Dynamic strategy control method and device for data query interface and computer equipment

By introducing SpringCloud Gateway and dynamic policy control mechanism, the problem of inflexible policy control in the data query interface management system is solved, and efficient and secure interface management is achieved to adapt to changing enterprise needs.

CN120281515APending Publication Date: 2025-07-08HANGZHOU BREEZE ENTERPRISE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510335634.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-20
Publication Date
2025-07-08

AI Technical Summary

Technical Problem

The existing data query interface management system has inflexible policy control and is difficult to adapt to complex and changing business needs of enterprises, and lacks a centralized management platform, resulting in insecurity and management efficiency.

Method used

SpringCloud Gateway is used as the gateway system, and by initializing the service routing and interface control policy configuration, the control policy is accurately matched and executed in predefined order, request forwarding is performed based on interface path matching rules and routing tables, and request traces are recorded.

Benefits of technology

It improves the flexibility and security of the data query interface, realizes efficient policy management, reduces system coupling, simplifies the development process, reduces costs, and provides global monitoring capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120281515A_ABST
    Figure CN120281515A_ABST
Patent Text Reader

Abstract

The invention discloses a dynamic strategy control method and device for a data query interface and computer equipment. The method comprises the following steps: initializing a gateway system, and loading the configuration of a service route and the configuration of an interface control strategy; obtaining an external request, and analyzing the external request to obtain an analysis result; executing the interface control strategy according to the analysis result to obtain an execution result; when the execution result is that all policies pass verification, forwarding the external request to a target service system according to the configuration of the service route, so that the target service system performs corresponding processing to generate a response result; and receiving a response result fed back by the target service system, forwarding the response result to the external request initiating end, and recording a request trace. By implementing the method provided by the invention, the defects in the existing data query interface and the management system thereof can be overcome, a more flexible and efficient strategy management mechanism is introduced, and the security and management efficiency of the data query interface are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer networks, and more specifically to a dynamic policy control method, device, and computer device for a data query interface. Background Art

[0002] In a modern enterprise application environment, a data query interface plays an important role in connecting front-end user requests and back-end data resources. However, there are many deficiencies in the traditional management and control methods of data query interfaces. In traditional methods, the control of query policies is usually embedded in the specific data query interface implementations under each service. For example, when performing a query operation, functions such as identity authentication, billing processing, and whitelist access restrictions are directly integrated into the interface logic. Although this approach can meet basic security and management requirements, it greatly limits the flexibility and scalability of policy control. With the development of business and the progress of technology, when existing policies need to be adjusted or new policies need to be added, it often involves modifying the original code, which not only increases development costs but also may introduce additional risks, affecting the stability and security of the system.

[0003] The current data query interface management system shows a decentralized characteristic. Each system service has implemented its own policy control mechanism independently and has not formed a centralized management platform. Such an architecture results in the existence of multiple independent data query outlets, making it extremely difficult to deploy global policies. At the same time, since the data query record statistics function is also distributed within each system, it faces high complexity in collecting and summarizing this information, thereby increasing the overall operating cost. For managers, the lack of a unified perspective to monitor all data query activities also causes great inconvenience. Different system services define their externally provided data query interface parameters and response formats by themselves, resulting in inconsistent interface standards throughout the organization. This phenomenon not only reduces the cooperation efficiency between departments but also brings unnecessary trouble to external partners. Especially when facing the need for interconnection of a large number of heterogeneous systems, non-standard interface design will undoubtedly become one of the key factors hindering interoperability and user experience improvement. Although existing gateway systems have solved some of the above problems to a certain extent, they still have obvious limitations. Existing gateways usually adopt a one-size-fits-all approach to policy control, that is, either the same type of control measures such as unified identity authentication are implemented for all request interfaces, or classification control is performed according to the interface type. However, this mode cannot be accurately configured at the individual interface level for personalization and is difficult to adapt to the complex and changeable enterprise business requirements. Especially in the face of the need for differential security policies and service quality assurance, existing gateway solutions are inadequate.

[0004] Therefore, it is necessary to design a new method to overcome the defects existing in the existing data query interface and its management system, and introduce a more flexible and efficient policy management mechanism to improve the security and management efficiency of the data query interface. Summary of the Invention

[0005] The purpose of the present invention is to overcome the defects of the prior art and provide a dynamic policy control method, device, and computer device for a data query interface.

[0006] To achieve the above purpose, the present invention adopts the following technical solutions: A dynamic policy control method for a data query interface includes:

[0007] Initialize the gateway system and load the configurations of service routing and interface control policies.

[0008] Obtain an external request and perform external request parsing to obtain a parsing result.

[0009] Execute the interface control policy according to the parsing result to obtain an execution result.

[0010] When the execution result is that all policies are verified and passed, forward the external request to the target business system according to the configuration of service routing, so that the target business system performs corresponding processing to generate a response result.

[0011] Receive the response result feedback by the target business system, forward it to the external request initiator, and record the request trace.

[0012] A further technical solution thereof is: The initialization of the gateway system and the loading of the configurations of service routing and interface control policies include:

[0013] Use SpringCloud Gateway as the gateway central system, initialize and load the configuration of service routing, and configure corresponding control policies for each interface, including authentication and IP whitelist verification, and store the affiliated configurations in the routing configuration library and the policy configuration library.

[0014] A further technical solution thereof is: The obtaining of the external request and the performing of external request parsing to obtain a parsing result include:

[0015] Obtain an external request, where the external request includes the target interface address.

[0016] Parse the interface path address of the external request and obtain the control policy list corresponding to the interface path address from the policy configuration library to obtain a parsing result.

[0017] A further technical solution thereof is: executing an interface control policy according to the parsing result to obtain an execution result, including:

[0018] Executing each control policy in the parsing result one by one according to a predefined order to obtain an execution result.

