API service access method and device, equipment, storage medium and program product

By receiving and processing access requests with key information, authentication identifiers and signature codes in API service access, and generating and verifying signatures, the problem of difficulty in taking into account security and comprehensiveness in the prior art is solved, and high security and stability in the data transmission process is achieved.

CN120034337APending Publication Date: 2025-05-23CHONGQING ZUOSHIFU IND CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510191214.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-20
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

The existing API service access methods are difficult to take into account both security and comprehensiveness, and cannot effectively ensure the confidentiality and integrity of the data transmission process.

Method used

By receiving the access request from the user, processing the request to generate a character string to be signed, and a verification signature is generated based on the authentication identifier, key information and character string to be signed. Determine the corresponding authentication scheme based on the authentication identifier, perform signature verification, and ensure the security of data transmission.

Benefits of technology

Through the implementation of signature verification and authentication schemes, the security of API service access is improved, the risks faced by API services are reduced, and the stability and reliability of access are ensured.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120034337A_ABST
    Figure CN120034337A_ABST
Patent Text Reader

Abstract

The invention provides an API service access method and device, equipment, a storage medium and a program product. The method comprises the steps that an access request of a user side for an API service is received; the access request carries key information, an authentication identifier and a signature code; processing the access request to generate a corresponding character string to be signed; generating a corresponding verification signature according to the authentication identifier, the key information and the to-be-signed character string; determining a corresponding authentication scheme according to the authentication identifier; the authentication scheme is generated by comparing a corresponding verification signature with a signature code; or, comparing the corresponding verification signature with the key information; executing the corresponding authentication scheme, and generating a corresponding verification result; and determining that the verification result is passed, and providing an API service for the user side. By means of the method, identity verification and service response in API service access are achieved, safety and comprehensiveness are both considered, and access stability and reliability are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information network security technology, and in particular to an API service access method, device, equipment, storage medium and program product. Background Art

[0002] As a portal for data interaction, API gateways are responsible for the transmission of a large amount of sensitive information, covering functions such as control permissions, load balancing, and protocol conversion. With the development of the API economy, more and more companies are beginning to encapsulate their business capabilities into APIs and open them to the outside world. At the same time, in order to help companies improve the competitiveness of their business systems, when providing service access, API gateways not only need to combine actual external application scenarios and provide customized service responses based on the needs of different industries and customers, but must also be equipped with a variety of security management methods to ensure the confidentiality and integrity of data during transmission. However, existing service access methods are difficult to balance security and comprehensiveness. Summary of the invention

[0003] Based on this, it is necessary to provide an API service access method, device, equipment, storage medium and program product to address the above technical problems.

[0004] In a first aspect, the present application provides a method for secure access to an API service, the method comprising: receiving an access request from a user end for an API service; the access request carries key information, an authentication identifier, and a signature code; processing the access request to generate a corresponding string to be signed; generating a corresponding verification signature based on the authentication identifier, the key information, and the string to be signed; determining a corresponding authentication scheme based on the authentication identifier; the authentication scheme is generated by comparing the corresponding verification signature with the signature code; or by comparing the corresponding verification signature with the key information; executing the corresponding authentication scheme to generate a corresponding verification result; determining that the verification result is passed, and providing the API service to the user end.

[0005] In one embodiment, the access request also carries a user identifier; after the step of receiving the access request from the user end and before the step of generating a corresponding string to be signed based on the access request, it also includes: identifying the user identifier in the access request; and determining that the user identifier is in the permission whitelist of the API service.

[0006] In one embodiment, after the step of identifying the user identifier in the access request, it also includes: if the user identifier is in the permission blacklist of the API service, returning an error message to the user terminal; the error message is used to notify the user terminal that it is not authorized to access the API service.

[0007] In one embodiment, after determining that the verification result is passed, it also includes: adding the access request to a corresponding buffer queue based on the user identifier; counting the number of access requests in the buffer queue within a set time period; and when the number of access requests exceeds a preset threshold corresponding to the buffer queue, delaying the step of providing the API service to the user terminal.

[0008] In one embodiment, the access request also carries ciphertext data; the step of providing the API service to the user terminal includes: decrypting the ciphertext data in the access request according to the authentication identifier and the key information; and providing the API service to the user terminal according to the decrypted access request.

