API authority management method and device of service system, equipment and storage medium

By recording the identity correspondence between service API and matters in the business system, and combining matters and API identification for permission management, the risk of overprivileged access caused by setting API permissions to global uniqueness is solved, and the reliability of API permission management and the security of business system are improved.

CN120296752APending Publication Date: 2025-07-11HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410396506.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-01-11
Filing Date
2024-04-02
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

In the prior art, API permissions are set to globally unique in the business system, resulting in the risk of overprivileged access and reducing network security.

Method used

By recording the identity correspondence between the service API and the matter associated with the business page, combining the service API and the matter identification for permission management, distinguishing the matters to which the API belongs, setting matters to units to perform API permission grouping, reducing the amount of data and reducing the difficulty of permission maintenance.

Benefits of technology

It improves the reliability of API permission management, avoids network security problems caused by overpricing of matter permissions, and enhances the security of business systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120296752A_ABST
    Figure CN120296752A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an API authority management method and device of a service system, equipment and a storage medium, and relates to the technical field of computers. The method comprises the following steps: recording a first corresponding relationship between an identifier of a first service API associated with a first business page and an identifier of a first item; acquiring a first calling request; and allowing the first calling request to access the service corresponding to the first service API according to the identifier of the first service API carried by the first calling request, the identifier of the first item and the first corresponding relation. Compared with a mode of judging whether the user has the authority of the API or not, in the embodiment of the invention, the item to which the API belongs is distinguished through the identifier of the item. The authority management of the service API is carried out from two aspects of the item to which the service API belongs and the identifier of the service API, so that the reliability of the authority management of the API is improved. And the network security problem caused by the unauthorized item authority is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims the priority of a Chinese patent application with the application number 202410043980.7 and the application title "An Interface Management Method, System, Device and Storage Medium" submitted to the National Intellectual Property Administration on January 11, 2024, the entire content of which is incorporated herein by reference. Technical Field

[0002] This application relates to the field of computer technology, and more particularly to an API permission management method, device, equipment and storage medium for a business system. Background Art

[0003] With the development of Internet technology, more and more business processes have been digitized. For example, a business system based on various services provided by a cloud system. Currently, different permissions can be set for different users to control different users' access to different services in the business system to ensure the data security of the business system. Generally, various services in the business system provide application programming interfaces (APIs), and services can be accessed by calling the APIs of the services. Then, by setting permissions for multiple APIs for users, users can access different services in the business system. However, there is a nested relationship between the APIs of different services in the business system. By verifying the API permissions to control users' access to different services in the business system, it is possible that users access services that they do not have permission to access. This causes unauthorized access to services and reduces the network security of the business system. Summary of the Invention

[0004] Embodiments of this application provide an API permission management method, device, equipment and storage medium for a business system to improve the network security problem caused by API permission overstep.

[0005] In a first aspect, embodiments of this application provide an API permission management method for a business system. The method publishes a first business page associated with a first matter, where the first business page is associated with a first service API. By recording a first correspondence between the identifier of the first service API and the identifier of the first matter. After obtaining a first call request for the first service API, when the first call request carries the identifier of the first service API and the identifier of the first matter, allow the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first correspondence.

[0006] Compared with the method of controlling access to a business system by determining whether a user has the permission to use an API, the permission settings for the same API in different services are the same, which poses a risk of unauthorized access across services. In the embodiments of the present application, the corresponding relationship between the identifier of the service API associated with a business page and the identifier of an item is recorded to associate the service API with the item to which it belongs. In this way, the item to which the API belongs is distinguished by the identifier of the item in the call request for the service API. Moreover, in the embodiments of the present application, the permission management of the service API is carried out from two aspects: the access permission of the item to which the service API belongs and the identifier of the service API, by combining the identifier of the service API and the identifier of the item. In this way, the reliability of API permission management is improved, and network security issues caused by unauthorized item permissions are avoided.

[0007] In a possible implementation, it is specifically implemented as follows: A second service API is associated with a first business page. The second corresponding relationship between the identifier of the second service API and the identifier of the first item is recorded. The second call request for the second service API is obtained. When the second call request carries the identifier of the second service API and the identifier of the first item, the second call request is allowed to access the service corresponding to the second service API according to the identifier of the second service API and the identifier of the first item carried in the second call request, and the second corresponding relationship.

[0008] Based on this possible implementation, in the case where multiple service APIs are associated with a business page, the business system respectively establishes the corresponding relationship between each service API associated with the business page and the identifier of the item associated with the business page. When a call request for multiple service APIs associated with a business page is received, if the call request carries the identifier of the item associated with the business page, the call request is allowed to access the service corresponding to the service API. In this way, the fine-grained management of API permissions is realized.

[0009] In a possible implementation, it is specifically implemented as follows: The third call request for the first service API is obtained. When the third call request carries the identifier of the first service API and does not carry the identifier of the first item, the third call request is rejected from accessing the service corresponding to the first service API according to the identifier of the first service API carried in the third call request and the first corresponding relationship.

[0010] In this way, the reliability of API permission management is ensured by the identifier of the first item, and network security issues caused by unauthorized item permissions are avoided.

[0011] In a possible implementation, a second service page associated with a second matter is published. The second service page is associated with a first service API. A third correspondence between the identifier of the first service API and the identifier of the second matter is recorded. A fourth call request for the first service API is obtained. When the fourth call request carries the identifier of the first service API and the identifier of the second matter, the fourth call request is allowed to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the second matter carried in the fourth call request, and the third correspondence.

[0012] Since the service APIs for different matters overlap, that is, the same service API may be associated with business pages related to multiple matters. Based on this possible implementation, for different matters, the correspondence between the identifier of the matter and the service API associated with the business page related to the matter is set. In this way, the business system distinguishes the matter to which the service API belongs according to the correspondence under different matters, and avoids the risk of unauthorized access to matters through constructing service APIs in the case of overlapping service APIs for different matters.

[0013] In a possible implementation, the specific implementation is as follows: A fourth call request for the first service API is obtained. When the fourth call request carries the identifier of the first service API and does not carry the identifier of the second matter, the fourth call request is denied access to the service corresponding to the first service API according to the identifier of the first service API carried in the fourth call request, and the third correspondence and the first correspondence.

[0014] Based on this possible implementation, when the fourth call request carries the identifier of the first service API and does not carry the identifier of the second matter, the business system denies the fourth call request access to the service corresponding to the first service API according to the identifier of the first service API carried in the fourth call request, and the third correspondence and the first correspondence. In this way, the business system distinguishes the matter to which the service API belongs according to the correspondence under different matters, and avoids the risk of unauthorized access to matters through constructing service APIs in the case of overlapping service APIs for different matters.

[0015] In a possible implementation, the specific implementation is as follows: The first service API and / or the second service API is set in the first business page, or set in a page with the first business page as the parent page.

[0016] In this way, the correspondence between each service API associated with the business page and the identifier of the matter associated with the business page is established respectively. Fine-grained management of API permissions is achieved.

[0017] In a possible implementation, record the first correspondence relationship between the identifier of the first service API and the identifier of the first matter. The specific implementation is as follows: create a first business session for the first matter; generate the identifier of the first matter in the first business session, associate the identifier of the first service API with the identifier of the first matter, and establish the first correspondence relationship.

[0018] In this way, when the user accesses the business session of the first matter, the identifier of the matter of the service API is dynamically generated. Compared with the static API permissions, it can finely distinguish the matter to which the API belongs and the business session of the matter. When there is an overlap in the APIs associated with the matter, it can avoid the over-authorization of the matter's permissions.

[0019] In a possible implementation, the specific implementation is as follows: the first call request carries the user role. When the first correspondence relationship includes the identifier of the first service API and the identifier of the first matter, the identifier of the first matter is included in the first business session of the first matter, and the first service API is in the set of API permissions allowed to be accessed by the user role, the first call request is allowed to access the service corresponding to the first service API.

[0020] Since the business session created by the business system when the user accesses the first matter is temporary and time-sensitive, and the attacker intercepts the first correspondence relationship in the business system, it takes time to construct the first call request message of the first service API based on the first correspondence relationship. It is possible that after the business system closes the business session of the first matter, the attacker sends the first call request of the first service API to the business system. Therefore, in this possible implementation, add the judgment on whether the identifier of the first matter is included in the first business session of the first matter. By virtue of the characteristics of the business session being temporary and time-sensitive, and identifying whether the API indicated by the first session identifier matches the API associated with the target business, the reliability of the API permission verification is improved, thereby ensuring the network security of the business system.

[0021] In a possible implementation, the specific implementation is as follows: the first business page is associated with a second service API. After allowing the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the first matter carried by the first call request, and the first correspondence relationship, publish the mapping value of the keyword of the first matter, and send the mapping value of the keyword to the client corresponding to the first call request. Obtain a second call request for the second service API. The second call request carries the identifier of the second service API, the identifier of the first matter, and the first mapping value. According to the identifier of the second service API, the first mapping value, and the identifier of the first matter carried by the second call request, and the second correspondence relationship, allow the second call request to access the service corresponding to the second service API. The second correspondence relationship is used to indicate the correspondence relationship between the identifier of the second service API and the identifier of the first matter.

[0022] When the message constructed by the attacker includes the first service API permission verification, if the first call request of the first service API is directly responded to, there may be a risk of unauthorized access to matters. Therefore, in this possible implementation, after the business system allows the first call request to access the service corresponding to the first service API, it publishes the mapping value of the keyword of the first matter. When obtaining the call request of the API, the call request is managed for permissions through the identifier of the matter carried by the call request, the identifier of the service API, and the mapping value. In this way, the reliability of the API permission management of the business system is further improved by adding the mapping value. The network security of the business system is improved.

[0023] In a possible implementation, the specific implementation is as follows: Before publishing the first business page associated with the first matter, set the access permissions of multiple roles to multiple matters provided by the business system; According to the access permissions of multiple roles to multiple matters, set the access permissions of at least one API associated with multiple matters to obtain the API call permission set corresponding to the role.

