Object access method and device and readable storage medium
By performing multiple verification and analysis of the access strategy, the problem of low access efficiency during the seller's access process is solved, and the demand for fast and large-scale access to sellers is achieved, and the access efficiency and system security are improved.
Patent Information
- Application Number
- CN202510197959.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-21
- Publication Date
- 2025-06-10
AI Technical Summary
In the prior art, the access efficiency of sellers during the access process is low, and relying on human experience and "patching" methods, it cannot meet the market's demand for fast and large-scale access to sellers.
By obtaining the access policy of the target object, performing multiple verifications and analysis, ensuring the accuracy of the access policy, and connecting the target object to the target system according to the access policy.
It improves the access efficiency of sellers during the access process, reduces manpower investment, reduces the risk of system transformation, and achieves the demand for fast and large-scale access to sellers.
Smart Images

Figure CN120123210A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of big data, and in particular, to a method, an apparatus, and a readable storage medium for accessing an object. Background Art
[0002] Currently, the core system related to fund raising undertakes important responsibilities such as accepting transaction applications from sales channels, managing investor accounts, recording investors' share rights and interests, and various business changes, covering the entire process from product raising, establishment, operation to liquidation. In order to further broaden sales channels and enrich product types, new distributors are continuously connected to sell wealth management products on a commission basis. During the process of connecting distributors, multiple complex factors such as data interaction protocols, time, and channels are involved. Since the initial design of the core system related to the fund raising end did not foresee the need for multi-distributor access, for the access of new distributors, the core system related to fund raising has undergone multiple transformations and has been gradually improved by means of "patching". Each time a new distributor is connected, it is necessary to start from the working perspective of the core system related to fund raising, convert the actual business content of the distributor into technical requirements, and judge the compatibility with the system one by one, as well as whether system transformation is required. Before the formal connection, developers also need to judge and verify again, and pass multiple tests by testers.
[0003] In the related art, the process of connecting a distributor to the current core system related to fund raising takes a long time and requires a huge amount of human input. The entire process relies too much on the experience and carefulness of the docking personnel, and there are many uncertain risks from docking to formal production and operation. The traditional method relying on manpower and "patching" no longer meets the market's demand for quickly and massively connecting distributors. Therefore, there is a problem of low access efficiency in the process of connecting distributors.
[0004] In view of the problem of low access efficiency in the process of connecting distributors in the related art, no effective solution has been proposed yet. Summary of the Invention
[0005] The main purpose of the present application is to provide a method, an apparatus, and a readable storage medium for accessing an object, so as to solve the problem of low access efficiency in the process of connecting distributors in the related art.
[0006] To achieve the above object, according to one aspect of the present application, a method for accessing an object is provided. The method includes: obtaining an access policy for a target object, where the access policy is used to indicate the rules for accessing the target object to a target system; verifying the access policy to obtain a first verification result, where the first verification result is used to indicate the matching degree between the access policy and the target system; in response to the first verification result indicating successful verification of the access policy, parsing the access policy to obtain a parsing result; verifying the parsing result to obtain a second verification result; and in response to the second verification result indicating successful verification of the parsing result, accessing the target object to the target system according to the access policy.
[0007] Optionally, verifying the access policy to obtain a first verification result includes: extracting parameter dependency information in the access policy, where the parameter dependency information is used to indicate the dependency relationship between different parameters in the access policy; and verifying the access policy based on the parameter dependency information to obtain a first verification result.
[0008] Optionally, in response to the first verification result indicating successful verification of the access policy, parsing the access policy to obtain a parsing result includes: in response to the first verification result indicating successful verification of the access policy, extracting parameter information in the access policy, where the parameter information is used to indicate information of the target object; converting the parameter information into behavior information, where the behavior information is used to indicate the operation behavior of accessing the target object; and determining the behavior information as the parsing result.
[0009] Optionally, the method for accessing an object further includes: in response to the second verification result indicating failure to verify the parsing result, re-obtaining the modified access policy for the target object.
[0010] Optionally, the method for accessing an object further includes: obtaining permission information of the management account of the target system; determining output information in the target system based on the permission information, where the output information is used to indicate information of the target object output in the target system; and outputting the output information to the client logged in by the management account.
[0011] Optionally, the method for accessing an object further includes: outputting the first verification result, the second verification result, and the access policy.
[0012] To achieve the above object, according to another aspect of the present application, there is provided an access device for an object. The device includes: an acquisition unit configured to acquire an access policy for a target object, where the access policy is used to indicate the rules for accessing the target object to a target system; a first verification unit configured to verify the access policy to obtain a first verification result, where the first verification result is used to indicate the matching degree between the access policy and the target system; an analysis unit configured to, in response to the first verification result indicating successful verification of the access policy, analyze the access policy to obtain an analysis result; a second verification unit configured to verify the analysis result to obtain a second verification result; and an access unit configured to, in response to the second verification result indicating successful verification of the analysis result, access the target object to the target system according to the access policy.
