understandable that the M tasks include the task i to be executed created by the process engine component 21d, where i is a positive integer less than or equal to M, that is, task i can be any one of task 1, task 2, task 3, ..., task M, and there is no limitation here. The processing process of each atomic task in the embodiment of the present application is consistent, and the specific process of task verification will be described here by taking task i as an example.
[0097] It should be noted that any process can be composed of one or more tasks, and the same task can be reused by multiple different processes. For example, the server startup task can be reused by the reinstallation process and the deployment process. Therefore, the embodiment of the present application will perform precise interception on demand from the two dimensions of task + process.
[0098] like Figure 2As shown, before executing task i, in order to determine whether task verification is required for task i, interception can be performed on demand from the task dimension. For example, device 20B can obtain task auxiliary parameters of task i (such as parameter 21g) through process engine component 21d, and then search for the task interception identifier associated with task interceptor 21j in parameter 21g to obtain the first identifier search result (such as identifier search result 21i). It can be understood that, optionally, if a task interception identifier (such as identifier 21h) is found in parameter 21g, it means that there may be risks in any process (such as process 21f) for task i (i.e., task i in process 21f may be a high-risk task), and it is necessary to further trigger task interceptor 21j to determine whether it is really necessary to perform task verification on task i; conversely, optionally, if no task interception identifier (such as identifier 21h) is found in parameter 21g, it means that there is no risk in any process (such as process 21f) for task i (i.e., task i in process 21f is not a high-risk task), and there is no need to perform task verification on task i, and the notification server 20C can directly execute task i. Among them, the task auxiliary parameters and task interception identifiers in the embodiments of the present application can have a variety of different forms of expression, which are not limited here. For example, the aforementioned parameter 21g can specifically be the task function header of task i, and correspondingly, the identifier 21h can specifically be the task interception annotation information, that is, the task interception annotation information associated with the task interceptor 21j can be searched in the task function header of task i to obtain the corresponding identifier search result 21i.
[0099] Furthermore, within the task interceptor, interception can be performed as needed from the process dimension. For example, when the identifier search result 21i indicates that the identifier 21h is found in the parameter 21g, the task interceptor 21j can be called through the process engine component 21d to search for the process interception identifier associated with the task interceptor 21j in the process auxiliary parameters corresponding to the process 21f (such as parameter 21k), and obtain the second identifier search result (such as the identifier search result 21n). It can be understood that, optionally, if a process interception identifier (such as identifier 21m) is found in parameter 21k, it means that there is a risk in task i in process 21f (that is, task i in process 21f is a high-risk task), and it is necessary to further trigger the verification service component 21o to perform task verification on task i; conversely, optionally, if no process interception identifier (such as identifier 21m) is found in parameter 21k, it means that there is no risk in task i in process 21f (that is, task i in process 21f is not a high-risk task), and there is no need to perform task verification on task i through verification service component 21o, and the notification server 20C can directly execute task i. Among them, the process auxiliary parameters and process interception identifiers in the embodiments of the present application can have a variety of different forms of expression, which are not limited here. For example, the aforementioned parameter 21k can specifically be a process interception list (also called a process interception whitelist) configured by the task interceptor 21j, which records all process identifiers that require the task interceptor 21j to perform task interception. Correspondingly, the identifier 21m can specifically be a process identifier corresponding to the process 21f. That is to say, the process identifier corresponding to the process 21f can be searched in the process interception list to obtain the corresponding identifier search result 21n.
[0100] Further, when the identification search result 21n indicates that the identification 21m is found in the parameter 21k, the task i in the process 21f may be checked, such as Figure 2As shown, the task interceptor 21j can call the verification service component 21o to perform task verification on task i to obtain the task verification result (such as task verification result 21p). It can be understood that, optionally, when the task verification result 21p indicates that the task verification is successful, it means that it is safe to execute task i. The device 20B can notify the server 20C associated with the process engine component 21d to execute task i for the device 20D. Subsequently, the next task can be intercepted and verified as needed through a similar process until all tasks in the process 21f are completed or the process processing is interrupted. Among them, the server 20C is deployed with a business module 21q. The server 20C can call the business module 21q to execute the business logic corresponding to task i, and log in to the device 20D to execute the corresponding operation / command. For example, when task i is a server hard disk formatting-task, it can log in to the device 20D to execute the hard disk formatting command (i.e., format the hard disk of the device 20D). On the contrary, optionally, when the task verification result 21p indicates that the task verification has failed, it means that it is unsafe to execute task i. At this time, task i and other tasks after task i will not be executed, that is, the processing of process 21f will be interrupted at the task node corresponding to task i; the device 20B can send a corresponding prompt message to the client 21b based on the task verification result 21p, to notify the user 21a that the task verification has failed.
[0101] It is understandable that one or more business modules can be deployed on the business server according to business needs, and when the task is executed, the business module associated with the business operation device can be selected from these one or more business modules for calling. As can be seen from the above, in the field of IT automated process operations, the embodiment of the present application does not perform security checks in the business module (highly coupled with the business), but takes the process engine component as the scheduling core. Before the process engine component drives the scheduling task, a multi-dimensional security check is uniformly performed through the task interceptor, which efficiently and concisely implements the function of performing task checks on demand before task execution, which is independent of the specific business. The advantage of this is that there is no need to change any logic of the business module, and the task scheduling characteristics of the process engine component are used to solve the problem of universality. It has the characteristics of high cohesion, is decoupled from the specific business, has high scalability, and is easy to maintain later.
[0102] It should be noted that the embodiments of the present application can use a parallel or serial method to identify and perform on-demand task verification on multiple tasks to be executed (such as the aforementioned tasks 1 to M to be executed) in the same process (such as the aforementioned process 21f), but the tasks are still executed in sequence (for example, the process engine component can use queues to implement serial execution of tasks). When there are multiple processes at the same time, only one task interceptor needs to be deployed on the process engine component, and all processes can schedule the same task interceptor. In other words, in a lightweight way, the same process engine component and task interceptor can be used to identify and perform optional task verification on tasks to be executed in different processes. The specific processing of other processes is similar to the aforementioned processing of process 21f, which will not be repeated here.
[0103] It can be understood that the interactive operations involved in all embodiments of the present application (such as the aforementioned process start operation) may include but are not limited to gesture operations, voice signal input operations, etc.; wherein, gesture operations may include but are not limited to: single-click operations, double-click operations (such as clicking the same position in the interface twice in a short time (such as 3 seconds)), long press operations (such as performing continuous pressing operations on any position in the interface), sliding operations (such as fast sliding operations in different directions, sliding operations with preset shapes (such as sliding tracks of "S" shape or "L line"), etc.), drag operations, etc.; voice signal input operations may refer to the operation of collecting voice signals in the physical environment (i.e., the surrounding environment where the business object is located) through the microphone of the business terminal to indicate the display of a certain interface. The specific form of the interactive operation is not limited here.
[0104] From the above, it can be seen that the solution provided by the embodiment of the present application, in the field of IT workflow, takes the process engine as the scheduling core, and implements task interception through a task pre-interceptor inside the process engine. Before the process engine drives the scheduling of atomic tasks in the business process, it searches to see whether there is an interception identifier associated with the task interceptor, so as to achieve precise interception on demand from the two dimensions of task + process, and then trigger task verification of the intercepted atomic task, and execute the atomic task after the verification is successful. In other words, task operations can be performed under the premise of ensuring safety, thereby improving the safety and reliability of task execution.
[0105] It should be noted that the method provided in the embodiment of the present application is applicable to various business scenarios such as instant messaging, shopping, social networking, entertainment, education, etc. that require security verification of IT automated process operations or workflow atomic tasks, such as server and application deployment, fault diagnosis and repair, backup and recovery, update and patch processing, detection and reminders, user account management, auditing and compliance, work order and request processing, reporting and analysis, etc. The specific business scenarios will not be listed one by one here.
[0106] For example, in the server and application deployment scenario, process D1 can be started, and then before executing any atomic task in process D1, it can be determined whether to intercept and verify the atomic task based on the relevant identification search results, and the atomic task can be executed when the task verification is successful, thereby automating the deployment, configuration and management of servers and applications, and ensuring the consistency of the system in different environments. For example, assuming that a game application needs to be deployed on a designated game server, the game developer, as the aforementioned business object, can initiate a game application deployment process through an associated business client (such as a game client). The game application deployment process can be used as the aforementioned business process, and the relevant process processing equipment can perform task verification on demand before executing the atomic task in the game application deployment process by deploying a process engine component with a task interceptor and a verification service component; when determining to execute the task, the business server associated with the game application is dispatched, and the designated game server is logged in to perform the corresponding operation, and finally the deployment of the game application is realized.
[0107] For example, in a fault diagnosis and repair scenario, process D2 can be started, and then before executing any atomic task in process D2, it can be determined whether to intercept and verify the atomic task based on the relevant identification search results, and the atomic task can be executed when the task verification is successful, thereby automating the fault detection, diagnosis and repair process to reduce downtime and improve system availability.
[0108] For example, in a backup and recovery scenario, process D3 can be started, and before executing any atomic task in process D3, it can be determined whether to intercept and verify the atomic task based on the relevant identification search results, and the atomic task can be executed when the task verification is successful, thereby automating the data backup and recovery process and ensuring data security and reliability.
[0109] For example, in the update and patch processing scenario, process D4 can be started, and then before executing any atomic task in process D4, it can be determined whether to intercept and verify the atomic task based on the relevant identification search results, and the atomic task can be executed when the task verification is successful, thereby automating the update and patch processing of the operating system and software to maintain the security and stability of the system.
[0110] For example, in the detection and reminder scenario, process D5 can be started, and then before executing any atomic task in process D5, it can be determined whether to intercept and verify the atomic task based on the relevant identification search results, and the atomic task can be executed when the task verification is successful, thereby automatically detecting the operating status of the system, sending reminder notifications when problems occur, and executing predetermined response measures.
[0111] For example, in the user account management scenario, process D6 can be started, and then before executing any atomic task in process D6, it can be determined whether to intercept and verify the atomic task based on the relevant identification search results, and the atomic task can be executed when the task verification is successful, thereby automating the creation, modification and cancellation of user accounts to ensure correct management of permissions.
[0112] For example, in an audit and compliance scenario, process D7 can be started, and before executing any atomic task in process D7, it can be determined whether to intercept and verify the atomic task based on the relevant identification search results, and the atomic task can be executed when the task verification is successful, thereby automating audits and compliance checks to ensure that the system complies with regulations and standards.
[0113] For example, in the work order and request processing scenario, process D8 can be started, and then before executing any atomic task in process D8, it can be determined whether to intercept and verify the atomic task based on the relevant identification search results, and the atomic task can be executed when the task verification is successful, thereby automating the work order and request processing flow and improving service response speed and quality.
[0114] For example, in a reporting and analysis scenario, process D9 can be started, and before executing any atomic task in process D9, it can be determined whether to intercept and verify the atomic task based on the relevant identification search results, and the atomic task can be executed when the task verification is successful, thereby automatically generating reports and analyzing data to provide decision support information.
[0115] The specific process of the process processing device performing task verification on the tasks in the business process can be seen as follows Figures 3 to 14 The corresponding embodiment.
[0116] For further information, see Figure 3 , Figure 3 This is a flowchart of a task data processing provided by an embodiment of the present application. Figure 1 .like Figure 3 As shown, the method can be executed by a process processing device, and a task interceptor is deployed on the process engine component in the process processing device. The method can specifically include the following steps S101-S104.
[0117] Step S101, obtaining a business process associated with a business operation device, and creating a task i to be executed through M tasks associated with the business operation device in the business process;
[0118] It can be understood that in order to ensure that the execution of each atomic task in the IT process is safe and reliable, when the business object requests to start the IT process associated with the business operation device, the process processing device can generate a corresponding process instance and create a corresponding atomic task, that is, the process processing device can obtain the business process associated with the business operation device, and then create a task i to be executed through the M tasks associated with the business operation device in the business process, where M is a positive integer and i is a positive integer less than or equal to M, that is, task i can be any one of the M tasks to be executed.
[0119] The embodiment of the present application can support the business object to initiate a process start request to the process processing device through the business client, so that the process processing device starts the corresponding process instance. Figure 2 The device 20B shown in FIG. 20B) can be connected to the process engine component (such as the above Figure 2 The process engine component 21d shown in the figure obtains the business client associated with the process engine component (such as the above Figure 2 The process start request (such as the above Figure 2 The process start request 21c shown in the figure); the process start request is used to start the business operation device (such as the above Figure 2 The business process associated with the device 20D shown in the figure (such as the above Figure 2 The process processing device can obtain process template data associated with the business process based on the process start request (such as the above Figure 2The process template data can be understood as the basic template required to start a process instance, which may include but is not limited to the flowchart and process definition files pre-configured for the process engine component. The form, content and data format of the process template data are not limited here; the process template data can be customized by the business object through the modeling tool provided by the process engine component, and can be deployed in the template database associated with the process engine component, which is equivalent to the configuration file of the process engine component. For example, the business object can draw the required flowchart through the modeling tool and import it into the process engine component as a configuration file. The flowchart can be scheduled as needed to generate the corresponding process instance. The template database refers to a database (DataBase, which can be referred to as DB) for storing process template data, which can store any one or more of multiple flowcharts and multiple process definition files. The type of the template database is not limited here. Correspondingly, the business process here is actually a process instance for a specified business operation device, which can represent a series of operations that need to be performed on the business operation device. The specific content of the business process is not limited here. The embodiment of the present application generates process instances through process template data, which can improve the generation efficiency of process instances (such as the aforementioned business processes), thereby helping to improve the overall process processing efficiency.
