Authorization authentication method and device based on capability open gateway, equipment and medium

By introducing authorization and authentication of the user terminal between the calling server and the capability exposure gateway and generating authorization codes and tokens, the problem of the caller obtaining user privacy information at will is solved, and the security protection of user privacy information is achieved.

CN120602106APending Publication Date: 2025-09-05CHINA UNITED NETWORK COMM GRP CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410245171.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-04
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

In the existing technology, the caller can arbitrarily call the user information interface or parameters to obtain the user's private information, resulting in a lack of authorization protection for the user's private information and a risk of leakage.

Method used

The authorization and authentication process of the user terminal is introduced between the calling server and the capability exposure gateway. By obtaining user information and target subscription services, an authorization code and authorization token are generated to ensure that the caller can access the target subscription service interface only after user authorization.

Benefits of technology

It implements double verification of the caller, avoids unauthorized interface calls, improves the security of user privacy information, and prevents privacy information leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602106A_ABST
    Figure CN120602106A_ABST
Patent Text Reader

Abstract

The invention provides an authorization authentication method and device based on a capability open gateway, equipment and a medium, and is specifically applied to the technical field of authorization authentication. According to the method, a user terminal is introduced in the process that a calling server completes authorization authentication in the mode that a capacity opening gateway is connected with a service interface, the authentication process of a user on the calling server is added, in the calling process of the service interface, the gateway can verify authorization information sent by the user and intercept unauthorized requests, and the service interface of the calling server is not authorized. The calling action of the calling server for correspondingly calling the service interface can be completed after the user is authorized, and the problem that the user privacy information is lack of authorization protection due to the fact that a calling party randomly calls the interface or parameters to obtain the user privacy information is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application belongs to the field of authorization and authentication technology, and specifically relates to an authorization and authentication method, apparatus, device, and medium based on a capability exposure gateway. Background Art

[0002] Cloud computing is an internet-based computing method that allows users to access and use shared computing resources and services over the network. Capability exposure refers to a mechanism by which a system or organization provides a set of services that are accessible and usable, either internally or externally. This openness allows users and other entities (such as developers, consumers, and operators) to leverage these services to achieve specific goals. A capability exposure platform, based on cloud computing technology, allows enterprises to share their business capabilities and resources with other enterprises and developers through open application programming interfaces (APIs) and data. It aims to provide a unified, secure output interface that integrates multiple system interfaces, enabling the exposure of external capabilities and internal service integration.

[0003] The caller uses the capability exposure gateway to transfer business data between the caller and the business interface. A gateway is a device that connects two or more networks, acting as both an entry and exit point for data transfer between them. Gateway authentication is the identity verification process performed within the gateway device to ensure that only authenticated callers can access the gateway and connect to the target network through it. Security protocols and technologies are typically used during gateway authentication to protect user identity information and communication data.

[0004] However, the gateway authentication mechanism only considers the authentication of both the caller and the gateway, and only verifies the permissions for process calls. For some interfaces containing sensitive information or business parameters that require invocation through a request, the gateway does not verify the authorization information before the call, failing to intercept unauthorized requests. The interface or parameter is then open to the caller without restriction, allowing the caller to freely access the interface or parameter to obtain user privacy information. This lack of authorization protection for user privacy information may lead to leakage of user privacy information. Summary of the Invention

[0005] The present application provides an authorization and authentication method, apparatus, device, and medium based on a capability exposure gateway, which is used to solve the defects in the prior art that the caller can arbitrarily call the user information interface or parameters to obtain user privacy information, and the user privacy information lacks authorization protection, thereby leading to the leakage of user privacy information.

[0006] In a first aspect, the present application provides an authorization and authentication method based on a capability exposure gateway, which is applied to a calling server, and the method includes:

[0007] Obtaining a service subscription request sent by a user terminal, wherein the service subscription request includes: user information and target subscription service;

[0008] Sending the user information, the target subscription service, and the identity information of the calling server to the capability opening gateway, so that the capability opening gateway authenticates the calling server according to the identity information, and authenticates and authorizes the user corresponding to the user terminal according to the user information and the target subscription service;

[0009] Obtaining an authorization code sent by the capability opening gateway, where the authorization code is generated by the capability opening gateway after the user authentication and authorization are passed;

[0010] Generate an authorization token request according to the authorization code and the identity information, and send the authorization token request to the capability opening gateway.

[0011] In a second aspect, the present application provides an authorization and authentication method based on a capability exposure gateway, which is applied to the capability exposure gateway. The method includes:

[0012] Obtaining user information, target subscription service, and identity information of the calling server sent by the calling server, and performing authentication processing on the calling server based on the identity information;

[0013] After the calling server passes the authentication, an authorization request is sent to the user terminal so that the user terminal jumps to the authorization page and completes the authorization process;

[0014] Acquire authorization information sent by the user terminal, the authorization information including: the user's authorization identifier for the target subscription service and the authorization validity period;

[0015] generating an authorization code corresponding to the target subscription service based on the authorization identifier and the authorization validity period, and sending the authorization code to the calling server, so that the calling server generates an authorization token request based on the authorization code and the identity information;

[0016] The authorization token request sent by the calling server is obtained, and according to the authorization token request, a corresponding authorization token is sent to the calling server, wherein the authorization token is used to enable the calling server to call a service interface corresponding to the target subscription service.

