Cross-order multi-level authority authentication method and device, medium and program product
Patent Information
- Application Number
- CN202510512124.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-23
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2045-04-23
Smart Images

Figure CN120030526A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data processing technology, and in particular to a cross-order multi-level authority authentication method, device, medium and program product. Background Art
[0002] Cloud services are computing resources and services provided on demand through the Internet. With the development of Internet technology, cloud service subscription models are becoming more and more popular. Usually, cloud service rights are presented in the form of virtual orders.
[0003] In the permission authentication scenario of cloud service subscription, a user may have multiple orders for the same type of cloud service. Therefore, the permissions granted by different orders can be accumulated during the same request for cloud service resources. For example, when the user's original order is not enough to deduct service resources, another order can be purchased and combined with the original order to obtain service permissions.
[0004] Currently, for cross-order permission authentication scenarios, the existing solution is usually to lock order permissions by adding locks, and check whether the order permissions meet the resource request one by one. If they meet, the order permissions are deducted, and if they do not meet, they are unlocked and the authentication failure is returned. However, in the high-concurrency request scenario of cloud service subscription, the use of locking solutions will cause a large number of requests to be blocked, affecting the system's response performance. Summary of the invention
[0005] The purpose of the embodiments of the present application is to provide a cross-order multi-level authority authentication method, device, medium and program product to solve the problem of poor system response performance in cloud service high-concurrency request scenarios.
[0006] In a first aspect, an embodiment of the present application provides a cross-order multi-level authority authentication method, including: Constructing an outer process interceptor responsibility chain for the current resource request; wherein the outer process interceptor responsibility chain includes an order adapter interceptor; determining an initial resource requirement corresponding to the current resource request; Utilizing the order adapter interceptor to pull an order set corresponding to the current resource request, and constructing an order interceptor responsibility chain corresponding to the order set; wherein the order set includes at least one order with a corresponding resource authority, and the order interceptor responsibility chain includes at least one order interceptor corresponding to the order set; According to the responsibility chain order of the order interceptor responsibility chain, the resource authority of each order interceptor is deducted based on the current resource demand until the current resource demand is zero, or until the authentication process reaches the last order interceptor; wherein the current resource demand is the remaining resource demand after each authority deduction from the initial resource demand; When the current resource demand is zero, jump out of the outer process interceptor responsibility chain and return a successful resource request result; When the authentication process reaches the last order interceptor and the resource authority corresponding to the current order interceptor is less than the current required resource authority, the deducted resource authority is rolled back in reverse order according to the responsibility chain, jumping out of the outer process interceptor responsibility chain and returning the result of permission authentication failure.
[0007] In an embodiment of the present application, a multi-level authentication responsibility chain is constructed for resource requests, and an authentication process of first deducting permissions and rolling back step by step is adopted to avoid request blocking due to the locking mechanism, thereby effectively improving the system response performance in high-concurrency request scenarios.
[0008] In some possible embodiments, when the authentication process reaches the last order interceptor and the resource authority amount corresponding to the current order interceptor is less than the current required resource amount, the deducted resource authority is rolled back in reverse order according to the responsibility chain, the outer process interceptor responsibility chain is jumped out and the authority authentication failure result is returned, including: When the authentication process reaches the last order interceptor and the resource authority corresponding to the current order interceptor is less than the current required resource amount, determine whether the current authentication scenario is a scenario that allows partial success; If yes, then jump out of the outer process interceptor responsibility chain and return a partial success result of the resource request based on the deducted resource authority; If not, the deducted resource permissions are rolled back in reverse order according to the chain of responsibility, the outer process interceptor chain of responsibility is jumped out and a permission authentication failure result is returned.
[0009] In an embodiment of the present application, permission authentication is performed based on whether partially successful authentication scenarios are allowed, thereby returning partial authentication success results or rolling back the deducted resources when authentication fails, thereby further improving the flexibility and scalability of cross-order permission authentication.
[0010] In some possible embodiments, each order has resource authority quantities of multiple authority authentication dimensions, each of the order interceptors includes a sub-authentication interceptor responsibility chain, and each of the sub-authentication interceptor responsibility chain includes multiple sub-authentication interceptors corresponding to the multiple authority authentication dimensions; The resource authority of each order interceptor is deducted in sequence based on the current resource demand according to the responsibility chain order of the order interceptor responsibility chain until the current resource demand is zero, or until the authentication process reaches the last order interceptor, including: In the authentication process of each of the order interceptors, the resource authority amount of each of the sub-authentication interceptors is deducted based on the current resource demand amount in the order of the responsibility chain of the sub-authentication interceptor, until the authentication process reaches a sub-authentication interceptor whose resource authority amount is insufficient to deduct the current required resource amount, or until the authentication process reaches the last sub-authentication interceptor; When the authentication process reaches a sub-authentication interceptor whose resource permissions are insufficient to deduct the currently required resource permissions, based on the actual resource permissions deducted by the current sub-authentication interceptor, the deducted resource permissions of the previous sub-authentication interceptor are rolled back in reverse order of the responsibility chain, and the actual resource permissions deducted by the current sub-authentication interceptor are used as the current required resource permissions of the next sub-authentication interceptor to start the authentication process of the next sub-authentication interceptor; When the authentication process reaches the last sub-authentication interceptor of the current order interceptor, and the resource permission amount corresponding to the current sub-authentication interceptor is less than the current required resource amount, based on the actual resource amount deducted by the current sub-authentication interceptor, the deducted resource permissions of the previous sub-authentication interceptor are rolled back in reverse order according to the chain of responsibility, and the remaining required resource amount after the settlement of the current sub-authentication interceptor is used as the current required resource amount of the next order interceptor to start the authentication process of the next order interceptor; When the authentication process reaches the last sub-authentication interceptor of the last order interceptor, and the resource authority corresponding to the current sub-authentication interceptor is less than the current required resource authority, the deducted resource authority is rolled back in reverse order according to the chain of responsibility, jumping out of the outer process interceptor chain of responsibility and returning the result of permission authentication failure.
[0011] In an embodiment of the present application, by constructing sub-authentication interceptor responsibility chains corresponding to multiple permission authentication dimensions inside the order interceptor, the authentication requirements of multi-dimensional permissions across orders are met, the scalability of the authentication process is further improved, and the response performance of multi-dimensional permission authentication in high-concurrency request scenarios is improved.