[0019] A further technical solution thereof is: executing each control policy in the parsing result one by one according to a predefined order to obtain an execution result, including:

[0020] Identifying the implementation class of each control policy in the parsing result through the policy code identifier, and executing the corresponding implementation class in a hierarchical manner to obtain an execution result; wherein, the implementation class includes identity verification and IP white list verification.

[0021] A further technical solution thereof is: the hierarchical manner includes executing in the order of a common layer, a logic layer, an external interface call layer, and a parameter processing layer. The common layer is used to process common tasks; the logic layer is used to process specific business logics; the external interface call layer interacts with an external system; and the parameter processing layer is used to transfer and format parameters.

[0022] A further technical solution thereof is: when the execution result is that all policies are verified to pass, forwarding the external request to a target business system according to the configuration of service routing, so that the target business system performs corresponding processing to generate a response result, including:

[0023] When the execution result is that all policies are verified to pass, obtaining a routing forwarding rule according to the interface path matching rule;

[0024] Determining the address of the target business system service through the configured routing table, and forwarding the external request to the corresponding target business system by using the routing forwarding rule. Among them, when forwarding, according to the parameters passed in the configuration, including identity ID, institution ID, and billing product ID, and performing transparent transmission.

[0025] A further technical solution thereof is: receiving the response result fed back by the target business system, forwarding it to the external request initiator, and recording the request trace, including:

[0026] Receiving the response result fed back by the target business system, forwarding it to the external request initiator, and recording the relevant log information of all requests, including the request URL, request headers, request body, and response data, to form a request trace.

[0027] The present invention also provides a dynamic policy control device for a data query interface, including:

[0028] An initialization and loading unit, configured to initialize the gateway system and load the configurations of service routing and interface control policies;

[0029] A parsing unit, configured to obtain an external request and perform external request parsing to obtain a parsing result;

[0030] An execution unit, configured to execute the interface control policy according to the parsing result to obtain an execution result;

[0031] A forwarding unit, configured to, when the execution result indicates that all policies are verified and passed, forward the external request to the target business system according to the configuration of service routing, so that the target business system performs corresponding processing to generate a response result;

[0032] A receiving unit, configured to receive the response result fed back by the target business system, forward it to the external request initiator, and record the request trace.

[0033] The present invention also provides a computer device, which includes a memory and a processor. A computer program is stored on the memory, and when the processor executes the computer program, the above method is implemented.

[0034] The beneficial effects of the present invention compared with the prior art are as follows: By introducing a dynamic policy control mechanism, the present invention improves the flexibility and security of data query interfaces. First, SpringCloud Gateway is used as the gateway system to achieve the configuration and dynamic loading of service routing and interface control policies. Second, through the parsing of external requests, the corresponding control policies are accurately matched and executed in a predefined order to ensure the step-by-step verification of the policies. Based on the interface path matching rules and the routing table, the requests are accurately forwarded to the target business system, improving the forwarding efficiency. The fed-back response results are recorded through logs to ensure the traceability of the request traces. Finally, this method can effectively avoid the rigidity problems of static configuration and policy management in traditional systems, making the interface control more flexible, efficient, and adaptable to changing requirements.

[0035] The present invention will be further described below with reference to the accompanying drawings and specific embodiments. Description of the Drawings

[0036] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings required for the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0037] Figure 1Schematic diagram of the application scenario of the dynamic policy control method for the data query interface provided by the embodiment of the present invention;

[0038] Figure 2 Schematic flow diagram of the dynamic policy control method for the data query interface provided by the embodiment of the present invention;

[0039] Figure 3 Schematic diagram of the sub - process of the dynamic policy control method for the data query interface provided by the embodiment of the present invention Figure 1 ;

[0040] Figure 4 Schematic diagram of the sub - process of the dynamic policy control method for the data query interface provided by the embodiment of the present invention Figure 2 ;

[0041] Figure 5 Schematic diagram of the policy pattern class provided by the embodiment of the present invention;

[0042] Figure 6 Schematic diagram of the hierarchical execution mode of the policy provided by the embodiment of the present invention;

[0043] Figure 7 Schematic block diagram of the dynamic policy control device for the data query interface provided by the embodiment of the present invention;

[0044] Figure 8 Schematic block diagram of the computer device provided by the embodiment of the present invention. Detailed implementation manners

[0045] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0046] It should be understood that when used in this specification and the appended claims, the terms "comprises" and "comprising" indicate the presence of the described features, wholes, steps, operations, elements, and / or components, but do not preclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.

[0047] It should also be understood that the terms used in this specification of the present invention are only for the purpose of describing specific embodiments and are not intended to limit the present invention. As used in this specification of the present invention and the appended claims, unless the context clearly indicates otherwise, the singular forms "a", "an" and "the" are intended to include the plural forms.

[0048] It should also be further understood that the term "and / or" used in the specification and appended claims of the present invention refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.

[0049] Please refer to Figure 1 and Figure 2 , Figure 1 which is a schematic diagram of the application scenario of the dynamic policy control method for the data query interface provided by the embodiment of the present invention. Figure 2 which is a schematic flowchart of the dynamic policy control method for the data query interface provided by the embodiment of the present invention. The dynamic policy control method for the data query interface is applied to a gateway system, which conducts data interaction with an external request initiator and a service system. Herein, the service system refers to the target service system, such as Figure 1 shown, the configuration of service routing and the configuration of interface control policies are carried out in sequence to form an interface configuration policy library and a server routing configuration table. Among them, the interface configuration policy library includes interface information, identity verification, whitelist verification, order verification, billing processing control, etc., and the service routing configuration table includes a routing ID, a forwarding address, a routing basis, pass-through parameters, and a priority. After initialization and loading are completed, an external request is obtained. After an interface query request and the acquisition of interface policy configuration, the Strategy mode is used for control, and the policies are executed in sequence and processed in a policy hierarchy. When the policy verification or execution is successful, the interface forwarding route is obtained, and the external request is forwarded to the service system service. After being processed by the distributed microservices in the service system service, the result is fed back to the gateway system, and the gateway system responds to the queried result and records the request trace, which can be recorded in the log library, so as to overcome the defects existing in the existing data query interface and its management system, and introduce a more flexible and efficient policy management mechanism to improve the security and management efficiency of the data query interface.

