Signature system, data processing method, signature management method, device and medium

By using a cross-cloud architecture of public and private cloud servers, and determining the signature policy based on the mapping relationship, the system generates and verifies signature authorization information, which solves the security and management problems of the service authorization process, realizes flexible signature and effective access management, and improves the security and resource utilization efficiency of the cloud service platform.

CN120825291APending Publication Date: 2025-10-21CHANGCHUN DAYI GAMMA KNIFE TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510872709.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-26
Publication Date
2025-10-21

AI Technical Summary

Technical Problem

In existing technologies, the signature method of the service authorization process is simple and inflexible, easily cracked or imitated, has low security, fails to effectively manage the service access process, lacks security and traceability, and cannot detect and prevent unauthorized access in a timely manner.

Method used

The system employs information processing and management modules from public cloud servers. Based on the mapping relationship between service access requests and service interfaces of private cloud servers, it determines signature policies, generates authorization information carrying signatures, and verifies the signatures through private cloud servers. This enables flexible signing and effective management, supports fixed-item and random-item signature policies, and enhances security.

Benefits of technology

It improves the security and reliability of the cloud service platform, prevents unauthorized access, supports dynamic signatures, enhances data security, adapts to different types of medical business data needs, and improves resource utilization efficiency and service response efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120825291A_ABST
    Figure CN120825291A_ABST
Patent Text Reader

Abstract

The invention provides a signature system, a data processing method, a signature management method, equipment and a medium, relates to the technical field of computers, and is used for realizing flexible signature in a service authorization process, effectively managing a service access process and improving the security of a cloud service platform. The signature system comprises a client used for sending a service access request and / or a management instruction to a public cloud server; an information processing module of the public cloud server is used for determining a signature strategy according to the service access request and the mapping relationship, signing an item to be signed in the service access request based on the signature strategy, generating authorization information carrying a signature, and sending the authorization information to the client; the management module of the public cloud server is used for managing the signature strategy based on the management instruction; the client is also used for forwarding the authorization information to the private cloud server; and the private cloud server is used for verifying the signature in the authorization information from the client, and allowing access to the private cloud server when the verification is passed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a signature system, a data processing method, a signature management method, a device, and a medium. Background Art

[0002] Currently, the signature methods used in service authorization processes are often simple and inflexible, making them easily cracked or imitated, resulting in low security. Furthermore, the authorized service access process is often not effectively managed, lacking security and traceability, making it impossible to promptly detect and prevent illegal service access. Summary of the Invention

[0003] The present application provides a signature system, data processing method, signature management method, device and medium for realizing flexible signature in the service authorization process and effective management of the service access process, thereby improving the security of the cloud service platform.

[0004] In the first aspect, the present application provides a signature system, comprising: a client, a public cloud server and a private cloud server; the client is used to send a service access request and / or a management instruction to the public cloud server; the service access request is a request to access the private cloud server; the service access request includes at least one item to be signed; the public cloud server includes an information processing module and a management module; wherein the information processing module is used to respond to the service access request, and determine the signature policy based on the mapping relationship between the service access request and the service interface of the private cloud server to be accessed, sign the item to be signed in the service access request based on the signature policy, generate authorization information carrying the signature, and send it to the client; the management module is used to respond to the management instruction, and manage the signature policy based on the management instruction; the client is also used to receive authorization information and send the authorization information to the private cloud server; the private cloud server includes at least one service interface, the private cloud server is used to receive authorization information from the client, and verify the signature in the authorization information. When the verification passes, the client is allowed to access the private cloud server through the service interface corresponding to the service access request.

[0005] In some embodiments, a signature strategy is determined based on a mapping relationship between a service access request and a service interface of a private cloud server to be accessed, including: determining whether the signature strategy is a fixed-item signature strategy or a random-item signature strategy based on a mapping relationship between a service access request and a service interface of a private cloud server to be accessed.

[0006] In some embodiments, the items to be signed in the service access request correspond one-to-one to the preset signature items of the service interface of the private cloud server to be accessed; the fixed item signature strategy is a strategy for signing the items to be signed in the service access request according to the preset signature items to generate a first signature code; or, the random item signature strategy is a strategy for randomly signing one or more items to be signed in the service access request within the range of the preset signature items to generate a first signature code.

[0007] In some embodiments, the item to be signed includes at least one of: user information, request path, request method, request header, query parameter, and request body.

[0008] In some embodiments, the management instructions include at least one of the following: adding a signature policy corresponding to a preset signature item of the service interface of the private cloud server; deleting an existing signature policy corresponding to the service interface of the private cloud server; adjusting the items to be signed in the existing signature policy corresponding to the service interface of the private cloud server.

[0009] In some embodiments, the public cloud server also includes a gateway verification module, which is used to verify the legitimacy of service access requests or management instructions. When the verification passes, the information processing module is allowed to sign the service access request based on the signature policy, or the management module is allowed to manage the signature policy based on the management instruction.

[0010] In some embodiments, the authorization information carrying the signature includes: a first signature code, a signature code generation rule, a service access request, and an access address of a private cloud server.

[0011] In some embodiments, the private cloud server is used to receive authorization information from the client and verify the signature in the authorization information, including: the private cloud server generates a second signature code according to the signature code generation rule, compares the first signature code with the second signature code, and passes the verification if the comparison is consistent.

[0012] In some embodiments, the private cloud server includes multiple service interfaces, and the multiple service interfaces allow access to different types of data; the data is medical business data, and the types of medical business data include any one of the following: case type, examination type, and test type.

[0013] In a second aspect, the present application provides a data processing method, which is applied to any possible signature system as described in the first aspect. The data processing method includes: a client sends a service access request to a public cloud server, where the service access request is used to request access to a private cloud server; an information processing module of the public cloud server responds to the service access request, determines a signature strategy based on a mapping relationship between the service access request and the service interface of the private cloud server to be accessed, signs the items to be signed in the service access request based on the signature strategy, generates authorization information carrying the signature, and sends the signature to the client; the client receives the authorization information and sends the authorization information to the private cloud server; the private cloud server receives the authorization information from the client and verifies the signature in the authorization information. If the verification is successful, the client is allowed to access the private cloud server through the service interface corresponding to the service access request.

