Virtual API (Application Program Interface) gateway system consisting of distributed equipment and implementation method of virtual API gateway system
Through the virtual API gateway system composed of distributed devices, the collaborative work of the main device and the target distributed device is solved, and the existing API gateway authentication mechanism is single and not intelligent, achieving efficient and secure authentication, and improving the intelligence of the API gateway.
Patent Information
- Application Number
- CN202510452502.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-06-13
AI Technical Summary
The existing API gateway authentication mechanism is relatively single and lacks intelligence, making it difficult to perform efficient and secure authentication under the circumstances of a large number of authentication requests.
A virtual API gateway system composed of distributed devices receives authentication requests through the main device, and determines the target distributed device based on the identification information and geographical location of the terminal device to perform identity authentication. The target distributed device obtains the reference identity password information and matches the identity password information entered by the user to achieve identity authentication.
By diversion of authentication requests, the workload of the master device is reduced, the authentication efficiency and security are improved, and the intelligence of API gateway authentication is improved.
Smart Images

Figure CN120151091A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology or computer technology, and specifically to a virtual API gateway system composed of distributed devices and an implementation method thereof. Background Art
[0002] At present, the application programming interface gateway can also be called API (Application Programming Interface, API) gateway can be regarded as a server, and the API gateway is the only entrance to the system. In actual applications, the API gateway encapsulates the internal architecture of the system and provides a customized API for each client.
[0003] In the specific implementation, the API gateway can realize identity authentication, but the identity authentication is relatively simple, resulting in insufficient intelligence of the identity authentication. Therefore, the problem of how to improve the intelligence of the API gateway identity authentication needs to be solved urgently. Summary of the invention
[0004] The embodiments of the present application provide a virtual API gateway system composed of distributed devices and an implementation method thereof, which can improve the intelligence of API gateway identity authentication.
[0005] In a first aspect, an embodiment of the present application provides a virtual API gateway system composed of distributed devices, wherein the virtual API gateway system includes m distributed devices and a master device, where m is an integer greater than 1; wherein,
[0006] The main device is used to receive an identity authentication request from a first terminal device, the identity authentication request including: first user identity information of the first terminal device, first identification information of the first terminal device, and a first geographic location of the first terminal device; the first user identity information includes a first user name and a first identity password information;
[0007] The master device is further configured to determine a target distributed device according to the first identification information and the first geographical location; the target distributed device is at least one distributed device among the m distributed devices;
[0008] The target distributed device is used to obtain reference identity and password information corresponding to the first user name, match the first identity and password information with the reference identity and password information, and determine that the identity authentication of the first terminal device is passed when the first identity and password information successfully match the reference identity and password information.
[0009] Second aspect, an embodiment of the present application provides an authentication method applied to a virtual API gateway system composed of distributed devices. The virtual API gateway system includes m distributed devices and a master device, where m is an integer greater than 1. The method includes:
[0010] Receiving, by the master device, an authentication request from a first terminal device. The authentication request includes: first user identity information of the first terminal device, first identification information of the first terminal device, and a first geographical location of the first terminal device. The first user identity information includes a first username and first identity password information.
[0011] Determining, by the master device, a target distributed device according to the first identification information and the first geographical location. The target distributed device is at least one of the m distributed devices.
[0012] Obtaining, by the target distributed device, reference identity password information corresponding to the first username, matching the first identity password information with the reference identity password information, and determining that the authentication of the first terminal device is passed when the first identity password information matches the reference identity password information.
[0013] Implementing the embodiment of the present application has the following beneficial effects:
[0014] It can be seen that in the virtual API gateway system composed of distributed devices and its implementation method described in the embodiment of the present application, the virtual API gateway system includes m distributed devices and a master device, where m is an integer greater than 1. Among them, the master device receives an authentication request from a first terminal device. The authentication request includes: first user identity information of the first terminal device, first identification information of the first terminal device, and a first geographical location of the first terminal device. The first user identity information includes a first username and first identity password information. The master device determines a target distributed device according to the first identification information and the first geographical location. The target distributed device is at least one of the m distributed devices. The target distributed device obtains reference identity password information corresponding to the first username, matches the first identity password information with the reference identity password information, and determines that the authentication of the first terminal device is passed when the first identity password information matches the reference identity password information. The master device can be regarded as a "communication interface", and communication is carried out between the master device and the first terminal device, which is equivalent to shunting the authentication. Thus, the workload of the master device can be reduced, that is, the system advantages of the virtual API gateway system are fully utilized, and a suitable distributed device is selected for authentication, which can improve the authentication efficiency and ensure security in the case of a large number of authentications. Furthermore, the intelligence of the API gateway authentication can be improved. Description of the Drawings
[0015] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0016] Figure 1 It is a schematic structural diagram of a virtual API gateway system composed of distributed devices provided by an embodiment of the present application;
[0017] Figure 2 It is a schematic flowchart of an authentication method applied to a virtual API gateway system composed of distributed devices provided by an embodiment of the present application;
[0018] Figure 3 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application;
[0019] Figure 4 It is a block diagram of the functional units of an authentication device applied to a virtual API gateway system composed of distributed devices provided by an embodiment of the present application. Detailed implementation manners
[0020] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may also include unlisted steps or units in a possible example, or other steps or units inherent to these processes, methods, products, or devices in a possible example.
[0021] Referring to "embodiment" herein means that a specific feature, structure, or characteristic described in connection with the embodiment may be included in at least one embodiment of the present application. The phrase appears in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will explicitly and implicitly understand that the embodiments described herein may be combined with other embodiments.
[0022] To enable those skilled in the art to better understand the solution of this application, the technical solutions in the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without making creative efforts shall fall within the protection scope of this application.
[0023] In the embodiments of this application, the distributed device may include any electronic product with specific communication functions. The electronic product may include but is not limited to: servers, smart watches, in-vehicle devices, smart bracelets, smart phones, routers, gateways, smart robots, smart switches, tablet computers, smart cars, smart glasses, computing devices or other processing devices connected to a wireless modem, as well as various forms of user equipment (User Equipment, UE), mobile stations (Mobile Station, MS), terminal devices, etc., which are not limited herein. The distributed device may also include a computer cluster.