[0050] Figure 2 which is a schematic flowchart of the dynamic policy control method for the data query interface provided by the embodiment of the present invention. As Figure 2 shown, the method includes the following steps S110 to S150.

[0051] S110. Initialize the gateway system and load the configuration of service routing and the configuration of interface control policies.

[0052] In this embodiment, service routing configuration refers to a set of rules that define how to forward received external requests to specific internal business system services. These rules include, but are not limited to, the URL address of the target service, routing judgment conditions (i.e., predicates), the parameter list (metadata) passed to the downstream service, and the order attribute that determines the routing priority. Service routing configuration is usually set through YML files, which makes the configuration more intuitive and easy to understand, manage, and maintain.

[0053] Interface control policy configuration refers to a series of verification and execution policies set for each specific service interface. These policies are designed to ensure the security and compliance of the interface, and can also implement functions such as pre-billing verification. The policy configuration is described in JSON format and contains key information such as strategy code, strategy name, and execution order. In addition, each interface has a unique identifier ID, interface name (api_name), interface URL address (api_url), and the type of business product it belongs to (product_type).

[0054] Specifically, use SpringCloud Gateway as the gateway central system to initialize and load the service routing configuration, and configure the corresponding control policies for each interface, including authentication and IP white list verification, and store the affiliated configuration in the routing configuration library and the policy configuration library.

[0055] Specifically, the core configuration information of the interface policy rules is shown in Table 1, and the service routing configuration information is shown in Table 2.

[0056] Table 1. Core Configuration Information of Interface Policy Rules

[0057]

[0058] During the startup process, the gateway system will also read these policy configurations to build a globally available policy library. Whenever a new request arrives, the gateway will retrieve the list of policies related to the current request from this policy library and execute them in the established order. If all policies can pass successfully, the request is allowed to continue; otherwise, an error response is immediately returned.

[0059] Table 2. Service Routing Configuration Information

[0060]

[0061]

[0062] When the gateway system starts, it reads a predefined service routing configuration file (such as in YML format), parses the content therein, and converts it into an internal data structure for storage. The purpose of doing this is to quickly find the matching service routing rules based on the request characteristics when receiving an actual request, so as to accurately forward the request to the correct backend service.

[0063] In summary, during the initialization phase of the gateway system, the loading of service routing configuration and service interface control policy configuration must be completed. The former determines where the request should be sent, while the latter stipulates what checks and processing need to be done to the request before forwarding. The two work together to ensure that the gateway can correctly distribute the request to the corresponding backend service on the premise of security and efficiency.

[0064] S120, Obtain an external request and perform external request parsing to obtain a parsing result.

[0065] In this embodiment, the parsing result mainly includes:

[0066] Interface path address: That is, the path of the specific service or API that the request attempts to access.

[0067] Control policy list: A set or multiple sets of control policies found from the policy configuration library according to the interface path address. These policies stipulate all the conditions that the request must meet or all the processing steps that the request must go through before being forwarded to the final target service.

[0068] In one embodiment, please refer to Figure 3 , the above step S120 may include steps S121 to S122.

[0069] S121, Obtain an external request, where the external request includes a target interface address.

[0070] In this embodiment, the gateway system receives an external request from a client. This request contains all the information required to access a specific interface, and the most core part is the target interface address. The target interface address usually consists of a protocol (such as HTTP or HTTPS), a domain name or IP address, and a specific URL path, which indicates which API or service the request wants to call.

[0071] S122, Parse the interface path address of the external request and obtain the control policy list corresponding to the interface path address from the policy configuration library to obtain a parsing result.

[0072] In this embodiment, in step S122, the gateway further parses the obtained external request, especially to parse out its interface path address. The interface path address refers to the part of the URL after removing the domain name / IP and port number, and this part directly points to a specific service or function point in the backend. By parsing this path, the gateway can clearly know what specific resource the request intends to access.

[0073] Then, based on the parsed interface path address, the gateway will query the pre-constructed policy configuration library to retrieve a series of control policies that match the interface path. These policies may include but are not limited to authentication, permission checking, traffic limitation, etc., and they together constitute the so-called control policy list. Each policy defines a set of rules for guiding how the gateway processes the upcoming request.

[0074] The role of the parsing result is to provide necessary guidance for subsequent request processing. For example, it can help the gateway determine whether to allow the request to proceed, or whether certain pre-operations need to be performed first (such as authenticating the user's identity, checking the IP whitelist, etc.). In addition, the parsing result can also affect the request routing - that is, determining which specific backend service instance the request should be sent to for processing.

[0075] In summary, the parsing result not only clarifies the target location of the request, but also provides all the instructions required to achieve secure and compliant access, thus ensuring that the entire system can maintain a high level of security while operating efficiently.

[0076] S130. Execute the interface control policy according to the parsing result to obtain an execution result.

[0077] In this embodiment, the execution result refers to the result of whether the policy verification is successful.

[0078] Specifically, each control policy in the parsing result is executed one by one in a predefined order to obtain an execution result.

[0079] Identify the implementation class of each control policy in the parsing result through the policy code, and execute the corresponding implementation class in a hierarchical manner to obtain an execution result; among them, the implementation class includes identity verification and IP whitelist verification.

[0080] The hierarchical manner includes executing in the order of the common layer, the logic layer, the external interface call layer, and the parameter processing layer. The common layer is used to process common tasks; the logic layer is used to process specific business logics; the external interface call layer interacts with external systems; the parameter processing layer is used to transfer and format parameters.