[0120] Among them, the process start request can be generated by the business client in response to the process start operation of the business object for the business operation device. For example, the business client can display the process start interface, and an entry for submitting relevant information (which can be called the process information submission entry) can be provided on the process start interface. The business object enters the relevant information required to start the business process (which can be called the process start information, such as the process identifier corresponding to the business process, the device identifier of the specified business operation device, etc.) through the process information submission entry and clicks submit (for example, the process start interface can include a submit control), and this information can be submitted to the process engine component, which is equivalent to notifying the process engine component that the current business object needs to initiate a process instance, and then the process engine component can generate the corresponding process instance. It should be noted that the form of the process start operation and the form of the process start interface (or other interface, or no interactive interface) are related to the specific business, and the embodiments of the present application do not limit this.
[0121] It can be understood that the business client and the process engine component can exchange data through a specified communication protocol to achieve secure and reliable data transmission and improve data transmission efficiency. The embodiment of the present application does not limit the communication protocol used between the business client and the process engine component. For example, HTTP (HyperText Transfer Protocol), SMTP (Simple Mail Transfer Protocal), FTP (File Transfer Protocol), etc. can be used. Based on the specified communication protocol, the business client can send the aforementioned process startup information to the process engine component by requesting reorganization or directly sending. For example, the business client can reorganize the process startup information into a process startup request, and then send the reorganized process startup request to the process engine component; or, optionally, the business client can also directly send the process startup information to the process engine component. The embodiment of the present application does not limit the specific method of transmitting the process startup information.
[0122] To facilitate understanding, taking a process start request as an example, the process start request can carry a process identifier corresponding to the business process. The process identifier here can also be called a process ID (ID is the abbreviation of identity document), which can be used to identify process instances (including business processes) generated by the same process template data. Usually, the corresponding process identifier is configured when configuring the process template data, and the process identifier can be associated with the process template data and stored in the template database. Therefore, the process identifier can also be understood as a template identifier of the process template data, for example, it can be a process name (such as an English name, a Chinese name or a name expressed in other languages), a process identification number or other forms, and the embodiments of the present application are not limited to this. That is to say, even if they are different process instances, as long as they are generated using the same process template data, they will have the same process identifier, but they can have different instance identifiers (that is, one instance identifier uniquely identifies a process instance). For example, the process identifier corresponding to the reinstallation process instance can be "ServerReinstallProcess" (or "reinstallation process"), and the process identifier corresponding to the deployment process instance can be "ServerDeployProcess" (or "deployment process"). For example, taking the aforementioned reinstallation process instance C1 and reinstallation process instance C2 as examples, the process identifier corresponding to the reinstallation process instance C1 and the process identifier corresponding to the reinstallation process instance C2 are both "ServerReinstallProcess" (or "reinstallation process"), but the instance identifier of the reinstallation process instance C1 can be "001", and the instance identifier of the reinstallation process instance C2 can be "002".
[0123] Based on this, the specific process of generating a business process through process template data can be: obtaining the process identifier corresponding to the business process from the process start request, and obtaining the business process diagram of the business process configuration from the template database associated with the process engine component according to the process identifier corresponding to the business process (such as the above Figure 2 21e), that is, obtaining the business process diagram associated with the process identifier, and the business process diagram can be used as the process template data associated with the business process. Or, optionally, the process definition file configured for the business process can be obtained from the template database associated with the process engine component according to the process identifier corresponding to the business process, that is, obtaining the process definition file associated with the process identifier, and the process definition file can be used as the process template data associated with the business process. For example, taking the aforementioned reinstallation process instance C1 as an example of the business process, the process processing device can obtain the flowchart or process definition file associated with the process identifier (such as "ServerReinstallProcess") corresponding to the reinstallation process instance C1 from the template database as the process template data associated with the reinstallation process instance C1.
[0124] Furthermore, the process processing device can initialize the process template data through the process engine component to obtain the initialized process template data, and perform process instantiation processing based on the initialized process template data to obtain the business process. Among them, initializing the process template data specifically refers to initializing the business process diagram or process definition file of the business process configuration, that is, initializing the process configuration, the main purpose of which is to prepare for subsequent instantiation. The process instantiation processing is equivalent to treating the initialized process template data as an initial template, which is not executable. It is necessary to instantiate a specific and executable process object (process instance) based on the initial template, that is, process instantiation, which may involve the instantiation of related operations and parameters.
[0125] Optionally, if the business client directly sends the process startup information to the process engine component, the process processing device can obtain the process startup information through the process engine component, and obtain the process identifier corresponding to the business process from the process startup information. Similarly, according to the process identifier corresponding to the business process, the business process diagram or process definition file configured by the business process can be obtained from the template database, and the obtained business process diagram or process definition file can be used as process template data associated with the business process; further, the process template data can be initialized through the process engine component to obtain initialized process template data, and the process instantiation processing can be performed based on the initialized process template data to obtain the business process.
[0126] It can be understood that after obtaining the business process, the process processing device can create M tasks through the process engine component for scheduling. The embodiment of the present application can support the creation of tasks in parallel or in serial. In actual applications, the appropriate task creation method can be selected as needed.
[0127] For example, optionally, if tasks are created in parallel, the process engine component can create M tasks associated with the business operation device through the business process (in parallel), and then obtain the task i to be executed from the M tasks. For example, assuming M=2, the process engine component can create task 1 and task 2 at the same time.
[0128] For another example, optionally, if a task is created in a serial manner, the process engine component can obtain the task execution order of the M tasks associated with the business operation device in the business process, and then create the task i to be executed according to the task execution order. For example, assuming M=2, after task 1 is created and executed, the process engine component will create task 2; or, after creating task 1 in sequence, task 1 may not be executed first, but task 2 may continue to be created. Among them, the task execution order of the M tasks is pre-defined in the above process template data, for example, the operation execution order of the M operations in the business process diagram is the task execution order of the corresponding M tasks.
[0129] It can be understood that the embodiments of the present application provide a variety of task creation methods, which can improve the flexibility of task creation and improve the overall process processing efficiency.
[0130] Step S102, before executing task i, searching the task auxiliary parameters of task i for a task interception identifier associated with the task interceptor to obtain a first identifier search result;
[0131] It is understandable that there may be hundreds or thousands of tasks processed by the process engine component, but not every task needs to be determined by the task interceptor whether to perform task verification (or multi-dimensional security verification). For example, assuming that a task will not operate a business operation device (such as a designated server), it is not a high-risk task, and there is no need to perform task verification on it. Therefore, the embodiment of the present application supports adding a task verification switch (also called a security verification switch or a multi-verification switch) to risky tasks, while there is no need to add a task verification switch to tasks without risks. Among them, the "adding a task verification switch" here can be expressed as adding a task interception identifier associated with the task interceptor to the task auxiliary parameters of the risky task, thereby triggering the task interceptor to make the next judgment.
[0132] It is understandable that whether a task is risky can be determined by the background judgment or IT personnel, which is mainly related to the specific purpose of the business operation equipment. The embodiments of the present application do not limit this. For example, tasks that actually operate business operation equipment can be designated as possible high-risk tasks (that is, they may not be high-risk tasks in some processes), such as shutdown, restart, formatting, OS installation and other tasks. It is necessary to add a task interception identifier to the task auxiliary parameters corresponding to such tasks. Since tasks can be reused by different processes, it is necessary to determine whether a task is a high-risk task based on the specific process in which it is located. On the contrary, tasks that will not actually operate business operation equipment can be designated as non-high-risk tasks, such as inspection tasks such as ping-tasks, where ping-tasks can be used to detect network connectivity and analyze network speed; that is, such tasks are not high-risk tasks under any circumstances and will not cause any damage to business operation equipment, so there is no need to add a task interception identifier to the corresponding task auxiliary parameters.
[0133] Based on this, for the aforementioned task i, when executing task i (such as the aforementioned Figure 2 Before the task i shown in the figure, the task auxiliary parameters of task i (such as the aforementioned Figure 2 The parameter 21g shown in FIG. 21a) searches for the task interception identifier associated with the task interceptor (such as the aforementioned Figure 2 The identification 21h shown in the figure) is used to obtain the first identification search result (such as the aforementioned Figure 2 The identification search result 21i shown, and whether to call the task interceptor can be determined later by the first identification search result. In the embodiment of the present application, it can support a variety of different forms of task auxiliary parameters and task interception identification. The task auxiliary parameters here refer to the general term for parameters associated with specific tasks, which can be used to assist in determining whether it is necessary to call a task interceptor, including but not limited to task function headers, task interception lists, task switch lists, etc.; the task interception identification here refers to the identification in the task auxiliary parameters used to indicate that there is a risk in the task and that the task interceptor needs to be called, which may include but is not limited to task interception annotation information, task identification, task interception status, etc. The embodiment of the present application will not list the forms of expression of task auxiliary parameters and task interception identification one by one.
[0134] For example, optionally, before executing task i, the task function header of task i can be obtained through the process engine component, and the task function header of task i can be used as the task auxiliary parameter of task i; the task interception annotation information associated with the task interceptor can be searched in the task auxiliary parameter of task i, and when the task interception annotation information is found, it can be determined that the task interception identifier associated with the task interceptor is found in the task auxiliary parameter of task i; and then the result of finding the task interception identifier in the task auxiliary parameter of task i can be used as the first identifier search result. The subsequent process can be further transferred to the processing process of step S103.
[0135] It can be understood that when executing task i, it is actually executing the task function of task i. The task function header of task i is the header of the task function. Therefore, before executing task i, if it is detected that there is task interception annotation information associated with the task interceptor in the task function header of task i, the task interception annotation information can be used as a task interception identifier, indicating that the task interceptor needs to be called. Among them, the task interception annotation information refers to the mark / annotation information in the task function header used to indicate that there is a risk in the task and the task interceptor needs to be called. Specifically, it can be a comment, mark, field, keyword or key-value pair added to the task function header. The specific form of the task interception annotation information is not limited here. Among them, for different tasks, the content of the task interception annotation information can be the same or different, which is not limited here.
[0136] For easier understanding, please also refer to Figure 4 , Figure 4 Schematic diagram of a task function header provided in an embodiment of the present application. Figure 4 The three tasks shown are task 401a (e.g., restart task), task 402a (e.g., operating system installation task), and task 403a (e.g., network detection task, i.e., ping task). Assuming that there are risks in task 401a and task 402a, but there is no risk in task 403a, specified task interception annotation information (e.g., task verification switch represented by comments 401b and 402b) can be added to the task function header of task 401a and the task function header of task 402a, and there is no need to add specified task interception annotation information in the task function header of task 403a.
[0137] It can be understood that, optionally, if the task interception annotation information is not found in the task auxiliary parameters of task i, it can be determined that the task interception identifier associated with the task interceptor is not found in the task auxiliary parameters of task i, and then the result when the task interception identifier is not found in the task auxiliary parameters of task i can be used as the first identifier search result. At this time, there is no need to call the task interceptor, that is, there is no need to perform task verification on task i, and the task interceptor can be directly skipped to execute task i.
[0138] For another example, optionally, before executing task i, the task interception list configured by the task interceptor can be obtained through the process engine component, and the task interception list can be used as the task auxiliary parameter of task i; the task interception list contains a task identifier for triggering the task interceptor; the task identifier of task i is searched in the task auxiliary parameter of task i, and when the task identifier of task i is found, it can be determined that the task interception identifier associated with the task interceptor is found in the task auxiliary parameter of task i; and then the result of finding the task interception identifier in the task auxiliary parameter of task i can be used as the first identifier search result. The subsequent process can be further transferred to the processing process of step S103.
[0139] It can be understood that the task interception list can be understood as a task interception whitelist for tasks configured by the task interceptor, which can be used to record the task identifiers of one or more tasks that need to call the task interceptor. That is to say, before executing task i, if it is detected that the task identifier of task i is included in the task interception list, the task identifier of task i can be used as the task interception identifier, indicating that the task interceptor needs to be called. Among them, the task identifier can also be called the task id, for example, it can be a task name, task sequence number or task identification number, etc., which is not limited here, and a task identifier is used to uniquely identify a task.
[0140] For easier understanding, please also refer to Figure 5 , Figure 5 Schematic diagram of a task interception list provided in an embodiment of the present application. Figure 5 The shown list 50 is an exemplary task interception list. Assuming that there are risks in task 501a (such as a restart task) and task 502a (such as an operating system installation task), task identifier 501b (such as "123") of task 501a and task identifier 502b (such as "456") of task 502a can be added to list 50.
[0141] It can be understood that, optionally, if the task identifier of task i is not found in the task auxiliary parameters of task i, it can be determined that the task interception identifier associated with the task interceptor is not found in the task auxiliary parameters of task i, and then the result when the task interception identifier is not found in the task auxiliary parameters of task i can be used as the first identifier search result. At this time, there is no need to call the task interceptor again, that is, there is no need to perform task verification on task i, and the task interceptor can be directly skipped to execute task i.
[0142] For another example, optionally, before executing task i, the task switch list configured by the task interceptor can be obtained through the process engine component, and the task switch list can be used as the task auxiliary parameter of task i; the task switch state of task i is searched in the task auxiliary parameter of task i, and when the task switch state found is the task interception state, it can be determined that the task interception identifier associated with the task interceptor is found in the task auxiliary parameter of task i; and then the result of finding the task interception identifier in the task auxiliary parameter of task i can be used as the first identifier search result. The subsequent process can be further transferred to the processing process of step S103.