[0014] In some embodiments, a signature strategy is determined based on a mapping relationship between a service access request and a service interface of a private cloud server to be accessed, and signing the items to be signed in the service access request based on the signature strategy includes: determining whether the signature strategy is a fixed-item signature strategy or a random-item signature strategy based on a mapping relationship between the service access request and the service interface of the private cloud server to be accessed; when the signature strategy is a fixed-item signature strategy, signing the items to be signed in the service access request according to preset signature items to generate a first signature code; or, when the signature strategy is a random-item signature strategy, randomly signing one or more items to be signed in the service access request within the range of preset signature items to generate a first signature code.

[0015] In some embodiments, the item to be signed includes at least one of: user information, request path, request method, request header, query parameter, and request body.

[0016] In some embodiments, the public cloud server further includes a gateway verification module, which is used to verify the legitimacy of the service access request. When the verification passes, the information processing module is allowed to sign the service access request based on the signature policy.

[0017] In some embodiments, the authorization information carrying the signature includes: a first signature code, a signature code generation rule, a service access request, and an access address of a private cloud server.

[0018] In some embodiments, receiving authorization information from the client and verifying the signature in the authorization information includes: the private cloud server generates a second signature code according to a signature code generation rule, compares the first signature code with the second signature code, and passes the verification if the comparison is consistent.

[0019] In some embodiments, the private cloud server includes multiple service interfaces, and the multiple service interfaces allow access to different types of data; the data is medical business data, and the types of medical business data include any one of the following: case type, examination type, and test type.

[0020] In a third aspect, a signature management method is provided, which is applied to any possible signature system as described in the first aspect. The signature management method includes: a client sending a management instruction to a public cloud server; and a management module of the public cloud server managing a signature policy in response to the management instruction.

[0021] In some embodiments, the management instructions include at least one of the following: adding a signature policy corresponding to a preset signature item of the service interface of the private cloud server; deleting an existing signature policy corresponding to the service interface of the private cloud server; adjusting the items to be signed in the existing signature policy corresponding to the service interface of the private cloud server.

[0022] In some embodiments, the public cloud server further includes a gateway verification module, which is used to verify the legitimacy of the management instruction. When the verification passes, the management module is allowed to manage the signature policy based on the management instruction.

[0023] In a fourth aspect, the present application provides an electronic device comprising: a processor and a communication interface; the communication interface and the processor are coupled, and the processor is used to run a computer program or instruction to implement any possible data processing method as in the second aspect or any possible signature management method as in the third aspect.

[0024] In a fifth aspect, the present application provides a computer-readable storage medium having instructions stored therein, and when a computer executes the instructions, the computer executes any possible data processing method in the second aspect or any possible signature management method in the third aspect.

[0025] In a sixth aspect, the present application provides a computer program product comprising computer instructions, which, when executed on an electronic device, enables the electronic device to execute any possible data processing method as in the second aspect or any possible signature management method as in the third aspect.

[0026] These and other aspects of the present application will become more readily apparent from the following description.

[0027] The technical solution provided by this application brings at least the following beneficial effects:

[0028] In this application, the signature policy can be flexibly managed through the management module of the public cloud server, and the information processing module of the public cloud server can sign the items to be signed in the service access request based on the signature policy corresponding to the service interface of the private cloud server to be accessed by the service access request, so that the signature policy can be flexibly managed and flexible signature can be achieved.

[0029] In addition, through the cross-cloud architecture of public cloud server authorization and private cloud server authentication, the security and reliability of the cloud service authorization and authentication process can be guaranteed, the effective management of the service access process can be achieved, and the security of the cloud service platform can be improved.

[0030] Furthermore, while this application supports signing the pending items in service access requests based on preset signature items, it also supports signing the pending items in service access requests based on random items in the preset signature items. In this case, for two service access requests from the same client to the same service interface, the public cloud server can generate two different signatures based on the random item signature strategy, enabling dynamic signing of service access requests and thus generating dynamic authorization information. This makes it difficult for unauthorized access to obtain the correct signature strategy and forge signatures, effectively resisting attacks such as data theft and tampering, and improving the data security of the cloud service platform.

[0031] Furthermore, this application can support flexible management of the signature policy of the service interface in the private cloud server through management instructions according to business needs, such as deleting, adding or changing the signature policy of the service interface.

[0032] Furthermore, the name of the item to be signed in this application can be flexibly configured based on the user information or request information in the service access request, which can improve the flexibility of the signature strategy.

[0033] Furthermore, the service interface of the private cloud server in this application can provide services for different types of medical business data. By configuring different signature strategies for different types of medical business data, the service interface corresponding to the new medical business data can be quickly configured with a signature strategy corresponding to the targeted data type, effectively supporting the centralized deployment of service interfaces in the private cloud server, realizing efficient utilization of resources and rapid deployment of services, and providing the cloud service platform with response efficiency and stability when facing large-scale concurrent access or complex business logic, thereby meeting the needs of diverse medical business scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art.

[0035] Figure 1 A schematic diagram of the structure of a signature system provided in an embodiment of the present application;

[0036] Figure 2 A flowchart of a data processing method provided in an embodiment of the present application;

[0037] Figure 3 A schematic diagram of the structure of a data processing device provided in an embodiment of the present application;

[0038] Figure 4 A schematic structural diagram of another data processing device provided in an embodiment of the present application;

[0039] Figure 5 A schematic structural diagram of another data processing device provided in an embodiment of the present application;

[0040] Figure 6 A flowchart of a signature management method provided in an embodiment of the present application;

[0041] Figure 7 A schematic diagram of the structure of a signature management device provided in an embodiment of the present application;

[0042] Figure 8 A schematic diagram of the structure of another signature management device provided in an embodiment of the present application;

[0043] Figure 9 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application;

[0044] Figure 10 A schematic structural diagram of another electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0045] The following will describe in detail the signature system, data processing method, signature management method, device and medium provided in the embodiments of the present application in conjunction with the accompanying drawings.