[0012] In some possible embodiments, when the authentication process reaches the last sub-authentication interceptor of the last order interceptor, and the resource authority amount corresponding to the current sub-authentication interceptor is less than the current required resource amount, the deducted resource authority is rolled back in reverse order according to the responsibility chain, the outer process interceptor responsibility chain is jumped out and the authority authentication failure result is returned, including: When the authentication process reaches the last sub-authentication interceptor of the last order interceptor, and the resource authority corresponding to the current sub-authentication interceptor is less than the current required resource amount, determine whether the current authentication scenario is a scenario that allows partial success; If so, then jump out of the outer process interceptor responsibility chain, and based on the remaining required resource amount after the current sub-authentication interceptor is settled, roll back the deducted resource permissions of other sub-authentication interceptors in reverse order according to the responsibility chain order, and return a partial success result of the resource request based on the deducted resource permissions; If not, the deducted resource permissions are rolled back in reverse order according to the chain of responsibility, the outer process interceptor chain of responsibility is jumped out and a permission authentication failure result is returned.
[0013] In an embodiment of the present application, by providing an authentication scenario that allows partial success and rolling back the undeducted resource permissions level by level when partial authentication is successful, the flexibility and scalability of cross-order multi-dimensional permission authentication are further improved.
[0014] In some possible embodiments, the outer process interceptor responsibility chain further includes a cache interceptor; Before determining the initial resource requirement corresponding to the current resource request, the method further includes: Acquire the historical authentication record of the current resource request based on the cache interceptor, and determine whether the current resource request meets the preset consumption-free authentication condition according to the historical authentication record; When it is determined that the current resource request meets the consumption-free authentication condition, the outer process interceptor responsibility chain is jumped out and a successful resource request result is returned.
[0015] In an embodiment of the present application, a cache interceptor is added to the outer responsibility chain to omit the specific multi-order merge authentication process when it is determined that the consumption-free authentication conditions are met, thereby further improving the response efficiency of resource request authentication.
[0016] In some possible embodiments, the using the order adapter interceptor to pull the order set corresponding to the current resource request and constructing an order interceptor responsibility chain corresponding to the order set includes: Utilize the order adapter interceptor to pull the order set corresponding to the current resource request, and obtain the order authority consumption strategy corresponding to the current resource request; wherein the order authority consumption strategy is used to characterize the consumption priority of each order in the order set; An order interceptor responsibility chain corresponding to the order set is constructed based on the order authority consumption strategy.
[0017] In an embodiment of the present application, by determining the order of authorization authentication for each order according to the order authorization consumption strategy, the user's needs for customized configuration of order consumption priority are met, and the flexibility of multi-order authorization authentication is further improved.
[0018] In some possible embodiments, the outer process interceptor responsibility chain also includes at least one authentication interceptor connected in series with the order adapter interceptor, and the authentication order of the at least one authentication interceptor is arranged before the order adapter interceptor.
[0019] In an embodiment of the present application, by adding at least one authentication interceptor before the order adapter interceptor of the outer responsibility chain, the response efficiency in complex authentication process scenarios is further improved.
[0020] In a second aspect, an embodiment of the present application provides a cross-order multi-level authority authentication device, including: An outer chain building module, used to build an outer process interceptor responsibility chain for the current resource request; wherein the outer process interceptor responsibility chain includes an order adapter interceptor; A demand determination module, configured to determine an initial resource demand corresponding to the current resource request; An order chain building module, used to use the order adapter interceptor to pull the order set corresponding to the current resource request, and build an order interceptor responsibility chain corresponding to the order set; wherein the order set includes at least one order with a corresponding resource authority, and the order interceptor responsibility chain includes at least one order interceptor corresponding to the order set; The authority authentication module is used to deduct the resource authority of each order interceptor based on the current resource demand in the responsibility chain order of the order interceptor responsibility chain until the current resource demand is zero, or until the authentication process reaches the last order interceptor; wherein the current resource demand is the remaining resource demand after each authority deduction from the initial resource demand; A success result return module, used to jump out of the outer process interceptor responsibility chain and return a successful result of the resource request when the current resource demand is zero; The resource rollback module is used to roll back the deducted resource permissions in reverse order of the chain of responsibility when the authentication process reaches the last order interceptor and the resource permissions corresponding to the current order interceptor are less than the current required resource permissions, jump out of the outer process interceptor chain of responsibility and return the result of permission authentication failure.
[0021] In a third aspect, an embodiment of the present application provides an electronic device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor can implement the method described in any embodiment of the first aspect when executing the program.
[0022] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the method described in any embodiment of the first aspect can be implemented.
[0023] In a fifth aspect, an embodiment of the present application provides a computer program product, wherein the computer program product includes a computer program, wherein when the computer program is executed by a processor, the method described in any embodiment of the first aspect can be implemented. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0025] Figure 1 A flowchart of a cross-order multi-level authority authentication method provided in an embodiment of the present application; Figure 2 The overall flow chart of the cross-order multi-level permission authentication solution provided in the embodiment of the present application; Figure 3 A schematic diagram of the structure of a cross-order multi-level authority authentication device provided in an embodiment of the present application; Figure 4 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0026] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0027] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0028] It should be noted that with the development of Internet technology, the cloud service subscription model has become increasingly popular. Usually, cloud service permissions are presented in the form of virtual orders. In the permission authentication scenario of cloud service subscriptions, a user may have multiple orders for the same type of cloud service. Therefore, in the process of requesting cloud service resources at the same time, the permissions granted by different orders can be accumulated and used. For example, when the existing orders of the user are not sufficient to deduct the service resources that the user wants to obtain, the user can purchase another order and merge it with the existing orders to obtain service permissions.
[0029] It can be understood that for single resource consumption, in a set of order permissions, if it is determined that a single order meets the resource consumption, there is no need to consume across orders. When it does not meet the requirement, then jump to the next order for judgment and resource consumption. For batch resource consumption, it is necessary to specify whether partial authentication consumption (partial authentication success) is allowed. For example, the requested resource quantity is 100, and the user currently has two orders, with the resource permission quantities of the two orders being 50 and 30 respectively, which are not sufficient to deduct the requested resource quantity. If partial authentication consumption is allowed, the system can return a resource quantity of 80 for this request. If partial authentication consumption is not allowed, the request authentication fails and no resource quantity is returned.
[0030] In addition, in most scenarios of cloud service subscriptions, there are different permission authentication dimensions, such as the total amount that can be used, the amount that can be used per month, the amount that can be used per day, the amount that can be used per hour, etc. That is, the authentication consumption of permissions in the same order is also hierarchical.
[0031] Currently, for the scenario of cross-order permission authentication, the existing solutions usually lock the order permissions by locking, and then check one by one whether the order permissions meet the resource requests. If they meet the requirements, the order permissions are deducted. If they do not meet the requirements, the lock is released and authentication failure is returned. However, in the high-concurrency request scenario of cloud service subscriptions, the locking solution will cause a large number of requests to be blocked, affecting the response performance of the system. Especially in the mode of cross-order and multi-dimensional permission authentication, more resources are locked, and the decline in system response performance is more obvious.