[0009] In one embodiment, when the access request carries a callback address, the step of providing the API service to the user terminal includes: parsing the access request based on a communication protocol to generate routing information; calling the API service according to the routing information to generate a response message; the response message is used to notify the user terminal that part of the API service has been completed; sending the response message to the user terminal and executing the remaining services of the API service; when all services of the API service are executed, feeding back the service results to the callback address.

[0010] In the second aspect, the present application also provides an API service access device, including: a receiving module, used to receive an access request from a user terminal for an API service; the access request carries key information, an authentication identifier and a signature code; a processing module, used to process the access request to generate a corresponding string to be signed; a verification module, used to generate a corresponding verification signature based on the authentication identifier, the key information and the string to be signed; based on the authentication identifier, a corresponding authentication scheme is determined; the authentication scheme is generated by comparing the corresponding verification signature with the signature code; or by comparing the corresponding verification signature with the key information; executing the corresponding authentication scheme to generate a corresponding verification result; a response module, determining that the verification result is passed, and providing the API service to the user terminal.

[0011] In a third aspect, the present application provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor implements the steps of an API service access method when executing the computer program.

[0012] In a fourth aspect, the present application provides a computer-readable storage medium, on which a computer program is stored, and the computer program is used to enable a machine to execute any of the above methods of the present application.

[0013] In a fifth aspect, the present application provides a computer program product, which includes a computer program code. When the computer program code is executed by a computer, the computer executes the method in the above-mentioned first aspect or any possible implementation of the first aspect.

[0014] One of the above technical solutions has the following advantages or beneficial effects: by carrying key information, authentication identifier and signature code in the access request, the access request is processed and the corresponding string to be signed is generated, and then the corresponding verification signature is generated; further, according to the authentication identifier, the corresponding authentication scheme is determined to implement signature verification, thereby ensuring the security of the data transmission process and reducing the risks faced by the API service; by processing the information in the access request, the user's identity authentication and service response are realized, taking into account both security and comprehensiveness, and ensuring the stability and reliability of access.

[0015] Other features and advantages of the embodiments of the present invention will be described in detail in the subsequent detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] The accompanying drawings are used to provide a further understanding of the embodiments of the present invention and constitute a part of the specification. Together with the following specific implementations, they are used to explain the embodiments of the present invention, but do not constitute a limitation on the embodiments of the present invention. In the accompanying drawings:

[0017] Figure 1 is an application environment diagram of an API service access method in an embodiment;

[0018] Figure 2 is a flowchart of an API service access method in an embodiment;

[0019] Figure 3 is a flowchart of an API service access method in another embodiment;

[0020] Figure 4 is a structural block diagram of an API service access device in an embodiment;

[0021] Figure 5 The figure is a diagram of the internal structure of a computer device in an embodiment. DETAILED DESCRIPTION

[0022] The specific implementation of the embodiment of the present invention is described in detail below in conjunction with the accompanying drawings. It should be understood that the specific implementation described here is only used to illustrate and explain the embodiment of the present invention, and is not used to limit the embodiment of the present invention.

[0023] It should be noted that the acquisition, transmission, storage, use, and processing of data in the technical solution of this application are in compliance with the relevant provisions of national laws and regulations. In the embodiments of this application, some existing solutions in the industry such as certain software, components, and models may be mentioned, which should be considered as exemplary. Their purpose is only to illustrate the feasibility of implementing the technical solution of this application, but it does not mean that the applicant has or will necessarily use the solution.

[0024] In such Figure 1 In the application environment shown, the user terminal can be run in the first device 101, the second device 102, and the third device 103. The first device 101, the second device 102, and the third device 103 include but are not limited to various personal computers, laptops, smart phones, and vehicle terminals; the server 104 can be implemented by an independent server or a server cluster composed of multiple servers, and the user terminal and the server 104 can be connected to the network communication through a wired or wireless network, specifically through the Internet, a local area network, Bluetooth, or ZigBee protocol and other communication methods.

[0025] In one embodiment, Figure 2 As shown, a method for accessing an API service is provided, comprising the following steps:

[0026] S202, receiving an access request from a user end for an API service; the access request carries key information, an authentication identifier, and a signature code.

