Capability access method and device, computer and storage medium
By uniformly managing and authenticating capability components and interfaces on the capability platform and building a capability center, the problems of high labor costs and low operation and maintenance efficiency of multi-interface calls in the business process are solved, and efficient integration and unified authentication of interfaces are achieved.
Patent Information
- Application Number
- CN202510108402.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-23
- Publication Date
- 2025-06-20
AI Technical Summary
In the prior art, multi-interface calls have problems such as high labor costs and low operation and maintenance efficiency in the business processing process, making it difficult to effectively integrate and manage interfaces in multiple different business scenarios.
By registering and auditing capability components on the capability platform, creating and testing interfaces, achieving unified management and certification, building capability centers to integrate and provide public capabilities.
It has realized the integration of interfaces in multiple different business scenarios to form unified authentication capabilities, significantly reducing the adaptation work of applications when connecting to public capabilities, simplifying the interface docking process, and improving efficiency and flexibility.
Smart Images

Figure CN120179547A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of information processing, and particularly relates to a method and device for accessing capabilities, a computer, and a storage medium. Background Art
[0002] With the continuous progress of IT informatization, the demand for interfaces in the process of business handling has become increasingly complex. In practical applications, a single business scenario often cannot be fully realized through a single business scenario interface, but rather requires the invocation of multiple interfaces of different business scenarios to jointly complete. For example, in the user login scenario, in addition to the basic login interface, multiple interfaces such as the interface for obtaining verification codes, the permission authentication interface, and the single sign-on jump interface need to be invoked to ensure that the user can successfully complete the login process.
[0003] However, this multi-interface invocation method has many deficiencies. There are also significant problems with traditional interface docking methods in terms of human costs. As the number of interfaces continues to increase, in order to ensure the stable operation and timely maintenance of the interfaces, enterprises need to continuously invest more human resources. This not only increases the operating costs of enterprises but also may lead to low efficiency in subsequent interface operation and maintenance work. Summary of the Invention
[0004] In order to solve the above technical problems, the present invention provides a method and device for accessing capabilities, a computer, and a storage medium to solve the technical problems in the prior art.
[0005] On the one hand, the invention provides the following technical solution. A method for accessing capabilities, the method comprising:
[0006] The capability provider registers a capability on the capability platform and enters the capability components of the capability, wherein the capability components include basic information, deliverables, functions, and performance;
[0007] The capability operator audits the registered capability and its corresponding capability components, and after passing the audit, creates multiple interfaces, each of the interfaces corresponding to a specific function or operation of the capability;
[0008] Conduct a comprehensive test on the capability, its capability components, and the interfaces to evaluate whether the preset release conditions are met;
[0009] If the release conditions are met, deploy the capability components and their corresponding interfaces on the capability platform;
[0010] The capability requester subscribes to the capability on the capability platform, and the capability platform generates a unique authorization authentication parameter information for the capability. After the capability provider identifies the unique authorization authentication parameter information, it authorizes the capability requester to call the corresponding interface service via the capability gateway;
[0011] During the entire process, the capability operator monitors the entry, review, release, subscription and call of the capability and records relevant operation data.
[0012] Compared with the existing technology, the beneficial effects of this application are: by implementing unified management in the process of entering, reviewing, publishing, subscribing and calling capabilities, it realizes the integration of various business scenario interfaces, forms a unified authentication capability, and builds a capability center for integrating and providing various public capabilities. Through this capability center, a unified docking solution is provided for different applications, which significantly reduces the various adaptation work required for applications to dock with public capabilities. Such a design not only simplifies the interface docking process, but also improves efficiency and flexibility.
[0013] Furthermore, the basic information includes capability name, version information, capability form, applicable terminals, capability description and application scenario.
[0014] Furthermore, the step of the capability demander applying to subscribe to the capability on the capability platform, and the capability platform generating unique authorization authentication parameter information of the capability includes:
[0015] The capability demander initiates an application to subscribe to the capability to the capability platform;
[0016] After accepting the application, the capability platform transmits the application information to the capability provider;
[0017] After the capability provider reviews and authorizes the application, the capability platform generates a capability authorization key and provides it to the capability demander.