[0024] In the embodiments of this application, the first terminal device may include any electronic product with specific communication functions. The electronic product may include but is not limited to: servers, smart watches, in-vehicle devices, smart bracelets, smart phones, routers, gateways, smart robots, smart switches, tablet computers, wearable devices, smart cars, smart glasses, computing devices or other processing devices connected to a wireless modem, as well as various forms of user equipment, mobile stations, terminal devices, etc., which are not limited herein.
[0025] In the embodiments of this application, the electronic device may include a master device, or any distributed device.
[0026] Please refer to Figure 1 , Figure 1 which is a schematic diagram of the architecture of a virtual API gateway system composed of distributed devices provided in the embodiments of this application. The virtual API gateway system includes m distributed devices and a master device, where m is an integer greater than 1; among them,
[0027] the master device is configured to receive an authentication request from the first terminal device. The authentication request includes: the first user identity information of the first terminal device, the first identification information of the first terminal device, and the first geographical location of the first terminal device; the first user identity information includes a first user name and first identity password information.
[0028] The master device is further configured to determine a target distributed device according to the first identification information and the first geographical location; the target distributed device is at least one of the m distributed devices;
[0029] The target distributed device is configured to obtain reference identity password information corresponding to the first user name, match the first identity password information with the reference identity password information, and determine that the identity authentication of the first terminal device is passed when the first identity password information matches the reference identity password information.
[0030] Wherein, the virtual API gateway system may include m distributed devices and a master device, and the master device may also be a distributed device. The master device can be regarded as a "communication interface" for communication between the master device and the first terminal device. The m distributed devices and the master device can be communicatively connected, and the m distributed devices and the master device can form a virtual API gateway system composed of distributed devices. The master device in the virtual API gateway system may include one or more devices, and any one of the m distributed devices can be understood as an independent device or a computer cluster.
[0031] Wherein, the first identification information can be used to uniquely identify the first terminal device, and the first identification information may include at least one of the following: physical address (Media Access Control, MAC), integrated circuit card identification code (Integrate circuit card identity, ICCID), international mobile equipment identity (International Mobile Equipment Identity, IMEI), etc., which is not limited herein.
[0032] Wherein, the first identity password information may include at least one of the following: string, pattern, fingerprint image, iris image, face image, vein image, etc., which is not limited herein.
[0033] Wherein, the identity authentication request may include: the first user identity information of the first terminal device, the first identification information of the first terminal device, and the first geographical location of the first terminal device. The first user identity information may include a first user name and the first identity password information. The first geographical location can be understood as the login location (i.e., the location where the virtual API gateway system is accessed).
[0034] Furthermore, the master device can also determine the target distributed device according to the first identification information and the first geographical location. The target distributed device is at least one of the m distributed devices, which is equivalent to shunting the authentication. Of course, the request tasks can include at least one of the following: authentication, protocol conversion, load balancing, etc., which are not limited here. Different request tasks can also correspond to different distributed devices. For example, some distributed devices are responsible for authentication, some distributed devices can also be responsible for protocol conversion, and some distributed devices can also be responsible for load balancing, etc. Thus, the workload of the master device can be reduced, that is, the system advantages of the virtual API gateway system can be fully utilized, and appropriate distributed devices can be selected for authentication. In the case of a large number of request tasks (such as authentication tasks), the authentication efficiency can be improved, and the security can also be guaranteed.
[0035] Among them, the reference identity password information can include at least one of the following: string, pattern, fingerprint image, iris image, face image, vein image, etc., which are not limited here. In specific implementation, when the first username is registered, the reference identity password information can be saved.
[0036] In specific implementation, the target distributed device can obtain the reference identity password information corresponding to the first username, match the first identity password information with the reference identity password information. When the first identity password information matches the reference identity password information successfully, it is determined that the first terminal device passes the authentication, and then the first terminal device is allowed to access the virtual API gateway system, realizing authentication shunting, reducing the workload of the master device, that is, fully utilizing the system advantages of the virtual API gateway system, selecting appropriate distributed devices for authentication, and being able to improve the authentication efficiency and ensure security in the case of a large number of authentications.
[0037] Optionally, in terms of determining the target distributed device according to the first identification information and the first geographical location, the master device is specifically used for:
[0038] Detect whether the first identification information exists through the historical successful access records of the virtual API gateway system; the historical successful access records include multiple device identification information;
[0039] If so, determine the distributed device identifier corresponding to the first geographical location to obtain the first distributed device identifier set; the first distributed device identifier set includes n first distributed device identifiers; n is a positive integer;
[0040] Determine the working state parameters of the distributed device corresponding to each first distributed device identifier in the n first distributed device identifiers to obtain n working state parameters;
[0041] Determine the state evaluation parameters corresponding to the n working state parameters to obtain n state evaluation parameters;
[0042] Determine the state evaluation parameters that meet the preset conditions among the n state evaluation parameters to obtain k state evaluation parameters; k is an integer less than or equal to n;
[0043] Determine the communication path lengths between the master device and the distributed devices corresponding to the k state evaluation parameters to obtain k communication path lengths;
[0044] Select the minimum value among the k communication path lengths, and use the distributed device corresponding to the minimum value as the target distributed device.
[0045] In specific implementation, the historical successful access records may include multiple device identification information, and this device identification information can be used to uniquely identify the logged-in device. The distributed device identification can be used to uniquely identify the distributed device.
[0046] In specific implementation, it can be detected whether there is a first identification information through the historical successful access records of the virtual API gateway system. If so, in specific implementation, the mapping relationship between the preset geographical location and the distributed device identification can be stored in advance. Furthermore, the distributed device identification corresponding to the first geographical location can be determined based on this mapping relationship to obtain a first set of distributed device identifications, and this first set of distributed device identifications can include n first distributed device identifications, where n is a positive integer.
[0047] Among them, the working state parameters of the distributed device may include at least one of the following: the load condition of the distributed device, the occupancy rate of the remaining memory resources of the distributed device (the ratio between the remaining memory resources of the distributed device and the total memory resources of the distributed device), etc., which are not limited here. The working state parameters reflect the working stability or performance of the distributed device to a certain extent. The larger the working state parameters, the better the working stability or performance of the distributed device, and vice versa.
[0048] Among them, the preset conditions can be set in advance or be the system default. For example, if the state evaluation parameter is greater than the preset state evaluation parameter, it means that the preset conditions are met. The preset state evaluation parameter can be set in advance or be the system default. The preset state evaluation parameter can be set in advance or be the system default. For example, the preset state evaluation parameter can be the average value of the n state evaluation parameters.
