Access control method and device, storage medium and program product

Through the collaborative efforts of the management side, the service side, and the client side, the basic information and control levels of microservices are obtained and converted, which solves the problem of insufficient granularity of access control between microservices and realizes refined access control.

CN120602139APending Publication Date: 2025-09-05AGRICULTURAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510716759.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-30
Publication Date
2025-09-05

AI Technical Summary

Technical Problem

Traditional access control technologies fail to distinguish the hierarchical differences between calls between microservices, resulting in insufficient granularity of access control and inability to achieve precise protection between microservices.

Method used

The basic information and control level of microservices are obtained through the management device, which is converted into control configuration by the server device. The access rights between microservices are determined by the client device to achieve precise access control.

Benefits of technology

It achieves precise access permission control at different levels between microservices, meeting the refined security management needs under complex microservice architecture.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120602139A_ABST
    Figure CN120602139A_ABST
Patent Text Reader

Abstract

The invention discloses an access control method and device, a storage medium and a program product, and the method is applied to an access control system, and comprises the steps: obtaining micro-service basic information and micro-service management and control levels of at least two micro-services through a management end device, the micro-service basic information and the micro-service management and control level are transmitted to the server-side device through the management-side device; the micro-service basic information and the micro-service management and control level are converted into management and control configuration of each micro-service through the server device, and the management and control configuration is transmitted to the client device; and determining the access authority of the access among the micro-services through the client device based on the management and control configuration. According to the embodiment of the invention, the management and control configuration is generated based on the micro-service basic information and the micro-service management and control level, and the access permissions of different levels among the micro-services can be accurately determined through the management and control configuration, so that the problem of insufficient access control granularity among the micro-services in a traditional scheme is solved; and the requirements on refined safety management under a complex micro-service architecture can be met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data processing, and in particular to an access control method, device, storage medium and program product. Background Art

[0002] Driven by cloud computing, microservice architectures have become mainstream due to their lightweight and scalable advantages. However, the complexity of service call relationships places higher demands on access control. Traditional access control technologies fail to distinguish between the hierarchical levels of calls between microservices, resulting in insufficient granularity in access control between microservices and inability to achieve precise protection between microservices. Therefore, providing an access control method that can implement hierarchical access control between microservices has become a pressing technical challenge in the data processing field. Summary of the Invention

[0003] The present invention provides an access control method, device, storage medium and program product, which solves the problem of insufficient granularity of access control between microservices in traditional solutions and can meet the needs of refined security management under complex microservice architectures.

[0004] In one aspect of an embodiment of the present invention, an access control method is provided, which is applied to an access control system. The access control system includes: a management terminal device, a server terminal device, and a client terminal device; the method includes:

[0005] Obtaining microservice basic information and microservice control levels of at least two microservices through the management end device, and transmitting the microservice basic information and microservice control levels to the service end device through the management end device;

[0006] Convert the basic information of microservices and the control level of microservices into the control configuration of each microservice through the server device, and transmit the control configuration to the client device;

[0007] The access rights between microservices are determined by the client device based on the control configuration.

[0008] Another aspect of an embodiment of the present invention provides a device, including:

[0009] at least one processor;

[0010] and a memory communicatively coupled to the at least one processor;

[0011] The memory stores a computer program that can be executed by at least one processor, and the computer program is executed by at least one processor so that the at least one processor can execute the access control method of any embodiment of the present invention.

[0012] Another aspect of an embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores:

[0013] Computer instructions, the computer instructions are used to enable a processor to execute the access control method of any embodiment of the present invention.

[0014] Another aspect of the present invention provides a computer program product, the computer program product comprising:

[0015] A computer program, wherein the computer program is executed by a processor to implement the access control method of any embodiment of the present invention.

[0016] In an embodiment of the present invention, the microservice basic information and microservice control levels of at least two microservices are obtained through a management-end device, and the microservice basic information and microservice control levels are transmitted to a server-end device through the management-end device; the microservice basic information and microservice control levels are converted into control configurations for each microservice through the server-end device, and the control configurations are transmitted to a client device; and the access rights for access between each microservice are determined based on the control configurations by the client device. In an embodiment of the present invention, a control configuration is generated based on the microservice basic information and the microservice control levels. The control configuration can accurately determine the access rights at different levels between microservices, thereby solving the problem of insufficient granularity of access control between microservices in traditional solutions and meeting the demand for refined security management under complex microservice architectures.

[0017] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0018] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0019] Figure 1 This is a flow chart of an access control method provided according to the first embodiment of the present invention;

[0020] Figure 2 This is a flow chart of another access control method provided according to the second embodiment of the present invention;

[0021] Figure 3 This is a flowchart of a method for setting a microservice control level according to Embodiment 3 of the present invention;

[0022] Figure 4 This is a flowchart of a method for generating a microservice management and control configuration according to Embodiment 3 of the present invention;

[0023] Figure 5 This is a flowchart of a method for verifying access rights between microservices according to Embodiment 3 of the present invention;

[0024] Figure 6 This is a flowchart of another method for verifying access rights between microservices according to the third embodiment of the present invention;

[0025] Figure 7 This is a flowchart of a management and control configuration synchronization method provided according to embodiment three of the present invention;

[0026] Figure 8 This is a structural diagram of an access control system provided according to Embodiment 3 of the present invention;

[0027] Figure 9 This is a structural diagram of another access control system provided according to the fourth embodiment of the present invention;

[0028] Figure 10 This is a block diagram of a device for executing an access control method provided in Embodiment 5 of the present invention. DETAILED DESCRIPTION

[0029] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0030] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0031] Example 1

[0032] Figure 1This is a flowchart of an access control method provided in the first embodiment of the present invention. The embodiment of the present invention is applicable to the situation where hierarchical control of access rights between microservices is performed. The method can be executed by an access control system, which can be implemented in the form of hardware and / or software. The access control system can be configured and integrated into any device that provides access control functions. Figure 1 As shown, the method includes:

[0033] S110: Obtain microservice basic information and microservice control levels of at least two microservices through the management end device, and transmit the microservice basic information and microservice control levels to the service end device through the management end device.

