A smart park enterprise resource coordination optimization method and system
By establishing an independent collaborative service authentication space and authentication certificate within the enterprise park, and using dynamic microservice verification codes, the problem of trade secret leakage during enterprise collaboration is solved, and secure and efficient resource collaboration is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- ZHEJIANG WANCHUANG HUIZHI TECHNOLOGY GROUP CO LTD
- Filing Date
- 2025-06-13
- Publication Date
- 2026-05-12
AI Technical Summary
Within a business park, there is a risk of trade secret leakage during resource collaboration between companies. How can we protect corporate trade secrets and improve security during this collaboration process?
By establishing an independent collaborative service authentication space and random paths, and using authentication certificates and dynamic microservice verification codes, authentication rules for enterprise collaborative tasks are constructed to ensure the security of access permissions and data transmission, and to avoid the risks of man-in-the-middle attacks and temporary authorizations.
It effectively prevents the leakage of trade secrets, improves the security of enterprise collaborative tasks, reduces the risk of microservice hijacking, and enhances the reliability of access control.
Smart Images

Figure CN120579674B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of smart park management technology, and in particular to a method and system for collaborative optimization of enterprise resources in smart parks. Background Technology
[0002] Existing business parks typically cluster different types of enterprises in an industrial cluster model, resulting in a rational division of labor. To enhance the overall competitiveness of the park, achieve resource sharing, reduce costs, promote innovation, and drive regional economic development, numerous different enterprises within the park need to collaborate on resource management. This includes collaboration in procurement and supply chains, joint R&D, shared public services, upstream and downstream support, and emergency assistance. All of these collaborations are conducted via the internet or the Internet of Things (IoT). These different collaborative methods can effectively break down barriers between enterprises within the park and improve the park's industrial competitiveness. However, while collaboration between enterprises can improve service efficiency, different companies still possess different trade secrets, and collaboration between different companies can lead to the accidental leakage of these secrets. Therefore, how to ensure efficient collaboration among enterprises within the park while protecting the individual trade secrets of each enterprise is a technical problem that needs to be solved. Summary of the Invention
[0003] One objective of this invention is to provide a method and system for optimizing collaborative enterprise resources in a smart park. This method and system establish an independent authentication space for collaborative services. This independent authentication space establishes a random path with an external collaborative API interface. The independent authentication space contains no related resources, only microservice modules. When an external enterprise sends an access request to the collaborative API interface, the collaborative API interface redirects the access information to the authentication space. The authentication space then parses and authenticates the collaborative access request. If authentication is successful, an internal data transmission path is established, and the resources requiring collaboration are returned to the external enterprise through this internal data transmission path and the random path channel. Therefore, this invention, through the use of a random path isolated from real enterprise resources and an independent authentication space, effectively avoids the acquisition of the enterprise's internal real resource addresses via, but not limited to, man-in-the-middle attacks, during the collaboration process, thereby effectively preventing the leakage of confidential data during collaboration.
[0004] Another objective of this invention is to provide a method and system for optimizing collaborative enterprise resources in a smart park. This method and system construct an authentication certificate for collaborative enterprise tasks. This certificate declares access roles, metadata entity type permissions, metadata entity operation permissions, and metadata entity attributes. The authentication certificate declaration provided by this invention includes metadata operation permission fields and metadata attribute fields based on collaborative task rules. This ensures that collaborative access to enterprises can only access attribute resources associated with the collaborative task and execute metadata operations within the permissions associated with that task. Therefore, this invention can effectively improve the security of collaborative task interactions and prevent the leakage of sensitive data in collaborative tasks. Since collaborative tasks interact through the encrypted authentication certificate, authorized collaborative services can be effectively provided between different enterprises at any time, thus avoiding the security risks of uncertain access scope due to temporary authorizations and the inconvenience of managing expired access.
[0005] Another objective of this invention is to provide a method and system for collaborative optimization of enterprise resources in a smart park. This method and system constructs YAML metadata within the enterprise and builds a search directory for internal resources in key-value pairs. Specifically, this invention constructs key-value pairs of dynamically distributed microservice sequence numbers and microservice verification codes within the YAML metadata. The microservice verification code is a dynamically changing random number sent to the microservice corresponding to the sequence number. When the corresponding microservice is randomly selected as the authentication service module of the collaborative service and passes authentication, the verification code stored within the current microservice is retrieved and sent to the key-value pair of the enterprise resource node for secondary verification. If the secondary verification passes, the resource is sent to the collaborating enterprise through a temporary path of the microservice module in a specific manner. This reduces the security risks associated with microservice hijacking.