[0017] Optionally, the obtaining the authorization information sent by the user terminal includes:

[0018] Obtaining user identity verification information sent by the user terminal, and performing verification processing on the user according to the user identity verification information;

[0019] After the user verification is passed, sending an identity verification pass response to the user terminal;

[0020] The authorization information sent by the user terminal is obtained, where the authorization information includes: an authorization identifier of the user for the target subscription service and an authorization validity period.

[0021] In a third aspect, the present application provides an authorization and authentication method based on a capability exposure gateway, which is applied to a user terminal. The method includes:

[0022] Obtaining a service subscription request sent by a user and sending the service subscription request to a calling server, wherein the service subscription request includes: user information and target subscription service;

[0023] Obtain the authorization request sent by the capability exposure gateway, and display the authorization page according to the authorization request;

[0024] The authorization information entered by the user on the authorization page is obtained, and the authorization information is sent to the capability opening gateway so that the capability opening gateway generates an authorization code according to the authorization information. The authorization information includes: the authorization identifier of the target subscription service and the authorization validity period.

[0025] Optionally, obtaining authorization information entered by the user on the authorization page and sending the authorization information to the capability exposure gateway includes:

[0026] Obtaining user identity verification information entered by the user on the authorization page, and sending the user identity verification information to the capability opening gateway, so that the capability opening gateway verifies the user according to the user identity verification information;

[0027] After determining that the user verification has passed, the authorization information entered by the user on the authorization page is obtained, and the authorization information is sent to the capability exposure gateway.

[0028] In a fourth aspect, the present application provides an authorization and authentication device based on a capability exposure gateway, which is applied to a calling server, and includes:

[0029] An acquisition module is used to acquire a service subscription request sent by a user terminal, wherein the service subscription request includes user information and a target subscription service;

[0030] a sending module, configured to send the user information, the target subscription service, and the identity information of the calling server to a capability opening gateway, so that the capability opening gateway performs authentication processing on the calling server according to the identity information, and performs authentication and authorization processing on the user corresponding to the user terminal according to the user information and the target subscription service;

[0031] The acquisition module is further configured to acquire an authorization code sent by the capability opening gateway, where the authorization code is generated by the capability opening gateway after the user authentication and authorization are passed;

[0032] The sending module is further configured to generate an authorization token request according to the authorization code and the identity information, and send the authorization token request to the capability opening gateway.

[0033] In a fifth aspect, the present application provides an authorization and authentication device based on a capability exposure gateway, which is applied to the capability exposure gateway, and the device includes:

[0034] An acquisition module, configured to acquire user information, target subscription services, and identity information of the calling server sent by the calling server;

[0035] An authentication module, configured to authenticate the calling server based on the identity information;

[0036] The sending module is used to send an authorization request to the user terminal after the calling server authentication is passed, so that the user terminal jumps to the authorization page and completes the authorization process;

[0037] The acquisition module is further configured to acquire the authorization information sent by the user terminal, wherein the authorization information includes: the authorization identifier of the user for the target subscription service and the authorization validity period;

[0038] The sending module is further configured to generate an authorization code corresponding to the target subscription service based on the authorization identifier and the authorization validity period, and send the authorization code to the calling server, so that the calling server generates an authorization token request based on the authorization code and the identity information;

[0039] The acquisition module is further configured to acquire the authorization token request sent by the calling server.

[0040] The sending module is further configured to send a corresponding authorization token to the calling server according to the authorization token request, wherein the authorization token is used to enable the calling server to call a service interface corresponding to the target subscription service.

[0041] Optionally, the acquisition module is further configured to acquire user identity verification information sent by the user terminal;

[0042] The authentication module is further configured to perform verification processing on the user according to the user identity verification information;

[0043] The sending module is further configured to send an identity verification pass response to the user terminal after the user verification passes.

[0044] In a sixth aspect, the present application provides an authorization and authentication device based on a capability exposure gateway, applied to a user terminal, the device comprising:

[0045] The acquisition module is used to obtain the service subscription request sent by the user;

[0046] A sending module, configured to send the service subscription request to a calling server, wherein the service subscription request includes: user information and target subscription service;

[0047] The acquisition module is further configured to acquire the authorization request sent by the capability exposure gateway;

[0048] A display module, configured to display an authorization page according to the authorization request;

[0049] The acquisition module is further used to obtain the authorization information entered by the user on the authorization page;

[0050] The sending module is further configured to send the authorization information to the capability opening gateway so that the capability opening gateway generates an authorization code according to the authorization information. The authorization information includes: an authorization identifier of the target subscription service and an authorization validity period.

[0051] Optionally, the acquisition module is further configured to acquire user identity verification information entered by the user on the authorization page, and send the user identity verification information to the capability opening gateway, so that the capability opening gateway performs verification processing on the user according to the user identity verification information;

[0052] The acquisition module is further configured to acquire the authorization information entered by the user on the authorization page after determining that the user verification has passed.

[0053] In a seventh aspect, the present application provides an authorization and authentication device based on a capability exposure gateway, comprising:

[0054] processor;

[0055] Memory;

[0056] wherein the memory stores computer-executable instructions;

[0057] The at least one processor executes the computer-executable instructions stored in the memory, so that the at least one processor executes the authorization and authentication method based on the capability exposure gateway as described in the first aspect and various possible implementations of the first aspect, the second aspect and various possible implementations of the second aspect, or the third aspect and various possible implementations of the third aspect.

