Service request processing method and device, computer equipment and readable storage medium

By analyzing and decrypting the request header and request body parameters in HTTP service requests, and generating and sending encrypted service requests, the problem of low data security in HTTP service request processing is solved, and higher data security and reliability are achieved.

CN120091015APending Publication Date: 2025-06-03SHENZHEN COMTOP INFORMATION TECH
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510264247.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-06
Publication Date
2025-06-03

AI Technical Summary

Technical Problem

In HTTP-based service request processing, service requests and response content are easily exposed, resulting in low data security, especially the leakage of sensitive information may cause serious losses to users and enterprises.

Method used

By analyzing the request header parameters and the request body parameters, using a decryption method matching the service type to obtain the target access address and the target service parameters, a second service request is generated and sent to the service end pointed to by the target access address, ensuring the encryption and security of the data during transmission.

Benefits of technology

It improves data security during business request processing, ensures the reliability of request header parameters and request body parameters, and reduces the risk of sensitive information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120091015A_ABST
    Figure CN120091015A_ABST
Patent Text Reader

Abstract

The invention relates to a business request processing method and device, computer equipment, a computer readable storage medium and a computer program product. The method comprises the following steps: analyzing a first service request sent by a request end to obtain a request header parameter; under the condition that the request header parameter passes parameter verification, according to a first decryption mode matched with the service type of the first service request, performing decryption from the request header parameter to obtain a target access address; according to a second decryption mode matched with the service type of the first service request, performing decryption from the request body parameter of the first service request to obtain a target service parameter; sending a second service request generated according to the target access address and the target service parameter to a service end pointed by the target access address so as to indicate the service end to perform service processing according to the target service parameter, and returning an obtained response message; and sending the received response message to the request end. By adopting the method, the data security in service request processing can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a method and apparatus for processing service requests, a computer device, a computer-readable storage medium, and a computer program product. Background Art

[0002] In the Internet application architecture, the processing of service requests based on the HTTP (Hyper Text Transfer Protocol) protocol has long been the mainstream communication mode. Its open feature can effectively improve the compatibility of service systems. In the processing of service requests based on HTTP, service requests and response contents, such as user credentials, transaction information, API (Application Programming Interface) keys, etc., are easily exposed in the network link and are easily intercepted and read by third parties. Especially sensitive information such as user accounts, passwords, personal identity information, and business transaction data, once leaked, will cause serious losses to users and enterprises. Therefore, the data security in the traditional service request processing process is relatively low. Summary of the Invention

[0003] Based on this, it is necessary to provide a method and apparatus for processing service requests, a computer device, a computer-readable storage medium, and a computer program product that can improve data security for the above technical problems.

[0004] In a first aspect, this application provides a method for processing service requests, including:

[0005] Obtain a first service request sent by a request end, and parse request header parameters from the first service request;

[0006] When the request header parameters pass parameter verification, decrypt a target access address from the request header parameters according to a first decryption method that matches the service type of the first service request;

[0007] Decrypt target service parameters from the request body parameters of the first service request according to a second decryption method that matches the service type of the first service request;

[0008] Generate a second service request according to the target access address and the target service parameters, and send the second service request to the service end pointed to by the target access address. The second service request is used to instruct the service end to perform service processing according to the target service parameters and return the obtained response message;

[0009] Receive the response message and send the response message to the request end.

[0010] In one embodiment, decrypting a target access address from request header parameters according to a first decryption method matching the service type of the first service request includes: determining the service type of the first service request and determining a decryption method matching the service type, where the decryption method includes a first decryption method and a second decryption method; decrypting the request header parameters according to the first decryption method to obtain the target access address; decrypting a target service parameter from the request body parameters of the first service request according to a second decryption method matching the service type of the first service request, including: decrypting the request body parameters of the first service request according to the second decryption method to obtain the target service parameter.

[0011] In one embodiment, determining a decryption method matching the service type includes: determining a decryption replacement period for the service type; determining a decryption method matching the service type according to the decryption replacement period and the service type.

[0012] In one embodiment, when the request header parameters pass parameter verification, decrypting a target access address from the request header parameters according to a first decryption method matching the service type of the first service request includes: determining a verification method matching the service type of the first service request; verifying the request header parameters according to the verification method to obtain a parameter verification result; when the parameter verification result is verification passed, decrypting the target access address from the request header parameters according to the first decryption method matching the service type of the first service request.

[0013] In one embodiment, sending a response message to the request end includes: determining a response encryption method for the response message; encrypting the response message according to the response encryption method to obtain an encrypted message; sending the encrypted message to the request end so that the request end decrypts the response message from the encrypted message according to a response decryption method matching the response encryption method.

[0014] In one embodiment, the generation step of the first service request includes: obtaining an original service request with a target access address carried therein; replacing the target access address in the original service request with a proxy address and adding the target access address to the request header parameters of the intermediate service request to obtain an intermediate service request; performing an encryption process on the intermediate service request to obtain the first service request.

