SaaS service processing method, system and device and storage medium

By establishing interconnection between service users, providers and PaaS platforms in different VPCs, and using the PaaS platform's routing information forwarding requests and response results, the inconvenience of service use caused by network isolation is solved, and convenient and secure use of SaaS services is achieved.

CN120238325APending Publication Date: 2025-07-01HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311862082.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

Due to network isolation, service providers and service users in different virtual private clouds (VPCs) cannot conveniently use SaaS services on the PaaS platform.

Method used

By establishing VPC interconnection between service users, service providers and PaaS platform, using the PaaS platform's routing information to achieve communication, forward usage requests and response results, and eliminating network isolation.

Benefits of technology

It improves the convenience and security of service use, reduces the processing pressure of service providers, reduces deployment costs, and increases the security level of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238325A_ABST
    Figure CN120238325A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a SaaS service processing method, system and device and a storage medium, and the system comprises that for a service provider, a service user and a PaaS platform in different VPCs, the VPCs where the service user, the service provider and the PaaS platform are located are interconnected, that is, network isolation among the three parties is relieved. Afterwards, the PaaS platform can further utilize the local routing information to realize communication between the service user and the service providers, so that the service user can use any SaaS service which is issued on the PaaS platform and provided by any service provider in any VPC, thereby improving the use convenience of the service in the PaaS platform by the service user.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cloud computing, and in particular, to a method, system, device, and storage medium for processing SaaS services. Background Art

[0002] The service models of cloud computing can include Software as a Service (SaaS for short) and Platform as a Service (PaaS for short). Among them, PaaS is a model that provides a software development platform as a service to users, and SaaS is a service model that provides software applications through the Internet.

[0003] In practice, different service providers can publish the SaaS services they provide to the PaaS platform, using the PaaS platform as a service market containing multiple SaaS services for service users to select and use. Among them, both service providers and service users can be in a Virtual Private Cloud (VPC for short) network. When the service provider and the service user are in different VPCs, due to network isolation, the service user cannot conveniently use various SaaS services published on the PaaS platform.

[0004] Therefore, how to achieve the convenient use of SaaS services has become an urgent problem to be solved. Summary of the Invention

[0005] In view of this, embodiments of the present invention provide a method, system, device, and storage medium for processing SaaS services, so as to enable service users to conveniently use SaaS services.

[0006] In a first aspect, an embodiment of the present invention provides a processing system for SaaS services, including: a service provider, a service user, and a Platform as a Service (PaaS) platform, wherein the VPCs where the service provider, the service user, and the PaaS platform are located are interconnected;

[0007] The service user is configured to send a usage request for any Software as a Service (SaaS) service published on the PaaS platform to the PaaS platform; and receive a response result of the usage request forwarded by the PaaS platform;

[0008] The PaaS platform is configured to forward the usage request to a target service provider providing the any SaaS service according to the network address in the routing information;

[0009] The target service provider is used to respond to the usage request and send the response result of the usage request to the PaaS platform.

[0010] In a second aspect, an embodiment of the present invention provides a processing method for SaaS services, which is applied to a Platform as a Service (PaaS) platform and includes:

[0011] Receiving a usage request sent by a service user, where the usage request corresponds to any Software as a Service (SaaS) service published on the PaaS platform;

[0012] Forwarding the usage request to a target service provider that provides the any SaaS service according to the network address in the routing information;

[0013] Sending the response result generated by the target service provider to the service user, where the PaaS platform, the service user, and the virtual private cloud (VPC) where the service provider is located are interconnected.

[0014] In a third aspect, an embodiment of the present invention provides a processing method for SaaS services, which is applied to a service user and includes:

[0015] Sending a usage request corresponding to any SaaS service published on a Platform as a Service (PaaS) platform to the PaaS platform;

[0016] Receiving a response result generated by a service provider, where the response result corresponds to the usage request, and the PaaS platform, the service user, and the virtual private cloud (VPC) where the service provider is located are different from each other.

[0017] In a fourth aspect, an embodiment of the present invention provides a processing method for SaaS services, which is applied to a service provider and includes:

[0018] Receiving a usage request from a service user for any SaaS service published on a Platform as a Service (PaaS) platform;

[0019] Responding to the usage request to obtain a response result;

[0020] Sending the response result required by the service user, where the PaaS platform, the service user, and the virtual private cloud (VPC) where the service provider is located are interconnected.

[0021] Fifth aspect, an embodiment of the present invention provides an electronic device, including a processor and a memory, where the memory is used to store one or more computer instructions. When the one or more computer instructions are executed by the processor, the processing method of the SaaS service described in the second aspect above is implemented. The electronic device may further include a communication interface for communicating with other devices or communication networks.

[0022] Sixth aspect, an embodiment of the present invention provides an electronic device, including a processor, a memory, and a network access module. The electronic device uses the network access module to interconnect the electronic device with the virtual private cloud (VPC) where the platform as a service (PaaS) platform is located. The memory is used to store one or more computer instructions. When the one or more computer instructions are executed by the processor, the processing method of the SaaS service described in the third aspect or the fourth aspect above is implemented. The electronic device may further include a communication interface for communicating with other devices or communication networks.

[0023] Seventh aspect, an embodiment of the present invention provides a non-transitory machine-readable storage medium, on which executable code is stored. When the executable code is executed by a processor of an electronic device, the processor can at least implement the processing method of the SaaS service described in any one of the second aspect to the fourth aspect.

[0024] The processing system of the SaaS service provided by the embodiment of the present invention. In this system, for the service provider, service user, and PaaS platform located in different VPCs, the VPCs where they are located are interconnected. Then, when the service user needs to use any SaaS service published on the PaaS platform, a usage request for this any SaaS service can be sent to the PaaS platform. The PaaS platform can forward this usage request to the target service provider that provides this any SaaS service according to the network address in the local routing information. The target service provider can respond to this usage request to obtain a response result and send the response result to the PaaS platform. The PaaS platform finally sends the response result to the service user, that is, the use of any SaaS service in the PaaS platform is realized.

[0025] In the above solution, the VPCs where the service user, service provider, and PaaS platform are located are interconnected, that is, the network isolation between the three parties is lifted. After lifting the network isolation, the PaaS platform can use its own routing information to realize communication between the service user and the service provider, so that the service user can use any SaaS service published on the PaaS platform and provided by any service provider in any VPC, thus improving the convenience of service use. On the other hand, since the three parties in the system are all in the VPC, it indicates that the three parties all have a high security level. Therefore, using the above system can also improve the security of the service. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0027] Figure 1 Structural schematic diagram of a processing system for a SaaS service provided by an embodiment of the present invention;

[0028] Figure 2 Interface schematic diagram of the home page provided by the PaaS platform according to an embodiment of the present invention;

[0029] Figure 3 Interface schematic diagram of the service details page provided by the PaaS platform according to an embodiment of the present invention;

[0030] Figure 4 Structural schematic diagram of another processing system for a SaaS service provided by an embodiment of the present invention;

[0031] Figure 5 Structural schematic diagram of yet another processing system for a SaaS service provided by an embodiment of the present invention;

[0032] Figure 6 Structural schematic diagram of yet another processing system for a SaaS service provided by an embodiment of the present invention;

[0033] Figure 7 Interface schematic diagram of the configuration interface of the SaaS service provided by the PaaS platform according to an embodiment of the present invention;

[0034] Figure 8 Interface schematic diagram of the management interface of the SaaS service provided by the PaaS platform according to an embodiment of the present invention;