[0018] Furthermore, after the capability provider identifies the unique authorization authentication parameter information, the step of authorizing the capability demander to call the corresponding interface service via the capability gateway includes:
[0019] The capability demander uses its calculation information in combination with the capability authorization key to perform signature calculation to generate a signature, wherein the calculation information includes the identity identifier of the capability demander, a random string, and a request time;
[0020] Embed the signature into the Header area of the HTTP request and send the request to the capability gateway;
[0021] The capability gateway extracts the signature of the Header area and verifies it according to a preset signature verification algorithm;
[0022] If the signature verification is successful, the capability gateway transmits the verification result to the capability provider, and the capability provider allows the capability demander to call the corresponding interface service accordingly.
[0023] Further, after the signature is extracted by the capability gateway, the method further includes:
[0024] The capability platform performs secondary verification on the signature in the request based on the authorization key of the capability provider and the corresponding signature verification algorithm;
[0025] If the signature verification is successful, the capability platform transmits the verification result to the capability provider.
[0026] Further, after the step of creating multiple interfaces, the method further includes:
[0027] Performing availability detection on each of the created interfaces to ensure that the parameter format of the interface conforms to a preset standard and meets the development requirements of the monitoring function of the interface;
[0028] When the access volume of the interface exceeds the single-machine bearing capacity, cluster deployment is used to ensure service continuity and maintain the uniqueness of the external service address.
[0029] Further, during the invocation of the capability, the capability gateway sequentially performs identity authentication verification, request rate, and concurrent request quantity limit. After meeting the conditions of the identity authentication verification, request rate, and concurrent request quantity limit, the invocation request of the capability is accurately routed to the corresponding capability service.
[0030] In a second aspect, the present invention provides the following technical solution, a capability access device, the device includes:
[0031] A registration module, configured to enable a capability provider to register a capability on a capability platform and input the capability components of the capability, wherein the capability components include basic information, deliverables, functions, and performance;
[0032] A creation module, configured to enable a capability operator to review the registered capability and its corresponding capability components. After passing the review, multiple interfaces are created, and each interface corresponds to a specific function or operation of the capability;
[0033] A release module, configured to comprehensively test the capability, its capability components, and interfaces, and evaluate whether the preset release conditions are met;
[0034] A deployment module, configured to, if the release conditions are met, deploy the capability components and their corresponding interfaces on the capability platform;
[0035] A calling module, which is used for a party with capacity requirements to apply for subscribing to the capacity on the capacity platform, and the capacity platform generates unique authorized authentication parameter information for the capacity. After the capacity provider identifies the unique authorized authentication parameter information, it authorizes the party with capacity requirements to call the corresponding interface service via the capacity gateway;
[0036] A recording module, which is used for the capacity operator to monitor the entire process of input, review, release, subscription and call of the capacity during the whole process, and record the relevant operation data.
[0037] Thirdly, the present invention provides the following technical solution. A computer includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the capacity access method as described above.
[0038] Fourthly, the present invention provides the following technical solution. A storage medium stores a computer program, and when the computer program is executed by a processor, it implements the capacity access method as described above. Description of the Drawings
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for use in the embodiments or the description of the prior art. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0040] Figure 1 It is a framework diagram of the capacity access method provided by the first embodiment of the present invention;
[0041] Figure 2 It is a flowchart of the capacity access method provided by the first embodiment of the present invention;
[0042] Figure 3 It is a schematic diagram of the interface encapsulation provided by the first embodiment of the present invention;
[0043] Figure 4 It is a schematic diagram of the interface availability detection provided by the first embodiment of the present invention;
[0044] Figure 5 It is a structural block diagram of the capacity access device provided by the second embodiment of the present invention;
[0045] Figure 6 It is a schematic diagram of the hardware structure of the computer provided by the third embodiment of the present invention.
[0046] The following will further explain the embodiments of the present invention with reference to the drawings. Detailed implementation mode
[0047] The following information describes embodiments of the present invention. Examples of the embodiments are shown in the accompanying drawings, where the same or similar reference numerals throughout denote the same or similar elements or elements having the same or similar functions. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to explain the embodiments of the present invention and should not be construed as limiting the present invention.
[0048] In the description of the embodiments of the present invention, it should be understood that the orientation or positional relationship indicated by terms such as "length", "width", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. is based on the orientation or positional relationship shown in the accompanying drawings, and is only for the convenience of describing the embodiments of the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and therefore should not be construed as limiting the present invention.
