Authority verification method and device, electronic equipment and storage medium

By judging the update status of the cache permission list and looking for the real-time permission list in the API's permission verification, the problem of low verification accuracy during the cache permission list is solved, and the security and stability of API access is improved.

CN120068113APending Publication Date: 2025-05-30PEOPLE'S INSURANCE COMPANY OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510135504.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-06
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

In the prior art, the cache permission list of the API may result in a low accuracy of permission verification during the update process.

Method used

Determine the update status by obtaining the cached account permission list of the target API that the account to be verified requests. If it is in an updated state, look for the target real-time account permission list in the account permission database to perform permission verification.

Benefits of technology

Improve the accuracy of permission verification, avoid misjudgments caused by inconsistent cache data, and ensure the security and stability of API access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120068113A_ABST
    Figure CN120068113A_ABST
Patent Text Reader

Abstract

The invention discloses a permission verification method and device, electronic equipment and a storage medium, and relates to the technical field of data processing, and the main technical scheme comprises the steps of obtaining a cache account permission list of a target application programming interface requested to be accessed by a to-be-verified account; determining whether the cache account permission list is in an updating state or not; if the cache account permission list is in an updating state, searching a target real-time account permission list of the target application programming interface in an account permission database; and determining a verification result of the to-be-verified account according to the target real-time account permission list. Compared with the prior art, according to the embodiment of the invention, when the cache account permission list is in the update state, the target real-time account permission list of the target application programming interface in the account permission database is used for performing permission verification on the to-be-verified account, and the target real-time account permission list is updated in real time, so that the permission verification efficiency is improved. Therefore, the data in the target real-time account permission list is not delayed, and the permission verification accuracy is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of data processing, and in particular, to a method and device for verifying permissions, an electronic device, and a storage medium. Background Art

[0002] With the development of the Internet, Application Programming Interfaces (APIs) are widely used in various system interactions. However, since they directly expose data and functions, they are vulnerable to illegal calls, resulting in data leakage and business disorders. To ensure data security and business stability, API permissions are verified to ensure legitimate access.

[0003] In the related technologies of permission verification, it is usually determined whether an account has the permission to access an API based on whether the account sending the verification request exists in the cached permission list of the API. However, the cached permission list is dynamically updated. During the update process of the cached permission list, if there is a verification request for permission verification, since there are unupdated data in the cached permission list at this time, the accuracy rate of permission verification is relatively low. Summary of the Invention

[0004] The present disclosure provides a method and device for verifying permissions, an electronic device, and a storage medium. Its main purpose is to solve the problem of relatively low accuracy rate of permission verification.

[0005] According to a first aspect of the present disclosure, a method for verifying permissions is provided, which includes:

[0006] Obtain the cached account permission list of the target application programming interface requested by the account to be verified;

[0007] Determine whether the cached account permission list is in an updated state;

[0008] If the cached account permission list is in an updated state, search for the target real-time account permission list of the target application programming interface in the account permission database; the account permission database contains the real-time account permission lists of all application programming interfaces;

[0009] Determine the verification result of the account to be verified according to the target real-time account permission list.

[0010] Optionally, the determining whether the cached account permission list is in an updated state includes:

[0011] Determine whether there is an update flag in the cached account permission list; the update flag is a flag that exists when the cached account permission list is in an updated state;

[0012] If the update identifier does not exist in the cached account permission list, it is determined that the cached account permission list is not in an updated state;

[0013] If the update identifier exists in the cached account permission list, it is determined that the cached account permission list is in an updated state.

[0014] Optionally, before obtaining the cached account permission list of the target application programming interface requested by the account to be verified, the method further includes;

[0015] Obtain the verification request sent by the account to be verified to the target application programming interface; the verification request includes a request path, a request type, and the account to be verified;

[0016] Combine the request path, the request type, and the account to be verified into a first sequence;

[0017] Store the first sequence and the cached account permission list in the form of key-value pairs for the key-value pair to look up the cached account permission list; wherein, the first sequence is the key and the cached account permission list is the value.

[0018] Optionally, after obtaining the verification request sent by the account to be verified to the target application programming interface, the method further includes:

[0019] Generate a lock identifier for the cached account permission list;

[0020] Combine the lock identifier, the request path, the request type, and the account to be verified into a second sequence; the update identifier is the second sequence;

[0021] When the cached account permission list is in an updated state, cache the second sequence into the cached account permission list until the cached account permission list is not in an updated state, then delete the second sequence from the cached account permission list to determine whether the cached account permission list is in an updated state based on the second sequence.