[0024] In the related technology, by allocating the permissions of each API in the business system, according to the business that each role needs to access and the API associated with the business, the permissions of the API of each role are allocated, and the permissions of the role and the API are associated to form the API call permission set of each role. There are problems such as large difficulty in API permission allocation and a large amount of data. In this possible implementation, based on multiple matters provided by the business system and the API associated with each matter, by allocating the access permissions of each matter, the access permissions of the API associated with each matter are set to obtain the API call permission set. In this way, the API is grouped by matter, and the access permissions of the API are set based on the access permissions of the matter, which can reduce the amount of data compared to directly allocating the permissions of the API. And taking the matter as the unit, the difficulty of permission maintenance and allocation is reduced.

[0025] In a possible implementation, according to the access permissions of multiple roles to multiple matters, setting the access permissions of at least one API associated with multiple matters is specifically implemented as follows: According to multiple matters provided by the business system, as well as the trigger component of each matter and the association relationship between the trigger component and the business page, obtain the association relationship between each matter and the business page; According to the API associated with each business page and the association relationship between each matter and the business page, obtain at least one API associated with each matter; According to the access permissions of the role to multiple matters and at least one API associated with each matter, set the access permissions of at least one API associated with each matter.

[0026] Based on this possible implementation, group the APIs by matter and set the access permissions of the APIs based on the access permissions of the business. Compared with directly assigning the permissions of the APIs, the amount of data can be reduced. And by taking the business as the unit, the difficulty of permission maintenance and assignment can be reduced.

[0027] In a second aspect, an embodiment of the present application provides an API permission management device for a business system. The API permission management device for the business system may be a computing device cluster for executing the API permission management method of the business system, or a chip or system-on-chip in the computing device cluster. The API permission management device for the business system may implement the functional modules of the method in the first aspect or any possible implementation manner of the first aspect. The functions executed by the computing device in the first aspect or any possible implementation manner of the first aspect can be implemented by the API permission management device for the business system. The hardware or software includes one or more modules corresponding to the above functions, such as a service module, a configuration module, an acquisition module, and a permission module.

[0028] Among them, the service module is used to publish a first service page associated with a first matter. Among them, the first service page is associated with a first service API.

[0029] The configuration module is used to record a first corresponding relationship between the identifier of the first service API and the identifier of the first matter.

[0030] The acquisition module is used to acquire a first call request for the first service API. Among them, the first call request carries the identifier of the first service API and the identifier of the first matter.

[0031] The permission module is used to allow the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first corresponding relationship.

[0032] In a possible implementation manner, the specific implementation is: the first service page is associated with a second service API. The configuration module is further used to record a second corresponding relationship between the identifier of the second service API and the identifier of the first matter.

[0033] The acquisition module is further used to acquire a second call request for the second service API. Among them, the second call request carries the identifier of the second service API and the identifier of the first matter.

[0034] The permission module is further used to allow the second call request to access the service corresponding to the second service API according to the identifier of the second service API and the identifier of the first matter carried in the second call request, and the second corresponding relationship.

[0035] In a possible implementation, the specific implementation is as follows: The acquisition module is further configured to acquire a third call request for the first service API. The third call request carries the identifier of the first service API and does not carry the identifier of the first matter.

[0036] The permission module is further configured to reject the third call request from accessing the service corresponding to the first service API according to the identifier of the first service API carried in the third call request and the first corresponding relationship.

[0037] In a possible implementation, the specific implementation is as follows: The business module is further configured to publish a second business page associated with the second matter, and the second business page is associated with the first service API.

[0038] The configuration module is further configured to record a third corresponding relationship between the identifier of the first service API and the identifier of the second matter.

[0039] The acquisition module is further configured to acquire a fourth call request for the first service API. The fourth call request carries the identifier of the first service API and the identifier of the second matter.

[0040] The permission module is further configured to allow the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the second matter carried in the fourth call request and the third corresponding relationship.

[0041] In a possible implementation, the specific implementation is as follows: The acquisition module is further configured to acquire a fourth call request for the first service API. The fourth call request carries the identifier of the first service API and does not carry the identifier of the second matter.

[0042] The permission module is further configured to reject the fourth call request from accessing the service corresponding to the first service API according to the identifier of the first service API carried in the fourth call request, and the third corresponding relationship and the first corresponding relationship.

[0043] In a possible implementation, the first service API and the second service API associated with the first business page published by the business module are specifically implemented as follows: The first service API and / or the second service API are set in the first business page or in a page with the first business page as the parent page.

[0044] In a possible implementation, the specific implementation is as follows: The configuration module is used to create a first business session for the first matter. In the first business session, the identifier of the first matter is generated, and the identifier of the first service API is associated with the identifier of the first matter to establish the first corresponding relationship.

[0045] In a possible implementation, the specific implementation is as follows: The first call request obtained by the obtaining module carries a user role. The obtaining module is further configured to, when the first correspondence includes the identifier of the first service API and the identifier of the first matter, the identifier of the first matter is included in the first business session of the first matter, and the first service API is in the set of API permissions allowed to be accessed by the user role, allow the first call request to access the service corresponding to the first service API.

[0046] In a possible implementation, the specific implementation is as follows: The first business page published by the business module is associated with a second service API. The business module is further configured to publish the mapped value of the keyword of the first matter and send the mapped value of the keyword to the client corresponding to the first call request.

[0047] The obtaining module is further configured to obtain a second call request for the second service API, where the second call request carries the identifier of the second service API, the identifier of the first matter, and the first mapped value.

[0048] The permission module is further configured to, according to the identifier of the second service API, the first mapped value, and the identifier of the first matter carried in the second call request, and the second correspondence, allow the second call request to access the service corresponding to the second service API. The second correspondence is used to indicate the correspondence between the identifier of the second service API and the identifier of the first matter.

[0049] In a possible implementation, the specific implementation is as follows: The configuration module is further configured to set the access permissions of multiple roles for multiple matters provided by the business system. According to the access permissions of multiple roles for multiple matters, set the access permissions of at least one API associated with multiple matters to obtain the set of API call permissions corresponding to the roles.

[0050] In a possible implementation, when the configuration module sets the access permissions of at least one API associated with multiple matters according to the access permissions of multiple roles for multiple matters, the specific implementation is as follows: The configuration module is further configured to obtain the association relationship between each matter and the business page according to multiple matters provided by the business system, the trigger component of each matter, and the association relationship between the trigger component and the business page. According to the APIs associated with each business page and the association relationship between each matter and the business page, obtain at least one API associated with each matter. According to the access permissions of the roles for multiple matters and at least one API associated with each matter, set the access permissions of at least one API associated with each matter.

[0051] In a third aspect, embodiments of the present application provide a computing device cluster, which includes at least one computing device. Each computing device includes a processor and a memory. The processor of at least one computing device is configured to execute instructions stored in the memory of at least one computing device, so that the computing device cluster executes the method in the first aspect or any possible implementation manner of the first aspect as described above.

[0052] In a fourth aspect, embodiments of the present application provide a computer-readable storage medium, which summarizes computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster executes the computer program instructions stored in the computer-readable storage medium to execute the method in the first aspect or any possible implementation manner of the first aspect as described above.

[0053] In a fifth aspect, embodiments of the present application provide a computer program product. When the instructions are run by a computing device or a computing device cluster, the computing device cluster is caused to execute the method in the first aspect or any possible implementation manner of the first aspect as described above.

[0054] For the technical effects brought by any implementation manner in the second aspect to the fifth aspect, reference may be made to the technical effects brought by the first aspect to the first aspect or different implementation methods, which will not be elaborated here.

[0055] Based on the implementation manners provided in the above aspects, the present application can be further combined to provide more implementation manners. BRIEF DESCRIPTION OF THE DRAWINGS

[0056] Figure 1 A schematic diagram showing a business system providing different services to different personnel;

[0057] Figure 2 A schematic diagram showing the permission configuration of an API in the related art;

[0058] Figure 3 A schematic diagram showing the permission verification of an API in the related art;

[0059] Figure 4 A schematic diagram of an application scenario of the API permission management method for the business system provided by the embodiments of the present application;

[0060] Figure 5 A schematic diagram of the business system process provided by the embodiments of the present application;

[0061] Figure 6 A schematic diagram of the process of API permission management for the business system provided by the embodiments of the present application;

[0062] Figure 7 A schematic diagram of the process of API call permission allocation provided by the embodiments of the present application;

[0063] Figure 8 Schematic diagram of the process for configuring the call permission of the API provided by the embodiment of the present application;

[0064] Figure 9 Schematic diagram of the association relationship between the trigger control and the business page provided by the embodiment of the present application;

[0065] Figure 10 Schematic diagram of keyword mapping provided by the embodiment of the present application;

[0066] Figure 11 Schematic diagram of the matter query operation interface provided by the embodiment of the present application;

[0067] Figure 12 Schematic diagram of the event submission operation interface provided by the embodiment of the present application;

[0068] Figure 13 Schematic diagram of the structure of the business system provided by the embodiment of the present application;

[0069] Figure 14 Schematic diagram of the structure of the API permission management device of the business system provided by the embodiment of the present application;

[0070] Figure 15 Schematic diagram of the structure of the API permission management system of the business system provided by the embodiment of the present application;

[0071] Figure 16 Schematic diagram of the structure of the computing device provided by the embodiment of the present application;

[0072] Figure 17 Schematic diagram of the structure of the computing device cluster provided by the embodiment of the present application;

[0073] Figure 18 Schematic diagram of the network connection between computing devices in the computing device cluster provided by the embodiment of the present application. Detailed implementation manners

[0074] There are multiple types of personnel accessing the business system. Each type of personnel can access different services, and accordingly, the access permissions of each person to the business system are also different. For example Figure 1As shown in the figure, the business system A provides services S1, S2, S3, and S4. The personnel who can access the business system A include the first type of personnel, the second type of personnel, the third type of personnel, and the fourth type of personnel. Among them, the first type of personnel can access S1 and S4. The second type of personnel can access S2. The third type of personnel can access S3. The fourth type of personnel can access S1, S2, S3, and S4. Correspondingly, the access rights of the first type of personnel, the second type of personnel, the third type of personnel, and the fourth type of personnel to the business system A are (S1, S4), (S2), (S3), and (S1, S2, S3, S4) respectively.