[0058] In an eighth aspect, an embodiment of the present invention provides a readable storage medium on which a computer program is stored. When the computer program is executed by a processor, it is an authorization and authentication method based on a capability exposure gateway as described in the first aspect and various possible implementations of the first aspect, the second aspect and various possible implementations of the second aspect, or the third aspect and various possible implementations of the third aspect.

[0059] The present application provides an authorization and authentication method based on a capability exposure gateway. This method introduces a user terminal during the process of the calling server connecting to the service interface of the capability exposure gateway to complete the authorization and authentication, and adds the user's authentication process to the calling server. During the service interface call process, the gateway verifies the authorization information sent by the user and intercepts and processes unauthorized requests. This ensures that the calling action of the calling server corresponding to the calling service interface can only be completed after the user has authorized it, avoiding the problem that the caller arbitrarily calls the interface or parameters to obtain user privacy information, resulting in a lack of authorization protection for user privacy information. BRIEF DESCRIPTION OF THE DRAWINGS

[0060] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.

[0061] Figure 1 This is a scenario diagram of the authorization and authentication method based on the capability exposure gateway provided in this application;

[0062] Figure 2 This is an interactive diagram of the authorization and authentication method based on the capability exposure gateway provided by this application Figure 1 ;

[0063] Figure 3 This is an interactive diagram of the authorization and authentication method based on the capability exposure gateway provided by this application Figure 2 ;

[0064] Figure 4 This is a schematic diagram of the structure of the authorization and authentication device based on the capability exposure gateway provided by this application Figure 1 ;

[0065] Figure 5 Schematic diagram of the structure of the authorization and authentication device based on the capability exposure gateway provided in this application Figure 2 ;

[0066] Figure 6 Schematic diagram of the structure of the authorization and authentication device based on the capability exposure gateway provided in this application Figure 3 ;

[0067] Figure 7 This is a schematic diagram of the structure of the authorization and authentication device based on the capability exposure gateway provided in this application.

[0068] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION

[0069] To make the objectives, technical solutions, and advantages of this application more clear, the technical solutions in this application will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.

[0070] The terms "first," "second," "third," "fourth," and so forth (if any) in the description and claims of the present invention and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequential sequence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments of the present invention described herein can, for example, be implemented in sequences other than those illustrated or described herein.

[0071] In the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.

[0072] First, let’s explain the terms involved in this application:

[0073] Capability Exposure Platform: Capability exposure refers to a mechanism by which a system or organization provides a set of services that are accessible and usable, either internally or externally. This openness allows users and other entities (such as developers, consumers, and operators) to leverage these services to achieve specific goals. A capability exposure platform, based on cloud computing technology, allows enterprises to share their business capabilities and resources with other enterprises and developers through open APIs and data. It provides a unified, secure output interface that integrates multiple system interfaces, enabling both external capability exposure and internal service integration.

[0074] Gateway: A gateway is a device that connects two or more networks. It acts as both an ingress and egress point for data transmission between networks. The caller uses the capability exposure gateway to transfer business data between the caller and the business interface.

[0075] Gateway authentication: Gateway authentication is the process of identifying users within a gateway device to ensure that only authenticated callers can access the gateway and connect to the target network through the gateway. During gateway authentication, security protocols and technologies are typically used to protect user identity information and communication data.

[0076] At present, in the existing technology, when performing authentication and certification, usually only the authentication of the caller and the gateway is considered, in which only the authority of the process call is verified. For some interfaces containing sensitive information or business parameters that need to be called after a request, before the calling process, due to the lack of user authorization, the gateway will not verify the authorization information during the calling process and will not be able to intercept unauthorized requests. The interface or parameter will be open to the caller without restriction, and the caller can call this interface or parameter at will to obtain user privacy information, resulting in a lack of authorization protection for user privacy information and leakage of user privacy information. For example: taking the interface for obtaining user location through user information as an example, if the user location interface is open to the caller without restriction, the caller can call the user location interface at will to obtain the user's location information, thereby causing the defect of user privacy leakage.

[0077] To address the above issues, this application provides an authorization and authentication method based on a capability exposure gateway. Figure 1 Schematic diagram of the authorization and authentication method based on the capability exposure gateway provided in the embodiment of this application. Figure 1As shown, the interaction objects in this application include: user terminal 101, calling server 103, and capability exposure gateway 102. Among them, user terminal 101 is in communication with calling server 103 and capability exposure gateway 102, and capability exposure gateway 102 is in communication with calling server 103. When calling server 103 wants to call a service interface, it needs to first send a request to capability exposure gateway 102 so that capability exposure gateway 102 can authorize and authenticate the calling server 103. The interaction process between capability exposure gateway 102 and user terminal 101 can realize the user's authorization and authentication of calling server 103.

[0078] This method adds a user authorization process to the calling server during the authorization and authentication process. That is, during the calling process, the gateway verifies the authorization information sent by the user and intercepts unauthorized requests. At the same time, if the calling server wants to call the corresponding business interface, it must first ensure that the user has authorized the call action before making the call. This prevents the caller from arbitrarily calling interfaces or parameters to obtain user privacy information, resulting in the lack of authorization protection for user privacy information and the leakage of user privacy information, thereby improving the security of user privacy information.

