Method and system for data interaction among multiple data domains based on HTTP (Hyper Text Transport Protocol)

By using HTTP-based multi-data inter-domain data interaction methods and systems in network applications, and using a transit server to forward and process data requests and responses, the problems of high data integration difficulty and high data security risks are solved, and a secure and trustworthy multi-data inter-domain data interaction is achieved.

CN120074910APending Publication Date: 2025-05-30RUN TECH CO LTD BEIJING
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510212192.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-25
Publication Date
2025-05-30

AI Technical Summary

Technical Problem

The existing technology faces the problems of high data integration and high data security risks in the field of network applications.

Method used

A multi-data domain data interaction method and system based on HTTP is provided. Through the transit server, the data request parameters issued by the first data domain are obtained, the trust identity token is parsed, the corresponding data request is intercepted and forwarded to the second data domain, and the response data returned by the second data domain is received, and the response data is forwarded to the first data domain after processing based on the predefined format.

Benefits of technology

It reduces the difficulty of data integration, improves data security, and realizes secure and trustworthy data interaction between multiple data domains.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120074910A_ABST
    Figure CN120074910A_ABST
Patent Text Reader

Abstract

The invention provides a data interaction method and system among multiple data domains based on HTTP, and relates to the technical field of communication, the method is applied to a transit server, and the transit server is used for configuring a transit interface application; the method comprises the following steps: acquiring a data request parameter sent by a first data field based on HTTP, and analyzing to acquire a trust identity token; based on the data request parameter and the trust identity token, intercepting a corresponding data request and forwarding the data request to a second data domain; at least one of domain names, protocols and ports of the first data domain and the second data domain is different; the data request comprises a user browser request or a service request; and receiving response data returned by the second data field, processing the response data based on a predefined format, and forwarding the processed response data to the first data field. Through the method, the technical problems of high data integration difficulty and high data security risk in the prior art are solved, and the technical effects of reducing the data integration difficulty and improving the data security are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technologies, and particularly to a method and system for data interaction between multiple data domains based on HTTP. Background Art

[0002] With the rapid development of network technologies and the extensive promotion of informatization, more and more offline office and business models have been successfully migrated to online platforms. For example, the development of fields such as e-commerce, online education, and telemedicine has greatly enriched people's daily life and work styles. These online platforms are usually built based on specific business modules, and each module focuses on processing certain aspects of data or functions, such as user management, order processing, payment systems, etc.

[0003] However, this specialized construction method based on business modules also brings some problems. Due to the differences in construction entities and the diversity of business requirements, each business application often exhibits the characteristics of being single and isolated. Each application maintains its own independent database and data processing logic, resulting in difficulties in data circulation and sharing between different applications. For example, an e-commerce platform may not be able to directly access the user data of its payment system partner and needs users to manually input relevant information, which not only reduces the user experience but also increases the risk of data errors.

[0004] In addition, the singularity and isolation of data also limit the quality of data and the possibility of further analysis and prediction. In the era of big data and artificial intelligence, the integration and analysis of data are crucial for mining potential value, optimizing business processes, and improving decision-making efficiency. However, since data is scattered in different applications and databases, it is extremely difficult to integrate this data, thus limiting the maximum utilization of data value.

[0005] That is to say, the existing technologies face technical problems such as high data integration difficulty and high data security risks in the field of network applications. Summary of the Invention

[0006] The purpose of the present invention is to provide a method and system for data interaction between multiple data domains based on HTTP to solve the technical problems of high data integration difficulty and high data security risks existing in the prior art.

[0007] In a first aspect, an embodiment of the present invention provides a method for data interaction between multiple data domains based on HTTP, which is applied to a relay server. The relay server is used to configure a relay interface application. The method includes: obtaining data request parameters sent by a first data domain based on HTTP and parsing to obtain a trusted identity token; intercepting a corresponding data request based on the data request parameters and the trusted identity token and forwarding it to a second data domain; at least one of the domain names, protocols, and ports of the first data domain and the second data domain is different; the data request includes a user browser request or a service request; receiving response data returned by the second data domain and forwarding it to the first data domain after processing based on a predefined format.

