High-frequency data transmission and cross-domain authentication method based on middleware layer

By introducing a unified middleware layer between multiple gates, using encryption and authentication mechanisms, combining distributed architecture and streaming processing technology, the problems of complex communication protocol processing, data transmission integrity guarantee and high-frequency data exchange are solved, and efficient and secure data transmission is achieved.

CN120128422AActive Publication Date: 2025-06-10XIAMEN DEL MICRO TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510497964.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-06-10
Estimated Expiration
2045-04-21

AI Technical Summary

Technical Problem

In communication between multiple gates, the prior art is difficult to effectively handle complex communication protocols, ensure the integrity of data transmission and meet the needs of high-frequency data exchange, resulting in data leakage, packet loss, delay and data corruption.

Method used

By introducing a unified middleware layer between multiple gates, an efficient encryption and authentication mechanism is adopted, combined with distributed architecture and streaming processing technology, the reliability, security and efficiency of data transmission are achieved.

Benefits of technology

It realizes seamless docking between multiple protocols, ensures the security and integrity of data during cross-domain transmission, improves data transmission efficiency, supports high-frequency and high-concurrent request processing, and has good scalability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120128422A_ABST
    Figure CN120128422A_ABST
Patent Text Reader

Abstract

The invention discloses a middleware layer-based high-frequency data transmission and cross-domain authentication method, which specifically comprises the following steps that: a request system calls an HTTP (Hyper Text Transport Protocol) interface of an API (Application Program Interface) gateway of a UniBridge middleware layer to send user update data in a JSON (JavaScript Object Notation) format, and an OAuth 2.0 authorization token is attached; the API gateway performs identity authentication on the OAuth 2.0, converts an HTTP (Hyper Text Transport Protocol) request into a gRPC format, encrypts a parameter request through a TLS (Transport Layer Security) and performs Hash signature through an SHA-256, and transmits the request to a receiving system; after the receiving system receives the gRPC request forwarded by the API gateway from the UniBridge middleware layer, data integrity verification is carried out, the SHA-256 hash value of the request data is calculated, if the data is complete and effective, user information in a database is updated, and a gRPC response message of successful updating is returned; and the API gateway converts the gRPC response message back to the HTTP format and returns the gRPC response message to the request system.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer network technologies, and mainly relates to a high-frequency data transmission and cross-domain authentication method based on a middleware layer, which is particularly applicable to scenarios of processing complex communication protocols, ensuring the integrity of big data transmission, and high-frequency data exchange. Background Art

[0002] With the development of Internet technologies, the mutual communication between various network devices and application programs has increased day by day. Especially when data is transmitted between multiple independent domains, the complexity of communication protocols, the integrity of data transmission, and frequent data exchange have become urgent problems to be solved. Currently, cross-domain data transmission often faces problems such as inconsistent protocols, complex authentication, large amounts of data, and stability issues during high-frequency communication. If these problems are not properly handled, it may not only lead to data leakage, but also cause packet loss, delay, and data corruption during the transmission process, seriously affecting the reliability and security of the system.

[0003] Therefore, there is a need for a solution that can provide reliability, efficiency, and security between multiple network gates, can process complex communication protocols, ensure the integrity of data transmission, and meet the requirements of high-frequency data exchange. Summary of the Invention

[0004] The present invention provides a high-frequency data transmission and cross-domain authentication solution based on a middleware layer, aiming to solve the problems of communication protocol processing, cross-domain authentication, ensuring the integrity of data transmission, and the requirements of high-frequency data exchange between multiple network gates.

[0005] The core idea of the present invention is to introduce a unified middleware layer between multiple network gates and adopt efficient encryption and authentication mechanisms to ensure the reliability, security, and efficiency of data transmission. At the same time, through a distributed architecture and streaming processing technology, it can ensure the processing of high-frequency and large amounts of data.