[0079] The following specific embodiments describe in detail the technical solution of the present application and how the technical solution of the present application solves the above-mentioned technical problems. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be repeated in some embodiments. The embodiments of the present application will be described below in conjunction with the accompanying drawings.

[0080] Figure 2 This is an interactive diagram of the authorization and authentication method based on the capability exposure gateway provided in the embodiment of the present application. Figure 1 The interaction objects in this embodiment may include, for example, user terminals, calling servers, and capability exposure gateways. Figure 2 As shown, the authorization and authentication method based on the capability exposure gateway shown in this embodiment includes:

[0081] S101: A user terminal obtains a service subscription request from a user, where the service subscription request includes user information and a target subscription service.

[0082] The service subscription request includes: user information and target subscription service. The user information may be, for example, the user's user ID, user basic personal information, etc. The target subscription service is the subscription service that the user wants to subscribe to or process.

[0083] In this embodiment, when a user wants to order or process a target ordering service, the user may input a corresponding service ordering request through an ordering page displayed on the user terminal, and the user terminal obtains the service ordering request input by the user.

[0084] It is understandable that the target subscription service is a service product registered and created by the calling server based on the capability exposure gateway. Specifically:

[0085] Before this step, the calling server will first send a registration request to the capability exposure gateway. The registration request includes the registration information of the calling server. The capability exposure gateway registers and stores the registration information of the calling server according to the registration request.

[0086] After the calling server completes the registration operation on the capability exposure gateway, the calling server can create at least one application on the capability exposure gateway and subscribe to the relevant services set up on the capability exposure gateway according to the business interface of the application; the calling server then encapsulates the subscribed related services and pushes the encapsulated subscribed services to the application on the user terminal, thereby enabling the user to perform the subscription operation of the relevant services through the application on the user terminal.

[0087] S102: The user terminal sends the user information and the target subscription service to the calling server.

[0088] When the user terminal obtains the service subscription request, the user terminal will determine the calling server corresponding to the target subscription service according to the target subscription service in the service subscription request, and send the service subscription request to the calling server so that the calling server can perform authorization and authentication operations according to the service subscription request.

[0089] S103: The calling server sends the acquired user information, target subscription service, and identity information of the calling server to the capability exposure gateway.

[0090] After receiving the service subscription request, the calling server sends the service subscription request and its own identity information to the capability exposure gateway.

[0091] The identity information is used to enable the capability exposure gateway to determine whether the calling server is the corresponding authentication server. The identity information can be, for example: the application key obtained by the calling server when subscribing to the capability on the capability exposure gateway, the calling server identifier, the identification information of the corresponding application, and the interface information of the calling server, etc.

[0092] The purpose of sending its own identity information in this step is to enable the capability opening gateway to determine whether the calling server is an authentication server based on the identity information.

[0093] S104: The capability opening gateway performs authentication processing on the calling server according to the identity information.

[0094] The capability opening gateway pre-stores the registration information of multiple registered call servers. When the capability opening gateway obtains the identity information sent by the call server, the capability opening gateway can determine whether the call server is a registered call server based on the identity information. If so, it authenticates the call server.

[0095] The authentication process may include, for example, first authenticating the identity of the calling server by the capability opening gateway, and then authenticating whether the calling server has an association relationship with the target subscription service after the identity authentication is passed, that is, performing subscription service authentication.

[0096] Specifically: the identity authentication process can be, for example: the capability exposure gateway compares the registration information and identity information of the calling server. When the registration information and identity information match, it is determined that the identity authentication of the calling server is passed; when the registration information and identity information do not match, it is determined that the identity authentication of the calling server is failed, that is, the calling server authentication is failed.

[0097] The process of performing subscription service authentication may, for example, be as follows: the capability exposure gateway first obtains all subscribed services subscribed by the calling server, and determines whether the subscribed services include the target subscription service. If so, it is determined that the subscription service authentication of the calling server is passed, that is, it is determined that the calling server authentication is passed; if the subscribed services do not include the target subscription service, it indicates that the calling server has not subscribed to the target subscription service on the capability exposure gateway, that is, the calling server does not have the ability to call the service interface corresponding to the target subscription service. Therefore, it is determined that the subscription service authentication of the calling server has failed, that is, the calling server authentication has failed.

[0098] S105: After the calling server passes the authentication, the capability opening gateway sends an authorization request to the user terminal.

[0099] If the calling server passes authentication, it indicates that the calling server is a registered server on the capability exposure gateway and is qualified to call the service interface corresponding to the target subscription service through the capability exposure gateway. However, at this point, the calling server has not yet received the user's authorization information for calling this service interface, meaning that the calling server cannot currently directly call the service interface corresponding to the target subscription service. Therefore, the capability exposure gateway needs to send an authorization request to the user terminal so that the user can authorize the calling server to directly call the service interface corresponding to the target subscription service.

[0100] It is understandable that if the calling server fails authentication, the capability opening gateway will feedback authentication failure prompt information to the calling server and the user terminal, and will not send an authorization application to the user terminal.

[0101] S106: The user terminal displays an authorization page according to the authorization request and obtains the authorization information input by the user on the authorization page. The authorization information includes the authorization identifier of the user for the target subscription service and the authorization validity period.

[0102] S107: The user terminal sends the obtained authorization identifier of the target subscription service and the authorization validity period to the capability exposure gateway.