[0143] It can be understood that the task switch list can be used to record the task switch status of all tasks. The task switch status here refers to the state of the task interceptor for a certain task, which may include the task interception status and the task release status. The task interception status can be used to indicate that the task interceptor is in an enabled state for a certain task, that is, the task needs to call the task interceptor; the task release status can be used to indicate that the task interceptor is in a disabled state for a certain task, that is, the task does not need to call the task interceptor. The task switch status can be represented in the form of fields, keywords, or key-value pairs, which are not limited here. Based on this, before executing task i, if it is detected that the task switch status of task i in the task switch list is a task interception status, the task interception status can be used as a task interception identifier. For ease of understanding, please refer to Figure 6 , Figure 6 is a schematic diagram of a task switch list provided in an embodiment of the present application. Figure 6 The shown list 60 is an exemplary task switch list. Assuming that there is a risk in task 601a (such as a restart task), the task switch state 601b of task 601a can be configured in list 60 as a task interception state (such as represented by "1"); assuming that there is no risk in task 602a (such as a network detection task), the task switch state 602b of task 602a can be configured in list 60 as a task release state (such as represented by "0").
[0144] It can be understood that, optionally, if the task switch state of task i found in the task auxiliary parameters of task i is the task release state, it can be determined that the task interception identifier associated with the task interceptor is not found in the task auxiliary parameters of task i, and then the result when the task interception identifier is not found in the task auxiliary parameters of task i can be used as the first identifier search result. At this time, there is no need to call the task interceptor again, that is, there is no need to perform task verification on task i, and the task interceptor can be directly skipped to execute task i.
[0145] It can be understood that the embodiments of the present application can enrich the triggering methods of the task interceptor and enhance the flexibility of the task verification switch configuration by providing various forms of task auxiliary parameters and task interception identifiers.
[0146] Step S103, when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, the task interceptor is called through the process engine component, and the process interception identifier associated with the task interceptor is searched in the process auxiliary parameters corresponding to the business process to obtain a second identifier search result;
[0147] It is understandable that a task interceptor before task execution is added to the internal execution link of the process engine component. Since tasks and processes are two different dimensions, a task can belong to multiple processes, and the risk level of the same task in different processes may be different. For example, the restart-task is a high-risk task in a certain process and requires task verification, but it is not a high-risk task in another process, so task verification is not required. Therefore, the embodiment of the present application also needs to determine whether task verification is required according to the process dimension in the task interceptor, that is, in the task interceptor, a process verification switch is added to the process containing high-risk tasks, while the process that does not contain high-risk tasks does not need to add a process verification switch. Among them, the "adding a process verification switch" here can be expressed as adding a process interception identifier associated with the task interceptor to the process auxiliary parameters corresponding to the process containing high-risk tasks, so that task verification can be triggered for high-risk tasks in the process.
[0148] Based on this, for the aforementioned task i, in the first identification search result (such as the aforementioned Figure 2 The identification search result 21i shown in FIG. 21 indicates that the task auxiliary parameters of task i (such as the aforementioned Figure 2 The task interception identifier (such as the aforementioned Figure 2 When the identifier 21h is shown, the process engine component (such as the aforementioned Figure 2 The process engine component 21d shown in the figure calls the task interceptor (such as the aforementioned Figure 2 The task interceptor 21j shown in the figure) is used to add auxiliary parameters of the business process (such as the aforementioned Figure 2 The parameter 21k shown in FIG. 21a) searches for the process interception identifier associated with the task interceptor (such as the aforementioned Figure 2 The identification 21m shown in the figure) is used to obtain the second identification search result (such as the aforementioned Figure 2 The identification search result 21n shown, the second identification search result can be used to determine whether to perform task verification on task i.
[0149] Among them, the process engine component can call the task interceptor through the specified communication protocol to achieve safe and reliable data transmission and improve data transmission efficiency. The embodiment of the present application does not limit the communication protocol used between the process engine component and the task interceptor. For example, HTTP protocol, SMTP protocol, FTP protocol, etc. can be used. Based on the specified communication protocol, the process engine component can send a call request to the task interceptor according to the first identifier search result. The call request can be used to instruct the task interceptor to search for the process interception identifier associated with the task interceptor in the process auxiliary parameters corresponding to the business process.
[0150] In an embodiment of the present application, multiple different forms of process auxiliary parameters and process interception identifiers can be supported. The process auxiliary parameters here refer to the general term for parameters associated with a specific process, which can be used to assist in determining whether a task in the process needs to be verified, including but not limited to process function headers, process interception lists, process switch lists, etc.; the process interception identifier here refers to an identifier in the process auxiliary parameters used to indicate that there are high-risk tasks in the process, which must be intercepted and verified, and may include but not limited to process interception annotation information, process identifiers, process interception status, etc. The embodiment of the present application will not list the forms of expression of process auxiliary parameters and process interception identifiers one by one.
[0151] For example, optionally, when the first identification search result indicates that the task interception identification is found in the task auxiliary parameters of task i, the task interceptor can be called through the process engine component to obtain the process function header of the business process, and the process function header of the business process can be used as the process auxiliary parameters corresponding to the business process; the process interception annotation information associated with the task interceptor is searched in the process auxiliary parameters, and when the process interception annotation information is found, it can be determined that the process interception identification associated with the task interceptor is found in the process auxiliary parameters; and then the result when the process interception identification is found in the process auxiliary parameters can be used as the second identification search result. The subsequent process can be further transferred to the processing process of step S104.
[0152] It can be understood that when executing task i in a business process, the task function of task i can be specifically called by executing the process function of the business process. The process function header is the header of the process function. Therefore, if it is detected that there is process interception annotation information associated with the task interceptor in the process function header of the business process, the process interception annotation information can be used as a process interception identifier, indicating that task i needs to be verified. Among them, the process interception annotation information refers to the mark / annotation information in the process function header that is used to indicate that task i is a high-risk task and needs to be verified. Specifically, it can be a comment, mark, field, keyword or key-value pair added to the process function header. The specific form of the process interception annotation information is not limited here. Among them, for different processes, the content of the process interception annotation information can be the same or different, which is not limited here.
[0153] For easier understanding, please also refer to Figure 7 , Figure 7 Schematic diagram of a process function header provided by an embodiment of the present application. Figure 7 The task 70 shown (such as the restart task) is reused by process 701a (such as the reinstallation process) and process 702a (such as the deployment process). Assuming that task 70 is a high-risk task in process 701a, the specified process interception annotation information (such as the process verification switch represented by comment 701b) can be added to the process function header of process 701a; and assuming that task 70 is not a high-risk task in process 702a, there is no need to add the specified process interception annotation information in the process function header of process 702a.
[0154] It can be understood that, optionally, if the process interception annotation information is not found in the process auxiliary parameters corresponding to the business process, it can be determined that the process interception identifier associated with the task interceptor is not found in the process auxiliary parameters, and then the result when the process interception identifier is not found in the process auxiliary parameters can be used as the second identifier search result. At this time, there is no need to perform task verification on task i, and the task interceptor can be directly skipped to execute task i.
[0155] For another example, optionally, when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, the task interceptor can be called through the process engine component to obtain the process interception list configured by the task interceptor, and the process interception list can be used as the process auxiliary parameters corresponding to the business process; wherein the process interception list contains a process identifier for instructing the task interceptor to perform task interception; the process identifier corresponding to the business process is searched in the process auxiliary parameters, and when the process identifier corresponding to the business process is found, it can be determined that the process interception identifier associated with the task interceptor is found in the process auxiliary parameters; and then the result of finding the process interception identifier in the process auxiliary parameters can be used as the second identifier search result. The subsequent process can be further transferred to the processing of step S104.
[0156] It can be understood that the process interception list can be understood as a process interception whitelist for the process maintained in the task interceptor, which can be used to record the process identifier corresponding to the process of the high-risk task that needs to be intercepted by the task interceptor. In other words, if it is detected that the process identifier corresponding to the business process is included in the process interception list, the process identifier corresponding to the business process can be used as the process interception identifier, indicating that task verification is required for task i.
[0157] For easier understanding, please also refer to Figure 8 , Figure 8 Schematic diagram of a process interception list provided in an embodiment of the present application. Figure 8 The shown list 80 is an exemplary process interception list. Assuming that there are high-risk tasks in process 801a (such as the reinstallation process) and process 802a (such as the deployment process), the process identifier 801b corresponding to process 801a (such as "ServerReinstallProcess") and the process identifier 802b corresponding to process 802a (such as "ServerDeployProcess") can be added to list 80.
[0158] It can be understood that, optionally, if the process identifier corresponding to the business process is not found in the process auxiliary parameters corresponding to the business process, it can be determined that the process interception identifier associated with the task interceptor is not found in the process auxiliary parameters, and then the result when the process interception identifier is not found in the process auxiliary parameters can be used as the second identifier search result. At this time, there is no need to perform task verification on task i, and the task interceptor can be directly skipped to execute task i.
[0159] For another example, optionally, when the first identification search result indicates that the task interception identification is found in the task auxiliary parameters of task i, the task interceptor can be called through the process engine component to obtain the process switch list configured by the task interceptor, and the process switch list can be used as the process auxiliary parameters corresponding to the business process; the process switch state of the business process is searched in the process auxiliary parameters, and when the found process switch state is the process interception state, it can be determined that the process interception identification associated with the task interceptor is found in the process auxiliary parameters; and then the result of finding the process interception identification in the process auxiliary parameters can be used as the second identification search result. The subsequent process can be further transferred to the processing process of step S104.
[0160] It can be understood that the process switch list can be used to record the process switch status of all processes. The process switch status here refers to the state of the task interceptor for a certain process, which may include the process interception state and the process release state, wherein the process interception state can be used to indicate that the task interceptor is in an enabled state for a certain process, that is, the task interceptor needs to intercept high-risk tasks in the process; the process release state can be used to indicate that the task interceptor is in an inactive state for a certain process, that is, the task interceptor does not need to intercept tasks in the process (all non-high-risk tasks). Among them, the process switch state can be represented in the form of fields, keywords or key-value pairs, which are not limited here. Based on this, if it is detected that the process switch state of the business process in the process switch list is a process interception state, the process interception state can be used as a process interception identifier, indicating that task verification is required for task i.
[0161] For easier understanding, please also refer to Fig. 9 , Fig. 9 is a schematic diagram of a process switch list provided in an embodiment of the present application. Fig. 9 The shown list 90 is an exemplary process switch list. Assuming that there are high-risk tasks in process 901a (such as the reinstallation process), the process switch state 901b of process 901a can be configured in list 90 as a process interception state (such as represented by "1"); assuming that there are no high-risk tasks in process 902a (such as the deployment process), the process switch state 902b of process 902a can be configured in list 90 as a process release state (such as represented by "0").
[0162] It can be understood that, optionally, if the process switch state of the business process found in the process auxiliary parameters corresponding to the business process is the process release state, it can be determined that the process interception identifier associated with the task interceptor is not found in the process auxiliary parameters, and then the result when the process interception identifier is not found in the process auxiliary parameters can be used as the second identifier search result. At this time, there is no need to perform task verification on task i, and the task interceptor can be directly skipped to execute task i.
[0163] For easier understanding, please also refer to Fig.10 , Fig.10 Schematic diagram of a task interception scenario provided by an embodiment of the present application. Fig.10 As shown in the figure, a task can belong to multiple processes at the same time, so the task interceptor needs to perform interception verification according to the process dimension. Fig.10 Take task 10a in as an example, task 10a is reused by K processes (K is a positive integer greater than 1), and the K processes are specifically process 1, process 2, ..., process K. Assume that process 1 can be specifically process 10b (such as a restart process), and process 10b can be composed of multiple tasks, such as server initialization-task, server shutdown-task, ..., server startup-task, process 2 can be specifically process 10c (such as a deployment process), and process 10c can be composed of multiple tasks, such as server startup-task, server hard disk formatting-task, server operating system installation-task, ..., server restart-task, then task 10a can be any task belonging to process 10b and process 10c (such as server startup-task). Assuming that there is a risk in task 10a, a corresponding task verification switch can be set for it. When task 10a in process 1 is a high-risk task, a corresponding process verification switch can be set for process 1 inside the task interceptor so that interception and verification of task 10a can be implemented through the task interceptor; when task 10a in process 2 is not a high-risk task, the corresponding process verification switch for process 2 can be omitted in the task interceptor, and the task interceptor does not need to intercept and verify task 10a.
[0164] It can be understood that the embodiments of the present application can enrich the methods of triggering the task interceptor to intercept tasks by providing various forms of process auxiliary parameters and process interception identifiers, thereby improving the flexibility of the process verification switch configuration.
[0165] It can be seen that the embodiment of the present application intercepts the configured interception according to the process dimension. While implementing the process verification switch in the task interceptor, it is also necessary to add a task verification switch to the specific task. Therefore, when a task is configured with a task verification switch, the task interceptor will be triggered, and then it can be determined according to the process dimension whether an interception verification is needed, that is, a two-dimensional switch is implemented. Therefore, accurate interception can be achieved on demand from the two dimensions of task + process, thereby improving the accuracy of task interception.
[0166] Step S104, when the second identifier search result indicates that the process interception identifier is found in the process auxiliary parameters, task verification is performed on task i in the business process. When the task verification is successful, the business server associated with the process engine component is notified to execute task i for the business operation device.