[0008] In some alternative implementations, the data request parameters include URL parameters or token request header parameters. Obtaining data request parameters sent by a first data domain based on HTTP and parsing to obtain a trusted identity token includes: obtaining data request parameters sent by an authentication center based on HTTP; the data request parameters are obtained by the authentication center through authenticating the original data request parameters sent by the user side or the service side of the first data domain; the authentication center is used to authenticate the identity of the data request party; parsing the data request parameters to generate a trusted identity token; the trusted identity token includes the identity information of the request party.

[0009] In some alternative implementations, the method further includes: obtaining a token based on the token request header parameter and storing it in the session of the relay server; redirecting to the front-end application corresponding to the relay server based on the token.

[0010] In some alternative implementations, intercepting a corresponding data request based on the data request parameters and the trusted identity token and forwarding it to a second data domain includes: determining a corresponding data request based on the data request parameters; intercepting the corresponding data request according to the trusted identity token; encapsulating the data request according to the parameter requirements of the data request; forwarding the processed data request to the party to be requested in the second data domain.

[0011] In some alternative implementations, receiving response data returned by the second data domain and forwarding it to the first data domain after processing based on a predefined format includes: receiving response data returned by the party to be requested in the second data domain; the response data is returned by the party to be requested after being verified by the authentication center; processing the returned response data according to a predefined format; sending the processed response data to the request party in the first data domain; the request party includes a user browser side or a service side.

[0012] In some alternative implementations, the above-mentioned predefined format includes the Multipurpose Internet Mail Extensions (MIME) format.

[0013] In a second aspect, an embodiment of the present invention provides an HTTP-based data interaction system between multiple data domains. The system includes: a relay server, a first data domain, and a second data domain; at least one of the domain names, protocols, and ports of the first data domain and the second data domain is different; wherein, the relay server includes: a request acquisition unit, configured to acquire data request parameters sent by the first data domain based on HTTP and parse to obtain a trusted identity token; a request forwarding unit, configured to intercept a corresponding data request based on the data request parameters and the trusted identity token and forward it to the second data domain; at least one of the domain names, protocols, and ports of the first data domain and the second data domain is different; the data request includes a user browser request or a service request; a data response unit, configured to receive response data returned by the second data domain and forward it to the first data domain after processing based on a predefined format.

[0014] In a third aspect, an embodiment of the present invention provides a relay server, which is used to configure a relay interface application. The relay server includes: a request acquisition unit, configured to acquire data request parameters sent by the first data domain based on HTTP and parse to obtain a trusted identity token; a request forwarding unit, configured to intercept a corresponding data request based on the data request parameters and the trusted identity token and forward it to the second data domain; at least one of the domain names, protocols, and ports of the first data domain and the second data domain is different; the data request includes a user browser request or a service request; a data response unit, configured to receive response data returned by the second data domain and forward it to the first data domain after processing based on a predefined format.

[0015] In a fourth aspect, an embodiment of the present invention provides an electronic device, including a memory and a processor. A computer program that can run on the processor is stored in the memory. When the processor executes the computer program, the steps of the method described in any item of the first aspect are implemented.

[0016] In a fifth aspect, an embodiment of the present invention provides a computer-readable storage medium. The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are called and run by the processor, the computer-executable instructions cause the processor to run the method described in any item of the first aspect.

[0017] The present invention provides a method and system for data interaction between multiple data domains based on HTTP. The method is applied to a transit server, which is used to configure a transit interface application. The method includes: obtaining data request parameters sent by a first data domain based on HTTP and parsing to obtain a trusted identity token; intercepting a corresponding data request based on the data request parameters and the trusted identity token and forwarding it to a second data domain; at least one of the domain name, protocol, and port of the first data domain and the second data domain is different; the data request includes a user browser request or a service request; receiving response data returned by the second data domain and forwarding it to the first data domain after processing based on a predefined format. By this method, the technical problems of high difficulty in data integration and high data security risks in the prior art are solved, and the technical effects of reducing the difficulty in data integration and improving data security are achieved. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for use in the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0019] Figure 1 It is a schematic flow chart of a method for data interaction between multiple data domains based on HTTP provided by an embodiment of the present invention;

[0020] Figure 2 It is a schematic diagram of the implementation principle of a method for data interaction between multiple data domains based on HTTP provided by an embodiment of the present invention;

[0021] Figure 3 It is a schematic structural diagram of a transit server provided by an embodiment of the present invention;

[0022] Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0023] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and illustrated in the drawings here can be arranged and designed in various different configurations.