[0006] To achieve at least one of the above-mentioned objectives, the present invention provides a method for collaborative optimization of enterprise resources in a smart industrial park, the method comprising the following steps:
[0007] Construct an independent microservice authentication space, generate n microservice instances with different paths within the microservice authentication space, obtain the serial number of each microservice instance, and send the microservice serial number to the enterprise internal resource node;
[0008] The resource node dynamically generates n random numbers, stores the n random numbers and the corresponding microservice sequence number as key-value pairs in the resource node, and sends the corresponding random number as a check code to the microservice instance with the corresponding sequence number.
[0009] Obtain metadata features and construct different enterprise collaborative authentication rules, then send the enterprise collaborative authentication rules to all microservice instances for storage;
[0010] A collaborative access request from an enterprise is obtained, and the collaborative access request is randomly redirected to a first microservice instance. The first microservice instance parses the collaborative access request and authenticates the access request according to the enterprise collaborative authentication rules.
[0011] After successful authentication, the first microservice instance and the corresponding resource node establish a communication connection, and after secondary authentication by the resource node, the first microservice instance sends the corresponding response message to the request through the temporary path of the first microservice instance.
[0012] According to a preferred embodiment of the present invention, the method includes: configuring a redirection gateway, wherein the redirection gateway obtains the path information of each microservice instance in all microservice authentication spaces and constructs a corresponding random routing rule, wherein the random routing rule includes: the redirection gateway obtains the sequence number and heartbeat data of each microservice instance, filters out the sequence numbers of surviving microservice instances, and randomly selects a microservice sequence number and path information as a redirection target, redirecting the enterprise collaborative access request to the first microservice instance, and the first microservice instance parses the request content after obtaining the enterprise collaborative access request.
[0013] According to another preferred embodiment of the present invention, the authentication method of the first microservice instance for the enterprise collaborative access request includes: obtaining the visitor name, collaboration type, access metadata type, metadata attribute, and metadata operation in the enterprise collaborative access request, and verifying the verification items of the visitor name, access metadata type, metadata attribute, and metadata operation in the first microservice instance respectively; if at least one verification item does not meet the verification rule of the corresponding collaboration type, a verification failure message is returned to the redirection gateway, and the redirection gateway and service instance are disconnected; the first microservice instance sends the verification failure message to the enterprise internal resource node.
[0014] According to another preferred embodiment of the present invention, after receiving the verification failure message, the enterprise internal resource node regenerates a second random number, uses the second random number as a key name, and stores the sequence number of the first microservice instance that failed verification as a key value in the key-value pair of the enterprise internal resource node, and sends the second random number to the first microservice instance that failed verification in encrypted form. The first microservice instance stores the second random number as a new checksum in the first microservice instance. The redirection gateway receives the new enterprise collaborative access request and redirects the new collaborative access request to the new second microservice instance in a random routing manner.
[0015] According to another preferred embodiment of the present invention, when the first microservice instance verifies that the visitor name, collaboration type, accessed metadata type, metadata attributes, and metadata operations in the enterprise collaborative access request all meet the corresponding type of collaboration rules, the first microservice instance extracts the encrypted first random number and sends the encrypted first random number, the first microservice instance serial number, the visitor name, collaboration type, accessed metadata type, metadata attributes, and metadata operations to the enterprise internal resource node. The enterprise resource node decrypts the first random number and uses the decrypted first random number as the key to search for the corresponding key-value stored microservice serial number in the resource node for a second verification. If the key-value stored microservice serial number is the same as the first microservice serial number, the second verification passes, and the resource corresponding to the collaboration rule is sent to the first microservice instance; otherwise, the communication between the resource node and the first microservice instance is closed.