[0046] Furthermore, the terms "including," "having," and any variations thereof, mentioned in the description of this application are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or units is not limited to the listed steps or units, but may optionally include other steps or units not listed, or may optionally include other steps or units inherent to the process, method, product, or apparatus.

[0047] It should be noted that in the embodiments of this application, words such as "exemplarily" or "for example" are used to indicate examples, illustrations, or explanations. Any embodiment or design described as "exemplarily" or "for example" in the embodiments of this application should not be interpreted as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplarily" or "for example" is intended to present the relevant concepts in a concrete manner.

[0048] The term "and / or" used in this application includes using either of the two methods or using both methods simultaneously.

[0049] The terms "first", "second" and "third" etc. in the description and drawings of this application are used to distinguish different objects, rather than to describe the specific order of the objects, nor do they indicate or imply relative importance or implicitly indicate the number of the indicated technical features.

[0050] In the description of the present application, unless otherwise specified, “plurality” means two or more.

[0051] The following briefly introduces the scenarios involved in a signature system, data processing method, signature management method, device and medium provided in the embodiments of the present application.

[0052] Currently, the signature methods used in service authorization processes are often simple and inflexible, making them easily cracked or imitated, resulting in low security. Furthermore, the authorized service access process is often not effectively managed and monitored, lacking security and traceability, making it impossible to promptly detect and prevent illegal service access.

[0053] Moreover, due to the lack of centralized allocation of cloud environments, it is difficult to achieve efficient resource utilization and rapid deployment of services. When faced with large-scale concurrent access or complex business logic, the system's response efficiency and stability are low.

[0054] In the signature system of the first aspect of the present application:

[0055] In order to improve the security of the cloud service authorization and authentication process, an embodiment of the present application provides a signature system.

[0056] As an example, Figure 1 , which is a schematic diagram of the structure of a signature system provided in an embodiment of the present application. Figure 1 The illustrated signature system 100 includes a client 101 , a public cloud server 102 , and a private cloud server 103 .

[0057] Client 101

[0058] Figure 1The client 101 is used to send service access requests and / or management instructions to the public cloud server 102.

[0059] For example, client 101 may be an application terminal for accessing a cloud service platform. A user may use client 101 to send a request (i.e., a service access request) to public cloud server 102 for accessing private cloud server 103 to obtain authorization from public cloud server 102. Furthermore, upon receiving authorization information from public cloud server 102, client 101 may send the authorization information to private cloud server 103.

[0060] The service access request includes at least one item to be signed, which can be any one of user information, request path, request method, request header, query parameter, and request body.

[0061] For another example, when the client 101 is a web page for managing a cloud service platform, the cloud administrator may send management instructions to the public cloud server 102 via the web page to manage the signature policy deployed in the public cloud server 102 .

[0062] Public cloud server 102

[0063] Figure 1 The public cloud server 102 includes an information processing module and a management module.

[0064] Among them, the information processing module is used to respond to the service access request from the client 101, determine the signature strategy based on the mapping relationship between the service access request and the service interface of the private cloud server 103 to be accessed, and sign the items to be signed in the service access request based on the signature strategy, generate authorization information carrying the signature, and send it to the client 101.

[0065] The management module is used to respond to management instructions and manage signature policies based on the management instructions.

[0066] Private Cloud Server 103

[0067] Figure 1 The private cloud server 103 in the example may include at least one service interface. The private cloud server 103 may be configured to receive authorization information from the client 101 and verify the signature in the authorization information. If the signature verification succeeds, the private cloud server 103 may allow the client 101 to access the private cloud server 103 through the service interface corresponding to the service access request. If the signature verification fails, the private cloud server 103 may deny the client 101 access to the private cloud server 103 through the service interface corresponding to the service access request.

[0068] Based on this, this application can improve the security and reliability of the cloud service authorization and authentication process through a cross-cloud architecture with authorization by the public cloud server 102 and authentication by the private cloud server 103.

[0069] In one embodiment, the signature policy includes two types of policies: a fixed-item signature policy and a random-item signature policy. The fixed-item signature policy can be used to indicate a preset signature item and sign the to-be-signed items in the service access request that correspond one-to-one with the preset signature items. The random-item signature policy can be used to indicate a preset signature item and select one or more preset signature items from the preset signature items and sign the to-be-signed items in the service access request that correspond to the selected one or more preset signature items.

[0070] For example, assume that the preset signature items indicated by the fixed-item signature policy and the random-item signature policy are all user information, request path, and request method. The fixed-item signature policy can be used to indicate that all three to-be-signed items in the service access request, namely, user information, request path, and request method, are to be signed. The random-item signature policy can be used to indicate that one or more preset signature items are randomly selected from the three preset signature items, namely, user information, request path, and request method, and that the to-be-signed items corresponding to the selected one or more preset signature items in the service access request are to be signed. The selected one or more preset signature items can be user information, user information and request path, request path and request method, etc.

[0071] Based on this, when the information processing module in public cloud server 102 determines the signature policy based on the mapping relationship between the service access request and the service interface of the private cloud server 103 to be accessed, it can determine whether the signature policy is a fixed-item signature policy or a random-item signature policy based on the mapping relationship between the service access request and the service interface of the private cloud server 103 to be accessed. Furthermore, the information processing module in public cloud server 102 can sign the to-be-signed items in the service access request based on the fixed-item signature policy or the random-item signature policy.

[0072] In one embodiment, the service interface of the private cloud server 103 may be configured with a corresponding pre-set signature item. The item to be signed in the service access request may correspond one-to-one with the pre-set signature item of the service interface of the private cloud server 103 to be accessed. In other words, the pre-set signature item configured for the service interface of the private cloud server 103 to be accessed by the service access request is the item to be signed in the service access request.

[0073] In this case, the fixed item signature strategy may be a strategy for signing the item to be signed in the service access request according to a preset signature item corresponding to the service interface to generate a first signature code.

[0074] Furthermore, the random item signature strategy may be a strategy for randomly selecting a preset signature item corresponding to the service interface, and signing one or more items to be signed in the service access request based on the randomly selected preset signature item to generate a first signature code.

