Application trust authorization method and device for low-code platform and medium

By obtaining application registration data and deployment data, configuring API open rules and encryption requirements, and using business gateway interception analysis, data security issues when opening APIs on low-code development platforms are solved, and the customization of API open rules and data access security is realized.

CN120030521APending Publication Date: 2025-05-23SHANDONG INSPUR SCI RES INST CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510120291.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-25
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

When the low-code development platform opens API, the data security level is low, and there is a data security risk when external system integration.

Method used

By obtaining application registration data, determining application deployment data based on application registration characteristics, configuring API open rules, analyzing application access rules, obtaining management encryption requirements, performing accessKey encryption, and obtaining low-code application trust authorization data through business gateway interception analysis.

Benefits of technology

It realizes the customization and management of open rules for low-code platform APIs, strengthens the security of data access, simplifies external system docking, and improves development efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120030521A_ABST
    Figure CN120030521A_ABST
Patent Text Reader

Abstract

The invention discloses an application trust authorization method and device for a low-code platform and a medium, and relates to the technical field of low-code platform security, and the method comprises the steps: obtaining application registration data, and obtaining application deployment data through application registration feature judgment based on the application registration data; according to the application deployment data, API opening rule data are determined through API opening rule configuration; based on the API open rule data, obtaining an application access rule through application access analysis; acquiring a management encryption demand, and based on the management encryption demand, encrypting through the accessKey to determine request encryption data; and according to the request encryption data, intercepting and analyzing through the service gateway to obtain low-code application trust authorization data. By means of the method, the technical problem that in the prior art, under the condition that a low-code development platform opens an API, the data security degree is low is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of low-code platform security technology, and in particular to an application trust authorization method, device and medium for a low-code platform. Background Art

[0002] The Low-Code Development Platform (LCDP) enables developers to quickly build and deploy applications through a graphical interface, drag-and-drop components, and model-driven logic without writing a lot of code, greatly reducing the labor cost of system construction, shortening the development cycle, and being able to quickly respond to changes in business needs and achieve system updates and maintenance.

[0003] Among the applications of low-code development platforms, there are applications that need to be integrated with big data and digital twin systems to facilitate real-time observation and operation by managers. Taking the industrial Internet as an example, in the case of sensitive data, the opening of all APIs by devices in order to integrate with external systems will seriously affect data security and create security risks for low-code development platforms. Summary of the invention

[0004] The embodiments of the present application provide an application trust authorization method, device and medium for a low-code platform, which solves the technical problem of low data security when the low-code development platform opens the API in the prior art.

[0005] In the first aspect, an embodiment of the present application provides a low-code application trust authorization method, characterized in that the method includes: obtaining application registration data, and based on the application registration data, obtaining application deployment data through application registration feature determination; determining API open rule data through API open rule configuration according to the application deployment data; obtaining application access rules through application access analysis based on the API open rule data; obtaining management encryption requirements, and determining request encryption data through accessKey encryption based on the management encryption requirements; obtaining low-code application trust authorization data through business gateway interception and analysis based on the request encryption data.

[0006] In one implementation of the present application, based on the application registration data, the application deployment data is obtained through application registration feature determination, specifically including: performing a field query on the application registration data to obtain application registration feature data; based on the application registration feature data, obtaining the application deployment status through deployment status detection; when the application deployment status is that the application is registered with the same service registration center through a business gateway, the application deployment data is obtained.

[0007] In one implementation of the present application, API open rule data is determined through API open rule configuration based on application deployment data, specifically including: based on the application deployment data, determining the API list through automatic registration of fixed APIs; performing configuration field detection on the API list to obtain API parameters; wherein the API parameters include: application ID, API path, and enabled status; according to the API parameters, determining the API open rule data through enabled status configuration.

[0008] In one implementation of the present application, application access rules are obtained through application access analysis based on API open rule data, specifically including: based on API open rule data, access rule groups are obtained through EasyRule rule definition; execution priority is configured for the access rule groups to determine the access rule priority; application access rules are obtained through execution condition analysis based on the access rule priority.

[0009] In one implementation of the present application, based on the management encryption requirements, the accessKey encryption is used to determine the requested encrypted data, specifically including: obtaining the user encryption algorithm, and applying for the encryption key value of the user encryption algorithm to obtain an encryption key-value pair; based on the encryption key-value pair, encrypting the accessKey through the secretKey key to determine the header Authorizaion additional attribute of the requesting application; assigning the header Authorizaion additional attribute to the applied application to obtain the determined requested encrypted data.