[0081] In this embodiment, when a query interface request is received, it first needs to go through a parsing stage to determine which interface control policies are applicable to the request. Next, it enters step S130, that is, to execute the interface control policy according to the parsing result, so as to obtain the execution result. The execution result here specifically refers to the determination of whether the verification of each control policy is successful.

[0082] Execution in predefined order: For each control policy in the parsing result, the system will execute them one by one in the predefined order (i.e., the order attribute). This means that some policies may be executed prior to others, depending on their priority settings.

[0083] Policy matching and implementation class invocation: Through the policy code identifier, the system can accurately match to the corresponding policy implementation class. For example, for identity authentication and IP whitelist verification, there will be specific implementation classes to handle these functions. Once the matching is successful, the system will execute these implementation classes in a hierarchical manner.

[0084] Execution in a hierarchical manner: As mentioned above, policy processing is divided into four main levels - the common layer, the logic layer, the external interface call layer, and the parameter processing layer. Each layer has its specific tasks:

[0085] Common layer: Responsible for handling tasks shared by all policies, such as initialization or general preprocessing work.

[0086] Logic layer: This is where the core business logic lies. Here, specific business rules will be processed, such as verifying the user's identity or checking whether the IP address is in the whitelist.

[0087] External interface call layer: If it is necessary to interact with other services or databases, this part will be responsible for initiating requests and obtaining the necessary information.

[0088] Parameter processing layer: Finally, at this level, the system will assemble and format the data to be passed to the next layer or returned to the client.

[0089] This hierarchical design ensures the clarity and modularity of policy execution. At the same time, it also improves the maintainability and extensibility of the system. Whenever new requirements or changes occur, developers can more easily add new policies or adjust existing policies without affecting other parts of the system. In addition, such a design also separates policy control from the actual business logic, further reducing the coupling degree and enhancing the flexibility and security of the system.

[0090] To sum up, step S130 is not only a simple policy execution process, but also an important mechanism to ensure the safe and reliable operation of the gateway system through a carefully designed mode and structure.

[0091] In this embodiment, the policy execution control module in the gateway system is a key component that ensures that query interface requests are processed and verified according to the current interface control policy during access. The design of this module aims to provide a flexible, scalable, and easy-to-maintain mechanism to execute different policies, ensuring that only requests that have been properly verified and authorized can continue to be processed.

[0092] The Strategy design pattern is adopted. This is a behavioral design pattern that allows a series of algorithms (or strategies) to be defined, each algorithm encapsulated, and they can be used interchangeably. In this way, the policy execution control module can match the corresponding policy implementation class according to a specific policy code, and thus execute the corresponding logic. As Figure 5 shown, FilterContext: As a policy encapsulation class, it is the entry point for external access. When a new request arrives, FilterContext is responsible for receiving these requests and coordinating the execution of each policy.

[0093] ControlFilter: This is an abstract interface that defines the methods that all specific policies must implement and the shared common attributes. This provides a unified interface standard for specific policy implementations.

[0094] Specific policy implementation classes: For example, CheckAuthControlFilter is used for identity authentication, and CheckIPControlFilter is used for IP whitelist verification, etc. These classes implement the ControlFilter interface and provide specific policy processing logic. Each policy has its own order attribute, which determines its execution order; at the same time, the code is the only identifier to distinguish different policies and directly corresponds to the identifier in the interface policy configuration.

[0095] To further optimize the policy execution process, this module also adopts a hierarchical processing method, which is divided into four main levels, as Figure 6 shown, including:

[0096] Common layer: Processes general tasks applicable to all policies, such as initialization, resource allocation, etc.

[0097] Logic layer: Focuses on specific business logic processing, such as user identity authentication or IP address checking.

[0098] External interface call layer: Responsible for interacting with external systems, possibly to obtain additional data or perform certain operations.

[0099] Parameter processing layer: Processes the assembly and formatting of parameters to ensure that data is passed to the next processing stage or returned to the client in the correct form.

[0100] This hierarchical structure not only makes the program clearer and easier to understand, but also has distinct responsibilities, which helps improve the readability and maintainability of the code. In addition, due to the fewer dependencies between layers, the flexibility and adaptability of the system are also enhanced.

[0101] Currently, the gateway system supports various types of policy controls, including but not limited to:

[0102] Identity authentication; Request IP whitelist verification; Order number verification; Billing pre-verification; Query data billing processing;

[0103] These policy control measures are automatically managed by the gateway system, and developers do not need to care about their implementation details, thus reducing the coupling with the business logic. The benefit of this is that developers can focus more on business development and leave the consideration of security and compliance to the gateway system to handle.

[0104] In summary, the policy execution control module of the gateway system provides a powerful and flexible way to manage and execute various interface access control policies by combining the Strategy design pattern and the hierarchical processing method, ensuring the security, stability, and efficiency of the system.

[0105] S140. When the execution result is that all policies are verified and passed, forward the external request to the target business system according to the service routing configuration, so that the target business system performs corresponding processing to generate a response result.

[0106] In this embodiment, a routing and forwarding method based on policy verification is provided for the gateway system to process requests from the outside. This method ensures that only requests that pass all the predefined policy verifications will be correctly forwarded to the corresponding target business system, and finally the response result of the business system is returned to the original request initiator. This process also includes recording detailed request traces for subsequent log management and monitoring.

[0107] When all the policy verifications are successfully passed (i.e., the execution result is "all policies are verified and passed"), the gateway system will forward the external request to the target business system according to the service routing configuration for corresponding business logic processing and generating a response result.

[0108] In one embodiment, please refer to Figure 4 , the above step S140 may include steps S141 to S142.

[0109] S141. When the execution result is that all policies are verified and passed, obtain the routing and forwarding rule according to the interface path matching rule.

[0110] In this embodiment, according to the interface path matching rule, a routing forwarding rule applicable to the current request is retrieved from a predefined routing rule set. This step ensures that each request can accurately find its corresponding target business system.