[0075] For example, assume that the preset signature items corresponding to the service interface include user information, request header, and request body. The fixed-item signature strategy is a strategy that signs the corresponding items in the service access request based on the three preset signature items corresponding to the service interface: user information, request header, and request body, to generate a first signature code. The random-item signature strategy is a strategy that randomly selects from the three preset signature items corresponding to the service interface: user information, request header, and request body, and signs one or more items to be signed in the service access request based on the randomly selected preset signature item to generate a first signature code. The randomly selected preset signature item can be user information, user information and request header, request header and request body, etc.

[0076] In one embodiment, the management instructions may include at least one of the following: adding a signature policy corresponding to a preset signature item of the service interface of the private cloud server 103, deleting an existing signature policy corresponding to the service interface of the private cloud server 103, and adjusting the item to be signed in the existing signature policy corresponding to the service interface of the private cloud server 103.

[0077] In one embodiment, the public cloud server 102 may further include a gateway verification module. The gateway verification module is configured to verify the legitimacy of service access requests or management instructions. Furthermore, if the verification passes, the gateway verification module may allow the information processing module to sign the service access request based on the signature policy, or allow the management module to manage the signature policy based on the management instruction.

[0078] For example, a service access request or management instruction may include identity information. The gateway verification module may be used to verify the legitimacy of the identity information in the service access request or management instruction, obtain a verification result, and allow or deny access by the client 101 based on the verification result.

[0079] In one embodiment, the authorization information carrying the signature may include: a first signature code, a signature code generation rule, a service access request, and the access address of private cloud server 103. Based on this, client 101 can directly jump to private cloud server 103 based on the authorization information. If private cloud server 103 verifies the signature successfully, client 101 can access private cloud server 103 through the corresponding service interface. The signature code generation rule is a signature algorithm that indicates how to generate the first signature code.

[0080] Based on this, the private cloud server 103 is used to receive the authorization information from the client 101, and when verifying the signature in the authorization information, it can generate a second signature code according to the signature code generation rule in the authorization information, and compare the first signature code with the second signature code to further determine that the verification is passed if the comparison is consistent, or determine that the verification is failed if the comparison is inconsistent.

[0081] In this way, the private cloud server 103 can obtain the signature code generation rules used by the public cloud server 102 when signing through the client 101, and verify the signature in the authorization information, thereby achieving effective management and monitoring of the authorized service access process, improving security and traceability, and avoiding illegal service access.

[0082] In one embodiment, the management module can also be used to manage signature code generation rules.

[0083] In one embodiment, the management instruction may further include adjusting the signature code generation rules.

[0084] In one embodiment, the private cloud server 103 may include multiple service interfaces. These multiple service interfaces allow access to different types of data. That is, different service interfaces may provide access to different types of data. This data is medical service data and may include any of the following: case type, examination type, and test type.

[0085] In the data processing method of the second aspect of the present application:

[0086] In order to improve the security of the cloud service authorization and authentication process, an embodiment of the present application provides a data processing method that can be applied to a signature system.

[0087] The data processing method includes: the client sends a service access request to the public cloud server, and the service access request is used to request access to the private cloud server. The information processing module of the public cloud server responds to the service access request, determines the signature strategy based on the mapping relationship between the service access request and the service interface of the private cloud server to be accessed, signs the items to be signed in the service access request based on the signature strategy, generates authorization information carrying the signature, and sends it to the client. The client receives the authorization information and sends the authorization information to the private cloud server. The private cloud server receives the authorization information from the client and verifies the signature in the authorization information. If the verification is successful, the client is allowed to access the private cloud server through the service interface corresponding to the service access request.

[0088] This application enables flexible management of signature policies through the public cloud server's management module. Furthermore, the public cloud server's information processing module signs the items to be signed in the service access request based on the signature policy corresponding to the service interface of the private cloud server to be accessed by the service access request. This allows for flexible management of signature policies and flexible signing. Furthermore, through a cross-cloud architecture combining public cloud server authorization and private cloud server authentication, the cloud service authorization and authentication process can be secured and reliable, effectively managing the service access process and improving the security of the cloud service platform.

[0089] like Figure 2 FIG2 is a flow chart of a data processing method provided in an embodiment of the present application. The data processing method includes: S201-S204.

[0090] S201. The client sends a service access request to the public cloud server.

[0091] The service access request is used to request access to a private cloud server. Furthermore, the service access request may include at least one item to be signed. The item to be signed may be any one of user information, request path, request method, request header, query parameters, and request body.

[0092] For example, the client can be an application terminal for accessing a cloud service platform. The user can send a request for accessing a private cloud server (i.e., a service access request) to the public cloud server through the client to obtain authorization from the public cloud server, thereby further accessing the private cloud server.

[0093] S202. The information processing module of the public cloud server responds to the service access request, determines the signature strategy based on the mapping relationship between the service access request and the service interface of the private cloud server to be accessed, signs the items to be signed in the service access request based on the signature strategy, generates authorization information carrying the signature, and sends it to the client.

[0094] For example, a private cloud server may be configured with at least one service interface to provide access to different types of data. Furthermore, each service interface may correspond to a signature policy. Different service interfaces may correspond to different signature policies, or the same signature policy. A signature policy may be used to indicate the items to be signed and the rules for generating signature codes. Different signature policies may be used to indicate different items to be signed.

[0095] Based on this, the public cloud server's information processing module can identify the type of data requested by the service access request and, based on the type of data requested, determine the service interface of the private cloud server that the service access request intends to access. Furthermore, the public cloud server's information processing module can determine the signature policy corresponding to the service interface of the private cloud server that the service access request intends to access, determine the item to be signed based on this signature policy, and then sign the item to be signed, generating a first signature code. Furthermore, the public cloud server's information processing module can include this signature in the authorization information and send it to the client.

[0096] Furthermore, when the public cloud server's information processing module generates authorization information, it can also set a validity period for the authorization information. Thus, within the validity period, the client can access the private cloud server using the authorization information. If the validity period expires, the client must obtain new authorization information from the public cloud server, thereby improving the security of the cloud service platform.

[0097] S203: The client receives the authorization information and sends the authorization information to the private cloud server.

