Cross-domain multi-system data processing method and system based on supercomputing Internet
The issuance of access tokens through the edge platform of the supercomputing Internet solves the problem of repeated login of users during cross-domain login, and seamless cross-system access is achieved, improving user experience and ensuring the reliability and security between systems.
Patent Information
- Application Number
- CN202510601600.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-12
- Publication Date
- 2025-07-04
AI Technical Summary
During the cross-domain login process between different systems, users need to log in repeatedly, resulting in poor user experience, and identity attribute updates rely on centralized servers, resulting in a surge in server load and significant data delay in high concurrency scenarios.
Access tokens are issued nearby through the edge platform of the supercomputing Internet, and a decentralized mutual trust mechanism is adopted. Each edge node independently completes token issuance and verification. It uses standardized token formats and unified signature verification rules, and combines the hierarchical mechanism of long and short-term tokens to achieve low latency and high concurrency trust transmission.
It enables users to seamlessly access multiple systems without repeated login, improves cross-domain operation experience, ensures the reliability and security of cross-platform access, and reduces the need for frequent authentication of cross-domain access, ensuring the consistency of user data status and the stability of system collaborative operation.
Smart Images

Figure CN120263522A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of cross - domain access, and particularly to a data processing method and system between cross - domain multiple systems based on the Supercomputing Internet. Background Art
[0002] In order to meet the user login requirements between different system platforms, traditional methods such as the Cookie - Session mechanism, OAuth 2.0, OpenID Connect, JWT (JSON Web Token) stateless authentication, and single sign - on (SSO) are often used to achieve the application requirements of cross - domain multiple - system user login scenarios.
[0003] In related technologies, since different commonly used cross - domain multiple - system login methods use heterogeneous authentication protocols such as OAuth, SAML, JWT, etc., due to differences in the trust transfer mechanisms of heterogeneous authentication protocols, identity credentials cannot be directly recognized between different systems. As a result, when users switch between different protocol platforms, they need to log in repeatedly, resulting in a poor user experience. Summary of the Invention
[0004] To solve or partially solve the problems existing in related technologies, this application provides a data processing method and system between cross - domain multiple systems based on the Supercomputing Internet, which can issue access tokens nearby through a platform at the network edge, avoid the repeated dependence on a centralized authentication server during cross - domain requests in traditional solutions, and users can seamlessly access multiple systems without repeated login, effectively improving the user's cross - domain operation experience.
[0005] The first aspect of this application provides a data processing method between cross - domain multiple systems based on the Supercomputing Internet, which is applied to the current service system. The current service system and the target service system are connected to the same Supercomputing Internet, and it includes: In response to an access request initiated by a user to the target service system after logging in to the current service system, obtain the user identity information from the corresponding Supercomputing Internet node; Generate first token information in a preset format according to the user identity information, output the first token information to the target service system, and the target service system performs signature verification according to the preset public key.
[0006] In some embodiments, the generating first token information in a preset format according to the user identity information includes: Extract the identity identification information from the user identity information, and generate first token information according to the identity identification information and a first preset validity period.
[0007] In some embodiments, the method further includes: Generate second token information that matches the first token information according to the first token information and a second preset validity period; wherein, the second preset validity period is greater than the first preset validity period. After detecting that the first token information has expired within the second preset validity period, refresh the first token information according to the second token information.
[0008] In some embodiments, the user identity information is generated in the following manner, including: In response to a user's registration request, call the registration page. Receive the registration information input by the user on the registration page, generate user identity information according to the registration information, and synchronize it to the corresponding hypercomputing Internet node after distributed storage encryption; wherein, the user identity information at least includes: identity identification information and user basic information.
[0009] In some embodiments, the method further includes: When detecting an update of the user basic information, trigger a preset broadcast event mechanism, and transmit the updated user basic information to the hypercomputing Internet for broadcasting.
[0010] In some embodiments, the transmitting the updated user basic information to the hypercomputing Internet for broadcasting includes: Perform a preset shared data type definition on the updated user basic information according to the user preset user information sharing scope. Perform a preset broadcast operation on the updated user basic information according to the defined shared data type.
[0011] A second aspect of the present application provides a cross-domain multi-system data processing system based on a hypercomputing Internet, which is applied to the current service system, where the current service system and the target service system are connected to the same hypercomputing Internet, including: A request response module, configured to, in response to an access request initiated by a user to the target service system after logging in to the current service system, obtain user identity information from the corresponding hypercomputing Internet node. A token generation module, configured to generate first token information in a preset format according to the user identity information, and output the first token information to the target service system for signature verification.