[0075] The business system mainly realizes different business functions by calling different APIs. Since each type of personnel can access different services, the call rights of different personnel to the service APIs in the business system are also different. To manage the access rights of users to the system, it is necessary to assign roles to each person and set the corresponding API call rights for each role.

[0076] Currently, in the related technologies, mainly by assigning the rights of each API in the business system, according to the services that each role needs to access and the APIs associated with the services, the rights of the APIs of each role are assigned, and the roles are associated with the rights of the APIs to form the API call right set of each role. Exemplarily, taking the example that the service S1 in the business system includes n service APIs, as Figure 2 shown, when the rights of the n service APIs are set to right-1, right-2, ···, right-n respectively, if the rights of the service APIs of role 1 are right-1, right-2, ···, right-n, then the users of role J01 have the access rights to service API-1, service API-2, ···, service API-n.

[0077] When a user accesses the business system, the business system determines the service APIs that the user has access rights to according to the API call right set of the role to which the user belongs. When the service API requested by the user to be called is the service API that the user has access rights to, the business system allows access. When the service API requested by the user to be called is not the service API that the user has access rights to, the business system refuses access. As Figure 3 shown, when the API call right set of the role to which the user belongs has the right-k of service API-SK but does not have the right-n of service API-n, this user is allowed to access service API-SK and prohibited from accessing service API-n.

[0078] As described in the background art, currently, the business system mainly controls whether a user can access an API by determining whether the user has the permission to the API, so as to achieve the controlled access of the business system. Since the permission setting of the API is globally unique, that is, the permissions of the same API in different services are the same. Moreover, when verifying the API permission, it only verifies whether the user has the permission to the API. When there are overlapping APIs related to the service, an attacker can directly construct an API message to stack the APIs that a certain user has access permission to, and then access the services that the user does not have access permission to. It can be seen that there are potential risks of unauthorized access to services in the related technology. This will reduce the network security of the business system.

[0079] Exemplarily, as shown in Table 1, Service 1 is associated with API-1 and API-2. Service 2 is associated with API-1 and API-3. Service 3 is associated with API-1, API-2, and API-3. When a user is allowed to access Service 1 and Service 2 but prohibited from accessing Service 3, since the user has the permissions to API-1, API-2, and API-3, by constructing the messages of API-1, API-2, and API-3, the user can access Service 3, resulting in unauthorized access of the user to Service 3.

[0080] Table 1 Example of Service-Associated APIs

[0081] Business Name Associated API Business 1 Service API-1, Service API-2 Business 2 Service API-1, Service API-3 Business 3 Service API-1, Service API-2, Service API-3

[0082] Based on this, to solve the problem of unauthorized access to services and improve the network security of the service system, an API permission management method for a service system is provided in an embodiment of this application. In this method, after publishing a service page associated with a matter provided by the service system, the correspondence between the identifier of the service API associated with the service page and the identifier of the matter is recorded. When a call request for the service API is received, if the call request for the service API carries the identifier of the service API and the identifier of the matter, the call request for the service API is allowed to access the service corresponding to the service API according to the identifier of the service API and the identifier of the matter carried in the call request for the service API, and the correspondence. Compared with the method of controlling access to the service system by determining whether a user has the permission for the API, the permission settings for the same API in different services are the same, and there is a risk of unauthorized access to services. In the embodiment of this application, by recording the correspondence between the identifier of the service API associated with the service page and the identifier of the matter, the service API is associated with the matter to which it belongs. In this way, the matter to which the API belongs is distinguished by the identifier of the matter in the call request for the service API. Moreover, in the embodiment of this application, through the combination of the identifier of the service API and the identifier of the matter, the permission management of the service API is carried out from two aspects: the access permission of the matter to which the service API belongs and the identifier of the service API. In this way, the reliability of the API permission management is improved. The network security problem caused by unauthorized access to matters is avoided.

[0083] It should be noted that the API permission management method for the service system provided in the embodiment of this application can be applied to service scenarios based on cloud computing. For example, it can be applied to service scenarios such as retrieval service scenarios, financial service scenarios, medical service scenarios, education service scenarios, audio service scenarios, and software development service scenarios based on cloud computing. The embodiment of this application does not limit this. The API permission management method for the service system provided in the embodiment of this application can also be applied to other service scenarios that are not cloud computing.

[0084] When the API permission management method for the service system provided in the embodiment of this application is applied to a service scenario based on cloud computing, the service system is deployed in the cloud. The client accesses the service system through the network. The service system provides service functions to the client. When the service system is deployed in the cloud, the service system can be referred to as a cloud system.

[0085] When the API permission management method for the service system provided in the embodiment of this application is applied to other service scenarios that are not cloud computing, the service system is deployed in a local computing device, and the user interacts with the service system through the interface of the local computing device.

[0086] Exemplarily, taking a retrieval service scenario based on cloud computing as an example, the application scenario of the API permission management method for the service system provided in the embodiment of this application is introduced. AsFigure 4 As shown Figure 4 This is an application scenario of the API permission management method for the business system provided by the embodiments of the present application. The shown application scenario includes a client 20, a business system 10, and a network 30. The client 20 performs data interaction with the business system 10 through the network 30. For example, the client 20 logs in to the business system 10. Another example is that the client 20 requests to call an API from the business system 10.

[0087] Among them, the business system 10 provides multiple services to the client 20. For example, the business system 10 provides services such as retrieval services, query services, output services, input services, etc. The embodiments of the present application do not limit this. Each service is used for different matters. Each matter-associated service page is associated with at least one API. The business system 10 realizes the business functions of the service by calling at least one API associated with the service page. For example, when service A is a query service, the service page associated with the matter of service A is associated with query APIs, read APIs, and output APIs. The business system 10 realizes the business query matter by calling the query APIs, read APIs, and output APIs.

[0088] In the embodiments of the present application, the client 20 sends a call request for a service API to the business system 10. The business system 10 receives the call request for the service API sent by the client 20, executes the API permission management method for the business system provided by the embodiments of the present application, and determines whether to allow the call request for the service API to access the service corresponding to the service API.

[0089] In the first possible implementation manner, as Figure 4 shown, the business system 10 includes an access layer 101, a processing layer 102, and a resource layer 103.

[0090] The access layer 101 is used to receive the call request for the service API sent by the client. The processing layer 102 is used to provide the service corresponding to the service API. The resource layer 103 is used to provide the computing resources, storage resources, and network resources required by the business system. For example, store search terms, search results, and databases in the search service scenario.

[0091] Among them, a processing module 1021 is deployed in the processing layer 102.

[0092] Among them, an access gateway 1011 is deployed in the access layer 101.

[0093] In one example, the access gateway 1011 is configured to receive a call request for a service API sent by a client, run the API permission management method of the service system provided by the embodiments of the present application, and forward the call request for the service API to the processing layer 102 when allowing the call request for the service API to access the service corresponding to the service API.

[0094] In another example, the access gateway 1011 is configured to receive a call request for a service API sent by a client. The API request is passed to the processing layer 102. The processing module 1021 in the processing layer 102 runs the API permission management method of the service system provided by the embodiments of the present application, and when allowing the call request for the service API to access the service corresponding to the service API, the processing module 1021 in the processing layer 102 provides the service corresponding to the service API.

[0095] It should be noted that Figure 4 only for exemplary drawings, which do not constitute a limitation on the API permission management method of the service system provided by the embodiments of the present application. In actual application scenarios, the API permission management method of the service system can be applied to other business scenarios, such as financial business scenarios, medical business scenarios, educational business scenarios, audio business scenarios, and software development business scenarios, etc. And Figure 4 the naming and grouping of the service system are illustrative, only a logical function grouping, and there can be other grouping methods in actual implementation. For example, the service system can also be divided into a permission control module and an API processing module. Specifically, another division example can refer to the Figure 13 corresponding example below. In addition, the service system can also be named as the API permission management device of the service system, and the API permission management device of the service system can include modules different from Figure 4 those shown in the cloud server in Figure 14 the corresponding embodiment, and the embodiments of the present application will not be elaborated herein.

[0096] Based on Figure 4 the application scenarios provided, the embodiments of the present application provide an API permission management method for a service system. The API permission management method of the service system of the embodiments of the present application will be introduced below in combination with specific embodiments.

[0097] In the embodiments of the present application, as Figure 5As shown, the business system provides multiple matters to the client. The client sends a matter access request for the first matter to the business system (S51). The business system publishes the first business page associated with the first matter (S52). The business system records the first correspondence between the identifier of the first service API associated with the first business page and the identifier of the first matter. The client sends a call request carrying the identifier of the first service API and the identifier of the first matter to the business system (S53). The business system performs permission verification on the first service API requested to be called by the client according to the identifier of the first service API and the identifier of the matter carried in the call request and the first correspondence (S54).

[0098] As Figure 6 shown Figure 6 is a schematic flowchart of the API permission management method of the business system provided by an embodiment of the present application. The shown API permission management method of the business system includes steps S610 to S650.

[0099] S610, obtain a matter access request for the first matter.

[0100] Among them, the business access request includes a matter identifier. The matter identifier is used to indicate any one of the multiple matters provided by the business system.

[0101] In a first possible implementation manner, the business system obtains the matter access request for the first matter input by the user through the interface of the business system.

[0102] In a second possible implementation manner, the business system obtains the matter access request for the first matter sent by the client.

[0103] In an example, the client can send a matter access request to the business system by clicking the trigger component of the matter in the business system interface displayed on the client.

[0104] In another example, the client can directly send a matter access request to the business system by constructing a message.

[0105] S620, the business system publishes the first business page associated with the first matter.

[0106] Among them, the first business page is associated with a first service API.

[0107] In a first possible implementation manner, the business system displays the first business page associated with the first matter in the interface.

[0108] In a second possible implementation manner, the business system sends the first business page associated with the first matter to the client. The client displays the first business page associated with the first matter in the interface.