[0111] S142. Determine the address of the target business system service through the configured routing table, and forward the external request to the corresponding target business system by using the routing forwarding rule. When forwarding, according to the parameters passed in the configuration, including the identity ID, institution ID, and billing product ID, and perform transparent transmission.

[0112] In this embodiment, the obtained routing table is used to determine the specific network address of the target business system service. On this basis, the gateway system forwards the external request together with the necessary context information (such as identity ID, institution ID, billing product ID, etc.) to the corresponding business system. These additional information is passed to the target business system in the way of HTTP Header or Request Body, thereby reducing the need for the business system to process the same information twice.

[0113] Based on the service routing table, the query data request is accurately forwarded to the corresponding business system service, and the response result can be processed and returned. This process not only involves simple address mapping, but also includes passing the necessary context information (such as the current identity ID, institution ID, billing product ID, etc.) during the forwarding process. These information are transparently transmitted to the target business system through HTTP Header or Request Body, reducing the need for secondary processing on the business system side.

[0114] S150. Receive the response result feedback by the target business system, forward it to the external request initiator, and record the request trace.

[0115] In this embodiment, receive the response result feedback by the target business system, forward it to the external request initiator, and record the relevant log information of all requests, including the request URL, request headers, request body, and response data, to form a request trace.

[0116] Record the log information of all query requests passing through the gateway system. This includes but is not limited to the request URL, Header, Request Body, and the response result Response. The log information is very important for unified management and monitoring. They can help identify problems, optimize performance, audit access behaviors, and provide a basis for troubleshooting.

[0117] Once the target business system has completed processing the request and returned the response result, the gateway system is responsible for receiving the response and forwarding it back to the original request initiator. Meanwhile, the gateway also records all relevant log information of this interaction, including but not limited to the request URL, request headers, request body, and response data. These log information is of great significance for unified management, performance optimization, access behavior auditing, and troubleshooting.

[0118] Through the above steps, the method of this embodiment realizes an efficient and secure request routing and response processing mechanism, and at the same time provides a detailed logging function, enhancing the traceability and maintainability of the system.

[0119] In this embodiment, SpringCloud Gateway is adopted as the core of the gateway technology, providing powerful function support and service governance capabilities. It enables the efficient implementation of functions such as gateway service routing mapping for query data requests, filter configuration, and routing forwarding. In this way, any service provider for query requests only needs to provide its service address and parameter requirements to seamlessly access the gateway, simplifying the integration process.

[0120] The gateway uniformly processes all incoming requests and uses hierarchical filter technology to verify and preprocess the requests. Such a design ensures that only properly verified requests can be routed to the corresponding business system services. This mode improves security and at the same time reduces the burden on each business system to implement these functions by itself. Finally, the gateway is responsible for collecting and returning the query results to the client, ensuring the consistency and reliability of the response.

[0121] The dynamic policy control technology allows each interface to independently configure and manage its own access control policies. This means that the data interface provider only needs to simply configure the interface address, the affiliated product, the required verification / control policy list, and the IP whitelist for restricted access, etc., to meet the requirements of fine-grained access control and billing processing for the interface. The dynamic configuration feature means that these policies can take effect in real time without restarting the service, enhancing flexibility and response speed.

[0122] In the specific implementation, the easy-to-expand Strategy design pattern is adopted to build the policy control mechanism. When adding a new policy, only the corresponding program implementation needs to be added without modifying the existing code. In addition, a hierarchical processing mechanism is introduced to enable each type of policy to perform its duties within a specific layer, avoiding interference between different logics.

[0123] To ensure the uniqueness and traceability of policies, a unique code is assigned to each type of policy. This code is used as an identifier during the configuration phase and is also relied upon by the gateway to determine the specific set of policies to be executed when the gateway enforces policies.

[0124] In summary, by combining the above technologies and design patterns, the gateway system not only achieves efficient routing and forwarding and comprehensive logging but also provides a flexible, secure, and easily maintainable dynamic policy control system, greatly enhancing the functionality and usability of the gateway.

[0125] The method of this embodiment realizes the separation of the business system and policy control by stripping the policy control of the query data interface from the business logic and centralizing it in the gateway system. This design not only reduces the coupling degree of the system but also enhances the robustness and stability of the program. The business system can now focus on the implementation of its core functions without worrying about changes or complexities in the policy logic. In addition, due to the independence of the policy logic, when adjustments or expansions are needed, only the gateway part needs to be modified, without affecting the business logic code, thus simplifying the maintenance work.

[0126] In the traditional solution, any policy change usually requires modifying the program code and may involve redeploying the application. In this embodiment, however, the policy control is managed by the gateway system, which means that policies can be added, removed, or updated through simple configuration changes without modifying the underlying code. This enables policy adjustments to take effect in real time, greatly improving the response speed and service flexibility to adapt to rapidly changing business requirements.

[0127] After the policy control is transformed from decentralized management in each business system to unified processing by the gateway system, business developers no longer need to repeatedly implement the same or similar policy control logic in each project. This not only reduces duplicate labor but also avoids potential problems caused by differences in implementation methods among different developers. At the same time, the clear division of responsibilities (i.e., policy control is the responsibility of a dedicated team) also reduces cross-team communication costs and technical debt, further reducing the development difficulty and overall cost.

[0128] By adopting the technology of this embodiment, the management can obtain a comprehensive view of all product interfaces of the company, facilitating unified supervision, comprehensive statistics, and auditing. This feature helps ensure that data usage within the company complies with regulatory requirements and supports more efficient resource planning and decision-making. In addition, the centralized management platform simplifies the interface configuration and permission management processes, improving work efficiency.

[0129] In this embodiment, the core of the method lies in that it provides a brand-new idea to solve the problems of centralized management and output of data query interfaces. By introducing a gateway as an intermediate layer, all external requests first pass through the gateway and are accurately distributed to the corresponding business services according to the pre-set service routing mapping rules. This method not only realizes the centralized management of data interfaces, but also provides flexible routing configuration options for each interface, including but not limited to exact path matching, fuzzy matching mechanism, and forwarding rules for specific parameters, etc.