[0010] In one implementation of the present application, based on the request encrypted data, the business gateway intercepts and analyzes it to obtain the low-code application trust authorization data, specifically including: based on the request encrypted data, through Authorization interception, obtain the Authorization to be decrypted; map the decryption algorithm for the Authorization to be decrypted, and decrypt the Authorization to be decrypted through the decryption algorithm obtained by the mapping to obtain the decrypted Authorization; perform consistency analysis on the decrypted Authorization to obtain the first low-code application trust authorization data; obtain the key information of the received request, and based on the key information of the received request, intercept through the gateway rules to obtain the second low-code application trust authorization data; based on the first low-code application trust authorization data or the second low-code application trust authorization data, obtain the low-code application trust authorization data.

[0011] In one implementation of the present application, based on the key information of the received request, the second low-code application trust authorization data is obtained through gateway rule interception, specifically including: obtaining the administrator interception rule, and based on the administrator interception rule, determining the interception execution rule through rule priority mapping; according to the interception execution rule, the key information of the received request is intercepted to obtain the second low-code application trust authorization data.

[0012] In one implementation of the present application, after encrypting the data according to the request and intercepting and analyzing it through the business gateway to obtain the low-code application trust authorization data, the method also includes: verifying the validity of the code application trust authorization data to determine the validity of the authorization; based on the authorization validity, determining the API security optimization strategy through authorization security analysis.

[0013] In the second aspect, an embodiment of the present application also provides a low-code application trust authorization device, characterized in that the device includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions that can be executed by at least one processor, and the instructions are executed by at least one processor so that the at least one processor can: obtain application registration data, and based on the application registration data, obtain application deployment data through application registration feature determination; determine API open rule data through API open rule configuration based on the application deployment data; obtain application access rules through application access analysis based on the API open rule data; obtain management encryption requirements, and determine request encryption data through accessKey encryption based on the management encryption requirements; obtain low-code application trust authorization data through business gateway interception and analysis based on the request encryption data.

[0014] On the third aspect, the embodiment of the present application also provides a non-volatile computer storage medium for low-code application trust authorization, which stores computer executable instructions, and is characterized in that the computer executable instructions are set to: obtain application registration data, and based on the application registration data, obtain application deployment data through application registration feature determination; determine API open rule data through API open rule configuration based on the application deployment data; obtain application access rules through application access analysis based on the API open rule data; obtain management encryption requirements, and determine request encryption data based on the management encryption requirements through accessKey encryption; obtain low-code application trust authorization data through business gateway interception and analysis based on the request encrypted data.

[0015] The embodiments of the present application provide an application trust authorization method, device and medium for a low-code platform. Through API open rule customization, key management and business gateway interception, it solves the technical problem of low data security when the low-code development platform opens the API in the prior art, simplifies the connection with external systems, and improves development efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0017] Figure 1 A flow chart of an application trust authorization method for a low-code platform provided in an embodiment of the present application;

[0018] Figure 2 A schematic diagram of the internal structure of an application trust authorization device of a low-code platform provided in an embodiment of the present application. DETAILED DESCRIPTION

[0019] In order to make the purpose, technical solution and advantages of the present application clearer, the technical solution of the present application will be clearly and completely described below in combination with the specific embodiments of the present application and the corresponding drawings. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of the present application.

[0020] The embodiments of the present application provide an application trust authorization method, device and medium for a low-code platform. Through API open rule customization, key management and business gateway interception, it solves the technical problem of low data security when the low-code development platform opens the API in the prior art, simplifies the connection with external systems, and improves development efficiency.

[0021] The technical solution proposed in the embodiments of the present application is described in detail below with reference to the accompanying drawings.

[0022] Figure 1 A flow chart of an application trust authorization method for a low-code platform provided in an embodiment of the present application. Figure 1 As shown, an application trust authorization method for a low-code platform provided in an embodiment of the present application specifically includes the following steps:

[0023] Step 101: Acquire application registration data, and obtain application deployment data based on the application registration data and application registration feature determination.

[0024] Specifically, it includes: performing field query on application registration data to obtain application registration feature data; obtaining application deployment status through deployment status detection based on application registration feature data; and obtaining application deployment data when the application deployment status is that the application is registered with the same service registration center through the business gateway.

[0025] This application obtains application registration data and obtains application deployment data based on the application registration data and application registration feature determination, thereby realizing the configuration and key field analysis of application registration and application deployment, and improving the security of application registration and deployment.

[0026] In the examples of the present application, detailed explanation is given by the following Example 1.