[0022] Optionally, after determining whether the cached account permission list is in an updated state, the method further includes:

[0023] If the cached account permission list is not in an updated state, determine whether the account to be verified has permission to access the target application programming interface according to whether the same account exists in the cached account permission list for the account to be verified.

[0024] Optionally, determining the verification result of the account to be verified according to the target real-time account permission list includes:

[0025] Determine whether the to-be-verified account has the permission to access the target application programming interface according to whether there is the same account in the target real-time account permission list of the to-be-verified account.

[0026] According to a second aspect of the present disclosure, a permission verification device is provided, including:

[0027] An obtaining unit, configured to obtain a cached account permission list of a target application programming interface requested to be accessed by a to-be-verified account;

[0028] A first determination unit, configured to determine whether the cached account permission list is in an updated state;

[0029] A searching unit, configured to search for a target real-time account permission list of the target application programming interface in an account permission database when the cached account permission list is in an updated state; the account permission database contains real-time account permission lists of all application programming interfaces;

[0030] A second determination unit, configured to determine a verification result of the to-be-verified account according to the target real-time account permission list.

[0031] Optionally, the first determination unit includes:

[0032] A determination module, configured to determine whether there is an update identifier in the cached account permission list; the update identifier is an identifier that exists when the cached account permission list is in an updated state;

[0033] The determination module is further configured to determine that the cached account permission list is not in an updated state when the update identifier does not exist in the cached account permission list;

[0034] The determination module is further configured to determine that the cached account permission list is in an updated state when the update identifier exists in the cached account permission list.

[0035] Optionally, the device further includes;

[0036] The obtaining unit is further configured to obtain a verification request sent by the to-be-verified account to the target application programming interface before obtaining the cached account permission list of the target application programming interface requested to be accessed by the to-be-verified account; the verification request includes a request path, a request type, and the to-be-verified account;

[0037] A composition unit, configured to compose the request path, the request type, and the to-be-verified account into a first sequence;

[0038] A storage unit for storing the first sequence and the cached account permission list in the form of key-value pairs, so as to find the cached account permission list through the key-value pair; wherein, the first sequence is the key and the cached account permission list is the value.

[0039] Optionally, the device further includes:

[0040] A generation unit for generating a lock identifier for the cached account permission list after obtaining a verification request sent by the account to be verified to the target application programming interface;

[0041] The composition unit is further configured to compose the lock identifier, the request path, the request type, and the account to be verified into a second sequence; the update identifier is the second sequence;

[0042] A caching unit for caching the second sequence into the cached account permission list when the cached account permission list is in an updated state, and deleting the second sequence from the cached account permission list until the cached account permission list is not in an updated state, so as to determine whether the cached account permission list is in an updated state based on the second sequence.

[0043] Optionally, the device further includes:

[0044] The second determination unit is further configured to, after determining whether the cached account permission list is in an updated state, when the cached account permission list is not in an updated state, determine whether the account to be verified has the permission to access the target application programming interface according to whether there is the same account of the account to be verified in the cached account permission list.

[0045] Optionally, the second determination unit includes:

[0046] A determination module for determining whether the account to be verified has the permission to access the target application programming interface according to whether there is the same account of the account to be verified in the target real-time account permission list.

[0047] According to a third aspect of the present disclosure, an electronic device is provided, including:

[0048] At least one processor; and

[0049] A memory communicatively connected to the at least one processor; wherein,

[0050] The memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the method described in the foregoing first aspect.

[0051] According to a fourth aspect of the present disclosure, there is provided a non-transitory computer-readable storage medium storing computer instructions, wherein the computer instructions are used to cause the computer to execute the method described in the foregoing first aspect.

[0052] According to a fifth aspect of the present disclosure, there is provided a computer program product including a computer program, which implements the method described in the foregoing first aspect when executed by a processor.

[0053] The authentication method and device, electronic device, and storage medium for permissions provided by the present disclosure obtain a cached account permission list of a target application programming interface (API) requested to be accessed by a to-be-authenticated account; determine whether the cached account permission list is in an updated state; if the cached account permission list is in an updated state, search for a target real-time account permission list of the target API in an account permission database; the account permission database contains real-time account permission lists of all application programming interfaces; and determine an authentication result of the to-be-authenticated account according to the target real-time account permission list. Compared with the related art, in the embodiment of the present disclosure, by determining whether the cached account permission list of the target API is in an updated state, when it is determined that the cached account permission list is in an updated state, the target real-time account permission list of the target API in the account permission database is used to perform permission authentication on the to-be-authenticated account. Since the target real-time account permission list is updated in real time, the data in the target real-time account permission list has no delay, improving the accuracy of permission authentication.

