Access request processing method, deployment method and related equipment

By leveraging ISV VPC to enhance multi-tenancy capabilities around existing single-tenant applications, the cost and time constraints of transforming single-tenant applications into multi-tenant applications are resolved, enabling rapid and low-cost deployment of multi-tenant applications and improving the efficiency of enterprise digital transformation.

CN120872607APending Publication Date: 2025-10-31SANGFOR TECH INC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511039086.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-25
Publication Date
2025-10-31

AI Technical Summary

Technical Problem

In existing technologies, software developers need to spend a lot of manpower and time to transform single-tenant applications into multi-tenant applications, which cannot meet the requirements of multi-tenant architecture in SaaS scenarios and hinders the efficiency of enterprise digital transformation.

Method used

ISV VPC provides multi-tenant unified user management, unified access entry, unified application automated construction, shared security components and database host instances, wrapping around the original single-tenant application, and realizing the transformation to a multi-tenant application with zero modification.

Benefits of technology

Without modifying single-tenant applications, it saves on transformation costs and time, improves the efficiency of enterprise digital transformation, and enables rapid deployment of multi-tenant applications.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120872607A_ABST
    Figure CN120872607A_ABST
Patent Text Reader

Abstract

The invention provides an access request processing method, a deployment method and related equipment. The access request processing method comprises the following steps: receiving an access request sent by any tenant through a unified access entry; if the access request passes the check, the access request is responded to enable the tenant to access the corresponding single-tenant application, and the tenant is pre-created and associated with the corresponding single-tenant application; and performing data reading and writing on the storage partition corresponding to the single-tenant application in the database according to a service operation triggered by the tenant on the single-tenant application. On the basis of zero transformation, a single-tenant application is directly converted into a multi-tenant application capable of providing services for multiple tenants at the same time, the transformation cost and the transformation time are saved, and the enterprise digital transformation efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of data processing technology, and specifically to a method for processing access requests, a deployment method, and related equipment. Background Technology

[0002] The Software as a Service (SaaS) model allows users to access software applications over the web, and more and more companies are choosing to transform their traditional businesses into SaaS to adapt to the needs of digitalization.

[0003] However, most software applications developed by software developers are currently in a single-tenant mode, which cannot meet the requirements of multi-tenant architecture in SaaS scenarios. If software developers want to transform single-tenant applications into multi-tenant applications, they need to spend a lot of manpower and time, which greatly hinders the efficiency of enterprise digital transformation.

[0004] Therefore, there is an urgent need for a way to provide services to multiple customers simultaneously without modifying single-tenant applications. Summary of the Invention

[0005] In view of this, embodiments of the present invention provide a method for processing access requests, a deployment method, and related equipment, so as to provide services to multiple customers simultaneously without modifying a single-tenant application.

[0006] To achieve the above objectives, the embodiments of the present invention provide the following technical solutions:

[0007] The first aspect of this invention discloses a method for processing access requests, the method comprising:

[0008] Receive access requests from any tenant through a unified access portal;

[0009] If the access request passes the check, the access request is responded to to allow the tenant to access its corresponding single-tenant application, where the tenant is a pre-created single-tenant application associated with its corresponding application.

[0010] Based on the business operations triggered by the tenant on the single-tenant application, data read and write operations are performed on the storage partition in the database corresponding to the single-tenant application.

[0011] Preferably, the inspection includes at least an authorization check and a security check;

[0012] The process of checking the access request includes:

[0013] Determine whether the access request belongs to a request made by someone who is not logged in;

[0014] If the access request is a login request, perform an authorization check on the access request;

[0015] Perform a security check on the access request that passes the authorization check;

[0016] If the access request is for someone who is not logged in, the login screen will be displayed.

[0017] Determine whether the tenant has completed the login action on the login interface;

[0018] If the tenant completes the login action on the login interface, return to the step of determining whether the access request belongs to a request made without logging in.

[0019] Preferably, determining whether the tenant has completed the login action on the login interface includes:

[0020] Obtain the first username and first password entered by the tenant on the login interface;

[0021] Extract the tenant's organization identifier, and extract the application ID bound to the organization identifier;

[0022] The first username and the application ID bound to the organization identifier are combined to obtain the second username;

[0023] Compare the first password with the second password corresponding to the second username;

[0024] If the first password and the second password are the same, it is determined that the tenant has completed the login action on the login interface.

[0025] Preferably, according to the business operation triggered by the tenant on the single-tenant application, data read and write operations are performed on the storage partition in the database corresponding to the single-tenant application, including:

[0026] Obtain the connection request sent by the single-tenant application related to the business operation triggered by the tenant;

[0027] Add the application ID of the single-tenant application to the connection request;

[0028] The connection request, which includes the application ID of the single-tenant application, is forwarded to the database host instance, enabling the database host instance to read and write data to the storage partition in the database corresponding to the single-tenant application.

[0029] Preferably, before checking the access request, the method further includes:

[0030] The access request is transformed using network security protocols.

[0031] Preferred options also include:

[0032] When a change is detected in the user table of the single-tenant application, the change information of the user table is extracted;

[0033] The change information is written into the database.

[0034] Preferred options also include:

[0035] Monitor the performance status of the single-tenant application and the database.

[0036] A second aspect of this invention discloses a deployment method, the method comprising:

[0037] Receive application deployment requests for the created single-tenant application;

[0038] Obtain the application template corresponding to the single-tenant application carried in the application deployment request;

[0039] Execute the corresponding deployment and configuration actions according to the application template to complete the deployment of the single-tenant application;

[0040] Among them, at least one single-tenant application created for the same application template reuses the same access entry, access request inspection capabilities, and database capabilities.

[0041] Preferably, before receiving an application deployment request for a single-tenant application, the process further includes:

[0042] Create a single-tenant application on the cloud platform and select the application template corresponding to the single-tenant application.