[0027] Example 1: Applications are logical units used by low-code platforms to solve real-world business problems. Applications usually include forms, processes, web pages, reports, and other functions. There are usually two deployment modes: one is to run independently from the platform, and the other is to run on the basis of the low-code platform to solve more complex business problems based on some of the capabilities of the low-code platform.

[0028] It should be noted that the premise for both application deployments is that the application must be registered with the same service registration center as the business gateway.

[0029] The low-code platform responds to external system requests through a dedicated business gateway, and only opens API access to registered applications. Requests to unregistered applications will be intercepted by the business gateway by default. The registration feature data of the application is explained in Table 1 below.

[0030]

[0031] Table 1

[0032] Step 102: Determine the API open rule data through API open rule configuration according to the application deployment data.

[0033] Specifically, it includes: determining the API list based on application deployment data through automatic registration of fixed APIs; performing configuration field detection on the API list to obtain API parameters; wherein the API parameters include: application ID, API path, and enabled status; and determining the API open rule data through enabled status configuration according to the API parameters.

[0034] This application determines the API open rule data based on the application deployment data through API open rule configuration, realizes the formulation and automatic registration of API open rules, and improves the data security after the API is opened.

[0035] In the examples of the present application, detailed explanation is given by the following Example 2.

[0036] Example 2: Define a list of APIs open to the application. Usually, low-code platform applications will have some fixed APIs such as querying form data, modifying form data, etc., which will follow the REST style.

[0037] These fixed APIs are automatically registered in the API list, and users can choose to enable or disable them. In addition, there are some application-specific APIs, such as querying report data, etc. The API parameters are explained in Table 2 below.

[0038]

[0039]

[0040] Table 2

[0041] Step 103: Based on the API open rule data, application access rules are obtained through application access analysis.

[0042] Specifically, it includes: based on API open rule data, access rule groups are obtained through EasyRule rule definitions; execution priority configuration is performed on access rule groups to determine access rule priorities; and application access rules are obtained through execution condition analysis based on access rule priorities.

[0043] This application is based on API open rule data and obtains application access rules through application access analysis, thereby realizing rule formulation and action processing for accessing applications, and improving the security and development efficiency of application access.

[0044] In the examples of the present application, this is explained in detail through the following Example 3.

[0045] Example 3: Access rules refer to the conditions under which an application is allowed to access the application, such as whitelist and blacklist of request sources, time period and frequency of allowed access, etc. Different rules correspond to different action processors.

[0046] By adopting EasyRule as the rule engine, as a lightweight rule engine, it supports the ability to create combined rules from simple rules and supports the ability to define rules using expression languages ​​such as MVEL and SpEL.

[0047] An application can define multiple rules, and EasyRule will execute the rules in order of priority. The data required by the rules is recorded in JSON format and passed to the rule engine through Facts when constructing the rules.

[0048] The rule engine will execute the conditional processors, i.e., actions, in sequence according to the conditions and priorities defined by the user. Actions can obtain the necessary real data, i.e., facts, from the rule engine.

[0049] Step 104: Obtain management encryption requirements, and encrypt the requested encrypted data based on the management encryption requirements through accessKey.

[0050] Specifically, it includes: obtaining the user encryption algorithm, and applying for the encryption key value of the user encryption algorithm to obtain the encryption key value pair; based on the encryption key value pair, encrypting the accessKey with the secretKey key to determine the header Authorizaion additional attribute of the requesting application; assigning the header Authorizaion additional attribute to the applied application to obtain the confirmed request encrypted data.

[0051] This application obtains management encryption requirements, and based on the management encryption requirements, determines the requested encrypted data through accessKey encryption, implements the adaptation of the user encryption algorithm and the configuration of the Authorizaion additional attribute, and improves access security and encryption algorithm adaptability.

[0052] In the examples of the present application, a detailed explanation is given by the following Example 4.

[0053] Example 4: The key is requested by a service manager who needs to access application data. The key includes three fields, which are explained in Table 3 below.

[0054] Fields type illustrate accessKey String Accessing Key Values secretKey String Encryption Key algorithm enmu Encryption Algorithm

[0055] Table 3

[0056] The service manager applies for an encrypted key-value pair based on the encryption algorithm he is familiar with. When requesting an application, the service needs to add the Authorization attribute to the request header. The attribute value is obtained by encrypting the accessKey using the encryption algorithm using the secretKey as the key.

[0057] Step 105: Encrypt data according to the request, intercept and analyze it through the business gateway, and obtain the low-code application trust authorization data.