[0013] To achieve the above object, according to another aspect of the present application, there is provided a computer-readable storage medium. The computer-readable storage medium includes a stored program, where when the program is run by a processor, it controls the device where the storage medium is located to execute the object access method in the embodiments of the present invention.
[0014] To achieve the above object, according to another aspect of the present application, there is provided an electronic device. A memory stores an executable program; a processor is configured to run the program, where when the program runs, it executes the object access method in the embodiments of the present invention.
[0015] To achieve the above object, according to another aspect of the present application, there is provided a computer program product. The program product includes computer instructions that, when executed by a processor, implement the object access method in the embodiments of the present invention.
[0016] In the embodiments of the present application, an access policy for a target object is acquired, where the access policy is used to indicate the rules for accessing the target object to a target system; the access policy is verified to obtain a first verification result, where the first verification result is used to indicate the matching degree between the access policy and the target system; in response to the first verification result indicating successful verification of the access policy, the access policy is analyzed to obtain an analysis result; the analysis result is verified to obtain a second verification result; and in response to the second verification result indicating successful verification of the analysis result, the target object is accessed to the target system according to the access policy. That is to say, the present invention verifies the access policy to obtain a first verification result. When the first verification result passes, the access policy is analyzed, and then the analysis result is verified again. When the verification passes, the target object is accessed to the target system according to the access policy. Since the present invention can verify the access policy multiple times, the accuracy of the access policy is ensured, and thus the technical effect of improving the access efficiency in the reseller access process is achieved, and the technical problem of low access efficiency in the reseller access process is solved. Description of the Drawings
[0017] The accompanying drawings, which form a part of this application, are used to provide a further understanding of this application. The schematic embodiments and descriptions thereof of this application are used to explain this application and do not constitute an improper limitation to this application. In the drawings:
[0018] Figure 1 is a hardware structural block diagram of a computer terminal for implementing an object access method according to an embodiment of this application;
[0019] Figure 2 is a flowchart of an object access method according to an embodiment of this application;
[0020] Figure 3 is a flowchart of a flow visualization-based automatic access method for a vendor according to an embodiment of this application;
[0021] Figure 4 is a schematic diagram of an object access device according to an embodiment of this application;
[0022] Figure 5 is a structural block diagram of an electronic device according to an embodiment of this application. Detailed implementation manners
[0023] In order to enable those skilled in the art to better understand the solutions of this application, the technical solutions in the embodiments of this application will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of this application.
[0024] It should be noted that the terms "first", "second", etc. in the specification and claims of this application and the above-mentioned accompanying drawings are used to distinguish similar objects and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of this application described here can be implemented in an order other than those illustrated or described here. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units does not necessarily need to be limited to those clearly listed steps or units, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products, or devices.
[0025] According to an embodiment of the present application, an embodiment of an access method for an object is further provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.
[0026] The access method for the object provided by the embodiment of the present application can be executed in a mobile terminal, a computer terminal, or a similar computing device. Figure 1 It is a hardware structure block diagram of a computer terminal for implementing an access method for an object according to an embodiment of the present invention. As Figure 1 shown, the computer terminal 10 (or mobile device) may include one or more processors 102 (shown as 102a, 102b,..., 102n in the figure) (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA), a memory 104 for storing data, and a transmission device 106 for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the BUS bus), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 the structure shown is only illustrative and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown, or have a different configuration from Figure 1 shown.
[0027] It should be noted that the above one or more processors 102 and / or other data processing circuits are generally referred to as "data processing circuits" in this article. The data processing circuit can be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of the other elements in the computer terminal 10 (or mobile device). As involved in the embodiment of the present application, the data processing circuit is a processor control (such as the selection of a variable resistance terminal path connected to an interface).
[0028] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the object access method in the embodiments of the present application. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the above-mentioned object access method. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely disposed relative to the processor 102, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above network include but are not limited to the Internet, enterprise intranets, local area networks, mobile communication networks, and combinations thereof.
[0029] The transmission device 106 can be used to receive or send data via a network. Specific examples of the above network may include a wireless network provided by the communication provider of the computer terminal 10. In one instance, the transmission device 106 includes a network adapter (Network Interface Controller, abbreviated as NIC), which can be connected to other network devices through a base station and thus can communicate with the Internet. In one instance, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.
[0030] The display can be, for example, a touch-screen liquid crystal display (Liquid Crystal Display, abbreviated as LCD), and the liquid crystal display enables a user to interact with the user interface of the computer terminal 10 (or mobile device).
[0031] Under the above operating environment, the present application provides an object access method as Figure 2 shown. Figure 2 It is a flowchart of an object access method provided according to an embodiment of the present application.
[0032] Step S201, obtain the access policy of the target object.
[0033] In the technical solution provided in step S201 of the present invention above, the access policy is used to indicate the rules for accessing the target object to the target system. Among them, the target object can also be called the vendor parameter to be accessed, and the access policy can also be called the access plan.
[0034] In this embodiment, to obtain the access policy of the target object, for example, by obtaining the access policy input by the business personnel. This is only an exemplary example here and does not limit the specific method for obtaining the access policy of the target object.