[0167] It is understandable that when the aforementioned second identification search result indicates that the process interception identification is found in the process auxiliary parameters, it means that the process processing device needs to perform task verification on task i in the business process, and when the task verification is successful, the business server associated with the process engine component can be notified to execute task i for the business operation device. In other words, before automatically executing the task, the business background (the process processing device in) performs a multi-dimensional security verification on the operation object specified by the task (i.e., the business operation device, such as a server), without the need for a UI (User Interface). IT personnel are unaware of the work done by the business background (such as creating tasks, calling task interceptors, task verification, etc.), and no manual intervention is required, thereby ensuring the high degree of automation and security of the entire processing flow, achieving efficient and safe automatic task operations, and improving user experience.
[0168] Specifically, in the second identification search result (such as the aforementioned Figure 2 The identification search result 21n shown in the figure indicates that in the process auxiliary parameters (such as the aforementioned Figure 2 The process interception identifier (such as the aforementioned Figure 2 When the mark 21m shown in the figure is displayed, the task interceptor (such as the aforementioned Figure 2 The task interceptor 21j shown in the figure calls the process processing device (such as the aforementioned Figure 2 The verification service component (such as the aforementioned Figure 2 The verification service component 21o shown in the figure is used to check the task i in the business process (such as the aforementioned Figure 2 The task i) in the process 21f shown in the figure performs task verification and obtains the task verification result (such as the aforementioned Figure 2 When the task verification result indicates that the task verification is successful, the task can be verified based on task i and the process engine component (such as the aforementioned Figure 2The process engine component 21d shown in the figure) is associated with a business server (such as the aforementioned Figure 2 The server 20C shown in the figure sends a task execution request to enable the business server to execute the task execution request for the business operation device (such as the aforementioned Figure 2 Task i of the device 20D) shown.
[0169] Among them, the verification service component can provide the task interceptor with a verification service interface for calling, which can also be called a security API (Application Programming Interface), which can be used for data interaction between the task interceptor and the verification service component. In order to provide multi-dimensional security verification services, the verification service component can pre-configure one or more verification rules, so that when a task needs to be verified, it can obtain matching verification rules from one or more configured verification rules to perform task verification. Verification rules refer to rules used to determine whether the environment and status of the object of the task operation (i.e., the business operation equipment) are safe. When the verification rules are met, it means that the environment and status of the business operation equipment are safe, that is, the task verification is successful, and only then can the automated task be executed. In actual applications, verification rules can be defined according to specific business conditions. The specific content and quantity of the verification rules are not limited in the embodiments of the present application. In one embodiment, the above-mentioned one or more verification rules can be stored in a database (which can be called a rule database) associated with the verification service component in the form of a verification rule table.
[0170] Among them, the task interceptor can call the verification service component through the specified communication protocol to achieve safe and reliable data transmission and improve data transmission efficiency. The communication protocol used between the task interceptor and the verification service component is not limited in the embodiment of the present application. For example, HTTP protocol, SMTP protocol, FTP protocol, etc. can be used. In order to obtain the corresponding verification rules to perform task verification on task i, the task interceptor can send the process identifier corresponding to the business process and the device identifier of the business operation device to the verification service interface of the verification service component based on the specified communication protocol in a request reorganization manner or a direct sending manner. For example, the task interceptor can reorganize the process identifier corresponding to the business process and the device identifier of the business operation device into a task verification request, and then send the reorganized task verification request to the verification service interface; or, optionally, the task interceptor can also directly send the process identifier corresponding to the business process and the device identifier of the business operation device to the verification service interface. The embodiment of the present application does not limit the specific method of transmitting the process identifier and the device identifier. Among them, the process identifier corresponding to the business process can be used to pull the verification rule associated with task i from one or more verification rules configured by the verification service component (for the convenience of distinction, it can be called a task verification rule). The device identification of the business operation device can also be called the fixed asset or device ID of the business operation device, which refers to the identification that uniquely identifies the business operation device, that is, a device identification uniquely identifies a business operation device, for example, it can be the network address of the business operation device (that is, IP address, IP is the abbreviation of Internet Protocol), the device name (for example, it can be an English name, Chinese name or a name expressed in other languages), a unique device identification number, etc., and the embodiments of the present application do not limit this. The device identification of the business operation device can be used to obtain the device configuration information of the business operation device, to compare with the aforementioned task verification rules, to obtain the task verification result, and thus to determine whether the environment and status of the business operation device are safe.
[0171] Among them, the device identification of the business operation device can be obtained from the device indication information of the business operation device. The device indication information can be used to jointly indicate a machine for a task operation, and can specifically include one or more of the network address, device name, device identification number, and device location information of the business operation device (such as the name of the computer room where the business operation device is located, the name of the rack in the computer room). The specific content of the device indication information is not limited here. In an embodiment of the present application, the device indication information of the business operation device can be obtained from the process variables associated with task i. The process variables here refer to the data stored in the process engine component, which is used when executing tasks in the corresponding process. When the business client initiates a process instance, the relevant process variables can be transmitted to the process engine component, and different process instances can use different process variables. For ease of understanding, please refer to Fig.11 , Fig.11 Schematic diagram of a process variable provided in an embodiment of the present application. Fig.11 As shown, task 11a is a task in a certain process (such as restart-task), which can be used as the aforementioned task i. The process variable 11b associated with task 11a contains a series of data required to execute task 11a. Assuming that the operation object of task 11a is server 11c, server 11c can be used as the aforementioned business operation device. The process variable 11b may include relevant server information of server 11c (i.e., device indication information), such as the IP address of server 11c (i.e., network address, such as 127.0.0.01), the unique identification number serverId of server 11c (i.e., device identification number, such as 111), the name idcName of the computer room where server 11c is located (such as aaa), and the name rackName of the specific rack in the computer room where server 11c is located (such as bbb). Therefore, the IP address or unique identification number of server 11c stored in the process variable 11b can be used as the device identification of server 11c. Through the server information in process variable 11b, we can know the IP address and specific location of the operation object of task 11a (that is, which rack in which computer room), and also know which machine we need to log in to when executing task 11a, ensuring the smooth execution of task 11a.
[0172] It is understandable that in the specific implementation of the present application, it is necessary to obtain the device indication information of the business operation device (such as the network address, device name, device identification number, and device location information of the business operation device). When the embodiments in the present application are applied to specific products or technologies, it is necessary to obtain the permission or consent of third-party business personnel, and the collection, use, and processing of relevant data must comply with the relevant laws and standards of relevant countries and regions. For example, a prompt interface or pop-up window can be displayed, which is used to prompt the third-party business personnel that the device indication information of the business operation device is currently being collected. Only after the third-party business personnel issues a confirmation operation on the prompt interface or pop-up window, the relevant steps of data acquisition are started, otherwise it ends.
[0173] For ease of understanding, taking the transmission task verification request as an example, the process processing device can generate a task verification request for task i in the business process through a task interceptor, and send the task verification request to the verification service interface of the verification service component; wherein the task verification request carries the process identifier corresponding to the business process and the device identifier of the business operation device; further, based on the task verification request, the verification service interface can be called to search the verification rule table configured by the verification service component for a verification rule that matches the process identifier corresponding to the business process, and when a verification rule that matches the process identifier corresponding to the business process is found in the verification rule table, the found verification rule can be used as the task verification rule associated with task i; based on the task verification rule, the first device configuration information associated with the device identifier of the business operation device can be obtained from the device configuration system associated with the business operation device, and the first device configuration information can be compared with the task verification rule through the verification service component to obtain the task verification result.
[0174] For easier understanding, please also refer to Fig.12 , Fig.12 Schematic diagram of a verification rule table provided in an embodiment of the present application. Fig.12 As shown, the rule table 120 exemplarily shows a verification rule table, which may include one or more verification rules, and the number of verification rules is not limited here. For easy search, the process identifier and the verification rule can be associated and stored in the rule table 120, that is, one process identifier can correspond to one verification rule, which is equivalent to using the process identifier as an index of the verification rule table, so the corresponding verification rule can be found through the process identifier. For example, as shown in rule table 120, assume that verification rule 121a and verification rule 122a are configured in the table, wherein the process identifier corresponding to verification rule 121a includes identifier 121b (for example, the English name of the process is "ServerReinstallProcess") and identifier 121c (for example, the Chinese name of the process is "reinstall process"), and the process identifier corresponding to verification rule 122a includes identifier 122b (for example, the English name of the process is "ServerDeployProcess") and identifier 122c (for example, the Chinese name of the process is "deployment process"). In this way, when the business process is a reinstallation process, through identifier 121b or identifier 121c, the verification service component can find verification rule 121a in rule table 120 as the task verification rule associated with task i; similarly, when the business process is a deployment process, through identifier 122b or identifier 122c, the verification service component can find verification rule 122a in rule table 120 as the task verification rule associated with task i. It can be understood that in some embodiments, the verification rule table may store only one process identifier, such as storing either the English name of the process or the Chinese name of the process.
[0175] Optionally, each verification rule in the verification rule table can be valid by default, that is, each verification rule can be used normally for task verification. Alternatively, optionally, the usage status of each verification rule can also be set in the verification rule table to indicate whether each verification rule is valid. For example, when the usage status of a verification rule is set to the rule enabled state, the verification rule is determined to be valid, and the verification rule can be used normally for task verification; and when the usage status of the verification rule is set to the rule deprecated state, the verification rule is determined to be invalid, and the verification rule cannot be used for task verification. In this case, even if the verification rule is still retained in the verification rule table, it can be set to be invisible to the verification service component, and the verification service component cannot find the verification rule through its corresponding process identifier; or, although the verification service component can find the verification rule through its corresponding process identifier, because it detects that the usage status of the verification rule is the rule deprecated state, it abandons the use of the verification rule for task verification. Among them, the usage status of the verification rule can be set in the form of fields, keywords, or key-value pairs, and there is no restriction here. For example, continue to refer to the above Fig.12 , assuming that the verification rule 121a is expected to be used normally, the usage status 121d of the verification rule 121a can be set in the rule table 120 as the rule enabled status (for example, represented by "enabled"); assuming that the verification rule 122a is expected to be suspended, the usage status 122d of the verification rule 122a can be set in the rule table 120 as the rule abandoned status (for example, represented by "abandoned"); the usage status of the verification rule 121a and the verification rule 122a can be switched later as needed. The embodiment of the present application supports setting the usage status of the verification rules, improves the flexibility and convenience of configuring and using the verification rules, reduces the frequent deletion and modification of the verification rule table, and improves the user experience.
[0176] Optionally, if no verification rule matching the process identifier corresponding to the business process is found in the verification rule table, it is equivalent to not configuring rules for the business process, and task verification for task i in the business process is skipped, and task i can be directly executed.
[0177] It can be understood that the verification rules specify the environment and state in which the object of the task operation is safe. Taking the aforementioned task verification rules as an example (other verification rules are similar), the task verification rules can be used to specify the target device department to which the business operation device belongs, the target device state of the business operation device, and the target network state. Among them, the target device department refers to any department of a third party that is allowed to operate the business operation device (such as a business department, an operation department, etc.). Only when the business operation device belongs to the specified target device department can the environment (or department) in which the business operation device is located be considered safe; the target device state refers to the internal state that the business operation device is allowed to have, including but not limited to one or more of the states of reinstalling, allocating, restarting, starting up, shutting down, operating, failing, and formatting. There is no limitation here. Only when the business operation device is in the target device state can the device state of the business operation device be considered safe. The target network state refers to the network state that the business operation device is allowed to be in, such as specifically referring to detecting / verifying whether the network card of the business operation device has network traffic. Only when the business operation device is in the target network state can the network state of the business operation device be considered safe. Among them, when the specified department or status is a null value, it means that there is no need to check the department or status, that is, any department or status can be considered safe. In addition, task verification rules can also be used to specify other states or environments, and the specific content of task verification rules is not limited here. It can be seen that the purpose of task verification is to perform multi-dimensional environment and status checks on business operation equipment, and execute tasks for the business operation equipment after checking safety, which can ensure the safety and reliability of task operations.
[0178] For example, see again the above Fig.12 ,like Fig.12As shown, assuming that a server X1 (which can be used as a business operation device) needs to be security checked in the reinstallation process (which can be used as a business process) (that is, there are high-risk tasks for server X1 in the reinstallation process), in the rule table 120, it can be found that the verification rule 121a specifies that the department allowed to operate on the server X1 is a null value, that is, any department (which can be used as a target device department) is allowed to operate on the server X1, and the verification rule 121a specifies that the internal state that the server X1 is allowed to have is the reinstallation state (which can be used as the target device state), and specifies the network state that the server X1 is allowed to be in (which can be used as the target network state), that is, it is necessary to detect whether the network card of the server X1 has network traffic. If it is detected that its network card has network traffic, then the network state of the server X1 can be considered to be safe; conversely, if it is detected that its network card has no network traffic, then the network state of the server X1 can be considered to be unsafe. Similarly, assuming that a server X2 (which can be used as a business operation device) needs to be security checked in the deployment process (which can be used as a business process) (that is, there are high-risk tasks for server X2 in the deployment process), in the rule table 120, it can be found that the verification rule 122a specifies that the departments allowed to operate server X2 are business department 1 and business department 2 (which can be used as target device departments), and the verification rule 122a specifies that the internal state allowed for server X2 is the reinstalling state or the allocating state (which can be used as the target device state), and specifies the network state allowed for server X2 (which can be used as the target network state), that is, there is no need to detect whether the network card of server X2 has network traffic, and the network state of server X2 can be considered safe with or without network traffic.