[0027] Among them, the access request is a data set generated by the user end through the program according to the interface rules provided by the platform. The access request carries a request message, which is a structured data format defined according to the message protocol. Accordingly, the message protocol includes various message assembly modes such as request, response, and notification. The message can be sent from the user end to the server end or from the server end to the user end.

[0028] At the same time, all message structures include at least two parts: HTTP-HEADER and HTTP-BODY; HTTP-HEADER includes at least key information, authentication identifier and signature code; HTTP-BODY is the message data body of the specific business request.

[0029] Key information is used to distinguish and identify different users' identity credentials for accessing API service resources. A user can have multiple key information, which can be a string of characters or a certificate file containing the user's private key and public key.

[0030] The authentication identifier is the selected signature authentication method, which is used to identify different access requests for decryption, signature verification or other services. It can be a separate identifier or a string. The signature code refers to the signature value calculated based on the key information corresponding to the authentication identifier, which can be composed of a string of characters.

[0031] S204, processing the access request to generate a corresponding character string to be signed.

[0032] Among them, the string to be signed refers to the string corresponding to the original data in the message sent or received, for example, in the form of: var waitForSignString = {"service":"withdraw","context":"session parameters","notifyUrl":"20912213123sdf","busiType":"BUSI2","returnUrl":,"userId":"1.0","20198982938272827232"}.

[0033] S206: Generate a corresponding verification signature according to the authentication identifier, key information and the character string to be signed.

[0034] The verification signature refers to a signature that is associated with the original data and cannot be tampered with, generated based on the string to be signed and the key information.

[0035] Exemplarily, the verification signature generated according to the authentication identifier includes a digest verification signature and a certificate verification signature. For example, when the authentication identifier is an identifier such as MD5, Sha1Hex, and Sha256Hex, the verification signature is a digest verification signature.

[0036] First, add the key information to the string to be signed, for example: the signature string is: {"service":"withdraw","context":...} The key information is: c9cef22553afujh64b04a012f9cb8ea9 Generate: {"service":"withdraw","context":...}c9cef22553afujh64b04a012f9cb8ea9. Further, the format needs to be converted. First, the signature is converted into a UTF-8 byte array, and the byte array form of the digest value is calculated through the standard digest algorithm. Then, the byte array of the digest is converted into a Hex (hexadecimal form of lowercase letters) string format to generate the final verification signature.

[0037] For example, when the authentication identifier is an RSA identifier, the verification signature is a certificate verification signature. First, the standard RSA signature algorithm is used in combination with the private key in the user key information to perform signature calculation on the string to be signed, generate 256 bytes (byte array) of signature data, and perform standard base64 encoding on the signature data, and finally obtain a 344-byte string as the verification signature of the message.

[0038] It should be understood that, of course, the specific selected scheme is determined by the request information sent by the user end, wherein the determination method may be an identifier or a character string carried in the authentication identifier.

[0039] S208, determining a corresponding authentication scheme according to the authentication identifier; the authentication scheme is generated by comparing the corresponding verification signature with the signature code; or by comparing the corresponding verification signature with the key information.

[0040] Among them, the authentication scheme refers to the implementation plan selected when performing signing, signature verification, encryption, decryption and other services. Specifically, the user terminal receives the authentication identification and key information by default when opening an account, and determines the corresponding authentication scheme based on the authentication identification. Exemplarily, when the authentication identification is a non-RSA identification, the verification signature is compared with the signature code carried in the access request. When the authentication identification is an RSA identification, the RSA standard algorithm and the user's public key in the key information are used to verify the verification signature, which can ensure that the data has not been tampered with or damaged during transmission.

[0041] S210, executing a corresponding authentication scheme and generating a corresponding verification result.

[0042] The verification result refers to the message code of the response processing result, which is uniformly defined according to the specific business, for example, authentication error: UNAUTHENTICATED_ERROR.

[0043] S212, determine that the verification result is passed, and provide API service to the user end.

[0044] Among them, if the verification result is passed, the server will parse the response access request and generate structured entity information, which includes the user's name, key, password, API service name and other information, and locate the specific API service according to the service name to initiate the call processing.