[0012] In some embodiments, the system further includes: A data update module, configured to, when detecting an update of the user identity information, trigger a preset broadcast event mechanism, and transmit the updated user basic information to the hypercomputing Internet for broadcasting.
[0013] A third aspect of the present application provides an electronic device, including: a processor; and a memory storing executable code, which, when executed by the processor, causes the processor to execute the method as described above.
[0014] A fourth aspect of the present application provides a computer-readable storage medium storing executable code, which, when executed by a processor of an electronic device, causes the processor to execute the method as described above.
[0015] The technical solution provided by the present application may include the following beneficial effects: In the technical solution of the present application, in the scenario of cross-system access by users, it is possible to issue access tokens nearby through a platform at the network edge, such as a community platform, replacing the single issuance mode of the traditional centralized authentication server, forming a decentralized mutual trust mechanism. Each edge node independently completes the operations of token issuance and verification, avoiding the repeated dependence on the centralized authentication server in cross-domain requests in the traditional solution, and significantly improving the data processing efficiency between multiple systems; by standardizing the token format and unifying the signature verification rules, the problem of identity mutual recognition failure caused by protocol differences between heterogeneous systems is solved, ensuring the reliability and security of cross-platform access; at the same time, by utilizing the parallel computing power of the supercomputer Internet, low-latency and high-concurrency trust transfer is achieved during the process of token generation and verification. Users can seamlessly access multiple systems without repeated login, effectively improving the cross-domain operation experience, and ensuring the consistency of user data status between multiple platforms and the stability of system collaborative operation.
[0016] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] By describing the exemplary embodiments of the present application in more detail in conjunction with the drawings, the above and other objects, features, and advantages of the present application will become more obvious. Among them, in the exemplary embodiments of the present application, the same reference numerals generally represent the same components.
[0018] Figure 1 is a schematic flowchart of a method for data processing between cross-domain multiple systems based on the supercomputer Internet shown in an embodiment of the present application; Figure 2 is another schematic flowchart of a method for data processing between cross-domain multiple systems based on the supercomputer Internet shown in an embodiment of the present application; Figure 3 is another schematic flowchart of a method for data processing between cross-domain multiple systems based on the supercomputer Internet shown in an embodiment of the present application; Figure 4It is another schematic flowchart of the data processing method between cross-domain multiple systems based on the supercomputing Internet shown in the embodiments of this application; Figure 5 It is another schematic flowchart of the data processing method between cross-domain multiple systems based on the supercomputing Internet shown in the embodiments of this application; Figure 6 It is a schematic structural diagram of the data processing system between cross-domain multiple systems based on the supercomputing Internet shown in the embodiments of this application; Figure 7 It is another schematic structural diagram of the data processing system between cross-domain multiple systems based on the supercomputing Internet shown in the embodiments of this application; Figure 8 It is a schematic structural diagram of the electronic device shown in the embodiments of this application. Specific Embodiment Hereinafter, embodiments of the present application will be described in more detail with reference to the accompanying drawings. Although the embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided so that the present application will be more thorough and complete, and can fully convey the scope of the present application to those skilled in the art.
[0020] The terms used in this application are only for the purpose of describing specific embodiments and are not intended to limit the present application. The singular forms "a", "the" and "said" used in this application and the appended claims are also intended to include the plural forms unless the context clearly dictates otherwise. It should also be understood that the term "and / or" as used herein refers to and includes any and all possible combinations of one or more of the associated listed items.
[0021] It should be understood that although the terms "first", "second", "third", etc. may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present application, "a plurality" means two or more unless otherwise specifically defined.
[0022] In related technologies, since the commonly used different cross-domain multi-system login methods use heterogeneous authentication protocols, such as OAuth, SAML, JWT, etc., due to the differences in the trust transfer mechanisms of heterogeneous authentication protocols, identity credentials cannot be directly recognized between different systems. As a result, when users switch between different protocol platforms, they need to log in repeatedly, resulting in a poor user experience. Moreover, the update of user identity attributes depends on the polling synchronization of the centralized server, leading to a significant increase in server load and data latency in high-concurrency scenarios.
[0023] To address the above problems, the embodiments of the present application provide a data processing method between cross-domain multi-systems based on the supercomputing Internet, which can issue access tokens nearby through a platform at the network edge, avoiding the repeated dependence on the centralized authentication server in traditional solutions. Moreover, users can seamlessly access multiple systems without repeated login, effectively improving the user experience of cross-domain operations.
[0024] The technical solutions of the embodiments of the present application are described in detail below with reference to the accompanying drawings.