[0049] In a specific implementation, the working state parameters of the distributed devices corresponding to each of the n first distributed device identifiers can be determined to obtain n working state parameters. The mapping relationship between the preset working state parameters and the state evaluation parameters can also be stored in advance. Furthermore, based on this mapping relationship, the state evaluation parameters corresponding to the n working state parameters can be determined to obtain n state evaluation parameters. Then, the state evaluation parameters that meet the preset conditions among the n state evaluation parameters can be determined to obtain k state evaluation parameters. In this way, distributed devices with good working stability or performance can be selected to act as the target distributed devices, which can ensure the stability and efficiency of identity verification.
[0050] Furthermore, the communication path lengths between the master device and the distributed devices corresponding to the k state evaluation parameters can also be determined to obtain k communication path lengths. Then, the minimum value among the k communication path lengths is selected, and the distributed device corresponding to the minimum value is used as the target distributed device. In this way, the data transmission efficiency can be ensured, and the identity verification efficiency can be further improved.
[0051] Furthermore, optionally, the master device is further specifically configured to:
[0052] When the first identification information does not exist in the historical successful access records, push a verification code to the first terminal device;
[0053] When the verification code is successfully verified, execute the step of determining the distributed device identifier corresponding to the first geographical location to obtain the first set of distributed device identifiers.
[0054] In the embodiments of the present application, when the first identification information does not exist in the historical successful access records, it indicates that the first terminal device has not successfully accessed the virtual API gateway system before. To ensure security, a verification code can be pushed to the first terminal device. The verification code can include at least one of the following: patterns, strings, etc., which are not limited herein. When the verification code is successfully verified, the step of determining the distributed device identifier corresponding to the first geographical location to obtain the first set of distributed device identifiers can be executed, thereby ensuring the stability, security, and efficiency of identity verification.
[0055] Optionally, in terms of successfully matching the first identity password information with the reference identity password information, the target distributed device is specifically configured to:
[0056] When the first identification information exists in the historical successful access records, obtain the matching degrees of the successful accesses corresponding to the first identification information to obtain p matching degrees, each matching degree corresponding to a matching moment and a matching threshold; p is a positive integer;
[0057] Determine the access time of the most recent successful access corresponding to the first identification information;
[0058] Determine the first time interval between the access time and the current time;
[0059] Determine the first matching threshold corresponding to the first time interval;
[0060] Determine q matching values corresponding to the first time interval from the p matching degrees, where q is a positive integer less than or equal to p;
[0061] Determine the q matching thresholds corresponding to the q matching values;
[0062] Determine the deviation degrees between the q matching values and the q matching thresholds to obtain q deviation degrees;
[0063] Determine the q matching times corresponding to the q matching thresholds, and determine the time intervals between the q matching times and the current time to obtain q time intervals, and determine the weights corresponding to the q time intervals to obtain q weights;
[0064] Perform a weighted operation according to the q weights and the q deviation degrees to obtain a target deviation degree;
[0065] Determine the first adjustment parameter corresponding to the target deviation degree;
[0066] Adjust the first matching threshold according to the first adjustment parameter to obtain a second matching threshold;
[0067] Match the first identity password information with the reference identity password information according to the second matching threshold.
[0068] In specific implementation, when there is the first identification information in the historical successful access records, it indicates that the first terminal device has accessed the virtual API gateway system before. Then, the matching degrees of the successful access corresponding to the first identification information can be obtained to get p matching degrees, and each matching degree corresponds to a matching time and a matching threshold; p is a positive integer, that is, the historical access records of the first terminal device can be obtained, and then the matching threshold can be dynamically adjusted based on the historical access records of the first terminal device. Thus, both the security of identity authentication can be ensured and the efficiency of identity authentication can be improved.
[0069] Furthermore, the access time of the most recent successful access corresponding to the first identification information can be determined, and the first time interval between the access time and the current time can also be determined. The first time interval = current time - access time. In specific implementation, the first time interval reflects the user's habit of accessing the virtual API gateway system. The longer the first time interval is, the longer the interval between accessing the virtual API gateway system is, and vice versa.
[0070] Next, the mapping relationship between the preset time interval and the matching threshold can be pre-stored. Furthermore, based on this mapping relationship, the first matching threshold corresponding to the first time interval can be determined. For example, the longer the time interval, the larger the first matching threshold; conversely, the shorter the time interval, the smaller the first matching threshold. For different time intervals, the number of determined matching values is different. In specific implementation, the matching values corresponding to the number of matching values corresponding to the first time interval can be obtained in the order of time before and after the matching moment, that is, q matching values corresponding to the first time interval can be determined from p matching degrees, where q is a positive integer less than or equal to p. Correspondingly, q matching thresholds corresponding to the q matching values can be determined, and then the deviation degrees between the q matching values and the q matching thresholds can be determined to obtain q deviation degrees. Each deviation degree can be determined in the following manner: deviation degree = (matching value - matching threshold) / matching threshold.
[0071] Next, the q matching moments corresponding to the q matching thresholds can also be determined, and the time intervals between the q matching moments and the current moment can be determined to obtain q time intervals. The weights corresponding to the q time intervals can be determined to obtain q weights. Among them, the larger the time interval, the smaller the weight; conversely, the smaller the time interval, the larger the weight. Specifically, the mapping relationship between the preset time interval and the weight factor can be pre-stored, and based on this mapping relationship, the q weight factors corresponding to the q time intervals can be determined; the larger the time interval, the smaller the weight factor; conversely, the smaller the time interval, the larger the weight factor. That is, the q weight factors can be summed to obtain the total weight factor, and then the ratio between each weight factor in the q weight factors and the total weight factor can be determined to obtain q weights.