[0035] For example, an access parameter visualization page is provided, where business personnel can add vendors to be accessed, modify parameters, and display all the parameters of the vendors to be accessed. After the solution parameters pass multiple-level approvals, they are submitted to the target system.
[0036] Step S202: Verify the access policy to obtain a first verification result.
[0037] In the technical solution provided in step S202 of the present invention, the first verification result is used to indicate the matching degree between the access policy and the target system.
[0038] In this embodiment, after obtaining the access policy of the target object in step S201, the access policy is verified to obtain a first verification result. For example, a test tool is used to perform a preliminary security check on the access policy, that is, verification. Here, it is only an exemplary example and does not limit the specific method of verifying the access policy.
[0039] For example, a security test tool is used to perform vulnerability scanning and other methods to comprehensively check and verify the access solution to ensure that the solution meets the standards.
[0040] Optionally, by verifying the access policy, the rationality and effectiveness of the access policy are ensured, loopholes and problems are avoided, and the security and stability of the system are improved.
[0041] Step S203: In response to the first verification result indicating that the access policy verification is successful, parse the access policy to obtain a parsing result.
[0042] In the technical solution provided in step S203 of the present invention, when the first verification result indicates that the access policy verification is successful, it means that the access policy passes the preliminary security check. Based on this, the access policy can be parsed to obtain a parsing result.
[0043] In this embodiment, after obtaining the first verification result in step S202, according to the first verification result, the access policy is parsed to obtain a parsing result. For example, the dependency relationship between the parameters of the access policy is parsed to determine the rationality, conflictiveness, and logic of the access policy. Here, it is only an exemplary example and does not limit the specific method of parsing the access policy.
[0044] For example, the access solution submitted by business personnel is routed to the vendor management center through the pre-node for preliminary security check, that is, verification of the access solution. After the preliminary check passes, the dependency relationship of each parameter is parsed and checked.
[0045] Optionally, by analyzing the dependencies between parameters, it can be ensured that the access policy is feasible in practical applications and no unreasonable situations will occur. At the same time, by analyzing the access policy, potential conflicts between different parameters can be discovered, avoiding problems during implementation.
[0046] Step S204: Verify the parsing result to obtain a second verification result.
[0047] In the technical solution provided in step S204 of the present invention, after obtaining the parsing result in step S203, the parsing result is verified to obtain a second verification result.
[0048] In this embodiment, the parsing result is verified. For example, the parsing result is manually verified. This is only an exemplary example here and does not limit the specific method of verifying the parsing result, to obtain a second verification result.
[0049] For example, the access solutions that pass the preliminary screening will be pushed to the access administrator of the target system reseller for manual verification.
[0050] Optionally, verifying the parsing result can ensure the accuracy and integrity of the parsing process, avoiding data errors or system failures caused by parsing errors. Obtaining the second verification result can further confirm the correctness of the data, improving the reliability and security of data processing. By comparing the verification results, potential problems can be discovered and corrected in a timely manner, ensuring the accuracy and consistency of the data. This can effectively avoid risks and losses caused by data errors, improving data quality and processing efficiency.
[0051] Step S205: In response to the second verification result indicating successful verification of the parsing result, access the target object to the target system according to the access policy.
[0052] In the technical solution provided in step S205 of the present invention, the target system can be a core system related to the raising of wealth management funds.
[0053] In this embodiment, after verifying the parsing result in step S204 to obtain the second verification result, when the second verification result indicates successful verification of the parsing result, it means that the access policy passes the verification, and based on this, the target object can be accessed according to the access policy, and the target object is accessed to the target system according to the access policy.
[0054] Optionally, after strict verification and review, the access policy can effectively reduce the risk of system attacks and ensure the security of the system.
[0055] It should be noted that the above embodiments can be executed by the access device of the object.
[0056] In this embodiment, an access policy for a target object is obtained, where the access policy is used to indicate the rules for accessing the target object to the target system; the access policy is verified to obtain a first verification result, where the first verification result is used to indicate the matching degree between the access policy and the target system; in response to the first verification result indicating that the access policy verification is successful, the access policy is parsed to obtain a parsing result; the parsing result is verified to obtain a second verification result; in response to the second verification result indicating that the parsing result verification is successful, the target object is accessed to the target system according to the access policy. That is to say, the present invention verifies the access policy to obtain a first verification result. After the first verification result passes, the access policy is parsed, and then the parsing result is verified again. After the verification passes, the target object is accessed to the target system according to the access policy. Since the present invention can verify the access policy multiple times, the accuracy of the access policy is ensured, and the technical effect of improving the access efficiency in the process of accessing the reseller is achieved, and the technical problem of low access efficiency in the process of accessing the reseller is solved.
[0057] The above method of this embodiment will be further introduced below.
[0058] As an optional embodiment, in the object access method provided in the embodiments of the present application, verifying the access policy to obtain a first verification result includes: extracting parameter dependency information in the access policy, where the parameter dependency information is used to indicate the dependency relationship between different parameters in the access policy; based on the parameter dependency information, verifying the access policy to obtain a first verification result.