[0054] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become easily understandable through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0055] The drawings are used to better understand the solution and do not constitute a limitation to the present disclosure. Among them:

[0056] Figure 1 is a schematic flowchart of a method for authenticating permissions provided by an embodiment of the present disclosure;

[0057] Figure 2 is a schematic flowchart of a method for determining whether a cached account permission list is in an updated state provided by an embodiment of the present disclosure;

[0058] Figure 3 is a schematic flowchart of a full-process processing of permission authentication provided by an embodiment of the present disclosure;

[0059] Figure 4Structural schematic diagram of an authentication device for permissions provided by an embodiment of the present disclosure;

[0060] Figure 5 Structural schematic diagram of another authentication device for permissions provided by an embodiment of the present disclosure;

[0061] Figure 6 Schematic block diagram of an exemplary electronic device provided by an embodiment of the present disclosure. Detailed implementation manners

[0062] The following describes exemplary embodiments of the present disclosure with reference to the accompanying drawings. Various details of the embodiments of the present disclosure are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, descriptions of well-known functions and structures are omitted below for clarity and conciseness.

[0063] Next, a method and device for authenticating permissions, an electronic device, and a storage medium according to embodiments of the present disclosure will be described with reference to the accompanying drawings.

[0064] Figure 1 Flow schematic diagram of a method for authenticating permissions provided by an embodiment of the present disclosure.

[0065] As Figure 1 shown, this method is applied to a server, and this method includes the following steps:

[0066] Step 101, obtain the cached account permission list of the target application programming interface requested to be accessed by the account to be authenticated.

[0067] The account to be authenticated refers to a user account or a client identifier that requests to access the target application programming interface. The account to be authenticated is the object of permission verification, and the server needs to determine whether the account to be authenticated has the permission to access the target application programming interface. For ease of understanding, an example is provided. Suppose a user logs in to a certain software through the account to be authenticated, and the software backend will interact with the server through the application programming interface, and the user's account is the account to be authenticated.

[0068] The cached account permission list is an account permission list of the target application programming interface stored in a cached database, which records which accounts have permissions to access the target application programming interface. The cached database can be a remote dictionary service (Redis). When the account to be verified first performs permission verification with the target application programming interface, a mapping relationship can be established between the account to be verified and the cached account permission list. When the account to be verified subsequently performs permission verification with the target application programming interface for the first time, the cached account permission list can be quickly found in the cached database. However, it should be clear that this statement is not intended to limit that the mapping relationship can only be established between the account to be verified and the cached account permission list. A mapping relationship can also be established between other data and the cached account permission list. The present disclosure does not make any limitations on other data. Through the mapping relationship, the cached account permission list can be quickly found, improving the search efficiency of the cached account permission list.

[0069] Step 102, determine whether the cached account permission list is in an updated state.

[0070] The updated state refers to the state in which an account is being added to or deleted from the cached account permission list. The method for determining whether the cached account permission list is in an updated state can be to check whether there is an update flag in the cached account permission list. If there is no update flag in the cached account permission list, it is determined that the cached account permission list is not in an updated state. If there is an update flag in the cached account permission list, it is determined that the cached account permission list is in an updated state. However, it should be clear that this statement is not intended to limit that the method for determining whether the cached account permission list is in an updated state can only be the above method, and it can also be implemented by other methods.

[0071] By checking whether the cache is in an updated state, the accuracy of the permission verification result is improved, and the reduction in the accuracy of permission verification caused by the possible incompleteness or inaccuracy of the data in the cache of the cached account permission list is avoided.

[0072] Step 103, if the cached account permission list is in an updated state, then search for the target real-time account permission list of the target application programming interface in the account permission database; the account permission database contains the real-time account permission lists of all application programming interfaces.

[0073] The account permission database is a database that stores the real-time permission information of all application programming interfaces, including the latest real-time account permission list of each application programming interface. When the account permissions of an application programming interface change, they are first synchronously updated in the account permission database, and then the cached account permission list is updated using the real-time account permission list in the account permission database.