[0024] Accordingly, the following detailed description of the embodiments of the present invention provided in the accompanying drawings is not intended to limit the scope of the claimed invention, but merely represents selected embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0025] It should be noted that like reference numerals and letters denote like items in the following drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. Some embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Without conflict, the following embodiments and the features in the embodiments can be combined with each other.

[0026] With the popularization of network technology and the construction of informatization, various offline office and business models have been moved online and are in full swing, bringing great convenience to people's work and life. However, the differences in construction entities and the professionalism of business modules have led to the simplification and isolation of business applications, and further the simplification and isolation of data. This phenomenon causes inconvenience to the need to integrate business and comprehensively analyze data. The vertical construction of business will inevitably face the bottleneck problem of horizontal expansion at a certain stage, and the simplification and isolation of data greatly reduce the quality of data and the need for further analysis and prediction. At the same time, data security is also an important link that cannot be ignored. Integrating applications and integrating data play an important role in improving the quality of informatization, and protecting data security is to protect the achievements of informatization construction.

[0027] That is to say, the prior art faces technical problems such as high difficulty in data integration and high data security risks in the field of network applications. Based on this, the embodiments of the present invention provide a method and system for data interaction between multiple data domains based on HTTP to solve the above technical problems.

[0028] For the convenience of understanding this embodiment, first, a method for data interaction between multiple data domains based on HTTP disclosed in the embodiments of the present invention will be introduced in detail. Refer to Figure 1 the flowchart of a method for data interaction between multiple data domains based on HTTP shown in the figure. This method is applied to a relay server configured with a relay interface application and mainly includes the following steps S110 to S130:

[0029] S110: Obtain the data request parameters sent by the first data domain based on HTTP, and parse to obtain a trusted identity token;

[0030] Among them, the Hypertext Transfer Protocol (HTTP), as the "common language" of Internet infrastructure, directly reusing existing network middleware (such as reverse proxy, cache server) can simplify the deployment and maintenance of cross-domain systems. It is generally used to transfer hypertext from a server to a local browser, and can transfer not only text, but also multimedia content such as images, audio, and video. The wide compatibility of HTTP (any device supporting TCP / IP can achieve it) makes it convenient to connect different technology stacks (such as Java services and Python services) or data protocols (such as database interfaces and message queues).

[0031] In this application, HTTP is used as a standardized connection method for cross-domain communication. Its core value lies in achieving the secure interconnection of heterogeneous systems at a relatively low cost through mature and open protocol features. Compared with private protocols or protocols for specific scenarios, HTTP has the advantages of generality, toolchain support, and infrastructure compatibility in the application of cross-domain data interaction, and is particularly suitable for scenarios that require rapid iteration, compatibility with multiple terminals, and reliance on cloud-native architectures.

[0032] It should be noted that the method provided in the embodiments of this application is not limited to data interaction between multiple data domains based on HTTP, but can also be applied to data interaction between multiple data domains based on HTTPS, that is, secure or HTTP protocol-based data interaction between multiple data domains based on SSL.

[0033] In one embodiment, the data request parameters include URL parameters or token request header parameters; the step of obtaining the data request parameters sent by the first data domain based on HTTP and parsing to obtain a trusted identity token in S110 includes:

[0034] (S11) Obtain the data request parameters sent by the authentication center based on HTTP; the data request parameters are obtained by the authentication center after authenticating the original data request parameters sent by the user side or the service side of the first data domain; the authentication center is used to authenticate the data requester;

[0035] (S12) Parse the data request parameters to generate a trusted identity token; the trusted identity token includes the identity information of the requester.

[0036] In one embodiment, the above method further includes: (S13) Obtain the token based on the token request header parameter and store it in the session of the transfer server; (S14) Redirect to the front-end application corresponding to the transfer server based on the token.