[0006] According to the first aspect of the present invention, a high-frequency data transmission and cross-domain authentication method based on a middleware layer is proposed. The specific steps include: S1. The requesting system calls the HTTP interface of the API gateway of the UniBridge middleware layer to send user update data in JSON format, accompanied by an OAuth 2.0 authorization token. Among them, the request sent by the requesting system to the receiving system is in a synchronous mode; S2. The API gateway authenticates the OAuth 2.0, converts the HTTP request into the gRPC format, and transmits the request to the receiving system through TLS encryption parameters request and SHA-256 hash signature; S3. After the receiving system receives the gRPC request forwarded by the API gateway in the UniBridge middleware layer, it performs data integrity verification, calculates the SHA-256 hash value of the request data. If the data is complete and valid, it updates the user information in the database and returns a gRPC response message indicating successful update. S4. The API gateway converts the gRPC response message back to the HTTP format and returns it to the requesting system.

[0007] Furthermore, the requesting system and the receiving system use different communication protocols. The requesting system communicates based on the HTTP REST API interface, and the receiving system communicates based on the gRPC interface. The communication process follows identity authentication and data integrity verification.

[0008] Furthermore, the UniBridge middleware layer incorporates an API gateway, a message queue, identity authentication, security encryption, and intelligent traffic control for requesting systems and receiving systems with different communication protocols.

[0009] Furthermore, the UniBridge middleware layer adopts a microservices architecture, and its core components include: a protocol gateway component, a security center component, a traffic optimizer component, an asynchronous processor component, a data optimizer component, and an observability module component.

[0010] Furthermore, the protocol gateway component is used for dynamic protocol conversion, including: conversion between HTTP protocol and gRPC protocol, conversion between WebSocket protocol and MQTT protocol, and conversion between REST API protocol and AMQP protocol; The security center component incorporates the OAuth 2.0 protocol to achieve cross-system secure access, is encrypted by TLS 1.3 to prevent man-in-the-middle attacks during communication, and uses SHA-256 data integrity verification to attach a hash signature during transmission to ensure that the information has not been tampered with; The traffic optimizer component is used for AI-driven traffic optimization, and uses machine learning models for traffic analysis, including: intelligent load balancing, anomaly detection, and dynamic rate limiting; The asynchronous processor component incorporates a Kafka / RabbitMQ message queue to achieve asynchronous task processing, automatic retry, and transaction consistency; The data optimizer component incorporates gzip / zstd data compression, incremental transmission, and edge caching to reduce network transmission overhead.

[0011] Furthermore, when the request sent by the requesting system to the receiving system is in asynchronous mode, the specific steps include: The requesting system submits a user update request to the receiving system by calling the HTTP interface of the API gateway in the UniBridge middleware layer; After the API gateway verifies the identity and performs data integrity verification, it pushes the data to the user-update-topic message queue of Kafka; The receiving system obtains new messages in real time through the user-update-topic message queue. After the receiving system reads the messages, it performs data integrity verification. After the verification passes, it executes the database update operation; The requesting system periodically queries the status query interface of the API gateway or obtains the processing result through the user-update-topic message queue.

[0012] Furthermore, in the data integrity verification, if the data verification fails, that is, the receiving system finds that the received data hash values do not match, it rejects the processing and returns an error message. The API gateway triggers an automatic retry and notifies the requesting system to send the correct data again; if the receiving system cannot complete the update due to database exceptions, the API gateway stores the failed requests in the Redis queue and resends them after a time threshold. The requesting system receives the failure notice and chooses to retry manually.

[0013] Furthermore, in the UniBridge middleware layer, in the synchronous mode or asynchronous mode, if high-frequency data transmission occurs, gzip or zstd compression can be used to reduce resource consumption; and Nginx + Kubernetes is used to ensure the horizontal expansion of multiple API gateways to handle high-concurrency requests.

[0014] According to the second aspect of the present invention, a computer program product is proposed, on which one or more computer programs are stored. When the one or more computer programs are executed by a computer processor, the above method is implemented.

[0015] According to the third aspect of the present invention, a computer system is proposed, including a processor and a memory. The processor is configured to implement the above method when executed.