[0058] Specifically, it includes: based on the request encrypted data, intercepting through Authorization, obtaining the Authorization to be decrypted; mapping the decryption algorithm of the Authorization to be decrypted, and decrypting the Authorization to be decrypted through the decryption algorithm obtained by the mapping to obtain the decrypted Authorization; performing consistency analysis on the decrypted Authorization to obtain the first low-code application trust authorization data; obtaining the key information of the received request, and based on the key information of the received request, intercepting through the gateway rules to obtain the second low-code application trust authorization data; based on the first low-code application trust authorization data or the second low-code application trust authorization data, obtaining the low-code application trust authorization data.

[0059] Based on the key information of the received request, the gateway rule interception is used to obtain the trust authorization data of the second low-code application, specifically including: obtaining the administrator interception rule, and based on the administrator interception rule, determining the interception execution rule through rule priority mapping; according to the interception execution rule, the key information of the received request is intercepted to obtain the trust authorization data of the second low-code application.

[0060] After encrypting the data according to the request and intercepting and analyzing it through the business gateway to obtain the low-code application trust authorization data, the method also includes: verifying the validity of the code application trust authorization data to determine the validity of the authorization; and determining the API security optimization strategy through authorization security analysis based on the authorization validity.

[0061] This application encrypts data according to the request, intercepts and analyzes it through the business gateway, obtains the low-code application trust authorization data, realizes multi-faceted interception of the business gateway, and improves the data security of API opening.

[0062] In the examples of the present application, this is explained in detail through the following Example 5.

[0063] Example 5: The basic function of the gateway supports traffic routing. In addition, the business gateway in this article sets multiple interceptors. The first layer of interceptors is the identity authentication interceptor. The second layer of interceptors is the rule interceptor, which executes rules according to the target application requested for access.

[0064] The first-level interceptor intercepts identity authentication and obtains the attribute Authorization of the request header. This attribute needs to be actively filled in by the service when sending a request. The attribute refers to the access key obtained by using the encryption algorithm and the secret key.

[0065] After the interceptor obtains the Authorization, it uses the same encryption algorithm to decrypt it and determine whether the access key is consistent with the one issued to the service. If they are inconsistent, the request is directly rejected. If they are consistent, the next interceptor, i.e. the rule interceptor, is executed.

[0066] The second layer of interceptors is rule interceptors, where rules are defined by application administrators. The interceptors extract key information (such as API path, request source) from requests received by the business gateway and execute rules in the order of priority defined by the user.

[0067] The execution results are asynchronously written to the database as structured objects via CompleteFuture.

[0068] The above is an embodiment of the method proposed in this application. Based on the same inventive concept, this application embodiment also provides an application trust authorization device for a low-code platform, whose structure is as follows: Figure 2 shown.

[0069] Figure 2 A schematic diagram of the internal structure of an application trust authorization device of a low-code platform provided in an embodiment of the present application. Figure 2 As shown, the device includes:

[0070] at least one processor 201;

[0071] and, a memory 202 communicatively connected to the at least one processor;

[0072] The memory 202 stores instructions that can be executed by at least one processor, and the instructions are executed by at least one processor 201 to enable at least one processor 201 to:

[0073] Obtain application registration data, and based on the application registration data, determine the application deployment data through application registration features; determine the API open rule data through API open rule configuration based on the application deployment data; obtain application access rules through application access analysis based on the API open rule data; obtain management encryption requirements, and determine the request encryption data through accessKey encryption based on the management encryption requirements; obtain low-code application trust authorization data through business gateway interception and analysis based on the request encryption data.

[0074] Some embodiments of the present application provide corresponding Figure 1 A non-volatile computer storage medium for application trust authorization of a low-code platform, storing computer executable instructions, wherein the computer executable instructions are set to:

[0075] Obtain application registration data, and based on the application registration data, determine the application deployment data through application registration features; determine the API open rule data through API open rule configuration based on the application deployment data; obtain application access rules through application access analysis based on the API open rule data; obtain management encryption requirements, and determine the request encryption data through accessKey encryption based on the management encryption requirements; obtain low-code application trust authorization data through business gateway interception and analysis based on the request encryption data.

[0076] Each embodiment in this application is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the IoT device and medium embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.

[0077] The system and medium provided in the embodiments of the present application correspond one-to-one to the method. Therefore, the system and medium also have similar beneficial technical effects to the corresponding methods. Since the beneficial technical effects of the methods have been described in detail above, the beneficial technical effects of the system and medium will not be repeated here.

[0078] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0079] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0080] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0081] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0082] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0083] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0084] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0085] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0086] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.