[0025] The data processing method between cross-domain multi-systems based on the supercomputing Internet of the present application is mainly applied to the current service system, where the current service system and the target service system are connected to the same supercomputing Internet. Among them, the current service system can include, but is not limited to, a community platform, and the target service system can be a third-party platform of the same type or different types as the current service system.
[0026] Figure 1 is a schematic flowchart of the data processing method between cross-domain multi-systems based on the supercomputing Internet shown in the embodiments of the present application.
[0027] See Figure 1 , the data processing method between cross-domain multi-systems based on the supercomputing Internet of the present application includes: S110, in response to an access request initiated by a user to the target service system after logging in to the current service system, obtain the user identity information from the corresponding supercomputing Internet node.
[0028] In this step, after the user logs in to the current service system and initiates an access request to the target service system, in response to the above access request, obtain the pre-stored user identity information from the supercomputing Internet node.
[0029] Among them, the user identity information can at least include: identity identification information. It should be understood that in the registration process, identity identification information corresponding to the user identity is generated through registration.
[0030] S120, generate first token information in a preset format according to the user identity information, output the first token information to the target service system, and the target service system performs signature verification according to the preset public key.
[0031] In this step, according to the obtained user identity information, the first token information conforming to the preset format is generated, and along with the user's access action, the first token information is output to the target service system for signature verification, and the target service system verifies the signature of the first token information through the pre-set public key.
[0032] Among them, the preset public key can be distributed or synchronized to all target service systems through a key distribution center pre-constructed on the node network of the supercomputing Internet.
[0033] In this embodiment, in the scenario of cross-system user access, a platform at the network edge such as a community platform can be used to issue access tokens nearby, replacing the single issuance mode of the traditional centralized authentication server, forming a decentralized mutual trust mechanism. Each edge node independently completes the token issuance and verification operations, avoiding the repeated dependence on the centralized authentication server in cross-domain requests in the traditional solution, significantly improving the data processing efficiency between multiple systems, and solving the problem of identity mutual recognition failure caused by protocol differences between heterogeneous systems through standardized token formats and unified signature verification rules, ensuring the reliability and security of cross-platform access; at the same time, using the parallel computing power of the supercomputing Internet, low-latency and high-concurrency trust transfer is achieved during token generation and verification. Users can seamlessly access multiple systems without repeated login, effectively improving the cross-domain operation experience, and ensuring the consistency of user data status between multiple platforms and the stability of system collaborative operation.
[0034] Figure 2 It is another schematic flow diagram of the cross-domain multi-system data processing method based on the supercomputing Internet shown in the embodiments of the present application.
[0035] See Figure 2 , the cross-domain multi-system data processing method based on the supercomputing Internet of the present application includes: S210, in response to an access request initiated by the user to the target service system after logging in to the current service system, obtain the user identity information from the corresponding supercomputing Internet node.
[0036] In this step, after the user logs in to the current service system and initiates an access request to the target service system, in response to the above access request, obtain the pre-stored user identity information from the supercomputing Internet node.
[0037] Among them, the user identity information is generated through the following registration process, including: S2101, in response to the user's registration request, call the registration page.
[0038] In this step, after the user initiates a registration request in the current service system, the current service system responds to the user's registration request and calls the registration page.
[0039] S2102, receive the registration information input by the user on the registration page, generate user identity information according to the registration information, and synchronize it to the corresponding supercomputer Internet node after encryption through distributed storage; wherein, the user identity information at least includes: identity identification information and user basic information.
[0040] In this step, by receiving the registration information input by the user on the registration page, user identity information is generated, and the user identity information is synchronized to the adjacent supercomputer Internet node through distributed storage after encryption.
[0041] In this application, a distributed identity management protocol (such as the DID standard) in related technologies can be adopted to realize the generation of user identity information including identity identification information through the current service system, so as to realize the decentralized storage and verification of user identity.
[0042] Among them, the user identity information at least includes unique identity identification information (i.e., UUID) and user basic information related to the user. Among them, the user identity information may include, but is not limited to: user name information, encrypted password, biometric hash value.
[0043] Among them, the user identity information can be synchronized from the current service system to the nearest supercomputer Internet node for storage.
[0044] S220, extract the identity identification information in the user identity information, generate the first token information according to the identity identification information and the first preset validity period, output the first token information to the target service system, and the target service system performs signature verification according to the preset public key.
[0045] In this step, extract the unique identity identification information from the obtained user identity information, generate the first token information whose validity period corresponds to the preset validity period according to the preset validity period for setting the corresponding token validity time in advance, output the generated first token information to the target service system, and the target service system performs signature verification on the first token information through the preset public key.