[0016] One or more of the above technical solutions in the embodiments of the present application have at least one of the following technical effects: 1. Protocol unification and strong compatibility: Through the introduction of the middleware layer, seamless docking between multiple protocols can be achieved, simplifying the configuration and management of the system.

[0017] 2. Secure and reliable: The OAuth 2.0 / SAML authentication mechanism and TLS encryption technology are adopted to effectively ensure the security and integrity of data during cross-domain transmission.

[0018] 3. Efficient Data Processing and Transmission: The use of a distributed architecture and the Kafka streaming processing framework has greatly improved data transmission efficiency and supports high-frequency and high-concurrency request processing.

[0019] 4. Low Bandwidth Consumption: The combination of data compression and incremental transmission technologies has significantly reduced bandwidth consumption and improved transmission efficiency.

[0020] 5. High Scalability: The system can flexibly handle different data volumes, network topologies, and business requirements, and has good scalability. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] The accompanying drawings are included to provide a further understanding of the embodiments and are incorporated in and constitute a part of this specification. The drawings illustrate the embodiments and, together with the description, are used to explain the principles of the invention. Other embodiments and many of the intended advantages of the embodiments will be readily apparent as they become better understood by reference to the following detailed description. The elements of the drawings are not necessarily to scale relative to each other. Like reference numerals refer to corresponding like parts.

[0022] Figure 1 FIG. shows a schematic flowchart of a high-frequency data transmission and cross-domain authentication method based on a middleware layer according to an embodiment of the present invention.

[0023] Figure 2 FIG. shows a schematic diagram of the UniBridge middleware layer architecture according to an embodiment of the present invention.

[0024] Figure 3 is a schematic diagram of the structure of a computer system of an electronic device suitable for implementing the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only for explaining the related invention and not for limiting the invention. It should be noted that, for the sake of description, only parts related to the relevant invention are shown in the drawings.

[0026] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and embodiments.

[0027] Figure 1 FIG. shows a schematic flowchart of a high-frequency data transmission and cross-domain authentication method based on a middleware layer according to an embodiment of the present invention, as Figure 1 shown: When the requesting system sends a user information update request to the receiving system and is in the synchronous mode, the specific steps are as follows: S1. The request system calls the HTTP interface of the API gateway in the UniBridge middleware layer to send user update data in JSON format, along with an OAuth 2.0 authorization token; The reference code for the embodiment is as follows: POST https: / / api - gateway.com / updateUser Headers: Authorization: Bearer<access_token> Content - Type: application / json Body: { "userId": "12345", "name": "Alice", "email": "alice@example.com" } S2. The API gateway authenticates the OAuth 2.0, converts the HTTP request into gRPC format, and transmits the request to the receiving system through TLS - encrypted parameters and SHA - 256 hash signature; The reference code for the embodiment is as follows: gRPC Request: { "user_id": "12345", "name": "Alice", "email": "alice@example.com", "hash": "a94a8fe5ccb19ba61c4c0873d391e987982fbbd3" } S3. After receiving the gRPC request forwarded by the API gateway in the UniBridge middleware layer, the receiving system performs data integrity verification, calculates the SHA - 256 hash value of the request data. If the data is complete and valid, it updates the user information in the database and returns a gRPC response message indicating successful update; After success, the receiving system returns the response as follows: gRPC Response: { "status": "success", "message": "User updated" } S4. The API gateway converts the gRPC response message back to the HTTP format and returns it to the requesting system.

[0028] The reference code for the embodiment is as follows: HTTP Response: { "status": "success", "message": "User updated" } When the requesting system needs to send a batch of data update requests and does not want to wait for the immediate response of the receiving system, asynchronous communication is implemented using a message queue. The specific steps are as follows: Step 1. The requesting system submits a user update request to the receiving system by calling the HTTP interface of the API gateway in the UniBridge middleware layer. Step 2. After verifying the identity and performing data integrity verification, the API gateway does not directly call the receiving system, but pushes the data to the user-update-topic message queue of Kafka. The reference code for the embodiment is as follows: Kafka Message: { "userId": "12345", "name": "Alice", "email": "alice@example.com", "hash": "a94a8fe5ccb19ba61c4c0873d391e987982fbbd3" } Step 3. The receiving system obtains new messages in real time through the user-update-topic message queue. After the receiving system reads the messages, it performs data integrity verification, and after passing the verification, it performs database update operations. Step 4. The requesting system periodically queries the status query interface of the API gateway or obtains the processing result through the user-update-topic message queue.