[0032] In view of the problems existing in the above-mentioned prior art, the embodiments of the present application propose the following improvements: 1. Design an authentication method of responsibility chain within responsibility chain, define an order adapter interceptor as one of the interceptors of the outer responsibility chain, pull the order set of the current resource request in the order adapter interceptor and build a corresponding inner order-level interceptor to form an order interceptor responsibility chain; further, define a hierarchical inspection interceptor (sub-authentication interceptor) in each order-level interceptor to form an authority-level responsibility chain (sub-authentication interceptor chain). In this way, the authority authentication process is abstracted and streamlined, and the scalability is stronger; 2. Adopt an unlocked authentication method and ensure the ultimate consistency of the authority. During the authentication process, the chain of responsibility is designed, and a hierarchical rollback is performed when the interceptor authentication fails or partially passes. The rollback operation is mainly divided into three levels: authority level (sub-authentication interceptor responsibility chain), order level (order interceptor responsibility chain) and outer responsibility chain level (outer process interceptor responsibility chain). The rollback solutions at each level do not interfere with each other, and the permission rollback at the fine-grained level does not affect the scheduling of the outer responsibility chain, thereby ensuring the abstract internal coupling of the system and further improving the system's responsiveness.
[0033] like Figure 1 As shown, the embodiment of the present application provides a cross-order multi-level authority authentication method, which may include the following steps: S1. Build the outer process interceptor responsibility chain of the current resource request; wherein the outer process interceptor responsibility chain includes the order adapter interceptor.
[0034] It should be noted that when a user wants to obtain a resource or service of a cloud service, a resource acquisition request (i.e., a current resource request) can be initiated. The method of the embodiment of the present application can be executed by a cloud server. When the cloud server responds to the user's current resource request, it builds an outer process interceptor responsibility chain for the current resource request. The outer process interceptor responsibility chain may include one or more authentication interceptors and at least one order adapter interceptor.
[0035] S2. Determine the initial resource requirement corresponding to the current resource request.
[0036] It should be noted that cloud service is an Internet-based service model that provides users with computing resources, storage space, applications, etc. through remote servers. Users can use these services on demand without having to install or maintain hardware and software locally. When responding to the current resource request, the cloud server can obtain the initial resource demand that the user currently wants to request, for example, the user wants to obtain 50G of storage space, or request to obtain 100 times the number of times a certain tool is used.
[0037] S3. Use the order adapter interceptor to pull the order set corresponding to the current resource request, and build an order interceptor responsibility chain corresponding to the order set; wherein the order set includes at least one order with corresponding resource authority, and the order interceptor responsibility chain includes at least one order interceptor corresponding to the order set.
[0038] In the outermost responsibility chain (outer process interceptor responsibility chain), the order adapter interceptor is mainly used to pull the order set corresponding to the current resource request, and build the corresponding order interceptor responsibility chain based on the order set. After pulling the order set, the permissions of each order can be normalized according to the resource type of the current request.
[0039] Exemplarily, the user ID of the current user can be obtained based on the current resource request, and then one or more orders corresponding to the user ID can be pulled from the pre-stored subscription order database (other authentication interceptors can be used before the order adapter interceptor to filter user requests without subscription permissions or without orders), forming a corresponding order set, in which each order has a certain amount of resource permissions, and the specific amount of resource permissions is mainly determined by the type of package purchased by the user and the usage.
[0040] It should be noted that the order interceptor responsibility chain includes one or more order interceptors. Each order interceptor corresponds one-to-one to each order in the order collection. Therefore, each order interceptor is granted a resource authority consistent with the corresponding order. The authority authentication process of multiple order interceptors is carried out in sequence, and the order of order consumption can be customized by the user.
[0041] S4. According to the responsibility chain order of the order interceptor responsibility chain, the resource authority of each order interceptor is deducted based on the current resource demand until the current resource demand is zero, or until the authentication process reaches the last order interceptor; wherein, the current resource demand is the remaining resource demand after each authority deduction from the initial resource demand.
[0042] The initial resource demand enters the authentication process of the order interceptor responsibility chain. In the first order interceptor, the current resource demand is the initial resource demand. Each time the initial resource demand passes through an order interceptor, the corresponding authenticated resource demand will be deducted, and the remaining resource demand will be used as the current resource demand of the next order interceptor.
[0043] It should be noted that when the resource authority corresponding to an order interceptor is not enough to deduct the current resource demand, the current resource demand will be reduced according to the resource authority corresponding to the order interceptor, and the remaining resource demand will enter the next order interceptor, and the above authority deduction process will be repeated until the current resource demand is reduced to zero. Otherwise, the authentication process will flow through each order interceptor in turn and finally reach the last order interceptor in the order interceptor responsibility chain.
[0044] It can be understood that there are mainly two types of requests for the authentication process of the order interceptor responsibility chain: 1. After the authentication process passes through one or more order interceptors, if the resource requirements requested by the user are all met, the authentication is successful; 2. After the authentication process passes through one or more order interceptors, if the resource requirements requested by the user are not met, the authentication process enters the last order interceptor.
[0045] S5. When the current resource demand is zero, jump out of the outer process interceptor responsibility chain and return the result of successful resource request.
[0046] It should be noted that when an order interceptor makes deductions based on its own resource permissions and reduces the current resource demand to zero, it means that the user's order permissions have covered the initial resource demand of the current request, and the request is deemed to be authenticated successfully. At this time, the responsibility chain process is reversed from the current order interceptor until the outer process interceptor responsibility chain is jumped out, and the corresponding data service is returned to the user based on the deducted resource permissions (returning the result of a successful resource request). At the same time, the resource permissions of the user's order set are deducted based on the deducted resource permissions. Orders whose resource permissions have been deducted to zero can be deleted.
[0047] For example, the initial resource requirement currently requested by the user is 10. The user has two orders with resource permissions of 20 and 15 respectively. The two order interceptors constructed are Order Interceptor 1 (resource permission is 20) and Order Interceptor 2 (resource permission is 15). After the authentication process starts, the initial resource requirement enters Order Interceptor 1. The resource permission of Order Interceptor 1 changes from 20 to 10 after deducting the initial resource requirement. The initial resource requirement is reduced to zero after being consumed by Order Interceptor 1. At this time, the authentication is successful, and the responsibility chain is reversed and the data service with a resource amount of 10 is returned to the user.
[0048] S6. When the authentication process reaches the last order interceptor and the resource permissions corresponding to the current order interceptor are less than the current required resource permissions, the deducted resource permissions are rolled back in reverse order according to the responsibility chain, jumping out of the outer process interceptor responsibility chain and returning the permission authentication failure result.
[0049] It should be noted that if the current resource demand has not been reduced to zero after passing through each order interceptor in turn, the authentication process will eventually reach the last order interceptor in the order interceptor responsibility chain. If the resource authority of the order interceptor is greater than or equal to the current resource demand, the user's resource acquisition request can be satisfied. Otherwise, if the resource authority corresponding to the order interceptor is less than the current resource demand, the resource authority accumulated from all the user's orders is not enough to cover the resources requested by the user this time, and the authentication is deemed to have failed. At this time, it is necessary to roll back the resource authorities that have been deducted by each order interceptor in reverse order according to the responsibility chain (order interceptor responsibility chain).