[0049] In addition, the terms "first" and "second" are only used for descriptive purposes and should not be construed as indicating or implying relative importance or implicitly indicating the quantity of the indicated technical features. Thus, features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the embodiments of the present invention, the meaning of "plural" is two or more unless otherwise specifically defined.
[0050] Embodiment 1
[0051] In the first embodiment of the present invention, please refer to Figure 1 , a capability access method. The overall framework of the capability access method is as follows: The capability provider develops capability components according to a preset specification and registers the capabilities on the capability platform. After the capability operator (management party) approves, the capability requester can apply to subscribe to the approved capabilities on the capability platform. The capability platform will perform capability technology detection and monitoring on the capabilities that have been put on the shelves.
[0052] Please refer to Figure 2 , a capability access method, including the following steps S01 to S04:
[0053] S01, the capability provider registers the capabilities on the capability platform and enters the capability components of the capabilities, where the capability components include basic information, deliverables, functions, and performances;
[0054] In this embodiment, capability registration is the starting step of the capability access process. When a capability provider registers a capability on the capability platform, it is required to enter in detail service access information, basic information, business information, as well as the capability provider's authorization key and related support and maintenance information. Among them, the basic information covers key details such as the capability name, version information, capability form, applicable terminals, capability description, and application scenarios.
[0055] The capability types in this embodiment are mainly divided into API capabilities and SDK capabilities. API capabilities refer to the relevant function interfaces provided by the capability provider, and the capability requester can implement specific functions by calling these interface functions. SDK capabilities, on the other hand, are components with relatively independent functions in a software system. The interfaces of these components are specified by contracts, have an obvious dependence on the context, and can be independently deployed and assembled. SDK components can be implemented in multiple languages such as C++, Java, and Golang, and have various forms, including but not limited to Java packages, war packages, source code, image services, container images, and container orchestration.
[0056] S02, the capability operator reviews the registered capability and its corresponding capability components. After passing the review, multiple interfaces are created, and each of the interfaces corresponds to a specific function or operation of the capability;
[0057] In this embodiment, the capability review stage follows capability registration. In this stage, the reviewers on the capability platform will conduct a comprehensive review of the submitted capabilities, including but not limited to reviewing the basic information of the capabilities, capability deliverables, capability functions, and capability performance. This process ensures that the capabilities meet the established standards and requirements to guarantee their quality and reliability. Once the review process is completed, the capability platform will feedback the review results to the capability provider.
[0058] After the step of creating multiple interfaces, the method further includes:
[0059] S21, perform availability detection on each of the created interfaces to ensure that the interface parameter format conforms to the preset standard and meets the development requirements of the interface monitoring function;
[0060] S22, when the interface access volume exceeds the single-machine bearing capacity, ensure service continuity through cluster deployment and maintain the uniqueness of the external service address.
[0061] Such as Figures 3 to 4, in this embodiment, after auditing the capabilities, the capabilities are encapsulated. The capability encapsulation includes: based on the approved capability components, performing multiple interface encapsulations, and supporting availability detection for the encapsulated interfaces. For example, for the unified authentication capability: each manufacturer needs to perform interface encapsulation for the unified authentication capability. The encapsulated interfaces include: checking the validity of tokens, exchanging authorization codes for tokens, user password modification interfaces, and institutional updated data acquisition interfaces. At the same time, the encapsulated interfaces must meet the following interface development standards:
[0062] 1: Develop strictly in accordance with the interface parameter formats for input and output specified by the capability platform.
[0063] 2: Ensure that the capability requester can use the subscribed capabilities stably and without interruption. The capability provider needs to develop monitoring interfaces, and the capability platform system will regularly scan the monitoring interfaces of the capability provider to notify and give early warnings for problem interfaces.
[0064] 3: When the interface access volume exceeds the single-machine bearing capacity, the interface needs to be provided externally in a cluster mode, and there can only be one external address.
[0065] S03, comprehensively test the capabilities, their capability components, and interfaces to evaluate whether the preset release conditions are met;
[0066] After the capability encapsulation is completed, a capability review will be conducted (which can be understood as determining whether the encapsulated capabilities meet the release conditions). At this stage, the capability operator will review the basic information of the capabilities submitted by the capability provider, the capability deliverables, the encapsulated interfaces, the capability test results, and the capability performance, etc. After the review is passed, the capability platform will send the review results to the capability provider.