[0035] Figure 9Flowchart of a processing method for SaaS services provided by an embodiment of the present invention;

[0036] Figure 10 Flowchart of another processing method for SaaS services provided by an embodiment of the present invention;

[0037] Figure 11 Flowchart of yet another processing method for SaaS services provided by an embodiment of the present invention;

[0038] Figure 12 Schematic structural diagram of a processing device for SaaS services provided by an embodiment of the present invention;

[0039] Figure 13 Schematic structural diagram of an electronic device provided by an embodiment of the present invention;

[0040] Figure 14 Schematic structural diagram of another processing device for SaaS services provided by an embodiment of the present invention;

[0041] Figure 15 Schematic structural diagram of another electronic device provided by an embodiment of the present invention;

[0042] Figure 16 Schematic structural diagram of yet another processing device for SaaS services provided by an embodiment of the present invention;

[0043] Figure 17 Schematic structural diagram of yet another electronic device provided by an embodiment of the present invention. Detailed implementation manners

[0044] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0045] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. The singular forms "a", "said", and "the" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. "Multiple" generally includes at least two, but does not exclude the case of including at least one.

[0046] It should be understood that the term "and / or" used herein is merely a correlative relationship describing associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. Additionally, the character " / " in this text generally indicates that the associated objects before and after are in an "or" relationship.

[0047] Depending on the context, the words "if" and "when" as used herein can be interpreted as "when...", "while...", "in response to determining", or "in response to identifying". Similarly, depending on the context, the phrase "if determined" or "if identifying (stated condition or event)" can be interpreted as "when determined", "in response to determining", "when identifying (stated condition or event)", or "in response to identifying (stated condition or event)".

[0048] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present invention are all information and data that have been authorized by the user or fully authorized by all parties. Moreover, the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or refuse.

[0049] It should also be noted that the term "comprising", "including", or any other variant thereof is intended to cover non-exclusive inclusion, such that a commodity or system comprising a series of elements not only includes those elements but also includes other elements not explicitly listed, or further includes elements inherent to such commodity or system. Without further limitation, an element defined by the statement "comprising one..." does not exclude the existence of additional identical elements in the commodity or system comprising the said element.

[0050] Before describing the following embodiments of the present invention in detail, the roles involved in the present invention can also be described first:

[0051] The service provider, i.e., the party that develops, publishes, and maintains the SaaS service.

[0052] The service user, i.e., the party that uses the SaaS service. And the service user and the service provider can satisfy the client / server (Client / Server, abbreviated as C / S) architecture.

[0053] The PaaS platform is used to support the service provider in publishing the SaaS service and also to support the service user in using the SaaS service.

[0054] Among them, both the service provider and the service user can be regarded as users of the PaaS platform. Moreover, the PaaS platform can also manage SaaS services, service providers, and service users as users. For example, it authenticates service providers and restricts illegal service providers and illegal service users from accessing the PaaS platform (i.e., restricting illegal service providers from publishing SaaS services and restricting illegal service users from using SaaS services), deletes the account information of illegal service providers and illegal service users, takes down illegal SaaS services, and so on.

[0055] The above describes the roles from a functional perspective. It is easy to understand that the above functions of the roles are realized by being deployed on electronic devices. Therefore, in the following embodiments of the present invention, the PaaS platform, service providers, and service users mentioned specifically refer to the electronic devices corresponding to the roles.

[0056] In addition, before describing the following embodiments of the present invention in detail, a brief description of the usage background of the present invention can be given first:

[0057] As described in the background art, in practice, service users and service providers can be in different VPCs. In addition, different service providers can also be in different VPCs.

[0058] In one case, the PaaS platform and the service user are in the same VPC, but there are also SaaS services provided by service providers in other VPCs in the PaaS platform. At this time, due to network isolation, there will be the problems mentioned in the background art: it causes the service user not to be able to conveniently use any SaaS service published on the PaaS platform, that is, the service user can only use the services provided by service providers in the same VPC as itself with the help of the PaaS platform, that is, the use of SaaS services is restricted. In another more serious case, if the PaaS platform and the service provider are in different VPCs, then due to network isolation, the service user cannot even use all the SaaS services provided by the PaaS platform.

[0059] Then, when there is network isolation, in order to enable the service user to use any SaaS service published on the PaaS platform, at this time, the systems and methods provided in the following embodiments of the present invention can be used.

[0060] The following will describe some embodiments of the present invention in detail with reference to the accompanying drawings. Without conflict between the embodiments, the following embodiments and the features in the embodiments can be combined with each other. In addition, the step timings in the following method embodiments are only examples, not strictly limited.

[0061] Figure 1The figure is a schematic structural diagram of a processing system for SaaS services provided by an embodiment of the present invention. As Figure 1 shown, the system may include: a service provider, a service user, and a PaaS platform.

[0062] Initially, the service provider, the service user, and the PaaS platform may be deployed in different VPCs. Among them, the different VPCs where the three are located may include various situations: for example, the VPCs where the three are located are all different. Another example is that any two of the three are in the same VPC, and the other is in another VCP. For example, the service provider and the PaaS platform are in the same VPC, and the service user is in another VCP, or the service provider and the service user are in the same VPC, and the PaaS platform is in another VPC.

[0063] When the VPCs where the three are located are all different, the service user can interconnect its own VPC with the VPC where the PaaS platform is located, that is, break through the network isolation between the service user and the PaaS platform, and realize mutual communication between the service user and the PaaS platform. Optionally, this network interconnection can be realized by means of a network access module deployed inside the service usage. Optionally, the network access module can specifically be manifested as a network card. The service provider can also interconnect its own VPC with the VPC where the PaaS platform is located. The specific implementation method of the interconnection can be similar to that of the service user. At this time, there is no network isolation between the service user, the service provider, and the PaaS platform.

[0064] When the service provider or the service user and the PaaS platform are in the same VPC, the above process of network interconnection is not required. That is, when the VPCs where the three are located are all different, the network access modules configured inside the service provider and the service user will play the role of network interconnection.

[0065] Based on this, the specific working process of the system can be described in detail below:

[0066] In practice, the SaaS services published by different service providers on the PaaS platform can be displayed on the home page of the PaaS platform in the form of a text catalog or a combination of text and pictures. Optionally, it can be Figure 2 displayed in the shown manner. The SaaS services published on the PaaS platform may include vehicle identification number (VIN) query, bank card real-name authentication, ID card real-name authentication, weather forecast query, and so on.

[0067] After that, the service user can select or search for any SaaS service to be used on this homepage, thereby further generating a usage request for any of the SaaS services. The usage request generated by the service user can be sent to the PaaS platform.

[0068] For the selection of any SaaS service by the service user, in an optional way, the service user can directly select on the homepage or search result page of the PaaS platform. In another optional way, the service user can also perform further operations on the search result page of the PaaS platform or Figure 2 the homepage shown to obtain Figure 3 the service details page shown, and determine whether the SaaS service meets its own needs based on the content displayed on the service details page. After that, the service user can also directly select the SaaS service on the service details page.

[0069] As Figure 2 shown, on the homepage of the PaaS platform, the service names, service contents, release times, service providers and their contact information, etc. of different SaaS services can be displayed. As Figure 3 shown, in the service details page, the service name, usage method, delivery form (such as API interface or data, etc.), payment rules, etc. of the SaaS service can be displayed. And the information displayed in the two figures can be regarded as the service details information of the SaaS service, and this service details information is obviously visible to the service user.