[0050] Based on this, the embodiment of the present application constructs a multi-level authentication responsibility chain for resource requests, adopts an authentication process of first deducting permissions and rolling back step by step, avoids request blocking caused by the locking mechanism, and effectively improves the system response performance in high-concurrency request scenarios.
[0051] In some possible embodiments, step S6, when the authentication process reaches the last order interceptor and the resource authority amount corresponding to the current order interceptor is less than the current required resource amount, the deducted resource authority is rolled back in reverse order according to the responsibility chain, the outer process interceptor responsibility chain is jumped out and the authority authentication failure result is returned, which may include: S601: When the authentication process reaches the last order interceptor and the resource authority amount corresponding to the current order interceptor is less than the current required resource amount, determine whether the current authentication scenario is a scenario that allows partial success; S602: If yes, jump out of the outer process interceptor responsibility chain and return a partial success result of the resource request based on the deducted resource authority; S603: If not, roll back the deducted resource permissions in reverse order according to the responsibility chain, jump out of the outer process interceptor responsibility chain and return the permission authentication failure result.
[0052] It should be noted that in batch resource consumption scenarios, you can configure whether to allow partial authentication success. When the user's order resource permissions are not sufficient to cover the resources requested this time, for scenarios where partial success is allowed, the corresponding data or services are returned based on the user's order's existing resource permissions. For scenarios where partial success is not allowed, the authentication is judged to have failed, no data or services are returned, and the order permissions deducted in advance are rolled back.
[0053] Based on this, by performing permission authentication based on whether partially successful authentication scenarios are allowed, partial authentication success results are returned or the deducted resources are rolled back when authentication fails, thereby further improving the flexibility and scalability of cross-order permission authentication.
[0054] In some possible embodiments, each order has resource authority quantities of multiple authority authentication dimensions, each order interceptor includes a sub-authentication interceptor responsibility chain, and each sub-authentication interceptor responsibility chain includes multiple sub-authentication interceptors corresponding to the multiple authority authentication dimensions; Step S4, in accordance with the responsibility chain order of the order interceptor responsibility chain, deducting the resource authority of each order interceptor based on the current resource demand, until the current resource demand is zero, or until the authentication process reaches the last order interceptor, may include: S401. In the authentication process of each order interceptor, the resource authority of each sub-authentication interceptor is deducted based on the current resource demand in the order of the responsibility chain of the sub-authentication interceptor, until the authentication process reaches a sub-authentication interceptor whose resource authority is insufficient to deduct the current resource demand, or until the authentication process reaches the last sub-authentication interceptor.
[0055] It should be noted that the authentication consumption for an order can be divided into different multiple permission authentication dimensions (two or more dimensions), such as the total amount that can be used, the amount that can be used per month, and the amount that can be used per day. For example, assuming that the resource permissions of a user's order are 100 (the total amount that can be used), 50 (the amount that can be used per month), and 20 (the amount that can be used per day), if the user initiates a resource acquisition request with a resource amount of 15 (less than or equal to 20), the order meets the consumption. If the user initiates a resource acquisition request with a resource amount of 30 (greater than 20), the order does not meet the consumption and needs to merge the consumption across orders.
[0056] In each order interceptor, there is a sub-authentication interceptor responsibility chain. Each sub-authentication interceptor responsibility chain includes multiple sub-authentication interceptors corresponding to multiple authority authentication dimensions. Exemplarily, the multiple authority authentication dimensions include total dimension, month dimension and day dimension. Then, each order interceptor includes a sub-authentication interceptor responsibility chain of "sub-authentication interceptor 1 (corresponding to total dimension) - sub-authentication interceptor 2 (corresponding to month dimension) - sub-authentication interceptor 3 (corresponding to day dimension)".
[0057] It should be noted that in the authentication process of a single order interceptor, permissions are deducted in the sub-authentication interceptors of each dimension in turn according to the current remaining resource demand, until the sub-authentication interceptor of the last dimension (such as the day dimension). If all dimensions of the current order interceptor meet the resource demand requested by the user, the permissions are deducted in turn and the data or service is returned, and the responsibility chain of each level is reversed; if the resource permissions of a certain level in the current order interceptor are not enough to deduct the current resource demand, the authentication process needs to enter the next order interceptor after completing the last sub-authentication interceptor of the current order interceptor.
[0058] S402. When the authentication process reaches a sub-authentication interceptor where the amount of resource permissions is insufficient to deduct the currently required amount of resources, based on the amount of resources actually deducted by the current sub-authentication interceptor, the deducted resource permissions of the previous sub-authentication interceptor are rolled back in reverse order of the chain of responsibility, and the amount of resources actually deducted by the current sub-authentication interceptor is used as the currently required amount of resources for the next sub-authentication interceptor to start the authentication process for the next sub-authentication interceptor.
[0059] It should be noted that in each order interceptor, even if the resource authority of a certain sub-authentication interceptor is not enough to deduct the current required resource amount, it will eventually go to the last sub-authentication interceptor of the current order interceptor. Among them, in the previous sub-authentication interceptor, if the resource authority is not enough to deduct the current required resource amount, the current required resource amount will be reduced according to the resource authority of the sub-authentication interceptor. The remaining required resource amount after settlement is the insufficient resource amount to be deducted, and the previous other sub-authentication interceptors are rolled back in reverse based on this resource amount. At the same time, the resource amount deducted by the current sub-authentication interceptor is used as the current required resource amount of the next sub-authentication interceptor. And so on, until the last sub-authentication interceptor of the current order interceptor is reached.
[0060] S403. When the authentication process reaches the last sub-authentication interceptor of the current order interceptor, and the resource permission amount corresponding to the current sub-authentication interceptor is less than the current required resource amount, based on the actual amount of resources deducted by the current sub-authentication interceptor, the deducted resource permissions of the previous sub-authentication interceptor are rolled back in reverse order according to the chain of responsibility, and the remaining required resource amount after the settlement of the current sub-authentication interceptor is used as the current required resource amount of the next order interceptor to start the authentication process of the next order interceptor.
[0061] It should be noted that when the authentication process reaches the last sub-authentication interceptor of the current order interceptor (not the last order interceptor), there will be two situations: 1. The current resource demand has been reduced to zero, which means that the orders so far have met the resource authority consumption and the authentication is returned successfully; 2. The resource authority corresponding to the current sub-authentication interceptor is less than the current required resource amount, which means that the orders so far are still insufficient to deduct the authority consumption, and it is necessary to enter the next order to obtain authority.