[0045] In one embodiment, access requests can be accessed in two ways: Filter or restFul. The filterchain responsibility chain model is used internally to make the processing process sequentially executed and passed in sequence. Among them, the Filter interface allows the interception and processing of requests and responses, so that the application can check whether the user has the authority to access a certain service through the Filter, and record log information before and after the request is processed; the restFul interface is based on HTTP and URI (Uniform Resource Identifier) ​​principles to assist the interactive design of the present invention.

[0046] In one embodiment, the access request also carries a user identifier; after the step of receiving the access request from the user end and before the step of generating a corresponding string to be signed according to the access request, it also includes: identifying the user identifier in the access request; and determining that the user identifier is in the permission whitelist of the API service.

[0047] In one embodiment, after the step of identifying the user identifier in the access request, it also includes: if the user identifier is in the permission blacklist of the API service, an error message is returned to the user end; the error message is used to notify the user end that it has no right to access the API service.

[0048] Among them, user ID is usually used to distinguish and identify different users, and can be set to user IP address, signature, authentication code and other information, which are not listed here. To control the user's access rights, a permission blacklist and whitelist are set to allow or deny access requests in special circumstances. The whitelist allows the user to call API services, while the blacklist prohibits the user from accessing any API services. User permissions can be determined by comparing the user ID with the list.

[0049] In one embodiment, after determining that the verification result is passed, it also includes: adding the access request to the corresponding buffer queue based on the user identifier; counting the number of access requests in the buffer queue within a set time length; when the number of access requests exceeds the preset threshold corresponding to the buffer queue, delaying the execution of the step of providing API services to the user end.

[0050] Among them, the corresponding buffer queue can be set according to the user identifier, such as setting buffer queues in different areas according to the IP address, or it can be set according to a specific single API service, mainly setting the number of requests in the specified time period of the buffer queue, such as per second / per minute / per hour / per day, or the number of requests for the entire system. Through flow control, the system access response can be prevented from being overloaded, thereby improving the response speed and stability of the system. It should be understood that the flow control strategy can be selected and adjusted according to actual business needs and network environment, and is not limited here.

[0051] In one embodiment, the access request also carries ciphertext data; the step of providing API services to the user terminal includes: decrypting the ciphertext data in the access request according to the authentication identifier and key information; and providing API services to the user terminal according to the decrypted access request.

[0052] Among them, in order to ensure the security of some information during the transmission process, the data items need to be encrypted. Accordingly, the message in the access request received by the server will clearly state the data items that need to be decrypted. The server selects the corresponding decryption scheme according to the authentication identifier to decrypt the ciphertext data. After the decrypted data is processed by signature verification, for example, when the authentication identifier is an RSA identifier, the key information used is the user's private key. At the same time, combined with the asymmetric decryption algorithm, the decryption format is as follows: algorithm / mode / padding is: RSA / ECB / PKCS5Padding, and the decrypted information is UTF-8 encoded and converted into a string to complete the decryption. Exemplarily, when the authentication identifier is a non-RSA identifier, the ciphertext data is Base64 decoded and the decrypted information is UTF-8 encoded and converted into a string to complete the decryption.

[0053] In one embodiment, when an access request carries a callback address, the steps of providing API services to a user terminal include: parsing the access request based on a communication protocol and generating routing information; calling the API service according to the routing information and generating a response message; the response message is used to notify the user terminal that part of the API service has been completed; sending the response message to the user terminal and executing the remaining API service; when all API service operations are completed, feeding back the service results to the callback address.

[0054] In this embodiment, routing information refers to the entity generated after parsing the access request. The entity is a service class with annotations. The service class can be service information such as login, jump, payment, etc. The response message is a feedback message generated by the server according to the request processing result after the API service is called. It can be information such as success, service does not exist, parameter format error, etc.

[0055] Among them, Figure 3As shown, when the API service accessed by the user requires an asynchronous response, for example, the payment service requires the processing result of a third-party system, the server will first generate a response message and send it to the user to notify the user that the request has been received or part of the business processing has been completed, and the user needs to wait for the final processing result of the subsequent business; after receiving the response message, the user can perform related business or status processing. At the same time, the server executes the asynchronous processing-related business logic, and after obtaining the final processing result, it feeds back the service result to the callback address. Subsequently, after successfully receiving the service result, the user needs to feed back the response message body of the server to indicate that the user has successfully received all service results. If the merchant fails to feed back the response message body, the server will continue to resend the notification at a certain frequency, for example, completing 8 notifications within 24 hours.