[0067] When releasing capabilities, a series of requirements (release conditions) need to be met to ensure the smooth access and operation of the capabilities. These requirements include development requirements, that is, standardizing the input and output parameters of the API capabilities. For specific parameter requirements, please refer to Appendix A (API Capability Development). Monitoring requirements, that is, the capability provider needs to develop monitoring interfaces according to the requirements of Appendix B (Monitoring Development) so that the capability platform system can regularly scan the monitoring interfaces and give notifications and early warnings when problems are detected. Performance requirements, that is, when the service access volume exceeds the single-machine bearing capacity, the service needs to be provided in a cluster mode, and the external service address remains unique. Test requirements, that is, the capability provider needs to provide a set of capability test environments for the capability platform to test the capabilities and for the capability requester to debug the capabilities.
[0068] S04, if the release conditions are met, deploy the capability components and their corresponding interfaces on the capability platform;
[0069] After the review is passed (i.e., the release conditions are met), the capability will be released. After the release, capability management becomes a key link. Capability management functions include:
[0070] 1. Manage capability demanders to subscribe to capabilities and set corresponding access control rules.
[0071] 2.Perform performance monitoring and statistical data tracking of capacity usage, including key indicators such as call frequency and response time.
[0072] 3. Manage the lifecycle of capabilities and monitor the health status of released capabilities.
[0073] During the capability release process, the capability provider needs to upload the capability-related deliverables and apply to release the capability. The capability platform operator will review the registration information and deliverables of the capability to be released. After the review is passed, the capability to be put on the shelf will be tested. After the test passes, the release service is confirmed so that the capability can be subscribed and used by the capability demander. This process ensures the smooth release and efficient management of the capability.
[0074] S05, the capability demander applies to subscribe to the capability on the capability platform, and the capability platform generates unique authorization authentication parameter information of the capability. After the capability provider identifies the unique authorization authentication parameter information, it authorizes the capability demander to call the corresponding interface service via the capability gateway;
[0075] Specifically, the step of the capability demander applying to subscribe to the capability on the capability platform, and the capability platform generating unique authorization authentication parameter information of the capability includes:
[0076] S51, the capability demander initiates an application to subscribe to the capability to the capability platform;
[0077] S52, after accepting the application, the capability platform transmits the application information to the capability provider;
[0078] S53: After the capability provider reviews and authorizes the application, the capability platform generates a capability authorization key and provides it to the capability demander.
[0079] Specifically, after the capability provider identifies the unique authorization authentication parameter information, the step of authorizing the capability demander to call the corresponding interface service via the capability gateway includes:
[0080] S54, the capability demander uses its calculation information in combination with the capability authorization key to perform signature calculation to generate a signature, wherein the calculation information includes the identity identifier of the capability demander, a random string, and a request time;
[0081] S55. Embed the signature into the Header area of the HTTP request and send the request to the capability gateway.
[0082] S56. The capability gateway extracts the signature from the Header area and verifies it according to the preset signature verification algorithm.
[0083] S57. If the signature verification is successful, the capability gateway passes the verification result to the capability provider, and the capability provider allows the capability requester to call the corresponding interface service accordingly.
[0084] Optionally, after the capability gateway extracts the signature, the method further includes:
[0085] S58. The capability platform performs secondary verification on the signature in the request based on the authorization key of the capability provider and the corresponding signature verification algorithm.
[0086] S59. If the signature verification is successful, the capability platform passes the verification result to the capability provider.
[0087] In this embodiment, after the capability is published, the capability invocation process follows immediately. When the capability requester initiates an application to subscribe to a capability, the capability platform accepts the application and, after the capability provider's review and authorization are passed, generates an authorization key for the capability and provides it to the capability requester. Once the capability requester obtains the authorization key, they can start invoking the capability. The specific process of the capability gateway invoking the capability service is as follows:
[0088] Capability Requester:
[0089] 1. Calculate the signature using the requester identity identifier (rid), the requester authorization key (secret), the random string (nonce), and the request time (rtime) to obtain the capability requester signature (signature).
[0090] 2. Put the identity identifier (rid), the service identifier (sid), the random string (nonce), the request time
[0091] (rtime), and the signature (signature) into the Header area of the HTTP request and send the request to the capability gateway.