[0074] The real-time account permission list refers to the latest account permission list for the target application programming interface obtained from the account permission database.

[0075] When the cached account permission list is in an updated state, the account permission database is used for permission verification. When the cached account permission list is not in an updated state, the cached account permission list is used for permission verification, rationally utilizing the cached account permission list and the account permission database resources, reducing the load on the account permission database, and improving the overall system performance.

[0076] Step 104: Determine the verification result of the account to be verified according to the target real-time account permission list.

[0077] The final judgment result on whether the account to be verified has the right to access the target application programming interface usually includes two results. One is that the account to be verified has the right to access the target application programming interface, and the other is that the account to be verified has no right to access the target application programming interface.

[0078] Determining the verification result of the account to be verified according to the target real-time account permission list can be achieved through the following method. When the cached account permission list is in an updated state, obtain the target real-time account permission list of the target application programming interface from the account permission database. The target real-time account permission list is updated in real time and can reflect the latest account permission status. Check whether there is an account in the target real-time account permission list that is the same as the account to be verified. If the same account is found, it means that the account to be verified has the permission to access the target application programming interface. If the same account is not found, it means that the account to be verified has no permission to access the target application programming interface. If the account to be verified is in the target real-time account permission list, the verification result is "has permission", and the account to be verified is allowed to access the target application programming interface. If the account to be verified is not in the target real-time account permission list, the verification result is "has no permission", and the account to be verified is refused to access the target application programming interface.

[0079] The target real-time account permission list is updated in real time and can reflect the latest permission status. By directly using the real-time permission list for verification, it avoids misjudgment caused by inconsistent cached data and improves the accuracy of the verification result.

[0080] The authentication method for permissions provided by the present disclosure obtains the cached account permission list of the target application programming interface requested by the account to be authenticated; determines whether the cached account permission list is in an updated state; if the cached account permission list is in an updated state, searches for the target real-time account permission list of the target application programming interface in the account permission database; the account permission database contains the real-time account permission lists of all application programming interfaces; determines the authentication result of the account to be authenticated according to the target real-time account permission list. Compared with the related art, in the embodiment of the present disclosure, by determining whether the cached account permission list of the target application programming interface is in an updated state, when it is determined that the cached account permission list is in an updated state, the target real-time account permission list of the target application programming interface in the account permission database is used to perform permission authentication on the account to be authenticated. Since the target real-time account permission list is updated in real time, the data in the target real-time account permission list has no delay, improving the accuracy of permission authentication.

[0081] As a refinement of step 102, when performing the determination of whether the cached account permission list is in an updated state, it can be implemented by, but not limited to, the following methods, such as Figure 2 shown Figure 2 is a flowchart of a method for determining whether a cached account permission list is in an updated state provided by an embodiment of the present disclosure, including:

[0082] Step 201, determines whether there is an update identifier in the cached account permission list; the update identifier is an identifier that exists when the cached account permission list is in an updated state.

[0083] The update identifier is a special identifier used to mark whether the cached account permission list is being updated. The composition of the update identifier includes, but is not limited to, a lock identifier, a request path, a request type, and an account to be authenticated. Among them, the lock identifier is a unique mark for identifying cache updates. The request path refers to the path of the target application programming interface requested by the account to be authenticated. The lock identifier, request path, request type, and account to be authenticated are combined into a sequence as the update identifier. However, it should be clear that this statement is not intended to limit that the update identifier can only be composed of a lock identifier, a request path, a request type, and an account to be authenticated, and it can also be composed of other data.

[0084] If the permission information is directly retrieved from the database for each verification, although the accuracy can be guaranteed, it will increase the access pressure on the database and reduce the system performance. Only when the cached account permission list is in an updated state, the latest permission information is retrieved from the account permission database. If the cached account permission list is not in an updated state, the cached account permission list is directly used for verification. This reduces the frequent access to the database, improves the system response speed and performance, and at the same time reduces the load on the account permission database.

[0085] Step 202, if the update flag does not exist in the cached account permission list, it is determined that the cached account permission list is not in an updated state.

[0086] By checking whether the update flag exists in the cached account permission list and determining that the cached account permission list is not in an updated state when the update flag does not exist, it is not only possible to quickly judge the cache state, reduce unnecessary database access, but also improve the verification efficiency, reduce the system complexity, improve the system reliability, ensure the verification accuracy, optimize resource utilization, and support dynamic permission management.