[0056] It should be understood that the communication method is used to adapt to different API services. For example, in special cases where there is no prior asynchronous notification, the server ends the process after calling the corresponding API service and generating a response message.

[0057] In one embodiment, an API service access method is provided, in which the execution subject is a user end, and includes: constructing an access request corresponding to the API service according to an interface rule; the access request includes key information, an authentication identifier and a signature code; sending an access request; the access request is used by the server end to process the access request to generate a corresponding string to be signed; generating a corresponding verification signature according to the authentication identifier, the key information and the string to be signed; determining a corresponding authentication scheme according to the authentication identifier; the authentication scheme is generated by comparing the corresponding verification signature with the signature code; or comparing the corresponding verification signature with the key information; executing the corresponding authentication scheme, generating a corresponding verification result, determining that the verification result is passed, and providing API service; receiving a return message from the server end.

[0058] In one embodiment, the step of constructing an access request corresponding to the API service according to the interface rule includes: encrypting a specific data item in the access request according to the interface rule and the authentication identifier.

[0059] Among them, the interface rules are necessary protocols for communication and analysis between the server and the client, including detailed descriptions of the technical communication protocols that define the API interface and message definition rules. In this embodiment, in order to ensure the security of specific data items during transmission, it is necessary to encrypt specific data items. The corresponding encryption scheme is selected according to the authentication identifier, and the specific data to be encrypted is encrypted and replaced according to the interface rules. For example, when the authentication identifier is an RSA identifier, the public key loaded with the user key information adopts a segmented encryption method. The length of the encrypted data each time is the length of the public key minus 11 bytes, and then the segmented encrypted data is connected to form a ciphertext. The encryption format is as follows: algorithm / mode / padding is: RSA / ECB / PKCS5Padding, the encrypted specific data items are encoded using BASE64, and the remaining data items are encoded using UTF-8.

[0060] Exemplarily, when the authentication identifier is a non-RSA identifier, the first 16 bytes of the user key information are loaded, and the encryption format is as follows: algorithm / mode / padding is: AES / ECB / PKCS5Padding, the encrypted specific data items are encoded using BASE64, and the remaining data items are encoded using UTF-8.

[0061] Based on the same inventive concept, the embodiment of the present application also provides an API service access device for implementing the API service access method involved above. The implementation solution provided by the device to solve the problem is similar to the implementation solution recorded in the above method, so the specific limitations in one or more API service access device embodiments provided below can refer to the limitations on the API service access method above, and will not be repeated here.

[0062] In one embodiment, Figure 4 The API service access device 300 is provided, comprising: a receiving module 301, a verification module 302, a verification module 303 and a response module 304, wherein:

[0063] The receiving module 301 is used to receive an access request from a client for an API service; the access request carries key information, an authentication identifier and a signature.

[0064] The processing module 302 is used to process the access request and generate a corresponding character string to be signed.

[0065] The verification module 303 is used to generate a corresponding verification signature based on the authentication identifier, key information and the character string to be signed; determine the corresponding authentication scheme based on the authentication identifier; the authentication scheme is to generate the corresponding verification signature by comparing the corresponding verification signature and the signature code; or to compare the corresponding verification signature and the key information; execute the corresponding authentication scheme to generate the corresponding verification result.

[0066] The response module 304 is used to determine that the verification result is passed and provide API services to the user end.

[0067] In one embodiment, the access request also carries a user ID; the receiving module 301 is specifically used to identify the user ID in the access request; and determine whether the user ID is in the permission whitelist of the API service. If the user ID is in the permission blacklist of the API service, an error message is returned to the user end; the error message is used to notify the user end that it has no right to access the API service.

[0068] In one embodiment, the response module 304 also includes a flow control module, which is used to add access requests to a corresponding buffer queue based on a user identifier; count the number of access requests in the buffer queue within a set time period; and delay the execution of the step of providing API services to the user end when the number of access requests exceeds a preset threshold corresponding to the buffer queue.