[0015] In one embodiment, the intermediate service request is encrypted to obtain a first service request, including: determining an encryption method matching the service type of the original service request, where the encryption method includes a first encryption method and a second encryption method; encrypting the request header parameters in the intermediate service request according to the first encryption method to obtain an encrypted intermediate service request; encrypting the request body parameters in the encrypted intermediate service request according to the second encryption method to obtain a first service request.

[0016] In a second aspect, the present application further provides a service request processing device, including:

[0017] A service request parsing module, configured to obtain a first service request sent by a request end and parse request header parameters from the first service request;

[0018] A request header decryption module, configured to, when the request header parameters pass parameter verification, decrypt a target access address from the request header parameters according to a first decryption method matching the service type of the first service request;

[0019] A request body decryption module, configured to decrypt target service parameters from the request body parameters of the first service request according to a second decryption method matching the service type of the first service request;

[0020] A service request generation module, configured to generate a second service request according to the target access address and the target service parameters, send the second service request to a service end pointed to by the target access address, where the second service request is used to instruct the service end to perform service processing according to the target service parameters and return an obtained response message;

[0021] A response message forwarding module, configured to receive the response message and send the response message to the request end.

[0022] In a third aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps in the above service request processing method are implemented.

[0023] In a fourth aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps in the above service request processing method are implemented.

[0024] In a fifth aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps in the above service request processing method are implemented.

[0025] The above business request processing method, device, computer device, computer-readable storage medium, and computer program product parse the request header parameters from the first business request sent by the request end. When the request header parameters pass the parameter verification, according to the first decryption method matching the business type of the first business request, the target access address is decrypted from the request header parameters, and according to the second decryption method matching the business type of the first business request, the target business parameters are decrypted from the request body parameters of the first business request. A second business request is generated based on the target access address and the target business parameters, and the second business request is sent to the service end pointed to by the target access address, so that the service end processes the service according to the target business parameters and returns a response message, and the received response message is sent to the request end. During the business request processing, after the request header parameters in the first business request pass the parameter verification, according to the first decryption method and the second decryption method matching the business type of the first business request, the target access address and the target business parameters are respectively parsed from the request header parameters and the request body parameters, so as to generate a second business request through the target access address and the target business parameters and send it to the service end for business processing, which can ensure the reliability of the request header parameters and the request body parameters in the first business request, thereby improving the data security during the business request processing. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments of the present application or related technologies. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.

[0027] Figure 1 It is an application environment diagram of the business request processing method in an embodiment;

[0028] Figure 2 It is a flowchart of the business request processing method in an embodiment;

[0029] Figure 3 It is a timing diagram of the business request processing method in an embodiment;

[0030] Figure 4 It is a flowchart of generating the first business request in an embodiment;

[0031] Figure 5 It is a schematic diagram of the architecture of the business request processing system in an embodiment;

[0032] Figure 6 It is a schematic diagram of the architecture of the business request processing system in another embodiment;

[0033] Figure 7 is a structural block diagram of a service request processing device in an embodiment;

[0034] Figure 8 is an internal structure diagram of a computer device in an embodiment. Detailed implementation manners

[0035] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application.

[0036] The service request processing method provided by the embodiments of the present application can be applied to, for example, Figure 1 the application environment shown in the figure. Among them, the terminal 102 communicates with the proxy server 104 through the network. The data storage system of the proxy server 104 can store the data that the proxy server 104 needs to process. The data storage system can be integrated on the proxy server 104, or can be placed on the cloud or other network servers. The service server 106 communicates with the proxy server 104. The data storage system of the service server 106 can store the data that the service server 106 needs to process. The data storage system can be integrated on the service server 106, or can be placed on the cloud or other network servers.

[0037] The terminal 102 can be used as a request end for sending a service request. The terminal 102 can send a first service request to the proxy server 104. The proxy server 104 can parse the request header parameters from the first service request. When the request header parameters pass the parameter verification, according to the first decryption method matching the service type of the first service request, decrypt the target access address from the request header parameters, and according to the second decryption method matching the service type of the first service request, decrypt the target service parameters from the request body parameters of the first service request, and generate a second service request according to the target access address and the target service parameters. The proxy server 104 can send the second service request to the service end pointed to by the target access address. The specific service end can be the service server 106. The service server 106 can perform service processing according to the target service parameters and then return a response message to the proxy server 104. The proxy server 104 can send the received response message to the request end, that is, the proxy server 104 can send the response message to the terminal 102.

[0038] Among them, the terminal 102 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The head-mounted device can be a virtual reality (VR) device, an augmented reality (AR) device, smart glasses, etc. The proxy server 104 or the service server 106 can be an independent physical server, a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.

[0039] In an exemplary embodiment, as Figure 2 shown, a service request processing method is provided. Taking the proxy server in Figure 1 as an example, the method includes the following steps 202 to 210. Among them:

[0040] Step 202, obtain a first service request sent by a request end, and parse request header parameters from the first service request.