[0034] Among them, the management end device refers to a component used to store and push microservice configuration information. For example, the microservice configuration information may include microservice basic information and microservice control level, etc. The management end device provides an operation entry and a communication interface. The operation entry provided by the management end device can be used to perform operations to modify the microservice configuration information, and the communication interface provided by the management end device can be used to implement data interaction with the server device and / or client device. There are no restrictions on the type of operation entry provided by the management end device and the communication protocol used when the management end device interacts with the server device and / or client device through the communication interface. Optionally, in some embodiments, the management end device may also include an information acquisition module, a level setting module, and an information push module, etc., wherein the configuration information of the microservice can be obtained through the information acquisition module, the control level of the microservice can be adjusted through the level setting module, and the configuration information can be transmitted to other devices or modules through the information push module.

[0035] Microservice basic information can be understood as a series of data used to describe the static properties of a microservice. For example, microservice basic information may include the microservice name, microservice version, the name of the system to which the microservice belongs, or the name of the module to which the microservice belongs. By obtaining the microservice basic information of each microservice, you can understand the hierarchical relationship between microservices.

[0036] Microservice control levels can be understood as a hierarchical system that categorizes access control levels between microservices. For example, microservice control levels may include system-level control, module-level control, interface-level control, and no control. The microservice control level can be configured based on actual needs through the user interface in the management device. All microservices within the same application system or functional module have the same microservice control level.

[0037] Specifically, the configuration information of the microservice is obtained through the management-end device, and the configuration information includes at least the microservice basic information and the microservice control level, and the configuration information such as the microservice basic information and the microservice control level is transmitted to the server-end device through the communication interface in the management-end device. Optionally, in some embodiments, the configuration information of the microservice can be registered in the management-end device by the microservice provider, or in the microservice grid architecture, the management-end device can obtain the configuration information of the microservice through the application program interface that connects to the service grid. Optionally, in some embodiments, when the configuration information such as the microservice basic information and the microservice control level is transmitted to the server-end device, a failure reconnection mechanism is supported to ensure reliable data transmission. It can be understood that the failure reconnection mechanism can be supported for data interaction in this application, and it will not be repeated in the following steps.

[0038] S120: Convert the microservice basic information and the microservice control level into the control configuration of each microservice through the server-side device, and transmit the control configuration to the client device.

[0039] Among them, the server-side device serves as a connection hub connecting the management-side device and the client-side device, and can be used to receive the microservice configuration information transmitted by the management-side device and transmit the generated control configuration to the client-side device. The server-side device can also provide the same communication interface as the management-side device, and the communication interface is also used to interact with other devices for data. Optionally, in some embodiments, the server-side device may also include an information receiving module, a control configuration generation module, and a control configuration push module, among others, wherein the microservice basic information and microservice control level transmitted by the management-side device can be received through the information receiving module, the microservice basic information and microservice control level can be converted into the control configuration of the microservice through the control configuration generation module, and the control configuration can be transmitted to other devices or modules through the control configuration push module.

[0040] Control configuration refers to a series of structured data used to perform permission verification when calling microservices. For example, the data format of control configuration can include: key-value pairs or lists.

[0041] Specifically, the server receives the microservice basic information and microservice control level transmitted by the management device through the communication interface of the server device, encapsulates the received microservice basic information and microservice control level, obtains the corresponding control configuration, and transmits the control configuration to the client device through the communication interface. For example, the encapsulation of the microservice basic information and microservice control level may include: configuring a control configuration generation rule or using a trained control configuration generation model for encapsulation.

[0042] Optionally, in some embodiments, the server-side device may encapsulate the control configuration as a message. The message format may be JSON or other formats, which are not limited in the embodiments of the present invention. The message may be published to the topic corresponding to the message queue. Other devices receive the control configuration by listening to the messages of the corresponding topic, thereby ensuring the timeliness of data transmission. It is understood that data interaction in this application can be implemented in the form of a message queue, which will not be repeated in the following steps.

[0043] S130. Determine access rights between microservices based on the control configuration through the client device.

[0044] Among them, the client device refers to the device responsible for the interaction between the user and the microservice. In the microservice architecture, the client device can be responsible for initiating microservice access requests and interacting with the microservice to obtain the required services or data. The client device can also be responsible for executing access control logic and verifying the calling permissions between microservices. Optionally, in some embodiments, the client device may also include an information acquisition module, a control configuration loading module and an access permission control module, wherein the control configuration transmitted to the server device is received through the information acquisition module, the control configuration is transmitted to the access permission control module through the control configuration loading module, and the access permission control module determines the access permission between each microservice based on the control configuration. Optionally, in some embodiments, the client device can be associated with a log system to record the results of each permission check in the log system, which can be used for subsequent system security management.

[0045] Specifically, the client device receives the control configuration pushed by the server device, and based on the received control configuration, the client device determines the different levels of access permissions for the consumer microservice when accessing the provider microservice. Optionally, in some embodiments, the client device can record each determined permission level in a log system for subsequent system security management.