[0072] Further, weighted operations can be performed based on q weights and q deviation degrees to obtain a target deviation degree, that is, each weight is multiplied by the corresponding deviation degree to obtain q weighted deviation degrees, and then the q weighted deviation degrees are summed to obtain the target deviation degree. A mapping relationship between a preset deviation degree and an adjustment parameter can also be pre-stored. Furthermore, based on this mapping relationship, a first adjustment parameter corresponding to the target deviation degree can be determined. The value range of the adjustment parameter can be preset or default in the system. For example, the adjustment parameter can be 0 to 0.05. Furthermore, the first matching threshold can be adjusted according to the first adjustment parameter to obtain a second matching threshold. The second matching threshold = (1 - the first adjustment parameter) * the first matching threshold. Then, according to the second matching threshold, the first identity password information is matched with the reference identity password information, that is, the first terminal device has successfully accessed the virtual API gateway system. Specifically, when the matching value between the first identity password information and the reference identity password information is greater than the second matching threshold, it is determined that the identity verification of the first terminal device is passed; otherwise, it is determined that the identity verification of the first terminal device fails. In this way, the matching threshold can be dynamically lowered based on the historical access record of the first terminal device, that is, the identity verification security can be ensured and the identity verification efficiency can also be improved.
[0073] Optionally, the target distributed device is further specifically configured to:
[0074] When the first identification information does not exist in the historical successful access record, detect whether the first username exists in the registration information database;
[0075] When the first username exists in the registration information database, obtain the login locations corresponding to the first username to get a login locations, and select the login locations with the login times greater than the preset times from the a login locations to get b login locations; both a and b are positive integers, and b is less than or equal to a;
[0076] Determine the distances between the b login locations and the first geographical location to get b distances, and select the minimum distance among the b distances;
[0077] Determine a second adjustment parameter corresponding to the minimum distance;
[0078] Adjust the first matching threshold according to the second adjustment parameter to obtain a third matching threshold;
[0079] Match the first identity password information with the reference identity password information according to the third matching threshold.
[0080] In specific implementation, the registration information database may include multiple usernames, and the registration information database may be stored in the master device or any one of the m distributed devices.
[0081] In a specific implementation, when the first identification information does not exist in the historical successful access records, it indicates that the first terminal device has not successfully accessed the virtual API gateway system. Then, it is possible to detect whether the first username exists in the registration information repository. When the first username exists in the registration information repository, it indicates that the user corresponding to the first username may access the virtual API gateway system by changing the device.
[0082] In the embodiments of the present application, the preset number of times can be set in advance or be the system default. The login location where the number of logins is greater than the preset number of times can be understood as the common login location. It is possible to obtain the login locations corresponding to the first username, obtaining a login locations, and select the login locations where the number of logins is greater than the preset number of times from the a login locations, obtaining b login locations; both a and b are positive integers, and b is less than or equal to a.
[0083] Next, it is possible to determine the distances between the b login locations and the first geographical location, obtaining b distances, select the minimum distance among the b distances, and then determine the second adjustment parameter corresponding to the minimum distance. For example, it is possible to pre-store the mapping relationship between the preset distances and the adjustment parameters in advance. The value range of the adjustment parameter can be set in advance or be the system default. For example, the adjustment parameter can be 0 to 0.2. Furthermore, it is possible to determine the second adjustment parameter corresponding to the minimum distance based on this mapping relationship, and then adjust the first matching threshold according to the second adjustment parameter, obtaining the third matching threshold. The third matching threshold = (1 + the second adjustment parameter) * the first matching threshold. Finally, it is possible to match the first identity password information with the reference identity password information according to the third matching threshold, that is, when the matching value between the first identity password information and the reference identity password information is greater than the third matching threshold, it is determined that the identity authentication of the first terminal device is passed; otherwise, it is determined that the identity authentication of the first terminal device fails. In this way, when the first terminal device has not successfully accessed the virtual API gateway system, the matching threshold can be dynamically increased based on the distance between the login location and the common login location, that is, the identity authentication security can be ensured.
[0084] It can be seen that in the virtual API gateway system composed of distributed devices described in the embodiments of the present application, the virtual API gateway system includes m distributed devices and a master device, where m is an integer greater than 1. Among them, the master device receives an authentication request from a first terminal device. The authentication request includes: the first user identity information of the first terminal device, the first identification information of the first terminal device, and the first geographical location of the first terminal device. The first user identity information includes a first user name and first identity password information. The master device determines a target distributed device according to the first identification information and the first geographical location. The target distributed device is at least one of the m distributed devices. The target distributed device obtains reference identity password information corresponding to the first user name, matches the first identity password information with the reference identity password information, and when the first identity password information matches the reference identity password information successfully, it is determined that the authentication of the first terminal device is passed. The master device can be regarded as a "communication interface", and communication is carried out between the master device and the first terminal device, which is equivalent to shunting the authentication. Therefore, the workload of the master device can be reduced, that is, the system advantages of the virtual API gateway system can be fully utilized, and a suitable distributed device can be selected for authentication. When there are a large number of authentications, the authentication efficiency can be improved, and the security can also be ensured. Furthermore, the intelligence of the API gateway authentication can be improved.
[0085] Please refer to Figure 2 , Figure 2 which is a schematic flowchart of an authentication method applied to a virtual API gateway system composed of distributed devices provided by an embodiment of the present application, and is applied to a virtual API gateway system as Figure 1 shown. The virtual API gateway system includes m distributed devices and a master device. The authentication method includes:
[0086] 201. Receive an authentication request from a first terminal device through the master device. The authentication request includes: the first user identity information of the first terminal device, the first identification information of the first terminal device, and the first geographical location of the first terminal device. The first user identity information includes a first user name and first identity password information;
[0087] 202. Determine a target distributed device according to the first identification information and the first geographical location through the master device. The target distributed device is at least one of the m distributed devices;
[0088] 203. Obtain the reference identity password information corresponding to the first user name through the target distributed device, match the first identity password information with the reference identity password information, and when the first identity password information matches the reference identity password information successfully, determine that the identity authentication of the first terminal device passes.
[0089] Optionally, for step 202 above, determining the target distributed device according to the first identification information and the first geographical location can be implemented as follows:
[0090] Detect whether the first identification information exists through the historical successful access records of the virtual API gateway system; the historical successful access records include multiple device identification information;
[0091] If so, determine the distributed device identifier corresponding to the first geographical location to obtain a first set of distributed device identifiers; the first set of distributed device identifiers includes n first distributed device identifiers; n is a positive integer;
[0092] Determine the working state parameters of the distributed device corresponding to each first distributed device identifier in the n first distributed device identifiers to obtain n working state parameters;
[0093] Determine the state evaluation parameters corresponding to the n working state parameters to obtain n state evaluation parameters;
[0094] Determine the state evaluation parameters that meet the preset conditions among the n state evaluation parameters to obtain k state evaluation parameters; k is an integer less than or equal to n;
[0095] Determine the communication path lengths between the master device and the distributed devices corresponding to the k state evaluation parameters to obtain k communication path lengths;
[0096] Select the minimum value among the k communication path lengths, and use the distributed device corresponding to the minimum value as the target distributed device.