[0109] In an embodiment of the present application, the matter access request includes a first matter identifier. The business system determines that the user has access rights to the first matter based on the first matter identifier included in the matter access request, and publishes a first business page associated with the first matter. The business system determines that the user does not have access rights to the first matter based on the first matter identifier included in the matter access request, and refuses to publish the first business page associated with the first matter.

[0110] In an example, the business system stores system permission sets for different roles, and the system permission sets include the corresponding relationships between roles and matter access rights. The business system queries the corresponding relationships between roles and matter access rights according to the role to which the user belongs, and obtains the matter identifiers to which the role to which the user belongs has matter access rights. When the first matter identifier is included in the matter identifiers to which the role to which the user belongs has matter access rights, it is determined that the user has access rights to the first matter. When the first matter identifier is not included in the matter identifiers to which the role to which the user belongs has matter access rights, it is determined that the user does not have access rights to the first matter.

[0111] Among them, the corresponding relationship between the role and the business access right is used to indicate the corresponding relationship between different roles and the business identifiers to which the role has business access rights.

[0112] Among them, the system permission set is created by the business system setting the access rights of multiple roles to multiple services provided by the business system. For example, refer to the following Figure 7 Provide the implementation to establish the system permission set. The embodiments of the present application will not be described in detail here.

[0113] S630, the business system records the first corresponding relationship between the identifier of the first service API and the identifier of the first matter.

[0114] Among them, the identifier of the first service API is used to indicate the first service API in the business system. In an example, the identifiers of the service APIs in the business system are unique, that is, different service APIs have different identifiers.

[0115] The identifier of the first matter is used to indicate the matter to which the first service API belongs. The same service API has different matter identifiers under different matters.

[0116] Among them, the first corresponding relationship is used to indicate the corresponding relationship between the identifier of the first service API and the corresponding identifier of the first matter.

[0117] In an embodiment of the present application, the first business page associated with the first matter is associated with at least one service API. The first service API is included in the at least one service API associated with the first business page. Each service API corresponds to an identifier of a first matter.

[0118] In the first example, the identifiers of the first matters corresponding to each service API are the same. That is, the business system assigns the same identifier of the first matter to the service API associated with the first business page associated with the first matter.

[0119] In the second example, the identifiers of the first matters corresponding to each service API are different. That is, the business system assigns different identifiers of the first matter to each service API associated with the first business page associated with the first matter.

[0120] In a possible implementation, the business system obtains the stored identifier of the first matter. Or the business system dynamically generates the identifier of the first matter.

[0121] In the first possible implementation, taking the dynamic generation of the identifier of the first matter as an example, when the business system receives a matter access request, it creates a business session, and generates the identifier of the first matter in this business session. Associates the identifier of the first service API with the identifier of the first matter to establish a first correspondence.

[0122] In an example, the business system can perform encoding processing based on the matter identifier of the first matter, the identifier of the first service API, and the timestamp information of creating the business session to generate the identifier of the first matter. Among them, the encoding processing includes hash encoding.

[0123] In another example, in the business session when the user accesses the first matter, the business system generates the identifier of the first matter through a random number generation method.

[0124] It should be noted that in the case of dynamically generating a session identifier, for the first service API, it has different matter identifiers in different business sessions of the first matter. In this way, when accessing the business session of the first matter by the user, the matter identifier of the service API is dynamically generated. Compared with static API permissions, it can finely distinguish the matters to which the API belongs and the business sessions of the matters, and avoid permission overstepping of matters when the APIs associated with the matters overlap.

[0125] In the second possible implementation, taking the obtaining of the stored identifier of the first matter as an example, the business system can pre-set the identifiers of the matters when each service API belongs to different matters. Based on the matter identifier of the matter, the identifier of the service API, and the identifiers of the matters when each service API belongs to different matters, the correspondence between the matter and the identifier is obtained. In the business session of the first matter, the business system queries the correspondence between the matter and the session identifier based on the matter identifier of the first matter to obtain the identifier of the first matter corresponding to the first service API.

[0126] It should be noted that when obtaining the identifier of the first matter stored, since the identifier of the first matter is created in advance. Therefore, the same service API has the same matter identifier in different business sessions of the same matter. In this way, by creating a globally unique matter identifier, the uniqueness of the matter identifier is achieved. In this way, the business system can distinguish the matter to which the service API belongs according to the matter identifier. When there is an overlap in the service APIs associated with the matter, it can simplify the complexity of API permission verification while avoiding matter permission overstepping.

[0127] S640, the business system obtains a first call request for the first service API.

[0128] Among them, the first call request carries the identifier of the first service API and the identifier of the first matter.

[0129] In the first possible implementation, the business system obtains a first call request for the first service API input by the user based on the first business page.

[0130] In the second possible implementation, the business system obtains a first call request for the first service API sent by the client.

[0131] For example, the business system sends a first correspondence to the client. After receiving the first correspondence, the client displays the interface of the first business page of the first matter. The client responds to the trigger operation input by the user based on the interface of the first business page and sends a first service API call request to the business system. Among them, the trigger operation can be clicking on the page control displayed on the interface of the first business page.

[0132] In the third possible implementation, the business system receives a request message. The request message is used to indicate a first call request for the first service API.

[0133] S650, the business system allows the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first correspondence.

[0134] In one possible implementation, since when the call request for the first service API is normal, that is, when there is no unauthorized access to the first service API, the identifier of the first service API and the identifier of the first matter carried in the call request for the first service API are included in the first correspondence. And when the call request for the first service API is abnormal, that is, when there is unauthorized access to the first service API, the identifier of the first service API and the identifier of the first matter carried in the call request for the first service API are not included in the first correspondence.

[0135] Therefore, the business system can query the first corresponding relationship. When the identifier of the matter corresponding to the identifier of the first service API is consistent with the identifier of the first matter carried in the first call request, and the identifier of the service API corresponding to the identifier of the first matter is consistent with the identifier of the first service API carried in the first call request, the first call request is allowed to access the service corresponding to the first service API. When the identifier of the matter corresponding to the identifier of the first service API is inconsistent with the identifier of the first matter carried in the first call request, and / or the identifier of the service API corresponding to the identifier of the first matter is inconsistent with the identifier of the first service API carried in the first call request, the business system rejects the first call request from accessing the service corresponding to the first service API.

[0136] In an embodiment of the present application, when the business system allows the first call request to access the service corresponding to the first service API, it calls the first service API to perform a data operation and outputs the result of the data operation.

[0137] For example, the business system sends the result of the data operation to the client. The client receives the result of the data operation sent by the business system and displays the result of the data operation. Also for example, the result of the data operation is displayed in the first business page of the business system.

[0138] Among them, the data operation includes but is not limited to query operation, input operation, data submission operation, calculation operation, etc. Correspondingly, the services corresponding to the first service API include but are not limited to query service, input service, data submission service, data calculation service, etc.

[0139] Exemplarily, taking the query operation as an example, the business system calls the first service API to perform a query operation and generates a query result.

[0140] In an embodiment of the present application, when the call request of the service API does not carry the identifier of the matter, the business system does not allow the call request to access the service corresponding to the service API.

[0141] For example, the business system obtains a third call request for the first service API. Among them, the third call request carries the identifier of the first service API and does not carry the identifier of the first matter. According to the identifier of the first service API carried in the third call request and the first corresponding relationship, the third call request is rejected from accessing the service corresponding to the first service API. In this way, the reliability of API permission management is ensured through the identifier of the first matter. Avoiding network security problems caused by matter permission overstepping.

[0142] Among them, the third call request not carrying the identifier of the first matter may mean that the identifier of the matter carried in the third call request is inconsistent with the identifier of the first matter. Or, it may also mean that the third call request does not carry the identifier of the matter.

[0143] In an embodiment of the present application, when a call request is not allowed to access the service corresponding to the service API, the business system rejects the call request and outputs a prompt message to prompt the user that they do not have the call permission for the service API requested to be called. For example, the business system sends a prompt message to the client.

[0144] Based on Figure 6 In the provided embodiment, after publishing the business page associated with the matter provided by the business system, the correspondence between the identifier of the service API associated with the business page and the identifier of the matter is recorded. When a call request for the service API is received, if the call request for the service API carries the identifier of the service API and the identifier of the matter, the call request for the service API is allowed to access the service corresponding to the service API according to the identifier of the service API and the identifier of the matter carried in the call request for the service API and the correspondence. Compared with the method of implementing access control of the business system by determining whether the user has the permission for the API, the permission settings for the same API in different businesses are the same, and there is a risk of unauthorized access to the business. In the embodiment of the present application, by recording the correspondence between the identifier of the service API associated with the business page and the identifier of the matter, the service API is associated with the matter to which it belongs. In this way, the matter to which the API belongs is distinguished by the identifier of the matter in the call request for the service API. Moreover, in the embodiment of the present application, through the combination of the identifier of the service API and the identifier of the matter, the permission management of the service API is carried out from two aspects: the access permission of the matter to which the service API belongs and the identifier of the service API. In this way, the reliability of API permission management is improved, and network security problems caused by unauthorized access to matters are avoided.

[0145] In an embodiment of the present application, when multiple service APIs are associated with a business page, the business system respectively establishes the correspondence between each service API associated with the business page and the identifier of the matter associated with the business page. When a call request for multiple service APIs associated with the business page is received, if the call request carries the identifier of the matter associated with the business page, the call request is allowed to access the service corresponding to the service API. When the call request does not carry the identifier of the matter associated with the business page, the call request is not allowed to access the service corresponding to the service API.

[0146] Taking Figure 6 the provided embodiment as an example, when a second service API is also associated with the first business page, the business system records the second correspondence between the identifier of the second service API and the identifier of the first matter.

[0147] The business system obtains a second call request for a second service API. The second call request carries the identifier of the second service API and the identifier of the first matter. The business system allows the second call request to access the service corresponding to the second service API according to the identifier of the second service API and the identifier of the first matter carried in the second call request, and the second corresponding relationship.