[0046] In an embodiment of the present invention, the microservice basic information and microservice control levels of at least two microservices are obtained through a management-end device, and the microservice basic information and microservice control levels are transmitted to a server-end device through the management-end device; the microservice basic information and microservice control levels are converted into control configurations for each microservice through the server-end device, and the control configurations are transmitted to a client device; and the access rights for access between each microservice are determined based on the control configurations by the client device. In an embodiment of the present invention, a control configuration is generated based on the microservice basic information and the microservice control levels. The control configuration can accurately determine the access rights at different levels between microservices, thereby solving the problem of insufficient granularity of access control between microservices in traditional solutions and meeting the demand for refined security management under complex microservice architectures.

[0047] Optionally, an access control method mentioned in an embodiment of the present invention may be optimized. Specifically, the following steps may be included: setting the microservice control level of each microservice through the application programming operation interface provided by the management end device; the microservice control level includes at least: system-level control, module-level control, interface-level control and no control.

[0048] Among them, the application programming operation interface is an operation interface provided by the management end device, which is used for external systems or users to set the microservice control level through programming to achieve the update of the microservice control level. For example, the interface type of the application programming operation interface suitable for the microservice architecture can be an HTTP interface and / or a TCP interface, etc., which is not limited by the embodiments of the present invention. Optionally, in some embodiments, the management end device can also be equipped with a graphical interface, through which the microservice control level of the microservice can be manually set.

[0049] Specifically, through the application programming operation interface provided by the management-end device, the management-end device can obtain the adjustment instruction of the microservice control level, and the management-end device can parse the instruction to obtain the target microservice identity and target control level, determine the target microservice that needs to be adjusted according to the target microservice identity, and determine the target control level to which the target microservice needs to be adjusted according to the target control level.

[0050] Optionally, an access control method mentioned in an embodiment of the present invention may be optimized. Specifically, the method may further include the following steps: obtaining, through a management-end device, microservice system information, microservice functional module information, and microservice control levels of all microservices in an existing access control system, and transmitting the microservice system information, microservice functional module information, and microservice control levels to a server-end device; determining, through the server-end device, the application system to which each microservice belongs according to the system keyword in the microservice system information, and determining the functional module to which each microservice belongs according to the module keyword in the microservice functional module information; obtaining, through the server-end device, actual adjustment requirements, and adjusting the microservice control levels of microservices belonging to the same application system or the same functional module to new microservice control levels of the same level according to the actual adjustment requirements; using, through the server-end device, the microservice identity of each microservice as a key, the new microservice control level corresponding to the microservice identity as an associated value of the key, and mapping the key and the associated value one-to-one to form a key-value pair as a new control configuration for each microservice; and transmitting, through the server-end device, the new control configuration to the management-end device and the client device.

[0051] Among them, the microservice belonging system information refers to the relevant information of the application system to which the microservice belongs. The relevant information may include the system name or system number, etc. The system name or system number can be used as a keyword to match the microservice belonging system information to determine the application system to which the microservice belongs in the microservice system architecture.

[0052] The microservice functional module information refers to the information related to the functional module to which the microservice belongs. The relevant information may include the module name or module number, etc. The module name or module number can be used as a keyword to match the microservice functional module information to determine the functional module to which the microservice belongs in the microservice system architecture.

[0053] System keywords refer to fields or strings used to identify and / or classify application systems. For example, the system keyword is the system name or a string of hash values ​​obtained by hashing the system name. By matching the system keyword with the microservice's system information, the application system to which the microservice belongs can be determined.

[0054] Module keywords refer to fields or strings used to identify and / or classify functional modules. For example, module keywords may include module names or a string of hash values ​​obtained by hashing the module names. By matching the module keywords with the microservice affiliation system information, the functional module to which the microservice belongs can be determined.

[0055] A microservice identity is an identifier used to uniquely identify a microservice. Each microservice in the microservice system architecture is assigned a unique microservice identity. This microservice identity uniquely identifies a microservice in the access control system for permission management and access control. Microservice identities can be divided into two categories: consuming microservice identities and providing microservice identities. The consuming microservice identity is used to identify the microservice initiating the call request, while the providing microservice identity is used to uniquely identify the microservice receiving the call request.

[0056] Specifically, the management end device obtains the microservice belonging system information, microservice belonging functional module information and microservice control level of all existing microservices in the microservice architecture, and transmits the obtained microservice belonging system information, microservice belonging functional module information and microservice control level to the server end device through the communication interface or message queue. The server end device extracts system keywords and module keywords from the microservice belonging system information and microservice belonging functional module information respectively. According to the system keywords and module keywords, the application system and functional module to which each microservice belongs can be determined. The actual adjustment requirements are obtained through the client device, and the application provided by the management end device is used according to the actual adjustment requirements. The program programming operation interface uniformly adjusts the microservice control levels of microservices belonging to the same application system or the same functional module to new microservice control levels. The new microservice control level and the corresponding microservice identity are transmitted to the server device through the management device through the communication interface or message queue. The server device uses the microservice identity of each microservice as the key, and the new microservice control level corresponding to the microservice identity as the associated value of the key. A key-value pair is formed by the one-to-one correspondence between the key and the associated value. The formed key-value pair is used as the new control configuration of each microservice. The new control configuration is transmitted to the management device and the client device through the server device, and the synchronization of the management configuration is completed.