[0092] Capability Gateway:
[0093] 1. Obtain information such as the identity identifier (X-sso-rid), service identifier (X-sso-sid), random string (X-sso-nonce), request time (X-sso-rtime), and signature (X-sso-signature) in the request Header area, and perform signature verification according to the signature verification algorithm.
[0094] 2. If the signature verification is successful, forward the request to the capability provider.
[0095] Capability provider:
[0096] 1. Optionally, use the capability provider's authorization key (secret) for signature verification to ensure security.
[0097] 2. Obtain the request data and perform relevant business processing.
[0098] 3. Return the call result to the capability gateway, and then the capability gateway returns it to the capability requester.
[0099] During the process of calling the capability service, the capability gateway performs the following operations:
[0100] 1. Identity authentication verification: Ensure that the request comes from an authorized capability requester.
[0101] 2. Request rate and concurrent request quantity limit: Control the request traffic to prevent overload.
[0102] 3. Request routing: After meeting the conditions of the identity authentication verification, request rate, and concurrent request quantity limit, accurately route the call request for the capability to the corresponding capability service.
[0103] 4. If the service access volume exceeds the single-machine bearing capacity, the capability gateway needs to provide services externally in a cluster manner and ensure the uniqueness of the external service address to maintain the high availability and stability of the service.
[0104] S06. During the whole process, the capability operator monitors the entry, review, release, subscription, and call of the capability throughout the process and records the relevant operation data.
[0105] In this embodiment, the capability operator strictly supervises the entire life cycle of the capability to ensure that the capability requester can stably call the required capabilities. This supervision process covers all stages of the entry, review, release, subscription, and call of the capability and involves the following key measures:
[0106] Full-process monitoring and data recording:
[0107] The capability operator implements full - process monitoring, records relevant data, ensures the transparency and traceability of the capability process, and provides data support for the rapid location and solution of problems.
[0108] Regulatory measures:
[0109] Capability gateway log analysis:
[0110] The capability gateway monitors and analyzes API call log data in real - time, identifies potential anomalies or security threats, and issues early warning notifications in a timely manner so that countermeasures can be taken promptly.
[0111] Proactive detection:
[0112] The capability platform periodically sends detection requests to the API to ensure the availability and responsiveness of the API and prevent service interruptions.
[0113] In this embodiment, in terms of the API capability delivery standard, before the API is put on the capability platform, it is necessary to confirm that the API has the following resources:
[0114] I. API usage instruction document:
[0115] It includes the API usage environment, such as HTTP request / response functions, and data transmission and interaction capabilities on the Web.
[0116] Describe the main problems solved or functions possessed by the API.
[0117] Provide a detailed description of the API - related call parameters, including parameter descriptions, parameter types, and whether the parameters are required.
[0118] Describe the API response, including the description and type of response fields.
[0119] II. API call integration example:
[0120] Provide actual API call examples to help the capability requester quickly learn and effectively develop, debug problems, and verify the correctness of the integration.
[0121] In this embodiment, for the SDK capability delivery standard, the following resources need to be provided:
[0122] I. SDK package:
[0123] Provide the capability software entity package for the capability requester to obtain and use.
[0124] II. SDK usage instruction document:
[0125] List the system and environment requirements of the SDK, such as the supported operating system versions, minimum memory and storage requirements, etc.
[0126] Describe the steps required for installing and configuring the SDK.
[0127] Provide a list of common problems and solutions to help the requesters of capabilities quickly resolve issues when they arise.
[0128] III. SDK Usage Examples:
[0129] Provide rich sample codes that cover various usages and scenarios of the SDK to help the requesters of capabilities better understand how to use the SDK.
[0130] Finally, to ensure the security of data transmission, it is recommended to use the HTTPS protocol for API requests, and the server needs to be configured with a valid SSL / TLS certificate.
[0131] In summary, a method for accessing capabilities realizes the integration of interfaces for various different business scenarios, forms a unified authentication capability, and constructs a capability center for integrating and providing multiple common capabilities by implementing unified management during the processes of entering, reviewing, publishing, subscribing to, and invoking capabilities. Through this capability center, a unified docking solution is provided for different applications, significantly reducing the multi-faceted adaptation work required for applications to dock with common capabilities. Such a design not only simplifies the interface docking process but also improves efficiency and flexibility.