[0016] According to another preferred embodiment of the present invention, the redirection gateway is an Envoy gateway, the microservice authentication space has n service hosts, and the n service hosts have different service paths, and the n microservice instances are respectively set in the corresponding n different service hosts. When the Envoy gateway receives the enterprise collaborative access request, the Envoy gateway generates a RouteConfiguration abstract class, and the Envoy gateway is configured with a liveness status table of microservice instances. It randomly selects a microservice instance from the liveness status table to obtain the corresponding hostname, and selects the path of the corresponding hostname through the path random weight configured by the RouteConfiguration abstract class to redirect the enterprise collaborative access request, wherein the path random weight is a dynamically updated weight parameter of the service host and the path.
[0017] According to another preferred embodiment of the present invention, when the redirected enterprise collaborative access request is successfully authenticated, a collaborative authentication certificate is generated in the corresponding first microservice instance. The collaborative authentication certificate includes a public key based on symmetric encryption, a public key attribute declaration, an electronic signature, and a collaborative type. The public key attribute declaration is set according to the visitor name, accessed metadata type, metadata attributes, and metadata operation settings of the corresponding collaborative type. When the first verification of the collaborative task is successful, the authentication certificate containing the public key, public key attribute declaration, collaborative type, and electronic signature, along with the requested corresponding enterprise resource, is encrypted to obtain encrypted data. This encrypted data is then sent to the redirection gateway through the first microservice instance. The redirection gateway sends the encrypted data to the corresponding external collaborative enterprise. The external collaborative enterprise parses and saves the collaborative authentication certificate and uses it for subsequent collaborative access requests.
[0018] According to another preferred embodiment of the present invention, in order to complete the collaborative interaction operation more efficiently, when an external collaborative enterprise sends a second collaborative access request to the same target enterprise, the corresponding collaborative authentication certificate is encrypted and encapsulated in the second collaborative access request, and randomly routed to a new second microservice instance through the redirection gateway. The second microservice instance parses the collaborative authentication certificate in the second collaborative access request and determines whether the public key attribute declaration, collaborative type and electronic signature in the collaborative authentication certificate are consistent with the declaration content and electronic signature of the corresponding type of collaborative authentication rule pre-stored by the microservice instance. If they are consistent, the verification is successful; if they are inconsistent, the communication with the redirection gateway is disconnected and the verification code stored in the second microservice instance is updated in real time.
[0019] To achieve at least one of the above-mentioned objectives, the present invention provides a smart park enterprise resource collaborative optimization system, wherein the system executes the above-mentioned smart park enterprise resource collaborative optimization method.
[0020] The present invention further provides a computer-readable storage medium storing a computer program, which is executed by a processor to implement the above-described method for collaborative optimization of enterprise resources in a smart park. Attached Figure Description
[0021] Figure 1 The diagram shown is a flowchart of a smart park enterprise resource collaborative optimization method according to the present invention.
[0022] Figure 2 The diagram shown is a schematic diagram of the module communication of a smart park enterprise resource collaborative optimization system according to the present invention. Detailed Implementation
[0023] The following description is intended to disclose the present invention and enable those skilled in the art to implement it. The preferred embodiments described below are merely examples, and other obvious variations will occur to those skilled in the art. The basic principles of the invention defined in the following description can be applied to other embodiments, modifications, improvements, equivalents, and other technical solutions that do not depart from the spirit and scope of the invention.
[0024] It is understood that the term "a" should be understood as "at least one" or "one or more," that is, in one embodiment, the number of an element can be one, while in another embodiment, the number of the element can be multiple, and the term "a" should not be understood as a limitation on the number.
[0025] Please combine Figure 1 and Figure 2 This invention discloses a method and system for collaborative optimization of enterprise resources in a smart industrial park. The method mainly includes the following steps:
[0026] S01. Construct an independent microservice authentication space, generate n microservice instances with different paths within the microservice authentication space, obtain the serial number of each microservice instance, and send the microservice serial number to the enterprise internal resource node.
[0027] S02. The resource node dynamically generates n random numbers, stores the n random numbers and the corresponding microservice sequence number as key-value pairs in the resource node, and sends the corresponding random number as a check code to the microservice instance with the corresponding sequence number.
[0028] S03. Obtain metadata features and construct different enterprise collaborative authentication rules, and send the enterprise collaborative authentication rules to all microservice instances for storage;
[0029] S04. Obtain the enterprise collaborative access request, randomly redirect the enterprise collaborative access request to a first microservice instance, the first microservice instance parses the collaborative access request, and authenticates the access request according to the enterprise collaborative authentication rules;
[0030] S05. After successful authentication, the first microservice instance and the corresponding resource node establish a communication connection, and after secondary authentication by the resource node, send the corresponding response message to the request through the temporary path of the first microservice instance.