Claims

1. A low-code application trust authorization method, characterized in that: The method comprises: Acquire application registration data, and obtain application deployment data based on the application registration data and application registration feature determination; According to the application deployment data, the API opening rule data is determined through the API opening rule configuration; Based on the API open rule data, application access rules are obtained through application access analysis; Obtain management encryption requirements, and encrypt the requested encrypted data based on the management encryption requirements by using accessKey; The data is encrypted according to the request, intercepted and analyzed by the business gateway to obtain the low-code application trust authorization data.

2. A low-code application trust authorization method according to claim 1, characterized in that: Based on the application registration data, application deployment data is obtained by determining the application registration features, including: Performing a field query on the application registration data to obtain application registration feature data; Based on the application registration feature data, obtaining the application deployment status through deployment status detection; When the application deployment state is that the application is registered with the same service registration center through the business gateway, the application deployment data is obtained.

3. A low-code application trust authorization method according to claim 1, characterized in that: According to the application deployment data, the API open rule data is determined through the API open rule configuration, specifically including: Based on the application deployment data, determining an API list by automatically registering fixed APIs; Performing configuration field detection on the API list to obtain API parameters; wherein the API parameters include: application ID, API path, and activation status; According to the API parameters, the API opening rule data is determined by enabling the state configuration.

4. A low-code application trust authorization method according to claim 1, characterized in that: Based on the API open rule data, application access rules are obtained through application access analysis, specifically including: Based on the API open rule data, an access rule group is obtained through EasyRule rule definition; Performing execution priority configuration on the access rule group to determine the access rule priority; The application access rule is obtained by performing conditional analysis according to the access rule priority.

5. A low-code application trust authorization method according to claim 1, characterized in that: Based on the management encryption requirement, the accessKey is used to encrypt and determine the requested encrypted data, including: Obtain a user encryption algorithm, and apply an encryption key value to the user encryption algorithm to obtain an encryption key value pair; Based on the encryption key-value pair, accessKey is encrypted by using the secretKey key to determine the additional attribute of the Authorizaion header of the requesting application; The header Authorization additional attribute is given to the applied application to obtain the confirmed request encrypted data.

6. A low-code application trust authorization method according to claim 1, characterized in that: According to the encrypted data of the request, the low-code application trust authorization data is obtained through interception and analysis by the business gateway, including: Based on the encrypted data requested, the Authorization to be decrypted is obtained through Authorization interception; Performing a decryption algorithm mapping on the Authorization to be decrypted, and decrypting the Authorization to be decrypted by using the decryption algorithm obtained by mapping, so as to obtain a decrypted Authorization; Perform consistency analysis on the decrypted Authorization to obtain the first low-code application trust authorization data; Obtain key information of the received request, and based on the key information of the received request, intercept through gateway rules to obtain the second low-code application trust authorization data; Based on the first low-code application trust authorization data or the second low-code application trust authorization data, the low-code application trust authorization data is obtained.

7. A low-code application trust authorization method according to claim 1, characterized in that: Based on the key information of the received request, the second low-code application trust authorization data is obtained through gateway rule interception, specifically including: Obtaining an administrator interception rule, and determining an interception execution rule based on the administrator interception rule through rule priority mapping; According to the interception execution rules, the key information of the received request is intercepted to obtain the second low-code application trust authorization data.

8. A low-code application trust authorization method according to claim 1, characterized in that: After encrypting the data according to the request, intercepting and analyzing the data through the business gateway, and obtaining the low-code application trust authorization data, the method further includes: Verifying the validity of the code application trust authorization data to determine the validity of the authorization; According to the authorization validity, an API security optimization strategy is determined through authorization security analysis.

9. A low-code application trust authorization device, characterized in that: The device comprises: at least one processor; and, a memory communicatively coupled to the at least one processor; The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to: Acquire application registration data, and obtain application deployment data based on the application registration data and application registration feature determination; According to the application deployment data, the API opening rule data is determined through the API opening rule configuration; Based on the API open rule data, application access rules are obtained through application access analysis; Obtain management encryption requirements, and encrypt the requested encrypted data based on the management encryption requirements by using accessKey; The data is encrypted according to the request, intercepted and analyzed by the business gateway to obtain the low-code application trust authorization data.

10. A non-volatile computer storage medium for low-code application trust authorization, storing computer executable instructions, characterized in that: The computer executable instructions are configured to: Acquire application registration data, and obtain application deployment data based on the application registration data and application registration feature determination; According to the application deployment data, the API opening rule data is determined through the API opening rule configuration; Based on the API open rule data, application access rules are obtained through application access analysis; Obtain management encryption requirements, and encrypt the requested encrypted data based on the management encryption requirements by using accessKey; The data is encrypted according to the request, intercepted and analyzed by the business gateway to obtain the low-code application trust authorization data.