[0046] Among them, the first preset validity period can correspond to short-term validity. That is to say, the first token information can be a short-term access token, that is, the first token information is used for signature verification of the target service system within a short period of time.
[0047] For example, if the first preset validity period is 15 minutes, the validity period of the first token information corresponds to 15 minutes. After 15 minutes, the first token information automatically expires and can no longer be used for signature verification of the target service system.
[0048] Among them, the user identity information may further include: permission tags. It should be understood that the permission tags are used to distinguish user roles, such as ordinary users, administrators, and third-party services, so as to achieve different fine-grained access controls for different users during the access process to the target service system.
[0049] Among them, during the process of generating the first token information, the identity identification information and permission tags in the user identity information can be extracted, and the first token information is generated according to the identity identification information, the first preset validity period, and the permission tags. That is to say, the first token information may contain permission tag information used to distinguish user permission levels. When the target service system performs signature verification through the first token information after receiving it, the permission tag information contained in the first token information can also be parsed, so as to control the access permission of the user in the target service system, that is, to control the content range that the user can access through the parsed permission tag information.
[0050] S230. Generate a second token information that matches the first token information according to the first token information and the second preset validity period; wherein, the second preset validity period is greater than the first preset validity period.
[0051] In this step, a second token information that matches the first token information is generated according to the generated first token information and the pre-set second preset validity period. The second token information is used to refresh the first token information, and the second preset validity period is greater than the first preset validity period.
[0052] Among them, the second token information corresponds to a long validity period. That is to say, the second token information can be a long-term access token, that is, the second token information is used to refresh the first token information for a long time, so as to continuously generate the first token information for signature verification of the target service system for a long time.
[0053] For example, if the second preset validity period is 7 days, the validity period of the second token information corresponds to 7 days. After 7 days, the second token information automatically expires.
[0054] S240. After detecting that the first token information has expired within the second preset validity period, refresh the first token information according to the second token information.
[0055] In this step, within the second preset validity period, if it is detected that the first token information has expired, the first token information is refreshed according to the second token information to renew the first token information.
[0056] It should be understood that the first token information is different after being refreshed from before the refresh. That is to say, the first token information cannot be used to access the target server system after expiration. The refreshed first token information can be used to access the target server system only within the first validity period, and the refreshed first token information is different from the first token information before the refresh.
[0057] It is not difficult to understand that when a user first accesses other target service systems, the generated first token information is carried to the target service system for signature verification. After the first validity period, the first token information becomes invalid and is refreshed according to the second token information. In this way, when the user accesses other target service systems for the second time, the refreshed first token information can still be carried for signature verification, thereby implementing a dynamic key rotation mechanism. By regularly updating the first token information, the reliability and security of the signature verification process are ensured, and the risk of leakage and inability to expire immediately due to the long-term fixed validity of the key is effectively prevented. Among them, an asymmetric encryption algorithm can be used in the process of generating the first token information and refreshing the first token information according to the second token information.
[0058] For example, an asymmetric encryption algorithm such as RSA-2048 or national cipher SM2 is used to obtain the first token information. Obtaining the first token information through an asymmetric encryption algorithm can effectively improve the anti-tampering performance of the first token information.
[0059] In this embodiment, the cross-domain multi-system data processing method based on the supercomputing Internet of the present application ensures the precise binding of the token information with the user identity through a dynamic token generation rule based on the identity identifier and the preset validity period, and can achieve controllable timeliness of the token for cross-system access, avoiding the leakage risk caused by the long-term validity of traditional static tokens; through the hierarchical cooperation mechanism of long-term and short-term tokens, while ensuring the short-term validity of the main token, the token is refreshed without perception through the long-term token, effectively reducing the frequent authentication requirements caused by cross-domain access, thereby enhancing the continuous experience of the user's cross-domain access.
[0060] Figure 3 It is another process schematic diagram of the cross-domain multi-system data processing method based on the supercomputing Internet shown in the embodiment of the present application.
[0061] See Figure 3 , the cross-domain multi-system data processing method based on the supercomputing Internet of the present application includes: S310, in response to an access request initiated by a user to a target service system after logging in to the current service system, obtain the user identity information from the corresponding supercomputing Internet node.
[0062] In this step, after the user logs in to the current service system, an access request to the target service system is initiated. In response to the above access request, the user identity information pre-stored in the supercomputing Internet node is obtained.
[0063] S320, extract the identity identification information and permission tags in the user identity information, generate the first token information according to the identity identification information, permission tags, and the first preset validity period, output the first token information to the target service system, and the target service system performs signature verification according to the preset public key.