[0031] Specifically, this invention first requires constructing n microservice instances using, but not limited to, n service hosts. In one preferred embodiment, the microservice instances can be registered with the redirection gateway. The n service hosts include multiple different external paths. The redirection gateway obtains the path information of all n service hosts based on the microservice registration information and constructs a monitoring list of the n microservice instances. The redirection gateway obtains the liveness status of the n microservice instances through the monitoring list. Heartbeat technology is preferably used in this invention to detect whether the corresponding microservice is alive. Of course, in other preferred embodiments of this invention, other technologies can be used to determine the live microservice instances. When the redirection gateway filters out m live microservice instances based on the microservice heartbeat data, it randomly selects one of the m live microservice instances as the redirection target.
[0032] It should be noted that the redirection gateway described in this invention is preferably an Envoy gateway. The Envoy gateway can configure routing rules using the following instructions: the `virtual_hosts` instruction represents the virtual service host configuration, where multiple virtual hosts and paths can be configured for running the microservice instance; the `domains` instruction represents the domain name matched by the virtual service host, used to represent the corresponding microservice instance name and address. In this invention, the `virtual_hosts` and `domains` instructions can be used to configure n virtual service hosts and at least n virtual service host domain names. Further, the `routes` instruction is configured in the Envoy gateway to generate a corresponding virtual service host `virtual_hosts` routing list. The core technical solution of this invention is: a redirection instruction `redirect` is configured in the Envoy gateway. This redirection instruction is used to redirect requests from external enterprise collaborative access requests. The `redirect` instruction includes target virtual host redirection `virtual_host_redirect` and target path redirection `path_redirect`, thereby redirecting the external enterprise collaborative access requests according to different paths and hosts. In this invention, all collaborative access requests from external enterprises are redirected via the Envoy gateway through the target virtual host (virtual_host_redirect) and the target path (path_redirect) to the microservice authentication space in an independent space, thereby effectively improving the security of collaborative task communication.
[0033] Furthermore, to obfuscate the path and host information of external collaborative access requests, this invention provides a random routing rule for microservice instances based on random weight allocation. The specific method includes the following steps:
[0034] When the Envoy gateway receives the enterprise collaborative access request, the Envoy gateway generates a RouteConfiguration abstract class, and the Envoy gateway is configured with a liveness status table of microservice instances. It randomly selects a microservice instance from the liveness status table to obtain the corresponding hostname, and selects the path of the corresponding hostname to redirect the enterprise collaborative access request through the path random weight configured in the RouteConfiguration abstract class. The path random weight is a dynamically updated weight parameter of the service host and the path.
[0035] Specifically, a random number generator is configured in the Envoy gateway. This generator generates floating-point random numbers between 0 and 1, and these random numbers are sequentially allocated to microservice instances and route lists according to the corresponding microservice registration information. Each route path and each microservice instance receives exactly one floating-point random number. Further, a weight calculation is performed based on the floating-point data allocated to each path and microservice instance. The calculation method includes defining the corresponding path as i, the corresponding microservice instance as j, and the corresponding floating-point random number as v. i The floating-point random number corresponding to the microservice instance is v. j The weight parameter from path i to microservice instance j is: F ij = The weight parameter F from path i to microservice instance j ij As random weights for allocation, the Envoy gateway's weighted allocation instruction selects the microservice instance j with the highest weight and its corresponding path i as the redirection target. It should be noted that the path i of the corresponding microservice instance and the corresponding microservice are associated, and this association can be obtained through the routes instruction in the Envoy gateway. The gateway's random number dynamic distribution can be set to be globally released at certain time intervals. Therefore, the above technical solution of this invention can effectively obfuscate path information during collaborative access, improving access security.