[0037] S120: Intercept the corresponding data request based on the data request parameters and the trusted identity token and forward it to the second data domain; at least one of the domain name, protocol, and port of the first data domain and the second data domain is different; the data request includes a user browser request or a service request;

[0038] In one embodiment, the step of S120 intercepting the corresponding data request based on the data request parameters and the trusted identity token and forwarding it to the second data domain includes:

[0039] (S21) Determine the corresponding data request based on the data request parameters;

[0040] (S22) Intercept the corresponding data request according to the trusted identity token;

[0041] (S23) Perform encapsulation processing on the data request based on the parameter requirements of the data request;

[0042] (S24) Forward the processed data request to the requester in the second data domain.

[0043] S130: Receive the response data returned by the second data domain and forward it to the first data domain after processing based on a predefined format.

[0044] In one embodiment, the step of S130 receiving the response data returned by the second data domain and forwarding it to the first data domain after processing based on a predefined format includes:

[0045] (S31) Receive the response data returned by the requester in the second data domain; the response data is returned by the requester after being verified by the authentication center;

[0046] (S32) Process the returned response data according to the predefined format;

[0047] In one embodiment, the predefined format includes the Multipurpose Internet Mail Extensions (MIME) format. The Multipurpose Internet Mail Extensions (MIME) is a standard used to define the format and type of files sent in Internet protocols such as email and HTTP. In an HTTP response, the MIME type is used to tell the client the content type of the response body (such as text / html, application / json, etc.).

[0048] (S33) Send the processed response data to the requester in the first data domain; the requester includes the user browser side or the service side. That is, according to the content and type of the data returned from other data domains, necessary processing is performed on it, which may include parsing data in JSON, XML, or other formats, extracting useful information, or performing conversion and formatting on it; then the processed data is returned to the user - side browser or service in an appropriate MIME type.

[0049] That is to say, in combination with the above embodiments, the purpose of the present application is to construct a method for request forwarding and data response between multiple data domains based on the Hypertext Transfer Protocol, which uses the common Hypertext Transfer Protocol in network applications and secure connection communication provided by the network security protocol to connect multiple different data domains and integrate applications and data.

[0050] In one embodiment, first, use the Hypertext Transfer Protocol to obtain the URL parameters or request header parameters in the request sent by the authentication center, and parse and decode to obtain the trusted identity token; then use the Hypertext Transfer Protocol to intercept the user or service request, encapsulate and process it according to different application requests, and forward it to the applications in other data domains; then process the data returned by other data domains according to the MIME format and distribute it to the user-side browser or service. This method is simple and easy to implement, can accurately and reliably capture the requests initiated by users or services, forward them to different data domains after encapsulation processing, and then process and distribute the data returned by other data domains according to the MIME format, which has a good effect on communicating with different data domains.

[0051] The above method provided by this embodiment is applicable to the multi-domain communication situation where network channels and monitoring checkpoints have been built between different data domains. On the one hand, it can provide security authentication for the original application system; on the other hand, it can provide reliable support for the communication between multiple data domains.

[0052] As a specific example, in combination with Figure 2 As shown, after the transit interface application configured on the transit server receives the request carrying the token sent by the authentication center, it obtains the token from the request header and stores it in the session, and then redirects to the front-end application; the cross-data domain request initiated by the front-end application is first intercepted by the transit interface application, and after being encapsulated with different parameters according to different request applications, it is forwarded to the checkpoint; after the checkpoint verifies the token, it finds other data domain applications according to the routing path, and the subsequent application gives response data after business operations after receiving the request; after the response data returns to the transit interface application, it is processed according to the MIME type and then distributed, completing a cross-domain request.

[0053] In addition, the embodiment of the present invention also provides a data interaction system between multiple data domains based on HTTP. The system includes: a transit server, a first data domain, and a second data domain; at least one of the domain names, protocols, and ports of the first data domain and the second data domain is different.

[0054] Among them, the transit server includes: a request acquisition unit, a request forwarding unit, and a data response unit.

[0055] The request acquisition unit is used to obtain the data request parameters sent by the first data domain based on HTTP and parse to obtain the trusted identity token; the request forwarding unit is used to intercept the corresponding data request based on the data request parameters and the trusted identity token and forward it to the second data domain; at least one of the domain name, protocol, and port of the first data domain and the second data domain is different; the data request includes a user browser request or a service request; the data response unit is used to receive the response data returned by the second data domain and forward it to the first data domain after processing based on a predefined format.