[0059] In this embodiment, the parameter dependency information in the access policy is extracted, and based on the parameter dependency information, the access policy is verified to obtain a first verification result. For example, by checking whether the parameters meet the requirements of the specified format, type, value range, etc., the first verification result is determined. This is only an exemplary example and does not limit the specific method of verifying the access policy to obtain the first verification result.
[0060] For example, according to the parameter dependency information, the parameter dependency rules defined in the access policy are determined, and the input parameters are verified. The verification program can check whether the parameters meet the requirements of the specified format, type, value range, etc., and at the same time, it is also necessary to check whether the logical relationship between the parameters meets the conditions.
[0061] Optionally, by verifying the access policy, the rationality and logic of the access policy can be ensured, thereby improving the efficiency of accessing the target object to the target system.
[0062] As an alternative embodiment, in the object access method provided in the embodiments of the present application, in response to the first verification result indicating successful verification of the access policy, the access policy is parsed to obtain a parsing result, including: in response to the first verification result indicating successful verification of the access policy, extracting parameter information in the access policy, where the parameter information is used to indicate information about the target object; converting the parameter information into behavior information, where the behavior information is used to indicate the operation behavior of accessing the target object; and determining the behavior information as the parsing result.
[0063] In this embodiment, when the first verification result indicates successful verification of the access policy, it means that the access policy passes the verification. Based on this, the parameter information in the access policy is extracted, and thus the parameter information is translated into behavior information to determine the operation behavior of accessing the target object to the target system, and then the behavior information is determined as the parsing result.
[0064] For example, the access solutions that pass the preliminary screening will be pushed to the access administrator of the target system reseller for manual verification, and parameter parsing will be performed through a pre-configured template and translated into behavior descriptions.
[0065] Optionally, by extracting the parameter information in the access policy and translating it into behavior information, the operation behavior of accessing the target object to the target system can be determined more quickly, thus saving time and improving operation efficiency.
[0066] As an alternative embodiment, in the object access method provided in the embodiments of the present application, the object access method includes: in response to the second verification result indicating failure in verifying the parsing result, re-obtaining the modified access policy of the target object.
[0067] In this embodiment, when the second verification result indicates failure in verifying the parsing result, it means that there is a problem with the access solution and adjustment is needed. Based on this, the access solution is output, and the business personnel are reminded to modify the solution, so as to re-obtain the access policy.
[0068] Optionally, through the feedback of the second verification result, the problems existing in the access solution can be discovered in time, prompting the business personnel to modify and adjust the solution, thereby improving the accuracy and reliability of the access solution.
[0069] As an alternative embodiment, in the object access method provided in the embodiments of the present application, the object access method includes: obtaining the permission information of the management account of the target system; based on the permission information, determining the output information in the target system, where the output information is used to indicate the information of the target object output in the target system; and outputting the output information to the client logged in by the management account.
[0070] In this embodiment, the permission information of the management account is obtained, and then the output information in the target system is determined according to the permission information, where the output information may include the parameters of the vendor. After determining the output information, the output information is output to the management account.
[0071] For example, a metadata management page is provided, and only the viewing permission is open to business personnel for interpreting all vendor parameters. Technical personnel have the modification permission.
[0072] Optionally, determining the output content through the permissions of the management account can restrict business personnel to only view the management page of the output content, which can avoid the risk of misoperation or leakage of sensitive data and ensure data security.
[0073] As an alternative embodiment, in the object access method provided in the embodiments of the present application, the object access method includes: outputting a first verification result, a second verification result, and an access policy.
[0074] In this embodiment, a first verification result, a second verification result, and an access policy are output. For example, the inspection results are pushed to business personnel and system maintenance personnel in various forms such as phone calls, text messages, and emails. This is only an exemplary example and does not limit the specific manner of outputting the first verification result, the second verification result, and the access policy.
[0075] Optionally, pushing in multiple forms can improve the timeliness and comprehensiveness of information transmission. Different people may prefer to use different communication methods, and pushing in multiple forms can ensure that information can reach and be received in a timely manner.
[0076] It should be noted that the above embodiments can be executed by an object access device.
[0077] The access method for an object provided by an embodiment of the present application obtains an access policy for a target object, where the access policy is used to indicate the rules for accessing the target object to a target system; verify the access policy to obtain a first verification result, where the first verification result is used to indicate the matching degree between the access policy and the target system; in response to the first verification result indicating successful verification of the access policy, parse the access policy to obtain a parsing result; verify the parsing result to obtain a second verification result; in response to the second verification result indicating successful verification of the parsing result, access the target object to the target system according to the access policy. That is to say, the present invention verifies the access policy to obtain a first verification result. After the first verification result passes, the access policy is parsed, and then the parsing result is verified again. After the verification passes, the target object is accessed to the target system according to the access policy. Since the present invention can verify the access policy multiple times, the accuracy of the access policy is ensured, and the technical effect of improving the access efficiency in the process of accessing a distributor is achieved, and the technical problem of low access efficiency in the process of accessing a distributor is solved.
[0078] The technical solution of the embodiment of the present invention will be illustrated by way of preferred embodiments below.