[0043] Preferably, after completing the deployment of the single-tenant application, the method further includes:

[0044] A tenant is created using the tenant information, and the tenant is associated with the application ID of the single-tenant application.

[0045] A third aspect of this invention discloses an access request processing apparatus, the apparatus comprising:

[0046] The receiving unit is used to receive access requests sent by tenants through a unified access portal;

[0047] A response unit is configured to respond to the access request if the access request passes the check, thereby enabling the tenant to access its corresponding single-tenant application, wherein the tenant is a pre-created single-tenant application associated with its corresponding application.

[0048] The read / write unit is used to read and write data in the database corresponding to the single-tenant application according to the business operations triggered by the tenant on the single-tenant application.

[0049] Among them, at least one single-tenant application created for the same application template reuses the same access entry, access request inspection capabilities, and database capabilities.

[0050] A fourth aspect of this invention discloses a deployment apparatus, the apparatus comprising:

[0051] The receiving unit is used to receive application deployment requests for the created single-tenant application.

[0052] The acquisition unit is used to acquire the application template corresponding to the single-tenant application carried in the application deployment request;

[0053] The execution unit is used to perform corresponding deployment and configuration actions according to the application template to complete the deployment of the single-tenant application.

[0054] A fifth aspect of the present invention discloses an electronic device, comprising: a processor and a memory, the processor and the memory being connected via a communication bus; wherein, the processor is configured to call and execute a program stored in the memory; the memory is configured to store the program, the program being configured to implement the access request processing method disclosed in the first aspect of the present invention, or the program being configured to implement the deployment method disclosed in the second aspect of the present invention.

[0055] A sixth aspect of the present invention discloses a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, it implements the access request processing method disclosed in the first aspect of the present invention, or, when the computer program is executed by a processor, it implements the deployment method disclosed in the second aspect of the present invention.

[0056] Based on the access request processing method, deployment method and related equipment provided by the above embodiments of the present invention, a single-tenant application can be directly transformed into a multi-tenant application that can provide services to multiple tenants simultaneously without any modification, saving modification costs and time, and improving the efficiency of enterprise digital transformation. Attached Figure Description

[0057] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.

[0058] Figure 1 This is an example diagram of the architecture of the prior art provided for embodiments of the present invention;

[0059] Figure 2 This is an example diagram illustrating the overall conceptual architecture of an ISV VPC provided in an embodiment of the present invention.

[0060] Figure 3 A flowchart illustrating an access request processing method provided in an embodiment of the present invention;

[0061] Figure 4 A flowchart for checking access requests provided in an embodiment of the present invention;

[0062] Figure 5 A flowchart illustrating a deployment method provided in an embodiment of the present invention;

[0063] Figure 6 This is a specific architecture example diagram of an ISV VPC provided in an embodiment of the present invention;

[0064] Figure 7 This is an example diagram illustrating the workflow for creating a single-tenant application and a tenant, provided in an embodiment of the present invention.

[0065] Figure 8 An access business process diagram for the access request processing method provided in an embodiment of the present invention;

[0066] Figure 9 A structural block diagram of an access request processing apparatus provided in an embodiment of the present invention;

[0067] Figure 10 This is a structural block diagram of a deployment device provided in an embodiment of the present invention. Detailed Implementation

[0068] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0069] In this application, the terms "comprising," "including," or any other variations thereof are intended to cover a non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

[0070] To better understand the subsequent sections, the terminology used in this plan will be explained first.

[0071] Single-tenant application: A single-tenant application is a software architecture pattern in which each customer (also known as a tenant) has its own independent application instance and database. Single-tenant applications offer higher security and flexibility, but also bring higher costs and maintenance complexity.

[0072] Multi-tenant Application: A multi-tenant application is an efficient and flexible architectural pattern suitable for scenarios requiring rapid scaling and cost reduction. It allows multiple customers to share resources and infrastructure on the same application instance, with each tenant's data and configuration isolated to ensure security and privacy. Currently, common SaaS (Software as a Service) applications employ this multi-tenant architecture.

[0073] Independent Software Vendors (ISVs): Specifically refers to companies that specialize in the development, production, sales, and service of software.

[0074] Identity and Access Management (IAM) refers to unified identity authentication and access login management services.

[0075] Virtual Private Cloud (VPC): A private network in the cloud that allows users to configure and manage a logically isolated network area on a public cloud. This virtual network area enables users to control the virtual network environment, including choosing their own IP address range, creating subnets, configuring routing tables and network gateways.

[0076] Secure Sockets Layer (SSL): A network security protocol designed to protect the security of data transmitted over the Internet by using public-key cryptography to ensure that data is not stolen or tampered with during transmission between the client and the server.

[0077] Web Application Firewall (WAF): A network security technology designed to protect web applications from various network attacks by enforcing a series of security policies for HTTP / HTTPS. The main purpose of WAF is to prevent malicious activities such as SQL injection, cross-site scripting (XSS) attacks, parameter tampering, application platform vulnerability attacks, and denial-of-service attacks.

[0078] Cross-site scripting (XSS) is a common type of cybersecurity vulnerability attack. Attackers exploit vulnerabilities such as lax validation of user input on websites to inject malicious scripts (usually JavaScript, but can also be Java, VBScript, ActiveX, Flash, etc.) into the target website.

[0079] Remote Code Execution (RCE) is a security vulnerability that allows attackers to execute arbitrary code on a remote device. This vulnerability gives attackers complete control over the affected system, enabling them to perform any operation, including installing software, viewing or modifying files, creating new accounts, etc.

[0080] The above is an explanation of some of the terms.

[0081] SaaS has become a significant trend in the transformation of traditional businesses. The SaaS model allows users to access software applications via the web without local installation, offering advantages such as cost-effectiveness, rapid deployment, and easy scalability. With technological advancements and market maturity, more and more enterprises are choosing to transform their traditional businesses into SaaS to adapt to the demands of digitalization.