[0057] Example 2

[0058] Figure 2 This is a flowchart of another access control method provided in Example 2 of the present invention. This embodiment of the present invention refines the above embodiment. Specifically, it refines the steps of how to generate a control configuration and how to determine the access rights between microservices based on the control configuration.

[0059] like Figure 2 As shown, the other access control method may include the following specific steps:

[0060] S210: Obtain microservice basic information and microservice control levels of at least two microservices through the management end device, and transmit the microservice basic information and microservice control levels to the service end device through the management end device.

[0061] S220: extract the microservice identity from the microservice basic information through the server-side device, use the microservice identity of each microservice as a key, and use the microservice control level corresponding to the microservice identity as an associated value of the key.

[0062] Specifically, the server-side device uses a query statement to extract the microservice identity from each microservice's basic information, or uses a corresponding parsing tool to parse the microservice basic information to extract the required microservice identity. Each microservice has a unique microservice identity and a unique microservice control level. A unique microservice control level can be determined based on each microservice's unique microservice identity. The microservice identity is used as the key, and the microservice control level is used as the associated value to form a key-value pair.

[0063] S230. Map keys and associated values ​​one by one through the server device to form key-value pairs for each microservice, and use the key-value pairs as management configuration.

[0064] Specifically, the keys and associated values ​​of microservices have a one-to-one correspondence. These keys and associated values ​​are mapped to form key-value pairs, which serve as the control configuration for each microservice. These control configurations can be transmitted to client devices using a communication protocol or message queue.

[0065] S240. Obtain microservice level information of each microservice through the client device. The service level information at least includes: microservice belonging system information and microservice belonging function module information.

[0066] Among them, microservice hierarchical information refers to the hierarchical affiliation information of microservices in the microservice system architecture. Microservice hierarchical information is used to determine the position of microservices in the entire microservice system architecture and to clarify the application system or functional module to which the microservices belong.

[0067] Specifically, the client device calls the operation interface provided by the management device and transmits the microservice identity. After receiving the microservice identity, the management device executes the corresponding query service, queries the corresponding microservice level information, and returns it to the client device. Optionally, in some embodiments, the client device may send a request for obtaining microservice level information to the communication interface of the management device. After receiving the request, the management device parses the request to obtain the microservice identity, queries the database or cache file corresponding to the microservice identity, obtains the corresponding microservice level information, and returns the queried microservice level information to the client device through the communication interface of the management device.

[0068] S250: Obtain a microservice access request through a client device, and locate a consuming microservice corresponding to the consuming microservice identifier carried in the microservice access request and a providing microservice corresponding to the providing microservice identifier.

[0069] Among them, a microservice access request refers to a call request initiated by a consumer microservice to a provider microservice. The microservice access request may include a series of key parameters for calling the microservice. For example, the key parameters may include: the consumer microservice identifier, the provider microservice identifier, the request content, or the requested operation.

[0070] A consuming microservice refers to a microservice that initiates a call request, that is, a microservice that needs to call services or data provided by other microservices. A consuming microservice has a unique consuming microservice identifier.

[0071] A providing microservice refers to a microservice that is called and / or receives a calling request, that is, a microservice that provides services or data. A providing microservice has a unique providing microservice identifier.

[0072] Specifically, the microservice access request initiated by the consumer microservice to the provider microservice is obtained through the communication interface of the client device. The client device is responsible for parsing each obtained microservice access request, extracting the consumer microservice identifier and the provider microservice identifier, and locating the consumer microservice that initiates the call request based on the extracted identifier, the consumer microservice identifier, and locating the microservice that initiates the call request based on the provider microservice identifier.

[0073] S260. Perform permission verification when the consuming microservice accesses the providing microservice based on the control configuration and service level information through the client device.

[0074] Specifically, the client device receives the control configuration transmitted by the server device and the service level information transmitted by the management device. When the consuming microservice accesses the providing microservice, the different levels of access rights of the consuming microservice when accessing the providing microservice are determined according to the control configuration and service level information of the consuming microservice and the providing microservice.

[0075] In an embodiment of the present invention, microservice basic information and microservice control levels of at least two microservices are obtained through a management-end device, and the microservice basic information and microservice control levels are transmitted to a server-end device through the management-end device. The microservice identity identifier in the microservice basic information is extracted through the server-end device, and the microservice identity identifier of each microservice is used as a key, and the microservice control level corresponding to the microservice identity identifier is used as an associated value of the key. The key and the associated value are mapped one-to-one to form a key-value pair for each microservice. The key-value pair is used as a control configuration, and the control configuration is transmitted to the client. The microservice level information and microservice access request of each microservice are obtained through the client device. The consuming microservice corresponding to the consuming microservice identifier carried in the microservice access request and the providing microservice corresponding to the providing microservice identifier are located through the microservice access request. According to the received control configuration and service level information, permission verification is performed when the consuming microservice accesses the providing microservice. The embodiments of the present invention unify the data storage format through key-value structured storage of microservice identity identifiers and microservice control levels, realize standardized data storage, and improve the subsequent query speed; by combining the control configuration and service level information, the control level configured by the microservice and the level to which it belongs can be accurately matched, thereby clarifying the multi-dimensional granularity of access between microservices, solving the problem of insufficient access control granularity between microservices in traditional solutions.