[0064] In this step, extract the unique identity identification information from the obtained user identity information, and extract the permission tags used to distinguish user roles. According to the preset validity period that pre-sets the corresponding token validity time, generate the first token information whose validity period corresponds to the preset validity period, output the generated first token information to the target service system, and the target service system performs signature verification on the first token information through the pre-set public key.
[0065] Among them, after receiving the first token information, the target service system performs signature verification on the first token information according to the preset public key, and parses the permission tags in the first token information.
[0066] Among them, the first token information can be output to the target service system through a preset encrypted communication link, so as to achieve end-to-end encryption and further improve the security performance of cross-system data transmission. For example, the first token information is transmitted through the TLS1.3 protocol.
[0067] Furthermore, the sensitive data contained in the first token information can be encrypted twice. For example, the identity identification information in the first token information is processed by the national cryptography algorithm SM4 for double encryption, and then sent to the target service system.
[0068] Furthermore, the sensitive data contained in the first token information can be obfuscated. For example, the identity identification information in the first token information is processed by the method of hash value confusion to further ensure the data security during the data transmission process.
[0069] S330, generate the second token information that matches the first token information according to the first token information and the second preset validity period; where the second preset validity period is greater than the first preset validity period.
[0070] In this step, generate the second token information that matches the first token information according to the generated first token information and the pre-set second preset validity period. The second token information is used to refresh the first token information, and the second preset validity period is greater than the first preset validity period.
[0071] S340, after detecting that the first token information has expired within the second preset validity period, refresh the first token information according to the second token information.
[0072] In this step, within the second preset validity period, if it is detected that the first token information has expired, then refresh the first token information according to the second token information to renew the first token information.
[0073] S350, when it is detected that the user's basic information has been updated, trigger the preset broadcast event mechanism and transmit the updated user's basic information to the supercomputing Internet for broadcasting.
[0074] In this step, continuously detect whether the user's basic information on the current service system has been updated. When it is determined that an update has occurred, output the updated user's basic information to the supercomputing Internet for broadcasting through the preset broadcast event mechanism, so that the target service system subscribing to the above preset broadcast event can receive the updated user's basic information to achieve information synchronization between cross-domain systems.
[0075] Among them, the preset broadcast event mechanism can be implemented in the form of a message queue.
[0076] It should be understood that after the preset broadcast event is triggered, the target service system subscribing to the above preset broadcast event automatically obtains the updated data from the supercomputing Internet.
[0077] Among them, the process of transmitting the updated user's basic information to the supercomputing Internet for broadcasting can include the following steps: S3501, perform a preset shared data type definition on the updated user's basic information according to the user's preset user information sharing scope.
[0078] Among them, a declarative data model is adopted to define the sharing scope and synchronization rules of the user's basic information. Among them, the shared data types in the user's basic information can be predefined as the public layer, restricted layer, and privacy layer. The user can independently set the sharing level to control the sharing scope of the user's basic information between cross-domain systems. Among them, the public layer data can be the data information content that is publicly available by default in the system, such as the user name; the restricted layer can be the data information content with medium privacy level in the system, such as the email address, which requires the user to authorize again to be made public; the privacy layer can be the data information content with high privacy level in the system, such as the mobile phone number, which is not publicly available by default.
[0079] It should be understood that the user pre-sets the above public layer, restricted layer, and privacy layer independently to determine the data sharing scope, so that the information sharing degree of the user on the target service system can be set according to the user's needs, thereby further improving the user experience between cross-domain systems.
[0080] S3502, perform a preset broadcast operation on the updated user basic information according to the defined shared data type.
[0081] Among them, according to the preset shared data type, different broadcast operations are performed on the updated user basic information. It can be known that when the changed data in the updated user basic information is public layer data, broadcasting can be performed to achieve synchronization. When the changed data in the updated user basic information is restricted layer data, broadcasting can be performed after the user's secondary authorization. When the changed data in the updated user basic information is privacy layer data, the corresponding broadcast operation is not performed by default.
[0082] Among them, only the incremental data in the updated user basic information can be broadcast, that is, an incremental synchronization strategy is adopted, and only the changed fields are transmitted, so as to effectively reduce network overhead and reduce network operation load.
[0083] Among them, the updated user basic information for broadcasting can be converted into preset data format data before broadcasting. For example, through a unified data exchange protocol, such as JsonSchema, the updated user basic information to be broadcast is pre-processed for corresponding data format conversion to ensure the compatibility of data formats between different systems.