[0103] The authorization request may include, for example, the identification information of the calling server and the target subscription service. The authorization information may include, for example, the user's authorization identification for the target subscription service and the authorization validity period filled in by the user.

[0104] After receiving the authorization request, the user terminal can control the screen to jump to the corresponding authorization page according to the authorization request. The authorization page can, for example, display a control for the user to fill in the authorization information.

[0105] The user terminal can obtain the authorization information filled in by the user based on the authorization page, and send the authorization information to the capability opening gateway so that the capability opening gateway can authorize the calling server to call the service interface corresponding to the target subscription service based on the authorization information.

[0106] Optionally, if the authorization information entered by the user on the authorization page is not obtained within the preset time period or the authorization rejection information filled in by the user is obtained, the authorization process is terminated and the authorization failure information is fed back to the calling server, where the authorization failure information is used to indicate that the user is not authorized.

[0107] S108: The capability opening gateway generates an authorization code corresponding to the target subscription service according to the authorization identifier of the target subscription service and the authorization validity period.

[0108] Among them, after receiving the user authorization information, the capability exposure gateway retains and processes the authorization information.

[0109] When the calling server initiates a call application for the business interface corresponding to the application created by the calling server to the capability opening gateway based on the target subscription business, the capability opening gateway will generate a corresponding authorization code based on the retained user authorization information, and send the authorization code to the calling server, so that the calling server can complete the call operation of the business interface corresponding to the application to the capability opening gateway based on the authorization code.

[0110] S109: The capability opening gateway sends the authorization code to the calling server.

[0111] The authorization code is used to indicate that the user authorizes the calling server to directly call the service interface of the target subscription service corresponding to the authorization identifier within the authorization validity period.

[0112] If the capability exposure gateway receives the authorization information sent by the user terminal, it indicates that the user has agreed to allow the calling server to directly call the service interface of the target subscription service. Therefore, the capability exposure gateway can generate an authorization code corresponding to the target subscription service based on the authorization identifier and authorization validity period of the target subscription service and send the authorization code to the calling server.

[0113] S110: The calling server generates an authorization token request according to the authorization code and the identity information.

[0114] The authorization token request includes: the authorization identifier of the target subscription service, user authorization information, and the identity information of the calling server.

[0115] The authorization token request is used by the calling server to submit its identity information and authorization code to the capability exposure gateway, allowing the calling server to complete the call operation for the service interface corresponding to the target subscription service. The purpose of this step is to enable the capability exposure gateway to compare and confirm the calling server's identity information with the user's authorization information to confirm that the user authorization information corresponds to the service interface information required by the calling server.

[0116] S111: The calling server sends the authorization token application to the capability exposure gateway.

[0117] S112: The capability opening gateway sends the corresponding authorization token to the calling server according to the authorization token request.

[0118] The capability opening gateway may generate a corresponding authorization token according to the authorization token request, and send the authorization token to the calling server, so that the calling server calls the service interface corresponding to the target subscription service according to the authorization token.

[0119] The purpose of this step is to enable the calling server to carry the authorization token, and the capability opening gateway to open the service interface corresponding to the target subscription service to the calling server, so that the calling server can implement the calling operation on the service interface corresponding to the target subscription service.

[0120] It can be understood that the authorization token is randomly generated by the capability opening gateway at least once, and the validity period of the authorization token is set by the capability opening gateway. The random generation period and validity period of the authorization token are limited to the authorization period set by the user, that is, the capability opening gateway can only send the authorization token to the calling server and set a validity period for the authorization token during the validity period of the user authorization. After the validity period of the authorization token expires, the calling server will clear the stored authorization token and regenerate a new authorization token request based on the authorization code and identity information and send it to the capability opening gateway. The capability opening gateway will send the newly generated authorization token to the calling server. The calling server will use the new authorization token to continue calling the business interface corresponding to the target subscription business until the next authorization token expires. The above authorization token application process is repeated. After the user authorization validity period expires, the capability development gateway intercepts the authorization token application issued by the calling server, stops generating the authorization token for the calling server, and ends the open status of the business interface corresponding to the target subscription business to the calling server.

[0121] The purpose of randomly generating authorization tokens is to increase the security of the authorization and authentication process, and to authenticate the calling server at least once within the validity period of the user authorization.

[0122] The authorization and authentication method based on the capability exposure gateway provided in this embodiment introduces a user terminal in the process of the calling server completing authorization and authentication by connecting the service interface of the capability exposure gateway, thereby increasing the user's authentication process for the calling server. During the service interface calling process, the gateway verifies the authorization information sent by the user and intercepts and processes unauthorized requests, thereby ensuring that the calling action of the calling server corresponding to the calling service interface can only be completed after the user is authorized, thereby avoiding the problem that the caller arbitrarily calls the interface or parameters to obtain user privacy information, resulting in a lack of authorization protection for user privacy information.

[0123] Figure 3 This is an interactive diagram of the authorization and authentication method based on the capability exposure gateway provided in the embodiment of the present application. Figure 2 This embodiment is based on Figure 2 Based on the embodiment, the authorization and authentication method based on the capability exposure gateway is described in detail. Figure 3 As shown, the authorization and authentication method based on the capability exposure gateway shown in this embodiment includes:

[0124] S201: The user terminal obtains the user's service subscription request.