[0029] The reference code for the embodiment is as follows: GET https: / / api-gateway.com / updateUser / status?requestId=xyz123 Response: { "status": "completed", "message": "User updated successfully" } Whether it is synchronous mode communication or asynchronous mode communication, if the data integrity check fails, that is, the receiving system finds that the received data hash value does not match, it will reject the processing and return an error message. The API gateway triggers an automatic retry and re-informs the requesting system to send the correct data. If the receiving system cannot complete the update due to database exceptions, the API gateway stores the failed requests in the Redis queue and resends them after waiting for a time threshold. The requesting system receives the failure notice and chooses to retry manually.

[0030] For high-frequency data transmission, gzip or zstd compression can be adopted to reduce resource consumption; and Nginx + Kubernetes is used to ensure the horizontal expansion of multiple API gateways to handle high-concurrency requests.

[0031] The above-mentioned requesting system and receiving system adopt different communication protocols. The requesting system provides an HTTP REST API interface, and the receiving system communicates based on the gRPC interface, and requires identity authentication and data integrity verification.

[0032] Based on the above process steps, the UniBridge middleware layer is further introduced, as Figure 2 shown, Figure 2 shows a schematic diagram of the UniBridge middleware layer architecture according to an embodiment of the present invention. The specific content is as follows: The UniBridge middleware layer is an intelligent middleware layer for distributed systems, designed specifically for cross-protocol conversion, security authentication, and efficient data transmission. It integrates functions such as API gateways, message queues, identity authentication, security encryption, and intelligent traffic control, and can seamlessly connect requestor systems and receiver systems with different protocols to ensure the stability, security, and efficiency of data transmission.

[0033] The UniBridge middleware layer of the present invention adopts a microservices architecture, and its core components include: protocol gateway component, security center component, traffic optimizer component, asynchronous processor component, data optimizer component, and observability module component. The independent functions are distributed as shown in Table 1: Table 1 Microservices Architecture Components

[0034] The key functions of the UniBridge middleware layer include: intelligent protocol conversion, security authentication and encryption, AI-driven traffic optimization, asynchronous message queue, and data optimization.

[0035] ① The protocol gateway component is used for dynamic protocol conversion, including but not limited to: Conversion between HTTP protocol and gRPC protocol: The requesting system sends an HTTP request, and UniBridge automatically converts it into a gRPC call to adapt to the receiving system.

[0036] Conversion between WebSocket protocol and MQTT protocol: Supports low-latency two-way communication for IoT devices.

[0037] Conversion between REST API protocol and AMQP protocol: Smart switching between synchronous and asynchronous communication; For example, the requesting system (HTTP) UniBridge Receiving system (gRPC): The HTTP format of the requesting system is as follows: POST https: / / unibridge.com / updateUser Headers: Authorization: Bearer <token> Content-Type: application / json Body: { "userId": "12345", "name": "Alice", "email": "alice@example.com" } gRPC format after UniBridge conversion: message UpdateUserRequest { string user_id = 1; string name = 2; string email = 3; string hash = 4; } ② The security center component implements cross-system secure access by building in the OAuth 2.0 protocol, preventing man-in-the-middle attacks during communication through TLS 1.3 encryption, and ensuring the integrity of the information during transmission by using SHA-256 data integrity verification with an attached hash signature to ensure that the information has not been tampered with. UniBridge recalculates the hash value for verification when receiving. If there is a mismatch, the request is rejected.