[0070] Among them, the delivery form of information query services is usually an API interface, such as the above-mentioned VIN query, bank card real-name authentication, ID card real-name authentication, etc. The delivery form of data warehouse services is usually data, such as the above-mentioned weather forecast query service, etc.

[0071] Then, the PaaS platform can respond to the usage request and further forward the usage request to the target service provider that provides any of the SaaS services according to its own routing information. The target service provider can be Figure 1 one of the multiple service providers in

[0072] Among them, the routing information stored in the PaaS platform can include the network addresses of different service providers that publish SaaS services in the PaaS platform. Optionally, different service providers can be in the same VPC, different service providers can also be in different VPCs in the same region, and different service providers can also be in different VPCs in different regions.

[0073] For example, different service providers providing services to the PaaS platform may include Service Provider 1 to Service Provider 4. Then, Service Provider 1 may be located in VPC1 in Region 1, Service Provider 2 and Service Provider 3 may be located in VPC2 in Region 1, and Service Provider 4 may be located in VPC1 in Region 1. It can be seen that in the above example, Service Provider 1 and Service Provider 2 are in different VPCs in the same region, Service Provider 1 and Service Provider 4 are in different VPCs in different regions, and Service Provider 2 and Service Provider 3 are in the same VPC in the same region.

[0074] It should be noted that the present invention does not limit the region and VPC where the service provider is located. Any service provider can be in any VPC in any region.

[0075] Next, the target service provider can respond to the usage request forwarded by the PaaS platform to obtain a response result. Optionally, the content of the response result is related to the delivery form of the SaaS service. For services with an API interface as the delivery form, the response result generated by the target service provider is the interface information of the API interface; for services with data as the delivery form, the response result generated by the target service provider is the data required by the service user. Since the target service provider has accessed the VPC where the PaaS platform is located through the network access module configured by itself, the target service provider can directly send the response result of the usage request to the PaaS platform by means of the network access module configured by itself.

[0076] Finally, the service user can receive the response result forwarded by the PaaS platform, and at this time, the use of any SaaS service is realized. In this embodiment, for the service provider, service user, and PaaS platform located in different VPCs, the VPCs where the three are located are interconnected. Then, when the service user needs to use any SaaS service, the usage request for this any SaaS service can be sent to the PaaS platform. The PaaS platform can forward this usage request to the target service provider providing this any SaaS service according to the network address in the local routing information. The target service provider can respond to this usage request to obtain a response result and send the response result to the PaaS platform. The PaaS platform finally sends the response result to the service user, that is, the use of any SaaS service in the PaaS platform is realized.

[0077] In the above solution, the service user, service provider, and the VPC where the PaaS platform is located are interconnected, that is, the network isolation among the three parties is lifted. After lifting the network isolation, the PaaS platform can use its own routing information to achieve communication between the service user and the service provider, so that the service user can use any SaaS service published on the PaaS platform and provided by any service provider in any VPC, thus improving the convenience of service use. On the other hand, since the three parties in the system are all in the VPC, it indicates that all three parties have a high security level. Therefore, using the above system can also improve the security of the service.

[0078] The technical effects that can be achieved by the system provided in the above and following embodiments of the present invention can also be understood in combination with the following content:

[0079] When the PaaS platform, service provider, and service user are all in the public network, the PaaS platform and the SaaS services published on this platform can be deployed on cloud servers that provide elastic computing services (Elastic Compute Service, abbreviated as ECS) in the public network. The network address of this ECS cloud server in the public network can be exposed to the service user, and the service user can directly access this network address to use the SaaS service.

[0080] Optionally, in order to improve the network stability and service security, a Server Load Balancer (SLB) device and / or an Application Programming Interface (API) gateway can also be set up in the public network. At this time, the network address of the ECS cloud server does not need to be exposed to the service user, but the network address of the above SLB device or API gateway in the public network is exposed to the service user. The service user can then indirectly access the ECS cloud server by accessing the SLB device or API gateway, thus realizing the use of the SaaS service.

[0081] In the above situation, on the one hand, for service users with a low security level in the public network, it is easy to launch attacks on the PaaS platform, thus affecting the normal use of the SaaS service. On the other hand, due to the relatively complex network environment and poor stability of the public network, it can lead to a high latency in the use of the SaaS service, but this is not suitable for some service users who require low latency. On the other hand, for some service users in the VPC who have high requirements for data security, they cannot use the SaaS services on the PaaS platform in the public network.

[0082] When using the systems provided in the embodiments of the invention, both the service provider and the service user are deployed in the VPC. At the same time, by using their respective network access modules, the network isolation between them and the PaaS platform can be eliminated, enabling the service user to use the SaaS service in the VPC environment. Compared with the public network, the VPC has higher security and stability, and the service user in the VPC is also more secure. Therefore, it can reduce the possibility of the PaaS platform being attacked and also shorten the latency. And since the SaaS service on the PaaS platform is published in the VPC, the service user in the VPC can also use the SaaS service normally.

[0083] Optionally, for the PaaS platform in the systems provided in the embodiments of the present invention, the VPC it is located in can have various structures. For example, it can be at least one VPC within the same region, or at least one VPC in different regions, or at least one VPC within the same region and at least one VPC in different regions.

[0084] Optionally, for any two VPCs where the PaaS platform is located, they can be communicatively connected to each other through an interconnection medium, that is, the network isolation between them is eliminated. Optionally, for any two VPCs in the same region, the interconnection medium can specifically be a private network connection (PrivateLink) between two VPCs in the same region or a network card with cross-account mounting capabilities. This interconnection medium can be regarded as an intra-region interconnection module for interconnecting different VPCs within the same region. Optionally, for any two VPCs in different regions, the interconnection medium between them can be a VPC peering connection or a routing forwarding device set between two VPCs in different regions. This routing forwarding device can serve as a Cloud Enterprise Network (CEN for short). This interconnection medium can be regarded as an inter-region interconnection module for interconnecting different VPCs in different regions.

[0085] Optionally, the regions where the service user, the service provider, and the VPC where the PaaS platform is located can also be different from each other. That is, the service provider and the service user are in VPCs in different regions.

[0086] Assuming that the VPC where the PaaS platform is located includes multiple VPCs in different regions, from the perspective of network distribution, the processing system of the SaaS service provided by the present invention can also be manifested as Figure 4 . In Figure 4Among them, the service user is in VPC1 in region A, the service provider is in VPC2 in region B, and the PaaS platform is in VPC3, VPC4 in region A, VPC5 in region C, and VPC6 in region B. The service provider can deploy the SaaS service it provides in VPC2.

[0087] At this time, the service user can access VPC3 through its own network access module, and the service provider accesses VPC6 through its own network access module. At the same time, the interconnection medium between adjacent VPCs in VPC3 to VPC6 can also be used to realize the interconnection between different VPCs in the PaaS platform. Then, the combined use of the network access module and the interconnection medium can connect the service user, the service provider, and the PaaS platform in different VPCs in different regions to a network to eliminate the network isolation between the three.

[0088] In this embodiment, through the combined use of the network access module and the interconnection medium, different VPCs in different regions where the service user and the service provider are located can be interconnected with the VPC where the PaaS platform is located, and then by using the process described in the embodiment shown in Figure 1 the service user can use any SaaS service published on the PaaS platform.

[0089] Optionally, Figure 4 The network access module and the interconnection medium in the embodiment shown can form the network connection system in this embodiment. In addition, the content not described in detail and the technical effects that can be achieved in the above embodiments related to the network connection system can be referred to the relevant descriptions in the above embodiments, and will not be elaborated here.