[0076] Optionally, in an embodiment of the present invention, step S260 may be further refined, specifically, the following steps may be included: extracting the consumption microservice control level corresponding to the consumption microservice identifier and the provision microservice control level corresponding to the provision microservice identifier from the control configuration through the client device; extracting the first application system name and the first functional module name corresponding to the consumption microservice and the second application system name and the second functional module name corresponding to the provision microservice from the microservice hierarchy information through the client device; determining through the client device that the consumption microservice control level and the provision microservice control level are system-level controls, matching the first application system name and the second application system name, and if the first application system name and the second application system name are different, confirming If the consuming microservice and the providing microservice belong to different application systems, a permission check will be performed when the consuming microservice accesses the providing microservice; if the microservice control level of the consuming microservice and the providing microservice is determined to be module-level control, the first module name and the second module name will be matched. If the first module name and the second module name are different, it is determined that the consuming microservice and the providing microservice belong to different functional modules, and a permission check will be performed when the consuming microservice accesses the providing microservice; if the microservice control level of the consuming microservice and the providing microservice is determined to be interface-level control, a permission check will be performed when the consuming microservice accesses the providing microservice; if the microservice control level of the consuming microservice and the providing microservice is determined to be no control, no control will be performed when the consuming microservice accesses the providing microservice.

[0077] The consuming microservice control level refers to the access level set for the consuming microservice, including four levels: interface-level control, module-level control, system-level control, and no control. This level defines the scope of control over the consuming microservice when it calls other microservices. For example, if the consuming microservice control level is system-level control, the consuming microservice can only call the providing microservice within the same system. If the consuming microservice control level is module-level control, the consuming microservice can only call the providing microservice within the same module.

[0078] The provider microservice control level refers to the access level set for the provider microservice. It is consistent with the consumer microservice control level type and also includes four levels: interface-level control, module-level control, system-level control, and no control. The provider microservice control level is used to define the scope of control when the provider microservice is called by other microservices.

[0079] The first application system name refers to the name of the application system that consumes the microservice, while the second application system name refers to the name of the application system that provides the microservice. Both the first and second application system names serve the same purpose, identifying the application system within the microservice architecture to which the microservice belongs. The first and second application system names can be matched or compared using methods such as regular expression matching or hash value comparison to determine whether the consuming and providing microservices belong to the same application system.

[0080] The first functional module name refers to the name of the functional module to which the consuming microservice belongs, and the second functional module name refers to the name of the functional module to which the providing microservice belongs. The first functional module name and the second functional module name serve the same purpose, identifying which application system in the microservice architecture the microservice belongs to. The first functional module name and the second functional module name can be matched or compared using methods such as regular expression matching or hash value comparison to determine whether the consuming microservice and the providing microservice belong to the same functional module.

[0081] Specifically, the client device receives the control configuration pushed by the server device, parses the received control configuration, matches the consumer microservice identifier with the parsed control configuration, and obtains the consumer microservice control level corresponding to the consumer microservice identifier, matches the provider microservice identifier with the parsed control configuration, and obtains the provider microservice control level corresponding to the provider microservice identifier; obtains the microservice hierarchy information through the client device, and extracts the first application system name and the first functional module name corresponding to the consumer microservice from the obtained microservice hierarchy information, and extracts the second application system name and the second functional module name corresponding to the provider microservice; when the consumer microservice control level and the provider microservice control level are system-level controls, the first application system name and the second application system name are matched by regular expression matching or hash value comparison, and if the first application system If the name of the first module and the name of the second module are different, it is determined to be a cross-system call, and a permission check is required when the consuming microservice accesses the providing microservice; when the microservice control level of the consuming microservice and the providing microservice is module-level control, the first module name and the second module name are matched by regular expression matching or hash value comparison. If the first module name and the second module name are different, it is determined to be a cross-module call, and a permission check is required when the consuming microservice accesses the providing microservice; when the microservice control level of the consuming microservice and the providing microservice is interface-level control, it is not allowed to check whether the consuming microservice and the consuming microservice belong to the same application system or the same functional module, and a permission check is performed directly when the consuming microservice accesses the consuming microservice; when the microservice control level of the consuming microservice and the providing microservice is no control, the permission check link is skipped, and the consuming microservice directly calls the providing microservice.

[0082] Optionally, the technical steps for performing permission verification when the consuming microservice accesses the providing microservice in the embodiment of the present invention may be further refined. Specifically, the following steps may be included: obtaining a subscription list for the consuming microservice to access the providing microservice through the management end device; obtaining a pre-configured interface authorization scope for the consumer microservice to access the providing microservice in the subscription list through the management end device, and executing the access operation of the consuming microservice to the providing microservice according to the interface authorization scope.

[0083] Among them, the subscription list refers to a list of information that stores the interface subscriptions of the microservice consumer to the provider, including information such as the name of the subscription interface or the interface authorization scope. The subscription list defines the legal scope of interface call permissions.

[0084] The interface authorization scope refers to the specific interface range pre-configured in the subscription list, through which the consumer microservice can access the provider microservice. The consumer microservice accesses the provider microservice through the interface of the provider microservice included in the interface authorization scope.

[0085] Specifically, when the consuming microservice and the providing microservice are cross-system calls, cross-module calls and / or the microservice management level is interface-level management, it is necessary to continue to verify whether the consuming microservice is within the interface range of the providing microservice access. The following steps can be performed: retrieve the subscription interface of the consumer microservice and the provider microservice from the subscription list through the management end device, confirm that the consumer microservice is within the interface authorization scope of calling the provider microservice interface, and allow the consumer microservice to call the provider microservice interface within the interface authorization scope.