[0062] For the second situation mentioned above, the previous sub-authentication interceptors in this order interceptor are rolled back according to the actual amount of resources deducted by the current sub-authentication interceptor, and the remaining required resources after settlement of the current sub-authentication interceptor (the last sub-authentication interceptor of the current order interceptor) are used as the current required resources of the next order interceptor to start the authentication process of the next order interceptor.
[0063] It should be noted that in any sub-authentication interceptor, the resource authority may be insufficient to deduct the current resource demand. In this case, the part of the resources that the current sub-authentication interceptor cannot deduct needs to roll back the previously deducted resource authorities in sequence. For example, when the resource authority in the monthly dimension (such as 50) is less than the current resource demand (such as 60), the insufficient resource authority is 10, and the resource authority in the previous dimension (such as the total dimension) needs to be rolled back (the rolled back amount is 10); after passing through the sub-authentication interceptor in the monthly dimension, the current resource demand becomes 50, and enters the sub-authentication interceptor in the daily dimension (assuming the resource authority is 20). At this time, the insufficient resource amount is 50-20=30, and it is necessary to reversely roll back the resource authority in the monthly dimension and the resource authority in the total dimension by 30 respectively. Since the user's initial resource requirement is 60, and the current order interceptor finally only completes 20 resource permissions, there is still 60-20=40 resource requirements, and enters the authentication process of the next order interceptor, and so on, until the current resource requirement is reduced to zero, or reaches the last order interceptor.
[0064] S404. When the authentication process reaches the last sub-authentication interceptor of the last order interceptor, and the resource authority corresponding to the current sub-authentication interceptor is less than the current required resource authority, the deducted resource authority is rolled back in reverse order according to the responsibility chain, jumping out of the outer process interceptor responsibility chain and returning the result of authority authentication failure.
[0065] It should be noted that when the authentication process reaches the sub-authentication interceptor of the last order interceptor, and the resource permission amount corresponding to the current sub-authentication interceptor is still less than the current required resource amount, it means that the accumulated resource permissions of all the user's orders are not enough to cover the resources currently requested, and the authentication failure is returned. At the same time, all resources that have been deducted in this authentication process are rolled back in reverse.
[0066] Based on this, by constructing sub-authentication interceptor responsibility chains corresponding to multiple permission authentication dimensions inside the order interceptor, the authentication requirements of multi-dimensional permissions across orders are met, the scalability of the authentication process is further improved, and the response performance of multi-dimensional permission authentication in high-concurrency request scenarios is improved.
[0067] In some possible embodiments, step S404, when the authentication process reaches the last sub-authentication interceptor of the last order interceptor, and the resource authority amount corresponding to the current sub-authentication interceptor is less than the current required resource amount, the deducted resource authority is rolled back in reverse order according to the responsibility chain, the outer process interceptor responsibility chain is jumped out and the authority authentication failure result is returned, which may include: S4041. When the authentication process reaches the last sub-authentication interceptor of the last order interceptor, and the resource authority amount corresponding to the current sub-authentication interceptor is less than the current required resource amount, determine whether the current authentication scenario is a scenario that allows partial success; S4042, if yes, then jump out of the outer process interceptor responsibility chain, and based on the remaining required resource amount after the current sub-authentication interceptor is settled, roll back the deducted resource permissions of other sub-authentication interceptors in reverse order according to the responsibility chain order, and return a partial success result of the resource request based on the deducted resource permissions; S4043. If not, roll back the deducted resource permissions in reverse order according to the responsibility chain, jump out of the outer process interceptor responsibility chain and return the permission authentication failure result.
[0068] It should be noted that when the authentication process reaches the last sub-authentication interceptor of the last order interceptor, and the resource authority corresponding to the current sub-authentication interceptor is less than the current required resource authority, it can be determined whether the current authentication scenario is a scenario that allows partial success. If partial authentication is allowed, a partial success result of the resource request is returned based on the resource authority that is finally deducted successfully in all order interceptors. The remaining required resource authority after settlement of the current sub-authentication interceptor (the last sub-authentication interceptor of the last order interceptor) is the resource authority that has not been deducted successfully so far. Based on the resource authority that has not been deducted successfully, other sub-authentication interceptors before the current order interceptor are rolled back. It can be understood that, since in other order interceptors before the current order interceptor, when the resource authority of a certain sub-authentication interceptor is not enough for deduction, the relevant rollback operation has been performed, so in this process (the authentication process of the last sub-authentication interceptor of the last order interceptor), there is no need to perform resource rollback operations on other order interceptors.
[0069] Based on this, by providing authentication scenarios that allow partial success and rolling back the undeducted resource permissions layer by layer when partial authentication is successful, the flexibility and scalability of cross-order multi-dimensional permission authentication are further improved.
[0070] See also Figure 2The embodiment of the present application provides a cross-order multi-level (and multi-dimensional) permission authentication system based on the concept of optimistic locking. It uses the responsibility chain and adapter mode to dynamically encapsulate multiple orders into an order interceptor chain, and each order interceptor has multiple sub-authentication interceptors. By adopting a lock-free method, the problem of excessive use of permissions is avoided, and a reverse hierarchical rollback solution is provided when step-by-step authentication and authentication are not completely successful. The ultimate consistency of permissions is guaranteed through the seamless rollback of the sub-chain and the rule verification rollback of the outer layer. The authentication process is abstracted into a cascading responsibility chain black box. The responsibility interceptors at each level have a single responsibility and do not interfere with each other, realizing cross-order multi-level and multi-dimensional permission authentication and consumption; at the same time, due to the single responsibility of each interceptor, the scalability of the authentication system is effectively improved, and the system response performance is maximized in high-concurrency request scenarios.
[0071] The embodiment of the present application constructs a three-level interceptor responsibility chain to implement a cross-order multi-dimensional authentication process, including the outermost outer process interceptor responsibility chain, the middle order interceptor responsibility chain, and the inner sub-authentication interceptor responsibility chain.
[0072] It should be noted that when the authentication process enters the internal sub-authentication interceptor, in order to avoid the problem of overuse caused by concurrency, the auto-increment operation of redis can be used to increase the current dimension usage by 1 and then get the usage after the auto-increment (the deducted resource demand) and compare it with the resource authority of the dimension of the current order. If the verification passes, it will enter the next sub-authentication interceptor (or the sub-authentication interceptor responsibility chain of the next order interceptor) for verification. If the verification fails (insufficient resource authority), the excess usage (demand minus authority) is calculated, and a partial overlimit exception is thrown. After the main verification process of the sub-authentication interceptor responsibility chain captures the exception, it starts from the current sub-authentication interceptor and reverses the cycle to enter the rollback process. Resources that do not exceed the authority (actual deducted resource amount) enter the next sub-authentication interceptor for verification of the next dimension.