[0090] Based on Figure 4 the system shown, the technical effects that can be achieved in the above and below embodiments of the present invention can also be understood in combination with the following content:

[0091] When the service user, the service provider, and the PaaS platform are all deployed in different VPCs, and the service provider and the service user are in the same region, the service user can first subscribe to the SaaS service in the PaaS platform. After receiving the subscription request, the service provider that provides the SaaS service can enable the service user to use the SaaS service by itself, that is, in response to the service subscription, the service provider adds the service user to the whitelist corresponding to the SaaS service, so as to realize the point-to-point connection between the service user and the SaaS service, so that the service user can use the SaaS service normally.

[0092] However, in the above manner, while the service provider releases the SaaS service, it also needs to grant permissions to the service user, which will obviously increase the processing pressure on the service provider. Moreover, what the service provider realizes is only the point-to-point connection between the service user and the SaaS service it subscribes to. When the number of service users and SaaS services continues to increase, the subscription requests generated by the service users will also increase. Since the service provider cannot achieve the batch connection between the service user and multiple SaaS services, the service provider needs to frequently perform the above operation of granting permissions, thus further increasing the processing pressure on the service provider.

[0093] By using the system provided in each embodiment of the present invention, with the help of the network access module, the VPC interconnection between the service user and the PaaS platform can be realized, so that any SaaS service in the PaaS platform can be used. At this time, it is also to realize the connection between the service user and all SaaS services on the PaaS platform, that is, a point-to-face connection. And during the connection process, the participation of the service user and the service provider is not required, thus reducing the processing pressure on the service provider and improving the usage experience of the service user.

[0094] On the other hand, in practice, different service providers may be in different VPCs in different regions. Considering network isolation, in order for the service user to use any service on the PaaS platform, the service provider needs to deploy all the SaaS services it can provide in different regions, which will increase the deployment cost of the service provider.

[0095] By using the system provided in the embodiment of the present invention, the service provider can deploy the SaaS services it provides in the VPC of its own region. With the help of the interconnection medium between different VPCs in the PaaS platform, the network isolation between VPCs can be eliminated, that is, the network isolation between service providers in different VPCs included in the PaaS platform can be eliminated, and the service user can use any service on the PaaS platform, thus reducing the deployment cost of the service provider.

[0096] And Figure 4 Corresponding to the system shown, the composition of the PaaS platform can also be described from a functional perspective below. Then Figure 5 This is a schematic structural diagram of another processing system for SaaS services provided by the embodiment of the present invention. As Figure 5 shown, the PaaS platform in this system may specifically include a network connection system.

[0097] According to the above embodiments, the PaaS platform is used to forward the usage request and the response result by means of the routing information stored in itself, and the above forwarding function can be specifically realized by the network connection system in the PaaS platform.

[0098] For the forwarding of usage requests, specifically, the network connection system can receive the usage requests sent by the service user. Then, optionally, the network connection system can determine the target network address corresponding to any SaaS service from the routing information stored in the PaaS platform according to the service network parameters in the usage request. Then, the network connection system can forward the usage request to the target service provider with the target network address according to the preset routing policy.

[0099] Optionally, the forwarding function of the above network connection system can be specifically executed by the routing module in the network connection system.

[0100] Optionally, based on Figure 1 the embodiment shown, the service detail information can further include the service domain name. The service network parameters can specifically include the port number, usage protocol corresponding to the SaaS service, the VPC where the service is located, the network address of the service provider, and so on. Among them, the protocol can include the User Datagram Protocol (UDP for short), the Hypertext Transfer Protocol (HTTP), and so on. Here, the service network parameters and Figure 1 the service detail information in the embodiment shown can jointly constitute the attribute information of the SaaS service. Both can be configured by the service provider during service publication. From the above various examples, it can be seen that the service detail information in the attribute information can be text information used to describe the details of the SaaS service, which can be directly shown to the service user; the service network parameters in the attribute information can be the parameters configured to ensure the normal operation of the service in the network, which can be not shown to the service user.

[0101] And based on Figure 1 the embodiment shown, the routing information can include, in addition to the network addresses of different service providers that publish the SaaS service on the PaaS platform, the mapping relationship between the network address and the service domain name.

[0102] For the process of determining the target network address according to the service network parameters, optionally, the network connection system can resolve the service domain name in the service network parameters using the mapping relationship and compare whether the resolved network address matches the network address corresponding to a certain service provider stored in the routing information. If the resolved network address is included in the routing information, then the resolved network address is determined as the target network address of the target service provider that provides any SaaS service.

[0103] For the forwarding of response results, similarly, the network connection system can forward the response results according to the routing information and the network address of the service user in the usage request.

[0104] In this embodiment, through the network connection system in the PaaS platform, the routing and forwarding of usage requests and response results can be realized, so as to ensure that the service user can conveniently use any SaaS service published on the PaaS platform.

[0105] Based on Figure 5 the system shown above, further, before the service provider responds to the usage request generated by the service user, in order to improve the availability and security of the SaaS service, optionally, the network connection system can also verify the usage request to identify whether there is an illegal usage request that affects the service availability and security. Specifically, the network connection system can identify the data volume and / or data content of the usage request to determine the legality of the usage request received by the network connection system, that is, to determine whether the usage request belongs to a Distributed Denial of Service (DDoS) attack or other network attacks.

[0106] If the data volume of the usage request is greater than the preset quantity, indicating a large number of abnormal requests generated by the service user, the network connection system can determine that the usage request belongs to a DDoS attack or other network attacks, and the network connection system can directly intercept the illegal usage request.

[0107] If the data content in the usage request does not match the content of the SaaS service provided by the service provider. For example, the data content in the usage request indicates that the user needs to request weather data, while the SaaS service provided by the service provider is an identity card real-name authentication service, then the two contents are obviously inconsistent, and the network connection system can also directly intercept the illegal usage request.

[0108] Optionally, the above process can be specifically implemented by the security verification module in the network connection system.

[0109] In this embodiment, the network connection system is used to intercept illegal requests, which can block the SaaS service from responding to the illegal usage request, thus ensuring the availability and security of the SaaS service. And ensuring service security by the network connection system can also reduce the processing pressure on the service user.

[0110] Based on Figure 5 the system shown above, further, during the process of the service user using any selected SaaS service, in order to ensure the legality of the SaaS service, optionally, the network connection system can also identify the legality of the SaaS service.

[0111] Among them, it should be noted that in this embodiment, the legality of the SaaS service emphasizes whether the response result corresponds to the service content of the SaaS service. Therefore, the legality of the SaaS service in this embodiment can also be regarded as the compliance of the SaaS service. Optionally, the identification of the above service legality can be specifically implemented by the legality verification module in the network connection system.

[0112] For the identification of legality, in an optional manner, the network connection system can identify the data content of the response result sent by the target service provider to determine whether the SaaS service provided by the target service provider conforms to the service detail information.

[0113] Optionally, the network connection system can identify the data content of the response result according to the data type of the response result. Taking Figure 1 the weather query service mentioned in the illustrated embodiment as an example, if the network connection system identifies that the data type in the response result is a numerical value, the network connection system can identify that the data content of the response result is weather data. The network connection system can determine that the SaaS service actually provided by the target service provider matches the service detail information of the SaaS service, and the SaaS service provided by the target service provider is legal.