[0041] Among them, the request end may include a client that requests service processing. The first service request is a request message for the request end to send to the proxy server to request service processing. The request header (Headers) parameters are the parameters carried in the header of the first service request, and specifically may include, but are not limited to, metadata, authentication, content negotiation, and other metadata.

[0042] Exemplarily, a user may send a first service request to the proxy server through the request end to trigger service processing through the first service request. The proxy server may receive the first service request sent by the request end and parse the first service request to obtain the request header parameters in the first service request. In some embodiments, the first service request may be an http request, that is, the first service request is a request generated based on the http protocol. The proxy server may parse the request header fields in the first service request, so as to extract the request header parameters from the request header fields.

[0043] Step 204, in the case where the request header parameters pass the parameter verification, decrypt a target access address from the request header parameters according to a first decryption method matching the service type of the first service request.

[0044] Among them, the service type is used to characterize the service requirements for the service processing requested by the first service request. Different service types mean different service processing requirements for the corresponding service requests. The first decryption method is a decryption method for decrypting the request header parameters. For example, it can specifically include different methods such as decryption algorithms and decryption orders. The first decryption method matches the service type of the first service request, that is, service requests with different service processing requirements can be decrypted through different decryption methods. The target access address is a parameter decrypted from the request header parameters. The target access address can point to a service server, that is, the target access address can be the address of the service server, so as to perform service processing through the service server pointed to by the target access address.

[0045] Optionally, the proxy server can perform parameter verification on the request header parameters. For example, it can verify the integrity, reliability, etc. of the request header parameters, so as to avoid missing or tampered request header parameters. In some embodiments, the proxy server can determine the verification field parameters from the request header parameters and perform parameter verification on the request header parameters according to the verification field parameters to determine the legality of the request header parameters. For example, the verification field parameters can include an integrity flag and an anti-tampering flag. The proxy server can determine whether the request header parameters are complete and whether they have been tampered with based on the integrity flag and the anti-tampering flag, so as to obtain the corresponding parameter verification result. When the request header parameters are complete and not tampered with, the proxy server can determine that the request header parameters are legal, that is, determine that the request header parameters pass the parameter verification. The proxy server can decrypt the request header parameters to obtain the target access address. The proxy server can determine the service type of the first service request and determine the first decryption method that matches the service type. The proxy server can decrypt the request header parameters according to the first decryption method to obtain the target access address carried in the request header parameters.

[0046] In some embodiments, the first decryption method may include, but is not limited to, at least one of a decryption algorithm and a decryption order. The proxy server can decrypt the request header parameters according to the first decryption method to obtain the required target access address. For example, the first decryption method can include decryption algorithm A and decryption order 1. The proxy server can perform decryption processing on the request header parameters based on decryption algorithm A according to decryption order 1 to obtain the target access address.

[0047] Step 206, decrypt the target service parameters from the request body parameters of the first service request according to the second decryption method that matches the service type of the first service request.

[0048] Among them, the second decryption method is a decryption method for decrypting the request body parameters of the first service request, such as specifically including different methods such as decryption algorithms and decryption orders. The request body parameters are the data topics carried by the service request. The second decryption method matches the service type of the first service request, that is, service requests with different service processing requirements can be decrypted through different decryption methods. The target service parameters are the parameters for which service processing needs to be performed, such as at least one of various parameters such as service query parameters and transaction data query parameters. When different service processes need to be executed through the first service request, the target service parameters can correspond to different service parameters.

[0049] Exemplarily, the proxy server can determine the second decryption method that matches the service type of the first service request, and decrypt the request body parameters in the first service request according to the second decryption method, so as to obtain the target service parameters. In some embodiments, the proxy server can determine the request body parameters from the first service request, such as by identifying them according to the request body fields, so as to determine the request body parameters from the first service request. The proxy server can determine the second decryption method for the request body parameters according to the service type. The second decryption method can be different from the first decryption method. For example, the second decryption method can include decryption algorithm B and decryption order 2. The proxy server can decrypt the request body parameters based on decryption algorithm B according to decryption order 2, so as to obtain the target service parameters carried in the request body parameters.

[0050] Step 208, generate a second service request according to the target access address and the target service parameters, and send the second service request to the service end pointed to by the target access address. The second service request is used to instruct the service end to perform service processing according to the target service parameters and return the obtained response message.

[0051] Among them, the second service request is a service request sent to the service end. The second service request is generated based on the target access address and the target service parameters. The service end can be a device that specifically performs service processing, such as a computer device including a terminal or a server that performs service processing. The response message can include the service processing result corresponding to the service processing performed by the service end according to the target service parameters. For example, the target service parameters can include query parameters for the power grid system, and the response message can include the result obtained by corresponding query according to the query parameters, such as the operation data of the power grid system within a specified time range, specifically including at least one of various operation data such as voltage, current, and power.