[0098] S204. The private cloud server receives the authorization information from the client and verifies the signature in the authorization information. If the verification passes, the client is allowed to access the private cloud server through the service interface corresponding to the service access request.

[0099] Based on this, this application can improve the security and reliability of the cloud service authorization and authentication process through a cross-cloud architecture of public cloud server authorization and private cloud server authentication.

[0100] In one embodiment, in the above S202, the information processing module of the public cloud server determines the signature strategy based on the mapping relationship between the service access request and the service interface of the private cloud server to be accessed, and when signing the item to be signed in the service access request based on the signature strategy, the embodiment of the present application provides an optional implementation method, including: S2021-S2023.

[0101] S2021. Determine whether the signature strategy is a fixed-item signature strategy or a random-item signature strategy based on a mapping relationship between the service access request and the service interface of the private cloud server to be accessed.

[0102] Signature policies can include fixed-item signature policies and random-item signature policies. A fixed-item signature policy may sign the items to be signed in a service access request based on a preset signature item corresponding to a service interface to generate a first signature code. A random-item signature policy may sign one or more items to be signed in a service access request based on a randomly selected preset signature item within a range of preset signature items corresponding to a service interface to generate a first signature code.

[0103] Furthermore, the information processing module of the public cloud server can obtain the signature policy corresponding to the service interface of the private cloud server to be accessed by the service access request, which is a fixed-item signature policy or a random-item signature policy.

[0104] S2022: When the signature strategy is a fixed-item signature strategy, the item to be signed in the service access request is signed according to a preset signature item to generate a first signature code.

[0105] When the determined signature policy is a fixed-item signature policy, the information processing module of the public cloud server may sign the to-be-signed items in the service access request that correspond one-to-one to the preset signature items according to the preset signature items indicated by the fixed-item signature policy to generate a first signature code.

[0106] S2023: When the signature strategy is a random item signature strategy, one or more items to be signed in the service access request are randomly signed within a range of preset signature items to generate a first signature code.

[0107] When the signature strategy determined to be a random item signature strategy is determined, the information processing module of the public cloud server may select one or more preset signature items from the preset signature items indicated by the random item signature strategy, and sign the items to be signed corresponding to the one or more selected preset signature items in the service access request to generate a first signature code.

[0108] In this way, while supporting the signing of the to-be-signed items in the service access request based on the preset signature items, this application also supports the signing of the to-be-signed items in the service access request based on the random items in the preset signature items. In this case, for two service access requests from the same client to the same service interface, the public cloud server can generate two different signatures based on the random item signature strategy, enabling dynamic signing of service access requests and thus generating dynamic authorization information. This makes it difficult for unauthorized access to obtain the correct signature strategy and forge signatures, effectively resisting attacks such as data theft and tampering, and improving the data security of the cloud service platform.

[0109] In one embodiment, the public cloud server may further include a gateway verification module. In this case, the data processing method provided in the embodiment of the present application may further include: S301-S302.

[0110] S301. The gateway verification module of the public cloud server performs a validity check on the service access request.

[0111] S302. When the gateway verification module of the public cloud server passes the verification, the information processing module is allowed to sign the service access request based on the signature policy.

[0112] For example, a service access request may include user identity information. The gateway verification module of the public cloud server may verify the legitimacy of the user identity information in the service access request, obtain a verification result, and grant or deny access to the client based on the verification result.

[0113] In this way, the public cloud server can verify the identity of the source of service access requests through the gateway verification module, thereby improving the security of the cloud service platform.

[0114] In one embodiment, the signed authorization information may include: a first signature code, a signature code generation rule, a service access request, and the access address of the private cloud server. Based on this, the client can directly redirect to the private cloud server based on the authorization information. In this case, in S204 above, when the private cloud server receives the authorization information from the client and verifies the signature in the authorization information, this embodiment of the present application provides an optional implementation method, including S2041-S2042.

[0115] S2041. The private cloud server generates a second signature code according to the signature code generation rule in the authorization information, and compares the first signature code with the second signature code.

[0116] S2042: The private cloud server determines that the signature verification is successful if the comparison is consistent.

[0117] In this way, the private cloud server can obtain the signature code generation rules used by the public cloud server when signing through the client, and verify the signature in the authorization information, thereby achieving effective management and monitoring of the authorized service access process, improving security and traceability, and avoiding illegal service access.

[0118] In one embodiment, the private cloud server may further include a gateway verification module. In this case, the data processing method provided in the embodiment of the present application may further include: S401-S402.

[0119] S401. The gateway verification module of the private cloud server performs a validity check on the service access request in the authorization information.

[0120] S402: When the verification is passed, the gateway verification module of the private cloud server allows the signature in the authorization information to be verified.

[0121] In this way, the private cloud server can perform secondary identity verification during the authorized service access process, thereby improving the security of the cloud service platform.

[0122] In one embodiment, the management module of the public cloud server can also be used to manage signature code generation rules.

[0123] In one embodiment, the management instruction may further include adjusting the signature code generation rules.

[0124] In one embodiment, the private cloud server may further include multiple service interfaces. These multiple service interfaces allow access to different types of data. That is, different service interfaces can provide access to different types of data. This data is medical business data and may include any of the following: case type, examination type, and test type.

[0125] In some embodiments, the client, and / or public cloud server, and / or private cloud server can be divided into functional modules according to the example of the above-mentioned data processing method. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above-mentioned integrated module can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation.

[0126] For example, when the client is implemented in the form of a software function module, Figure 3 As shown in FIG, a structural diagram of a data processing device provided in an embodiment of the present application is provided. The data processing device 50 can be applied to a client to implement any of the data processing methods performed by the client in the above embodiments. Figure 3 As shown, the data processing device 50 may include: a sending unit 501 and a receiving unit 502.

[0127] The sending unit 501 is configured to send a service access request to a public cloud server.

[0128] The receiving unit 502 is configured to receive authorization information.

[0129] The sending unit 501 is further configured to send the authorization information to the private cloud server.