[0056] In addition, an embodiment of the present invention further provides a relay server, which is used to configure a relay interface application, combined with Figure 3 As shown, the relay server includes:

[0057] A request acquisition unit 310, which is used to obtain the data request parameters sent by the first data domain based on HTTP and parse to obtain the trusted identity token;

[0058] A request forwarding unit 320, which is used to intercept the corresponding data request based on the data request parameters and the trusted identity token and forward it to the second data domain; at least one of the domain name, protocol, and port of the first data domain and the second data domain is different; the data request includes a user browser request or a service request;

[0059] A data response unit 330, which is used to receive the response data returned by the second data domain and forward it to the first data domain after processing based on a predefined format.

[0060] It should be noted that the system provided by the embodiments of the present application is not limited to data interaction between multiple data domains based on HTTP, but can also be applied to data interaction between multiple data domains based on HTTPS, that is, secure or HTTP protocol based on SSL data interaction between multiple data domains. The data interaction system between multiple data domains based on HTTP provided by the embodiments of the present application can be specific hardware on a device or software or firmware installed on the device, etc. The device provided by the embodiments of the present application has the same implementation principle and the same technical effects as the foregoing method embodiments. For the sake of brief description, for the parts not mentioned in the system embodiments, reference can be made to the corresponding content in the foregoing method embodiments. Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the foregoing described system, device, and unit can all refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here. The data interaction system between multiple data domains based on HTTP provided by the embodiments of the present application has the same technical features as the data interaction method between multiple data domains based on HTTP provided by the foregoing embodiments, so it can also solve the same technical problems and achieve the same technical effects.

[0061] An embodiment of the present application further provides an electronic device. Specifically, the electronic device includes a processor and a storage device; a computer program is stored on the storage device, and when the computer program is run by the processor, it executes the method according to any one of the above-described embodiments.

[0062] Figure 4 FIG. 4 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. The electronic device 400 includes: a processor 40, a memory 41, a bus 42, and a communication interface 43. The processor 40, the communication interface 43, and the memory 41 are connected through the bus 42; the processor 40 is configured to execute an executable module stored in the memory 41, such as a computer program.

[0063] Among them, the memory 41 may include a high-speed random access memory (RAM, Random Access Memory), and may also include a non-volatile memory, such as at least one disk memory. Through at least one communication interface 43 (which may be wired or wireless), a communication connection is established between the system network element and at least one other network element, and the Internet, wide area network, local area network, metropolitan area network, etc. can be used.

[0064] The bus 42 may be an ISA bus, a PCI bus, an EISA bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 4 only a bidirectional arrow is used in FIG. 4, but it does not mean that there is only one bus or one type of bus.

[0065] Among them, the memory 41 is used to store a program. After receiving an execution instruction, the processor 40 executes the program. The method executed by the device defined by the process disclosed in any one of the foregoing embodiments of the present invention can be applied to the processor 40 or implemented by the processor 40.

[0066] The processor 40 may be an integrated circuit chip with the ability to process signals. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in the processor 40 or the instructions in the form of software. The above-mentioned processor 40 may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP for short), an application specific integrated circuit (ASIC for short), a field-programmable gate array (FPGA for short) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present invention can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by a combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 41, and the processor 40 reads the information in the memory 41 and combines its hardware to complete the steps of the above method.

[0067] Corresponding to the above method, the embodiment of the present application also provides a computer-readable storage medium, and the computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are called and run by the processor, the computer-executable instructions cause the processor to run the steps of the above method.

[0068] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only illustrative. For example, the division of the units is only a logical function division, and there may be other division methods in actual implementation. For another example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some communication interfaces, and the indirect coupling or communication connection of the devices or units can be in an electrical, mechanical or other form.

[0069] The unit described as a separation component may or may not be physically separated. The component shown as a unit may or may not be a physical unit, that is, it may be located in one place or distributed across multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0070] In addition, each functional unit in the embodiments provided in this application can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0071] If the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on such understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, an electronic device, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0072] It should be noted that similar reference numerals and letters indicate similar items in the drawings. Therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. In addition, the terms "first", "second", "third", etc. are only used for distinguishing descriptions and cannot be understood as indicating or implying relative importance.