[0052] Exemplarily, the proxy server may generate a second service request based on the target access address and the target service parameter. For example, the proxy server may generate a second service request according to the HTTP protocol based on the target access address and the target service parameter, and the second service request is specifically an HTTP request. The proxy server may send the second service request to the service end pointed to by the target access address. For example, the proxy server may determine the service end pointed to by the target access address and send the second service request to the service end. After receiving the second service request, the service end may perform service processing based on the target service parameter in the second service request and obtain a service processing result. The service end may generate a response message for the first service request based on the service processing result and return the response message to the proxy server.

[0053] Step 210, receive the response message and send the response message to the request end.

[0054] Optionally, the proxy server may receive the response message returned by the service end and forward the response message to the request end that sent the first service request, so as to implement the service processing response for the first service request. In some embodiments, the response message includes the service processing result, and the request end may display the service processing result so that the user can intuitively view the service processing result.

[0055] In some embodiments, as Figure 3 shown, the request end may send a first service processing request to the proxy server; after receiving the first service processing request, the proxy server may parse the request header parameter for the first service processing request. When the request header parameter passes the parameter verification, the proxy server decrypts the target access address from the request header parameter and decrypts the target service parameter from the request body parameter; the proxy server may generate a second service request according to the target access address and the target service parameter and send the second service request to the service end. After receiving the second service request, the service end may perform service processing, obtain a response message, and return the response message to the proxy server. The proxy server may send the response message returned by the service end to the request end.

[0056] In the above business request processing method, the request header parameters are parsed from the first business request sent from the request end. When the request header parameters pass the parameter verification, according to the first decryption method matching the business type of the first business request, the target access address is decrypted from the request header parameters, and according to the second decryption method matching the business type of the first business request, the target business parameters are decrypted from the request body parameters of the first business request. A second business request is generated based on the target access address and the target business parameters, and the second business request is sent to the service end pointed to by the target access address, so that the service end processes the business according to the target business parameters and then returns a response message, and the received response message is sent to the request end. During the business request processing, after the request header parameters in the first business request pass the parameter verification, according to the first decryption method and the second decryption method matching the business type of the first business request, the target access address and the target business parameters are respectively parsed from the request header parameters and the request body parameters, so that a second business request is generated through the target access address and the target business parameters and then sent to the service end for business processing, which can ensure the reliability of the request header parameters and the request body parameters in the first business request, thereby improving the data security during the business request processing.

[0057] In an exemplary embodiment, decrypting the target access address from the request header parameters according to the first decryption method matching the business type of the first business request includes: determining the business type of the first business request, and determining the decryption method matching the business type, where the decryption methods include the first decryption method and the second decryption method; decrypting the request header parameters according to the first decryption method to obtain the target access address.

[0058] Among them, the business type can represent the business requirements of the first business request, and different business requirements can correspond to different business types. Different business types can correspond to different decryption methods, and the decryption methods can include the first decryption method for decrypting the request header parameters and the second decryption method for decrypting the request body parameters. In some embodiments, the matching relationship between the business type and the decryption method can be pre-configured according to actual needs.

[0059] Exemplarily, the proxy server can determine the business type of the first business request. For example, the proxy server can determine the type identifier of the first business request and determine the business type of the first business request according to the type identifier. The proxy server can determine the matching decryption method based on the business type. For example, the proxy server can query the pre-configured matching relationship between the business type and the decryption method and determine the decryption method matching the business type of the first business request according to this matching relationship. The proxy server can decrypt the request header parameters according to the first decryption method in the decryption method, thereby obtaining the target access address.

[0060] Further, according to a second decryption method that matches the service type of the first service request, decrypt the target service parameter from the request body parameters of the first service request, including: decrypt the request body parameters of the first service request according to the second decryption method to obtain the target service parameter.

[0061] Optionally, for the request body parameters in the first service request, the proxy server may decrypt the request body parameters based on the second decryption method in the decryption method to obtain the target service parameter.

[0062] In this embodiment, the proxy server may determine a matching decryption method based on the service type of the first service request, and decrypt the request header parameters and the request body parameters respectively through the decryption method, and can perform flexible decryption processing on the request header parameters and the request body parameters respectively, which can ensure the data security of the request header parameters and the request body parameters, thereby improving the data security in the service request processing process.

[0063] In an exemplary embodiment, determining a decryption method that matches the service type includes: determining a decryption replacement period for the service type; and determining a decryption method that matches the service type according to the decryption replacement period and the service type.

[0064] Among them, the decryption replacement period may be the period for replacing the decryption method, and the decryption methods for different service types may be replaced periodically. The decryption replacement period is the period for replacing the decryption method for the service type. The decryption replacement period can be configured according to actual needs, such as 1 week, 1 month or 15 days, etc.

[0065] Optionally, the proxy server may determine the decryption replacement period for the service type, and determine the decryption method that matches the service type in combination with the decryption replacement period and the service type. In some embodiments, the proxy server may determine the current matching relationship between the service type and the decryption method based on the decryption replacement period, and determine the decryption method that matches the service type of the first service request based on the current matching relationship. For different decryption replacement periods, different matching relationships can be configured, so that the proxy server can determine the corresponding matching relationship based on the decryption replacement period of the service type, and determine the decryption method that matches the service type of the first service request based on the corresponding matching relationship.