[0082] However, most software applications developed by software developers are currently in a single-tenant mode, which cannot meet the requirements of multi-tenant architecture in SaaS scenarios. If software developers want to transform single-tenant applications into multi-tenant applications, they need to spend a lot of manpower and time, which greatly hinders the efficiency of enterprise digital transformation.

[0083] Research has revealed that the architecture of existing technologies is illustrated in the following diagram: Figure 1As shown, when an ISV activates a tenant for a software user in a SaaS model, it also creates a corresponding tenant on the cloud computing platform and creates a complete application (including the single-tenant application body, database, and security components) within the tenant's VPC based on the same application deployment template. However, this approach still essentially deploys a single-tenant application for each tenant, with all infrastructure resources being independent. This approach is still far from a standard SaaS application and does not solve the problem of shared resources and infrastructure in SaaS applications. The maintenance costs and operational efficiency of ISVs are not resolved, and the goal of reducing costs and increasing efficiency for enterprises is not achieved.

[0084] To address the aforementioned issues, this solution proposes a method for processing access requests, a deployment method, and related equipment. Without any modifications, it directly transforms single-tenant applications into multi-tenant applications capable of providing services to multiple tenants simultaneously, saving on modification costs and time, and improving the efficiency of enterprise digital transformation.

[0085] Overall, the access request processing method provided by this solution can be implemented by an ISV VPC. The overall architecture of the ISV VPC provided by this solution is as follows: Figure 2 As shown, the ISV VPC in this solution consists of several major parts, including multi-tenant application management, tenant operation and billing metering, security gateway, database, monitoring and analysis, and operation and maintenance management.

[0086] This solution can be implemented without modifying existing single-tenant applications (i.e., Figure 2 In the case of a monolithic application, only a single sign-on protocol and ISV VPC need to be provided for integration. This allows the ISV VPC to supplement all the capabilities required for multi-tenant applications (SaaS applications), thereby meeting the basic requirements for operating SaaS applications. Specifically, the ISV VPC in this solution can provide the following capabilities:

[0087] a. Provides unified user management for multi-tenant users;

[0088] b. Provide a unified access point for multiple tenants;

[0089] c. Provides automated building of unified multi-tenant applications;

[0090] d. Provide security components and database host instances shared by multiple tenants;

[0091] e. Provide unified login authentication for multi-tenant users;

[0092] f. Provide data and access isolation for multi-tenant environments;

[0093] g. Provide multi-tenant metering, billing, and operation and maintenance monitoring.

[0094] The overall idea of ​​this solution is to wrap the above capabilities around the original single-tenant application based on the application wrapping method, and enhance the original single-tenant application with zero modification in an external way, so as to quickly and cost-effectively convert the single-tenant application into a multi-tenant application. The following will describe this solution in detail through various embodiments.

[0095] First, the ISV VPC for implementing this solution will be explained. The ISV VPC for this solution includes at least a first gateway, an inspection component, an application resource pool, a second gateway, a security component, and a monitoring component.

[0096] The inspection components include: third-party gateway, identity recognition and access management service, and firewall.

[0097] See Figure 3 The flowchart illustrates a method for processing access requests according to an embodiment of the present invention. The method includes:

[0098] Step S301: Receive access requests sent by any tenant through a unified access portal.

[0099] In the specific implementation of step S301, an access request (such as an encrypted access request) initiated by any tenant (also known as a user or client) is received through a unified access entry point. This access request is used to access the single-tenant application corresponding to that tenant.

[0100] It should be noted that each tenant is a pre-created single-tenant application associated with it. Specifically, the application resource pool contains multiple single-tenant applications that have been pre-configured and deployed on the cloud host. Tenants are created in advance based on tenant information, and each created tenant is associated with its corresponding single-tenant application. This allows tenants to access their corresponding single-tenant application by initiating an access request through a browser in either a public or intranet environment.

[0101] In the specific implementation, the first gateway is used to receive access requests sent by any tenant. These access requests are used to access the single-tenant application corresponding to that tenant in the application resource pool.

[0102] After receiving the access request, the access request is checked. If the access request passes the check, step S302 is executed.

[0103] In its implementation, the first gateway forwards the received access request to the inspection component, which then inspects the request. This inspection includes at least authorization and security checks. If the access request passes both the authorization and security checks, step S302 is executed.

[0104] The process by which the first gateway forwards an access request to the inspection component is as follows: The first gateway uses network security protocols (such as SSL) to transform the access request, and then forwards the transformed access request to the inspection component. Specifically, after the access request arrives at the first gateway, the first gateway performs SSL offloading on the access request to transform it, and then the first gateway forwards the transformed access request to the inspection component.

[0105] Step S302: If the access request passes the check, respond to the access request to allow the tenant to access its corresponding single-tenant application.

[0106] In the specific implementation step S302, if the access request passes the inspection of the inspection component, the inspection component will forward the access request to the single-tenant application corresponding to the tenant, so that the tenant can access its corresponding single-tenant application.

[0107] Step S303: Based on the business operations triggered by the tenant on the single-tenant application, perform data read and write operations on the storage partition in the database corresponding to the single-tenant application.

[0108] In the specific implementation step S303, after forwarding the access request to the single-tenant application corresponding to the tenant, data read and write operations are performed on the storage partition in the database corresponding to the single-tenant application according to the business operation triggered by the tenant on its corresponding single-tenant application.

[0109] It should be noted that when a tenant triggers a business operation on its corresponding single-tenant application, the single-tenant application can read and write data to the storage partition in the database corresponding to the single-tenant application through the second gateway.

[0110] In some embodiments, a single-tenant application reads and writes data to the database through a second gateway in the following manner: in response to a business operation triggered by its corresponding tenant, the single-tenant application initiates a connection request to the second gateway to read and write data to the database.