[0148] Among them, the second service API may be a service API set in the first business page. Or, the second service API may also be a service API set in a page with the first business page as the parent page.

[0149] In the embodiments of the present application, since the service APIs of different matters overlap, that is, the same service API may be associated with multiple business pages associated with matters. The business system sets the corresponding relationship between the identifier of the matter and the service API associated in the business page associated with the matter for different matters. In this way, the business system distinguishes the matter to which the service API belongs according to the corresponding relationship under different matters, and avoids the risk of unauthorized access to matters through constructing service APIs in the case of overlapping service APIs of different matters.

[0150] Exemplarily, taking the business system providing a second matter as an example. Among them, the function implemented by the second matter is different from that of the first matter. The second business page associated with the second matter is associated with a first service API.

[0151] When the business system obtains a matter access request for the second matter, the business system publishes the second business page associated with the second matter. The business system records the third corresponding relationship between the identifier of the first service API and the identifier of the second matter. The business system obtains a fourth call request for the first service API. When the fourth call request carries the identifier of the first service API and the identifier of the second matter, the business system allows the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the second matter carried in the fourth call request, and the third corresponding relationship. When the fourth call request carries the identifier of the first service API and does not carry the identifier of the second matter, the business system rejects the fourth call request from accessing the service corresponding to the first service API according to the identifier of the first service API carried in the fourth call request, and the third corresponding relationship and the first corresponding relationship.

[0152] Among them, that the fourth call request does not carry the identifier of the second matter may be that the fourth call request carries the identifier of the first matter. Or the fourth call request does not carry the identifier of the matter.

[0153] In an embodiment of the present application, to improve the reliability of API permission management in a business system, when the business system receives a call request, the business system can verify the access permission of the service API according to the identifier of the service API and the set of API permissions allowed to be accessed. According to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first corresponding relationship, verify the access permission of the matter. When having the access permission of the service API and having the access permission of the matter, allow the call request to access the service corresponding to the service API. In this way, by combining the access permission of the service API and the access permission of the matter, manage the permission of the service API from two aspects: the permission of the API and the permission of the matter. Avoid network security problems caused by overstepping of matter permissions.

[0154] Among them, the API permission set includes the identifiers of the service APIs allowed to be called by users in the business system.

[0155] In a possible implementation manner, the business system can, according to the role to which the user belongs corresponding to the call request of the service API, determine the set of API call permissions allowed for the user from the set of API call permissions corresponding to the target role matched with the role to which the user belongs in the multiple sets of API call permissions corresponding to the roles stored in the business system.

[0156] Taking the first call request of the first API as an example below, the above S650 will be introduced.

[0157] First, introduce the API permission set.

[0158] In the related art, by allocating the permissions of each API in the business system, according to the services that each role needs to access and the APIs associated with the services, allocate the permissions of the APIs of each role, and associate the roles with the permissions of the APIs to form the set of API call permissions for each role. There are problems such as large difficulty in API permission allocation and large amount of data. Based on this, to reduce the difficulty of API permission allocation and reduce the amount of data, in an embodiment of the present application, based on multiple matters provided by the business system and the APIs associated with each matter, by allocating the access permissions of each matter and setting the access permissions of the APIs associated with each matter, obtain the set of API call permissions. In this way, group the APIs by matter, and set the access permissions of the APIs based on the access permissions of the matters, which can reduce the amount of data compared with directly allocating the permissions of the APIs. And taking the matter as the unit, reduce the difficulty of permission maintenance and allocation.

[0159] As Figure 7 shown, Figure 7 is a schematic flow diagram of API call permission allocation provided by an embodiment of the present application. The shown API call permission allocation includes S710 to S720.

[0160] S710. Set the access rights of multiple roles to multiple matters provided by the business system to obtain a set of permission systems.

[0161] Among them, the role is used to indicate the type of user accessing the business system. For example, taking the business system of video playback as an example, the roles of the business system include viewers and audio administrators. Among them, viewers watch the videos provided by the business system, and audio administrators manage video data in the business system, such as adding videos, deleting videos, etc. Correspondingly, the business system of video playback provides services such as video viewing, video downloading, video collection, and video management. Correspondingly, viewers have access rights to video viewing, video downloading, and video collection, while audio administrators have access rights to video management.

[0162] In a first possible implementation manner, based on the business permission configuration information input by the system operation and maintenance personnel of the business system, set the access rights of multiple roles to multiple matters provided by the business system.

[0163] Among them, the business permission configuration information includes the user roles accessing the business system, the matters provided by the business system, and the matters participated in by each role.

[0164] For example, the user roles accessing the business system include role A, role B, and role C. The business system provides S1 business matters, S2 business matters, S3 business matters, S4 business matters, and S7 business matters. When role A participates in S2 business matters and S3 business matters, role B participates in S4 business matters and S7 business matters, and role C participates in S1 business matters, correspondingly, role A has access rights to S2 business matters and S3 business matters. Role B has access rights to S4 business matters and S7 business matters. Role C has access rights to S1 business matters.

[0165] In a second possible implementation manner, the business system can determine the user roles accessing the business system, the matters provided by the business system, and the matters participated in by each role by analyzing the code files of the business system. Based on the matters provided by the business system and the matters participated in by each role, allocate the access rights of each role to the matters.

[0166] S720. According to the set of permission systems, set the call rights of at least one API associated with multiple matters to obtain a set of API call rights corresponding to the roles.

[0167] In a possible implementation, the code files of the business system can be analyzed to obtain the APIs associated with each matter. Based on the APIs associated with each matter in the business system and the access permissions for each matter, the call permissions for the APIs associated with each matter are set. For each role, based on the matters that the role is allowed to access and the call permissions for the APIs associated with the matters, an API call permission set corresponding to each role is obtained.

[0168] As Figure 8 shown, Figure 8 FIG. is a schematic diagram of the API call permission setting process provided by an embodiment of the present application. The shown API call permission setting process includes S721 to S724:

[0169] S721, analyze the code files of the business system to obtain various matters provided in the business system, the trigger components for each matter, and the association relationship between the trigger components and the business views.

[0170] Among them, the code file can be the front-end code file of the business system.

[0171] Among them, the trigger component of the matter is used to indicate the trigger entry of the matter in the business system. In one example, the trigger components of the matter include, but are not limited to, trigger buttons, menus, etc.

[0172] Among them, the association relationship between the trigger component and the business view is used to indicate the corresponding relationship between the trigger component and the business page associated with the trigger component, as well as the APIs associated in the business page. That is, after the business system responds to the trigger operation of the trigger component, the business page associated with the trigger component is displayed.

[0173] Among them, the association relationship between the trigger component and the business page can be a tree relationship or a forest relationship between the trigger component and the business page.

[0174] In one example, the APIs associated in the business page include the APIs set in the business page, the APIs called by the page controls displayed in the business page, the APIs set in the page with the business page as the parent page, and / or the APIs associated in the business page associated with the trigger controls of other services set in the business page.

[0175] In the embodiment of the present application, the association relationship between the trigger component and the business page can be formed according to the business page displayed after the trigger component is triggered, as well as the APIs set in the business page, the displayed page controls, the APIs set in the page with the business page as the parent page, and / or the displayed trigger components of other services.

[0176] Exemplarily, as Figure 9 shown, Figure 9It is a schematic diagram of the association relationship between the trigger control and the service page provided by the embodiments of the present application. The service pages associated with the trigger component of Service A include Page M and Page N. Among them, Page M displays page control K1, and Page M is associated with API-1 and API-n. Page N is provided with a trigger component of Service B, a trigger component of Service C, and Page N is associated with API-2 and API-k.

[0177] S722, Associated matters and service pages.

[0178] In the embodiments of the present application, according to the association relationship between the trigger component and the service page, and the trigger components of each service, the service can be associated with at least one service page, and at least one service page associated with the service can be obtained. Exemplarily, taking Figure 9 as an example, Service A is associated with Page M and Page N.

[0179] S723, Associated matters and APIs associated with service pages.

[0180] In one possible implementation, at least one API associated with multiple matters is obtained according to at least one service page associated with multiple matters and at least one API associated with the service page.

[0181] Exemplarily, taking Figure 9 as an example, Service A is associated with Page M and Page N. Page M is associated with API-1 and API-n, and Page N is associated with API-2 and API-k. Then the APIs associated with Service A include API-1, API-n, API-2, and API-k.

[0182] S724, Set the call permissions of the APIs associated with the matters.

[0183] In one possible implementation, according to the access permissions of roles to multiple matters, the call permissions of at least one API associated with multiple matters are set.

[0184] For example, for each matter, according to the roles allowed to access the matter and at least one API associated with the matter, the call permissions of at least one API associated with the matter are set.

[0185] Based on Figure 8 the embodiments provided, the APIs are grouped by matter, and the access permissions of the APIs are set based on the access permissions of the service. Compared with directly assigning permissions to the APIs, the data volume can be reduced. And taking the service as a unit, the difficulty of permission maintenance and assignment is reduced.

[0186] Next, taking the first call request of the first service API as an example, the permission verification of the call request of the service API is described.

[0187] In a first possible implementation, the first corresponding relationship can be queried based on the identifier of the first matter and the identifier of the first service API, and the set of API permissions allowed to be accessed can be queried based on the identifier of the first service API. When the first corresponding relationship includes the identifier of the first service API and the identifier of the first matter, and the first service API is in the set of API permissions allowed to be accessed by the user role, the first call request is allowed to access the service corresponding to the first service API.

[0188] In an example, when the identifier of the matter corresponding to the identifier of the first service API is consistent with the identifier of the first matter carried in the first call request, and the identifier of the service API corresponding to the identifier of the first matter is consistent with the identifier of the first service API carried in the first call request, it is determined that the first corresponding relationship includes the identifier of the first service API and the identifier of the first matter.

[0189] When the identifier of the matter corresponding to the identifier of the first service API is inconsistent with the identifier of the first matter carried in the first call request, and / or the identifier of the service API corresponding to the identifier of the first matter is inconsistent with the identifier of the first service API carried in the first call request, it is determined that the first corresponding relationship does not include the identifier of the first service API and the identifier of the first matter.