[0097] Optionally, the following steps may further be included:
[0098] When the first identification information does not exist in the historical successful access records through the master device, push a verification code to the first terminal device;
[0099] When the verification code is verified successfully, execute the step of determining the distributed device identifier corresponding to the first geographical location to obtain a first set of distributed device identifiers.
[0100] Optionally, for step 203 above, matching the first identity password information with the reference identity password information can be implemented as follows:
[0101] When the first identification information exists in the historical successful access records, obtain the matching degrees of the successful accesses corresponding to the first identification information, and obtain p matching degrees, where each matching degree corresponds to a matching moment and a matching threshold; p is a positive integer;
[0102] Determine the access moment of the most recent successful access corresponding to the first identification information;
[0103] Determine the first time interval between the access moment and the current moment;
[0104] Determine the first matching threshold corresponding to the first time interval;
[0105] Determine q matching values corresponding to the first time interval from the p matching degrees, where q is a positive integer less than or equal to p;
[0106] Determine the q matching thresholds corresponding to the q matching values;
[0107] Determine the deviation degrees between the q matching values and the q matching thresholds, and obtain q deviation degrees;
[0108] Determine the q matching moments corresponding to the q matching thresholds, and determine the time intervals between the q matching moments and the current moment, obtain q time intervals, determine the weights corresponding to the q time intervals, and obtain q weights;
[0109] Perform a weighted operation according to the q weights and the q deviation degrees to obtain a target deviation degree;
[0110] Determine the first adjustment parameter corresponding to the target deviation degree;
[0111] Adjust the first matching threshold according to the first adjustment parameter to obtain a second matching threshold;
[0112] Match the first identity password information with the reference identity password information according to the second matching threshold.
[0113] Optionally, the following steps may further be included:
[0114] When the first identification information does not exist in the historical successful access records through the target distributed device, detect whether the first username exists in the registration information database;
[0115] When the first user name exists in the registration information database, obtain the login locations corresponding to the first user name, obtain a login locations, and select from the a login locations the login locations where the number of logins is greater than a preset number, obtaining b login locations; both a and b are positive integers, and b is less than or equal to a;
[0116] Determine the distances between the b login locations and the first geographical location, obtaining b distances, and select the minimum distance among the b distances;
[0117] Determine the second adjustment parameter corresponding to the minimum distance;
[0118] Adjust the first matching threshold according to the second adjustment parameter, obtaining a third matching threshold;
[0119] Match the first identity password information with the reference identity password information according to the third matching threshold.
[0120] Among them, any step in the above identity verification method can refer to the corresponding description of the virtual API gateway system described above Figure 1 and will not be elaborated here.
[0121] It can be seen that the identity verification method applied to the virtual API gateway system composed of distributed devices described in the embodiments of the present application. The virtual API gateway system includes m distributed devices and a master device, where m is an integer greater than 1; among them, the master device receives an identity verification request from a first terminal device. The identity verification request includes: the first user identity information of the first terminal device, the first identification information of the first terminal device, and the first geographical location of the first terminal device; the first user identity information includes a first user name and first identity password information. The master device determines a target distributed device according to the first identification information and the first geographical location; the target distributed device is at least one of the m distributed devices. The target distributed device obtains reference identity password information corresponding to the first user name, and matches the first identity password information with the reference identity password information. When the first identity password information and the reference identity password information match successfully, it is determined that the identity verification of the first terminal device is passed. The master device can be regarded as a "communication interface", and communication is carried out between the master device and the first terminal device, which is equivalent to shunting the identity verification. Thus, the workload of the master device can be reduced, that is, the system advantages of the virtual API gateway system are fully utilized, and a suitable distributed device is selected for identity verification, which can improve the identity verification efficiency in the case of a large number of identity verifications and can also ensure security. Furthermore, the intelligence of the API gateway identity verification can be improved.
[0122] Consistent with the above embodiments, please refer to Figure 3 , Figure 3It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. The electronic device includes a processor, a memory, a communication interface, and one or more programs. Among them, the above one or more programs are stored in the above memory and are configured to be executed by the above processor. In the embodiment of the present application, it is applied to a virtual API gateway system, and the virtual API gateway system includes m distributed devices and a master device, where m is an integer greater than 1; the above program includes instructions for performing the following steps:
[0123] Receive an authentication request from a first terminal device through the master device. The authentication request includes: the first user identity information of the first terminal device, the first identification information of the first terminal device, and the first geographical location of the first terminal device; the first user identity information includes a first user name and first identity password information;
[0124] Determine a target distributed device through the master device according to the first identification information and the first geographical location; the target distributed device is at least one of the m distributed devices;
[0125] Obtain reference identity password information corresponding to the first user name through the target distributed device, match the first identity password information with the reference identity password information, and when the first identity password information matches the reference identity password information successfully, determine that the authentication of the first terminal device passes.
[0126] Optionally, in terms of determining the target distributed device according to the first identification information and the first geographical location, the above program includes instructions for performing the following steps:
[0127] Detect whether the first identification information exists through the historical successful access records of the virtual API gateway system; the historical successful access records include multiple device identification information;
[0128] If so, determine the distributed device identifier corresponding to the first geographical location to obtain a first distributed device identifier set; the first distributed device identifier set includes n first distributed device identifiers; n is a positive integer;
[0129] Determine the working state parameters of the distributed devices corresponding to each of the n first distributed device identifiers to obtain n working state parameters;
[0130] Determine the state evaluation parameters corresponding to the n working state parameters to obtain n state evaluation parameters;
[0131] Determine the state evaluation parameters that meet the preset conditions among the n state evaluation parameters to obtain k state evaluation parameters; k is an integer less than or equal to n;
[0132] Determine the communication path lengths between the master device and the distributed devices corresponding to the k state evaluation parameters, obtaining k communication path lengths;
[0133] Select the minimum value among the k communication path lengths, and use the distributed device corresponding to the minimum value as the target distributed device.