[0086] Example 3

[0087] Figure 3 This is a flowchart of a method for setting a microservice control level according to Embodiment 3 of the present invention; Figure 4 This is a flowchart of a method for generating a microservice management and control configuration according to Embodiment 3 of the present invention; Figure 5 This is a flowchart of a method for verifying access rights between microservices according to Embodiment 3 of the present invention; Figure 6 This is a flowchart of another method for verifying access rights between microservices according to the third embodiment of the present invention; Figure 7 This is a flowchart of a management and control configuration synchronization method provided according to embodiment three of the present invention; Figure 8 This is a schematic diagram of the structure of an access control system provided by Example 3 of the present invention. This embodiment of the present invention is a refinement of the above-mentioned embodiment. Specifically, it refines the overall process of setting microservice control levels, the specific steps for generating microservice control configurations, the specific steps for performing permission verification when consuming microservices access providing microservices, and the specific steps for synchronizing control configurations.

[0088] like Figure 3 As shown, a method for setting the microservice control level may include the following specific steps: obtaining the microservice basic information and access control control level of the microservice in the management-end component through the query entrance provided by the management-end component; by obtaining the actual adjustment requirements of the microservice control level, the control level of the microservice can be modified in the operation entrance provided by the management-end component according to the actual adjustment requirements, and the modifiable control levels include: interface-level control, module-level control, system-level control and no control; sending the microservice control level and microservice basic information to the server-end component through the management-end component, wherein the data sending method includes using HTTP communication method or TCP communication method, and adopting a failed timed reconnection method when sending data until the data is successfully sent.

[0089] like Figure 4As shown, a method process for generating microservice management and control configuration may include the following specific steps: after adjusting the access control control level through the management-side component, trigger the server to obtain the microservice management and control level and store it on the server to provide a basis for subsequent management and control configuration generation, generate the management and control configuration through the server-side component, the key value of the management and control configuration contains the identity information of the microservice, and the value value is the microservice management and control level. The generated management and control level configuration is used for subsequent microservice consumer access control, and the generated microservice management and control configuration is transmitted to the client component.

[0090] like Figure 5 As shown, a method for performing permission verification when a consuming microservice accesses a providing microservice may include the following specific steps: querying the microservice level information of the microservice through the management component, obtaining the control configuration and microservice level information issued by the server component through the client component, and performing control permission verification when calling the provider, performing access permission verification through the client component according to the control configuration and microservice level information of each loaded microservice, and judging whether it has the permission to call the microservice provider, when the microservice control level of the consumer microservice is the same as the microservice control level of the providing microservice During system-level control, if the consumer microservice and the provider microservice belong to different systems, permission verification is required; when the microservice control level of the consumer microservice and the provider microservice are managed as module-level control, if the consumer microservice and the provider microservice belong to different modules, permission verification is required; when the microservice control level of the consumer microservice and the provider microservice are managed as interface control, permission verification is required; when the microservice control level of the consumer microservice and the provider microservice are managed as no control, permission verification is not required.

[0091] like Figure 6 As shown, another method for performing permission verification when a consuming microservice accesses a providing microservice may include the following specific steps: when the consuming microservice and the providing microservice belong to different systems, different modules, or the microservice control level is interface control, it is necessary to query the subscription relationship of the consuming microservice to access the providing microservice; based on the obtained subscription relationship and control configuration, determine the interface range corresponding to the consumer microservice calling the providing microservice.

[0092] like Figure 7As shown, a management and control configuration synchronization method may also include the following specific steps: batch obtaining the existing configuration information such as the application system information of the microservices under the existing system, the functional module information of the microservices, and the microservice control level through the application programming operation interface of the management-side component, determining the application system to which each of the microservices belongs based on the queried application system information of the microservices, determining the functional module to which each of the microservices belongs based on the queried functional module information of the microservices, adjusting the microservice control level of the microservices belonging to the same application system or the same functional module to a new microservice control level of the same level, using the microservice identity in the existing configuration information of each microservice as the key through the server-side component, using the new microservice control level corresponding to the microservice identity as the associated value of the key, and using the key-value pair formed by the key and the associated value as the new management and control configuration of each microservice; transmitting the new management and control configuration to the management-side component and the client component through the server-side component.

[0093] Figure 8 This is a schematic diagram of the structure of an access control system provided by the third embodiment of the present invention. Figure 8 As shown, the access control system specifically includes: a management-side component 310, a server-side component 320 and a client-side component 330. The management-side component 310 also includes a first information acquisition module 3101, a control level setting module 3102 and a control level push module 3103. The server-side component 320 also includes a second information acquisition module 3201, a configuration generation module 3202 and a configuration push module 3203. The client-side component 330 also includes: a third information acquisition module 3301, a configuration loading module 3302 and an access permission control module 3303.

[0094] The microservice hierarchy information and access control management level of the microservice are obtained through the first information acquisition module 3101, the management level of the microservice is modified through the management level setting module 3102, and the microservice management level and microservice hierarchy information are sent to the server component through the management level push module 3103.

[0095] The microservice control level and microservice hierarchy information are obtained and sent through the second information acquisition module 3201, the microservice control level and microservice hierarchy information are converted into control configuration through the configuration generation module 3202, and the generated control configuration is transmitted to the client component through the configuration push module 3203.

[0096] The control configuration is obtained through the third information acquisition module 3301, the control configuration is loaded through the configuration loading module 3302 and transmitted to the access permission control module 3303, and the access permission between microservices is determined based on the control configuration through the access permission control module 3303.