[0066] In this embodiment, the proxy server may determine a matching decryption method based on the decryption replacement period of the service type and the service type, and can dynamically update the decryption method through the decryption replacement period, which can further ensure the data security in the service request processing process.

[0067] In an exemplary embodiment, when the request header parameter passes parameter verification, the target access address is decrypted from the request header parameter according to the first decryption method matching the service type of the first service request, including: determining the verification method matching the service type of the first service request; verifying the request header parameter according to the verification method to obtain a parameter verification result; when the parameter verification result is verification passed, decrypting the target access address from the request header parameter according to the first decryption method matching the service type of the first service request.

[0068] Among them, the verification method is a method for performing parameter verification on the request header parameter, which may include, for example, a verification algorithm, a verification object, etc. The parameter verification result is the verification result obtained by performing parameter verification on the request header parameter, and the parameter verification result can characterize whether the request header parameter is legal to determine whether the request header parameter passes verification.

[0069] Exemplarily, the proxy server can determine the verification method matching the service type of the first service request, for example, by querying the corresponding verification method based on the service type of the first service request. The verification method may include a verification object and a verification algorithm. For example, the verification object may include an integrity identifier and an anti-tampering identifier, and the verification algorithm may include a verification processing algorithm for the integrity identifier and the anti-tampering identifier, so as to perform integrity verification and reliability verification based on the integrity identifier and the anti-tampering identifier respectively. The proxy server can verify the request header parameter according to the verification method, for example, by verifying the integrity identifier and the anti-tampering identifier, so as to obtain a parameter verification result. When the parameter verification result indicates that the verification of the request header parameter passes, it indicates that the request header parameter belongs to a legal parameter, and the proxy server can decrypt the request header parameter according to the first decryption method to obtain the target access address.

[0070] In this embodiment, the proxy server can verify the request header parameter through the verification method matching the service type of the first service request, and perform decryption processing on the first service request when the verification passes, which can ensure the legality of the request header parameter, thereby improving the data security in the service request processing process.

[0071] In an exemplary embodiment, sending the response message to the request end includes: determining the response encryption method for the response message; encrypting the response message according to the response encryption method to obtain an encrypted message; sending the encrypted message to the request end so that the request end decrypts the response message from the encrypted message according to the response decryption method matching the response encryption method.

[0072] Among them, the response encryption method is a method for encrypting the response message. The response encryption method may specifically include, but is not limited to, encryption algorithms, encryption order, etc. The response decryption method is a decryption method that matches the response encryption method, and the user decrypts the result encrypted according to the response decryption method. The encrypted message is the encrypted result obtained after encrypting the response message.

[0073] Optionally, the proxy server can determine the response encryption method for the response message, and the response encryption method can be pre-configured according to actual needs. In some embodiments, the response encryption method can also match the service type of the first service request, that is, the proxy server can query the response encryption method that matches the service type based on the service type of the first service request. The proxy server can encrypt the response message according to the response encryption method to obtain the encrypted message. The proxy server can send the encrypted message to the request side. After receiving the encrypted message, the request side can decrypt the encrypted message according to the response decryption method that matches the response encryption method to obtain the response message.

[0074] In this embodiment, the proxy server can encrypt the response message according to the response encryption method and then send the encrypted message to the request side, so that the request side can obtain the response message by decrypting the encrypted message through the response decryption method, thereby encrypting the response message and improving the data security in the service request processing process.

[0075] In an exemplary embodiment, as Figure 4 shown, the processing of generating the first service request may include steps 402 to 406. Among them:

[0076] Step 402, obtain the original service request, and the target access address is carried in the original service request.

[0077] Among them, the first service request can be generated by the request side, and the original service request can be the service request originally obtained by the request side. For example, it can be sent by the user through other terminals or configured by the user through the request side. Optionally, the request side can obtain the original service request carrying the target access address, and the target access address points to the service side that needs to perform service processing.

[0078] Step 404, replace the target access address in the original service request with the proxy address, and add the target access address to the request header parameter of the intermediate service request to obtain the intermediate service request.

[0079] Among them, the proxy address can be the address of the proxy server, so that the forwarding of the service request and the forwarding of the service processing result can be realized through the proxy server. The intermediate service request is a request message obtained by updating the address in the original service request. Exemplarily, the requesting end can determine the proxy address of the proxy server and replace the target access address in the original service request, so as to replace the target access address in the original service request with the proxy address. The requesting end can also add the target access address to the request header parameter of the intermediate service request, so as to reconfigure the original service request to obtain the intermediate service request.

[0080] Step 406, perform encryption processing on the intermediate service request to obtain a first service request.