[0038] ③ The traffic optimizer component is used for AI-driven traffic optimization, analyzing traffic using machine learning models. Its specific functions include: Intelligent load balancing: Automatically select the optimal nodes, such as Nginx or Kubernetes; allocate traffic, where Nginx reverse proxy: Based on strategies such as round-robin, least connections, IP hashing, etc.; allocate request loads, and Kubernetes auto-scaling: Dynamically expand or contract according to CPU / memory load conditions.

[0039] Anomaly detection: Detect DDoS attacks and abnormal request traffic, and automatically adjust strategies.

[0040] Dynamic rate limiting: Adjust the request rate according to the real-time load to prevent system overload; For example, in load-based traffic distribution, when traffic is low, API requests are directly forwarded to the receiving system. When traffic is high, some requests are automatically sent to the Kafka queue for delayed processing to reduce system pressure.

[0041] ④ The asynchronous processor component has a built-in Kafka or RabbitMQ message queue, including an event-driven architecture for implementing the producer-consumer pattern, which improves the decoupling ability of the system. Its specific functions also include: Asynchronous task processing: The request system requests are deposited into Kafka, and the receiving system consumes them asynchronously, reducing blockages.

[0042] Automatic retry: If the receiving system crashes, UniBridge will periodically retry the requests until they succeed.

[0043] Transaction consistency: Combined with the idempotency mechanism, it avoids duplicate consumption; For example: The request system submits data, UniBridge deposits it into the Kafka queue, the receiving system consumes the data from Kafka, and returns the result, which is deposited into the Redis cache. The request system can query the processing status.

[0044] ⑤ The data optimizer component reduces network transmission overhead. Its specific functions include: gzip / zstd data compression: Reduces the amount of data transmitted and improves throughput.

[0045] Incremental transmission: Only sends the changed parts, avoiding full updates.

[0046] Edge caching: Reduces repeated calculations and improves response speed.

[0047] In some business embodiments, such as high-concurrency e-commerce or financial systems, which require the system to dynamically predict which data needs to be cached preferentially under high load to improve the cache hit rate. At this time, the quantum cache acceleration component is introduced and enabled in the UniBridge middleware layer. The implementation steps include: UniBridge records the data access history, constructs an access frequency model in combination with machine learning, calculates the optimal cache policy according to the historical access trend, ensures that high-frequency data is always retained, and for suddenly increased hot data, it is automatically promoted to the ultra-high-speed cache layer. In this way, the traditional fixed LRU algorithm is abandoned, which causes hot data to be prematurely eliminated. The quantum cache acceleration component can intelligently predict data requirements and cache data with possible high future access volumes in advance.

[0048] Among them, the quantum cache acceleration component adopts a three-level cache framework, including L1 ultra-high-speed cache, L2 edge intelligent cache, and L3 distributed long-term cache. For example, when the request system requests data from the receiving system, the quantum cache acceleration component automatically decides which cache layer to store the data in, reducing the number of database accesses. If the access frequency of a certain data suddenly increases (such as a product flash sale event), the quantum cache acceleration component will intelligently upgrade the cache level, from L3 to L1, to improve the access speed. Similarly, when caching data, security authentication and encryption are observed, and encryption verification is used to prevent cache pollution or tampering.

[0049] The unified middleware brings the risk of a single point of failure. For example, in the global e-commerce platform, System A and System B need to synchronize inventory, orders, and user data in real time. All API requests are processed by the middleware UniBridge. If there is a problem with the middleware UniBridge, the data synchronization will be interrupted.

[0050] Therefore, when necessary, the middleware UniBridge enables the Raft consensus algorithm. When the UniBridge of System A fails, System B can automatically take over the data synchronization. The Kafka framework in UniBridge will also store data through the message queue when a node fails and automatically process the unprocessed data after the failure is recovered.