[0190] In an example, when the set of API permissions allowed to be accessed includes the identifier of the first service API, it is determined that the first service API is in the set of API permissions allowed to be accessed by the user role.

[0191] When the set of API permissions allowed to be accessed does not include the identifier of the first service API, it is determined that the first service API is not in the set of API permissions allowed to be accessed by the user role.

[0192] In an example, when the first corresponding relationship does not include the identifier of the first service API and the identifier of the first matter, and / or the first service API is not in the set of API permissions allowed to be accessed by the user role, the first call request is refused to access the service corresponding to the first service API.

[0193] When the identifier of the first matter is included in the first business session of the first matter, and the first service API is in the set of API permissions allowed to be accessed by the user role, the first call request is allowed to access the service corresponding to the first service API.

[0194] In a second possible implementation, since the business session created by the business system when a user accesses the first matter is temporary and time-sensitive, and an attacker intercepts the first corresponding relationship in the business system, it takes time to construct the first call request message for the first service API based on the first corresponding relationship. It is possible that after the business system closes the business session of the first matter, the attacker sends a first call request for the first service API to the business system.

[0195] Therefore, to identify the construction of an API request message based on the first corresponding relationship and improve the network security of the business system, on the basis of the first possible implementation of the permission verification of the call request for the above service API, the judgment on whether the first business session of the first matter contains the identifier of the first matter is added. When the first corresponding relationship contains the identifier of the first service API and the identifier of the first matter, the first business session of the first matter contains the identifier of the first matter, and the first service API is in the set of API permissions allowed to be accessed by the user role, the first call request is allowed to access the service corresponding to the first service API. When the first corresponding relationship does not contain the identifier of the first service API and the identifier of the first matter, the first business session of the first matter does not contain the identifier of the first matter, and / or the first service API is not in the set of API permissions allowed to be accessed by the user role, the first call request is refused to access the service corresponding to the first service API.

[0196] In this way, by virtue of the characteristics that the business session is temporary and time-sensitive, and by identifying whether the API indicated by the first session identifier matches the API associated with the target service, the reliability of the API permission verification is improved, thereby ensuring the network security of the business system.

[0197] In the embodiment of the present application, after determining that the first API permission verification is passed, the call request for the first service API can be responded according to S650 above.

[0198] In a possible implementation, when the first service API permission verification is included in the message constructed by the attacker, if the first call request for the first service API is directly responded, there may be a risk of unauthorized access to the matter. Therefore, to further reduce the risk of unauthorized access, after the business system allows the first call request to access the service corresponding to the first service API, the mapping value of the keyword of the first matter is published. When the call request for the API is obtained, the call request is managed for permissions through the identifier of the matter, the identifier of the service API, and the mapping value carried by the call request. In this way, the reliability of the API permission management of the business system is further improved by adding the mapping value. The network security of the business system is improved.

[0199] Among them, the keyword is used to indicate the business object in the first matter. For example, taking the first matter as a query service as an example, the business object is the query matter.

[0200] In one example, keywords for each matter in the business system can be preset. After the business system's first call requests access to the service corresponding to the first service API, it obtains the keywords of the first matter and maps the keywords to obtain a mapped message of the keywords. The mapped message of the keywords is sent to the client. For example, when the business system returns the data of the service corresponding to the first service API to the client, it sends the mapped value of the query matter to the client.

[0201] In another example, the business system can identify the message sent to the client to obtain the keywords in the message. Map the keywords to obtain a mapped message of the keywords. The mapped message of the keywords is sent to the client.

[0202] For example, the message sent to the client is identified by a semantic parsing method to obtain the keywords in the message. Another example is that the message sent to the client can be identified by a field matching method to obtain the keywords in the message.

[0203] Exemplarily, taking the second service API associated with the first business page as an example. The business system obtains a second call request for the second service API. When the second call request carries the identifier of the second service API, the identifier of the first matter, and the first mapped value, the business system allows the second call request to access the service corresponding to the second service API according to the identifier of the second service API, the first mapped value, the identifier of the first matter carried in the second call request, and the second corresponding relationship.

[0204] For example, when the first mapped value passes the verification, the second corresponding relationship includes the identifier of the second service API and the identifier of the first matter, and the second service API is in the set of API permissions allowed to be accessed by the user role, the second call request is allowed to access the service corresponding to the second service API.

[0205] In the first example, the business system can compare the first mapped value carried in the second call request with the mapped values of multiple keywords of the first matter in the business session. When the mapped values of multiple keywords of the first matter include the first mapped value, it is determined that the first mapped value passes the verification. When the mapped values of multiple keywords of the first matter do not include the first mapped value, it is determined that the first mapped value fails the verification.

[0206] In the second example, the business system obtains the second keyword mapped by the first mapped value. The second keyword is verified according to the keyword corresponding to the first mapped value among the mapped values of multiple keywords. When the second keyword passes the verification, it is determined that the first mapped value passes the verification.

[0207] Wherein, the second keyword is the keyword obtained by restoring the first mapped value.

[0208] As Figure 10 shown Figure 10 is a schematic diagram of keyword mapping provided by an embodiment of the present application. The business system maps multiple keywords of a first matter during a business session to obtain mapping values of the multiple keywords, and sends the mapping values of the multiple keywords to the client. The mapping value of the keyword is carried in the call request of the service API sent by the client to the business system. The business system verifies the first mapping value carried in the call request of the service API according to the mapping values of the multiple keywords of the first matter in the business session. When the verification passes, the business system restores the first mapping value carried in the call request of the service API to a keyword to obtain a business object.

[0209] To better illustrate the API permission management method of the business system provided by the embodiment of the present application, taking the first matter as the matter query service as an example, an application scenario of the API permission management method of the business system in the matter query service is provided.

[0210] As Figure 11 shown in Figure (a) below, a quick entry box and an information display box are displayed in the business system interface of the client. Among them, "News Trends", "Announcements" and "Others" trigger components are displayed in the information display box. Trigger components for weather query service, matter query service, date query service and record query service are displayed in the quick entry box. The user triggers a matter access request for the matter query service by clicking the trigger component for the matter query service in the interface. The business system obtains the matter access request, creates a business session for the matter query service, and publishes a matter input page associated with the matter query service as shown in Figure (b) below. An event input box and a matter query control are set on the event input interface. The event input box is associated with an event submission API, and the matter query control is associated with a matter query API. That is, the APIs associated with the event input interface include an event submission API and a matter query API. Figure 11 As shown in Figure (b) below, an event input box and a matter query control are set on the event input interface. The event input box is associated with an event submission API, and the matter query control is associated with a matter query API. That is, the APIs associated with the event input interface include an event submission API and a matter query API.

[0211] Among them, the matter query API is used to return a matter query result, and the matter query result is used to indicate the matter to which the query term input by the user belongs. For example, when the query term input by the user is "cherry", the corresponding matter is "fruit query".

[0212] The event submission API is used to submit the query term input by the user to the processing module of the business system.

[0213] In this business session, the identifiers of the matters of the event submission API and the matter query API are generated respectively, and the corresponding relationship between the identifiers corresponding to the event submission API and the matter query API and the identifiers of the matters of the event submission API and the matter query API is established. As shown in Table 2.

[0214] Table 2 Session Identifiers of the Event Submission API and the Matter Query API

[0215] API Session ID of API Event Submission API 64565604 Matter Query API 23434302

[0216] It should be noted that the corresponding relationships shown in Table 2 are only examples and do not constitute a limitation on the API permission management method of the business system provided by the embodiments of the present application.

[0217] As Figure 11 shown in Figure (c) therein, for the query term "cherry" entered by the user, clicking the "Matter Query" control in the event input interface triggers a first call request for the first service API.

[0218] The business system obtains the first call request for the first service API. The first call request carries the identifier of the matter and the identifier of the first service API. When the identifier of the matter carried in the first call request is "23434302" and the identifier of the first service API carried is "Matter Query API", the business system allows the first call request to access the service of the matter query API. The business system establishes a mapping relationship between the keyword "fruit query" and the mapping value "1352101354" of "fruit query" in the business session of the matter query service. And returns the query result and the mapping value "1352101354" of "fruit query". As Figure 11 shown in Figure (d) therein, the matter to which "cherry" belongs shown on the page is "fruit query".

[0219] When the user clicks the "Submit" control in Figure (a) as Figure 12 therein, it triggers a second call request for the second service API.

[0220] The business system obtains the second call request for the second service API. The second call request carries the identifier of the matter, the identifier of the second service API, and the first mapping value. When the identifier of the matter is "64565604", the identifier of the second service API is "Event Submission API", and the first mapping value is "1352101354", the business system allows the second call request to access the service of the event submission API. As Figure 12 shown in Figure (b) therein, information such as classification, origin, variety, and cultivation techniques of "cherry" is displayed in the view.

[0221] The above mainly introduces the solution provided by the embodiments of the present application from the perspective of the interaction between the business system and the user. It can be understood that in order to implement the functions executed by the above business system, the above business system includes the corresponding hardware structures and / or software modules for executing each function. Those skilled in the art should easily realize that, combining the units and algorithm operations of each example described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the way of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0222] The embodiments of the present application can divide the functional modules of the above business system according to the above method examples. Each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. It can be understood that the naming and grouping of the devices and modules in the embodiments of the present application are schematic, only a logical functional grouping, and there can be other grouping methods in actual implementation.

[0223] For example, as Figure 13 shown, the business system can include a permission control module 131 and an API processing module 132.

[0224] Among them, the permission control module 131 is used to publish the first business page associated with the first matter, record the first corresponding relationship between the identifier of the first service API and the identifier of the first matter, obtain the first call request for the first service API, and allow the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first corresponding relationship. For example, the permission control module 131 executes the above Figure 6 steps S620 to S650.

[0225] The API processing module 132 is used to provide the service corresponding to the first service API for the first call request to access.

[0226] As Figure 13 shown, the permission control module 131 includes a permission configuration unit 1311, a permission control unit 1312, a page parsing unit 1313, an access adaptation unit 1314, and a routing adaptation unit 1315.