[0111] Specifically, a single-tenant application pre-connects to the identity and access management service via a single sign-on protocol. Upon receiving an access request, the single-tenant application requests single sign-on from the identity and access management service to obtain the tenant's identity. The identity and access management service then maps the tenant's account to the single-tenant application's administrator account (admin) and returns it to the single-tenant application. At this point, the single-tenant application obtains the administrator account as the tenant's identity.

[0112] It should be noted that the method of "mapping the tenant's account to the administrator account (admin) of the single-tenant application and then returning it to the single-tenant application" can prevent the default administrator account from being directly exposed to the public network and avoid the security risk of high-risk account leakage.

[0113] After mapping the tenant's account to the administrator account (admin) of the single-tenant application and returning it to the single-tenant application, the tenant can use the administrator account to perform business operations in the single-tenant application.

[0114] When a tenant performs business operations in a single-tenant application, the single-tenant application will initiate a connection request (a request to connect to the database, also known as a read-write connection request) to the second gateway. The single-tenant application writes data to the database or reads data from the database through the connection established by the connection request.

[0115] In some embodiments, the specific implementation of data reading and writing to the storage partition corresponding to the single-tenant application in the database is as follows: the second gateway obtains the connection request sent by the single-tenant application related to the business operation triggered by the tenant, the second gateway adds the application ID of the single-tenant application (the unique identifier of the single-tenant application) to the connection request, and the second gateway forwards the connection request with the application ID of the single-tenant application to the database host instance, so that the database host instance can read and write data to the storage partition corresponding to the single-tenant application in the database, thereby realizing the data storage of different tenants in separate databases.

[0116] In some embodiments, a security component is used to aggregate the security status of a single-tenant application. This security component comprises a zero-trust center, a security threat detection and incident response platform (such as XDR), and runtime application self-protection (RASP). The zero-trust center, security threat detection and incident response platform, and RASP provide a unified security view, aggregating the security status of the single-tenant application.

[0117] In some embodiments, a monitoring component is used to monitor the performance status of single-tenant applications and databases. This monitoring component comprises: APM (Application Performance Monitoring), AIOps (Artificial Intelligence for IT Operations), and DMP (Database Monitor Platform). APM, AIOps, and DMP provide unified monitoring and maintenance capabilities for single-tenant applications and databases.

[0118] In some embodiments, when a change is detected in the user table of a single-tenant application, the change information of the user table is extracted and written into the database.

[0119] Specifically, by monitoring database changes through logs, the user synchronization function is triggered when "addition, deletion, and modification" are detected in the user tables (which store user information such as usernames, emails, and passwords) of each single-tenant application.

[0120] The user synchronization function extracts change information from the user table, synchronizes the change information to the identity recognition and access management service, and then writes the change information into the database.

[0121] The process by which the Identity Recognition and Access Management Service writes the change information to the database is as follows: the user synchronization function calls the interface of the Identity Recognition and Access Management Service to issue a user update operation, at which point the Identity Recognition and Access Management Service writes the change information of the user table to the database.

[0122] In this embodiment of the invention, a single-tenant application can be directly converted into a multi-tenant application that can provide services to multiple tenants simultaneously without any modifications, saving modification costs and time and improving the efficiency of enterprise digital transformation.

[0123] Regarding the above embodiments of the present invention Figure 3 The step S301, which involves checking the access request, see [link / reference]. Figure 4 The diagram illustrates a flowchart of an access request inspection provided by an embodiment of the present invention. The inspection of the access request includes at least authorization checks and security checks. Figure 4 Includes the following steps:

[0124] It should be noted again that the inspection components that check access requests include third-party gateways, identity and access management services, and firewalls.

[0125] Step S401: Determine whether the access request belongs to an unlogged-in request. If the access request belongs to a logged-in request, execute steps S402 and S403; if the access request belongs to an unlogged-in request, execute steps S404 and S405.

[0126] In the specific implementation of step S401, the third gateway is used to determine whether the access request belongs to an unlogged-in request. If the access request belongs to a logged-in request, steps S402 and S403 are executed; if the access request belongs to an unlogged-in request, steps S404 and S405 are executed.

[0127] Step S402: Perform an authorization check on the access request.

[0128] In the specific implementation step S402, if the access request is a login request, the third-party gateway is used to perform authorization checks on the access request and to conduct trust and security assessments on identity, terminal, environment and behavior.

[0129] Step S403: Perform a security check on the access request that passes the authorization check.

[0130] In the specific implementation of step S403, the third gateway is used to send the access request that has passed the authorization check to the firewall. The firewall performs a security check on the access request that has passed the authorization check to block high-risk requests such as XSS, SQL injection and RCE. Then the firewall forwards the access request that has passed the security check to the single-tenant application corresponding to the tenant, so that the tenant can access its corresponding single-tenant application.

[0131] Step S404: Launch the login interface.

[0132] In the specific implementation of step S404, if the access request is a request from someone who is not logged in, the login interface is invoked using the identity recognition and access management service.

[0133] Step S405: Determine whether the tenant has completed the login action on the login interface. If the tenant has completed the login action on the login interface, return to step S401; if the tenant has not completed the login action on the login interface, continue to step S405.

[0134] In the specific implementation of step S405, the identity recognition and access management service is used to determine whether the tenant has completed the login action on the login interface. If the tenant has completed the login action on the login interface, the process returns to step S401; if the tenant has not completed the login action on the login interface, step S405 continues to be executed, that is, the process continues to determine whether the tenant has completed the login action on the login interface.

[0135] In some specific embodiments, the specific implementation process for determining whether a tenant has completed the login action on the login interface is as follows: obtain the first username and first password entered by the tenant on the login interface; extract the tenant's organization identifier and extract the application ID bound to the organization identifier, wherein the organization identifier can be an enterprise identifier, unit identifier, or class identifier, etc.