[0079] At present, the core system related to fund raising undertakes the important responsibilities of accepting transaction applications from sales channels, managing investor accounts, recording investor share rights and interests, and various business changes, covering the whole process from product raising, establishment, operation to liquidation. In order to further broaden sales channels and enrich product types, new distributors are constantly accessed to sell financial products on a commission basis. In the process of accessing a distributor, multiple complex factors such as data interaction protocols, time, and channels are involved. Since the initial design of the core system related to the fund raising end did not foresee the need for multi-distributor access, for the access of new distributors, the core system related to fund raising has undergone multiple transformations and has been gradually improved by means of "patching". Each time a new distributor is accessed, it is necessary to start from the working perspective of the core system related to fund raising, convert the actual business content of the distributor into technical requirements, and judge the compatibility with the system one by one, as well as whether system transformation is required. Before formal access, developers also need to judge and verify again, and pass multiple tests by testers.
[0080] In the related art, the process of the current core system related to fund raising accessing the resellers takes a long time and requires a huge amount of human input. The whole process relies too much on the experience and attentiveness of the docking personnel, and there are many uncertain risks from docking to formal production and operation. The traditional method relying on manpower and "patching" no longer meets the market's demand for quickly and massively accessing resellers. Therefore, there is a problem of low access efficiency in the process of reseller access. For the problem of low access efficiency in the process of reseller access in the related art, no effective solution has been proposed yet.
[0081] However, the embodiment of the present invention proposes an automatic reseller access method with process visualization. By managing all the parameters of existing and to-be-accessed resellers in the form of metadata and displaying them on the front-end page, and using the process center for circulation, the human cost is greatly reduced, the access efficiency is improved, and the technical effect of enhancing the access efficiency in the process of reseller access is realized, and the technical problem of low access efficiency in the process of reseller access is solved.
[0082] The following further introduces the embodiment of the present invention.
[0083] Figure 3 It is a flowchart of an automatic reseller access method with process visualization provided according to an embodiment of the present application. The automatic reseller access method with process visualization includes the following steps:
[0084] Step S301, obtain the solution parameters.
[0085] In this embodiment, a visualization page for access parameters is provided, where business personnel can add to-be-accessed resellers, modify parameters, and display all the parameters of to-be-accessed resellers. After the solution parameters pass through multiple-level approvals, they are submitted to the target system.
[0086] Optionally, the parameters of to-be-accessed resellers refer to the reseller-related information that business personnel need to add or modify, including the name, contact information, address, business scope, cooperation agreement, etc. of the reseller. These parameters are used to describe the basic information and cooperation conditions of the reseller so that the system can accurately process the business data of the reseller. Before being submitted to the target system, multiple-level approvals are required to ensure the accuracy and compliance of the information.
[0087] Step S302, conduct a preliminary check on the solution parameters.
[0088] In this embodiment, the access solution submitted by the business personnel is routed to the reseller management center through the pre-node for preliminary security check, and then the dependency relationships of each parameter are parsed and checked.
[0089] Optionally, the access solution submitted by the business personnel first needs to be routed to the reseller management center through the pre - configured nodes. This can be achieved by setting corresponding network routing rules or using specialized data transfer protocols.
[0090] Optionally, before accessing the reseller management center, the access solution needs to undergo a preliminary security check. This includes verifying the identity and permissions of the business personnel and checking whether the submitted access solution complies with security specifications, etc.
[0091] Optionally, once the security check is passed, the access solution will be parsed and the parameter dependency relationships will be checked. This can be achieved by writing corresponding parsing programs or using automated tools.
[0092] Optionally, during the process of parsing and checking each parameter dependency relationship, it is necessary to ensure that the relationships between the various parameters in the access solution are correct to avoid potential security vulnerabilities or business risks.
[0093] Optionally, if any problems or abnormal situations are found, the reseller management center needs to promptly notify the business personnel and take corresponding measures. At the same time, the abnormal situations can be recorded and followed up and analyzed later to improve the quality and security of the access solution.
[0094] Step S303: Output the preliminary inspection result.
[0095] In this embodiment, the inspection result is pushed to the business personnel and system maintenance personnel in various forms such as phone calls, text messages, and emails.
[0096] Optionally, the inspection result is pushed in various ways to ensure that relevant personnel are notified in a timely manner and necessary measures are taken. This can effectively improve work efficiency and the speed of problem - solving. At the same time, it can also track and record the inspection results in a timely manner, facilitating subsequent analysis and improvement work. Through various forms of pushing, the transmission and reception of information can be better guaranteed, avoiding delays caused by the inability of a certain notification method to reach in time. Therefore, in terms of pushing the inspection result, various forms of pushing methods are very important.
[0097] Optionally, this application realizes the visualization of the approval process through the process center, which is convenient for upstream and downstream to review the access progress and uniformly archive the approval materials.
[0098] Step S304: Manually check the solution parameters.
[0099] In this embodiment, the solutions that pass the preliminary screening will be pushed to the reseller access administrator of the target system for manual checking. The parameters will be parsed through a pre - configured template and translated into behavior descriptions. After successful checking, they will be deployed to the production environment with one key, and if they fail, they will be returned to the business personnel for modification.