[0130] For example, when a public cloud server is implemented in the form of software function modules, Figure 4As shown in FIG, it is a structural diagram of another data processing device provided in an embodiment of the present application. The data processing device 60 can be applied to a public cloud server to implement any of the data processing methods performed by the public cloud server in the above embodiments. Figure 4 As shown, the data processing device 60 may include: a processing unit 601 and a sending unit 602.

[0131] Processing unit 601 is used to respond to a service access request, determine a signature strategy based on the mapping relationship between the service access request and the service interface of the private cloud server to be accessed, sign the items to be signed in the service access request based on the signature strategy, and generate authorization information carrying the signature.

[0132] The sending unit 602 is configured to send the authorization information carrying the signature to the client.

[0133] In some embodiments, processing unit 601 is specifically configured to determine whether a signature strategy is a fixed-item signature strategy or a random-item signature strategy based on a mapping relationship between a service access request and a service interface of a private cloud server to be accessed. When the signature strategy is a fixed-item signature strategy, the to-be-signed item in the service access request is signed according to a preset signature item to generate a first signature code. When the signature strategy is a random-item signature strategy, one or more to-be-signed items in the service access request are randomly signed within a range of preset signature items to generate a first signature code.

[0134] In some embodiments, the data processing device 60 further includes: a verification unit 603 .

[0135] The verification unit 603 is used to verify the legitimacy of the service access request.

[0136] The verification unit 603 is further configured to allow the processing unit 601 to sign the service access request based on the signature policy when the verification passes.

[0137] For example, when a private cloud server is implemented in the form of software function modules, Figure 5 As shown in FIG, it is a structural diagram of another data processing device provided in an embodiment of the present application. The data processing device 70 can be applied to a private cloud server to implement any of the data processing methods performed by the private cloud server in the above embodiments. Figure 5 As shown, the data processing device 70 may include: a receiving unit 701 and a signature verification unit 702.

[0138] The receiving unit 701 is configured to receive authorization information from a client.

[0139] The signature verification unit 702 is used to verify the signature in the authorization information. When the signature verification passes, the client is allowed to access the private cloud server through the service interface corresponding to the service access request.

[0140] In some embodiments, the signature verification unit 702 is specifically configured to generate a second signature code according to the signature code generation rule in the authorization information, and compare the first signature code with the second signature code, and determine that the signature verification is successful if the comparison is consistent.

[0141] In some embodiments, the data processing device 70 further includes: a verification unit 703 .

[0142] The verification unit 703 is used to verify the legitimacy of the service access request in the authorization information.

[0143] The verification unit 703 is further configured to allow the signature verification unit 702 to verify the signature in the authorization information when the verification passes.

[0144] In the signature management method of the third aspect of this application:

[0145] The signature management method of this application is applied to a signature system.

[0146] The signature management method includes: a client sending a management instruction to a public cloud server, and a management module of the public cloud server managing a signature policy in response to the management instruction.

[0147] like Figure 6 FIG. 8 is a flow chart of a signature management method provided in an embodiment of the present application. The signature management method includes: S801-S802.

[0148] S801. The client sends a management instruction to the public cloud server.

[0149] For example, the client can be a web page for managing the cloud service platform. The cloud administrator can send management instructions to the public cloud server through the client to manage the signature policy deployed in the public cloud server.

[0150] In one embodiment, the management instructions may include at least one of the following: adding a signature policy corresponding to a preset signature item of the service interface of the private cloud server, deleting an existing signature policy corresponding to the service interface of the private cloud server, and adjusting the items to be signed in the existing signature policy corresponding to the service interface of the private cloud server.

[0151] In one embodiment, the management module of the public cloud server can also be used to manage signature code generation rules.

[0152] In one embodiment, the management instruction may further include adjusting the signature code generation rules.

[0153] S802. The management module of the public cloud server manages the signature policy in response to the management instruction.

[0154] The public cloud server may be deployed with a management module for managing signature policies. The management module can be used to respond to management instructions and manage signature policies based on the management instructions. Alternatively, the management module can be used to respond to management instructions and manage signature code generation rules.

[0155] In one embodiment, the public cloud server may further include a gateway verification module. In this case, the signature management method provided in the embodiment of the present application may further include: S901-S902.

[0156] S901. The gateway verification module of the public cloud server performs a validity check on the management instruction.

[0157] S901. When the gateway verification module of the public cloud server passes the verification, the management module is allowed to manage the signature policy based on the management instruction.

[0158] For example, the management instruction may include the identity information of the cloud administrator. The gateway verification module may be used to verify the legitimacy of the cloud administrator identity information in the management instruction, obtain a verification result, and allow or deny the client's access based on the verification result.

[0159] In one embodiment, the management module of the public cloud server can configure signature policies for multiple service interfaces on the private cloud server. These multiple service interfaces allow access to different types of data. That is, different service interfaces can provide access to different types of data. This data is medical service data and can include any of the following: case type, examination type, and test type.

[0160] Based on this, the management module of the public cloud server can quickly configure the signature policy corresponding to the data type for the new medical business data service based on the mapping relationship between the data type and the signature policy, as well as the data type targeted by the new medical business data service.

[0161] In this way, by configuring different signature strategies for different types of medical business data, flexible and rapid management of the signature strategies of service interfaces can be achieved, effectively supporting the centralized deployment of service interfaces in private cloud servers, achieving efficient resource utilization and rapid deployment of services, and providing cloud service platforms with response efficiency and stability when facing large-scale concurrent access or complex business logic, meeting the needs of diverse medical business scenarios.

[0162] In some embodiments, the client and / or public cloud server can be divided into functional modules according to the example of the above-mentioned signature management method. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. The above-mentioned integrated module can be implemented in the form of hardware or in the form of software functional modules. It should be noted that the division of modules in the embodiment of the present application is schematic and is only a logical functional division. There may be other division methods in actual implementation.

[0163] For example, when the client is implemented in the form of a software function module, Figure 7 As shown in FIG, a structural diagram of a signature management device provided in an embodiment of the present application is provided. The signature management device 200 can be applied to a client to implement any signature management method executed by a client in the above embodiments. Figure 7 As shown, the signature management device 200 may include: a sending unit 2001.

[0164] The sending unit 2001 is configured to send a management instruction to the public cloud server.