[0227] Among them, the permission configuration unit 1311 is used to record the first corresponding relationship between the identifier of the first service API and the identifier of the first matter. Set the access permissions of multiple roles for multiple matters provided by the business system, and set the access permissions of at least one API associated with multiple matters according to the access permissions of roles for multiple matters, so as to obtain the API call permission set corresponding to the role.

[0228] The permission control unit 1312 is used to allow the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first corresponding relationship.

[0229] The page parsing unit 1313 is used to publish the first business page associated with the first matter. And analyze the code file of the business system to obtain various matters provided in the business system, the trigger component of each matter, and the association relationship between the trigger component and the business page. According to the multiple matters provided by the business system, the trigger component of each matter, and the association relationship between the trigger component and the business page, obtain the association relationship between each matter and the business page. According to the API associated with each business page and the association relationship between each matter and the business page, obtain at least one API associated with each matter.

[0230] The access adaptation unit 1314 is used to maintain the business session, save the first corresponding relationship between the identifier of the first service API and the identifier of the first matter, and the mapping relationship between the keyword and the mapping value of the keyword.

[0231] The routing matching unit is used to obtain the matter access request and the first call request for the first service API.

[0232] Among them, the permission control module 131 and the API processing module 132 can be hardware modules or software modules, which are not limited in the embodiments of the present application.

[0233] It should be noted that the naming and grouping of the modules in the business system above Figure 13 are schematic, just a logical function grouping, and there can be other grouping methods in actual implementation.

[0234] For example, the business system can be named as the API permission management device of the business system. As Figure 14 shown, Figure 14 is the structural schematic diagram of the API permission management device of the business system provided by the embodiments of the present application. The API permission management device 14 of the business system shown includes:

[0235] The business module 141 is used to publish the first business page associated with the first matter, and the first business page is associated with the first service API. For example, the business module 141 executes the aboveFigure 6 S620 in

[0236] Configuration module 142 is used to record the first corresponding relationship between the identifier of the first service API and the identifier of the first matter. For example, the configuration module 142 executes the above Figure 6 S630 in

[0237] Obtaining module 143 is used to obtain a first call request for the first service API, where the first call request carries the identifier of the first service API and the identifier of the first matter. For example, the obtaining module 143 executes the above Figure 6 S640 in

[0238] Permission module 144 is used to allow the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first corresponding relationship. For example, the permission module executes the above Figure 6 S650 in

[0239] Among them, the service module 141, the configuration module 142, the obtaining module 143, and the permission module 144 can all be implemented by software or by hardware. Exemplarily, next, taking the service module 141 as an example, the implementation method of the service module 141 is introduced. Similarly, the configuration module 142, the obtaining module 143, and the permission module can refer to the implementation method of the service module 141.

[0240] As an example of a software functional unit, the service module 141 can be code running on a computing instance. Among them, the computing instance can include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above computing instance can be one or more. For example, the service module 141 can include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code can be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code can be distributed in the same availability zone (AZ) or in different AZs. Each AZ includes one data center or multiple geographically proximate data centers. Among them, generally, one region can include multiple AZs.

[0241] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed within the same virtual private cloud (VPC) or across multiple VPCs. Usually, one VPC is set up within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, communication gateways need to be set up within each VPC, and the interconnection between VPCs is achieved through the communication gateways.

[0242] As an example of a hardware functional unit, the service module 141 may include at least one computing device, such as a server. Alternatively, the service module 141 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0243] The multiple computing devices included in the service module 141 can be distributed within the same region or across different regions. The multiple computing devices included in the service module 141 can be distributed within the same availability zone (AZ) or across different AZs. Similarly, the multiple computing devices included in the service module 141 can be distributed within the same VPC or across multiple VPCs. Among them, the multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0244] It should be noted that in other embodiments, the service module 141 can be used to execute any step in the API permission management method of the service system, the permission module 144 can be used to execute any step in the API permission management method of the service system, the acquisition module 143 can be used to execute any step in the API permission management method of the service system, and the configuration module 142 can be used to execute any step in the API permission management method of the service system. The steps to be implemented by the service module 141, the configuration module 142, the acquisition module 143, and the permission module 144 can be specified as needed. By implementing different steps in the API permission management method of the service system through the service module 141, the configuration module 142, the acquisition module 143, and the permission module 144 respectively, all functions of the API permission management device 14 of the service system are realized.

[0245] This embodiment of the application also provides a business system API permission management system 15 provided with the above-mentioned Figure 14 API permission management device 14 of the business system provided. As Figure 15 shown, Figure 15 is a schematic structural diagram of the business system API permission management system provided by this embodiment of the application. The shown business system API permission management system 15 includes the API permission management device 14 of the business system and the client 20.

[0246] Among them, the client 20 is used to send a call request for the first service API to the API permission management device 14 of the business system.

[0247] The API permission management device 14 of the business system is used to obtain the matter access request of the first matter, publish the first service page associated with the first matter, record the first corresponding relationship between the identifier of the first service API and the identifier of the first matter, obtain the first call request for the first service API, and according to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first corresponding relationship, allow the first call request to access the service corresponding to the first service API. For example, the API permission management device 14 of the business system executes the above Figure 6 S610 to S650.

[0248] Both the API permission management device 14 of the business system and the client 20 can be implemented by software or can be implemented by hardware. Exemplarily, the implementation manner of the API permission management device 14 of the business system is introduced next. Similarly, for the implementation manner of the client 20, reference can be made to the implementation manner of the API permission management device 14 of the business system.

[0249] As an example of a software functional unit, the API permission management device 14 of the service system may include code running on a computing instance. The computing instance may be at least one of computing devices such as a physical host (computing device), a virtual machine, and a container. Further, the above computing devices may be one or more. For example, the API permission management device 14 of the service system may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running the application may be distributed in the same region or in different regions. The multiple hosts / virtual machines / containers for running the code may be distributed in the same AZ or in different AZs, and each AZ includes one data center or multiple data centers with close geographical locations. Usually, one region may include multiple AZs.

[0250] Similarly, the multiple hosts / virtual machines / containers for running the code may be distributed in the same VPC or in multiple VPCs. Usually, one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is achieved through the communication gateway.

[0251] As an example of a hardware functional unit, the API permission management device 14 of the service system may include at least one computing device, such as a server. Alternatively, the API permission management device 14 of the service system may also be a device implemented by ASIC or PLD. Among them, the above PLD may be implemented by CPLD, FPGA, GAL, or any combination thereof.

[0252] The multiple computing devices included in the API permission management device 14 of the service system may be distributed in the same region or in different regions. The multiple computing devices included in the API permission management device 14 of the service system may be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the API permission management device 14 of the service system may be distributed in the same VPC or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0253] The embodiment of the present application further provides a computing device for executing the above API permission management method of the service system.

[0254] In one example, the computing device may include, such as Figure 13The business system shown. The business system includes a permission control module 131 and an API processing module 132.

[0255] In another example, the computing device may include, as Figure 14 shown, an API permission management device 14 of the business system. The API permission management device 14 of the business system includes a service module 141, a configuration module 142, an acquisition module 143, and a permission module 144.

[0256] In another illustration, as Figure 16 shown, the computing device 16 includes a bus 162, a processor 164, a memory 166, and a communication interface 168. The processor 164, the memory 166, and the communication interface 168 communicate with each other via the bus 162. The computing device 16 may be a server or a terminal device. It should be understood that the present application does not limit the number of the processor 164 and the memory 166 in the computing device 16.

[0257] The bus 162 may be a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, or the like. The bus may be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 16 only one line is shown in, but it does not mean that there is only one bus or one type of bus. The bus 162 may include a path for transmitting information between various components (for example, the memory 166, the processor 164, the communication interface 168) of the computing device 16.

[0258] The processor 164 may include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP), etc.

[0259] In the present application, the processor 164 may execute the above Figure 6The API permission management method of the provided business system. For example, obtain the matter access request of the first matter, and publish the first business page associated with the first matter. Record the first corresponding relationship between the identifier of the first service API and the identifier of the first matter. Obtain the first call request for the first service API. And allow the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first corresponding relationship.

[0260] The memory 166 may include volatile memory, such as random access memory (RAM). The processor 164 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0261] The executable program code is stored in the memory 166, and the processor 164 executes the executable program code to implement the functions of the foregoing service module 141, permission module 144, and response module 143 respectively, so as to implement the API permission management method of the business system. That is, the memory 166 stores instructions for implementing the API permission management method of the business system.

[0262] The communication interface 168 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement the communication between the computing device 16 and other devices or communication networks.

[0263] The API permission management method of the business system disclosed in the foregoing method embodiment can be applied to or implemented by the processor 164. The processor 164 may be an integrated circuit chip with signal processing capabilities.

[0264] In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in the processor 164 or the instructions in the form of software. The above-mentioned processor 164 can be a general-purpose processor, including a CPU, a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete electron tubes or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by the combination of the hardware and software modules in the decoding processor. The software module can be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 166, and the processor 164 reads the information in the memory 166 and combines its hardware to complete the steps of the above method.

[0265] In a possible implementation manner, the processor 164 can also be used to execute the API permission management method of the service system. For the specific implementation, reference can be made to the embodiments provided in the above API permission management method of the service system, and the embodiments of the present application will not be elaborated herein.

[0266] In the embodiments of the present application, the chip system can be composed of chips, or can also include chips and other discrete devices.

[0267] The embodiments of the present application also provide a computing device cluster 17 for executing the above API permission management method of the service system.

[0268] In one example, the computing device cluster 17 may include, for example Figure 13 the service system as shown. The service system includes a permission control module 131 and an API processing module 132.

[0269] In another example, the computing device cluster 17 may include, for example Figure 14 the API permission management device 14 of the service system as shown. The API permission management device 14 of the service system includes a service module 141, a configuration module 142, an acquisition module 143 and a permission module 144.

[0270] In another example, the computing device cluster 17 may include, for example Figure 15 the API permission management system 15 of the service system as shown. The API permission management system 15 of the service system includes the API permission management device 14 of the service system and a client 20.