[0087] Step 203, if the update flag exists in the cached account permission list, it is determined that the cached account permission list is in an updated state.

[0088] By checking whether the update flag exists in the cached account permission list and determining that the cached account permission list is in an updated state when the update flag exists, it is not only possible to avoid using inconsistent cached data, ensure the verification accuracy, but also support dynamic permission management, reduce misjudgment and exceptions, optimize resource utilization, and simplify the permission verification logic.

[0089] In practical applications, before obtaining the cached account permission list of the target application programming interface requested by the account to be verified, in order to improve the speed of the cached account permission list, the following methods can be adopted but are not limited to: obtaining the verification request sent by the account to be verified to the target application programming interface; the verification request includes the request path, request type, and the account to be verified; combining the request path, request type, and the account to be verified into a first sequence; storing the first sequence and the cached account permission list in the form of key-value pairs so that the key-value pairs can find the cached account permission list; where the first sequence is the key and the cached account permission list is the value. Through the key-value pair storage method, the cached account permission list can be quickly located, the search time can be reduced, and the efficiency of permission verification can be improved.

[0090] In practical applications, after obtaining the verification request sent by the account to be verified to the target application programming interface, the method for creating the updated identifier can be implemented in, but not limited to, the following ways: generating a lock identifier for the cached account permission list; combining the lock identifier, the request path, the request type, and the account to be verified into a second sequence; the updated identifier being the second sequence; when the cached account permission list is in an updated state, caching the second sequence in the cached account permission list, and deleting the second sequence from the cached account permission list until the cached account permission list is no longer in an updated state, so as to determine whether the cached account permission list is in an updated state based on the second sequence.

[0091] The lock identifier is a unique identifier used to mark the update process of the cached account permission list. The ways to generate the lock identifier include, but are not limited to, using a random string as the lock identifier, generating the lock identifier based on a timestamp sequence number, and generating the lock identifier using an incrementing combination of numbers or characters. Ensure that the permission verification result is based on the latest permission information to avoid misjudgment caused by inconsistent cached data.

[0092] In practical applications, after determining whether the cached account permission list is in an updated state, when the cached account permission list is not in an updated state, it can be implemented in, but not limited to, the following ways: if the cached account permission list is not in an updated state, determine whether the account to be verified has the permission to access the target application programming interface based on whether the same account exists in the cached account permission list for the account to be verified. Frequent access to the real-time database will increase the load on the database and may lead to performance bottlenecks. When the cached account permission list has not been updated, give priority to using the cached account permission list for verification to reduce access to the account permission database. Reduce the pressure on the account permission database and improve the overall performance of the system.

[0093] As a refinement of step 104, when executing the determination of the verification result of the account to be verified according to the target real-time account permission list, it can be implemented in, but not limited to, the following ways: determine whether the account to be verified has the permission to access the target application programming interface based on whether the same account exists in the target real-time account permission list for the account to be verified. Improve the accuracy of verification, avoid permission errors caused by inconsistent cached data, and ensure the security of the data in the target application programming interface.

[0094] In one implementable manner of the embodiments of the present disclosure, for better understanding of the entire process of permission verification, as Figure 3 shown, Figure 3The following is a schematic diagram of the entire process for verifying permissions provided by an embodiment of the present disclosure. When an authentication request comes in, a result key (resultKey) for obtaining a result from Redis is formed based on the information in the request: / 0501020203 / ut iISvrApi / findUt iISvr:POST, and a lock key (lockKey) for whether the result of the current Application Programming Interface (API) is locked: frontLock: / 0501020203 / uti ISvrApi / findUtiISvr:POST. Data is obtained from Redis using resultKey and lockKey. (1) If no results are obtained for both. It indicates that the API in the request is being authenticated for the first time. Then, based on the requested API and the user identity document (ID), the exact result of this authentication is queried and returned. Then, an asynchronous thread is entered. After querying the full user list under the API, first, the result of this API is locked, that is, a cache with the key (KEY) lockKey is written to Redis. Then, the result list of the API is written to Redis. During this process, lockKey always exists in Redis to indicate that the result of this API in Redis is being written and not completed, and the result in Redis is not used. When the entire user list is written, finally, lockKey is deleted to indicate that the data in Redis is full data. (2) If a result is obtained for resultKey, but no result is obtained for lockKey. It proves that the user list of the API in the request has been fully written to Redis. Then, it is compared whether the user ID in the request is in the user list. If it exists, return TRUE, and if it does not exist, return FALSE. (3) If results are obtained for both, it indicates that the user list of the API in the request is being written to Redis, and there is no need to query the full user list under the API again. Just query the specific result based on the API and user ID in the current request and return it.