[0130] This technical solution of service routing mapping and interface routing forwarding based on the gateway in this embodiment, especially the creation and management methods of the routing mapping relationship table involved. These elements together constitute a powerful and flexible routing management system, which can meet the diverse enterprise-level application requirements.

[0131] The dynamic policy control method allows users to customize and adjust access control policies according to the requirements of specific interfaces. Different from the traditional static or category-fixed policy settings, the method provided in this embodiment is a highly flexible policy management mechanism, which can make corresponding changes quickly according to the actual application scenarios. For example, through the cooperation of the configuration module and the control module, the administrator can easily define new policy rules and immediately apply them to the relevant interfaces. The control module adopts the Strategy pattern and the hierarchical processing method to ensure efficient policy control even in complex multi-condition judgment scenarios.

[0132] The relationship establishment of the interface control policy is realized through the configuration table, and the specific implementation details of the policy pattern and the hierarchical processing method used in the control module. These two together ensure the flexibility and real-time nature of policy control.

[0133] To sum up, the method of this embodiment has significant advantages in aspects such as reducing coupling degree, improving robustness, simplifying the development process, reducing costs, and providing stronger management capabilities.

[0134] The above-mentioned dynamic policy control method for data query interfaces improves the flexibility and security of data query interfaces by introducing a dynamic policy control mechanism. First, SpringCloud Gateway is used as the gateway system to realize the configuration and dynamic loading of service routing and interface control policies. Second, through the parsing of external requests, the corresponding control policies are accurately matched and executed in the predefined order to ensure the verification of each policy one by one. Based on the interface path matching rules and the routing table, the requests are accurately forwarded to the target business system, improving the forwarding efficiency. The feedback response results are recorded through logs to ensure the traceability of request traces. Finally, this method can effectively avoid the rigid problems of static configuration and policy management in traditional systems, making the interface control more flexible, efficient and adaptable to changing requirements.

[0135] Figure 7 It is a schematic block diagram of a dynamic policy control device 300 for a data query interface provided by an embodiment of the present invention. As Figure 7 shown, corresponding to the above dynamic policy control method for a data query interface, the present invention also provides a dynamic policy control device 300 for a data query interface. The dynamic policy control device 300 for a data query interface includes units for executing the above dynamic policy control method for a data query interface, and this device can be configured in a server. Specifically, please refer to Figure 7 , the dynamic policy control device 300 for a data query interface includes an initialization and loading unit 301, a parsing unit 302, an execution unit 303, a forwarding unit 304, and a receiving unit 305.

[0136] The initialization and loading unit 301 is used to initialize the gateway system and load the configurations of service routes and interface control policies; the parsing unit 302 is used to obtain an external request and perform external request parsing to obtain a parsing result; the execution unit 303 is used to execute the interface control policy according to the parsing result to obtain an execution result; the forwarding unit 304 is used to, when the execution result is that all policies are verified and passed, forward the external request to the target business system according to the configuration of the service route, so that the target business system performs corresponding processing to generate a response result; the receiving unit 305 is used to receive the response result fed back by the target business system, forward it to the external request initiator, and record the request trace.

[0137] In one embodiment, the initialization and loading unit 301 is used to use SpringCloud Gateway as the gateway central system, initialize and load the configurations of service routes, and configure corresponding control policies for each interface, including authentication and IP whitelist verification, and store the affiliated configurations in a route configuration library and a policy configuration library.

[0138] In one embodiment, the parsing unit 302 includes:

[0139] A request acquisition subunit, which is used to acquire an external request, and the external request includes a target interface address; a parsing list acquisition subunit, which is used to parse the interface path address of the external request and acquire the control policy list corresponding to the interface path address from the policy configuration library to obtain a parsing result.

[0140] In one embodiment, the execution unit 303 is used to execute each control policy in the parsing result one by one in a predefined order to obtain an execution result.

[0141] In one embodiment, the execution unit 303 is configured to identify the implementation class of each control policy in the parsing result through policy code identification, and execute the corresponding implementation class in a hierarchical manner to obtain an execution result; wherein, the implementation class includes identity verification and IP whitelist verification.

[0142] In one embodiment, the forwarding unit 304 includes:

[0143] A rule acquisition subunit, configured to, when the execution result is that all policies are verified and passed, acquire a routing forwarding rule according to an interface path matching rule; a request forwarding subunit, configured to determine the address of the target business system service through a configured routing table, and forward the external request to the corresponding target business system by using the routing forwarding rule, wherein, when forwarding, parameters passed according to the configuration, including an identity ID, an organization ID, and a billing product ID, are transparently transmitted.

[0144] In one embodiment, the receiving unit 305 is configured to receive the response result fed back by the target business system, forward it to the external request initiator, and record relevant log information of all requests, including the URL, request headers, request body, and response data of the requests, so as to form a request trace.

[0145] It should be noted that those skilled in the art can clearly understand that the specific implementation processes of the above dynamic policy control device 300 for the data query interface and each unit can refer to the corresponding descriptions in the foregoing method embodiments. For the convenience and conciseness of description, they will not be elaborated herein.

[0146] The above dynamic policy control device 300 for the data query interface can be implemented in the form of a computer program, and this computer program can run on a computer device as shown in Figure 8 the following.

[0147] Please refer to Figure 8 , Figure 8 which is a schematic block diagram of a computer device provided by an embodiment of the present application. The computer device 500 can be a server, wherein the server can be an independent server or a server cluster composed of multiple servers.

[0148] Refer to Figure 8 , the computer device 500 includes a processor 502, a memory, and a network interface 505 connected through a system bus 501, wherein the memory can include a non-volatile storage medium 503 and an internal memory 504.