[0100] Optionally, the solutions that pass the preliminary screening will be pushed to the access administrator of the target system vendor for manual verification. The access administrator will parse the parameters according to a pre-configured template and translate them into behavior descriptions. After successful verification, the administrator can deploy them to the production environment with one click. If the verification fails, the solution will be returned to the business personnel for modification.
[0101] Optionally, through the preliminary screening and manual verification methods, the cumbersome deployment process can be simplified and the efficiency can be improved. At the same time, by parsing the parameters through a pre-configured template, human errors can be reduced and data accuracy can be improved.
[0102] Optionally, by means of manual verification and returning to the business personnel for modification, security vulnerabilities caused by incorrect configuration can be effectively avoided, and the system security can be enhanced. At the same time, deploying to the production environment with one click can save deployment time and speed up the system go-live speed.
[0103] Step S305, access the vendor parameters according to the solution parameters and output content according to the personnel permissions.
[0104] In this embodiment, a metadata management page is provided, which is only open to business personnel for viewing permissions to interpret all vendor parameters. Technical personnel have modification permissions.
[0105] Optionally, the metadata management page is an interface for managing and viewing all vendor parameters. This page is only open to business personnel for viewing permissions, and they can view the meanings and related information of all vendor parameters on the page to help them better understand and use these parameters.
[0106] Optionally, technical personnel have modification permissions, and they can modify, update, or delete vendor parameters on the metadata management page to ensure the accuracy and timeliness of parameter information.
[0107] Optionally, through the metadata management page, business personnel can easily search for and understand vendor parameters to help them better make business decisions and analyses. Technical personnel can manage and maintain the parameters through this page to ensure the normal operation of the system and the accuracy of data. Such a permission setting can effectively distinguish the responsibilities of business personnel and technical personnel and improve work efficiency and the quality of data management.
[0108] Optionally, this application ensures that all access parties access according to the same standard by formulating unified access specifications and standards, including access procedures, access conditions, access requirements, etc. Each link in the access process is implemented in a configurable manner to reduce manual intervention and improve efficiency. By establishing a monitoring and feedback mechanism, problems in the access process can be discovered and solved in a timely manner, and the access process can be continuously optimized and improved to improve access efficiency and quality.
[0109] Optionally, this application uses metadata to manage the parameters to be accessed and clearly displays the access process in the form of graphics + text.
[0110] In this embodiment, by managing all existing and to-be-accessed vendor parameters in the form of metadata, displaying them on the front-end page, and using the process center for transfer, the labor cost is significantly reduced, the access efficiency is improved, and the technical effect of improving the access efficiency in the vendor access process is achieved, and the technical problem of low access efficiency in the vendor access process is solved.
[0111] The embodiment of this application also provides an access device for an object. It should be noted that the access device for an object in the embodiment of this application can be used to execute the access method for an object provided in the embodiment of this application. The access device for an object provided in the embodiment of this application is introduced below.
[0112] According to the embodiment of this application, there is also provided an access device for implementing the above-mentioned object, as Figure 4 shown, the device includes: an acquisition unit 401, a first verification unit 402, an analysis unit 403, a second verification unit 404, and an access unit 405.
[0113] The acquisition unit 401 is used to acquire the access policy of the target object, where the access policy is used to indicate the rules for accessing the target object to the target system.
[0114] The first verification unit 402 is used to verify the access policy to obtain a first verification result, where the first verification result is used to indicate the matching degree between the access policy and the target system.
[0115] The analysis unit 403 is used to, in response to the first verification result indicating successful verification of the access policy, analyze the access policy to obtain an analysis result.
[0116] The second verification unit 404 is used to verify the analysis result to obtain a second verification result.
[0117] The access unit 405 is used to, in response to the second verification result indicating successful verification of the analysis result, access the target object to the target system according to the access policy.
[0118] The access device for an object provided in an embodiment of the present application obtains an access policy for a target object, where the access policy is used to indicate the rules for accessing the target object to a target system; verifies the access policy to obtain a first verification result, where the first verification result is used to indicate the matching degree between the access policy and the target system; in response to the first verification result indicating successful verification of the access policy, parses the access policy to obtain a parsing result; verifies the parsing result to obtain a second verification result; and in response to the second verification result indicating successful verification of the parsing result, accesses the target object to the target system according to the access policy. That is to say, the present invention verifies the access policy to obtain a first verification result. After the first verification result passes, the access policy is parsed, and then the parsing result is verified again. After the verification passes, the target object is accessed to the target system according to the access policy. Since the present invention can verify the access policy multiple times, the accuracy of the access policy is ensured, and the technical effect of improving the access efficiency in the process of accessing a reseller is achieved, and the technical problem of low access efficiency in the process of accessing a reseller is solved.
[0119] Optionally, in the access device for an object provided in an embodiment of the present application, the first verification unit 602 may include: a first extraction module, configured to extract parameter dependency information in the access policy, where the parameter dependency information is used to indicate the dependency relationship between different parameters in the access policy; and a verification module, configured to verify the access policy based on the parameter dependency information to obtain a first verification result.