[0081] Optionally, the requesting end can perform encryption processing on the intermediate service request to obtain a first service request to be sent to the proxy server. For example, the requesting end can determine the encryption method for the intermediate service request, and the encryption method can match the service type of the original service request. The requesting end can perform encryption processing on the intermediate service request through the determined encryption method to obtain the first service request. After receiving the first service request sent by the requesting end, the proxy server can decrypt the first service request based on the decryption method matching the encryption method to obtain the required target access address and target service parameters.

[0082] In this embodiment, the requesting end replaces the target access address in the original service request with the proxy address, adds the target access address to the request header parameter of the intermediate service request, and encrypts the obtained intermediate service request to obtain the first service request, which can ensure the reliability of the data in the first service request and thus improve the data security in the service request processing process.

[0083] In an exemplary embodiment, performing encryption processing on the intermediate service request to obtain a first service request includes: determining an encryption method matching the service type of the original service request, where the encryption method includes a first encryption method and a second encryption method; encrypting the request header parameter in the intermediate service request according to the first encryption method to obtain an encrypted intermediate service request; encrypting the request body parameter in the encrypted intermediate service request according to the second encryption method to obtain a first service request.

[0084] Among them, the encryption method matches the service type of the original service request. The service type of the original service request can represent the service processing requirements of the original service request, and different service processing requirements can correspond to different service types. The encryption method can include a first encryption method for encrypting the request header parameter and a second encryption method for encrypting the request body parameter.

[0085] Exemplarily, the requesting end may determine the service type of the original service request and determine an encryption method matching the service type. The encryption method includes a first encryption method and a second encryption method. In some embodiments, the encryption method determined by the requesting end may match the decryption method determined by the proxy server, so that the proxy server may perform decryption processing on the first service request encrypted by the requesting end according to the encryption method. For example, the first encryption method may match the first decrypted method, and the second encryption method may match the second decryption method. The requesting end may encrypt the request header parameters in the intermediate service request according to the first encryption method to obtain the encrypted intermediate service request, and then perform encryption processing on the request body parameters in the encrypted intermediate service request according to the second encryption method to obtain the first service request to be sent to the proxy server. In some embodiments, the requesting end may also first encrypt the request body parameters in the intermediate service request according to the second encryption method to obtain the encrypted intermediate service request, and then encrypt the request header parameters in the encrypted intermediate service request according to the first encryption method to obtain the first service request.

[0086] In this embodiment, the requesting end may encrypt the request header parameters and the request body parameters in the intermediate service request respectively by using an encryption method matching the service type of the original service request, which can ensure the reliability of the request header parameters and the request body parameters in the first service request, thereby improving the data security in the service request processing process.

[0087] This application also provides an application scenario, which applies the above service request processing method. Specifically, the application of the service request processing method in this application scenario is as follows:

[0088] In traditional service request proxy processing, in the face of complex customized requirements and strict security requirements for services, it is difficult to provide strong support in terms of data encryption and custom encryption and decryption schemes. For example, for each part of the head, body, url (Uniform Resource Locator), apiKey (API key), etc. in an HTTP request, it is impossible to perform encryption and decryption operations flexibly, and it is also difficult to regularly modify encryption and decryption methods and key configurations such as apiKey.

[0089] Based on this, the business request processing method provided in this embodiment is based on the HTTP proxy mode and integrates technologies such as data encryption, anti-tampering, and anti-DDoS (Distributed Denial of Service) to achieve stable operation of interface calls in a cross-network environment. In a complex network environment where the opening of network ports requires multiple layers of review and a long cycle, the business request processing method provided in this embodiment can be deeply customized precisely around business requirements and network conditions, showing unparalleled superiority in terms of function adaptability, performance optimization, and security protection, and strongly promoting the efficient implementation of various business cloud projects. Moreover, the business request processing method provided in this embodiment can closely focus on business requirements, quickly respond to and timely process business adjustments. Once a problem is found, it can be processed in real time, greatly improving the timeliness of problem-solving. It shows a high degree of customization ability in aspects such as function adaptability, performance optimization, and security protection, and can fully meet the special requirements of various businesses.

[0090] Specifically, the business request processing method provided in this embodiment can be deeply integrated with the business cloud system. In the business cloud system, users only need to simply configure whether to enable the proxy function and set the proxy address to easily send HTTP requests to the proxy server. Before sending the HTTP request, as the request end, the business cloud system will encrypt some or all of the business information data in the HTTP link according to the specific requirements of the current business. The encryption method will automatically and precisely match according to the different business requirements of each department to ensure the pertinence and effectiveness of encryption.

[0091] After receiving the request, the proxy server will immediately start the security verification process. First, it will strictly verify the legality of the business request and at the same time verify the anti-tampering information in the input parameters to ensure that the business request has not been maliciously tampered with. Subsequently, the proxy server will decrypt each business parameter in the HTTP link, reorganize the HTTP request, and then send it to the business end of the corresponding business system. When the business end of the business system returns the response information, the proxy server will encrypt the response information again and finally return the encrypted response information to the caller, that is, the request end. Through this series of rigorous processes, the security and reliability of data transmission throughout the proxy link are comprehensively guaranteed, laying a solid security line of defense for the stable development of system services.