[0036] It is worth mentioning that, in this invention, when the microservice instance is successfully registered, each microservice instance establishes a communication connection with the resource nodes within the enterprise, and can establish collaborative authentication rules based on the metadata characteristics and collaborative task types within the enterprise. The metadata characteristics include, but are not limited to, metadata types and metadata attributes. The metadata types include, but are not limited to, text metadata, video metadata, audio metadata, or confidential metadata set based on metadata classification tags. The metadata attributes include, but are not limited to, metadata owner, metadata domain, metadata authentication status (certificationStatus), and metadata tags. The collaborative task types are used to control access permissions for external visitors, specifically including control over the access role itself and permission allocation for specific types of visitors. For example, when a specific role accesses, it is necessary to define the permissions for the entity type and operation type of the metadata for that specific role. For instance, the entity type of metadata can be, but is not limited to, a table, a dashboard, and a glossary term. The operation type of the metadata includes, but is not limited to, creation, reading, updating, and deletion operations. Since different collaboration types have different access permissions, this invention requires setting access permissions separately for each collaboration type. The authentication rules for these access permissions are encapsulated into an inheritable `Class` method, which is then sent to all microservice instances. Each microservice instance executes the corresponding collaboration access authentication operation based on the inheritable `Class` method. In other words, the inheritable `Class` method configures multiple verification items, including metadata type, metadata attributes, visitor information, and collaboration business type integration. The authentication rules define an authentication method that requires all verification items to meet the verification conditions.
[0037] For example: After the external enterprise's collaborative access request sends an access request to the redirection gateway, the redirection gateway randomly selects a first microservice instance as the redirection target. The authentication method of the first microservice instance for the enterprise's collaborative access request includes: obtaining the visitor name, collaboration type, access metadata type, metadata attributes, and metadata operations in the enterprise's collaborative access request, and verifying the verification items of the visitor name, access metadata type, metadata attributes, and metadata operations in the first microservice instance respectively. The verification method includes: field verification based on enumeration, obtaining the content of the collaborative access request, obtaining the field information in the request content, and comparing the field information with the field information stored in the collaborative authentication rules in the first service instance according to the authentication rules. If the authentication rules are met, the verification item of the corresponding field information is considered to have passed the verification. If at least one verification item does not meet the corresponding collaboration type verification rule, a verification failure message is returned to the redirection gateway, and the redirection gateway and service instance are disconnected. The first microservice instance sends a verification failure message to the enterprise's internal resource nodes.
[0038] To avoid security risks arising from potential hijacking of the microservice instance, upon receiving the verification failure message, the enterprise internal resource node regenerates a second random number, uses this second random number as the key, and stores the sequence number of the first microservice instance that failed verification as the key-value pair in the enterprise internal resource node's key-value pair. The node then sends the second random number to the first microservice instance that failed verification. The first microservice instance stores the second random number as a new verification code in itself. The redirection gateway receives new enterprise collaborative access requests and redirects these requests to a new second microservice instance using random routing. In another preferred embodiment of the invention, the enterprise internal resource node can dynamically allocate the second random number at specified time intervals, store the corresponding second random number and the corresponding microservice instance sequence number in a corresponding key-value pair, and send the second random number to the corresponding microservice instance using methods including but not limited to symmetric encryption, thereby significantly improving the security of the microservice instance.
[0039] When the first microservice instance verifies that the visitor name, collaboration type, accessed metadata type, metadata attributes, and metadata operations in the enterprise collaborative access request all meet the corresponding type of collaboration rules, the first microservice instance extracts the encrypted first random number and sends the encrypted first random number, the first microservice instance serial number, the visitor name, collaboration type, accessed metadata type, metadata attributes, and metadata operations to the enterprise internal resource node. The enterprise resource node decrypts the first random number and uses the decrypted first random number as the key to search for the corresponding key-value stored microservice serial number in the resource node for a second verification. If the key-value stored microservice serial number is the same as the first microservice serial number, the second verification passes, and the resource corresponding to the collaboration rule is sent to the first microservice instance; otherwise, the communication between the resource node and the first microservice instance is closed.
[0040] To achieve more efficient collaborative interaction, when the redirected enterprise collaborative access request is successfully authenticated, a collaborative authentication certificate is generated in the corresponding first microservice instance. This certificate includes a public key based on symmetric encryption, a public key attribute declaration, a digital signature, and a collaboration type. The public key attribute declaration is set according to the visitor name, accessed metadata type, metadata attributes, and metadata operation settings for the corresponding collaboration type. Upon successful initial verification of the collaborative task, the public key, public key attribute declaration, collaboration type, and digital signature are encrypted with the requested corresponding enterprise resource to obtain encrypted data. This encrypted data is then sent to the redirection gateway via the first microservice instance. The redirection gateway sends the encrypted data to the corresponding external collaborative enterprise. The external collaborative enterprise parses and saves the collaborative authentication certificate and uses it for subsequent collaborative access requests.