[0136] The first username and the application ID bound to the organization identifier are combined to obtain the second username; the second password corresponding to the first password and the second username is compared; if the first password and the second password match, it is determined that the tenant has completed the login action on the login interface; otherwise, it is determined that the tenant has not completed the login action on the login interface.

[0137] As can be seen from the content of steps S401 to S405 above, the interaction process between the third gateway, the firewall, and the identity recognition and access management service is as follows: The third gateway determines whether the access request belongs to an unlogged-in request; if the access request belongs to a logged-in request, the third gateway performs an authorization check on the access request and sends the access request that passes the authorization check to the firewall; if the access request belongs to an unlogged-in request, the identity recognition and access management service is executed.

[0138] Specifically, the third-party gateway performs authorization checks on access requests, conducting trust and security assessments of identity, terminal, environment, and behavior. If the third-party gateway detects that the currently received access request is for someone who is not logged in, it will redirect the page to the identity recognition and access management service for login authentication via the single sign-on protocol.

[0139] If the third-party gateway determines that the currently received access request belongs to someone who is already logged in and has passed the authorization check, then the third-party gateway sends the access request to the firewall.

[0140] The firewall performs security checks on access requests that pass the authorization check and forwards the access requests that pass the security check to the single-tenant application corresponding to the tenant, so that the tenant can access the single-tenant application.

[0141] Specifically, the firewall performs security checks on access requests that pass the authorization check to block high-risk requests such as XSS, SQL injection, and RCE. Then, it forwards the access requests that pass the security check to the single-tenant application corresponding to the tenant, so that the tenant can access the single-tenant application.

[0142] If the access request is for someone who is not logged in, the identity recognition and access management service will invoke the login interface; if it is detected that the tenant has completed the login action on the login interface, it will return to the execution of the third gateway.

[0143] Specifically, the identity recognition and access management service checks whether the current access request has already been logged in. If not, it redirects to the login page, where the identity recognition and access management service obtains the first username and first password entered by the tenant on the login page.

[0144] The identity recognition and access management service extracts the subdomain of the current access request (i.e., the tenant's organization identifier) ​​and the application ID bound to that organization identifier. It combines the first username and the application ID bound to the organization identifier as the second username for actual login. Then, it matches the second password of the second username in the background. If the first password entered by the user matches the second password matched in the background, the login action can be completed, and the system will jump back to the third gateway for authorization check.

[0145] The above embodiments of the present invention Figure 4 This is a description of the procedures for checking access requests.

[0146] Regarding the above embodiments of the present invention Figure 3 The deployment of single-tenant applications involved in step S301 is addressed in this solution, which also provides a deployment method; see [link / reference]. Figure 5 The diagram shows a flowchart of a deployment method provided by an embodiment of the present invention. Figure 5Includes the following steps:

[0147] Step S501: Receive the application deployment request for the created single-tenant application.

[0148] In some embodiments, before performing step S501, a single-tenant application is created on the cloud platform, and an application template corresponding to the single-tenant application is selected.

[0149] In specific implementation step S501, an application deployment request for deploying the created single-tenant application is received.

[0150] Step S502: Obtain the application template corresponding to the single-tenant application carried in the application deployment request.

[0151] In the specific implementation step S502, the application template corresponding to the single-tenant application is obtained from the application deployment request.

[0152] Step S503: Perform the corresponding deployment and configuration actions according to the application template to complete the deployment of the single-tenant application.

[0153] In the specific implementation step S503, the content in the application template corresponding to the single-tenant application is parsed to perform the corresponding deployment and configuration actions, thereby completing the deployment of the single-tenant application.

[0154] The deployment and configuration actions performed include, but are not limited to: creating cloud hosts, issuing database rules, issuing WAF configurations, issuing zero-trust configurations, issuing application delivery configurations, and issuing user synchronization configurations.

[0155] It should be noted that for at least one single-tenant application created with the same application template, the same access entry point, access request inspection capabilities, and database capabilities are reused.

[0156] In some embodiments, after the deployment of a single-tenant application is completed, a tenant is created using the tenant information, and the tenant is associated with the application ID of the single-tenant application.

[0157] The above embodiments of the present invention Figure 5 This section contains instructions regarding the deployment of single-tenant applications.

[0158] To better understand the execution principles of the access request processing and deployment methods provided in this solution, we will start from a practical application perspective and combine... Figures 6 to 8 The examples shown are used to illustrate this point.

[0159] It should be noted that, in Figures 6 to 8In the example given, the first gateway is the application delivery gateway, the second gateway is the database gateway, the third gateway is the zero trust gateway, the identity and access management service is IAM, the firewall is WAF, the security component is application security, and the monitoring component is application monitoring.

[0160] like Figure 6 As shown in the example diagram of the ISV VPC architecture, the ISV VPC of this solution includes at least the following components: multi-tenant application building and management, IAM, application delivery gateway, zero trust gateway, WAF, application resource pool (containing multiple single-tenant applications deployed on cloud hosts), database gateway, application security, application monitoring, user synchronization, etc.

[0161] When a multi-tenant application (converted from a single-tenant application with zero modifications) is running, IAM, application delivery gateway, zero trust gateway, and WAF work together to handle access requests.

[0162] The functions provided by each of the above parts are as follows:

[0163] Multi-tenant application building and management: Provides functions such as tenant management, application building and application monitoring.

[0164] Application Delivery Gateway: Provides SSL offloading and request / response rewriting capabilities.

[0165] Zero Trust Gateway: Performs authorization checks on outbound requests, assessing trust in identity, endpoint, environment, and behavior.

[0166] WAF: Performs web security checks on requests, such as XSS, SQL injection, and RCE.

[0167] Database gateway: Performs tenant-based database sharding for data access requests based on source IP.