[0134] Optionally, the above program further includes instructions for performing the following steps:
[0135] When the first identification information does not exist in the historical successful access records through the master device, push a verification code to the first terminal device;
[0136] When the verification code is successfully verified, perform the step of determining the distributed device identifier corresponding to the first geographical location, obtaining the first set of distributed device identifiers.
[0137] Optionally, in terms of matching the first identity password information with the reference identity password information, the above program includes instructions for performing the following steps:
[0138] When the first identification information exists in the historical successful access records, obtain the matching degrees of the successful accesses corresponding to the first identification information, obtaining p matching degrees, each matching degree corresponding to a matching time and a matching threshold; p is a positive integer;
[0139] Determine the access time of the most recent successful access corresponding to the first identification information;
[0140] Determine the first time interval between the access time and the current time;
[0141] Determine the first matching threshold corresponding to the first time interval;
[0142] Determine q matching values corresponding to the first time interval from the p matching degrees, where q is a positive integer less than or equal to p;
[0143] Determine the q matching thresholds corresponding to the q matching values;
[0144] Determine the deviation degrees between the q matching values and the q matching thresholds, obtaining q deviation degrees;
[0145] Determine the q matching times corresponding to the q matching thresholds, and determine the time intervals between the q matching times and the current time, obtaining q time intervals, and determine the weights corresponding to the q time intervals, obtaining q weights;
[0146] Perform a weighted operation based on the q weights and the q deviations to obtain a target deviation;
[0147] Determine a first adjustment parameter corresponding to the target deviation;
[0148] Adjust the first matching threshold according to the first adjustment parameter to obtain a second matching threshold;
[0149] Match the first identity password information with the reference identity password information according to the second matching threshold.
[0150] Optionally, the above program further includes instructions for performing the following steps:
[0151] When the first identification information does not exist in the historical successful access records through the target distributed device, detect whether the first username exists in the registration information repository;
[0152] When the first username exists in the registration information repository, obtain the login locations corresponding to the first username to get a login locations, and select the login locations with the login times greater than a preset number from the a login locations to get b login locations; both a and b are positive integers, and b is less than or equal to a;
[0153] Determine the distances between the b login locations and the first geographical location to get b distances, and select the minimum distance among the b distances;
[0154] Determine a second adjustment parameter corresponding to the minimum distance;
[0155] Adjust the first matching threshold according to the second adjustment parameter to obtain a third matching threshold;
[0156] Match the first identity password information with the reference identity password information according to the third matching threshold.
[0157] It can be seen that the electronic device described in the embodiments of the present application is applied to a virtual API gateway system composed of distributed devices. The virtual API gateway system includes m distributed devices and a master device, where m is an integer greater than 1. Among them, the master device receives an authentication request from a first terminal device. The authentication request includes: the first user identity information of the first terminal device, the first identification information of the first terminal device, and the first geographical location of the first terminal device. The first user identity information includes a first username and first identity password information. The master device determines a target distributed device according to the first identification information and the first geographical location. The target distributed device is at least one of the m distributed devices. The target distributed device obtains reference identity password information corresponding to the first username, and matches the first identity password information with the reference identity password information. When the first identity password information matches the reference identity password information successfully, it is determined that the authentication of the first terminal device is passed. The master device can be regarded as a "communication interface", and communication is carried out between the master device and the first terminal device, which is equivalent to shunting the authentication. Therefore, the workload of the master device can be reduced, that is, the system advantages of the virtual API gateway system are fully utilized, and a suitable distributed device is selected for authentication. It can improve the authentication efficiency in the case of a large number of authentications and ensure security. Furthermore, the intelligence of the API gateway authentication can be improved.
[0158] Figure 4 It is a functional unit composition block diagram of an authentication device 400 involved in the embodiments of the present application, which is applied to a virtual API gateway system composed of distributed devices. The virtual API gateway system includes m distributed devices and a master device, where m is an integer greater than 1. The authentication device 400 includes: a receiving unit 401, a determining unit 402, and a verifying unit 403. Among them,
[0159] The receiving unit 401 is configured to receive an authentication request from a first terminal device through the master device. The authentication request includes: the first user identity information of the first terminal device, the first identification information of the first terminal device, and the first geographical location of the first terminal device. The first user identity information includes a first username and first identity password information;
[0160] The determining unit 402 is configured to determine a target distributed device according to the first identification information and the first geographical location through the master device. The target distributed device is at least one of the m distributed devices;
[0161] The verification unit 403 is configured to obtain, through the target distributed device, reference identity password information corresponding to the first user name, match the first identity password information with the reference identity password information, and determine that the identity authentication of the first terminal device is passed when the first identity password information matches the reference identity password information.
[0162] Optionally, in terms of determining the target distributed device according to the first identification information and the first geographical location, the determining unit 402 is specifically configured to:
[0163] Detect whether the first identification information exists through the historical successful access records of the virtual API gateway system; the historical successful access records include multiple device identification information;
[0164] If so, determine the distributed device identification corresponding to the first geographical location to obtain a first distributed device identification set; the first distributed device identification set includes n first distributed device identifications; n is a positive integer;
[0165] Determine the working state parameters of the distributed device corresponding to each of the n first distributed device identifications to obtain n working state parameters;
[0166] Determine the state evaluation parameters corresponding to the n working state parameters to obtain n state evaluation parameters;
[0167] Determine the state evaluation parameters that meet the preset conditions among the n state evaluation parameters to obtain k state evaluation parameters; k is an integer less than or equal to n;
[0168] Determine the communication path lengths between the master device and the distributed devices corresponding to the k state evaluation parameters to obtain k communication path lengths;
[0169] Select the minimum value among the k communication path lengths, and use the distributed device corresponding to the minimum value as the target distributed device.
[0170] Optionally, the identity authentication device 400 is further specifically configured to:
[0171] When the first identification information does not exist in the historical successful access records through the master device, push a verification code to the first terminal device;
[0172] When the verification code is successfully verified, execute the step of determining the distributed device identification corresponding to the first geographical location to obtain a first distributed device identification set.