[0097] Example 4

[0098] Figure 9 This is a schematic diagram of the structure of another access control system provided by the fourth embodiment of the present invention. This embodiment is applicable to the situation where access rights between microservices are controlled in a hierarchical manner. The device can be implemented in software and / or hardware. The access control system can be integrated into any device that provides access control functions and can execute the access control method of any of the above embodiments. Figure 8 As shown, the access control system specifically includes: a management end device 410 , a server end device 420 and a client end device 430 .

[0099] The management end device 410 obtains microservice basic information and microservice control levels of at least two microservices, and transmits the microservice basic information and microservice control levels to the service end device 420 through the management end device 410;

[0100] The server device 420 converts the microservice basic information and the microservice control level into the control configuration of each microservice, and transmits the control configuration to the client device 430;

[0101] The access rights between the microservices are determined by the client device 430 based on the control configuration.

[0102] Optionally, the microservice control level of each microservice can be set through the application programming interface provided by the client device 430; the microservice control levels include at least: system-level control, module-level control, interface-level control and no control.

[0103] Optionally, the server-side device 420 also includes: an identification extraction module and a configuration formation module, wherein the identification extraction module extracts the microservice identity from the microservice basic information, and uses the microservice identity of each microservice as a key, and uses the microservice control level corresponding to the microservice identity as an associated value of the key; the configuration formation module maps the key and the associated value one by one to form a key-value pair for each microservice, and uses the key-value pair as the control configuration.

[0104] Optionally, the client device 430 also includes: a hierarchical information acquisition module, a microservice positioning module and a permission verification module, wherein the microservice hierarchical information of each microservice is obtained through the hierarchical information acquisition module, and the service hierarchical information at least includes: microservice belonging system information and microservice belonging functional module information; the microservice access request is obtained through the microservice positioning module, and the consuming microservice corresponding to the consuming microservice identifier carried by the microservice access request and the providing microservice corresponding to the providing microservice identifier are located; the permission verification module performs permission verification when the consuming microservice accesses the providing microservice according to the management and control configuration and service hierarchical information.

[0105] Optionally, the permission check also includes: a level extraction unit, a name determination unit, and a permission check unit.

[0106] Among them, the consumption microservice control level corresponding to the consumption microservice identifier and the provision microservice control level corresponding to the provision microservice identifier are extracted from the control configuration through the level extraction unit; the first application system name and the first functional module name corresponding to the consumption microservice and the second application system name and the second functional module name corresponding to the provision microservice are extracted from the microservice hierarchy information through the name determination unit; the consumption microservice control level and the provision microservice control level are determined to be system-level control through the permission verification unit, and the first application system name and the second application system name are matched. If the first application system name and the second application system name are different, it is determined that the consumption microservice and the provision microservice belong to different applications. If the system is used, permission verification will be performed when the consuming microservice accesses the providing microservice; if the microservice control level of the consuming microservice and the providing microservice is determined to be module-level control, the first module name and the second module name will be matched. If the first module name and the second module name are different, it is determined that the consuming microservice and the providing microservice belong to different functional modules, and permission verification will be performed when the consuming microservice accesses the providing microservice; if the microservice control level of the consuming microservice and the providing microservice is determined to be interface-level control, permission verification will be performed when the consuming microservice accesses the providing microservice; if the microservice control level of the consuming microservice and the providing microservice is determined to be no control, no control will be performed when the consuming microservice accesses the providing microservice.

[0107] Optionally, the permission verification unit may be used to obtain a subscription list for the consumer microservice to access the provider microservice; the management terminal device may obtain a pre-configured interface authorization scope for the consumer microservice to access the provider microservice in the subscription list, and the access operation of the consumer microservice to the provider microservice may be performed according to the interface authorization scope.

[0108] The access control system provided by the embodiment of the present invention can execute the access control method provided by any embodiment of the present invention, and has the corresponding beneficial effects of the execution method.

[0109] Example 5

[0110] A fifth embodiment of the present invention provides a device for executing an access control method, a computer-readable storage medium, and a computer program product.

[0111] Figure 10A schematic diagram of the structure of an apparatus that can be used to implement an embodiment of the present invention is shown. The apparatus is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The apparatus may also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown in the embodiments of the present invention, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the embodiments of the present invention described and / or required herein.

[0112] like Figure 10 As shown, the device includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by the at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the ROM 12 or the computer program loaded from the storage unit 18 into the RAM 13. Various programs and data required for the operation of the device can also be stored in the RAM 13. The processor 11, ROM 12 and RAM 13 are connected to each other via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.

[0113] Multiple components in the device are connected to the I / O interface 15, including an input unit 16, such as a keyboard, mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a magnetic disk, optical disk, etc.; and a communication unit 19, such as a network card, modem, wireless communication transceiver, etc. The communication unit 19 allows the device to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0114] The processor 11 can be any general-purpose and / or specialized processing component with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit, a graphics processing unit, various dedicated artificial intelligence computing chips, various processors running machine learning model algorithms, a digital signal processor, and any suitable processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the access control method.

[0115] In some embodiments, the access control method may be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed onto the device via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps based on the access control method may be performed. Alternatively, in other embodiments, processor 11 may be configured to implement the access control method in any other suitable manner (e.g., via firmware).