[0114] Optionally, the network connection system can also identify the data content of the response result according to the data range of the response result. Similarly, taking Figure 1 the weather query service mentioned in the illustrated embodiment as an example, if the network connection system identifies that the data range in the response result is 100 - 1000, and this data obviously exceeds the range of weather temperature, the network connection system can identify that the data content of the response result is not weather data, and the network connection system can determine that the SaaS service actually provided by the target service provider does not match the service detail information of the SaaS service, and the SaaS service provided by the target service provider is illegal.

[0115] In this embodiment, the network connection system is used to judge whether the response result is legal, so as to further ensure the legality of the SaaS service.

[0116] Based on Figure 5For the system shown, further, during the process of a service user using any SaaS service selected by himself / herself, optionally, the network connection system can also count the data volume of the response results sent by the target service provider, and based on this data volume, the resource consumption of the service user can be further determined. It should be noted that the resources here are not the computing resources and / or network resources required during the use of the SaaS service, but the cost resources required by the service user to use the SaaS service. Therefore, the above process is actually a process of charging according to the data volume during the process of the service user using the SaaS service.

[0117] Optionally, the above charging process can also be specifically implemented by the charging module in the network connection system.

[0118] In this embodiment, while ensuring the availability, security, and legality of the SaaS service, the network connection system can also have a charging function.

[0119] Optionally, on the basis of Figure 5 the system shown, then Figure 6 it is a schematic structural diagram of another processing system for the SaaS service provided by the embodiment of the present invention. As Figure 6 shown, the PaaS platform can further include a service management system.

[0120] There can be data communication between the service management system, the network connection system, and the user management system and each service provider, and only the communication between one service provider and different systems is schematically drawn in Figure 6 .

[0121] Optionally, the service management system can manage the SaaS services provided by different service providers at different stages, and the management can involve the release stage and the use stage of the SaaS service. Among them, service release can specifically include the service deployment stage and the service online stage.

[0122] Optionally, during the service deployment stage, the service provider can trigger a service configuration operation on the configuration interface provided by the PaaS platform to configure the attribute information of the SaaS service on this interface. And the attribute information configured by the service provider can be stored in the database of the PaaS platform for sharing by the service management system, the user management system, and the network connection platform.

[0123] Just as Figure 1 and Figure 5 described in the embodiments shown, the attribute information of the SaaS service can specifically include service detail information and service network parameters. Just as Figure 1As given in the illustrated embodiment, the service detail information may include the service name visible to the service user, service content, release time, service provider and its contact information, usage mode of the SaaS service, delivery form, payment rules, etc. Just as Figure 5 As given in the illustrated embodiment, the service network parameters may include the port number, service domain name, usage protocol corresponding to the service that is invisible to the service user, the VPC where the service is located, the network address of the service provider, etc. Optionally, Figure 7 The illustrated configuration interface schematically shows the configuration styles of several types of attribute information. Such as Figure 7 As shown, the configuration interface may include multiple configuration items such as service name, service domain name, VPC, protocol, and port number.

[0124] Then, the service management system may further verify the SaaS service according to the attribute information of the SaaS service. An optional verification method is that if the service management system verifies that the service provider name included in the service detail information in the attribute information is compliant, it may determine that the service provider is a service provider with high security that has passed the PaaS platform certification. If the service provider passes the certification, the service management platform may consider that the SaaS provided by the service provider is legal, and the SaaS service provided by the service provider may be published to the PaaS platform by the service management system. Among them, the publishing process may refer to the relevant description in the following "service online phase". This verification process may be considered as the verification of service legality before service publishing.

[0125] Optionally, the service management system may also verify whether there are any illegal words in the service detail information. If there are no illegal words, the service management system determines that the SaaS service is legal. This legality may also be considered as the compliance of the SaaS service.

[0126] And in practice, the service management system may select at least one of the above multiple verifications to execute.

[0127] Optionally, after the SaaS service configuration is completed, the network connection system may also directly read the attribute information of the SaaS service from the database, obtain the network address of the service provider from the attribute information, and store the network address as routing information.

[0128] In the service online phase, if the service management system can first determine that the SaaS service provided by the service provider is legal and compliant in the above manner, the service management system may set the attribute of the field storing the service detail information in the database to visible, and then the service detail information is displayed on the page of the PaaS platform. At this time, that is, the SaaS service is successfully launched.

[0129] As the SaaS service is continuously upgraded, optionally, the service provider can also trigger an editing operation on the management interface provided by the service management system to edit the attribute information of the SaaS service provided by itself. Similarly, the service provider can also use this service management system to perform an overall deletion of the SaaS service.

[0130] The service management system can respond to the editing operation of the SaaS service by the service provider and edit the attribute information of the SaaS service. On this basis, optionally, during the use of any SaaS service selected by the service user, when the network connection system determines that the SaaS service is illegal, the service management system can automatically delete this SaaS service, that is, take this SaaS service offline.

[0131] Optionally, the management interface can be as Figure 8 shown. The service provider can perform operations such as "going online", "modifying", and "deleting" on the service. And as Figure 8 shown, the service provider can also see the status of different SaaS services in this interface, such as pending online, online in progress, already online, and so on.

[0132] Optionally, the PaaS platform provided in this embodiment can also include a user management system. Both the service provider and the service user can be users of the PaaS platform. Then the user management system can store the account information of the service user and the service provider, and verify the service publishing permissions of the service provider according to the stored account information. A service provider without publishing permissions can have the permission to view the SaaS services in the PaaS platform.

[0133] Among them, the account information of the service provider can include behaviors such as the historical publishing information or historical modification information of the service. The historical publishing information of the service provider can reflect the SaaS published by the service provider during the historical period. Similarly, the historical modification information can reflect the modification situation of the SaaS published by the service provider during the historical period.

[0134] Optionally, if the user management system identifies that the service provider has behaviors such as the release of illegal SaaS services or the illegal modification of SaaS services, it can determine that the service provider does not have the publishing permission of SaaS.

[0135] At the same time, the user management system can also verify whether the service user has the permission to use the SaaS service according to the account information. That is, the user management system can receive the use request generated by the service user, and when it determines that the service user has the use permission, it will forward the use request by the network connection system.

[0136] Among them, the account information of the service user can include historical usage behaviors, etc. The usage behavior can reflect the time period, frequency, quantity, etc. when the service user generates usage requests within the historical time period. Generating a large number of usage requests at a high frequency within a short time period can be considered that the service user has abnormal usage behavior.

[0137] Optionally, if the user management system identifies that the service user who generates the usage request has abnormal usage behavior within the historical time period, it can determine that the service user does not have the usage permission for SaaS.

[0138] In this embodiment, by using the service management system and the user management system in the PaaS platform, it is possible to better manage the service provider and the service user, thereby further improving the security and availability of the SaaS service, and also improving the convenience for the service user to use the SaaS service.

[0139] In addition, according to Figure 4 the embodiments shown, the PaaS platform can be in different VPCs. Optionally, in this embodiment, the user management system and the service management system mentioned can be deployed in the same VPC where the PaaS platform is located, and the account information stored in the user management system and the attribute information of the SaaS service stored in the service management system deployed in different VPCs can be shared.

[0140] Based on the above system embodiments, the processing process of the SaaS service can also be described from the perspective of methods below.

[0141] Figure 9 It is a flowchart of a method for processing a SaaS service provided by an embodiment of the present invention. The method provided by the embodiment of the present invention can be executed by the PaaS platform in the system shown in the above various embodiments. As Figure 9 shown, the method can include the following steps:

[0142] S101, receive a usage request sent by a service user, where the usage request corresponds to any SaaS service published on the PaaS platform.