[0120] Optionally, in the access device for an object provided in an embodiment of the present application, the parsing unit 403 may include: a second extraction module, configured to extract parameter information in the access policy in response to the first verification result indicating successful verification of the access policy, where the parameter information is used to indicate information of the target object; a conversion module, configured to convert the parameter information into behavior information, where the behavior information is used to indicate the operation behavior of accessing the target object; and a determination module, configured to determine the behavior information as the parsing result.
[0121] Optionally, in the access device for an object provided in an embodiment of the present application, the access device 400 for an object may include: a first output unit, configured to re-obtain the modified access policy of the target object in response to the second verification result indicating failure to verify the parsing result.
[0122] Optionally, in the access device for an object provided in an embodiment of the present application, the access device 400 for an object may include: a first acquisition unit, configured to acquire permission information of the management account of the target system; a determination unit, configured to determine output information in the target system based on the permission information, where the output information is used to indicate information of the target object output in the target system; and a second output unit, configured to output the output information to a client logged in by the management account.
[0123] Optionally, in the access device of an object provided in the embodiments of the present application, the access device 400 of the object may include: a third output unit, configured to output a first verification result, a second verification result, and an access policy.
[0124] It should be noted here that the above-mentioned obtaining unit 401, first verification unit 402, parsing unit 403, second verification unit 404, and access unit 405 correspond to steps S201 to S205 in the method embodiment. The instances and application scenarios implemented by the five units and the corresponding steps are the same, but are not limited to the content disclosed in the above-mentioned embodiment one. It should be noted that the above-mentioned module or unit may be a hardware component or software component stored in a memory (for example, memory 104) and processed by one or more processors (for example, processors 102a, 102b,..., 102n). The above-mentioned module may also be a part of the device and may run in the computer terminal 10 provided in the first embodiment.
[0125] Embodiments of the present application may provide an electronic device. Figure 5 It is a structural block diagram of an electronic device provided according to an embodiment of the present application. As Figure 5 shown, the electronic device may include: one or more ( Figure 5 only one is shown in the figure) processors 1002, a memory 1004, a storage controller, and a peripheral interface, where the peripheral interface is connected to a radio frequency module, an audio module, and a display.
[0126] Among them, the memory may be used to store software programs and modules, such as program instructions / modules corresponding to the methods and devices in the embodiments of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the above-mentioned method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely provided with respect to the processor, and these remote memories may be connected to the terminal through a network. Examples of the above-mentioned network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0127] The processor can call the information and application programs stored in the memory through the transmission device to execute the following steps: obtain the access policy of the target object, where the access policy is used to indicate the rules for accessing the target object to the target system; verify the access policy to obtain a first verification result, where the first verification result is used to indicate the matching degree between the access policy and the target system; in response to the first verification result indicating successful verification of the access policy, parse the access policy to obtain a parsing result; verify the parsing result to obtain a second verification result; in response to the second verification result indicating successful verification of the parsing result, access the target object to the target system according to the access policy.
[0128] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: extract the parameter dependency information in the access policy, where the parameter dependency information is used to indicate the dependency relationship between the parameters in the access policy; based on the parameter dependency information, verify the access policy to obtain a first verification result.
[0129] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: in response to the first verification result indicating successful verification of the access policy, extract the parameter information in the access policy, where the parameter information is used to indicate the information of the target object; translate the parameter information into behavior information, where the behavior information is used to indicate the operation behavior of accessing the target object; based on the behavior information, determine the parsing result.
[0130] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: in response to the second verification result indicating failure to verify the parsing result, output and re-obtain the access policy.
[0131] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: obtain the permission information of the management account; based on the permission information, determine the output information in the target system; output the output information to the client logged in by the management account.
[0132] The processor can also call the information and application programs stored in the memory through the transmission device to execute the following steps: output the first verification result, the second verification result, and the access policy.
[0133] An access method for an object is provided according to an embodiment of the present application. An access policy for a target object is obtained, where the access policy is used to indicate the rules for accessing the target object to a target system; the access policy is verified to obtain a first verification result, where the first verification result is used to indicate the matching degree between the access policy and the target system; in response to the first verification result indicating successful verification of the access policy, the access policy is parsed to obtain a parsing result; the parsing result is verified to obtain a second verification result; in response to the second verification result indicating successful verification of the parsing result, the target object is accessed to the target system according to the access policy. That is to say, the present invention verifies the access policy to obtain a first verification result. After the first verification result passes, the access policy is parsed, and then the parsing result is verified again. After the verification passes, the target object is accessed to the target system according to the access policy. Since the present invention can verify the access policy multiple times, the accuracy of the access policy is ensured, and the technical effect of improving the access efficiency in the process of accessing by a seller is achieved, and the technical problem of low access efficiency in the process of accessing by a seller is solved.