[0116] Various implementations of the systems and techniques described above in the embodiments of the present invention may be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays, application specific integrated circuits, application specific standard products, system-on-chip systems, load programmable logic devices, computer hardware, firmware, software, and / or combinations thereof. These various implementations may include: being implemented in one or more computer programs that are executable and / or interpreted on a programmable system including at least one programmable processor, which may be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0117] The computer programs for implementing the methods of the embodiments of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer programs are executed by the processor, the functions / operations specified in the flowcharts and / or block diagrams are implemented. The computer programs may be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0118] In the context of an embodiment of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. A computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, RAM, ROM, an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0119] To provide interaction with a user, the systems and techniques described herein can be implemented on a device having: a display device (e.g., a cathode ray tube or liquid crystal display monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0120] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include local area networks, wide area networks, blockchain networks, and the Internet.

[0121] A computing system may include clients and servers. The clients and servers are generally remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a host product within a cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosts and virtual private server services.

[0122] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.

[0123] The above specific embodiments do not constitute a limitation on the scope of protection of the embodiments of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.

Claims

1. An access control method, applied to an access control system, characterized in that: The access control system includes: a management terminal device, a server terminal device and a client terminal device; the method includes: Obtaining microservice basic information and microservice control levels of at least two microservices through the management end device, and transmitting the microservice basic information and the microservice control levels to the service end device through the management end device; Converting the microservice basic information and the microservice control level into a control configuration of each microservice through the server device, and transmitting the control configuration to the client device; The access rights for access between microservices are determined by the client device based on the control configuration.

2. The method according to claim 1, characterized in that The method further comprises: The microservice control level of each microservice is set through the application programming operation interface provided by the management end device; the microservice control level includes at least: system-level control, module-level control, interface-level control and no control.

3. The method according to claim 1, characterized in that The converting the microservice basic information and the microservice control level into the control configuration of each microservice by the server device includes: Extracting the microservice identity from the microservice basic information through the server-side device, using the microservice identity of each microservice as a key, and using the microservice control level corresponding to the microservice identity as an associated value of the key; The server-side device maps the key and the associated value one by one to form a key-value pair for each microservice, and uses the key-value pair as the control configuration.

4. The method according to claim 1, characterized in that Determining the access rights between microservices based on the control configuration by the client device includes: Acquiring, through the client device, microservice-level information of each microservice, wherein the service-level information includes at least: microservice-attribution system information and microservice-attribution function module information; Obtaining a microservice access request through the client device, and locating a consuming microservice corresponding to a consuming microservice identifier and a providing microservice corresponding to a providing microservice identifier carried in the microservice access request; The client device performs permission verification when the consuming microservice accesses the providing microservice according to the control configuration and the service level information.

5. The method according to claim 4, characterized in that: The performing, by the client device, permission verification when the consuming microservice accesses the providing microservice according to the control configuration and the service level information, includes: Extracting, by the client device, from the control configuration a consumption microservice control level corresponding to the consumption microservice identifier and a provisioning microservice control level corresponding to the provisioning microservice identifier; Extracting, by the client device, the first application system name and the first functional module name corresponding to the consuming microservice from the microservice hierarchical information, and extracting the second application system name and the second functional module name corresponding to the providing microservice; Determining, by the client device, that the consuming microservice control level and the providing microservice control level are system-level control, matching the first application system name with the second application system name; if the first application system name and the second application system name are different, determining that the consuming microservice and the providing microservice belong to different application systems, and performing permission verification when the consuming microservice accesses the providing microservice; Determine that the microservice control level of the consuming microservice and the providing microservice is module-level control, match the first module name and the second module name, and if the first module name and the second module name are different, determine that the consuming microservice and the providing microservice belong to different functional modules, and perform permission verification when the consuming microservice accesses the providing microservice; Determining that the microservice control level of the consuming microservice and the providing microservice is interface-level control, then performing permission verification when the consuming microservice accesses the providing microservice; If it is determined that the microservice control level of the consuming microservice and the providing microservice is no control, no control is performed when the consuming microservice accesses the providing microservice.

6. The method according to claim 5, characterized in that The performing of permission verification when the consuming microservice accesses the providing microservice includes: Obtaining, through the management end device, a subscription list of the consuming microservice to access the providing microservice; The management end device obtains a pre-configured interface authorization scope for the consumer microservice to access the provider microservice in the subscription list, and performs an access operation of the consumer microservice to the provider microservice according to the interface authorization scope.

7. According to claim 1, it is characterized in that The method further comprises: Obtaining, through the management end device, microservice belonging system information, microservice belonging function module information, and microservice control level of all microservices existing in the access control system, and transmitting the microservice belonging system information, the microservice belonging function module information, and the microservice control level to the server end device; Determining, by the server device, the application system to which each microservice belongs according to the system keyword in the microservice belonging system information, and determining the function module to which each microservice belongs according to the module keyword in the microservice belonging function module information; Acquiring actual adjustment requirements through the server-side device, and adjusting the microservice control levels of microservices belonging to the same application system or the same functional module to the same new microservice control level according to the actual adjustment requirements; The server-side device uses the microservice identity of each microservice as a key, uses the new microservice control level corresponding to the microservice identity as an associated value of the key, and performs a one-to-one mapping between the key and the associated value to form a key-value pair as a new control configuration for each microservice; The new control configuration is transmitted to the management device and the client device through the server device.

8. A device, characterized in that The device comprises: at least one processor; and a memory communicatively coupled to the at least one processor; The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the access control method according to any one of claims 1 to 7.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores: A computer instruction, wherein the computer instruction is used to enable a processor to implement the access control method according to any one of claims 1 to 7 when executed.

10. A computer program product, characterized in that The computer program product comprises: A computer program, which, when executed by a processor, implements the access control method according to any one of claims 1 to 7.