[0168] IAM: Provides unified access for single-tenant applications.

[0169] User synchronization: Provides the ability to synchronize user information within a single-tenant application to IAM.

[0170] Application security: Provides a unified security view that aggregates all security states of single-tenant applications.

[0171] It should be noted that application security includes components such as Zero Trust Center, XDR, and RASP.

[0172] Zero Trust Center, also known as Zero Trust Audit Center, provides unified auditing functionality for access logs, auditing access request operations, network behavior, and logs.

[0173] XDR is a security threat detection and incident response platform that aggregates key data on the XDR platform using native traffic collection tools and endpoint collection tools, and achieves in-depth attack chain tracing through the E+N aggregation analysis engine and contextual correlation analysis.

[0174] RASP "injects" protection features into applications, integrating them seamlessly. By hooking a few key functions, it monitors the internal workings of the application in real time. When suspicious behavior occurs, RASP accurately identifies the attack based on the current context and blocks it in real time, enabling the application to protect itself without manual intervention.

[0175] Application monitoring: Provides unified monitoring and maintenance functions for single-tenant applications and databases.

[0176] It should be noted that application monitoring includes components such as APM, AIOps, and DMP.

[0177] APM is a technology and tool for monitoring and managing application performance. It helps developers and operations teams monitor application performance metrics in real time, identify potential performance issues, and provide detailed performance analysis and reports.

[0178] AIOps is a methodology and toolset that uses big data analytics, machine learning, deep learning, and other technologies to optimize and automate the monitoring, fault detection, diagnosis, and response processes in IT operations.

[0179] DMP is a database performance monitoring platform that can observe and monitor the performance status of application databases and also provides functions such as fault prediction.

[0180] It should be noted that tenant and single-tenant applications need to be created in advance, as shown below. Figure 7 The example diagram illustrating the workflow for creating a single-tenant application and a tenant serves as a case study to explain the process of creating a tenant and a single-tenant application. Figure 7 It includes the content of sections “①-③”.

[0181] ① The software developer first creates a single-tenant application (which can be simply referred to as "application") on the cloud platform, and then selects the application template corresponding to the single-tenant application (which includes the resources and configuration behaviors required for the deployment of the single-tenant application). After successful creation, a unique identifier for the single-tenant application (called application ID, such as Uadx6E) will be generated, and an application deployment request will be sent to the automated deployment module of the cloud platform.

[0182] ② After receiving the application deployment request, the cloud platform's automated deployment module parses the content of the "application template corresponding to the created single-tenant application" and generates deployment and configuration actions. These actions include: creating a cloud host, distributing database rules, distributing WAF configuration, distributing zero-trust configuration, distributing application delivery configuration, and distributing user synchronization configuration. Through these deployment and configuration actions, the resources required by the single-tenant application are created, and the single-tenant application's configuration is initialized.

[0183] ③ Create a tenant. Create a tenant based on the tenant information (e.g., account name: tenantA, access domain name: sss.test.com, enterprise name: sss) and associate it with the application ID (Uadx6E) of the single-tenant application. Generate a mapping configuration in IAM, which includes the application ID corresponding to the enterprise name. DNS configuration and mapping configuration can also be generated.

[0184] above Figure 7 The sections “①-③” in the document contain instructions on creating single-tenant applications and creating tenants.

[0185] The process of accessing services after creating a single-tenant application and creating a tenant is as follows: Figure 8 As shown, Figure 8 It includes the content of sections “①-⑨”.

[0186] ①After the above Figure 7 After the application configuration steps, tenant A has its own access domain name (sss.test.com) and account (tenantA). In the public network or in the intranet environment after a secure tunnel has been established, tenant A sends an HTTPS encrypted access request (that is, the access request mentioned above) to the single-tenant application (which has been converted into a multi-tenant application) through a browser. For example, it sends an access request to the single-tenant application to "https: / / sss.test.com".

[0187] The browser performs Domain Name System (DNS) resolution on the domain name information (such as sss.test.com) in the access request to obtain the target IP address of the domain name corresponding to the access request returned by the DNS server.

[0188] It should be noted that an A record (Address Record) is a type of DNS record used to map a domain name to an IPv4 address. By setting an A record, a specific domain name can be directly pointed to a specific IP address, allowing users to access the corresponding server or network resources through that domain name.

[0189] CNAME is a record type in DNS. CNAME stands for Canonical Name, which is an alias record. CNAME records are used to map one domain name to another, realizing domain name aliases or redirections.

[0190] The DNS server is configured with an A record to resolve the main domain name to the public IP address configured on the application delivery gateway. At the same time, the application access domain names of each tenant are also resolved to the main domain name through CNAME records. This ensures that although different tenants may have different access domain names, they are actually accessing the same target IP address.

[0191] ② After the access request reaches the application delivery gateway, the application delivery gateway will perform SSL offloading on the access request, thereby converting the "https" access request into the "http" access request. For example, the access request "https: / / sss.test.com" will be converted into "http: / / sss.test.com", and the converted access request will be transferred to the zero trust gateway.

[0192] ③ The Zero Trust Gateway performs authorization checks on access requests, conducting trust and security assessments of identity, terminal, environment, and behavior. If the Zero Trust Gateway detects that the current access request belongs to an unauthenticated user, it will redirect the page to IAM for login authentication via the Single Sign-On protocol. If the Zero Trust Gateway determines that the current access request belongs to an authenticated user and is authorized, it will forward the access request to the cloud host IP bound to the domain "sss.test.com" in the Zero Trust Gateway via the WAF (equivalent to forwarding it to the single-tenant application deployed on that cloud host).