[0143] S102, forward the usage request to the target service provider that provides any SaaS service according to the network address in the routing information.

[0144] S103, send the response result generated by the target service provider to the service user, where the VPCs where the PaaS platform, the service user, and the service provider are located are interconnected.

[0145] The PaaS platform can forward the usage request and the response result by means of the routing information stored by itself.

[0146] For the forwarding of usage requests, specifically, the PaaS platform can receive usage requests sent by service consumers, where the usage requests can correspond to any SaaS service published on the PaaS platform. Subsequently, the PaaS platform can forward the usage requests to the target service provider that provides any SaaS service based on the network addresses in the routing information.

[0147] For the specific content of the routing information stored in the PaaS platform, reference can be made to the relevant descriptions in the embodiments shown in Figure 1 and will not be elaborated here. For the forwarding of response results, the PaaS platform can forward the response results based on the routing information and the network address of the service consumer included in the usage request, that is, send the response results generated by the target service provider to the service consumer.

[0148] Optionally, for the implementation method of the interconnection between the VPCs where the PaaS platform, service consumers, and service providers are located, reference can be made to the relevant descriptions in the embodiments shown in Figure 1 and will not be elaborated here.

[0149] In this embodiment, for the process of receiving usage requests, the process of forwarding usage requests, and the process of sending response results, reference can be made to the relevant descriptions in the above-mentioned embodiments and will not be elaborated here.

[0150] In this embodiment, the PaaS platform can receive usage requests sent by service consumers and forward these usage requests to the target service provider that provides any of these SaaS services based on the network addresses in the local routing information, so that the target service provider generates response results corresponding to these usage requests and sends the response results to the PaaS platform through the network access module configured by itself. The PaaS platform finally sends the response results to the service consumer, that is, realizes the usage of any SaaS service in the PaaS platform.

[0151] In the above method, the PaaS platform can use its own routing information to realize communication between service consumers and service providers, so that service consumers can use any SaaS service published on the PaaS platform and provided by any service provider in any VPC, thereby improving the convenience of service usage. On the other hand, since the three parties in the system are all in the VPC, it indicates that the three parties all have a high security level. Therefore, using the above system can also improve the security of the service.

[0152] In addition, for the technical effects that can be achieved in this embodiment, reference can also be made to the relevant descriptions in the above Figures 1 to 8 shown embodiments and will not be elaborated here.

[0153] Optionally, the VPC where the PaaS platform is located may include various structures, and peer connections between different VPCs within the same region and / or different regions can be established through an interconnection medium. For related content, reference can be made to the relevant descriptions in the above Figure 4 illustrated embodiments, which will not be elaborated here.

[0154] Optionally, the PaaS platform that executes Figure 9 the illustrated method may specifically further include a network connection system, a service management system, and a user management system.

[0155] Figure 9 In the illustrated embodiments, the forwarding of the usage request and response result can be implemented by the network connection system. The service management system can manage the SaaS services provided by different service providers during the service publishing phase and the usage phase.

[0156] The user management system can manage service providers and service users. For the specific working processes of different systems in the PaaS platform, reference can also be made to the relevant descriptions in the above embodiments, which will not be elaborated here.

[0157] Figure 10 FIG. is a flowchart of another method for processing SaaS services provided by an embodiment of the present invention. The method provided by the embodiment of the present invention can be executed by a service user in the system shown in the above embodiments. As Figure 10 shown, the method may include the following steps:

[0158] S201, send a usage request corresponding to any SaaS service published on the PaaS platform to the PaaS platform.

[0159] S202, receive the response result generated by the service provider, where the response result corresponds to the usage request, and the VPCs where the PaaS platform, the service user, and the service provider are located are interconnected.

[0160] Initially, the PaaS platform, the service user, and the service provider can be deployed in different VPCs. In this case, the VPCs where the PaaS platform, the service user, and the service provider are located can be interconnected, that is, the network isolation between the service user and the PaaS platform can be broken through, and communication between the service user and the PaaS platform can be realized. Optionally, for the specific implementation manner of the interconnection, reference can be made to Figure 1 the relevant descriptions in the illustrated embodiments, which will not be elaborated here.

[0161] After realizing the VPC interconnection, the service user can send a usage request corresponding to any SaaS service published on the PaaS platform to the PaaS platform, and can also receive the response result of the usage request forwarded by the PaaS platform and generated by the service provider.

[0162] In this embodiment, the processes of sending requests and receiving response results can refer to the relevant descriptions in the above embodiments, and will not be elaborated here.

[0163] In addition, the content not described in detail and the achievable technical effects in this embodiment can also refer to the relevant descriptions in the above Figures 1 to 8 illustrated embodiments, and will not be elaborated here.

[0164] Figure 11 It is a flowchart of another processing method for SaaS services provided by an embodiment of the present invention. The method provided by the embodiment of the present invention can be executed by the service provider in the system shown in the above embodiments. As Figure 11 shown, the method may include the following steps:

[0165] S301, receiving a usage request from a service user for any SaaS service published on the PaaS platform.

[0166] S302, responding to the usage request to obtain a response result.

[0167] S303, sending the response result required by the service user, where the VPCs where the PaaS platform, the service user, and the service provider are located are interconnected.

[0168] Similar to the Figure 10 illustrated embodiment, initially, the PaaS platform, the service user, and the service provider can be deployed in different VPCs. In this case, the VPCs among the three can also be interconnected to break through the network isolation between the service provider and the PaaS platform and enable communication between the service provider and the PaaS platform.

[0169] The service provider receives a usage request generated by the service user for any SaaS service published on the PaaS platform and forwarded by the PaaS platform. After that, the service provider can respond to this usage request and generate a response result corresponding to the usage request. The service provider can also send the response result required by the service user to the PaaS platform, so that the PaaS platform forwards the response result to the service user.

[0170] In this embodiment, the processes of receiving usage requests, responding to usage requests, and sending response results can refer to the relevant descriptions in the above embodiments, and will not be elaborated here.

[0171] In addition, the content not described in detail and the achievable technical effects in this embodiment can also refer to the relevant descriptions in the above Figures 1 to 8 illustrated embodiments, and will not be elaborated here.

[0172] The above embodiments have described in detail the processing process of SaaS services from the perspectives of systems and methods. For ease of understanding, the following will illustrate the specific implementation process of the above SaaS service processing system and method with a specific scenario.

[0173] Continuing with the SaaS service processing system architecture provided in the above embodiments, the VPC where the service user and the service provider providing the SaaS service are located can be interconnected with the VPC where the PaaS platform is located. Based on this, the service user can see the PaaS platform home page as shown in Figure 2 which can display 4 published SaaS services, namely the vehicle identification code query service, the bank card real-name authentication service, the ID card real-name authentication service, and the weather forecast query service.

[0174] In one case, the service user can directly initiate a usage request for the ID card real-name authentication service on the PaaS platform home page, such as clicking the "Try" or "Purchase" button in the identity real-name authentication on the home page. In another case, the service user can first view the PaaS platform home page and then further click on the identity real-name authentication service on the home page to obtain the service details page as shown in Figure 3 The service user can then initiate a usage request for the ID card real-name authentication service on this page, such as clicking the "Try" or "Purchase" button on the service details page. The service user can use the network access module configured by itself to send this usage request to the PaaS platform. Among them, the delivery form of the ID card real-name authentication service is a service of an API interface.