[0132] Appendix A
[0133] (Normative Appendix)
[0134] API Capability Development
[0135] A.1, Input Parameters
[0136] The Header area uses a key-value pair format and is commonly used to transmit control parameters. To reduce the access difficulty for the requesters of service capabilities and improve service utilization efficiency, this specification defines the service input parameter standard and authentication standard. To implement API service call authentication, it is necessary to add the X-sso-rid, X-sso-sid, X-sso-rtime, X-sso-nonce, and X-sso-signature attributes to the Header area of the Http request. The following table lists the input parameter standard.
[0137] Table G.1 Input Parameter Standard
[0138]
[0139] A.2, Output Format
[0140] The data content formats returned by the service are diverse and difficult to parse. To reduce the access difficulty of the business system and improve the resource utilization efficiency, this specification also defines the service output parameter standards. The following table lists the output parameter standards.
[0141] Table G.2 Output Parameter Standards
[0142]
[0143] Appendix B (Normative Appendix)
[0144] Monitoring Development
[0145] The service support of the monitoring capabilities provided by the capability platform system has two modes, and the capability provider can choose one monitoring method according to its own situation.
[0146] The first mode is that the provider monitors the interface. See Appendix A for details. Register the monitoring interface information and parameters in the capability platform system. The capability platform scans the monitoring interface regularly according to the monitoring interface information and parameters, obtains the return value of the monitoring interface, and judges whether the service is normal according to the return value;
[0147] The second mode stipulates to add the parameter X-options in the API capability request header. This parameter value can store multiple different values, separated by commas ",", such as: option1, option2. When the service provider receives an API request and the request header contains this parameter and the parameter value contains "test", it is regarded as a probe request.
[0148] Appendix C
[0149] (Normative Appendix)
[0150] Capability Invocation
[0151] API capability invocation is divided into two invocation methods: WEB Service service and RESTful service.
[0152] Appendix D
[0153] (Normative Appendix)
[0154] Signature Generation
[0155] D.1, Purpose Description:
[0156] The signature is used by the capability gateway or the capability provider to verify the identity of the capability requester and confirm the legitimacy of its invocation.
[0157] D.1.1, Obtaining the Signature
[0158] The party in need of capabilities splices the relevant information into a string according to a unified format: rid + ":" + secret + ":" + rtime (the current timestamp) + ":" + nonce (a random string). The generated string is encrypted using sha256Hex to form the signature.
[0159] The parameter descriptions are as follows:
[0160]
[0161] D.1.2, Signature Example
[0162] An example code for calculating the signature is as follows:
[0163]
[0164] Embodiment 2
[0165] As Figure 5 shown, in the second embodiment of the present invention, a capabilities access device is provided. The device includes:
[0166] A registration module 10, configured to enable a capabilities provider to register capabilities on a capabilities platform and input the capability components of the capabilities. Among them, the capability components include basic information, deliverables, functions, and performance;
[0167] A creation module 20, configured to enable a capabilities operator to review the registered capabilities and their corresponding capability components. After the review is passed, multiple interfaces are created, and each interface corresponds to a specific function or operation of the capabilities;
[0168] A release module 30, configured to comprehensively test the capabilities, their capability components, and interfaces, and evaluate whether the preset release conditions are met;
[0169] A deployment module 40, configured to, if the release conditions are met, deploy the capability components and their corresponding interfaces on the capabilities platform;
[0170] A call module 50, configured to enable a party in need of capabilities to apply for subscribing to the capabilities on the capabilities platform, and the capabilities platform generates unique authorized authentication parameter information for the capabilities. After the capabilities provider identifies the unique authorized authentication parameter information, the capabilities provider authorizes the party in need of capabilities to call the corresponding interface service via a capabilities gateway;
[0171] A recording module 60, configured to enable the capabilities operator to monitor the entire process of input, review, release, subscription, and call of the capabilities, and record the relevant operation data.
[0172] The capability access device provided by the embodiments of the present invention has the same implementation principle and technical effects as those of the foregoing method embodiments. For the sake of brief description, for the parts not mentioned in the device embodiments, reference may be made to the corresponding content in the foregoing method embodiments.
[0173] Embodiment III
[0174] As Figure 6 shown, in the third embodiment of the present invention, the embodiments of the present invention provide the following technical solution. A computer includes a memory 202, a processor 201, and a computer program stored on the memory 202 and executable on the processor 201. When the processor 201 executes the computer program, the capability access method described above is implemented.