[0051] In summary, as a new type of middleware layer, UniBridge breaks through the limitations of traditional API gateways and integrates intelligent protocol conversion, security authentication, traffic optimization, asynchronous message processing, and data optimization. It is suitable for high-concurrency, large-scale distributed systems and can improve the efficiency, security, and stability of cross-system communication. The usage scenarios include: enterprise-level microservice architecture: microservice communication across multiple protocols and languages. Large-scale IoT device communication: low-latency, high-throughput data transmission optimization. Financial security system: high-security, data integrity verification payment and transaction systems. High-concurrency e-commerce platform: automatic load balancing, asynchronous processing of order data.

[0052] Next, refer to Figure 3 , which shows a schematic structural diagram of a computer system 300 of an electronic device suitable for implementing the embodiments of the present application. Figure 3 The shown electronic device is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present application.

[0053] As Figure 3 shown, the computer system 300 includes a central processing unit (CPU) 301, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 302 or the program loaded from the storage section 308 into the random access memory (RAM) 303. In the RAM 303, various programs and data required for the operation of the system 300 are also stored. The CPU 301, ROM 302, and RAM 303 are connected to each other through a bus 304. The input / output (I / O) interface 305 is also connected to the bus 304.

[0054] The following components are connected to the I / O interface 305: an input section 306 including a keyboard, a mouse, etc.; an output section 307 including a liquid crystal display (LCD) and the like, and a speaker and the like; a storage section 308 including a hard disk and the like; and a communication section 309 including a network interface card such as a LAN card, a modem, etc. The communication section 309 performs communication processing via a network such as the Internet. A drive 310 is also connected to the I / O interface 305 as needed. A removable medium 311, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is mounted on the drive 310 as needed so that a computer program read therefrom is installed into the storage section 308 as needed.

[0055] In particular, according to embodiments of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of the present disclosure include a computer program product that includes a computer program carried on a computer-readable storage medium, and the computer program includes program code for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through the communication section 309 and / or installed from the removable medium 311. When the computer program is executed by the central processing unit (CPU) 301, the above-described functions defined in the methods of the present application are performed. It should be noted that the computer-readable storage medium of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. And in the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries the computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable storage medium other than the computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on the computer-readable storage medium can be transmitted by any suitable medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0056] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, Matlab, Labview, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., connected through the Internet using an Internet service provider).

[0057] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of the code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0058] The modules described in the embodiments of this application can be implemented in software or in hardware.

[0059] As another aspect, the present application also provides a computer-readable storage medium, which may be included in the electronic device described in the above embodiments; or may exist separately without being assembled into the electronic device. The above computer-readable storage medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device is caused to: request the system to call the HTTP interface of the API gateway of the UniBridge middleware layer to send user update data in JSON format, and attach an OAuth 2.0 authorization token; the API gateway authenticates the OAuth 2.0, converts the HTTP request into gRPC format, and transmits the request to the receiving system through TLS encryption parameters request and SHA-256 hash signature; after receiving the gRPC request forwarded by the API gateway of the UniBridge middleware layer, the receiving system performs data integrity verification, calculates the SHA-256 hash value of the request data, and if the data is complete and valid, updates the user information in the database and returns a gRPC response message indicating successful update; the API gateway converts the gRPC response message back into HTTP format and returns it to the requesting system.

[0060] The above description is only the preferred embodiments of the present application and the description of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above inventive concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features having similar functions disclosed in the present application.< / token>

Claims

1. A high-frequency data transmission and cross-domain authentication method based on a middleware layer, characterized in that: The following steps are involved: S1. The requesting system calls the HTTP interface of the API gateway of the UniBridge middleware layer to send the user update data in JSON format, and attaches an OAuth 2.0 authorization token. The request sent by the requesting system to the receiving system is in synchronous mode. S2. The API gateway authenticates the OAuth 2.0, converts the HTTP request into gRPC format, and transmits the request to the receiving system through TLS encryption parameter request and SHA-256 hash signature; S3. After receiving the gRPC request forwarded by the API gateway of the UniBridge middleware layer, the receiving system performs data integrity verification and calculates the SHA-256 hash value of the request data. If the data is complete and valid, the user information in the database is updated and a gRPC response message of successful update is returned. S4. The API gateway converts the gRPC response message back to HTTP format and returns it to the requesting system.