[0084] Among them, high-frequency access data of users from the current service system to the target service system can also be pre-cached in the edge nodes of the supercomputer Internet. When the user repeatedly accesses the same access data, the pre-cached high-frequency access data is called from the edge nodes of the supercomputer Internet, so as to effectively improve the data synchronization efficiency.
[0085] Among them, a data anomaly diagnosis mechanism can also be deployed in the supercomputer Internet to realize real-time monitoring of abnormal behaviors between cross-domain systems. When an anomaly occurs, a fuse instruction is sent to the current service system to realize the data protection function. The abnormal behaviors can include, but are not limited to: high-frequency Token requests. Among them, the fuse instruction can include, but is not limited to: banning IP, restricting the number of requests, forcing re-authentication, etc.
[0086] Among them, in the process of outputting the first token information or performing a preset broadcast operation on the updated user basic information, the zero-knowledge proof technology in related technologies can be used to verify the authenticity of permissions between the current service system and the target service system, so as to effectively avoid leaking the user's privacy information during the data transmission or sharing process between the current service system and the target service system.
[0087] In this embodiment, the cross-domain multi-system data processing method based on supercomputing Internet of the present application instantly triggers a broadcast event when user information is updated, thereby achieving efficient synchronization of user information between cross-domain systems, ensuring strong consistency of user data in cross-platform access scenarios, and avoiding data delay problems under traditional polling synchronization mechanisms; through user-defined sharing scope and data type definition rules, the updated information is classified as public, restricted, private and other multi-level data streams as needed, realizing a differentiated broadcast mechanism, and minimizing disclosure during data synchronization between different systems, thereby meeting the information sharing requirements necessary for cross-system collaboration, while effectively avoiding the risk of data interception by unauthorized nodes. In order to facilitate the understanding of the technical solution of the present application, the following takes the current service system which may include a business layer (Controller), a service layer (Service), a data access layer (Dao), and a third-party platform (i.e., the target service system) connected to the same supercomputing Internet as the current service system as an example to explain the user registration process in the current service system through the browser of a front-end device (such as a smart computer) and the user login process to the third-party platform.
[0088] Figure 4 It is another flow chart of a cross-domain multi-system data processing method based on supercomputing Internet shown in an embodiment of the present application.
[0089] See also Figure 4 , the user registration process may include the following steps: S401, the user initiates a registration request to the business layer through a browser; S402, the business layer controls the browser to call the registration page; S403, the user enters registration information on the registration page through a browser; S404, after the user completes entering the registration information on the registration page, the browser sends the registration information to the business layer; S405, the business layer receives the registration information, performs verification analysis, and extracts the user account; S406, the business layer initiates a user query request to the service layer according to the user account; S407, the service layer initiates a user table call request to the data access layer; S408, the data access layer returns the user object information in the user table to the service layer; S409, the service layer determines whether the account in the registration information already exists based on the user object information in the returned user table; S410, when it is determined that the account does not exist, returning the verification status information to the business layer; S411, the business layer sends the registration information to the service layer and requests to save it; S412, the service layer sends the received registration information to the data access layer and requests to write it into the user table; S413, the data access layer returns the writing status information to the service layer after completing the writing of the registration information; S414, the service layer returns the write status information to the business layer; S415, the business layer controls the browser to jump to the login page.
[0090] Through the above user registration process, user identity information can be generated.
[0091] After the above step S415, the following steps may also be included: S416, asynchronously notifying the third-party platform through the service layer and receiving feedback information from the third-party platform, that is, realizing user registration on the third-party platform.
[0092] Figure 5 It is another flow chart of a cross-domain multi-system data processing method based on supercomputing Internet shown in an embodiment of the present application.
[0093] See also Figure 5 , the user third-party platform process may include the following steps: S501, the user enters the URL of the third-party platform through the front-end browser; S502, the browser initiates an access request to the third-party platform according to the URL; S503, the third-party platform calls the current service system interface to access the business layer; S504, the business layer receives the access request, verifies the access request and extracts the user account; S505, the business layer initiates a user query request to the service layer according to the user account; S506, the service layer initiates a user table call request to the data access layer; S507, the data access layer returns the user object information in the user table to the service layer; S508, the service layer determines whether the user account is correct based on the user object information in the returned user table; S509, when it is determined that the user account is correct, the service layer returns the user account login status to the business layer; S510, the business layer sends a user identity information query request to the service layer; S511, after receiving the user identity information query request, the service layer requests the user identity information association table from the data access layer; S512, the data access layer returns the user identity information to the service layer for generating a user data list of token information; S513, the service layer returns the user data list used to generate token information to the business layer; S514. The service layer generates token information for accessing a third-party platform. S515. Jump to the home page of the third-party platform through the browser.