[0175] Specifically, the foregoing processor 201 may include a central processing unit (CPU), or a specific integrated circuit (Application Specific Integrated Circuit, abbreviated as ASIC), or may be configured with one or more integrated circuits for implementing the embodiments of the present application.
[0176] Among them, the memory 202 may include a mass storage for data or instructions. By way of example and not limitation, the memory 202 may include a hard disk drive (HDD), a floppy disk drive, a solid state drive (SSD), a flash memory, an optical disc, a magneto-optical disc, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. In a suitable case, the memory 202 may include a removable or non-removable (or fixed) medium. In a suitable case, the memory 202 may be inside or outside the data processing device. In a specific embodiment, the memory 202 is a non-volatile memory. In a specific embodiment, the memory 202 includes a read-only memory (ROM) and a random access memory (RAM). In a suitable case, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically alterable ROM (EAROM), or a flash memory, or a combination of two or more of these. In a suitable case, the RAM may be a static random access memory (SRAM) or a dynamic random access memory (DRAM), where the DRAM may be a fast page mode dynamic random access memory (FPMDRAM), an extended date out dynamic random access memory (EDODRAM), a synchronous dynamic random access memory (SDRAM), etc.
[0177] The memory 202 can be used to store or cache various data files required for processing and / or communication, as well as possible computer program instructions executed by the processor 201.
[0178] The processor 201 reads and executes the computer program instructions stored in the memory 202 to implement the above-mentioned capability access method.
[0179] In some of these embodiments, the computer may further include a communication interface 203 and a bus 200. Among them, as Figure 6 shown, the processor 201, the memory 202, and the communication interface 203 are connected through the bus 200 and complete communication with each other.
[0180] The communication interface 203 is used to implement communication between the various modules, devices, units, and / or devices in the embodiments of the present application. The communication interface 203 can also implement data communication with other components such as external devices, image / data acquisition devices, databases, external storage, and image / data processing workstations.
[0181] The bus 200 includes hardware, software, or both, and couples the components of a computer to each other. The bus 200 includes, but is not limited to, at least one of the following: Data Bus, Address Bus, Control Bus, Expansion Bus, Local Bus. By way of example and not limitation, the bus 200 may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an InfiniBand interconnect, a Low Pin Count (LPC) bus, a memory bus, a MicroChannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local Bus (VLB) bus, or other suitable bus or a combination of two or more of these. In a suitable case, the bus 200 may include one or more buses. Although the embodiments of the present application describe and illustrate specific buses, the present application contemplates any suitable bus or interconnect.
[0182] Embodiment Four
[0183] In the fourth embodiment of the present invention, in combination with the above-mentioned capability access method, the embodiments of the present invention provide the following technical solution: a storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the above-mentioned capability access method is implemented.
[0184] Those skilled in the art will understand that the data in the flowchart and / or the logic and / or steps described in other ways herein, for example, can be regarded as a sequenced data table of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution device, apparatus, or equipment (such as a computer-based device, a device including a processor, or other devices that can fetch and execute instructions from the instruction execution device, apparatus, or equipment), or used in combination with these instruction execution devices, apparatus, or equipment. For the purposes of this specification, a "computer-readable medium" can be any device that can contain, store, communicate, propagate, or transmit a program for use by an instruction execution device, apparatus, or equipment or in combination with these instruction execution devices, apparatus, or equipment.
[0185] More specific examples (non-exhaustive list) of readable media include the following: an electrical connection portion (electronic device) having one or more wirings, a portable computer disk cartridge (magnetic device), a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber device, and a portable compact disc read-only memory (CDROM). Additionally, a computer-readable medium can even be paper or other suitable media on which the program can be printed, because the program can be obtained electronically, for example, by optically scanning the paper or other media, followed by editing, interpretation, or other suitable processing as necessary, and then stored in a computer memory.
[0186] It should be understood that various parts of the present invention can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution device. For example, if implemented by hardware, as in another embodiment, any one or a combination of the following techniques well-known in the art can be used: discrete logic circuits having logic gate circuits for implementing logical functions on data signals, application-specific integrated circuits having suitable combinational logic gate circuits, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.