[0179] Based on this, when the task verification rule associated with task i is found in the verification rule table, the verification service component can obtain the current real environment and status configuration of the business operation device through the device identification of the business operation device, and compare it with the environment and status that need to be verified defined by the task verification rule (i.e., the aforementioned target device department, target device status, and target network status), so as to determine whether the current environment and status of the business operation device are safe. Optionally, the verification service component can obtain the device configuration information of the business operation device from the device configuration system through the device identification of the business operation device. The device configuration system here can also be called a device global configuration system, which can be understood as an external system (i.e., a third-party system) associated with the business operation device and independent of the process processing device. The device configuration system is used to store the latest device configuration information of the business operation device (for example, it can be requested from the business operation device at regular intervals). The device configuration information may include the latest environment and status configuration of the business operation device. Therefore, when it is necessary to perform a multi-dimensional environment and status check on the business operation device, the latest device configuration information queried in the device configuration system can be used as the basis. That is to say, after finding the task verification rule that matches the business process from the verification rule table through the process identifier corresponding to the business process, the corresponding device configuration information can be obtained from the device configuration system through the device identifier of the business operation device based on the content defined by the task verification rule. For the convenience of distinction and explanation, the device configuration information obtained when performing task verification on task i can be referred to as the first device configuration information. Combined with the content of the aforementioned task verification rule, the first device configuration information here can specifically include one or more information in the first device configuration department to which the business operation device belongs, the first device configuration state of the business operation device, and the first network configuration state. Among them, the first device configuration department refers to the department that currently operates the business operation device. The first device configuration state refers to the internal state of the current business operation device, including but not limited to one or more of the states of reinstalling, allocating, restarting, starting up, shutting down, operating, failing, formatting, etc., which are not limited here. The first network configuration state refers to the network state of the current business operation device, such as whether the network card has network traffic or no network traffic, which can be obtained by checking the network link of the business operation device. Optionally, when the department or status specified by the task verification rule is a null value, it is not necessary to obtain the corresponding configuration information from the device configuration system for inspection, thereby reducing the amount of data transmission and improving the efficiency of task verification. For example, if the aforementioned verification rule 121a specifies that the department allowed to operate server X1 is a null value, there is no need to check the department that is currently actually operating server X1.
[0180] Among them, the verification service component and the device configuration system can exchange data through a specified communication protocol to achieve safe and reliable data transmission and improve data transmission efficiency. The embodiment of the present application does not limit the communication protocol used between the verification service component and the device configuration system. For example, HTTP protocol, SMTP protocol, FTP protocol, etc. can be used. Based on the specified communication protocol, the verification service component can send a first configuration information acquisition request to the device configuration system according to the device identification of the business operation device. The first configuration information acquisition request can be used to instruct the device configuration system to return the first device configuration information associated with the device identification to the verification service component.
[0181] Among them, the device configuration system can be deployed together with the business module on the business server, or it can also be deployed independently on other servers. The embodiment of the present application does not limit the deployment method of the device configuration system.
[0182] Optionally, the verification service component may also directly obtain the first device configuration information from the business operation device. The verification service component and the business operation device may exchange data through a specified communication protocol to achieve secure and reliable data transmission and improve data transmission efficiency. The embodiment of the present application does not limit the communication protocol used between the verification service component and the business operation device. For example, HTTP protocol, SMTP protocol, FTP protocol, etc. may be used. Based on the specified communication protocol, the verification service component may send a second configuration information acquisition request to the business operation device indicated by the device identifier of the business operation device according to the device identifier of the business operation device. The second configuration information acquisition request may be used to instruct the business operation device to return the current latest device configuration information to the verification service component as the first device configuration information.
[0183] Among them, after obtaining the first device configuration information, the first device configuration information can be compared with the task verification rules through the verification service component. If the first device configuration information is consistent with the task verification rules, it can be determined that the task verification is successful, that is, it is safe to execute task i for the business operation device at this time; conversely, if the first device configuration information is inconsistent with the task verification rules, it can be determined that the task verification has failed, that is, it is unsafe to execute task i for the business operation device at this time; and then the result of the successful task verification or the result of the failed task verification can be used as the task verification result.
[0184] For example, taking the aforementioned server X2 as an example, based on the verification rule 122a, it is possible to check in the device configuration system associated with server X2 whether the department currently operating server X2 is business department 1 or business department 2, and whether the current internal state of server X2 is in the reinstalling state or the allocating state, and it is not necessary to check whether the current network card of server X2 has network traffic. If the department and state found match the verification rule 122a, it means that the environment and state of server X2 are safe; on the contrary, if the department and state found do not match the verification rule 122a (for example, server X2 is currently operated by business department 3), it means that the environment and state of server X2 are unsafe.
[0185] Among them, the verification service component can return the task verification result to the task interceptor through its verification service interface, and the task interceptor determines whether it is necessary to continue to execute task i through the received task verification result. The embodiment of the present application can support the representation of task verification results in a variety of ways, including but not limited to tags, fields, keywords or key-value pairs, so as to enrich the flexibility of the representation form of task verification results. For example, optionally, when the task verification result indicates that the task verification is successful, the verification service component can return a security mark (for example, represented by a mark "1") to the task interceptor through the verification service interface, which is used to instruct the process engine component to notify the business server to execute task i for the business operation device; optionally, when the task verification result indicates that the task verification fails, the verification service component can return an unsafe mark (for example, represented by a mark "-1") to the task interceptor through the verification service interface, which is used to instruct the process engine component to start from task i and interrupt the execution of tasks in the business process, that is, task i and the (Mi) tasks after task i are not executed.
[0186] Among them, when the task verification is successful, in order to be able to notify the business server associated with the process engine component to execute task i for the business operation device, the process engine component and the business server can exchange data through a specified communication protocol to achieve safe and reliable data transmission and improve data transmission efficiency. The embodiment of the present application does not limit the communication protocol used between the process engine component and the business server, such as HTTP protocol, SMTP protocol, FTP protocol, etc. Based on the specified communication protocol, the process engine component can send the task identifier of task i and the process variables associated with task i to the business server by requesting reorganization or directly sending. For example, the process engine component can reorganize the task identifier of task i and the process variables associated with task i into a task execution request, and then send the reorganized task execution request to the business server; or, optionally, the process engine component can also directly send the task identifier of task i and the process variables associated with task i to the business server; the embodiment of the present application does not limit this. Among them, the business server can deploy the business logic (i.e., executable code) corresponding to the aforementioned M tasks in its business module in advance, so that there is no need to repeatedly transmit the business logic to the business module for execution, which can reduce the amount of data transmission between the process engine component and the business server and save transmission bandwidth. Therefore, through the task identifier of task i (such as the task name of task i), the business server can obtain the specific business logic corresponding to task i deployed in its business module. Among them, through the process variables associated with task i, the business server can obtain the data required to execute the business logic corresponding to task i, such as the device indication information of the business operation device, so that the business server can accurately log in to the business operation device based on the device indication information to execute the corresponding command.
[0187] For ease of understanding, taking a task execution request as an example, the specific process of sending a task execution request to a business server can be: obtaining the task identifier of task i and the process variables associated with task i through the process engine component, generating a task execution request based on the task identifier and process variables of task i, and sending the task execution request to the business server associated with the process engine component, so that the business server obtains the business logic corresponding to task i for the business operation device based on the task identifier of task i, and executes the business logic corresponding to task i when logging in to the business operation device through the aforementioned process variables. Fig.11Taking the task 11a shown as an example, the process engine component can send a task execution request to the business module deployed on the business server based on the task identifier of task 11a (for example, the task name is "restart-task") and process variable 11b. When the business module receives the task execution request, it can know which specific task to execute through the task identifier of task 11a. For example, when the restart-task needs to be executed, the business module can execute the business logic corresponding to the restart-task (that is, the code of the restart-task), so that it can remotely log in to server 11c to execute the restart command through the server information of server 11c carried in the process variable 11b (for example, the IP address of server 11c, the unique identification number serverId, the name of the computer room where it is located idcName, the name of the specific rack in the computer room rackName, etc.).
[0188] Among them, the business server can establish a secure and reliable communication connection with the business operation device through a specified communication protocol (also known as a remote login protocol), so that the specified command or operation can be executed on the business operation device. The embodiment of the present application does not limit the communication protocol used between the business server and the business operation device. For example, the SSH protocol (Secure Shell, i.e., the secure shell protocol, is an encrypted network transmission protocol that provides a secure way to access a remote computer), Telnet protocol, RDP protocol (Remote Desktop Protocol, i.e., remote desktop protocol), etc. can be used. Based on the specified communication protocol, the business server can remotely log in to the business operation device. For example, the business server can log in to the business operation device through the SSH protocol by executing the corresponding remote login script, which is equivalent to establishing a communication connection based on the SSH protocol with the remote business operation device. The two parties can exchange data. For example, after the business server enters the specified command (such as a restart command) locally, these commands will be run on the business operation device. In this way, the business server can control the business operation device locally.
[0189] It is understood that the business operation device can be a server or a terminal device, and the specific form of the business operation device is not limited in the embodiments of the present application. Although the login method or script executed by different forms of business operation devices may be different, the logic of security detection is the same, and different forms of business operation devices will not be described separately here.
[0190] Optionally, when the task verification fails, the process processing device does not execute task i and the (Mi) tasks after task i in the business process, that is, the processing of the business process will be interrupted at the task node corresponding to task i, and a first verification failure prompt message can be sent to the business client associated with the process engine component. The first verification failure prompt message here can be used to prompt the task verification failure, and can be displayed in the form of email, conversation message, pop-up window, text message, etc. The embodiment of the present application does not limit the specific content and display form of the first verification failure prompt message.
[0191] It can be understood that adding a task interceptor before the process engine component drives the scheduling task is equivalent to adding a virtual task, that is, before executing the actual task, you need to stop and verify whether the object of the task operation is safe. If the verification is safe, you can execute the task, thereby ensuring the safety and reliability of task execution; if the verification is unsafe, then the task will be intercepted, and the process processing will be interrupted here without executing the task, thereby preventing high-risk tasks from being automatically executed.
[0192] It can be seen from this that the embodiment of the present application provides a solution based on the safety detection of task operations of the process engine. In the field of IT workflow, the process engine is used as the scheduling core, and task interception is realized by the task pre-interceptor inside the process engine. Before the atomic task in the process engine driving scheduling business process, it is necessary to find out whether there is an interception mark associated with the task interceptor, so as to realize accurate interception on demand from the two dimensions of task + process, and then trigger the intercepted atomic task to perform task verification, and execute the atomic task after the successful inspection, that is, the task operation can be performed under the premise of ensuring safety, so as to improve the safety and reliability of task execution. Safety is no small matter, and the method provided by the embodiment of the present application can be used to avoid operational accidents. The embodiment of the present application is aimed at the atomic tasks in the workflow, the operation field of business operation equipment (such as server), realizes task safety verification and interception, and is decoupled from the business in design to achieve the purpose of task operation safety.
[0193] For further information, see Fig.13 , Fig.13 This is a flowchart of a task data processing provided by an embodiment of the present application. Figure 2 .like Fig.13 As shown, the method can be executed by a process processing device, and a task interceptor is deployed on the process engine component in the process processing device. The method can specifically include the following steps:
[0194] Step S201, obtaining, through the process engine component, a process start request sent by a business client associated with the process engine component;
[0195] It can be understood that the process processing device can obtain the process start request sent by the business client associated with the process engine component through the process engine component. The specific implementation process of this step can be referred to above Figure 3 The relevant description in step S101 of the corresponding embodiment will not be repeated here.
[0196] For easier understanding, please also refer to Fig.14 , Fig.14 Schematic diagram of the architecture of a process engine-based automatic task operation safety detection system provided in an embodiment of the present application. Fig.14 As shown, the business front desk 14a can be used as the aforementioned business client, and the process engine 14b can be used as the aforementioned process engine component. There is an association relationship between the business front desk 14a and the process engine 14b. When a process instance needs to be initiated, the business front desk 14a can send a corresponding process start request to the process engine 14b.
[0197] Step S202, based on the process start request, obtaining process template data associated with the business process, and generating the business process through the process template data;
[0198] It can be understood that the process processing device can obtain the process template data associated with the business process based on the process start request, and can generate the corresponding business process through the process template data. The specific implementation process of this step can be referred to above Figure 3 The relevant description in step S101 of the corresponding embodiment will not be repeated here.
[0199] For example, Fig.14 As shown, when the process engine 14b receives the process start request, it can obtain the process matching the process identifier from the template database associated with the process engine 14b according to the process identifier carried in the process start request. Fig.14 d. The process Fig.14 d can be used as the aforementioned process template data. Fig.14 One or more operations can be defined in d. Fig.14 The operations defined by d are not limited, for example, the process Fig.14 d can define server restart operation, server disk array (i.e. server disk RAID) operation, server hard disk formatting operation, server operating system installation operation, and these 4 operations will be defined according to the process Fig.14 The operations defined in d are executed in sequence. The process engine 14b Fig.14 d After initialization and process instantiation, a specific process instance (such as process 1) can be obtained, which can be used as the aforementioned business process.
[0200] Step S203, creating a task i to be executed through M tasks associated with the business operation device in the business process;
[0201] It is understood that the embodiments of the present application can create tasks in the business process in a parallel or serial manner, and the task creation method is not limited here. The specific implementation process of this step can be referred to above Figure 3 The relevant description in step S101 of the corresponding embodiment will not be repeated here.