[0173] Optionally, in terms of matching the first identity password information with the reference identity password information, the verification unit 403 is specifically configured to:
[0174] When the first identification information exists in the historical successful access records, obtain the matching degrees of the successful accesses corresponding to the first identification information, obtaining p matching degrees, each matching degree corresponding to a matching moment and a matching threshold; p is a positive integer;
[0175] Determine the access moment of the most recent successful access corresponding to the first identification information;
[0176] Determine a first time interval between the access moment and the current moment;
[0177] Determine a first matching threshold corresponding to the first time interval;
[0178] Determine q matching values corresponding to the first time interval from the p matching degrees, where q is a positive integer less than or equal to p;
[0179] Determine q matching thresholds corresponding to the q matching values;
[0180] Determine the deviation degrees between the q matching values and the q matching thresholds, obtaining q deviation degrees;
[0181] Determine q matching moments corresponding to the q matching thresholds, and determine the time intervals between the q matching moments and the current moment, obtaining q time intervals, and determine the weights corresponding to the q time intervals, obtaining q weights;
[0182] Perform a weighted operation based on the q weights and the q deviation degrees to obtain a target deviation degree;
[0183] Determine a first adjustment parameter corresponding to the target deviation degree;
[0184] Adjust the first matching threshold according to the first adjustment parameter to obtain a second matching threshold;
[0185] Match the first identity password information with the reference identity password information according to the second matching threshold.
[0186] Optionally, the identity verification device 400 is further specifically configured to:
[0187] When the first identification information does not exist in the historical successful access records through the target distributed device, detect whether the first user name exists in the registration information repository;
[0188] When the first user name exists in the registration information database, obtain the login locations corresponding to the first user name, obtain a login locations, and select, from the a login locations, the login locations where the login times are greater than a preset number of times to obtain b login locations; both a and b are positive integers, and b is less than or equal to a;
[0189] Determine the distances between the b login locations and the first geographical location to obtain b distances, and select the minimum distance among the b distances;
[0190] Determine the second adjustment parameter corresponding to the minimum distance;
[0191] Adjust the first matching threshold according to the second adjustment parameter to obtain a third matching threshold;
[0192] Match the first identity password information with the reference identity password information according to the third matching threshold.
[0193] It can be seen that the identity verification device described in the embodiments of the present application is applied to a virtual API gateway system composed of distributed devices. The virtual API gateway system includes m distributed devices and a main device, where m is an integer greater than 1; among them, the main device receives an identity verification request from a first terminal device. The identity verification request includes: the first user identity information of the first terminal device, the first identification information of the first terminal device, and the first geographical location of the first terminal device; the first user identity information includes a first user name and first identity password information. The main device determines a target distributed device according to the first identification information and the first geographical location; the target distributed device is at least one of the m distributed devices. The target distributed device obtains the reference identity password information corresponding to the first user name, and matches the first identity password information with the reference identity password information. When the first identity password information and the reference identity password information match successfully, it is determined that the identity verification of the first terminal device is passed. The main device can be regarded as a "communication interface", and communication is carried out between the main device and the first terminal device, which is equivalent to shunting the identity verification. Therefore, the workload of the main device can be reduced, that is, the system advantages of the virtual API gateway system are fully utilized, and a suitable distributed device is selected for identity verification, which can improve the identity verification efficiency and ensure security in the case of a large number of identity verifications. Furthermore, the intelligence of the API gateway identity verification can be improved.
[0194] It can be understood that the functions of the program modules of the identity verification device applied to the virtual API gateway system composed of distributed devices in this embodiment can be specifically implemented according to the methods in the above method embodiments, and the specific implementation process can refer to the relevant descriptions of the above method embodiments, which will not be elaborated here.
[0195] An embodiment of the present application also provides a computer storage medium. The computer storage medium stores a computer program for electronic data exchange, and the computer program enables a computer to execute some or all of the steps of any one of the methods described in the foregoing method embodiments. The foregoing computer includes an electronic device.
[0196] An embodiment of the present application also provides a computer program product. The computer program product includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to enable a computer to execute some or all of the steps of any one of the methods described in the foregoing method embodiments. The computer program product may be a software installation package, and the foregoing computer includes an electronic device.
[0197] It should be noted that, for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, some steps may be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0198] In the above embodiments, the descriptions of the various embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0199] In several embodiments provided by the present application, it should be understood that the disclosed device can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the above division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection may be through some interfaces. The indirect coupling or communication connection of the device or unit may be in an electrical or other form.
[0200] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0201] In addition, in each embodiment of the present application, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0202] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the above-mentioned methods in each embodiment of the present application. The aforementioned memory includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs, etc., which are all media that can store program codes.
[0203] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing relevant hardware through a program. This program can be stored in a computer-readable memory, and the memory can include: flash drives, read-only memories (abbreviation: ROM), random access memories (abbreviation: RAM), magnetic disks, or optical discs, etc.
[0204] The above has introduced the embodiments of the present application in detail. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those of ordinary skill in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.
Claims
1. A virtual API gateway system composed of distributed devices, characterized in that: The virtual API gateway system includes m distributed devices and a master device, where m is an integer greater than 1; wherein, The main device is used to receive an identity authentication request from a first terminal device, the identity authentication request including: first user identity information of the first terminal device, first identification information of the first terminal device, and a first geographic location of the first terminal device; the first user identity information includes a first user name and a first identity password information; The master device is further configured to determine a target distributed device according to the first identification information and the first geographical location; the target distributed device is at least one distributed device among the m distributed devices; The target distributed device is used to obtain reference identity and password information corresponding to the first user name, match the first identity and password information with the reference identity and password information, and determine that the identity authentication of the first terminal device is passed when the first identity and password information successfully match the reference identity and password information.
2. The system according to claim 1, characterized in that In the aspect of determining the target distributed device according to the first identification information and the first geographical location, the master device is specifically configured to: Detecting whether the first identification information exists through the historical successful access record of the virtual API gateway system; the historical successful access record includes multiple device identification information; If yes, determine the distributed device identifier corresponding to the first geographical location to obtain a first distributed device identifier set; the first distributed device identifier set includes n first distributed device identifiers; n is a positive integer; Determine a working state parameter of a distributed device corresponding to each of the n first distributed device identifiers to obtain n working state parameters; Determine the state evaluation parameters corresponding to the n working state parameters to obtain n state evaluation parameters; Determine the state evaluation parameters that meet the preset conditions among the n state evaluation parameters to obtain k state evaluation parameters; k is an integer less than or equal to n; Determine the communication path length between the master device and the distributed devices corresponding to the k state evaluation parameters to obtain k communication path lengths; A minimum value among the k communication path lengths is selected, and a distributed device corresponding to the minimum value is used as the target distributed device.