[0073] For example, suppose in the daily sub-authentication interceptor, the order allows the user to access N resources (resource authority quantity) every day. The user requests N1 resources (resource demand quantity) this time. The amount used that day is recorded in redis. After entering the daily sub-authentication interceptor, the amount used today is first incremented in redis, and the value after increment is assumed to be N2. Compare the values of N2 and N. If N>=N2, it means that the daily level interceptor verification has passed. If N1+N>N2>N, it means that N1+N-N2 resources have been successfully authenticated and N2-N resources have failed to be authenticated.
[0074] It should be noted that the resource demand to be authenticated is the user's initial resource demand when entering the first sub-authentication interceptor. After passing each interceptor, it may be that the resource authority of this dimension is less than the resource demand, resulting in only part of the resource demand passing the verification and entering the next sub-authentication interceptor. The resource demand that fails the verification enters the reverse rollback process. After all sub-authentication interceptors have been verified, the resource demand that finally passes the verification is the resource amount that can be consumed by the current resource request.
[0075] After an order interceptor's authentication check, if the authenticated resource quantity is equal to the current resource demand (the resource demand is reduced to zero), the authentication is passed and there is no need to enter the next order interceptor. If the authenticated resource quantity is less than the current resource demand (the resource demand has not been reduced to zero), the next order interceptor is entered and the chain authentication and interception process of the sub-authentication interceptor is repeated in the next order interceptor.
[0076] Each time an order interceptor is passed, the amount of resources currently required (the current resource demand) is checked. If the current resource demand is 0, it means that the order interceptors that have been verified have met the user's total resource demand, and the authentication is successful; if the amount of resources required after settlement through an order interceptor is not 0, enter the next order interceptor. If the amount of resources required after passing through all order interceptors is still not 0, it means that the resource demand requested by the user this time exceeds the accumulated resource authority of all orders, then the authentication failure is returned, or scheduling is performed based on whether the current scenario allows partial success.
[0077] If a partially successful authentication scenario is allowed, that is, the actual deducted resource permissions are inconsistent with the resource requirements requested by the user, the corresponding business data will be returned based on the actual deducted resource quantities, and the resource permissions at each level will be rolled back in turn based on the unsuccessful deducted resource requirements; If the authentication scenario does not allow partial success, that is, sufficient permissions are required to consider the authentication successful, no resource business data will be returned, and the outer layer rollback process will be reversed to roll back according to the permission deduction details saved in the global context.
[0078] It should be noted that the rollback process is the opposite of the authentication process. It starts from the last order interceptor, takes out the permissions deducted from the current order from the global context, and starts rolling back from the last sub-chain interceptor. When all sub-chains are rolled back, the current order interceptor is rolled back, and the next order interceptor is entered in reverse. It should be noted that in order to avoid the impact of locking on the system response performance, the rollback process can also use the auto-increment function of redis. The auto-increment value is negative, which is equivalent to auto-decrement.
[0079] Based on this, the process of cross-order multi-level permission authentication and deduction is encapsulated using a three-layer interceptor responsibility chain. Each layer of the interceptor chain has its own responsibilities. The outer process interceptor responsibility chain promotes the overall process control. The order-level interceptor is responsible for sub-chain process control and the corresponding rollback process control, and the sub-chain interceptor is responsible for permission verification in different dimensions.
[0080] It should be noted that the process of the order-level interceptor includes the forward authentication process and the reverse rollback process. The authentication process is from the first sub-authentication interceptor to the last sub-authentication interceptor in sequence, and the rollback process is from the sub-authentication interceptor that needs to be rolled back to the first sub-authentication interceptor in reverse. The authentication of each sub-authentication interceptor may trigger the rollback process. When the Nth sub-authentication interceptor needs to be rolled back, the sub-authentication interceptors to be rolled back are N, N-1,...1 in sequence. When the N+1th sub-authentication interceptor needs to be rolled back, the sub-authentication interceptors to be rolled back are N+1, N, N-1,...1 in sequence.
[0081] Based on this, by deducting in advance and rolling back layer by layer, and relying on the security capability of redis's self-increasing competitive resource threads, the locking behavior of multi-level permission authentication across orders is avoided, and the mechanism of rolling back layer by layer is used to ensure that permissions are not overused. While ensuring the ultimate consistency of order permissions, the response performance of the authentication system in high-concurrency request scenarios is greatly improved. At the same time, the responsibilities of each level of the responsibility chain are single, and the maintainability and scalability of the system are enhanced through the abstracted interceptor chain with similar functions.
[0082] In some possible embodiments, the outer process interceptor responsibility chain also includes a cache interceptor; Before S2, it can also include: S101, based on the cache interceptor, obtain the historical authentication record of the current resource request, and determine whether the current resource request meets the preset consumption-free authentication condition according to the historical authentication record; S102: When it is determined that the current resource request meets the consumption-free authentication condition, jump out of the outer process interceptor responsibility chain and return a successful result of the resource request.
[0083] It should be noted that, considering that in actual scenarios, certain types of resources only need to be authenticated once within a certain period of time, for example, a resource that needs to be unlocked before viewing only needs to be unlocked once within the same day, and can be viewed an unlimited number of times on the same day without the need for authentication and consuming permissions each time.
[0084] Therefore, a cache interceptor can be added to the outer process interceptor responsibility chain. Before the order adapter interceptor starts working (or before step S2), the cache interceptor can be used as the first interceptor in the outer process interceptor responsibility chain. Based on the cache interceptor, the historical authentication record corresponding to the current resource request is obtained. If the resource type allows consumption-free authentication within a certain period of time, and the authentication time and authority information of the historical authentication record are judged to meet the consumption-free authentication conditions, then the current resource request authentication is directly judged to be successful, and the outer responsibility chain is jumped out and the corresponding data or service is returned without entering the order pulling and authority authentication process from S2 to S6. Otherwise, if the cache interceptor determines that the current resource request does not meet the consumption-free authentication conditions, the step process of steps S2 to S6 is executed normally.
[0085] Based on this, by adding a cache interceptor in the outer responsibility chain, the specific multi-order merging authentication process is omitted when it is judged that the consumption-free authentication conditions are met, thereby further improving the response efficiency of resource request authentication.
[0086] In some possible embodiments, step S3, using the order adapter interceptor to pull the order set corresponding to the current resource request and constructing an order interceptor responsibility chain corresponding to the order set, may include: S301, using the order adapter interceptor to pull the order set corresponding to the current resource request, and obtain the order authority consumption policy corresponding to the current resource request; wherein the order authority consumption policy is used to characterize the consumption priority of each order in the order set; S302: Construct an order interceptor responsibility chain corresponding to the order set based on the order authority consumption strategy.
[0087] It should be noted that in the embodiment of the present application, the core of the outer process interceptor responsibility chain is the order adapter interceptor. The order adapter interceptor is responsible for obtaining the user's order set and the permission set of each order and normalizing the permission information data, and dynamically creating an order interceptor responsibility chain based on the order set.