[0125] S202: The user terminal sends the service subscription request to the calling server, where the service subscription request includes user information and target subscription service.

[0126] S203: The calling server sends the acquired user information, target subscription service, and identity information of the calling server to the capability exposure gateway.

[0127] S204: The capability opening gateway performs authentication processing on the calling server according to the identity information.

[0128] S205: After successfully authenticating the calling server, the capability opening gateway sends an authorization request to the user terminal.

[0129] Among them, steps S201 to S205 are similar to the above steps S101 to S105 and will not be repeated here.

[0130] S206: The user terminal displays an authorization page according to the authorization request, and obtains user identity verification information entered by the user on the authorization page.

[0131] S207: The user terminal sends the acquired user identity verification information to the capability opening gateway.

[0132] The user identity verification is used by the capability exposure gateway to authenticate the identity of the user who subscribes to the service and determine whether the user has the service subscription capability. The user identity verification information may be, for example, the user's personal identity identifier, the user's personal contact information, and the like.

[0133] It is understandable that before requesting the user to perform an authorization operation, the capability opening gateway needs to authenticate the identity of the user to determine whether the user has the capability to subscribe to the target subscription service.

[0134] Therefore, a user identity verification box to be input may be displayed on the authorization page first, so that the user can input corresponding user identity verification information in the user identity verification box.

[0135] S208: The capability opening gateway verifies the user according to the user identity verification information.

[0136] S209: After the capability opening gateway verifies the user successfully, it sends an identity verification success response to the user terminal.

[0137] The capability opening gateway pre-stores user registration information of multiple users. When the capability opening gateway obtains the user identity verification information sent by the user terminal, it can perform identity verification on the user based on the user identity verification information and the pre-stored user registration information.

[0138] For example, the specific verification process may include: the capability exposure gateway determines whether there is user registration information among multiple users that matches the user's identity verification information. If so, it indicates that the user identity verification has passed, indicating that the user has the ability to subscribe to the target subscription service and has the ability to authorize the calling server. If not, it indicates that the user identity verification has failed, indicating that the user does not have the ability to subscribe to the target subscription service. In this case, the capability exposure gateway will not proceed with the subsequent authorization steps and will send a verification failure response to the user terminal, prompting the user to re-initiate verification or terminate the service subscription process.

[0139] When the capability opening gateway determines that the user has passed the verification, the capability opening gateway may send an identity verification pass response to the user terminal. The identity verification pass response is used to prompt the user to authorize the calling server.

[0140] It is understandable that after the user terminal obtains the identity verification pass response, the authorization page will synchronously display the authorization information input box to be entered, so that the user can enter the corresponding authorization information in the input box.

[0141] S210: The user terminal obtains the authorization information input by the user on the authorization page, where the authorization information includes the user's authorization identifier for the target subscription service and the authorization validity period.

[0142] S211: The user terminal sends the obtained authorization identifier of the target subscription service and the authorization validity period to the capability opening gateway.

[0143] S212: The capability opening gateway generates an authorization code corresponding to the target subscription service according to the authorization identifier of the target subscription service and the authorization validity period.

[0144] S213: The capability opening gateway sends the authorization code to the calling server.

[0145] S214: The calling server generates an authorization token request according to the authorization code and the identity information.

[0146] S215: The calling server sends the authorization token application to the capability exposure gateway.

[0147] S216: The capability opening gateway sends the corresponding authorization token to the calling server according to the authorization token request.

[0148] Among them, steps S210 to S216 are similar to the above-mentioned steps S107 to S112 and will not be repeated here.

[0149] The authorization and authentication method based on the capability exposure gateway provided in this embodiment introduces the authorization and authentication of the user terminal in the process of the calling server completing the authorization and authentication in the capability exposure gateway connecting to the service interface, so that the capability exposure gateway performs identity authentication processing on the user using the user terminal. At the same time, when the calling server calls the service interface, after the user authorization, after obtaining the authorization code through the capability exposure gateway, the call is carried out with the authorization code and the identity information of the calling server, thereby realizing that the gateway can realize dual verification of the caller and user authorization.

[0150] Figure 4 Schematic diagram of the structure of the authorization and authentication device based on the capability exposure gateway provided in this application Figure 1 , which is used to call the server. Figure 4 As shown, the authorization and authentication device 300 based on the capability exposure gateway provided in this embodiment includes:

[0151] An acquisition module 301 is configured to acquire a service subscription request sent by a user terminal, wherein the service subscription request includes user information and a target subscription service.

[0152] A sending module 302 is configured to send the user information, the target subscription service, and the identity information of the calling server to a capability opening gateway, so that the capability opening gateway authenticates the calling server according to the identity information, and authenticates and authorizes the user corresponding to the user terminal according to the user information and the target subscription service;

[0153] The acquisition module 301 is further configured to acquire an authorization code sent by the capability opening gateway, where the authorization code is generated by the capability opening gateway after the user authentication and authorization are passed;

[0154] The sending module 302 is further configured to generate an authorization token request according to the authorization code and the identity information, and send the authorization token request to the capability opening gateway.