[0187] The technical features of the above-described embodiments can be combined arbitrarily. For the sake of brevity in description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope described in this specification.
[0188] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.
Claims
1. A capability access method, characterized in that: The method comprises: The capability provider registers the capability on the capability platform and enters the capability components of the capability, wherein the capability components include basic information, deliverables, functions and performance; The capability operator reviews the registered capability and its corresponding capability components, and after the review is passed, creates multiple interfaces, each of which corresponds to a specific function or operation of the capability; Conduct comprehensive testing on the capability and its components and interfaces to assess whether they meet the preset release conditions; If the release conditions are met, the capability component and its corresponding interface are deployed on the capability platform; The capability demander applies to subscribe to the capability on the capability platform, and the capability platform generates unique authorization and authentication parameter information for the capability. After the capability provider identifies the unique authorization and authentication parameter information, it authorizes the capability demander to call the corresponding interface service via the capability gateway; During the entire process, the capability operator monitors the entry, review, release, subscription and call of the capability and records relevant operation data.
2. The capability access method according to claim 1, characterized in that: The basic information includes capability name, version information, capability form, applicable terminals, capability description and application scenario.
3. The capability access method according to claim 1, characterized in that: The step of the capability demander applying to subscribe to the capability on the capability platform and the capability platform generating unique authorization authentication parameter information of the capability includes: The capability demander initiates an application to subscribe to the capability to the capability platform; After accepting the application, the capability platform transmits the application information to the capability provider; After the capability provider reviews and authorizes the application, the capability platform generates a capability authorization key and provides it to the capability demander.
4. The capability access method according to claim 3, characterized in that: After the capability provider identifies the unique authorization authentication parameter information, the step of authorizing the capability demander to call the corresponding interface service via the capability gateway includes: The capability demander uses its calculation information in combination with the capability authorization key to perform signature calculation to generate a signature, wherein the calculation information includes the identity identifier of the capability demander, a random string, and a request time; Embed the signature into the Header area of the HTTP request and send the request to the capability gateway; The capability gateway extracts the signature of the Header area and verifies it according to a preset signature verification algorithm; If the signature verification is successful, the capability gateway transmits the verification result to the capability provider, and the capability provider allows the capability demander to call the corresponding interface service accordingly.
5. The capability access method according to claim 4, characterized in that: After the capability gateway extracts the signature, the method further includes: The capability platform performs secondary verification on the signature in the request based on the authorization key of the capability provider and the corresponding signature verification algorithm; If the signature verification is successful, the capability platform transmits the verification result to the capability provider.
6. The capability access method according to claim 1, characterized in that: After the step of creating multiple interfaces, the method further includes: Performing availability detection on each of the created interfaces to ensure that the parameter format of the interface complies with preset standards and meets the development requirements of the monitoring function of the interface; When the access volume of the interface exceeds the carrying capacity of a single machine, cluster deployment is used to ensure service continuity and maintain the uniqueness of the external service address.
7. The capability access method according to claim 1, characterized in that: During the process of calling the capability, the capability gateway performs identity authentication, request rate and concurrent request quantity limitation in sequence, and after meeting the identity authentication, request rate and concurrent request quantity limitation conditions, the capability call request is accurately routed to the corresponding capability service.
8. A capability access device, characterized in that: The device comprises: A registration module, used for a capability provider to register a capability on the capability platform and enter the capability components of the capability, wherein the capability components include basic information, deliverables, functions and performance; A creation module is used for the capability operator to review the registered capability and its corresponding capability components. After the review is passed, multiple interfaces are created, each of which corresponds to a specific function or operation of the capability; A release module, used to comprehensively test the capability and its components and interfaces, and evaluate whether the preset release conditions are met; A deployment module, configured to deploy the capability component and its corresponding interface on the capability platform if the release condition is met; A calling module is used for the capability demander to apply for subscription to the capability on the capability platform, and the capability platform generates unique authorization authentication parameter information of the capability. After the capability provider identifies the unique authorization authentication parameter information, the capability demander is authorized to call the corresponding interface service via the capability gateway; The recording module is used for the capability operator to monitor the entry, review, release, subscription and call of the capability throughout the entire process, and record relevant operation data.
9. A computer comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the capability access method according to any one of claims 1 to 7 is implemented.
10. A storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by the processor, the capability access method according to any one of claims 1 to 7 is implemented.