[0271] In another example, as Figure 17 shown, the computing device cluster 17 includes at least one computing device 16 as Figure 16 shown. The computing device 16 includes: a bus 162, a processor 164, a memory 166, and a communication interface 168. The processor 164, the memory 166, and the communication interface 168 communicate with each other through the bus 162. The computing device 16 can be a server or a terminal device.

[0272] In a possible implementation, one or more computing devices in the computing device cluster 17 can be connected through a network. Among them, the network can be a wide area network or a local area network, etc. Figure 18 A possible implementation is shown. As Figure 18 shown, two computing devices 16A and 16B are connected through a network. Specifically, they are connected to the network through the communication interfaces in each computing device. In this type of possible implementation, the memory 166 in the computing device 16A stores instructions for executing the functions of the configuration module 142 and the permission module 144. At the same time, the memory 166 in the computing device 16B stores instructions for executing the functions of the service module 141 and the acquisition module 143.

[0273] Figure 18 The connection method between the computing device clusters 17 shown as

[0274] should be understood that Figure 18 the functions of the computing device 16A shown in

[0275] can also be completed by multiple computing devices 16. Similarly, the functions of the computing device 16B can also be completed by multiple computing devices 16.

[0276] For example, when the computer program product runs on at least one computing device, it causes at least one computing device to execute Figure 6 the API permission management method of the business system shown.

[0277] The embodiments of the present application also provide a computer-readable storage medium. All or part of the processes in the above method embodiments can be completed by a computer program instructing related hardware. This program can be stored in the above computer-readable storage medium. When this program is executed, it can include the processes of the above method embodiments. The computer-readable storage medium can be the terminal in any of the foregoing embodiments, such as: an internal storage unit including a data transmission end and / or a data reception end, such as the hard disk or memory of the terminal. The above computer-readable storage medium can also be an external storage device of the above terminal, such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, etc. equipped on the above terminal. Further, the above computer-readable storage medium can also include both the internal storage unit and the external storage device of the above terminal. The above computer-readable storage medium is used to store the above computer program and other programs and data required by the above terminal. The above computer-readable storage medium can also be used to temporarily store the data that has been output or will be output.

[0278] It should be understood that in the technical solution of the present application, the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information and other processes all comply with relevant laws and regulations and do not violate public order and good customs. For example, in the technical solution of the present application, the processing of the user's personal information is carried out under the authorization of the user. It is hereby explained once and will not be repeated below.

[0279] It should be noted that the terms "first" and "second" in the description, claims, and drawings of the present application are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products, or devices.

[0280] It should be understood that in this application, "at least one (item)" means one or more, "a plurality" means two or more, "at least two (items)" means two, three or more, and "and / or" is used to describe the association relationship of associated objects, indicating that three relationships can exist. For example, "A and / or B" can represent: only A exists, only B exists, and both A and B exist at the same time. Among them, A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one (item) of the following" or its similar expression refers to any combination of these items, including any combination of single item (item) or plural items (items). For example, at least one (item) of a, b or c can represent: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or multiple.

[0281] It should be understood that in the embodiments of this application, "B corresponding to A" means that B is associated with A. For example, B can be determined according to A. It should also be understood that determining B according to A does not mean determining B only according to A, and B can also be determined according to A and / or other information. In addition, the "connection" mentioned in the embodiments of this application refers to various connection methods such as direct connection or indirect connection to achieve communication between devices, and this application does not make any limitations on this.

[0282] Through the description of the above embodiments, those skilled in the art can clearly understand that for the convenience and simplicity of description, only the grouping of the above function modules is used as an example. In actual applications, the above functions can be allocated to different function modules according to needs, that is, the internal structure of the device is divided into different function modules to complete all or part of the functions described above.

[0283] In several embodiments provided in this application, it should be understood that the disclosed device and method can be implemented in other ways. For example, the device embodiments described above are only illustrative. For example, the grouping of modules or units is only a logical function grouping. In actual implementation, there can be other grouping methods. For example, multiple units or components can be combined or integrated into another device, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of devices or units can be in electrical, mechanical or other forms.

[0284] The unit described as a separation component may or may not be physically separated. The component displayed as a unit may be a single physical unit or multiple physical units, that is, it may be located in one place, or it may be distributed to multiple different places. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0285] In addition, each functional unit in various embodiments of the present application may be integrated in a processing unit, or each unit may exist physically alone, or two or more units may be integrated in one unit. The above integrated unit may be implemented in the form of hardware or in the form of a software functional unit.

[0286] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a readable storage medium. Based on this understanding, the technical solution of the embodiments of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This software product is stored in a storage medium and includes several instructions for causing a device, such as a single-chip microcomputer, a chip, etc., or a processor to execute all or part of the steps of the methods of various embodiments of the present application. The aforementioned storage medium includes various media for storing program codes, such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs.

[0287] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A method for managing API permissions of a service application program in a service system, characterized in that, Including: Publish a first business page associated with a first matter, where the first business page is associated with a first service API; Record a first correspondence between the identifier of the first service API and the identifier of the first matter; Obtain a first call request for the first service API, where the first call request carries the identifier of the first service API and the identifier of the first matter; According to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first correspondence, allow the first call request to access the service corresponding to the first service API.

2. The method according to claim 1, characterized in that, The first business page is associated with a second service API, and the method further includes: Record a second correspondence between the identifier of the second service API and the identifier of the first matter; Obtain a second call request for the second service API, where the second call request carries the identifier of the second service API and the identifier of the first matter; According to the identifier of the second service API and the identifier of the first matter carried in the second call request, and the second correspondence, allow the second call request to access the service corresponding to the second service API.

3. The method according to claim 1 or 2, characterized in that The method further includes: Obtain a third call request for the first service API, where the third call request carries the identifier of the first service API and does not carry the identifier of the first matter; According to the identifier of the first service API carried in the third call request, and the first correspondence, reject the third call request from accessing the service corresponding to the first service API.

4. The method according to any one of claims 1 to 3, characterized in that, The method further includes: Publish a second business page associated with a second matter, where the second business page is associated with the first service API; Record a third correspondence between the identifier of the first service API and the identifier of the second matter; Obtain a fourth call request for the first service API, where the fourth call request carries the identifier of the first service API and the identifier of the second matter; According to the identifier of the first service API and the identifier of the second matter carried in the fourth call request, and the third correspondence, allow the first call request to access the service corresponding to the first service API.

5. The method according to claim 4, characterized in that, The method further includes: Obtain a fourth call request for the first service API, where the fourth call request carries the identifier of the first service API and does not carry the identifier of the second matter; According to the identifier of the first service API carried in the fourth call request, and the third correspondence and the first correspondence, reject the fourth call request from accessing the service corresponding to the first service API.

6. The method according to any one of claims 2 to 5, characterized in that The first service API and / or the second service API is set in the first business page or in a page with the first business page as the parent page.

7. The method according to any one of claims 1 to 6, characterized in that, The recording of the first correspondence between the identifier of the first service API and the identifier of the first matter includes: Create a first business session for the first matter; Generate an identifier for the first matter in the first service session, associate the identifier of the first service API with the identifier of the first matter, and establish the first corresponding relationship.

8. The method according to any one of claims 1 to 7, characterized in that, The first call request carries a user role; The step of allowing the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first corresponding relationship includes: When the first corresponding relationship includes the identifier of the first service API and the identifier of the first matter, the identifier of the first matter is included in the first service session of the first matter, and the first service API is in the set of API permissions allowed to be accessed by the user role, allow the first call request to access the service corresponding to the first service API.

9. The method according to any one of claims 1 to 8, characterized in that The first service page is associated with a second service API; after allowing the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first corresponding relationship, the method further includes: Publish the mapped value of the keyword of the first matter, and send the mapped value of the keyword to the client corresponding to the first call request; Obtain a second call request for the second service API, where the second call request carries the identifier of the second service API, the identifier of the first matter, and a first mapped value; Allow the second call request to access the service corresponding to the second service API according to the identifier of the second service API, the first mapped value, and the identifier of the first matter carried in the second call request, and a second corresponding relationship; the second corresponding relationship is used to indicate the corresponding relationship between the identifier of the second service API and the identifier of the first matter.

10. The method according to any one of claims 1 to 9, characterized in that, Before publishing the first service page associated with the first matter, the method further includes: Set the access permissions of multiple roles to multiple matters provided by the service system; According to the access permissions of the multiple roles to the multiple matters, set the access permissions of at least one API associated with the multiple matters to obtain the set of API call permissions corresponding to the roles.

11. The method according to claim 10, wherein The step of setting the access permissions of at least one API associated with the multiple matters according to the access permissions of the multiple roles to the multiple matters includes: Obtain the association relationship between each matter and the service page according to the multiple matters provided by the service system, the trigger component of each matter, and the association relationship between the trigger component and the service page; Obtain at least one API associated with each matter according to the API associated with each service page and the association relationship between each matter and the service page; Set the access permissions of at least one API associated with each matter according to the access permissions of the role to the multiple matters and at least one API associated with each matter.

12. An API permission management device for a service system, characterized in that, The device includes: A business module for publishing a first business page associated with a first matter, where the first business page is associated with a first service API; A configuration module for recording a first correspondence between the identifier of the first service API and the identifier of the first matter; An acquisition module for acquiring a first call request for the first service API, where the first call request carries the identifier of the first service API and the identifier of the first matter; An authorization module for allowing the first call request to access the service corresponding to the first service API according to the identifier of the first service API and the identifier of the first matter carried in the first call request, and the first correspondence; 13. A cluster of computing devices, characterized in that, Comprising at least one computing device, each computing device including a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 11; 14. A computer program product comprising instructions, characterized in that, When the instructions are run by the computing device cluster, the computing device cluster executes the method according to any one of claims 1 to 11; 15. A computer-readable storage medium, characterized in that, Comprising computer program instructions, when the computer program instructions are executed by the computing device cluster, the computing device cluster executes the method according to any one of claims 1 to 11.