[0175] Then, the PaaS platform can resolve the domain name of the ID card real-name authentication service in the usage request using the mapping relationship, and compare the obtained network address after resolution to find the target network address of the target service provider providing the ID card real-name authentication service from the network addresses stored in the routing information. After that, the PaaS platform can forward the usage request to the target service provider with the target network address. The target service provider can respond to this usage request forwarded by the PaaS platform to obtain the interface information of the API interface required to implement the identity authentication service. The target service provider can further use the network access module configured by itself to send the interface information of the API interface as the response result of the usage request to the PaaS platform. Finally, the service user can also use the network access module configured by itself to receive the interface information of the API interface required to implement the identity authentication service forwarded by the PaaS platform and use the identity authentication service by calling this interface.

[0176] The above only schematically presents a scenario of using the identity card real-name authentication service, and for the usage scenarios of any SaaS service in practice, reference can be made to the relevant descriptions in the above embodiments, which will not be elaborated here. In addition, for the content not described in detail in this embodiment and the achievable technical effects, reference can also be made to the relevant descriptions in the above embodiments, which will not be elaborated here.

[0177] The processing device of the SaaS service according to one or more embodiments of the present invention will be described in detail below. Those skilled in the art can understand that these processing devices can all be configured by using commercially available hardware components through the steps taught by this solution.

[0178] Figure 12 It is a schematic structural diagram of a processing device for a SaaS service provided by an embodiment of the present invention, as Figure 12 shown, the device includes:

[0179] A first receiving module 11, configured to receive a usage request sent by a service user, where the usage request corresponds to any SaaS service published on the PaaS platform.

[0180] A forwarding module 12, configured to forward the usage request to a target service provider that provides the any SaaS service according to the service provider address in the routing information.

[0181] A first sending module 13, configured to send a response result generated by the target service provider to the service user, where the PaaS platform, the service user, and the service provider are interconnected through a VPC.

[0182] Wherein, the service provider and the service user are in VPCs in different regions; the service provider uses an internally configured network access module to interconnect the VPC where the service provider is located with the VPC where the PaaS platform is located; the service user uses an internally configured network access module to interconnect the VPC where the service user is located with the VPC where the PaaS platform is located;

[0183] Wherein, the PaaS platform is in at least one VPC in the same region or in at least one VPC in different regions; the PaaS platform is configured with an interconnection medium; the interconnection medium is used to establish a communication connection between any two VPCs in the same region, or establish a communication connection between any two VPCs in different regions.

[0184] Among them, the routing information includes the network addresses of different service providers that publish SaaS services in the PaaS platform. The different service providers are in the same VPC, or in different VPCs in the same region, or in VPCs in different regions.

[0185] Optionally, the device further includes: an obtaining module 14, configured to obtain the attribute information of the SaaS service provided by the service provider in response to a service configuration operation triggered by the service provider.

[0186] A judging module 15, configured to judge the legality of the SaaS service according to the attribute information.

[0187] A displaying module 16, configured to display the service detail information in the attribute information if the SaaS service is legal.

[0188] A determining module 17, configured to determine the network address in the attribute information as the routing information if the SaaS service is legal.

[0189] Figure 12 The shown device can execute Figure 9 the method of the shown embodiment. For parts not described in detail in this embodiment, reference can be made to the relevant description of Figure 9 the shown embodiment. For the execution process and technical effects of this technical solution, refer to the description in Figure 9 the shown embodiment and will not be elaborated here.

[0190] In a possible design, the processing method of the SaaS service provided in the above embodiments can be applied to an electronic device, such as Figure 13 shown. The electronic device may include: a first processor 21 and a first memory 22. The first memory 22 is used to store a program that supports the electronic device to execute the processing method of the SaaS service provided in the above Figure 9 shown embodiment. The first processor 21 is configured to execute the program stored in the first memory 22.

[0191] The program includes one or more computer instructions. When the one or more computer instructions are executed by the first processor 21, the following steps can be implemented:

[0192] Receive a usage request sent by a service user, where the usage request corresponds to any SaaS service published on the PaaS platform;

[0193] Forward the usage request to a target service provider that provides the any SaaS service according to the service provider address in the routing information;

[0194] Send the response result generated by the target service provider to the service user, where the VPCs where the PaaS platform, the service user, and the service provider are located are interconnected.

[0195] Optionally, the first processor 21 is further configured to execute all or part of the steps in the foregoing Figure 9 illustrated embodiments.

[0196] Wherein, the structure of the electronic device may further include a first communication interface 23 for the electronic device to communicate with other devices or communication networks.

[0197] In addition, an embodiment of the present invention provides a computer storage medium for storing computer software instructions used by the foregoing electronic device, which includes a program for executing the processing method of the SaaS service described above Figure 9 shown.

[0198] Figure 14 FIG. is a schematic structural diagram of another processing device for SaaS services provided by an embodiment of the present invention, as Figure 14 shown, the device includes:

[0199] A second sending module 31, configured to send a usage request corresponding to any SaaS service published on the PaaS platform to the PaaS platform.

[0200] A second receiving module 32, configured to receive a response result generated by a service provider, where the response result corresponds to the usage request, and the VPCs where the PaaS platform, the service user, and the service provider are located are interconnected.

[0201] Figure 14 The device shown can execute the Figure 10 method of the illustrated embodiment. For parts not described in detail in this embodiment, reference may be made to the relevant descriptions of the Figure 10 illustrated embodiment. The execution process and technical effects of this technical solution are referred to the Figure 10 description in the illustrated embodiment and will not be elaborated here.

[0202] In a possible design, the processing methods for SaaS services provided in the foregoing embodiments can be applied to another electronic device, as Figure 15 shown, the electronic device may include: a second processor 41 and a second memory 42. The second memory 42 is used to store a program for supporting the electronic device to execute the processing method for SaaS services provided in the foregoing Figure 10 illustrated embodiment, and the second processor 41 is configured to execute the program stored in the second memory 42.

[0203] The program includes one or more computer instructions, and when the one or more computer instructions are executed by the second processor 41, the following steps can be implemented:

[0204] Send the usage request corresponding to any SaaS service published on the PaaS platform to the PaaS platform;

[0205] Receive the response result generated by the service provider, where the response result corresponds to the usage request, and the VPCs where the PaaS platform, the service user, and the service provider are located are interconnected.

[0206] Optionally, the second processor 41 is further configured to execute all or part of the steps in the foregoing Figure 10 illustrated embodiments.

[0207] Wherein, the structure of the electronic device may further include a second communication interface 43 for the electronic device to communicate with other devices or communication networks.

[0208] In addition, an embodiment of the present invention provides a computer storage medium for storing the computer software instructions used by the foregoing electronic device, which includes a program for executing the processing method of the SaaS service described above Figure 10 shown.

[0209] Figure 16 FIG. is a schematic structural diagram of another processing device for a SaaS service provided by an embodiment of the present invention, as Figure 16 shown, the device includes:

[0210] A third receiving module 51, configured to receive a usage request from a service user for any SaaS service published on the PaaS platform.

[0211] A response module 52, configured to respond to the usage request to obtain a response result.

[0212] A third sending module 53, configured to send the response result required by the service user, where the VPCs where the PaaS platform, the service user, and the service provider are located are interconnected.

[0213] Figure 16 The device shown can execute Figure 11 the method of the illustrated embodiment. For parts not described in detail in this embodiment, reference may be made to the relevant descriptions of Figure 11 the illustrated embodiment. The execution process and technical effects of this technical solution are referred to the description in Figure 11 the illustrated embodiment, and will not be elaborated here.