[0088] When the user initiates the current resource request, the user can configure the permission consumption priority for multiple existing orders according to the needs. That is, the user wants to deduct the resource permission of the order first. When the resource permission of the order is insufficient, the user will obtain the next order and deduct the permission, and so on.
[0089] When building the order interceptor responsibility chain corresponding to the order collection, it is built in order according to the order permission consumption strategy configured by the user.
[0090] Based on this, by determining the order of authorization authentication for each order according to the order authorization consumption strategy, the user's needs for customized configuration of order consumption priority are met, and the flexibility of multi-order authorization authentication is further improved.
[0091] It should be noted that the embodiment of the present application integrates multi-order and multi-dimensional permissions, abstracts the authentication processes at all levels into permission interceptors based on the principle of high cohesion and low coupling, and allows users to customize the use priority of orders through the construction of a three-layer responsibility chain and an internal rollback process. At the same time, multiple orders can be merged to achieve cumulative use of permissions, thereby improving the response performance of the system in high-concurrency request scenarios and ensuring the ultimate consistency of permissions. Since the overall process is highly abstract, whether it is the extension of the outer process interceptor responsibility chain or the inner sub-authentication interceptor, it only needs to follow the corresponding interface specifications, that is, the authentication verification process and rollback process can be customized according to needs, thereby quickly and conveniently enriching the verification rules, and it is also conducive to expanding the sales scenario of cloud service subscriptions.
[0092] In some possible embodiments, the outer process interceptor responsibility chain also includes at least one authentication interceptor connected in series with the order adapter interceptor, and the authentication order of the at least one authentication interceptor is before the order adapter interceptor.
[0093] It should be noted that in the outer process interceptor responsibility chain, in addition to the cache interceptor and order adapter interceptor, other authentication interceptors can also be defined and configured according to needs, such as resource cleanup interceptors, data type filtering interceptors, user IP interceptors, etc. The specific interception function can be set according to needs.
[0094] At the same time, the authentication order of different authentication interceptors can also be defined. Each authentication interceptor can be in series, together with the cache interceptor and / or the order adapter interceptor to form an outer process interceptor responsibility chain. It should be noted that, unlike the cache interceptor, other authentication interceptors are usually configured to enter the next authentication interceptor after the previous authentication interceptor passes the authentication, until entering the order adapter interceptor, or, when an authentication interceptor fails to authenticate, it jumps out of the outer process interceptor responsibility chain and returns authentication failure.
[0095] Based on this, by adding at least one authentication interceptor before the order adapter interceptor of the outer responsibility chain, the response efficiency in complex authentication process scenarios is further improved.
[0096] Please refer to Figure 3 , Figure 3 The following is a block diagram showing the composition of a cross-order multi-level authorization authentication device provided by some embodiments of the present application. Figure 1Corresponding to the method embodiment, it is able to execute each step involved in the above method embodiment. The specific functions of the cross-order multi-level authority authentication device can be found in the description above. To avoid repetition, the detailed description is appropriately omitted here.
[0097] Figure 3 The cross-order multi-level authority authentication device includes at least one software function module that can be stored in a memory in the form of software or firmware or solidified in the cross-order multi-level authority authentication device, and the cross-order multi-level authority authentication device includes: The outer chain building module 310 is used to build the outer process interceptor responsibility chain of the current resource request; wherein the outer process interceptor responsibility chain includes an order adapter interceptor; The demand determination module 320 is used to determine the initial resource demand corresponding to the current resource request; An order chain building module, used to use the order adapter interceptor to pull the order set corresponding to the current resource request, and build an order interceptor responsibility chain corresponding to the order set; wherein the order set includes at least one order with a corresponding resource authority, and the order interceptor responsibility chain includes at least one order interceptor corresponding to the order set; The authority authentication module 330 is used to deduct the resource authority of each order interceptor based on the current resource demand in the responsibility chain order of the order interceptor responsibility chain until the current resource demand is zero, or until the authentication process reaches the last order interceptor; wherein the current resource demand is the remaining resource demand after each authority deduction from the initial resource demand; The success result return module 340 is used to jump out of the outer process interceptor responsibility chain and return the resource request success result when the current resource demand is zero; The resource rollback module 350 is used to roll back the deducted resource permissions in reverse order of the chain of responsibility when the authentication process reaches the last order interceptor and the resource permissions corresponding to the current order interceptor are less than the current required resource permissions, jump out of the outer process interceptor chain of responsibility and return the result of permission authentication failure.
[0098] It can be understood that the above-mentioned device item embodiment corresponds to the method item embodiment of the present invention. The cross-order multi-level authority authentication device provided by the embodiment of the present invention can implement the cross-order multi-level authority authentication method provided by any method item embodiment of the present invention.
[0099] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method, and will not be described in detail here.
[0100] like Figure 4As shown, some embodiments of the present application provide an electronic device 400, which includes: a memory 410, a processor 420, and a computer program stored in the memory 410 and executable on the processor 420, wherein the processor 420 can implement a method of any embodiment of the cross-order multi-level authority authentication method as described above when reading the program from the memory 410 through a bus 430 and executing the program.
[0101] Processor 420 can process digital signals and can include various computing structures, such as complex instruction set computer structure, reduced instruction set computer structure, or a structure that implements a combination of multiple instruction sets. In some examples, processor 420 can be a microprocessor.
[0102] The memory 410 may be used to store instructions executed by the processor 420 or data related to the execution of instructions. These instructions and / or data may include codes for implementing some or all functions of one or more modules described in the embodiments of the present application. The processor 420 of the disclosed embodiment may be used to execute instructions in the memory 410 to implement the method shown above. The memory 410 includes a dynamic random access memory, a static random access memory, a flash memory, an optical memory, or other memory known to those skilled in the art.
[0103] Some embodiments of the present application further provide a computer-readable storage medium having a computer program stored thereon. The computer program is executed by a processor to execute the method described in the method embodiment.
[0104] Some embodiments of the present application further provide a computer program product, which, when executed on a computer, enables the computer to execute the method described in the method embodiment.
[0105] It should be noted that each embodiment in this specification is described in a progressive manner, and each embodiment focuses on the differences from other embodiments, and the same or similar parts between the embodiments can be referred to each other. For the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0106] In several embodiments provided by the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.
[0107] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.
[0108] If the function is implemented in the form of a software function module and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to perform all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, Read-Only Memory), random access memory (RAM, Random Access Memory), disk or optical disk, and other media that can store program codes.
[0109] The above description is only an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.