[0149] The non-volatile storage medium 503 can store an operating system 5031 and a computer program 5032. The computer program 5032 includes program instructions which, when executed, can cause the processor 502 to execute a dynamic policy control method for a data query interface.

[0150] The processor 502 is used to provide computing and control capabilities to support the operation of the entire computer device 500.

[0151] The internal memory 504 provides an environment for the operation of the computer program 5032 in the non-volatile storage medium 503. When the computer program 5032 is executed by the processor 502, it can cause the processor 502 to execute a dynamic policy control method for a data query interface.

[0152] The network interface 505 is used to communicate with other devices over a network. Those skilled in the art can understand that Figure 8 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device 500 to which the solution of this application is applied. The specific computer device 500 may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0153] Among them, the processor 502 is used to run the computer program 5032 stored in the memory to implement the following steps:

[0154] Initialize the gateway system, and load the configurations of service routing and interface control policies; obtain an external request and perform external request parsing to obtain a parsing result; execute the interface control policy according to the parsing result to obtain an execution result; when the execution result is that all policies are verified and passed, forward the external request to the target business system according to the configuration of service routing, so that the target business system performs corresponding processing to generate a response result; receive the response result fed back by the target business system, forward it to the external request initiator, and record the request trace.

[0155] In one embodiment, when the processor 502 implements the steps of initializing the gateway system and loading the configurations of service routing and interface control policies, the specific implementation steps are as follows:

[0156] Use SpringCloud Gateway as the gateway central system, initialize and load the configuration of service routing, and configure corresponding control policies for each interface, including authentication and IP whitelist verification, and store the affiliated configurations in the routing configuration library and the policy configuration library.

[0157] In one embodiment, when the processor 502 implements the step of obtaining an external request and parsing the external request to obtain a parsing result, the specific implementation is as follows:

[0158] Obtain an external request, where the external request includes a target interface address; parse the interface path address of the external request, and obtain a control policy list corresponding to the interface path address from the policy configuration library to obtain a parsing result.

[0159] In one embodiment, when the processor 502 implements the step of executing an interface control policy according to the parsing result to obtain an execution result, the specific implementation is as follows:

[0160] Execute each control policy in the parsing result one by one in a predefined order to obtain an execution result.

[0161] In one embodiment, when the processor 502 implements the step of executing each control policy in the parsing result one by one in a predefined order to obtain an execution result, the specific implementation is as follows:

[0162] Match the implementation class of each control policy in the parsing result through a policy code identifier, and execute the corresponding implementation class in a hierarchical manner to obtain an execution result; where the implementation class includes identity verification and IP white list verification.

[0163] Among them, the hierarchical manner includes executing in the order of a common layer, a logic layer, an external interface call layer, and a parameter processing layer. The common layer is used to process common tasks; the logic layer is used to process specific business logics; the external interface call layer interacts with an external system; the parameter processing layer is used to transfer and format parameters.

[0164] In one embodiment, when the processor 502 implements the step of when the execution result is that all policies are verified to pass, forwarding the external request to a target business system according to the configuration of service routing, so that the target business system performs corresponding processing to generate a response result, the specific implementation is as follows:

[0165] When the execution result is that all policies are verified to pass, obtain a routing forwarding rule according to an interface path matching rule; determine the address of the target business system service through a configured routing table, and forward the external request to the corresponding target business system by using the routing forwarding rule. Among them, when forwarding, according to the parameters passed in the configuration, including an identity ID, an organization ID, and a billing product ID, and perform pass-through.

[0166] In one embodiment, when the processor 502 implements the step of receiving the response result fed back by the target service system, forwarding it to the external request initiator, and recording the request trace, the specific implementation is as follows:

[0167] Receive the response result fed back by the target service system, forward it to the external request initiator, and record the relevant log information of all requests, including the request URL, request headers, request body, and response data, to form a request trace.

[0168] It should be understood that in the embodiments of the present application, the processor 502 may be a central processing unit (CPU), and the processor 502 may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. Among them, the general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc.

[0169] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program includes program instructions, and the computer program can be stored in a storage medium, and the storage medium is a computer-readable storage medium. The program instructions are executed by at least one processor in the computer system to implement the process steps of the embodiments of the above methods.

[0170] Therefore, the present invention also provides a storage medium. The storage medium may be a computer-readable storage medium. The storage medium stores a computer program, and when the computer program is executed by a processor, the processor is caused to execute the following steps:

[0171] Initialize the gateway system, and load the configurations of service routing and interface control policies; obtain an external request, and perform external request parsing to obtain a parsing result; execute the interface control policy according to the parsing result to obtain an execution result; when the execution result is that all policies are verified to pass, forward the external request to the target service system according to the configuration of service routing for corresponding processing by the target service system to generate a response result; receive the response result fed back by the target service system, forward it to the external request initiator, and record the request trace.

[0172] In one embodiment, when the processor executes the computer program to implement the initialization of the gateway system and load the configurations of service routing and interface control policies, the following specific steps are implemented:

[0173] Use SpringCloud Gateway as the gateway central system, initialize and load the configurations of service routing, and configure corresponding control policies for each interface, including authentication and IP whitelist verification, and store the affiliated configurations in the routing configuration library and the policy configuration library.

[0174] In one embodiment, when the processor executes the computer program to implement the acquisition of an external request and perform external request parsing to obtain a parsing result, the following specific steps are implemented:

[0175] Acquire an external request, where the external request includes a target interface address; parse the interface path address of the external request, and obtain the list of control policies corresponding to the interface path address from the policy configuration library to obtain a parsing result.

[0176] In one embodiment, when the processor executes the computer program to implement the execution of interface control policies based on the parsing result to obtain an execution result, the following specific steps are implemented:

[0177] Execute each control policy in the parsing result one by one in a predefined order to obtain an execution result.