[0155] Figure 5 Schematic diagram of the structure of the authorization and authentication device based on the capability exposure gateway provided in this application Figure 2 , the device is used in capability exposure gateway. Figure 5 As shown, the authorization and authentication device 400 based on the capability exposure gateway provided in this embodiment includes:

[0156] Acquisition module 401, used to acquire user information, target subscription service and identity information of the calling server sent by the calling server;

[0157] Authentication module 402, used to authenticate the calling server according to the identity information;

[0158] The sending module 403 is used to send an authorization request to the user terminal after the calling server authentication is passed, so that the user terminal jumps to the authorization page and completes the authorization process;

[0159] The acquisition module 401 is further configured to acquire the authorization information sent by the user terminal, the authorization information including: the user's authorization identifier for the target subscription service and the authorization validity period;

[0160] The sending module 403 is further configured to generate an authorization code corresponding to the target subscription service based on the authorization identifier and the authorization validity period, and send the authorization code to the calling server, so that the calling server generates an authorization token request based on the authorization code and the identity information;

[0161] The acquisition module 401 is further configured to acquire the authorization token request sent by the calling server.

[0162] The sending module 403 is further configured to send a corresponding authorization token to the calling server according to the authorization token request, wherein the authorization token is used to enable the calling server to call a service interface corresponding to the target subscription service;

[0163] Optionally, the acquisition module 401 is further configured to acquire user identity verification information sent by the user terminal;

[0164] The authentication module 402 is further configured to perform verification processing on the user according to the user identity verification information;

[0165] The sending module 403 is further configured to send an identity verification success response to the user terminal after the user verification is passed.

[0166] Figure 6 Schematic diagram of the structure of the authorization and authentication device based on the capability exposure gateway provided in this application Figure 3 , the device is applied to the user terminal. Figure 6 As shown, the authorization and authentication device 500 based on the capability exposure gateway provided in this embodiment includes:

[0167] Acquisition module 501, used to acquire a service subscription request sent by a user;

[0168] The sending module 502 is used to send the service subscription request to the calling server, wherein the service subscription request includes: user information and target subscription service;

[0169] The acquisition module 501 is further configured to acquire the authorization request sent by the capability exposure gateway;

[0170] Display module 503, used to display the authorization page according to the authorization request;

[0171] The acquisition module 501 is further used to obtain the authorization information entered by the user on the authorization page;

[0172] The sending module 502 is further configured to send the authorization information to the capability opening gateway so that the capability opening gateway generates an authorization code according to the authorization information, wherein the authorization information includes: an authorization identifier of the target subscription service and an authorization validity period;

[0173] Optionally, the acquisition module 501 is further configured to acquire user identity verification information entered by the user on the authorization page, and send the user identity verification information to the capability exposure gateway, so that the capability exposure gateway performs verification processing on the user according to the user identity verification information;

[0174] The acquisition module 501 is specifically configured to acquire the authorization information entered by the user on the authorization page after determining that the user verification has passed.

[0175] Figure 7 This is a schematic diagram of the structure of the authorization and authentication device based on the capability exposure gateway provided in this application. Figure 7 As shown, the present application provides an authorization and authentication device based on a capability exposure gateway. The authorization and authentication device 600 based on a capability exposure gateway includes: a receiver 601 , a transmitter 602 , a processor 603 and a memory 604 .

[0176] Receiver 601, for receiving instructions and data;

[0177] Transmitter 602, used to send instructions and data;

[0178] Memory 604, for storing computer-executable instructions;

[0179] The processor 603 is configured to execute the computer-executable instructions stored in the memory 604 to implement the steps executed by the various execution entities of the authorization and authentication method based on the capability exposure gateway in the above embodiment. For details, please refer to the relevant description in the above embodiment of the authorization and authentication method based on the capability exposure gateway.

[0180] Optionally, the memory 604 may be independent or integrated with the processor 603 .

[0181] When the memory 604 is independently provided, the electronic device further includes a bus for connecting the memory 604 and the processor 603 .

[0182] The present application also provides a computer-readable storage medium, which stores computer-executable instructions. When a processor executes the computer-executable instructions, it implements the authorization and authentication method based on the capability exposure gateway as performed by the authorization and authentication device based on the capability exposure gateway as described above.

[0183] It will be appreciated by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementations, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As is well known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable, and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media include, but are not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those skilled in the art that communication media generally embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.

[0184] Those skilled in the art will readily appreciate other embodiments of the present application after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present application that follow the general principles of the present application and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, and the true scope and spirit of the present application are indicated by the following claims.

[0185] It should be understood that the present application is not limited to the exact structure described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof. The scope of the present application is limited only by the appended claims.

Claims

1. An authorization and authentication method based on capability exposure gateway, characterized in that: Applied to calling a server, the method includes: Obtaining a service subscription request sent by a user terminal, wherein the service subscription request includes: user information and target subscription service; Sending the user information, the target subscription service, and the identity information of the calling server to the capability opening gateway, so that the capability opening gateway authenticates the calling server according to the identity information, and authenticates and authorizes the user corresponding to the user terminal according to the user information and the target subscription service; Obtaining an authorization code sent by the capability opening gateway, where the authorization code is generated by the capability opening gateway after the user authentication and authorization are passed; Generate an authorization token request according to the authorization code and the identity information, and send the authorization token request to the capability opening gateway.