[0202] For example, Fig.14 As shown, taking the serial creation of tasks as an example, the process engine 14b instantiates the process Fig.14 d, you can target the process Fig.14 Each operation in d is processed in the process of "create task->execute task". For example, after creating server restart-task->execute server restart-task, the state machine is updated to create server disk array-task->execute server disk array-task, and so on, until the last task is executed or the process processing is interrupted, the whole process will end. In the internal execution link of the process engine 14b, a task interceptor 14c before task execution is added. After creating a task and before executing it, the task interceptor 14c can realize multi-dimensional inspection of the operation object of the task (the task operates the machine, such as server 14f).
[0203] Step S204, before executing task i, searching the task auxiliary parameters of task i for a task interception identifier associated with the task interceptor to obtain a first identifier search result;
[0204] It can be understood that before executing task i, the task interception identifier associated with the task interceptor can be searched in the task auxiliary parameters of task i to obtain the first identifier search result, and whether the task interceptor needs to be triggered can be determined based on the first identifier search result. The specific implementation process of this step can be referred to above Figure 3 The relevant description in step S102 of the corresponding embodiment will not be repeated here.
[0205] Step S205, when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, the task interceptor is called through the process engine component, and the process interception identifier associated with the task interceptor is searched in the process auxiliary parameters corresponding to the business process to obtain a second identifier search result;
[0206] It can be understood that when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, the task interceptor can be called through the process engine component, and the process interception identifier associated with the task interceptor can be found in the process auxiliary parameters corresponding to the business process to obtain the second identifier search result. According to the second identifier search result, it is determined whether task verification is required for task i in the business process. The specific implementation process of this step can be referred to above Figure 3 The relevant description in step S103 of the corresponding embodiment will not be repeated here.
[0207] Step S206, when the second identifier search result indicates that the process interception identifier is found in the process auxiliary parameters, the task interceptor calls the verification service component in the process processing device to perform task verification on task i in the business process to obtain a task verification result;
[0208] It can be understood that when the second identifier search result indicates that the process interception identifier is found in the process auxiliary parameters, the task interceptor can call the verification service component in the process processing device to perform task verification on task i in the business process to obtain the task verification result. The specific implementation process of this step can be referred to above Figure 3 The relevant description in step S104 of the corresponding embodiment will not be repeated here.
[0209] Step S207, when the task verification result indicates that the task verification is successful, based on task i, a task execution request is sent to a business server associated with the process engine component, so that the business server executes task i for the business operation device based on the task execution request;
[0210] It can be understood that, optionally, when the task verification result in step S206 indicates that the task verification is successful, a task execution request can be sent to the business server associated with the process engine component based on task i, and the task execution request is used to instruct the business server to execute task i for the business operation device. The specific implementation process of this step can be referred to above Figure 3 The relevant description in step S104 of the corresponding embodiment will not be repeated here.
[0211] Step S208, when the task verification result indicates that the task verification has failed, task i and (Mi) tasks after task i in the business process are not executed, and a first verification failure prompt message is sent to the business client;
[0212] It can be understood that, optionally, when the task verification result in step S206 indicates that the task verification has failed, task i and (Mi) tasks after task i in the business process will not be executed, and a first verification failure prompt message can be sent to the business client. The specific implementation process of this step can be referred to above Figure 3 The relevant description in step S104 of the corresponding embodiment will not be repeated here.
[0213] Among them, step S207 and step S208 are two parallel and unrelated steps, and there is no order of precedence.
[0214] For example, Fig.14 As shown, assuming that the process Fig.14d Generate a process 1 associated with server 14f, which can be used as the aforementioned business process. For task i created in process 1, when i=1, the server restart-task can be used as task 1. Optionally, assuming that it is determined that there is no need to perform task verification on the server restart-task (i.e., there is no risk in the server restart-task), the business module 14e (deployed on the aforementioned business server) can be directly driven to log in to server 14f and execute the business logic corresponding to the server restart-task to restart server 14f, and then continue to process the next task (i.e., server disk array-task) in a similar process. Optionally, if it is determined that there is a need to perform task verification on the server restart-task (i.e., there is a risk in the server restart-task), the server restart-task can be verified through the multi-dimensional security verification service 14g (which can be deployed on the aforementioned verification service component). Among them, the multi-dimensional security verification service 14g can provide a security interface 14h (which can be used as the aforementioned verification service interface), and the task interceptor 14c can transmit the fixed assets of the server 14f (that is, the aforementioned device identifier, such as the IP address of the server 14f) and the process id corresponding to process 1 (that is, the aforementioned process identifier, such as the process name) to the security interface 14h. After the security interface 14h receives the fixed assets and process id, it can use these two pieces of information to call the security verification logic in the multi-dimensional security verification service 14g to perform task verification on the server restart-task. Among them, it is possible to check whether there is a check rule matching the aforementioned process id in the check rule table 14i (which can be stored in the rule database). If so, the check rule matching the process id (such as check rule 14j) can be pulled from the check rule table 14i for caching. Based on the equipment department, equipment status, network status, etc. that need to be checked defined by the check rule 14j, the latest equipment department, equipment status, network status, etc. currently configured by the server 14f can be obtained from another third-party system (i.e., the aforementioned equipment configuration system) according to the previous fixed information, and compared with the equipment department, equipment status, network status, etc. defined in the check rule. If the comparison is consistent, it means that the environment and status of the server 14f are safe, that is, the server restart-task verification is successful, and the business module 14e can be driven to log in to the server 14f and execute the business logic corresponding to the server restart-task to realize the restart of the server 14f. Subsequently, the next task (i.e., the server disk array-task) can be processed in a similar manner, and this will not be repeated. On the contrary, if the comparison is inconsistent, it means that the environment and status of server 14f are unsafe, that is, the server restart-task verification fails, and the corresponding prompt information (that is, the first verification failure prompt information) can be sent to the business front desk 14a in the form of conversation messages, emails, text messages, etc., but the server restart-task and subsequent tasks will no longer be executed at this time.
[0215] Step S209, obtain the process status table configured by the process engine component, scan the process status table, and when it is detected in the process status table that the process status of the business process is the process running status, perform device verification on the business operation device through the verification service component. When the device verification fails, send a second verification failure prompt message to the business client.
[0216] It can be understood that the embodiments of the present application can also support multi-dimensional security inspections, and determine whether the environment and status of the operation object are safe by asynchronously polling the unfinished process. Because the environment and status of the operation object may change during the process processing, if it is found that the environment and status do not meet the definition of the verification rules, timely reminders can be given, thereby improving the safety of the operation object.
[0217] Specifically, the process state table configured by the process engine component can be obtained; the process state table can record the process states of N processes; wherein N is a positive integer; and the N processes include business processes associated with business operation devices. That is to say, the process engine component can store the process state table in a related database (such as a process database or a business database), and the process state table can also be called a process instance table, which can be used to record the process state of each process instance created by the process engine component, and the number of process instances (i.e., N) is not limited here. In order to facilitate the query of the process state of each process instance, the process identifier corresponding to each process instance and the device identifier of the relevant operation object can be used as the index of the process state table, and the process state of each process instance can be associated and recorded later. Among them, the process state can specifically include the process running state and the process end state, the process running state is used to indicate that the corresponding process instance has not ended, and the process end state is used to indicate that the corresponding process instance has ended. The embodiment of the present application can use fields, keywords, or key-value pairs to represent the process running state, which is not limited here.
[0218] To facilitate understanding, taking the aforementioned business process as an example, the process status table can be scanned. When it is detected in the process status table that the process status of the business process is the process running status, it means that the business process has not yet ended. The verification service component in the process processing device can be used to perform device verification on the business operation device. When the device verification fails, a second verification failure prompt message can be sent to the business client associated with the process engine component. The second verification failure prompt message can be used to prompt the device verification failure and can be displayed in the form of email, conversation message, pop-up window, text message, etc. The embodiment of the present application does not limit the specific content and display form of the second verification failure prompt message.
[0219] The process of performing equipment verification on the business operation device is similar to the process of performing task verification on task i, which can be specifically as follows: when the process state of the business process is detected as the process running state in the process state table, a device verification request can be sent to the verification service interface of the verification service component in the process processing device; the device verification request carries the process identifier corresponding to the business process and the device identifier of the business operation device; further, based on the device verification request, the verification service interface can be called to search for a verification rule matching the process identifier corresponding to the business process in the verification rule table configured by the verification service component, and when a verification rule matching the process identifier corresponding to the business process is found in the verification rule table, the verification rule found is used as the device verification rule associated with the business operation device; based on the device verification rule, the second device configuration information associated with the device identifier of the business operation device can be obtained from the device configuration system associated with the business operation device, and the second device configuration information is compared with the device verification rule by the verification service component to obtain the device verification result. The process of performing equipment verification on other operation objects is similar to the process of performing equipment verification on the business operation device, and will not be repeated here.
[0220] Among them, the equipment verification rule here is actually the same verification rule as the aforementioned task verification rule, that is, the verification rule that matches the process identifier corresponding to the business process. Here, different naming methods are used only for the convenience of explanation. Therefore, the equipment verification rule can also be used to specify the target equipment department to which the business operation equipment belongs, the target equipment status of the business operation equipment, and the target network status. Among them, the second equipment configuration information refers to the equipment configuration information obtained when the business operation equipment is verified, which may be the same as or different from the aforementioned first equipment configuration information, and is not limited here. Combined with the content of the aforementioned equipment verification rule, the second equipment configuration information here may specifically include one or more information of the second equipment configuration department to which the business operation equipment belongs, the second equipment configuration status of the business operation equipment, and the second network configuration status. Among them, the second equipment configuration department refers to the department that currently operates the business operation equipment. The second equipment configuration status refers to the internal status of the current business operation equipment, including but not limited to one or more of the states of reinstalling, distributing, restarting, starting up, shutting down, operating, failing, and formatting, and is not limited here. The second network configuration state refers to the network state of the current business operation device, for example, it can be that the network card has network traffic or no network traffic, which can be obtained by checking the network link of the business operation device. Optionally, when the department or state specified by the device verification rule is a null value, it is not necessary to obtain the corresponding configuration information from the device configuration system for inspection, thereby reducing the amount of data transmission and improving the efficiency of task verification.
[0221] Among them, after obtaining the second device configuration information, the second device configuration information can be compared with the device verification rules through the verification service component. If the second device configuration information is consistent with the device verification rules, it can be determined that the device verification is successful, that is, the environment and status of the business operation device are safe at this time; conversely, if the second device configuration information is inconsistent with the device verification rules, it can be determined that the device verification has failed, that is, the environment and status of the business operation device are unsafe at this time; and then the result of the successful device verification or the result of the failed device verification can be used as the device verification result.
[0222] Optionally, when the device verification result indicates that the device verification has failed, it means that the environment and state of the business operation device are unsafe, and a second verification failure prompt message can be sent to the business client associated with the process engine component. At the same time, the processing of the business process can be suspended until the environment and state of the business operation device are restored to safety before continuing the processing.
[0223] Optionally, when the device verification result indicates that the device verification is successful, it means that the environment and status of the business operation device are safe and the business process can be processed normally.
[0224] It can be understood that the aforementioned task verification is a real-time check, while the multi-dimensional safety inspection here is an asynchronous check and has nothing to do with the task. Fig.14 As shown, it is assumed that the process engine 14b processes N processes, including process 1, process 2, ..., process N, each process corresponds to a device (i.e., the object of the task operation in the process), for example, process 1 corresponds to server 14f, and the security inspection tool 14k (which can be deployed in the verification service component) associated with the multi-dimensional security verification service 14g can be used to scan the unfinished processes in process 1 to process N (i.e., scan the process status table that records the process status of these N processes). For example, assuming that the unfinished process scanned has process 1 associated with server 14f, the security inspection tool 14k can send the fixed assets of server 14f and the process id corresponding to process 1 to the security interface 14h. After the security interface 14h receives the fixed assets and the process id, it can use these two information to call the security verification logic in the multi-dimensional security verification service 14g to perform device verification on server 14f, thereby realizing bypass multi-dimensional security inspection.
[0225] In summary, in the embodiment of the present application, the main processing steps of the automatic task operation safety detection system based on the process engine are as follows:
[0226] (1) The task interceptor is implemented inside the process engine, and the task interceptor is switched according to the process dimension.
[0227] (2) Add comments to the header of the task function that needs to be intercepted and schedule the task interceptor.
[0228] Therefore, through steps (1) and (2), we can intercept as needed based on the two dimensions of process + task. That is, a task may belong to multiple processes and be released and checked according to the process.
[0229] (3) In the multi-dimensional security microservice, configure the verification rule table to implement the security verification logic.
[0230] It can be seen that in the field of IT workflow, the embodiment of the present application takes the process engine as the scheduling core, and implements task interception through the task pre-interceptor inside the process engine. Before the process engine drives the atomic task in the scheduling business process, it is necessary to find out whether there is an interception mark associated with the task interceptor, so as to achieve accurate interception on demand from the two dimensions of task + process, and then trigger the intercepted atomic task to perform task verification, and execute the atomic task after the successful inspection, that is, the task operation can be performed under the premise of ensuring safety, so as to improve the safety and reliability of task execution. Safety is no small matter, and the method provided by the embodiment of the present application can be used to avoid operational accidents. The embodiment of the present application is aimed at the atomic tasks in the workflow, the operation field of business operation equipment (such as server), realizes task safety verification and interception, and is decoupled from the business in design to achieve the purpose of task operation safety.