[0041] When an external collaborating enterprise sends a second collaborative access request to the same target enterprise, the corresponding collaborative authentication certificate is encrypted and encapsulated into the second collaborative access request. This request is then randomly routed to a new second microservice instance via the redirection gateway. The second microservice instance parses the collaborative authentication certificate in the second collaborative access request and determines whether the public key attribute declaration, collaborative type, and electronic signature in the collaborative authentication certificate are consistent with the declaration content and electronic signature of the corresponding type of collaborative authentication rule pre-stored by the microservice instance. If they are consistent, the verification passes; otherwise, communication with the redirection gateway is disconnected, and the verification code stored in the second microservice instance is updated in real time.
[0042] The processes described in the flowcharts above, as disclosed in the embodiments of this invention, can be implemented as computer software programs. The embodiments disclosed in this invention include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication component, and / or installed from a removable medium. When the computer program is executed by a central processing unit (CPU), the methods of this application are not limited to the aforementioned functions. It should be noted that the computer-readable medium described above in this application can be a computer-readable signal medium or a computer-readable storage medium, or any combination of the two. A computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections having one or more wire segments, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this application, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in connection with an instruction execution system, apparatus, or device. In this application, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium may be transmitted using any suitable medium, including but not limited to: wireless segments, wire segments, optical fibers, RF, etc., or any suitable combination thereof.
[0043] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0044] Those skilled in the art should understand that the embodiments of the present invention described above and shown in the accompanying drawings are merely examples and do not limit the present invention. The purpose of the present invention has been fully and effectively achieved. The functions and structural principles of the present invention have been shown and explained in the embodiments. Without departing from the stated principles, the implementation of the present invention may have any variations or modifications.
Claims
1. A method for collaborative optimization of enterprise resources in a smart industrial park, characterized in that, The method includes the following steps: Construct an independent microservice authentication space, generate n microservice instances with different paths within the microservice authentication space, obtain the serial number of each microservice instance, and send the microservice instance serial number to the resource nodes within the enterprise; The resource nodes within the enterprise dynamically generate n random numbers, store the n random numbers and the corresponding microservice serial number as key-value pairs in the resource nodes within the enterprise, and send the corresponding random number as a check code to the microservice instance with the corresponding serial number. Obtain metadata features and construct different enterprise collaborative authentication rules, then send the enterprise collaborative authentication rules to all microservice instances for storage; A collaborative access request from an enterprise is obtained, and the collaborative access request is randomly redirected to a first microservice instance. The first microservice instance parses the collaborative access request and authenticates the access request according to the enterprise collaborative authentication rules. After successful authentication, the first microservice instance establishes a communication connection with the corresponding internal resource node of the enterprise, and after secondary authentication by the internal resource node, sends the corresponding response message to the request through the temporary path of the first microservice instance. When the first microservice instance verifies that the visitor name, collaboration type, accessed metadata type, metadata attributes, and metadata operations in the enterprise collaborative access request all meet the corresponding collaboration rules, the first microservice instance extracts the encrypted first random number and sends the encrypted first random number, the first microservice instance serial number, the visitor name, collaboration type, accessed metadata type, metadata attributes, and metadata operations to the enterprise's internal resource nodes. The enterprise's internal resource nodes decrypt the first random number and use the decrypted first random number as the key to search for the corresponding key-value stored microservice serial number in the enterprise's internal resource nodes for a second verification. If the key-value stored microservice serial number is the same as the first microservice instance serial number, the second verification passes, and the resources corresponding to the collaboration rules are sent to the first microservice instance; otherwise, communication between the enterprise's internal resource nodes and the first microservice instance is closed.