[0095] In summary, the embodiments of the present disclosure can achieve the following effects:

[0096] The embodiments of the present disclosure determine whether the cached account permission list of the target application programming interface is in an updated state. When it is determined that the cached account permission list is in an updated state, the target real-time account permission list of the target application programming interface in the account permission database is used to verify the permissions of the account to be verified. Since the target real-time account permission list is updated in real time, the data in the target real-time account permission list has no delay, improving the accuracy of permission verification.

[0097] Corresponding to the above-mentioned permission verification method, the present invention also provides a permission verification device. Since the device embodiment of the present invention corresponds to the above-mentioned method embodiment, for the details not disclosed in the device embodiment, reference may be made to the above-mentioned method embodiment, and details will not be repeated in the present invention.

[0098] Figure 4 As shown in the following figure, it is a schematic structural diagram of a permission verification device provided by an embodiment of the present disclosure. The device is applied to a server, such as Figure 4 shown, and includes:

[0099] An obtaining unit 31, configured to obtain a cached account permission list of a target application programming interface requested to be accessed by an account to be verified;

[0100] A first determination unit 32, configured to determine whether the cached account permission list is in an updated state;

[0101] A searching unit 33, configured to, when the cached account permission list is in an updated state, search for a target real-time account permission list of the target application programming interface in an account permission database; the account permission database contains real-time account permission lists of all application programming interfaces;

[0102] A second determination unit 34, configured to determine a verification result of the account to be verified according to the target real-time account permission list.

[0103] The permission verification device provided by the present disclosure obtains a cached account permission list of a target application programming interface requested to be accessed by an account to be verified; determines whether the cached account permission list is in an updated state; if the cached account permission list is in an updated state, searches for a target real-time account permission list of the target application programming interface in an account permission database; the account permission database contains real-time account permission lists of all application programming interfaces; and determines a verification result of the account to be verified according to the target real-time account permission list. Compared with the related art, the embodiment of the present disclosure determines whether the cached account permission list of the target application programming interface is in an updated state, and when it is determined that the cached account permission list is in an updated state, uses the target real-time account permission list of the target application programming interface in the account permission database to perform permission verification on the account to be verified. Since the target real-time account permission list is updated in real time, the data in the target real-time account permission list has no delay, improving the accuracy of permission verification.

[0104] Further, in a possible implementation manner of the embodiment of the present disclosure, as Figure 5 shown, the first determination unit 32 includes:

[0105] A determination module 321, configured to determine whether there is an update identifier in the cached account permission list; the update identifier is an identifier that exists when the cached account permission list is in an updated state;

[0106] The determination module 321 is further configured to, when the update identifier does not exist in the cached account permission list, determine that the cached account permission list is not in an updated state;

[0107] The determination module 321 is further configured to, when the update identifier exists in the cached account permission list, determine that the cached account permission list is in an updated state.

[0108] Further, in a possible implementation manner of the embodiment of the present disclosure, as Figure 5 shown, the device further includes;

[0109] The obtaining unit 31 is further configured to obtain a verification request sent by the to-be-verified account to the target application programming interface before obtaining the cached account permission list of the target application programming interface requested by the to-be-verified account; the verification request includes a request path, a request type, and the to-be-verified account;

[0110] A composition unit 35, configured to compose the request path, the request type, and the to-be-verified account into a first sequence;

[0111] A storage unit 36, configured to store the first sequence and the cached account permission list in a key-value pair form for the key-value pair to search for the cached account permission list; wherein, the first sequence is the key and the cached account permission list is the value.

[0112] Further, in a possible implementation manner of the embodiment of the present disclosure, as Figure 5 shown, the device further includes:

[0113] A generation unit 37, configured to generate a lock identifier for the cached account permission list after obtaining the verification request sent by the to-be-verified account to the target application programming interface;

[0114] The composition unit 35 is further configured to compose the lock identifier, the request path, the request type, and the to-be-verified account into a second sequence; the update identifier is the second sequence;

[0115] A caching unit 38, configured to, when the cached account permission list is in an updated state, cache the second sequence into the cached account permission list until the cached account permission list is not in an updated state, and then delete the second sequence from the cached account permission list, so as to determine whether the cached account permission list is in an updated state based on the second sequence.