[0231] For further information, see Fig.15 , Fig.15 Schematic diagram of the structure of a task data processing device provided in an embodiment of the present application. Fig.15 As shown, the task data processing device 1 can be applied to a process processing device. For example, the process processing device can be the above-mentioned Figure 2 The device 20B in the corresponding embodiment. It should be understood that the task data processing device 1 can be a computer program (including program code) running on a computer device (for example, the aforementioned device 20B), for example, the task data processing device 1 can be an application software; it can be understood that the task data processing device 1 can be used to execute the corresponding steps of the method provided in the embodiment of the present application. Fig.15 As shown, the task data processing device 1 may include: a task creation module 11, a first search module 12, a second search module 13, a verification success module 14, a verification failure module 15, and a process inspection module 16;
[0232] The task creation module 11 is used to obtain a business process associated with the business operation device, and create a task i to be executed through M tasks associated with the business operation device in the business process; M is a positive integer; i is a positive integer less than or equal to M;
[0233] The task creation module 11 may include: a process starting unit 111, a first creation unit 112, and a second creation unit 113;
[0234] The process start unit 111 is used to obtain a process start request sent by a business client associated with the process engine component through the process engine component; the process start request is used to start a business process associated with a business operation device; based on the process start request, the process template data associated with the business process is obtained, and the business process is generated through the process template data.
[0235] The process start request carries the process identifier corresponding to the business process;
[0236] The process initiation unit 111 may include: a template acquisition subunit 1111 and an instantiation subunit 1112;
[0237] The template acquisition subunit 1111 is used to obtain the process identifier corresponding to the business process from the process start request, obtain the business process diagram of the business process configuration from the template database associated with the process engine component according to the process identifier corresponding to the business process, and use the business process diagram as the process template data associated with the business process;
[0238] The instantiation subunit 1112 is used to initialize the process template data through the process engine component to obtain the initialized process template data, and perform process instantiation processing according to the initialized process template data to obtain the business process.
[0239] The specific functional implementation of the template acquisition subunit 1111 and the instantiation subunit 1112 can be found in the above Figure 3 The description of step S101 in the corresponding embodiment, or, alternatively, can refer to the above Fig.13 The description of step S202 in the corresponding embodiment will not be repeated here.
[0240] The first creating unit 112 is configured to create M tasks associated with the business operation device through a business process, and obtain a task i to be executed from the M tasks.
[0241] The second creating unit 113 is used to obtain the task execution order of M tasks associated with the business operation device in the business process, and create a task i to be executed according to the task execution order.
[0242] The specific functional implementation of the process starting unit 111, the first creation unit 112, and the second creation unit 113 can be found in the above Figure 3 The description of step S101 in the corresponding embodiment, or, alternatively, can refer to the above Fig.13The description of step S201 to step S203 in the corresponding embodiment will not be repeated here.
[0243] A first search module 12 is used to search for a task interception identifier associated with a task interceptor in the task auxiliary parameters of task i before executing task i, and obtain a first identifier search result;
[0244] The first search module 12 may include: a first search unit 121, a second search unit 122, and a third search unit 123;
[0245] The first search unit 121 is used to obtain the task function header of task i through the process engine component before executing task i, and use the task function header of task i as the task auxiliary parameter of task i; search for the task interception annotation information associated with the task interceptor in the task auxiliary parameters of task i, and when the task interception annotation information is found, determine that the task interception identifier associated with the task interceptor is found in the task auxiliary parameters of task i; and use the result of finding the task interception identifier in the task auxiliary parameters of task i as the first identifier search result.
[0246] The second search unit 122 is used to obtain the task interception list configured by the task interceptor through the process engine component before executing task i, and use the task interception list as the task auxiliary parameter of task i; the task interception list contains a task identifier for triggering the task interceptor; search for the task identifier of task i in the task auxiliary parameters of task i, and when the task identifier of task i is found, determine that the task interception identifier associated with the task interceptor is found in the task auxiliary parameters of task i; and use the result of finding the task interception identifier in the task auxiliary parameters of task i as the first identifier search result.
[0247] The third search unit 123 is used to obtain the task switch list configured by the task interceptor through the process engine component before executing task i, and use the task switch list as the task auxiliary parameter of task i; search for the task switch state of task i in the task auxiliary parameters of task i, and when the found task switch state is the task interception state, determine that the task interception identifier associated with the task interceptor is found in the task auxiliary parameters of task i; and use the result of finding the task interception identifier in the task auxiliary parameters of task i as the first identifier search result.
[0248] The specific functional implementation of the first search unit 121, the second search unit 122, and the third search unit 123 can be found in the above Figure 3 The description of step S102 in the corresponding embodiment, or the above Fig.13 The description of step S204 in the corresponding embodiment will not be repeated here.
[0249] The second search module 13 is used to call the task interceptor through the process engine component when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, and search the process interception identifier associated with the task interceptor in the process auxiliary parameters corresponding to the business process to obtain a second identifier search result;
[0250] The second search module 13 may include: a fourth search unit 131, a fifth search unit 132, and a sixth search unit 133;
[0251] The fourth search unit 131 is used to call the task interceptor through the process engine component when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, obtain the process function header of the business process, and use the process function header of the business process as the process auxiliary parameters corresponding to the business process; search for the process interception annotation information associated with the task interceptor in the process auxiliary parameters, and when the process interception annotation information is found, determine that the process interception identifier associated with the task interceptor is found in the process auxiliary parameters; and use the result of finding the process interception identifier in the process auxiliary parameters as the second identifier search result.
[0252] The fifth search unit 132 is used to call the task interceptor through the process engine component when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, obtain the process interception list configured by the task interceptor, and use the process interception list as the process auxiliary parameter corresponding to the business process; the process interception list contains a process identifier used to instruct the task interceptor to perform task interception; search for the process identifier corresponding to the business process in the process auxiliary parameters, and when the process identifier corresponding to the business process is found, determine that the process interception identifier associated with the task interceptor is found in the process auxiliary parameters; and use the result of finding the process interception identifier in the process auxiliary parameters as the second identifier search result.
[0253] The sixth search unit 133 is used to call the task interceptor through the process engine component when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of task i, obtain the process switch list configured by the task interceptor, and use the process switch list as the process auxiliary parameters corresponding to the business process; search the process switch state of the business process in the process auxiliary parameters, and when the found process switch state is the process interception state, determine that the process interception identifier associated with the task interceptor is found in the process auxiliary parameters; and use the result of finding the process interception identifier in the process auxiliary parameters as the second identifier search result.
[0254] The specific functional implementation of the fourth search unit 131, the fifth search unit 132, and the sixth search unit 133 can be found in the above Figure 3 The description of step S103 in the corresponding embodiment, or the above Fig.13 The description of step S205 in the corresponding embodiment will not be repeated here.
[0255] The verification success module 14 is used to perform task verification on task i in the business process when the second identifier search result indicates that the process interception identifier is found in the process auxiliary parameters. When the task verification is successful, it notifies the business server associated with the process engine component to execute task i for the business operation device.
[0256] The verification success module 14 may include: a task verification unit 141 and a task execution unit 142;
[0257] The task verification unit 141 is used to call the verification service component in the process processing device through the task interceptor to perform task verification on the task i in the business process and obtain the task verification result when the second identifier search result indicates that the process interception identifier is found in the process auxiliary parameter;
[0258] The task verification unit 141 may include: a rule search subunit 1411 and a comparison verification subunit 1412;
[0259] The rule search subunit 1411 is used to generate a task verification request for task i in the business process through the task interceptor, and send the task verification request to the verification service interface of the verification service component; the task verification request carries the process identifier corresponding to the business process and the device identifier of the business operation device; based on the task verification request, the verification service interface is called to search for a verification rule matching the process identifier corresponding to the business process in the verification rule table configured by the verification service component, and when a verification rule matching the process identifier corresponding to the business process is found in the verification rule table, the found verification rule is used as the task verification rule associated with task i;
[0260] The comparison and verification subunit 1412 is used to obtain the first device configuration information associated with the device identifier of the business operation device from the device configuration system associated with the business operation device based on the task verification rule, and compare the first device configuration information with the task verification rule through the verification service component to obtain the task verification result.
[0261] Among them, the comparison and verification sub-unit 1412 is specifically used to compare the first device configuration information with the task verification rules through the verification service component. If the first device configuration information is consistent with the task verification rules, the task verification is determined to be successful; if the first device configuration information is inconsistent with the task verification rules, the task verification is determined to have failed; the result of the successful task verification or the result of the failed task verification is used as the task verification result.
[0262] Among them, the task verification rules are used to specify the target device department to which the business operation device belongs, the target device status of the business operation device, and the target network status; the first device configuration information includes one or more information of the first device configuration department to which the business operation device belongs, the first device configuration status of the business operation device, and the first network configuration status.
[0263] The specific functional implementation of the rule search subunit 1411 and the comparison and verification subunit 1412 can be found in the above Figure 3 The description of step S104 in the corresponding embodiment, or, alternatively, can refer to the above Fig.13 The description of step S206 in the corresponding embodiment will not be repeated here.
[0264] The task execution unit 142 is used to send a task execution request to the business server associated with the process engine component based on task i when the task verification result indicates that the task verification is successful, so that the business server executes task i for the business operation device based on the task execution request.
[0265] Among them, the task execution unit 142 is specifically used to obtain the task identifier of task i and the process variables associated with task i through the process engine component when the task verification result indicates that the task verification is successful, generate a task execution request based on the task identifier and process variables of task i, and send the task execution request to the business server associated with the process engine component, so that the business server obtains the business logic corresponding to task i for the business operation device based on the task identifier of task i, and executes the business logic corresponding to task i when logging in to the business operation device through the process variables.
[0266] The specific functional implementation of the task verification unit 141 and the task execution unit 142 can be found in the above Figure 3 The description of step S104 in the corresponding embodiment, or, alternatively, can refer to the above Fig.13 The description of step S206-step S207 in the corresponding embodiment will not be repeated here.
[0267] The device may further include:
[0268] The verification failure module 15 is used for not executing task i and (Mi) tasks after task i in the business process when the task verification fails, and sending a first verification failure prompt message to the business client associated with the process engine component.
[0269] The process inspection module 16 is used to obtain the process status table configured by the process engine component; the process status table records the process status of N processes; N is a positive integer; the N processes include business processes associated with business operation devices; the process status table is scanned, and when it is detected in the process status table that the process status of the business process is a process running state, the business operation device is verified by the verification service component in the process processing device, and when the device verification fails, a second verification failure prompt message is sent to the business client associated with the process engine component.
[0270] The process inspection module 16 may include: a rule search unit 161, a comparison and verification unit 162, and a failure prompt unit 163;
[0271] A rule search unit 161 is used to send a device verification request to the verification service interface of the verification service component in the process processing device when it is detected in the process status table that the process state of the business process is the process running state; the device verification request carries the process identifier corresponding to the business process and the device identifier of the business operation device; based on the device verification request, the verification service interface is called to search for a verification rule matching the process identifier corresponding to the business process in the verification rule table configured by the verification service component, and when a verification rule matching the process identifier corresponding to the business process is found in the verification rule table, the found verification rule is used as the device verification rule associated with the business operation device;
[0272] The comparison and verification unit 162 is used to obtain the second device configuration information associated with the device identifier of the business operation device from the device configuration system associated with the business operation device based on the device verification rule, and compare the second device configuration information with the device verification rule through the verification service component to obtain the device verification result;
[0273] The failure prompt unit 163 is used to send a second verification failure prompt message to the business client associated with the process engine component when the device verification result indicates that the device verification has failed.
[0274] The specific functional implementation of the rule search unit 161, the comparison and verification unit 162, and the failure prompt unit 163 can be found in the above Fig.13 The description of step S209 in the corresponding embodiment, or, can refer to the above Fig.13 The description of step S209 in the corresponding embodiment will not be repeated here.
[0275] The specific functional implementation of the task creation module 11, the first search module 12, the second search module 13, the verification success module 14, the verification failure module 15, and the process inspection module 16 can be found in the above Figure 3 For the description of steps S101 to S104 in the corresponding embodiment, or, please refer to the above Fig.13 The description of steps S201 to S209 in the corresponding embodiment will not be repeated here. It should be understood that the description of the beneficial effects obtained by adopting the same method will not be repeated.
[0276] See also Fig.16 , Fig.16 Schematic diagram of the structure of a computer device provided in an embodiment of the present application. Fig.16 As shown, the computer device 1000 may include: a processor 1001, a network interface 1004 and a memory 1005. In addition, the above-mentioned computer device 1000 may also include: a user interface 1003, and at least one communication bus 1002. Among them, the communication bus 1002 is used to realize the connection and communication between these components. Among them, the user interface 1003 may include a display screen (Display), a keyboard (Keyboard), and the user interface 1003 may optionally include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a WI-FI interface). The memory 1005 may be a high-speed RAM memory, or it may be a non-volatile memory (non-volatile memory), such as at least one disk storage. The memory 1005 may optionally also be at least one storage device located away from the aforementioned processor 1001. As Fig.16 As shown, the memory 1005 as a computer-readable storage medium may include an operating system, a network communication module, a user interface module, and a device control application program.
[0277] In such Fig.16 In the computer device 1000 shown in the figure, the network interface 1004 can provide a network communication function; the user interface 1003 is mainly used to provide an input interface for the user; and the processor 1001 can be used to call the device control application stored in the memory 1005 to execute the above Figure 3 , Fig.13 The description of the task data processing method in any corresponding embodiment will not be repeated here. In addition, the description of the beneficial effects of adopting the same method will not be repeated here either.
[0278] In addition, it should be pointed out here that: the embodiment of the present application also provides a computer-readable storage medium, and the computer-readable storage medium stores a computer program executed by the task data processing device 1 mentioned above, and the computer program includes computer instructions. When the processor executes the computer instructions, it can execute the above-mentioned task data processing device 1. Figure 3 , Fig.13 The description of the task data processing method in any corresponding embodiment will not be repeated here. In addition, the description of the beneficial effects of adopting the same method will not be repeated. For technical details not disclosed in the computer-readable storage medium embodiment involved in this application, please refer to the description of the method embodiment of this application.