[0214] In a possible design, the processing method of the SaaS service provided in the above embodiments can be applied to another electronic device, such as Figure 17 As shown, the electronic device may include: a third processor 61 and a third memory 62. The third memory 62 is used to store a program that supports the electronic device to execute the processing method of the SaaS service provided in the above Figure 11 As shown in the embodiments. The third processor 61 is configured to execute the program stored in the third memory 62.

[0215] The program includes one or more computer instructions. When the one or more computer instructions are executed by the third processor 61, the following steps can be implemented:

[0216] Receive a usage request from a service user for any SaaS service published on the PaaS platform;

[0217] Respond to the usage request to obtain a response result;

[0218] Send the response result required by the service user, where the PaaS platform, the service user, and the service provider are interconnected through a VPC.

[0219] Optionally, the third processor 61 is further configured to execute all or part of the steps in the foregoing Figure 11 As shown in the embodiments.

[0220] Wherein, the structure of the electronic device may further include a third communication interface 63 for the electronic device to communicate with other devices or communication networks.

[0221] In addition, an embodiment of the present invention provides a computer storage medium for storing computer software instructions used by the above electronic device, which includes a program involved in executing the processing method of the SaaS service shown in the above Figure 11 As shown.

[0222] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A processing system for SaaS services, characterized in that, Including: A service provider, a service user, and a Platform as a Service (PaaS) platform, wherein the virtual private clouds (VPCs) where the service provider, the service user, and the PaaS platform are located are interconnected. The service user is configured to send a usage request for any Software as a Service (SaaS) service published on the PaaS platform to the PaaS platform, and receive a response result of the usage request forwarded by the PaaS platform. The PaaS platform is configured to forward the usage request to a target service provider that provides the any SaaS service according to the network address in the routing information. The target service provider is configured to respond to the usage request and send the response result of the usage request to the PaaS platform.

2. The system according to claim 1, wherein The service provider and the service user are in VPCs in different regions. The service provider uses an internally configured network access module to interconnect the VPC where the service provider is located with the VPC where the PaaS platform is located. The service user uses an internally configured network access module to interconnect the VPC where the service user is located with the VPC where the PaaS platform is located. The PaaS platform is in at least one VPC in the same region or in at least one VPC in different regions. The PaaS platform is configured with an interconnection medium, which is used to establish a communication connection between any two VPCs in the same region or establish a communication connection between any two VPCs in different regions.

3. The system according to claim 1, wherein The routing information includes the network addresses of different service providers that publish SaaS services in the PaaS platform. The different service providers are in the same VPC, or in different VPCs in the same region, or in VPCs in different regions.

4. The system according to claim 1, wherein The PaaS platform includes: a network connection system, which is configured to determine a target network address corresponding to the any SaaS service according to the service network parameters in the usage request. Forward the usage request to the target service provider with the target network address.

5. The system according to claim 5, characterized in that, The PaaS platform includes: a service management system, which is configured to, in response to a service configuration operation triggered by the service provider on the service management system, obtain the attribute information of the SaaS service provided by the service provider. The attribute information includes service detail information and service network parameters. Judge the legality of the SaaS service according to the attribute information. If the SaaS service is legal, display the service detail information in the attribute information. The network connection system is configured to, if the SaaS service is legal, obtain the network address included in the attribute information from the service management system. Determine the network address in the attribute information as the routing information.

6. The system according to claim 1, wherein The PaaS platform includes: a network connection system, which is configured to determine the legality of the usage request according to the data volume and / or data content of the usage request.

7. The system according to claim 1, wherein The PaaS platform includes: a network connection system, which is configured to determine the data volume of the response result sent by the target service provider. Determine the cost resource consumption of the service user according to the amount of data.

8. The system according to claim 1, wherein The PaaS platform includes: a network connection system and a service management system; The network connection system is used to determine the legality of any SaaS service according to the data content of the response result; The service management system is used to delete any SaaS service if the any SaaS service is illegal.

9. The system according to claim 1, characterized in that The PaaS platform includes: a service management system for displaying the SaaS services published on the PaaS platform; In response to the editing operation of the service provider, edit the attribute information of the SaaS service.

10. The system according to claim 1, wherein The PaaS platform includes: a user management system for storing the account information of the service provider; Verify the service publishing permission of the service provider according to the account information of the service provider.

11. A processing method for SaaS services, characterized in that, Applied to a Platform as a Service (PaaS) platform, including: Receive a usage request sent by a service user, where the usage request corresponds to any Software as a Service (SaaS) service published on the PaaS platform; Forward the usage request to the target service provider providing the any SaaS service according to the network address in the routing information; Send the response result generated by the target service provider in response to the usage request to the service user, where the PaaS platform, the service user, and the service provider are interconnected through a private virtual private cloud (VPC).

12. The method according to claim 11, wherein The service provider and the service user are in VPCs in different regions; the service provider uses an internally configured network access module to interconnect the VPC where the service provider is located with the VPC where the PaaS platform is located; the service user uses an internally configured network access module to interconnect the VPC where the service user is located with the VPC where the PaaS platform is located; The PaaS platform is in at least one VPC in the same region or in at least one VPC in different regions; the PaaS platform is configured with an interconnection medium; the interconnection medium is used to establish a communication connection between any two VPCs in the same region or establish a communication connection between any two VPCs in different regions.

13. The method according to claim 11, wherein The routing information includes the network addresses of different service providers who publish SaaS services in the PaaS platform, and the different service providers are in the same VPC, or in different VPCs in the same region, or in VPCs in different regions.

14. The method according to claim 11, characterized in that, The method further includes: In response to the service configuration operation triggered by the service provider, obtain the attribute information of the SaaS service provided by the service provider; Judge the legality of the SaaS service according to the attribute information; If the SaaS service is legal, display the service detail information in the attribute information; If the SaaS service is legal, determine the network address in the attribute information as the routing information.

15. A processing method for SaaS services, characterized in that, Applied to a service user, including: Send the usage request corresponding to any software - as - a - service (SaaS) service published on the platform - as - a - service (PaaS) platform to the PaaS platform; Receive the response result generated by the service provider, where the response result corresponds to the usage request, and the virtual private cloud (VPC) where the PaaS platform, the service user, and the service provider are located are interconnected.

16. A processing method for SaaS services, characterized in that, Applied to the service provider, including: Receive the usage request of the service user for any software - as - a - service (SaaS) service published on the platform - as - a - service (PaaS) platform; Respond to the usage request to obtain a response result; Send the response result required by the service user, where the virtual private cloud (VPC) where the PaaS platform, the service user, and the service provider are located are interconnected.

17. An electronic device, characterized in that, Including: A memory and a processor; wherein, executable code is stored on the memory, and when the executable code is executed by the processor, the processor executes the processing method of the SaaS service according to any one of claims 11 - 14.

18. An electronic device, characterized in that, Including: A memory, a processor, and a network access module; wherein, the electronic device uses the network access module to interconnect the electronic device and the virtual private cloud (VPC) where the platform - as - a - service (PaaS) platform is located, and executable code is stored on the memory, and when the executable code is executed by the processor, the processor executes the processing method of the SaaS service according to claim 15 or 16.

19. A non-transitory machine-readable storage medium, characterized in that, Executable code is stored on the non - transitory machine - readable storage medium, and when the executable code is executed by the computing system of the electronic device, the computing system executes the processing method of the SaaS service according to any one of claims 11 - 16.