2. An authorization and authentication method based on capability exposure gateway, characterized in that: Applied to a capability exposure gateway, the method includes: Obtaining user information, target subscription service, and identity information of the calling server sent by the calling server, and performing authentication processing on the calling server based on the identity information; After the calling server passes the authentication, an authorization request is sent to the user terminal so that the user terminal jumps to the authorization page and completes the authorization process; Acquire authorization information sent by the user terminal, the authorization information including: the user's authorization identifier for the target subscription service and the authorization validity period; generating an authorization code corresponding to the target subscription service based on the authorization identifier and the authorization validity period, and sending the authorization code to the calling server, so that the calling server generates an authorization token request based on the authorization code and the identity information; The authorization token request sent by the calling server is obtained, and according to the authorization token request, a corresponding authorization token is sent to the calling server, wherein the authorization token is used to enable the calling server to call a service interface corresponding to the target subscription service.

3. The method according to claim 2, characterized in that The obtaining of the authorization information sent by the user terminal includes: Obtaining user identity verification information sent by the user terminal, and performing verification processing on the user according to the user identity verification information; After the user verification is passed, sending an identity verification pass response to the user terminal; The authorization information sent by the user terminal is obtained, where the authorization information includes: an authorization identifier of the user for the target subscription service and an authorization validity period.

4. An authorization and authentication method based on capability exposure gateway, characterized in that: Applied to a user terminal, the method includes: Obtaining a service subscription request sent by a user and sending the service subscription request to a calling server, wherein the service subscription request includes: user information and target subscription service; Obtain the authorization request sent by the capability exposure gateway, and display the authorization page according to the authorization request; The authorization information entered by the user on the authorization page is obtained, and the authorization information is sent to the capability opening gateway so that the capability opening gateway generates an authorization code according to the authorization information. The authorization information includes: the authorization identifier of the target subscription service and the authorization validity period.

5. The method according to claim 4, characterized in that The obtaining the authorization information entered by the user on the authorization page and sending the authorization information to the capability exposure gateway includes: Obtaining user identity verification information entered by the user on the authorization page, and sending the user identity verification information to the capability opening gateway, so that the capability opening gateway verifies the user according to the user identity verification information; After determining that the user verification has passed, the authorization information entered by the user on the authorization page is obtained, and the authorization information is sent to the capability exposure gateway.

6. An authorization and authentication device based on a capability exposure gateway, characterized in that: Applied to calling the server, including: An acquisition module is used to acquire a service subscription request sent by a user terminal, wherein the service subscription request includes user information and a target subscription service; a sending module, configured to send the user information, the target subscription service, and the identity information of the calling server to a capability opening gateway, so that the capability opening gateway performs authentication processing on the calling server according to the identity information, and performs authentication and authorization processing on the user corresponding to the user terminal according to the user information and the target subscription service; The acquisition module is further configured to acquire an authorization code sent by the capability opening gateway, where the authorization code is generated by the capability opening gateway after the user authentication and authorization are passed; The sending module is further configured to generate an authorization token request according to the authorization code and the identity information, and send the authorization token request to the capability opening gateway.

7. An authorization and authentication device based on capability exposure gateway, characterized in that: Applied to capability exposure gateways, including: An acquisition module, configured to acquire user information, target subscription services, and identity information of the calling server sent by the calling server; An authentication module, configured to authenticate the calling server based on the identity information; The sending module is used to send an authorization request to the user terminal after the calling server authentication is passed, so that the user terminal jumps to the authorization page and completes the authorization process; The acquisition module is further configured to acquire the authorization information sent by the user terminal, wherein the authorization information includes: the authorization identifier of the user for the target subscription service and the authorization validity period; The sending module is further configured to generate an authorization code corresponding to the target subscription service based on the authorization identifier and the authorization validity period, and send the authorization code to the calling server, so that the calling server generates an authorization token request based on the authorization code and the identity information; The acquisition module is further configured to acquire the authorization token request sent by the calling server. The sending module is further configured to send a corresponding authorization token to the calling server according to the authorization token request, wherein the authorization token is used to enable the calling server to call a service interface corresponding to the target subscription service; The acquisition module is also used to obtain the user identity verification information sent by the user terminal The authentication module is further configured to perform verification processing on the user according to the user identity verification information; The sending module is further configured to send an identity verification pass response to the user terminal after the user verification passes.

8. An authorization and authentication device based on a capability exposure gateway, characterized in that: Applied to user terminals, including: The acquisition module is used to obtain the service subscription request sent by the user; A sending module, configured to send the service subscription request to a calling server, wherein the service subscription request includes: user information and target subscription service; The acquisition module is further configured to acquire the authorization request sent by the capability exposure gateway; A display module, configured to display an authorization page according to the authorization request; The acquisition module is further configured to acquire authorization information entered by the user on the authorization page and send the authorization information to the capability exposure gateway so that the capability exposure gateway generates an authorization code based on the authorization information, wherein the authorization information includes: an authorization identifier of the target subscription service and an authorization validity period; The acquisition module is further configured to acquire user identity verification information entered by the user on the authorization page, and send the user identity verification information to the capability exposure gateway, so that the capability exposure gateway performs verification processing on the user according to the user identity verification information; The acquisition module is further configured to acquire the authorization information entered by the user on the authorization page after determining that the user verification has passed.

9. An authorization and authentication device based on a capability exposure gateway, characterized in that: include: Memory; processor; wherein the memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the authorization and authentication method based on the capability opening gateway according to any one of claims 1 to 5.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the authorization and authentication method based on the capability exposure gateway according to any one of claims 1 to 5.