2. The method for collaborative optimization of enterprise resources in a smart industrial park according to claim 1, characterized in that, The method includes: configuring a redirection gateway, wherein the redirection gateway obtains the path information of each microservice instance in all microservice authentication spaces and constructs corresponding random routing rules, wherein the random routing rules include: the redirection gateway obtains the sequence number and heartbeat data of each microservice instance, filters out the sequence numbers of surviving microservice instances, and randomly selects a microservice sequence number and path information as a redirection target, redirecting the enterprise collaborative access request to the first microservice instance, and the first microservice instance parses the request content after obtaining the enterprise collaborative access request.
3. The method for collaborative optimization of enterprise resources in a smart industrial park according to claim 2, characterized in that, The authentication method for the enterprise collaborative access request by the first microservice instance includes: obtaining the visitor name, collaboration type, access metadata type, metadata attributes, and metadata operations from the enterprise collaborative access request; verifying the verification items of the visitor name, access metadata type, metadata attributes, and metadata operations in the first microservice instance respectively; if at least one verification item does not meet the verification rules of the corresponding collaboration type, returning a verification failure message to the redirection gateway, disconnecting the redirection gateway and the service instance, and sending the verification failure message to the enterprise internal resource nodes.
4. The method for collaborative optimization of enterprise resources in a smart industrial park according to claim 3, characterized in that, After receiving the verification failure message, the enterprise internal resource node regenerates a second random number, uses the second random number as the key name, and stores the sequence number of the first microservice instance that failed verification as the key value in the key-value pair of the enterprise internal resource node. It then sends the second random number to the first microservice instance that failed verification. The first microservice instance stores the second random number as a new checksum in the first microservice instance. The redirection gateway receives the new enterprise collaborative access request and redirects the new collaborative access request to the new second microservice instance in a random routing manner.
5. The method for collaborative optimization of enterprise resources in a smart industrial park according to claim 2, characterized in that, The redirection gateway is an Envoy gateway. The microservice authentication space has n service hosts, each with a different service path. The n microservice instances are each set up on one of the n different service hosts. When the Envoy gateway receives the enterprise collaborative access request, it generates a RouteConfiguration abstract class. The Envoy gateway is configured with a liveness status table for the microservice instances. It randomly selects a microservice instance from the liveness status table to obtain the corresponding hostname, and uses the path random weight configured in the RouteConfiguration abstract class to select the path corresponding to the hostname for redirection of the enterprise collaborative access request. The path random weight is a dynamically updated weight parameter for the service host and the path.
6. The method for collaborative optimization of enterprise resources in a smart industrial park according to claim 2, characterized in that, When the redirected enterprise collaborative access request is successfully authenticated, a collaborative authentication certificate is generated in the corresponding first microservice instance. The collaborative authentication certificate includes a public key based on symmetric encryption, a public key attribute declaration, a collaboration type, and a digital signature. The public key attribute declaration is set according to the visitor name, accessed metadata type, metadata attributes, and metadata operation settings of the corresponding collaboration type. When the collaborative task is successfully verified for the first time, the authentication certificate containing the public key, public key attribute declaration, collaboration type, and digital signature, along with the requested corresponding enterprise resource, is encrypted to obtain encrypted data. This encrypted data is then sent to the redirection gateway through the first microservice instance. The redirection gateway sends the encrypted data to the corresponding external collaborative enterprise. The external collaborative enterprise parses and saves the collaborative authentication certificate and uses it for subsequent collaborative access requests.
7. The method for collaborative optimization of enterprise resources in a smart industrial park according to claim 6, characterized in that, When an external collaborating enterprise sends a second collaborative access request to the same target enterprise, the corresponding collaborative authentication certificate is encrypted and encapsulated into the second collaborative access request. This request is then randomly routed to a new second microservice instance via the redirection gateway. The second microservice instance parses the collaborative authentication certificate in the second collaborative access request and determines whether the public key attribute declaration, collaborative type, and electronic signature in the collaborative authentication certificate are consistent with the declaration content and electronic signature of the corresponding type of collaborative authentication rule pre-stored by the microservice instance. If they are consistent, the verification passes; otherwise, communication with the redirection gateway is disconnected, and the verification code stored in the second microservice instance is updated in real time.
8. A smart industrial park enterprise resource collaborative optimization system, characterized in that, The system executes a smart park enterprise resource collaborative optimization method as described in any one of claims 1-7.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, which is executed by a processor to implement a smart park enterprise resource collaborative optimization method as described in any one of claims 1-7.