[0116] Further, in a possible implementation manner of the embodiments of the present disclosure, as Figure 5 shown, the apparatus further includes:

[0117] The second determination unit 34 is further configured to, after determining whether the cached account permission list is in an updated state, when the cached account permission list is not in an updated state, determine whether the to-be-verified account has the permission to access the target application programming interface according to whether there is the same account in the cached account permission list.

[0118] Further, in a possible implementation manner of the embodiments of the present disclosure, as Figure 5 shown, the second determination unit 34 includes:

[0119] A determination module 341, configured to determine whether the to-be-verified account has the permission to access the target application programming interface according to whether there is the same account in the target real-time account permission list.

[0120] It should be noted that the foregoing explanation of the method embodiments also applies to the apparatus of the embodiments of the present disclosure, with the same principle, which is not limited in the embodiments of the present disclosure.

[0121] According to the embodiments of the present disclosure, the present disclosure also provides an electronic device, a readable storage medium, and a computer program product.

[0122] Figure 6 FIG. shows a schematic block diagram of an exemplary electronic device 400 that can be used to implement the embodiments of the present disclosure. The electronic device is intended to represent various forms of digital computers, such as, a laptop computer, a desktop computer, a workbench, a personal digital assistant, a server, a blade server, a mainframe computer, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, a personal digital processor, a cellular phone, a smart phone, a wearable device, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or claimed herein.

[0123] As Figure 6As shown, device 400 includes a computing unit 401, which can perform various appropriate actions and processes according to computer programs stored in ROM (Read-Only Memory) 402 or computer programs loaded from a storage unit 408 into RAM (Random Access Memory) 403. In RAM 403, various programs and data required for the operation of device 400 can also be stored. The computing unit 401, ROM 402, and RAM 403 are connected to each other via a bus 404. An I / O (Input / Output) interface 405 is also connected to the bus 404.

[0124] Multiple components in device 400 are connected to the I / O interface 405, including: an input unit 406, such as a keyboard, mouse, etc.; an output unit 407, such as various types of displays, speakers, etc.; a storage unit 408, such as a disk, optical disc, etc.; and a communication unit 409, such as a network card, modem, wireless communication transceiver, etc. The communication unit 409 allows device 400 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0125] The computing unit 401 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 401 include, but are not limited to, a CPU (Central Processing Unit), a GPU (Graphic Processing Units), various dedicated AI (Artificial Intelligence) computing chips, various computing units running machine learning model algorithms, a DSP (Digital Signal Processor), and any appropriate processor, controller, microcontroller, etc. The computing unit 401 executes the various methods and processes described above, such as the method for verifying permissions. For example, in some embodiments, the method for verifying permissions can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as the storage unit 408. In some embodiments, part or all of the computer program can be loaded and / or installed onto device 400 via ROM 402 and / or the communication unit 409. When the computer program is loaded into RAM 403 and executed by the computing unit 401, one or more steps of the method described above can be executed. Alternatively, in other embodiments, the computing unit 401 can be configured to execute the aforementioned method for verifying permissions by any other appropriate means (e.g., by means of firmware).

[0126] Various embodiments of the systems and techniques described above in this specification can be implemented in digital electronic circuitry, integrated circuit systems, FPGAs (Field Programmable Gate Arrays), ASICs (Application-Specific Integrated Circuits), ASSPs (Application Specific Standard Products), SOCs (System On Chip), CPLDs (Complex Programmable Logic Devices), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which may be a special-purpose or general-purpose programmable processor that can receive data and instructions from, and transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0127] The program code for implementing the methods of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, special-purpose computer, or other programmable data processing apparatus, such that the program codes, when executed by the processor or controller, cause the functions / operations specified in the flowchart and / or block diagram to be implemented. The program code can be executed entirely on the machine, partly on the machine, as a stand-alone software package partly on the machine and partly on a remote machine, or entirely on the remote machine or server.

[0128] In the context of this disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a RAM, a ROM, an EPROM (Electrically Programmable Read-Only Memory), or a flash memory, an optical fiber, a CD-ROM (Compact Disc Read-Only Memory), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0129] To provide for interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (Cathode-Ray Tube) or LCD (Liquid Crystal Display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0130] The systems and techniques described herein can be implemented in a computing system that includes backend components (such as, for example, a data server), or a computing system that includes middleware components (such as, for example, an application server), or a computing system that includes frontend components (such as, for example, a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (such as, for example, a communication network). Examples of a communication network include: a LAN (Local Area Network), a WAN (Wide Area Network), the Internet, and a blockchain network.