[0092] Furthermore, as Figure 5As shown in the figure, the cloud management, namely cloud computing management (Cloud Management), can act as the requestor, the cloud management proxy can act as the proxy server, and the business terminals in each region can act as the business terminals. From the application program to the cloud management proxy service and then to the underlying real server, the combination of each process, encryption parameters, anti-tampering measures, and the return of encrypted business data in the entire proxy mode effectively meets the requirements of the business and the group. Specifically, the cloud management sends an HTTP request, uniformly replaces the original URL address with the proxy address, and at the same time encrypts the real URL and saves it in the Head. The proxy receives the request, parses out the real URL and sends the request, and returns the response content to the cloud management. In the cloud business system, by verifying and enabling the proxy switch, the HTTP request is re-encapsulated, encrypted, and anti-tampered with, and finally assembled into a new HTTP request and sent to the proxy server. Among them, the cloud management can configure the proxy switch, so that it can choose whether to enable the proxy server according to actual needs. The cloud management can replace the URL address, encrypt the head parameters (request header parameters) and body parameters (request body parameters) respectively, and perform DDoS processing on the HTTP request. The cloud management can send the HTTP request to the proxy server. The proxy server can perform DDoS verification on the HTTP request and verify the URL permissions, that is, verify whether it has the access permission to the target access address URL. The proxy server can also verify the head parameters, and when the verification passes, it can decrypt the head parameters and body parameters respectively. The proxy server can build a new request based on the head parameters and body parameters and send it to the business terminal for the business terminal to perform business processing. For example, it can be sent to the corresponding business terminal for business processing through various APIs such as user service API, network service API, basic service API, monitoring service API, or tenant service API.

[0093] Furthermore, as Figure 6 shown in the figure, the management platform can manage the business processing in multiple regions. The internal networks between each region can be shielded, and a corresponding proxy server can be set in each region to communicate with the corresponding business terminal through the proxy server to implement business request processing. The business request processing method provided in this embodiment does not require deploying the cloud management in each region to collect business data, enabling the management platform to grasp the business data in each region in real time, while greatly saving labor costs and the risks of installation and operation and maintenance operations.

[0094] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments, and the execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0095] Based on the same inventive concept, an embodiment of the present application further provides a service request processing apparatus for implementing the service request processing method described above. The solution provided by this apparatus for solving problems is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the service request processing apparatus provided below can refer to the limitations on the service request processing method in the foregoing, and will not be repeated here.

[0096] In an exemplary embodiment, as Figure 7 shown, a service request processing apparatus 700 is provided, including: a service request parsing module 702, a request header decryption module 704, a request body decryption module 706, a service request generation module 708, and a response message forwarding module 710, where:

[0097] The service request parsing module 702 is configured to obtain a first service request sent by a request end, and parse request header parameters from the first service request;

[0098] The request header decryption module 704 is configured to, when the request header parameters pass parameter verification, decrypt a target access address from the request header parameters according to a first decryption method matching the service type of the first service request;

[0099] The request body decryption module 706 is configured to decrypt target service parameters from the request body parameters of the first service request according to a second decryption method matching the service type of the first service request;

[0100] The service request generation module 708 is configured to generate a second service request according to the target access address and the target service parameters, and send the second service request to the service end pointed to by the target access address. The second service request is used to instruct the service end to perform service processing according to the target service parameters and return the obtained response message;

[0101] A response message forwarding module 710, configured to receive a response message and send the response message to the request side.

[0102] In an exemplary embodiment, the request header decryption module 704 is further configured to determine the service type of the first service request and determine a decryption method matching the service type. The decryption methods include a first decryption method and a second decryption method; decrypt the request header parameters according to the first decryption method to obtain a target access address; the request body decryption module 706 is further configured to decrypt the request body parameters of the first service request according to the second decryption method to obtain target service parameters.

[0103] In an exemplary embodiment, the request header decryption module 704 is further configured to determine a decryption replacement period for the service type; determine a decryption method matching the service type according to the decryption replacement period and the service type.

[0104] In an exemplary embodiment, the request header decryption module 704 is further configured to determine a verification method matching the service type of the first service request; verify the request header parameters according to the verification method to obtain a parameter verification result; in the case where the parameter verification result is verified to pass, decrypt the target access address from the request header parameters according to the first decryption method matching the service type of the first service request.

[0105] In an exemplary embodiment, the response message forwarding module 710 is further configured to determine a response encryption method for the response message; encrypt the response message according to the response encryption method to obtain an encrypted message; send the encrypted message to the request side so that the request side decrypts the response message from the encrypted message according to a response decryption method matching the response encryption method.

[0106] In an exemplary embodiment, a first request generation module is further included, configured to obtain an original service request, where the original service request carries a target access address; replace the target access address in the original service request with a proxy address and add the target access address to the request header parameters of the intermediate service request to obtain an intermediate service request; perform an encryption process on the intermediate service request to obtain a first service request.