[0165] For example, when a public cloud server is implemented in the form of software function modules, Figure 8 As shown in FIG, it is a structural diagram of another signature management device provided in an embodiment of the present application. The signature management device 300 can be applied to a public cloud server to implement any signature management method performed by a public cloud server in the above embodiments. Figure 8 As shown, the signature management device 300 may include: a management unit 3001.

[0166] The management unit 3001 is configured to manage the signature policy in response to a management instruction, or to manage the signature code generation rules in response to a management instruction.

[0167] In some embodiments, the signature management device 300 may further include: a verification unit 3002 .

[0168] The verification unit 3002 is used to verify the validity of the management instruction.

[0169] The verification unit 3002 is further configured to, when the verification passes, allow the management unit 3001 to respond to a management instruction and manage the signature policy, or to allow the management unit 3001 to respond to a management instruction and manage the signature code generation rules.

[0170] In the electronic device of the fourth aspect of the present invention:

[0171] In the case of integrated units, such as Figure 9, which is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. The electronic device 400 can be a client to implement any of the data processing methods or signature management methods performed by the client in the above embodiments. Alternatively, the electronic device 400 can be a public cloud server to implement any of the data processing methods or signature management methods performed by the public cloud server in the above embodiments. Alternatively, the electronic device 400 can be a private cloud server to implement any of the data processing methods performed by the private cloud server in the above embodiments.

[0172] like Figure 9 As shown, the electronic device 400 may include: a processing module 4001 and a communication module 4002. The processing module 4001 may be used to control and manage the actions of the electronic device 400. The communication module 4002 may be used to support the communication between the electronic device 400 and other entities. Figure 9 As shown, the electronic device 400 may further include a storage module 4003 for storing program codes and data of the electronic device 400 .

[0173] The processing module 4001 may be a processor or a controller, the communication module 4002 may be a transceiver, a transceiver circuit or a communication interface, etc., and the storage module 4003 may be a memory.

[0174] When the processing module 4001 is a processor, the communication module 4002 is a transceiver, and the storage module 4003 is a memory, the processor, the transceiver, and the memory may be connected via a bus.

[0175] In some embodiments, when the electronic device 400 serves as a client, it may be a terminal, which may be at least one of a smartphone, a smartwatch, a desktop computer, a laptop computer, a virtual reality terminal, an augmented reality terminal, a wireless terminal, and a laptop computer.

[0176] In some embodiments, the electronic device 400 can be a server when acting as a public cloud server or a private cloud server. The server can be an independent physical server, or a server cluster or distributed file system composed of multiple physical servers, or at least one of the cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content distribution networks, and big data or artificial intelligence platforms, and the embodiments of the present disclosure are not limited to this. In some embodiments, the number of the above-mentioned servers can be more or less, and the embodiments of the present disclosure are not limited to this. Of course, the server can also include other functions to provide more comprehensive and diversified services. In some embodiments, the server is used to provide background services for the above-mentioned clients, such as executing signature policy management services or medical business data access services.

[0177] In the computer-readable storage medium of the fifth aspect of the present invention:

[0178] Instructions are stored in the computer-readable storage medium. When the computer executes the instructions, the computer executes any possible data processing method in the second aspect or any possible signature management method in the third aspect.

[0179] In the computer program product of the sixth aspect of the present invention:

[0180] The computer program product includes computer instructions, which, when executed on an electronic device, enable the electronic device to execute any possible data processing method as in the second aspect or any possible signature management method as in the third aspect.

[0181] In one embodiment, if Figure 10 As shown in FIG, it is a structural diagram of another electronic device provided in an embodiment of the present application. Figure 10 As shown, the electronic device 500 includes a computing unit 5001, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 5002 or a computer program loaded from a storage unit 5008 into a random access memory 5003. In the random access memory (RAM) 5003, various programs and data required for the operation of the electronic device 500 can also be stored. The computing unit 5001, the ROM 5002, and the RAM 5003 are connected to each other via a bus 5004. An input / output (I / O) interface 5005 is also connected to the bus 5004.

[0182] Multiple components in the electronic device 500 are connected to the input / output interface 5005, including: an input unit 5006, such as a keyboard, a mouse, etc.; an output unit 5007, such as various types of displays, speakers, etc.; a storage unit 5008, such as a magnetic disk, an optical disk, etc.; and a communication unit 5009, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 5009 allows the electronic device 500 to exchange information / data with other devices via a computer network such as the Internet and / or various telecommunication networks.

[0183] The computing unit 5001 can be a variety of general-purpose and / or specialized processing components with processing and computing capabilities. Some examples of the computing unit 5001 include, but are not limited to, a central processing unit, a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, digital signal processors, and any appropriate processors, controllers, microcontrollers, etc. The computing unit 5001 performs the various methods and processes described above, such as the data processing method or the signature management method. For example, in one embodiment, the data processing method can be implemented as a computer software program that is tangibly included in a machine-readable medium, such as the storage unit 5008. For another example, in one embodiment, the signature management method can be implemented as a computer software program that is tangibly included in a machine-readable medium, such as the storage unit 5008.

[0184] In one embodiment, part or all of the computer program may be loaded and / or installed into the computer via the ROM 5002 and / or the communication unit 5009. Figure 10 When the computer program is loaded into RAM 5003 and executed by the computing unit 5001, one or more steps of the data processing method described above may be performed, or one or more steps of the signature management method described above may be performed. Alternatively, in other embodiments, the computing unit 5001 may be configured as the data processing method or the signature management method in any other appropriate manner (e.g., by means of firmware).

[0185] Various embodiments of the systems and techniques described herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays, application specific integrated circuits, application specific standard parts (ASSPs), system on chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0186] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0187] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or apparatus. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or apparatus, or any suitable combination of the foregoing. More specific examples of machine-readable storage media may include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory, a read-only memory, an erasable programmable read-only memory, an optical fiber, a portable compact disk read-only memory, an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0188] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device for displaying information to the user, such as a cathode ray tube (CRT) or a liquid crystal display (LCD) monitor; and a keyboard and pointing device (such as a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (such as visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0189] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0190] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact through a communication network. The client-server relationship arises through computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.