2. The high-frequency data transmission and cross-domain authentication method according to claim 1 is characterized in that: The requesting system and the receiving system use different communication protocols. The requesting system communicates based on the HTTP REST API interface, and the receiving system communicates based on the gRPC interface. The communication process uses identity authentication and data integrity verification.

3. The high-frequency data transmission and cross-domain authentication method according to claim 1 is characterized in that: The UniBridge middleware layer has built-in API gateway, message queue, identity authentication, security encryption and intelligent flow control, and is used for request systems and receiving systems of different communication protocols.

4. The high-frequency data transmission and cross-domain authentication method according to claim 1 is characterized in that: The UniBridge middleware layer adopts a microservice architecture, in which the core components include: a protocol gateway component, a security center component, a traffic optimizer component, an asynchronous processor component, a data optimizer component and an observability module component.

5. The high-frequency data transmission and cross-domain authentication method according to claim 4 is characterized in that: The protocol gateway component is used for dynamic conversion of protocols, including conversion between HTTP protocol and gRPC protocol, conversion between WebSocket protocol and MQTT protocol, conversion between REST API protocol and AMQP protocol; The security center component has a built-in OAuth 2.0 protocol to achieve secure access across systems, uses TLS 1.3 encryption to prevent middleman attacks during communication, and uses SHA-256 data integrity verification to attach hash signatures during transmission; The traffic optimizer component is used for AI-driven traffic optimization, using machine learning models for traffic analysis, including: intelligent load balancing, anomaly detection, and dynamic rate limiting; The asynchronous processor component has a built-in Kafka / RabbitMQ message queue, including: asynchronous task processing, automatic retry, and transaction consistency; The data optimizer component has built-in gzip / zstd data compression, incremental transmission and edge caching.

6. The high-frequency data transmission and cross-domain authentication method according to claim 1, characterized in that: When the request sent by the requesting system to the receiving system is in asynchronous mode, the specific steps include: The requesting system calls the HTTP interface of the API gateway of the UniBridge middleware layer to submit a user update request to the receiving system; After the API gateway verifies the identity and performs data integrity check, it pushes the data to Kafka's user-update-topic message queue; The receiving system obtains new messages in real time through the user-update-topic message queue. After reading the message, the receiving system performs a data integrity check and executes the database update operation after the check passes. The request system periodically queries the status query interface of the API gateway, or obtains the processing results through the user-update-topic message queue.

7. The high-frequency data transmission and cross-domain authentication method according to claim 1 or 6, characterized in that: In the data integrity check, if the data check fails, that is, the receiving system finds that the hash value of the received data does not match, it will refuse to process and return an error message. The API gateway triggers automatic retry and re-notifies the requesting system to send the correct data. If the receiving system cannot complete the update due to database abnormalities, the API gateway will store the failed request in the Redis queue and resend it after a time threshold. The requesting system receives the failure notification and chooses to retry manually.

8. The high-frequency data transmission and cross-domain authentication method according to claim 1 or 6, characterized in that: The UniBridge middleware layer can use gzip or zstd compression in synchronous mode or asynchronous mode if high-frequency data transmission occurs to reduce resource consumption; and use Nginx+Kubernetes to ensure horizontal expansion of multiple API gateways to cope with high-concurrency requests.

9. A computer program product, characterized in that A computer program is stored thereon, and when the computer program is executed by a processor, the method according to any one of claims 1 to 8 is implemented.

10. A computing system, characterized in that: The method comprises a processor and a memory, wherein the processor is configured to execute the method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Semantic conversion method of edge layer in industrial internet and middleware

    CN110399612A

  • Gateway traffic control method and device, electronic equipment and storage medium

    CN114827246A

  • EAST experimental data release information exchange system and method

    CN116192928A

  • Industrial internet protocol conversion system and method based on middleware

    CN117176825A

  • Live app testing within an app editor for an information technology and security operations application

    US12120124B1