[0107] In an exemplary embodiment, the first request generation module is further configured to determine an encryption method matching the service type of the original service request. The encryption methods include a first encryption method and a second encryption method; encrypt the request header parameters in the intermediate service request according to the first encryption method to obtain an encrypted intermediate service request; encrypt the request body parameters in the encrypted intermediate service request according to the second encryption method to obtain a first service request.

[0108] Each module in the above-mentioned service request processing device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0109] In an exemplary embodiment, a computer device is provided. The computer device can be a server or a terminal, and its internal structure diagram can be as Figure 8 shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store various data such as a first service request, request header parameters, a first decryption method, a target access address, a second decryption method, target service parameters, a second service request, or a response message. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a service request processing method.

[0110] Those skilled in the art can understand that Figure 8 the structure shown in

[0111] is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0112] In an embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0113] In an embodiment, a computer-readable storage medium is provided, storing a computer program, and when the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0114] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.

[0115] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in this application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in this application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.

[0116] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this application.

[0117] The above-described embodiments merely represent several implementation manners of this application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of this application. It should be noted that for those of ordinary skill in the art, without departing from the concept of this application, several modifications and improvements can still be made, and these all belong to the protection scope of this application. Therefore, the protection scope of this application shall be subject to the appended claims.

Claims

1. A method for processing a business request, characterized in that: The method comprises: Obtaining a first service request sent by a requesting end, and parsing the first service request to obtain a request header parameter; In a case where the request header parameter passes parameter verification, decrypting the request header parameter to obtain a target access address according to a first decryption method that matches the service type of the first service request; decrypting the request body parameters of the first service request to obtain target service parameters according to a second decryption method that matches the service type of the first service request; Generate a second service request according to the target access address and the target service parameter, and send the second service request to the service end pointed to by the target access address, wherein the second service request is used to instruct the service end to perform service processing according to the target service parameter and return the obtained response message; The response message is received, and the response message is sent to the requesting end.

2. The method according to claim 1, characterized in that Decrypting the request header parameter to obtain the target access address according to the first decryption method matching the service type of the first service request includes: Determine a service type of the first service request, and determine a decryption method matching the service type, wherein the decryption method includes a first decryption method and a second decryption method; Decrypt the request header parameters according to the first decryption method to obtain the target access address; The decrypting the request body parameters of the first service request to obtain the target service parameters according to the second decryption method matching the service type of the first service request includes: Decrypt the request body parameters of the first service request according to the second decryption method to obtain target service parameters.

3. The method according to claim 2, characterized in that The determining of a decryption method matching the service type includes: Determine a decryption replacement cycle for the service type; According to the decryption change cycle and the service type, a decryption method matching the service type is determined.

4. The method according to claim 1, characterized in that: The step of decrypting the request header parameters to obtain the target access address in accordance with a first decryption method matching the service type of the first service request when the request header parameters pass the parameter verification includes: Determining a verification method that matches a service type of the first service request; Verify the request header parameters according to the verification method to obtain parameter verification results; When the parameter verification result is that the verification is passed, the target access address is decrypted from the request header parameter in accordance with a first decryption method that matches the service type of the first service request.

5. The method according to claim 1, characterized in that The sending the response message to the requesting end includes: Determining a response encryption method for the response message; Encrypt the response message according to the response encryption method to obtain an encrypted message; The encrypted message is sent to the requesting end, so that the requesting end decrypts the encrypted message according to a response decryption method matching the response encryption method to obtain the response message.

6. The method according to any one of claims 1 to 5, characterized in that The step of generating the first service request includes: Obtaining an original service request, wherein the original service request carries a target access address; Replacing the target access address in the original service request with a proxy address, and adding the target access address to a request header parameter of the intermediate service request to obtain an intermediate service request; The intermediate service request is encrypted to obtain a first service request.

7. The method according to claim 6, characterized in that The encrypting the intermediate service request to obtain the first service request includes: Determine an encryption method that matches the service type of the original service request, wherein the encryption method includes a first encryption method and a second encryption method; Encrypting the request header parameters in the intermediate service request according to the first encryption method to obtain an encrypted intermediate service request; The request body parameters in the encrypted intermediate service request are encrypted according to the second encryption method to obtain a first service request.

8. A service request processing device, characterized in that: The device comprises: A service request parsing module, used to obtain a first service request sent by a request end, and parse the first service request to obtain a request header parameter; a request header decryption module, configured to decrypt the request header parameters to obtain a target access address in accordance with a first decryption method matching a service type of the first service request when the request header parameters pass parameter verification; a request body decryption module, configured to decrypt the request body parameters of the first service request to obtain target service parameters according to a second decryption method matching the service type of the first service request; A service request generation module, used to generate a second service request according to the target access address and the target service parameters, and send the second service request to the service end pointed to by the target access address, wherein the second service request is used to instruct the service end to perform service processing according to the target service parameters and return the obtained response message; The response message forwarding module is used to receive the response message and send the response message to the requesting end.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.