[0094] Corresponding to the foregoing method embodiments for implementing application functions, the present application further provides a data processing system, an electronic device, and corresponding embodiments for cross-domain multi-system data processing based on the supercomputer Internet.
[0095] Figure 6 It is a schematic structural diagram of a cross-domain multi-system data processing system based on the supercomputer Internet shown in the embodiments of the present application.
[0096] See Figure 6 , the cross-domain multi-system data processing system 600 based on the supercomputer Internet of the present application is applied to the current service system, where the current service system and the target service system are connected to the same supercomputer Internet, and includes: A request response module 610, configured to respond to an access request initiated by a user to the target service system after logging in to the current service system, and obtain user identity information from a corresponding supercomputer Internet node.
[0097] In some embodiments, the user identity information is generated in the following manner, including: responding to a user's registration request, invoking a registration page; receiving registration information input by the user on the registration page, generating user identity information according to the registration information, and synchronizing it to the corresponding supercomputer Internet node after encryption through distributed storage; where the user identity information at least includes: identity identification information and user basic information.
[0098] A token generation module 620, configured to generate first token information in a preset format according to the user identity information, and output the first token information to the target service system for signature verification.
[0099] In some embodiments, the token generation module 620 generates first token information in a preset format according to the user identity information, including: extracting the identity identification information in the user identity information, and generating the first token information according to the identity identification information and a first preset validity period.
[0100] In some embodiments, the token generation module 620 is further configured to generate second token information that matches the first token information according to the first token information and a second preset validity period; where the second preset validity period is greater than the first preset validity period; after detecting that the first token information fails within the second preset validity period, the first token information is refreshed according to the second token information.
[0101] Figure 7 It is a schematic structural diagram of a cross-domain multi-system data processing system based on the supercomputer Internet shown in the embodiments of the present application.
[0102] See Figure 7 , in some embodiments, the system further includes: A data update module 630, configured to trigger a preset broadcast event mechanism when detecting an update of user identity information, and transmit the updated user basic information to the supercomputing Internet for broadcasting. Wherein, the user identity information may include identity identification information and user basic information.
[0103] In some embodiments, the data update module 630 may perform a preset shared data type definition on the updated user basic information according to the user-predefined user information sharing range; and perform a preset broadcast operation on the updated user basic information according to the defined shared data type.
[0104] In this embodiment, the cross-domain multi-system data processing system based on the supercomputing Internet of the present application can, in the scenario of cross-system user access, implement proximity issuance of access tokens through a platform at the network edge such as a community platform, replacing the single issuance mode of the traditional centralized authentication server, forming a decentralized mutual trust mechanism. Each edge node independently completes the token issuance and verification operations, avoiding the repeated dependence on the centralized authentication server in the traditional solution during cross-domain requests, and significantly improving the data processing efficiency between multiple systems; by standardizing the token format and unified signature verification rules, solving the problem of identity mutual recognition failure caused by protocol differences between heterogeneous systems, ensuring the reliability and security of cross-platform access; at the same time, utilizing the parallel computing power of the supercomputing Internet to achieve low-latency and high-concurrency trust transfer during the token generation and verification process, enabling users to seamlessly access multiple systems without repeated login, effectively improving the cross-domain operation experience, and ensuring the consistency of user data status between multiple platforms and the stability of system collaborative operation.
[0105] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated herein.
[0106] Figure 8 is a schematic structural diagram of an electronic device shown in the embodiments of the present application.
[0107] See Figure 8 , the electronic device 1000 includes a memory 1010 and a processor 1020.
[0108] The processor 1020 can be a Central Processing Unit (CPU), or it can also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field-Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The memory 1010 can include various types of storage units, such as system memory, read-only memory (ROM), and permanent storage devices. Among them, the ROM can store static data or instructions required by the processor 1020 or other modules of the computer. The permanent storage device can be a readable and writable storage device. The permanent storage device can be a non-volatile storage device that does not lose the stored instructions and data even when the computer is powered off.
[0109] In some embodiments, the permanent storage device uses a mass storage device (such as a magnetic disk or optical disc, flash memory) as the permanent storage device. In some other embodiments, the permanent storage device can be a removable storage device (such as a floppy disk, optical drive). The system memory can be a readable and writable storage device or a volatile readable and writable storage device, such as dynamic random access memory. The system memory can store some or all of the instructions and data required by the processor during operation. In addition, the memory 1010 can include any combination of computer-readable storage media, including various types of semiconductor storage chips (such as DRAM, SRAM, SDRAM, flash memory, programmable read-only memory), and magnetic disks and / or optical discs can also be used.