3. The system according to claim 2, characterized in that The master device is also specifically used for: When the first identification information does not exist in the historical successful access record, pushing a verification code to the first terminal device; When the verification code is successfully verified, the step of determining the distributed device identification corresponding to the first geographical location to obtain a first distributed device identification set is performed.
4. The system according to claim 3, characterized in that In the aspect of matching the first identity password information with the reference identity password information, the target distributed device is specifically used to: When the first identification information exists in the historical successful access record, the matching degree of the successful access corresponding to the first identification information is obtained to obtain p matching degrees, each matching degree corresponds to a matching time and a matching threshold; p is a positive integer; Determine the access time of the most recent successful access corresponding to the first identification information; Determining a first time interval between the access time and the current time; determining a first matching threshold corresponding to the first time interval; Determine q matching values corresponding to the first time interval from the p matching degrees, where q is a positive integer less than or equal to p; Determine q matching thresholds corresponding to the q matching values; Determine the deviations between the q matching values and the q matching thresholds to obtain q deviations; Determine q matching moments corresponding to the q matching thresholds, determine the time intervals between the q matching moments and the current moment, obtain q time intervals, determine the weights corresponding to the q time intervals, and obtain q weights; Perform a weighted operation according to the q weights and the q deviations to obtain a target deviation; determining a first adjustment parameter corresponding to the target deviation; Adjust the first matching threshold according to the first adjustment parameter to obtain a second matching threshold; The first identity password information is matched with the reference identity password information according to the second matching threshold.
5. The system according to claim 4, characterized in that The target distributed device is also specifically used for: When the first identification information does not exist in the historical successful access record, detecting whether the first user name exists in a registration information database; When the first user name exists in the registration information database, obtaining a login position corresponding to the first user name to obtain a login position, and selecting a login position having a login number greater than a preset number from the a login positions to obtain b login positions; a and b are both positive integers, b is less than or equal to a; Determine the distance between the b login locations and the first geographical location, obtain b distances, and select the minimum distance among the b distances; determining a second adjustment parameter corresponding to the minimum distance; Adjust the first matching threshold according to the second adjustment parameter to obtain a third matching threshold; The first identity password information is matched with the reference identity password information according to the third matching threshold.
6. An identity authentication method applied to a virtual API gateway system composed of distributed devices, characterized in that: The virtual API gateway system includes m distributed devices and a master device, where m is an integer greater than 1; the method includes: receiving, by the main device, an identity authentication request from a first terminal device, the identity authentication request including: first user identity information of the first terminal device, first identification information of the first terminal device, and a first geographic location of the first terminal device; the first user identity information including a first user name and a first identity password information; Determine, by the master device, a target distributed device according to the first identification information and the first geographical location; the target distributed device is at least one distributed device among the m distributed devices; The reference identity and password information corresponding to the first user name is obtained through the target distributed device, and the first identity and password information is matched with the reference identity and password information. When the first identity and password information match successfully, it is determined that the identity authentication of the first terminal device is passed.
7. The method according to claim 6, characterized in that The determining the target distributed device according to the first identification information and the first geographical location includes: Detecting whether the first identification information exists through the historical successful access record of the virtual API gateway system; the historical successful access record includes multiple device identification information; If yes, determine the distributed device identifier corresponding to the first geographical location to obtain a first distributed device identifier set; the first distributed device identifier set includes n first distributed device identifiers; n is a positive integer; Determine a working state parameter of a distributed device corresponding to each of the n first distributed device identifiers to obtain n working state parameters; Determine the state evaluation parameters corresponding to the n working state parameters to obtain n state evaluation parameters; Determine the state evaluation parameters that meet the preset conditions among the n state evaluation parameters to obtain k state evaluation parameters; k is an integer less than or equal to n; Determine the communication path length between the master device and the distributed devices corresponding to the k state evaluation parameters to obtain k communication path lengths; A minimum value among the k communication path lengths is selected, and a distributed device corresponding to the minimum value is used as the target distributed device.
8. The method according to claim 7, characterized in that The method is also specifically used for: When the first identification information does not exist in the historical successful access record, pushing a verification code to the first terminal device through the main device; When the verification code is successfully verified, the step of determining the distributed device identification corresponding to the first geographical location to obtain a first distributed device identification set is performed.
9. The method according to claim 8, characterized in that The matching the first identity password information with the reference identity password information includes: When the first identification information exists in the historical successful access record, the matching degree of the successful access corresponding to the first identification information is obtained to obtain p matching degrees, each matching degree corresponds to a matching time and a matching threshold; p is a positive integer; Determine the access time of the most recent successful access corresponding to the first identification information; Determining a first time interval between the access time and the current time; determining a first matching threshold corresponding to the first time interval; Determine q matching values corresponding to the first time interval from the p matching degrees, where q is a positive integer less than or equal to p; Determine q matching thresholds corresponding to the q matching values; Determine the deviations between the q matching values and the q matching thresholds to obtain q deviations; Determine q matching moments corresponding to the q matching thresholds, determine the time intervals between the q matching moments and the current moment, obtain q time intervals, determine the weights corresponding to the q time intervals, and obtain q weights; Perform a weighted operation according to the q weights and the q deviations to obtain a target deviation; determining a first adjustment parameter corresponding to the target deviation; Adjust the first matching threshold according to the first adjustment parameter to obtain a second matching threshold; The first identity password information is matched with the reference identity password information according to the second matching threshold.
10. The method according to claim 9, characterized in that The method further comprises: When the first identification information does not exist in the historical successful access record, detecting whether the first user name exists in a registration information database through the target distributed device; When the first user name exists in the registration information database, obtaining a login position corresponding to the first user name, obtaining a login position, and selecting a login position having a login number greater than a preset number from the a login positions, obtaining b login positions; a and b are both positive integers, and b is less than or equal to a; Determine the distance between the b login locations and the first geographical location, obtain b distances, and select the minimum distance among the b distances; determining a second adjustment parameter corresponding to the minimum distance; Adjust the first matching threshold according to the second adjustment parameter to obtain a third matching threshold; The first identity password information is matched with the reference identity password information according to the third matching threshold.