[0069] In one embodiment, the access request also carries ciphertext data, and the response module 304 further includes a decryption module, which is used to decrypt the ciphertext data in the access request according to the authentication identifier and key information; and provide API services to the user terminal according to the decrypted access request.

[0070] In one embodiment, when the access request carries a callback address, the response module 304 is specifically used to parse the access request based on the communication protocol to generate routing information; call the API service according to the routing information to generate a response message; the response message is used to notify the user end that part of the service has been completed; perform asynchronous processing; and when the API service is fully completed, feedback the service results to the callback address.

[0071] In addition, in the implementation of the API service access device in the above example, the logical division of each program module is only an example. In actual applications, the above functions can be assigned to different program modules as needed, for example, for the configuration requirements of the corresponding hardware or the convenience of software implementation. That is, the internal structure of the API service access device is divided into different program modules to complete all or part of the functions described above.

[0072] In one embodiment, a computer device is provided. The computer device may be a mobile terminal. The internal structure diagram of the computer device may be as follows: Figure 5As shown. The computer device includes a processor, a memory, an input / output interface, and a communication interface. The processor, the memory and the input / output interface are connected via a system bus, and the network interface is connected to the system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, NFC (near field communication) or other technologies. When the computer program is executed by the processor, an API service access method is implemented.

[0073] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0074] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0075] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0076] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0077] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices, and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of the processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0078] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0079] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0080] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0081] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.

Claims

1. A method for accessing an API service, characterized in that: include: Receive access requests from the client for API services; The access request carries key information, authentication identifier and signature code; Processing the access request to generate a corresponding character string to be signed; Generate a corresponding verification signature according to the authentication identifier, the key information and the character string to be signed; Determine a corresponding authentication scheme according to the authentication identifier; The authentication scheme is to generate the corresponding verification signature by comparing it with the signature code; or comparing the corresponding verification signature with the key information; Execute the corresponding authentication scheme and generate a corresponding verification result; Determine that the verification result is passed, and provide the API service to the user terminal.

2. The method according to claim 1, characterized in that The access request also carries a user identifier; After the step of receiving the access request from the user terminal and before the step of generating a corresponding character string to be signed according to the access request, the method further includes: identifying the user identifier in the access request; Determine that the user identifier is in the permission whitelist of the API service.

3. The method according to claim 2, characterized in that After the step of identifying the user identifier in the access request, the method further includes: If the user identifier is in the permission blacklist of the API service, an error message is returned to the user terminal; the error message is used to notify the user terminal that it has no right to access the API service.

4. The method according to claim 2, characterized in that: After determining that the verification result is passed, the method further includes: adding the access request to a corresponding buffer queue based on the user identifier; Count the number of access requests to the buffer queue within a set time period; When the number of access requests exceeds a preset threshold corresponding to the buffer queue, the step of providing the API service to the user terminal is delayed.

5. The method according to any one of claims 1 to 4, characterized in that The access request also carries ciphertext data; The step of providing the API service to the user terminal includes: decrypting the ciphertext data in the access request according to the authentication identifier and the key information; The API service is provided to the user terminal according to the decrypted access request.

6. The method according to any one of claims 1 to 4, characterized in that In the case where the access request carries a callback address, the step of providing the API service to the user terminal includes: Parsing the access request based on the communication protocol to generate routing information; The API service is called according to the routing information to generate a response message; the response message is used to notify the user end that part of the API service has been completed; Send the response message to the user terminal and execute the remaining business of the API service; When all business executions of the API service are completed, the service results are fed back to the callback address.

7. An API service access device, characterized in that: include: A receiving module, used to receive access requests from the user end for the API service; The access request carries key information, authentication identifier and signature code; A processing module, used for processing the access request to generate a corresponding character string to be signed; A verification module, used to generate a corresponding verification signature according to the authentication identifier, the key information and the character string to be signed; Determine a corresponding authentication scheme according to the authentication identifier; The authentication scheme is to generate the corresponding verification signature by comparing it with the signature code; or to compare the corresponding verification signature with the key information; execute the corresponding authentication scheme to generate a corresponding verification result; The response module is used to determine that the verification result is passed and provide the API service to the user terminal.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Cited By

  • Butt-joint method and device for external service integrated by mobile terminal and back-end autonomous service

    CN121125839A