[0110] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art who is familiar with the present technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0111] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
Claims
1. A cross-order multi-level authority authentication method, characterized in that: include: Constructing an outer process interceptor responsibility chain for the current resource request; wherein the outer process interceptor responsibility chain includes an order adapter interceptor; determining an initial resource requirement corresponding to the current resource request; Utilizing the order adapter interceptor to pull an order set corresponding to the current resource request, and constructing an order interceptor responsibility chain corresponding to the order set; wherein the order set includes at least one order with a corresponding resource authority, and the order interceptor responsibility chain includes at least one order interceptor corresponding to the order set; According to the responsibility chain order of the order interceptor responsibility chain, the resource authority of each order interceptor is deducted based on the current resource demand until the current resource demand is zero, or until the authentication process reaches the last order interceptor; wherein the current resource demand is the remaining resource demand after each authority deduction from the initial resource demand; When the current resource demand is zero, jump out of the outer process interceptor responsibility chain and return a successful resource request result; When the authentication process reaches the last order interceptor and the resource authority corresponding to the current order interceptor is less than the current required resource authority, the deducted resource authority is rolled back in reverse order according to the responsibility chain, jumping out of the outer process interceptor responsibility chain and returning the result of permission authentication failure.
2. The cross-order multi-level authority authentication method according to claim 1 is characterized in that: When the authentication process reaches the last order interceptor and the resource authority amount corresponding to the current order interceptor is less than the current required resource amount, the deducted resource authority is rolled back in reverse order according to the responsibility chain, the outer process interceptor responsibility chain is jumped out and the authority authentication failure result is returned, including: When the authentication process reaches the last order interceptor and the resource authority corresponding to the current order interceptor is less than the current required resource amount, determine whether the current authentication scenario is a scenario that allows partial success; If yes, then jump out of the outer process interceptor responsibility chain and return a partial success result of the resource request based on the deducted resource authority; If not, the deducted resource permissions are rolled back in reverse order according to the chain of responsibility, the outer process interceptor chain of responsibility is jumped out and a permission authentication failure result is returned.
3. The cross-order multi-level authority authentication method according to claim 1 is characterized in that: Each order has resource authority quantities of multiple authority authentication dimensions, each of the order interceptors includes a sub-authentication interceptor responsibility chain, and each of the sub-authentication interceptor responsibility chain includes multiple sub-authentication interceptors corresponding to the multiple authority authentication dimensions; The resource authority of each order interceptor is deducted in sequence based on the current resource demand according to the responsibility chain order of the order interceptor responsibility chain until the current resource demand is zero, or until the authentication process reaches the last order interceptor, including: In the authentication process of each of the order interceptors, the resource authority amount of each of the sub-authentication interceptors is deducted based on the current resource demand amount in the order of the responsibility chain of the sub-authentication interceptor, until the authentication process reaches a sub-authentication interceptor whose resource authority amount is insufficient to deduct the current required resource amount, or until the authentication process reaches the last sub-authentication interceptor; When the authentication process reaches a sub-authentication interceptor whose resource permissions are insufficient to deduct the currently required resource permissions, based on the actual resource permissions deducted by the current sub-authentication interceptor, the deducted resource permissions of the previous sub-authentication interceptor are rolled back in reverse order of the responsibility chain, and the actual resource permissions deducted by the current sub-authentication interceptor are used as the current required resource permissions of the next sub-authentication interceptor to start the authentication process of the next sub-authentication interceptor; When the authentication process reaches the last sub-authentication interceptor of the current order interceptor, and the resource permission amount corresponding to the current sub-authentication interceptor is less than the current required resource amount, based on the actual resource amount deducted by the current sub-authentication interceptor, the deducted resource permissions of the previous sub-authentication interceptor are rolled back in reverse order according to the chain of responsibility, and the remaining required resource amount after the settlement of the current sub-authentication interceptor is used as the current required resource amount of the next order interceptor to start the authentication process of the next order interceptor; When the authentication process reaches the last sub-authentication interceptor of the last order interceptor, and the resource authority corresponding to the current sub-authentication interceptor is less than the current required resource authority, the deducted resource authority is rolled back in reverse order according to the chain of responsibility, jumping out of the outer process interceptor chain of responsibility and returning the result of permission authentication failure.
4. The cross-order multi-level authority authentication method according to claim 3 is characterized in that: When the authentication process reaches the last sub-authentication interceptor of the last order interceptor, and the resource authority amount corresponding to the current sub-authentication interceptor is less than the current required resource amount, the deducted resource authority is rolled back in reverse order according to the responsibility chain, the outer process interceptor responsibility chain is jumped out and the authority authentication failure result is returned, including: When the authentication process reaches the last sub-authentication interceptor of the last order interceptor, and the resource authority corresponding to the current sub-authentication interceptor is less than the current required resource amount, determine whether the current authentication scenario is a scenario that allows partial success; If so, then jump out of the outer process interceptor responsibility chain, and based on the remaining required resource amount after the current sub-authentication interceptor is settled, roll back the deducted resource permissions of other sub-authentication interceptors in reverse order according to the responsibility chain order, and return a partial success result of the resource request based on the deducted resource permissions; If not, the deducted resource permissions are rolled back in reverse order according to the chain of responsibility, the outer process interceptor chain of responsibility is jumped out and a permission authentication failure result is returned.
5. The cross-order multi-level authority authentication method according to claim 1 is characterized in that: The outer process interceptor responsibility chain also includes a cache interceptor; Before determining the initial resource requirement corresponding to the current resource request, the method further includes: Acquire the historical authentication record of the current resource request based on the cache interceptor, and determine whether the current resource request meets the preset consumption-free authentication condition according to the historical authentication record; When it is determined that the current resource request meets the consumption-free authentication condition, the outer process interceptor responsibility chain is jumped out and a successful resource request result is returned.
6. The cross-order multi-level authority authentication method according to claim 1 is characterized in that: The using the order adapter interceptor to pull the order set corresponding to the current resource request and constructing an order interceptor responsibility chain corresponding to the order set includes: Utilize the order adapter interceptor to pull the order set corresponding to the current resource request, and obtain the order authority consumption strategy corresponding to the current resource request; wherein the order authority consumption strategy is used to characterize the consumption priority of each order in the order set; An order interceptor responsibility chain corresponding to the order set is constructed based on the order authority consumption strategy.
7. The cross-order multi-level authority authentication method according to claim 1 is characterized in that: The outer process interceptor responsibility chain also includes at least one authentication interceptor connected in series with the order adapter interceptor, and the authentication order of the at least one authentication interceptor is arranged before the order adapter interceptor.
8. An electronic device, characterized in that: It includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the cross-order multi-level authority authentication method described in any one of claims 1-7 can be implemented.
9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the cross-order multi-level authority authentication method as described in any one of claims 1 to 7 is executed.
10. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the cross-order multi-level authority authentication method described in any one of claims 1-7 is implemented.
Citation Information
Patent Citations
Business approval processing method, device and system
CN108346028A
Service request processing method and device
CN113326153A
Control method and device based on function permission and data permission
CN117932576A
Injection of information technology management process into resource request flows
US20180241690A1