[0134] Figure 5 is a structural block diagram of an electronic device provided according to an embodiment of the present application. Those of ordinary skill in the art can understand that Figure 5 the structure shown is only schematic, and the electronic device can also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a handheld computer, and a mobile Internet device (Mobile Internet Devices, MID), a PAD and other terminal devices. Figure 5 It does not limit the structure of the above electronic device. For example, the electronic device may further include more or fewer components (such as a network interface, a display device, etc.) than those shown Figure 5 in the figure, or have a different configuration from that shown Figure 5 in the figure.
[0135] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by a program instructing the relevant hardware of the terminal device. The program can be stored in a computer-readable storage medium, and the storage medium can include: a flash drive, a read-only memory (Read-Only Memory, abbreviated as ROM), a random access memory (Random Access Memory, abbreviated as RAM), a magnetic disk or an optical disc, etc.
[0136] According to an embodiment of the present invention, a processor is further provided, and the processor is used to run a program, where the program, when run by the processor, executes the object access method in the embodiment.
[0137] According to an embodiment of the present invention, there is also provided an electronic device, including: a memory storing an executable program; and a processor for running the program, wherein when the program runs, it executes the access method of the object in the embodiment.
[0138] According to another aspect of the embodiment of the present invention, there is also provided a computer-readable storage medium. The computer-readable storage medium includes a stored program, wherein when the program runs, it controls the device where the computer-readable storage medium is located to execute the access method of the object in the embodiment.
[0139] According to an embodiment of the present invention, there is also provided a computer program product, which includes a computer program, wherein when the computer program is executed by a processor, it implements the access method of the object in the embodiment.
[0140] According to an embodiment of the present invention, there is also provided a computer program product, including a non-volatile computer-readable storage medium for storing a computer program, and when the computer program is executed by a processor, it implements the access method of the object in the embodiment.
[0141] According to an embodiment of the present invention, there is also provided a computer program, and when the computer program is executed by a processor, it implements the access method of the object in the embodiment.
[0142] The serial numbers of the above embodiments of the present application are only for description and do not represent the advantages or disadvantages of the embodiments.
[0143] In the above embodiments of the present application, the descriptions of the respective embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0144] In the several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed with each other can be through some interfaces. The indirect couplings or communication connections of units or modules can be in electrical or other forms.
[0145] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0146] In addition, in each embodiment of the present application, each functional unit can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0147] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the related technology, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in the various embodiments of the present invention. The aforementioned storage medium includes: various media such as USB flash drives, ROMs, RAMs, mobile hard disks, magnetic disks, or optical discs that can store program codes.
[0148] The above is only the preferred embodiment of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A method for accessing an object, characterized in that: include: Acquire an access policy of a target object, wherein the access policy is used to indicate a rule for accessing the target object to a target system; Verifying the access policy to obtain a first verification result, wherein the first verification result is used to indicate a matching degree between the access policy and the target system; In response to the first verification result being that the access policy is successfully verified, parsing the access policy to obtain a parsing result; Verifying the analysis result to obtain a second verification result; In response to the second verification result being successful verification of the parsing result, the target object is connected to the target system according to the access policy.
2. The method according to claim 1, characterized in that Verifying the access policy to obtain a first verification result includes: Extracting parameter dependency information in the access policy, wherein the parameter dependency information is used to indicate a dependency relationship between different parameters in the access policy; Based on the parameter dependency information, the access policy is verified to obtain the first verification result.
3. The method according to claim 1, characterized in that In response to the first verification result being that the access policy is successfully verified, parsing the access policy to obtain a parsing result, including: In response to the first verification result being that the access policy is successfully verified, extracting parameter information in the access policy, wherein the parameter information is used to indicate information of the target object; Converting the parameter information into behavior information, wherein the behavior information is used to indicate an operation behavior of accessing the target object; The behavior information is determined as the parsing result.
4. The method according to claim 1, characterized in that: The method further comprises: In response to the second verification result being a failure in verifying the parsing result, the modified access policy of the target object is re-acquired.
5. The method according to claim 1, characterized in that The method further comprises: Obtaining permission information of the management account of the target system; Based on the permission information, determining output information in the target system, wherein the output information is used to indicate information of the target object output in the target system; The output information is output to the client logged in by the management account.
6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: Output the first verification result, the second verification result and the access policy.
7. An object access device, characterized in that: include: An acquisition unit, configured to acquire an access policy of a target object, wherein the access policy is used to indicate a rule for accessing the target object to a target system; A first verification unit, configured to verify the access policy to obtain a first verification result, wherein the first verification result is used to indicate a matching degree between the access policy and the target system; A parsing unit, configured to, in response to the first verification result being that the access policy is successfully verified, parse the access policy to obtain a parsing result; A second verification unit, used to verify the analysis result to obtain a second verification result; An access unit is used to connect the target object to the target system according to the access policy in response to the second verification result being a successful verification of the parsing result.
8. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored executable program, wherein when the executable program is executed, the device where the computer-readable storage medium is located is controlled to execute the method according to any one of claims 1 to 6.
9. An electronic device, characterized in that: include: A memory storing an executable program; A processor, configured to run the program, wherein the program executes the method according to any one of claims 1 to 6 when running.
10. A computer program product comprising computer instructions, characterized in that When the computer instructions are executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.