[0073] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of various embodiments of the present invention.

Claims

1. A method for data interaction between multiple data domains based on HTTP, characterized in that: Applied to a transit server, the transit server is used to configure a transit interface application, the method comprising: Obtaining data request parameters sent by the first data domain based on HTTP, and parsing and obtaining a trusted identity token; Based on the data request parameter and the trusted identity token, intercept the corresponding data request and forward it to the second data domain; the first data domain and the second data domain have at least one different domain name, protocol and port; the data request includes a user browser request or a service request; Receive response data returned by the second data domain and forward it to the first data domain after processing based on a predefined format.

2. The method for data interaction between multiple data domains based on HTTP according to claim 1, characterized in that: The data request parameters include URL parameters or token request header parameters; Obtaining data request parameters sent by the first data domain based on HTTP, and parsing to obtain a trust identity token, including: Obtaining data request parameters sent by the authentication center based on HTTP; the data request parameters are obtained by the authentication center performing authentication processing on the original data request parameters sent by the user end or the server end of the first data domain; the authentication center is used to authenticate the data requester; The data request parameters are parsed to generate a trusted identity token; the trusted identity token includes identity information of the requester.

3. The method for data interaction between multiple data domains based on HTTP according to claim 2, characterized in that: The method further comprises: Obtaining a token based on the token request header parameter and storing it in the session of the transit server; Redirect to the front-end application corresponding to the transit server based on token.

4. The method for data interaction between multiple data domains based on HTTP according to claim 2, characterized in that: Based on the data request parameter and the trusted identity token, intercepting the corresponding data request and forwarding it to the second data domain includes: determining a corresponding data request based on the data request parameters; intercepting the corresponding data request according to the trusted identity token; Encapsulating the data request based on the parameter requirements of the data request; The processed data request is forwarded to the requesting party of the second data domain.

5. The method for data interaction between multiple data domains based on HTTP according to claim 4, characterized in that: Receiving response data returned by the second data domain and forwarding it to the first data domain after processing based on a predefined format, including: Receiving response data returned by the requesting party in the second data domain; after the response data is verified by the authentication center, it is returned by the requesting party; Processing the returned response data according to a predefined format; The processed response data is sent to the requester of the first data domain; the requester includes a user browser or a server.

6. The method for data interaction between multiple data domains based on HTTP according to claim 5, characterized in that: The predefined format includes Multipurpose Internet Mail Extensions (MIME) format.

7. A multi-data domain data interaction system based on HTTP, characterized in that: The system comprises: a transfer server, a first data domain, and a second data domain; at least one of the domain name, protocol, and port of the first data domain and the second data domain is different; wherein the transfer server comprises: A request acquisition unit, used to acquire data request parameters issued by the first data domain based on HTTP, and parse and acquire a trusted identity token; a request forwarding unit, configured to intercept the corresponding data request based on the data request parameter and the trusted identity token and forward the request to a second data domain; the first data domain and the second data domain have at least one different domain name, protocol and port; the data request includes a user browser request or a service request; A data response unit is used to receive the response data returned by the second data domain and forward it to the first data domain after processing based on a predefined format.

8. A transit server, characterized in that: The relay server is used to configure the relay interface application, and the relay server includes: A request acquisition unit, used to acquire data request parameters issued by the first data domain based on HTTP, and parse and acquire a trusted identity token; a request forwarding unit, configured to intercept the corresponding data request based on the data request parameter and the trusted identity token and forward the request to a second data domain; the first data domain and the second data domain have at least one different domain name, protocol and port; the data request includes a user browser request or a service request; A data response unit is used to receive the response data returned by the second data domain and forward it to the first data domain after processing based on a predefined format.

9. An electronic device comprising a memory and a processor, wherein the memory stores a computer program that can be run on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions prompt the processor to execute the method according to any one of claims 1 to 6.

Citation Information

Cited By

  • HTTP (Hyper Text Transport Protocol) multi-level automatic authentication data migration method and system based on multi-task scheduling

    CN121691353A