[0110] In some embodiments, the memory 1010 can include a removable storage device that is readable and / or writable, such as a compact disc (CD), read-only digital versatile disc (such as DVD-ROM, dual-layer DVD-ROM), read-only Blu-ray disc, super density disc, flash memory card (such as SD card, min SD card, Micro-SD card, etc.), magnetic floppy disk, etc. The computer-readable storage medium does not include carrier waves and instantaneous electronic signals transmitted wirelessly or by wire.
[0111] Executable code is stored on the memory 1010, and when the executable code is processed by the processor 1020, it can cause the processor 1020 to execute some or all of the methods described above.
[0112] In addition, the method according to the present application can also be implemented as a computer program or a computer program product, which includes computer program code instructions for performing some or all of the steps in the above-mentioned method of the present application.
[0113] Alternatively, the present application can also be implemented as a computer-readable storage medium (or a non-transitory machine-readable storage medium or a machine-readable storage medium), on which executable code (or a computer program or computer instruction code) is stored. When executed by a processor of an electronic device (or a server, etc.), the processor is caused to execute some or all of the steps of the above-mentioned method according to the present application.
[0114] The present application also provides a computer program product, the computer program product includes computer instructions, and when the computer instructions are executed by a processor, the above-mentioned method is implemented.
[0115] The various embodiments of the present application have been described above. The above description is exemplary, not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations are obvious to those of ordinary skill in the art in the technical field without departing from the scope and spirit of the described embodiments. The selection of the terms used herein is intended to best explain the principles of the embodiments, the practical application, or the improvement of the technology in the market, or to enable other ordinary skill in the art in the technical field to understand the embodiments disclosed herein.
Claims
1. A data processing method between cross - domain multi - systems based on the supercomputing Internet, characterized in that, Applied to the current service system, where the current service system and the target service system are connected to the same supercomputing Internet, including: In response to an access request initiated by a user to the target service system after logging in to the current service system, obtain the user identity information from the corresponding supercomputing Internet node; Generate first token information in a preset format according to the user identity information, output the first token information to the target service system, and the target service system performs signature verification according to a preset public key.
2. The method according to claim 1, characterized in that, The generating first token information in a preset format according to the user identity information includes: Extract the identity identification information in the user identity information, and generate first token information according to the identity identification information and a first preset validity period.
3. The method according to claim 2, characterized in that, The method further includes: Generate second token information that matches the first token information according to the first token information and a second preset validity period; wherein, the second preset validity period is greater than the first preset validity period; After detecting that the first token information fails within the second preset validity period, refresh the first token information according to the second token information.
4. The method according to claim 1, characterized in that The user identity information is generated by the following method, including: In response to a user registration request, call the registration page; Receive the registration information input by the user on the registration page, generate user identity information according to the registration information, and synchronize it to the corresponding supercomputing Internet node after encryption by distributed storage; wherein, the user identity information at least includes: identity identification information and user basic information.
5. The method according to claim 1, wherein The method further includes: When detecting an update of the user basic information, trigger a preset broadcast event mechanism, and transmit the updated user basic information to the supercomputing Internet for broadcasting.
6. The method according to claim 5, wherein The transmitting the updated user basic information to the supercomputing Internet for broadcasting includes: Perform a preset shared data type definition on the updated user basic information according to the user preset user information sharing scope; Perform a preset broadcast operation on the updated user basic information according to the defined shared data type.
7. A data processing system between cross-domain multiple systems based on the supercomputing Internet, which is applied to the current service system, where the current service system and the target service system are connected to the same supercomputing Internet, and is characterized in that, Including: A request response module, configured to, in response to an access request initiated by a user to the target service system after logging in to the current service system, obtain the user identity information from the corresponding supercomputing Internet node; A token generation module, configured to generate first token information in a preset format according to the user identity information, and output the first token information to the target service system for signature verification.
8. The system according to claim 7, wherein The system further includes: A data update module, configured to, when detecting an update of the user identity information, trigger a preset broadcast event mechanism, and transmit the updated user basic information to the supercomputing Internet for broadcasting.
9. An electronic device, characterized in that, Including: A processor; And A memory, on which executable code is stored, and when the executable code is executed by the processor, the processor is caused to execute the method according to any one of claims 1-6.
10. A computer-readable storage medium, on which executable code is stored, and when the executable code is executed by a processor of an electronic device, the processor is caused to execute the method according to any one of claims 1-6.
Citation Information
Cited By
Permission data management method, device and system, medium, equipment and product
CN121530703A