[0191] It should be understood that in the various embodiments of the present application, the size of the serial numbers of the above-mentioned processes does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.

[0192] Those skilled in the art will appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0193] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.

[0194] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0195] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented using a software program, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When loading and executing computer program instructions on a computer, the process or function according to the embodiment of the present application is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website, computer, server or data center to another website, computer, server or data center by wired (such as coaxial cable, optical fiber, digital subscriber line (Digital Subscriber Line, DSL)) or wireless (such as infrared, wireless, microwave, etc.) mode. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrations. The available medium may be a magnetic medium (eg, a floppy disk, a hard disk, a magnetic tape), an optical medium (eg, a DVD), or a semiconductor medium (eg, a solid state disk (SSD)).

[0196] The above are only specific embodiments of the present application, but the scope of protection of this application is not limited thereto. Any changes or substitutions that can be easily conceived by a person skilled in the art within the technical scope disclosed in this application should be included in the scope of protection of this application. Therefore, the scope of protection of this application should be based on the scope of protection of the claims.

Claims

1. A signature system, characterized in that: include: Clients, public cloud servers, and private cloud servers; The client is used to send a service access request and / or a management instruction to the public cloud server; The service access request is a request for accessing the private cloud server; The service access request includes at least one item to be signed; The public cloud server includes an information processing module and a management module; The information processing module is configured to respond to the service access request, determine a signature policy based on a mapping relationship between the service access request and the service interface of the private cloud server to be accessed, sign the to-be-signed item in the service access request based on the signature policy, generate authorization information carrying the signature, and send the signature to the client; The management module is used to respond to the management instruction and manage the signature policy based on the management instruction; The client is further configured to receive the authorization information and send the authorization information to the private cloud server; The private cloud server includes at least one service interface, which is used to receive the authorization information from the client and verify the signature in the authorization information. When the verification is successful, the client is allowed to access the private cloud server through the service interface corresponding to the service access request.

2. The signature system according to claim 1, characterized in that The determining of the signature strategy according to the mapping relationship between the service access request and the service interface of the private cloud server to be accessed includes: The signature strategy is determined to be a fixed-item signature strategy or a random-item signature strategy according to a mapping relationship between the service access request and the service interface of the private cloud server to be accessed.

3. The signature system according to claim 2, characterized in that The to-be-signed items in the service access request correspond one-to-one to the preset signature items of the service interface of the private cloud server to be accessed; The fixed item signature strategy is a strategy for signing the item to be signed in the service access request according to the preset signature item to generate a first signature code; Alternatively, the random item signature strategy is a strategy for randomly signing one or more items to be signed in the service access request within the range of the preset signature item to generate a first signature code.

4. The signature system according to claim 1, wherein: The item to be signed includes at least one of: user information, request path, request method, request header, query parameters and request body.

5. The signature system according to claim 1, wherein: The management instruction includes at least one of the following: Adding a signature policy corresponding to a preset signature item of the service interface of the private cloud server; Deleting the existing signature policy corresponding to the service interface of the private cloud server; Adjust the to-be-signed item in the existing signature policy corresponding to the service interface of the private cloud server.

6. The signature system according to claim 1, wherein: The public cloud server also includes a gateway verification module, which is used to verify the legitimacy of the service access request or the management instruction. When the verification passes, the information processing module is allowed to sign the service access request based on the signature policy, or the management module is allowed to manage the signature policy based on the management instruction.

7. The signature system according to claim 1, wherein: The authorization information carrying the signature includes: a first signature code, a signature code generation rule, the service access request, and an access address of the private cloud server.

8. The signature system according to claim 7, characterized in that: The private cloud server is used to receive the authorization information from the client and verify the signature in the authorization information, including: the private cloud server generates a second signature code according to the signature code generation rule, compares the first signature code with the second signature code, and passes the verification if the comparison is consistent.

9. The signature system according to claim 1, wherein: The private cloud server includes multiple service interfaces, and the types of data allowed to be accessed by the multiple service interfaces are different; the data is medical business data, and the types of the medical business data include any one of the following: case type, examination type and test type.

10. A data processing method, characterized in that: The method is applied to the signature system according to any one of claims 1 to 9, and the method comprises: The client sends a service access request to the public cloud server, wherein the service access request is used to request access to the private cloud server; The information processing module of the public cloud server responds to the service access request, determines a signature policy based on a mapping relationship between the service access request and the service interface of the private cloud server to be accessed, signs the to-be-signed items in the service access request based on the signature policy, generates authorization information carrying the signature, and sends the signature to the client; The client receives the authorization information and sends the authorization information to the private cloud server; The private cloud server receives the authorization information from the client and verifies the signature in the authorization information. When the verification passes, the client is allowed to access the private cloud server through the service interface corresponding to the service access request.

11. The data processing method according to claim 10, characterized in that: The determining of a signature strategy according to a mapping relationship between the service access request and a service interface of the private cloud server to be accessed, and signing the to-be-signed item in the service access request based on the signature strategy includes: Determining, according to a mapping relationship between the service access request and the service interface of the private cloud server to be accessed, whether the signature strategy is a fixed-item signature strategy or a random-item signature strategy; When the signature strategy is the fixed-item signature strategy, signing the item to be signed in the service access request according to the preset signature item to generate a first signature code; Alternatively, when the signature strategy is the random item signature strategy, one or more items to be signed in the service access request are randomly signed within a range of preset signature items to generate a first signature code.

12. A signature management method, characterized in that: The method is applied to the signature system according to any one of claims 1 to 9, and the method comprises: The client sends management instructions to the public cloud server; The management module of the public cloud server manages the signature policy in response to the management instruction.

13. An electronic device, characterized in that: The electronic device comprises: processor and communication interface; The communication interface is coupled to the processor, and the processor is configured to run a computer program or instruction to implement the data processing method according to claim 10 or 11 or the signature management method according to claim 12.

14. A computer-readable storage medium, characterized in that The computer-readable storage medium stores instructions. When a computer executes the instructions, the computer executes the data processing method according to claim 10 or 11 or the signature management method according to claim 12.