[0279] The computer-readable storage medium may be the task data processing device provided in any of the aforementioned embodiments or the internal storage unit of the computer device, such as the hard disk or memory of the computer device. The computer-readable storage medium may also be an external storage device of the computer device, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the computer device. Further, the computer-readable storage medium may also include both the internal storage unit of the computer device and an external storage device. The computer-readable storage medium is used to store the computer program and other programs and data required by the computer device. The computer-readable storage medium may also be used to temporarily store data that has been output or is to be output.
[0280] In addition, it should be noted that: the embodiment of the present application also provides a computer program product or a computer program, the computer program product or the computer program includes computer instructions, the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the above Figure 3 , Fig.13 Any method provided by the corresponding embodiment. In addition, the description of the beneficial effects of the same method will not be repeated. For technical details not disclosed in the computer program product or computer program embodiment involved in this application, please refer to the description of the method embodiment of this application.
[0281] The terms "first", "second", etc. in the description, claims, and drawings of the embodiments of the present application are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any of their variations are intended to cover non-exclusive inclusions. For example, a process, method, device, product, or equipment that includes a series of steps or units is not limited to the listed steps or modules, but optionally includes steps or modules that are not listed, or optionally includes other step units inherent to these processes, methods, devices, products, or equipment.
[0282] In the embodiments of the present application, the term "module" or "unit" refers to a computer program or a part of a computer program with a predetermined function, and works together with other related parts to achieve a predetermined goal, and can be implemented in whole or in part by using software, hardware (such as processing circuits or memories) or a combination thereof. Similarly, a processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be part of an overall module or unit that includes the function of the module or unit.
[0283] Those of ordinary skill in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in terms of function in the above description. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0284] It should be noted that, for the above-mentioned various method embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, some steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.
[0285] The steps in the method of the embodiment of the present application can be adjusted in order, combined and deleted according to actual needs.
[0286] The modules in the device of the embodiment of the present application can be merged, divided and deleted according to actual needs.
[0287] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing related hardware through a computer program, and the computer program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM), etc.
[0288] The above disclosure is only the preferred embodiment of the present application, which certainly cannot be used to limit the scope of rights of the present application. Therefore, equivalent changes made according to the claims of the present application are still within the scope covered by the present application.
Claims
1. A task data processing method, characterized in that: The method is executed by a process processing device, and a task interceptor is deployed on a process engine component in the process processing device; the method comprises: Acquire a business process associated with a business operation device, and create a task i to be executed through M tasks associated with the business operation device in the business process; M is a positive integer; i is a positive integer less than or equal to M; Before executing the task i, searching the task auxiliary parameters of the task i for a task interception identifier associated with the task interceptor to obtain a first identifier search result; When the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of the task i, the task interceptor is called by the process engine component, and the process interception identifier associated with the task interceptor is searched in the process auxiliary parameters corresponding to the business process to obtain a second identifier search result; When the second identifier search result indicates that the process intercept identifier is found in the process auxiliary parameters, a task verification is performed on the task i in the business process. When the task verification is successful, the business server associated with the process engine component is notified to execute the task i for the business operation device.
2. The method according to claim 1, characterized in that The acquiring of the business process associated with the business operation device includes: Acquiring, through the process engine component, a process start request sent by a business client associated with the process engine component; the process start request is used to start a business process associated with a business operation device; Based on the process start request, process template data associated with the business process is obtained, and the business process is generated through the process template data.
3. The method according to claim 2, characterized in that The process start request carries a process identifier corresponding to the business process; The acquiring, based on the process start request, process template data associated with the business process, and generating the business process through the process template data, includes: Obtaining a process identifier corresponding to the business process from the process start request, obtaining a business process diagram configured for the business process from a template database associated with the process engine component according to the process identifier corresponding to the business process, and using the business process diagram as process template data associated with the business process; The process template data is initialized by the process engine component to obtain the initialized process template data, and the process instantiation is performed according to the initialized process template data to obtain the business process.
4. The method according to claim 1, characterized in that: Before executing the task i, searching the task auxiliary parameters of the task i for a task interception identifier associated with the task interceptor to obtain a first identifier search result includes: Before executing the task i, obtaining the task function header of the task i through the process engine component, and using the task function header of the task i as the task auxiliary parameter of the task i; Searching for task interception annotation information associated with the task interceptor in the task auxiliary parameters of the task i, and when the task interception annotation information is found, determining that a task interception identifier associated with the task interceptor is found in the task auxiliary parameters of the task i; The result of finding the task interception identifier in the task auxiliary parameters of the task i is used as the first identifier search result.
5. The method according to claim 1, characterized in that Before executing the task i, searching the task auxiliary parameters of the task i for a task interception identifier associated with the task interceptor to obtain a first identifier search result includes: Before executing the task i, the task interception list configured by the task interceptor is obtained through the process engine component, and the task interception list is used as the task auxiliary parameter of the task i; the task interception list contains a task identifier for triggering the task interceptor; searching for a task identifier of the task i in the task auxiliary parameters of the task i, and when the task identifier of the task i is found, determining that a task interception identifier associated with the task interceptor is found in the task auxiliary parameters of the task i; The result of finding the task interception identifier in the task auxiliary parameters of the task i is used as the first identifier search result.
6. The method according to claim 1, characterized in that Before executing the task i, searching the task auxiliary parameters of the task i for a task interception identifier associated with the task interceptor to obtain a first identifier search result includes: Before executing the task i, obtaining the task switch list configured by the task interceptor through the process engine component, and using the task switch list as the task auxiliary parameter of the task i; Searching for the task switch state of the task i in the task auxiliary parameters of the task i, and when the found task switch state is a task interception state, determining that a task interception identifier associated with the task interceptor is found in the task auxiliary parameters of the task i; The result of finding the task interception identifier in the task auxiliary parameters of the task i is used as the first identifier search result.
7. The method according to claim 1, characterized in that When the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of the task i, the task interceptor is called by the process engine component, and the process interception identifier associated with the task interceptor is searched in the process auxiliary parameters corresponding to the business process to obtain a second identifier search result, including: When the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of the task i, the task interceptor is called by the process engine component to obtain the process function header of the business process, and the process function header of the business process is used as the process auxiliary parameter corresponding to the business process; Searching for process interception annotation information associated with the task interceptor in the process auxiliary parameters, and when the process interception annotation information is found, determining that a process interception identifier associated with the task interceptor is found in the process auxiliary parameters; The result of finding the process interception identifier in the process auxiliary parameters is used as the second identifier search result.
8. The method according to claim 1, characterized in that When the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of the task i, the task interceptor is called by the process engine component, and the process interception identifier associated with the task interceptor is searched in the process auxiliary parameters corresponding to the business process to obtain a second identifier search result, including: When the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of the task i, the task interceptor is called through the process engine component to obtain the process interception list configured by the task interceptor, and the process interception list is used as the process auxiliary parameter corresponding to the business process; the process interception list contains a process identifier for instructing the task interceptor to perform task interception; Searching for a process identifier corresponding to the business process in the process auxiliary parameters, and when the process identifier corresponding to the business process is found, determining that a process interception identifier associated with the task interceptor is found in the process auxiliary parameters; The result of finding the process interception identifier in the process auxiliary parameters is used as the second identifier search result.
9. The method according to claim 1, characterized in that: When the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of the task i, the task interceptor is called by the process engine component, and the process interception identifier associated with the task interceptor is searched in the process auxiliary parameters corresponding to the business process to obtain a second identifier search result, including: When the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of the task i, the task interceptor is called by the process engine component to obtain the process switch list configured by the task interceptor, and the process switch list is used as the process auxiliary parameters corresponding to the business process; Searching for the process switch state of the business process in the process auxiliary parameters, and when the found process switch state is a process interception state, determining that a process interception identifier associated with the task interceptor is found in the process auxiliary parameters; The result of finding the process interception identifier in the process auxiliary parameters is used as the second identifier search result.
10. The method according to claim 1, characterized in that When the second identifier search result indicates that the process intercept identifier is found in the process auxiliary parameter, performing task verification on the task i in the business process, and when the task verification succeeds, notifying the business server associated with the process engine component to execute the task i for the business operation device, including: When the second identifier search result indicates that the process interception identifier is found in the process auxiliary parameters, the task interceptor calls the verification service component in the process processing device to perform task verification on the task i in the business process to obtain a task verification result; When the task verification result indicates that the task verification is successful, based on the task i, a task execution request is sent to the business server associated with the process engine component, so that the business server executes the task i for the business operation device based on the task execution request.
11. The method according to claim 10, characterized in that The calling of the verification service component in the process processing device by the task interceptor to perform task verification on the task i in the business process to obtain a task verification result includes: Generate a task verification request for the task i in the business process through the task interceptor, and send the task verification request to the verification service interface of the verification service component; the task verification request carries the process identifier corresponding to the business process and the device identifier of the business operation device; Based on the task verification request, the verification service interface is called to search for a verification rule that matches the process identifier corresponding to the business process in the verification rule table configured by the verification service component, and when a verification rule that matches the process identifier corresponding to the business process is found in the verification rule table, the found verification rule is used as the task verification rule associated with the task i; Based on the task verification rule, first device configuration information associated with the device identifier of the business operation device is obtained from the device configuration system associated with the business operation device, and the first device configuration information is compared with the task verification rule through the verification service component to obtain a task verification result.
12. The method according to claim 11, characterized in that The task verification rule is used to specify the target device department to which the business operation device belongs, the target device status of the business operation device, and the target network status; the first device configuration information includes one or more information of the first device configuration department to which the business operation device belongs, the first device configuration status of the business operation device, and the first network configuration status.
13. The method according to claim 10, characterized in that When the task verification result indicates that the task verification is successful, based on the task i, sending a task execution request to a business server associated with the process engine component includes: When the task verification result indicates that the task verification is successful, the task identifier of task i and the process variables associated with task i are obtained through the process engine component, a task execution request is generated based on the task identifier of task i and the process variables, and the task execution request is sent to a business server associated with the process engine component, so that the business server obtains the business logic corresponding to the task i for the business operation device based on the task identifier of task i, and executes the business logic corresponding to task i when logging into the business operation device through the process variables.
14. The method according to claim 1, characterized in that Also includes: When task verification fails, the task i and (Mi) tasks after the task i in the business process are not executed, and a first verification failure prompt message is sent to the business client associated with the process engine component.
15. The method according to claim 1, characterized in that Also includes: Obtaining a process status table configured by the process engine component; The process status table records the process status of N processes; N is a positive integer; The N processes include the business process associated with the business operation device; The process status table is scanned, and when it is detected in the process status table that the process status of the business process is a process running state, the business operation device is verified by the verification service component in the process processing device. When the device verification fails, a second verification failure prompt message is sent to the business client associated with the process engine component.
16. The method according to claim 15, characterized in that When the process state of the business process is detected in the process state table as a process running state, the business operation device is verified by the verification service component in the process processing device, and when the device verification fails, a second verification failure prompt message is sent to the business client associated with the process engine component, including: When it is detected in the process status table that the process status of the business process is the process running state, a device verification request is sent to the verification service interface of the verification service component in the process processing device; the device verification request carries the process identifier corresponding to the business process and the device identifier of the business operation device; Based on the device verification request, the verification service interface is called to search for a verification rule that matches the process identifier corresponding to the business process in the verification rule table configured by the verification service component, and when a verification rule that matches the process identifier corresponding to the business process is found in the verification rule table, the found verification rule is used as the device verification rule associated with the business operation device; Based on the device verification rule, obtaining second device configuration information associated with the device identifier of the business operation device from a device configuration system associated with the business operation device, and comparing the second device configuration information with the device verification rule through the verification service component to obtain a device verification result; When the device verification result indicates that the device verification has failed, second verification failure prompt information is sent to a business client associated with the process engine component.
17. A task data processing device, characterized in that: The device runs on a process processing device, and a task interceptor is deployed on a process engine component in the process processing device; the device includes: A task creation module, used to obtain a business process associated with a business operation device, and create a task i to be executed through M tasks associated with the business operation device in the business process; M is a positive integer; i is a positive integer less than or equal to M; A first search module is used to search for a task interception identifier associated with the task interceptor in the task auxiliary parameters of the task i before executing the task i, and obtain a first identifier search result; A second search module is used to call the task interceptor through the process engine component when the first identifier search result indicates that the task interception identifier is found in the task auxiliary parameters of the task i, and search for the process interception identifier associated with the task interceptor in the process auxiliary parameters corresponding to the business process to obtain a second identifier search result; A verification success module is used to perform task verification on the task i in the business process when the second identifier search result indicates that the process interception identifier is found in the process auxiliary parameters. When the task verification is successful, the business server associated with the process engine component is notified to execute the task i for the business operation device.
18. A computer device, characterized in that: include: Processor and memory; The processor is connected to the memory, wherein the memory is used to store a computer program, and the processor is used to call the computer program so that the computer device executes the method according to any one of claims 1 to 16.
19. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, which is suitable for being loaded and executed by a processor, so that a computer device having the processor executes the method according to any one of claims 1 to 16.
20. A computer program product, characterized in that The computer program product comprises computer instructions, which are stored in a computer-readable storage medium. The computer instructions are suitable for being read and executed by a processor, so that a computer device having the processor executes the method according to any one of claims 1 to 16.