[0193] ④ IAM checks if the current access requester is already logged in. If not, it redirects to the login page. After tenant A enters the first username and password ("tenantA"), the access request reaches IAM. IAM first extracts the subdomain of the currently accessed domain (tenant A's organization identifier, such as "sss" in sss.test.com). IAM then retrieves the subdomain from the mapping configuration (see [link to configuration]). Figure 7 Extract the application ID bound to the organization identifier "sss" from the content of the document, and combine the first username and the application ID bound to the organization identifier to use as the second username for actual login.

[0194] For example, combining the first username "tenantA" with the "application ID" results in the second username "{application ID}@tenantA", which is the actual username used for login.

[0195] IAM matches the second password corresponding to the second username in the background. If the first password and the second password match, the login action can be completed, and the system will jump back to the zero-trust gateway for subsequent identity-based authorization checks.

[0196] ⑤ The WAF performs web security checks on access requests to block high-risk requests such as XSS, SQL injection, and RCE.

[0197] ⑥ The access request enters the single-tenant application in the cloud host. The single-tenant application is pre-connected to IAM via the single sign-on protocol. After receiving the access request, the single-tenant application obtains the tenant's identity by requesting single sign-on from IAM. In this example, tenantA is used for login. IAM maps this account to the administrator account (admin) of the single-tenant application and returns it to the single-tenant application. At this time, the tenant identity obtained by the single-tenant application is the administrator account.

[0198] ⑦ Tenant A, acting as admin, performs business operations in a single-tenant application. The single-tenant application initiates a connection request to the database gateway to read and write data to the database. Upon receiving the connection request, the database gateway retrieves the source IP (i.e., the IP address of the cloud host where the single-tenant application resides) from the connection request, looks up the mapping relationship sent locally, finds the application ID bound to the source IP (i.e., the identifier generated when the single-tenant application was created), and then transforms the connection request from "jdbc:mysql: / / localhost:3307 / app" to "jdbc:mysql: / / localhost:3307 / {application ID}_app". The transformed connection request is then forwarded to the subsequent database host instance to execute database read and write operations. This allows data read and write operations to be performed in the "sss_test" database, achieving database sharding for different tenants.

[0199] ⑧ By monitoring database changes through logs, when "addition, deletion, and modification" are detected in the user tables (which store user information such as usernames, emails, and passwords) of each single-tenant application, the user synchronization function is triggered.

[0200] ⑨ The user synchronization function extracts change information from the user table, extracts the application ID field based on the original database name (e.g., "{Application ID}_app"), and sends a user synchronization request to IAM by calling the IAM interface.

[0201] After receiving a user's synchronization request, IAM writes the "change information of the user table" into the database. This ensures that when a single-tenant application modifies its own user information, IAM can also synchronize and take effect.

[0202] above Figures 6 to 8The content provides examples illustrating the practical application of this solution.

[0203] Corresponding to the access request processing method provided in the above embodiments of the present invention, see also... Figure 9 The present invention also provides a structural block diagram of an access request processing device, which includes a receiving unit 901, a response unit 902, and a read / write unit 903.

[0204] The receiving unit 901 is used to receive access requests sent by tenants through a unified access portal.

[0205] The response unit 902 is used to respond to the access request if the access request passes the check, so that the tenant can access its corresponding single-tenant application, wherein the tenant is a pre-created and associated single-tenant application.

[0206] The read / write unit 903 is used to read and write data in the database to the storage partition corresponding to the single-tenant application, according to the business operations triggered by the tenant on the single-tenant application.

[0207] In some embodiments, the read / write unit 903 is specifically used to: obtain a connection request sent by a single-tenant application related to a business operation triggered by the tenant; add the application ID of the single-tenant application to the connection request; and forward the connection request with the application ID of the single-tenant application to the database host instance, so that the database host instance can read and write data to the storage partition in the database corresponding to the single-tenant application.

[0208] Preferred, combined Figure 9 The content shown can be inspected by an inspection unit, which includes at least authorization and security checks; this inspection unit is specifically used for:

[0209] Determine whether the access request belongs to someone who is not logged in;

[0210] If the access request is a login request, perform an authorization check on the access request;

[0211] Perform security checks on access requests that pass the authorization check;

[0212] If the access request belongs to someone who is not logged in, the login page will be displayed.

[0213] Determine whether the tenant has completed the login action on the login interface;

[0214] If the tenant completes the login action on the login interface, return to the step of determining whether the access request belongs to a request made without logging in.

[0215] In some specific embodiments, the specific implementation of determining whether a tenant has completed the login action on the login interface is as follows: obtain the first username and first password entered by the tenant on the login interface; extract the tenant's organization identifier and extract the application ID bound to the organization identifier; combine the first username and the application ID bound to the organization identifier to obtain the second username; compare the second password corresponding to the first password and the second username; if the first password and the second password are consistent, determine that the tenant has completed the login action on the login interface.

[0216] Preferred, combined Figure 9 The processing device, as shown, also includes:

[0217] The conversion unit is used to convert access requests using network security protocols.

[0218] The first monitoring unit is used to extract the change information from the user table of a single-tenant application when changes are detected, and then write the change information into the database.

[0219] The second monitoring unit is used to monitor the performance status of single-tenant applications and databases.

[0220] Corresponding to the deployment method provided in the above embodiments of the present invention, see also... Figure 10 The present invention also provides a structural block diagram of a deployment device, which includes: a receiving unit 1001, an acquiring unit 1002, and an execution unit 1003;

[0221] The receiving unit 1001 is used to receive application deployment requests for the created single-tenant application.

[0222] The acquisition unit 1002 is used to acquire the application template corresponding to the single-tenant application carried in the application deployment request.

[0223] The execution unit 1003 is used to perform corresponding deployment and configuration actions according to the application template to complete the deployment of the single-tenant application.

[0224] Among them, at least one single-tenant application created for the same application template reuses the same access entry, access request inspection capabilities, and database capabilities.

[0225] Preferred, combined Figure 10 The deployment device, as shown, also includes:

[0226] The first creation unit is used to create a single-tenant application on the cloud platform and select the application template corresponding to the single-tenant application.