[0178] In one embodiment, when the processor executes the computer program to implement the execution of each control policy in the parsing result one by one in a predefined order to obtain an execution result, the following specific steps are implemented:

[0179] Match the implementation class of each control policy in the parsing result through the policy code identifier, and execute the corresponding implementation class in a hierarchical manner to obtain an execution result; where the implementation class includes identity verification and IP whitelist verification.

[0180] Among them, the hierarchical manner includes execution in the order of the common layer, the logic layer, the external interface call layer, and the parameter processing layer. The common layer is used to handle common tasks; the logic layer is used to handle specific business logics; the external interface call layer interacts with external systems; and the parameter processing layer is used to transfer and format parameters.

[0181] In one embodiment, when the processor executes the computer program to implement the step of, when the execution result is that all policies are verified and passed, forwarding the external request to the target business system according to the service routing configuration for corresponding processing by the target business system to generate a response result, the specific implementation is as follows:

[0182] When the execution result is that all policies are verified and passed, obtain the routing forwarding rule according to the interface path matching rule; determine the address of the target business system service through the configured routing table, and forward the external request to the corresponding target business system by using the routing forwarding rule. Among them, when forwarding, according to the parameters passed in the configuration, including the identity ID, institution ID, and billing product ID, and perform pass-through transmission.

[0183] In one embodiment, when the processor executes the computer program to implement the step of receiving the response result fed back by the target business system, forwarding it to the external request initiator, and recording the request trace, the specific implementation is as follows:

[0184] Receive the response result fed back by the target business system, forward it to the external request initiator, and record the relevant log information of all requests, including the request URL, request headers, request body, and response data, to form a request trace.

[0185] The storage medium can be various computer-readable storage media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a magnetic disk, or an optical disc that can store program codes.

[0186] Those of ordinary skill in the art can realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of the examples have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.

[0187] In several embodiments provided by the present invention, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of each unit is only a logical function division, and there can be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed.

[0188] The steps in the method of the embodiments of the present invention can be adjusted in sequence, combined, and deleted according to actual needs. The units in the device of the embodiments of the present invention can be combined, divided, and deleted according to actual needs. In addition, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit.

[0189] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a terminal, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention.

[0190] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of various equivalent modifications or substitutions, and these modifications or substitutions should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A dynamic policy control method for a data query interface, characterized in that It includes: Initialize the gateway system and load the configurations of service routing and interface control policies. Obtain an external request and perform external request parsing to obtain a parsing result. Execute the interface control policy according to the parsing result to obtain an execution result. When the execution result is that all policies are verified and passed, forward the external request to the target business system according to the configuration of service routing, so that the target business system performs corresponding processing to generate a response result. Receive the response result fed back by the target business system, forward it to the external request initiator, and record the request trace.

2. The dynamic policy control method for a data query interface according to claim 1, wherein The initialization of the gateway system and the loading of the configurations of service routing and interface control policies include: Use SpringCloud Gateway as the gateway central system, initialize and load the configuration of service routing, and configure corresponding control policies for each interface, including authentication and IP whitelist verification, and store the affiliated configurations in the routing configuration library and the policy configuration library.

3. The dynamic policy control method for a data query interface according to claim 1, characterized in that The obtaining of the external request and the performance of external request parsing to obtain a parsing result include: Obtain an external request, where the external request includes the target interface address. Parse the interface path address of the external request and obtain the list of control policies corresponding to the interface path address from the policy configuration library to obtain a parsing result.

4. The dynamic policy control method for a data query interface according to claim 1, characterized in that, The execution of the interface control policy according to the parsing result to obtain an execution result includes: Execute each control policy in the parsing result one by one in a predefined order to obtain an execution result.

5. The dynamic policy control method for a data query interface according to claim 4, wherein The execution of each control policy in the parsing result one by one in a predefined order to obtain an execution result includes: Match the implementation class of each control policy in the parsing result through the policy code identifier, and execute the corresponding implementation class in a hierarchical manner to obtain an execution result; among them, the implementation class includes identity verification and IP whitelist verification.

6. The dynamic policy control method for a data query interface according to claim 5, characterized in that, The hierarchical manner includes execution in the order of the common layer, the logic layer, the external interface call layer, and the parameter processing layer. The common layer is used to process common tasks; the logic layer is used to process specific business logics; the external interface call layer interacts with external systems; the parameter processing layer is used to transfer and format parameters.

7. The dynamic policy control method for a data query interface according to claim 1, characterized in that When the execution result is that all policies are verified and passed, forward the external request to the target business system according to the configuration of service routing, so that the target business system performs corresponding processing to generate a response result, includes: When the execution result is that all policies are verified and passed, obtain the routing forwarding rule according to the interface path matching rule. Determine the address of the target business system service through the configured routing table, and forward the external request to the corresponding target business system using the routing forwarding rule. Among them, when forwarding, according to the parameters passed in the configuration, including the identity ID, organization ID, and billing product ID, and perform transparent transmission.

8. The dynamic policy control method for a data query interface according to claim 1, characterized in that, The receiving of the response result fed back by the target business system, forwarding it to the external request initiator, and recording the request trace includes: Receive the response result fed back by the target business system and forward it to the external request initiator, and record the relevant log information of all requests, including the request URL, request headers, request body, and response data, to form a request trace.

9. The dynamic policy control device for a data query interface, characterized in that It includes: An initialization and loading unit, configured to initialize the gateway system and load the configurations of service routing and interface control policies; A parsing unit, configured to obtain an external request and perform external request parsing to obtain a parsing result; An execution unit, configured to execute an interface control policy according to the parsing result to obtain an execution result; A forwarding unit, configured to, when the execution result is that all policies are verified and passed, forward the external request to the target business system according to the configuration of service routing, so that the target business system performs corresponding processing to generate a response result; A receiving unit, configured to receive the response result fed back by the target business system, forward it to the external request initiator, and record the request trace.

10. A computer device, characterized in that, The computer device includes a memory and a processor, and a computer program is stored on the memory. When the processor executes the computer program, the method described in any one of claims 1 to 8 is implemented.