[0131] A computer system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The relationship between the client and the server is generated by computer programs running on respective computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services ("Virtual Private Server", or simply "VPS"). The server may also be a server of a distributed system or a server combined with a blockchain.

[0132] Among them, it should be noted that artificial intelligence is a discipline that studies enabling a computer to simulate certain thinking processes and intelligent behaviors of humans (such as learning, reasoning, thinking, planning, etc.), and there are both hardware-level technologies and software-level technologies. Artificial intelligence hardware technologies generally include technologies such as sensors, dedicated artificial intelligence chips, cloud computing, distributed storage, and big data processing; artificial intelligence software technologies mainly include several major directions such as computer vision technology, speech recognition technology, natural language processing technology, and machine learning / deep learning, big data processing technology, and knowledge graph technology.

[0133] It should be understood that various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this disclosure can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved, and no limitation is made herein.

[0134] The above specific embodiments do not constitute a limitation on the protection scope of this disclosure. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this disclosure shall be included within the protection scope of this disclosure.

Claims

1. A method for verifying authority, characterized in that: include: Get the cached account permission list of the target application programming interface that the account to be verified requests to access; Determine whether the cache account permission list is in an updated state; If the cached account permission list is in an updated state, searching the target real-time account permission list of the target application programming interface in the account permission database; The account permission database contains a real-time account permission list of all application programming interfaces; The verification result of the account to be verified is determined according to the target real-time account permission list.

2. The method according to claim 1, characterized in that Determining whether the cache account permission list is in an updated state includes: Determine whether there is an update flag in the cache account permission list; the update flag is a flag that exists when the cache account permission list is in an update state; If the update identifier does not exist in the cache account permission list, it is determined that the cache account permission list is not in an update state; If the update identifier exists in the cache account permission list, it is determined that the cache account permission list is in an update state.

3. The method according to claim 2, characterized in that Before obtaining the cached account permission list of the target application programming interface that the to-be-verified account requests to access, the method further includes: Obtaining a verification request sent by the account to be verified to the target application programming interface; The verification request includes a request path, a request type and the account to be verified; The request path, the request type and the account to be verified are combined into a first sequence; The first sequence and the cache account permission list are stored in the form of a key-value pair, so that the key-value pair can search the cache account permission list; wherein the first sequence is a key and the cache account permission list is a value.

4. The method according to claim 3, characterized in that After obtaining the verification request sent by the to-be-verified account to the target application programming interface, the method further includes: Generate a lock identifier for the cache account permission list; The lock identifier, the request path, the request type and the account to be verified are combined into a second sequence; the update identifier is the second sequence; When the cache account permission list is in an updating state, the second sequence is cached in the cache account permission list until the cache account permission list is not in an updating state, at which time the second sequence is deleted from the cache account permission list, so as to determine whether the cache account permission list is in an updating state based on the second sequence.

5. The method according to claim 1, characterized in that After determining whether the cache account permission list is in an updated state, the method further includes: If the cached account permission list is not in an updated state, it is determined whether the account to be verified has permission to access the target application programming interface based on whether the account to be verified has the same account in the cached account permission list.

6. The method according to claim 1, characterized in that Determining the verification result of the account to be verified according to the target real-time account authority list includes: According to whether the account to be verified has the same account in the target real-time account permission list, it is determined whether the account to be verified has permission to access the target application programming interface.

7. A device for verifying authority, characterized in that: include: An acquisition unit, used to acquire a cached account permission list of a target application programming interface that the account to be verified requests to access; A first determining unit, configured to determine whether the cache account permission list is in an updating state; A search unit, configured to search the target real-time account permission list of the target application programming interface in the account permission database when the cached account permission list is in an updated state; The account permission database contains a real-time account permission list of all application programming interfaces; The second determining unit is used to determine the verification result of the account to be verified according to the target real-time account permission list.

8. An electronic device, characterized in that: include: at least one processor; as well as a memory communicatively connected to the at least one processor; wherein, The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium storing computer instructions, characterized in that: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-6.

10. A computer program product, characterized in that The invention comprises a computer program which, when executed by a processor, implements the method according to any one of claims 1 to 6.