[0227] The second creation unit is used to create tenants using tenant information and associate the tenants with the application ID of the single-tenant application.

[0228] Preferably, the present invention also provides an electronic device, including: a processor and a memory, the processor and the memory being connected via a communication bus; wherein, the processor is used to call and execute a program stored in the memory; the memory is used to store the program, the program being used to implement the access request processing method provided in the above method embodiments, or the program being used to implement the deployment method provided in the above method embodiments.

[0229] Preferably, embodiments of the present invention also provide a computer-readable storage medium storing a computer program, which, when executed by a processor, implements the access request processing method provided in the above method embodiments, or, when executed by a processor, implements the deployment method provided in the above method embodiments.

[0230] In summary, the embodiments of the present invention provide a method for processing access requests, a deployment method, and related equipment. Without any modifications, a single-tenant application can be directly transformed into a multi-tenant application that can provide services to multiple tenants simultaneously, saving modification costs and time, and improving the efficiency of enterprise digital transformation.

[0231] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to mutually. Each embodiment focuses on describing the differences from other embodiments. In particular, for system or system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and relevant parts can be referred to the descriptions in the method embodiments. The systems and system embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0232] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementations should not be considered beyond the scope of this invention.

[0233] The above description of the disclosed embodiments enables those skilled in the art to make or use the invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the scope of the invention. Therefore, the invention is not to be limited to the embodiments shown herein, but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.

Claims

1. A method for processing access requests, characterized in that, The method includes: Receive access requests from any tenant through a unified access portal; If the access request passes the check, the access request is responded to to allow the tenant to access its corresponding single-tenant application, where the tenant is a pre-created single-tenant application associated with its corresponding application. Based on the business operations triggered by the tenant on the single-tenant application, data read and write operations are performed on the storage partition in the database corresponding to the single-tenant application.

2. The method according to claim 1, characterized in that, The inspection should include at least an authorization check and a security check; The process of checking the access request includes: Determine whether the access request belongs to a request made by someone who is not logged in; If the access request is a login request, perform an authorization check on the access request; Perform a security check on the access request that passes the authorization check; If the access request is for someone who is not logged in, the login screen will be displayed. Determine whether the tenant has completed the login action on the login interface; If the tenant completes the login action on the login interface, return to the step of determining whether the access request belongs to a request made without logging in.

3. The method according to claim 2, characterized in that, Determining whether the tenant has completed the login action on the login interface includes: Obtain the first username and first password entered by the tenant on the login interface; Extract the tenant's organization identifier, and extract the application ID bound to the organization identifier; The first username and the application ID bound to the organization identifier are combined to obtain the second username; Compare the first password with the second password corresponding to the second username; If the first password and the second password are the same, it is determined that the tenant has completed the login action on the login interface.

4. The method according to claim 1, characterized in that, Based on the business operations triggered by the tenant on the single-tenant application, data read and write operations are performed on the storage partition in the database corresponding to the single-tenant application, including: Obtain the connection request sent by the single-tenant application related to the business operation triggered by the tenant; Add the application ID of the single-tenant application to the connection request; The connection request, which includes the application ID of the single-tenant application, is forwarded to the database host instance, enabling the database host instance to read and write data to the storage partition in the database corresponding to the single-tenant application.

5. The method according to any one of claims 1-4, characterized in that, Before inspecting the access request, the following is also included: The access request is transformed using network security protocols.

6. The method according to any one of claims 1-4, characterized in that, Also includes: When a change is detected in the user table of the single-tenant application, the change information of the user table is extracted; The change information is written into the database.

7. The method according to any one of claims 1-4, characterized in that, Also includes: Monitor the performance status of the single-tenant application and the database.

8. A deployment method, characterized in that, The method includes: Receive application deployment requests for the created single-tenant application; Obtain the application template corresponding to the single-tenant application carried in the application deployment request; Execute the corresponding deployment and configuration actions according to the application template to complete the deployment of the single-tenant application; Among them, at least one single-tenant application created for the same application template reuses the same access entry, access request inspection capabilities, and database capabilities.

9. The method according to claim 8, characterized in that, Before receiving application deployment requests for single-tenant applications, the following steps are also included: Create a single-tenant application on the cloud platform and select the application template corresponding to the single-tenant application.

10. The method according to claim 8 or 9, characterized in that, After completing the deployment of the single-tenant application, the following steps are also included: A tenant is created using the tenant information, and the tenant is associated with the application ID of the single-tenant application.

11. An access request processing apparatus, characterized in that, The device includes: The receiving unit is used to receive access requests sent by tenants through a unified access portal; A response unit is configured to respond to the access request if the access request passes the check, thereby enabling the tenant to access its corresponding single-tenant application, wherein the tenant is a pre-created single-tenant application associated with its corresponding application. The read / write unit is used to read and write data in the database corresponding to the single-tenant application according to the business operations triggered by the tenant on the single-tenant application. Among them, at least one single-tenant application created for the same application template reuses the same access entry, access request inspection capabilities, and database capabilities.

12. A deployment device, characterized in that, The device includes: The receiving unit is used to receive application deployment requests for the created single-tenant application. The acquisition unit is used to acquire the application template corresponding to the single-tenant application carried in the application deployment request; The execution unit is used to perform corresponding deployment and configuration actions according to the application template to complete the deployment of the single-tenant application.

13. An electronic device, characterized in that, include: A processor and a memory are connected via a communication bus; wherein the processor is used to call and execute a program stored in the memory; The memory is used to store a program for implementing the access request processing method as described in any one of claims 1-7, or the program for implementing the deployment method as described in any one of claims 8-10.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program that, when executed by a processor, implements the method for processing access requests as described in any one of claims 1-7, or, when executed by a processor, implements the deployment method as described in any one of claims 8-10.