Intelligent agent communication method and device, electronic equipment, storage medium and program product
By converting the format of authentication requests and sharing whitelist groups through the agent service bus, the problem of poor identity system compatibility in agent communication is solved, realizing a high-performance and scalable agent communication system, reducing authentication overhead and improving system scalability.
Patent Information
- Application Number
- CN202511101337.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-06
- Publication Date
- 2025-11-14
AI Technical Summary
Existing intelligent agent communication suffers from poor identity system compatibility, leading to identity silos. Furthermore, inconsistent communication protocols and data formats between different enterprises result in high semantic understanding costs, impacting the effectiveness of communication and interaction between intelligent agents.
The system receives identity authentication requests from intelligent agents through the identity authentication interface of the intelligent agent service bus, performs format conversion, processes the requests through the authentication management module, configures intelligent agent whitelist groups and their resource permission information, realizes the group sharing of identity whitelists, solves the problem of identity silos, reduces the identity authentication overhead of similar intelligent agents, and improves system scalability.
It realizes a high-performance, scalable communication system between intelligent agents, shields the compatibility differences between identity systems, reduces authentication overhead, and improves the system's scalability and communication efficiency.
Smart Images

Figure CN120956468A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, specifically to intelligent agent communication methods, devices, electronic devices, storage media, and program products. Background Technology
[0002] Intelligent agents are entities with autonomous perception, decision-making, and action capabilities. They can be software programs (e.g., algorithm modules, intelligent assistants, etc.) or hardware devices (e.g., lighting agents, decision-making agents, etc.). These intelligent agents do not exist in isolation; they need to be connected through communication to achieve complex functions beyond those of a single intelligent agent, such as collaboratively completing tasks, sharing key information, coordinating conflicts, and allocating resources. Therefore, there is a need to provide an intelligent agent communication method to achieve communication connections between intelligent agents. Summary of the Invention
[0003] In view of this, this application provides an intelligent agent communication method, device, electronic device, storage medium, and program product to solve the communication problem of intelligent agents.
[0004] In a first aspect, this application provides an agent communication method applied to an agent server, wherein the agent server is deployed with an agent service bus, including:
[0005] The first identity authentication request of the first intelligent agent is received through the identity authentication interface of the intelligent agent service bus, and the first identity authentication request is represented by a first format.
[0006] The first identity authentication request is converted into a second identity authentication request in a second format through the identity authentication interface.
[0007] The authentication management module of the intelligent agent service bus processes the second identity authentication request to obtain the first authentication result. The authentication management module is configured to have an intelligent agent whitelist group and resource permission information corresponding to the intelligent agent whitelist group. The intelligent agent whitelist group is used to represent the intelligent agent whitelist of the same intelligent agent type.
[0008] If the first authentication result indicates that the authentication is successful, then the communication request of the first intelligent agent is processed through the intelligent agent service bus.
[0009] Secondly, this application provides an intelligent agent communication device applied to an intelligent agent server, wherein the intelligent agent server is deployed with an intelligent agent service bus, including:
[0010] The first receiving module is configured to receive a first identity authentication request from a first intelligent agent through the identity authentication interface of the intelligent agent service bus, wherein the first identity authentication request is characterized by a first format.
[0011] The format conversion module is used to convert the format of the first identity authentication request through the identity authentication interface to obtain a second identity authentication request in a second format.
[0012] The first authentication module is used to process the second identity authentication request through the authentication management module of the intelligent agent service bus to obtain the first authentication result. The authentication management module is configured to have an intelligent agent whitelist group and resource permission information corresponding to the intelligent agent whitelist group. The intelligent agent whitelist group is used to represent the same intelligent agent type.
[0013] The communication processing module is used to process the communication request of the first intelligent agent through the intelligent agent service bus if the first authentication result indicates that the authentication is successful.
[0014] Thirdly, this application provides an electronic device, including: a memory and a processor, which are communicatively connected to each other. The memory stores computer instructions, and the processor executes the computer instructions to perform the intelligent agent communication method of the first aspect or any corresponding embodiment described above.
[0015] Fourthly, this application provides a computer-readable storage medium storing computer instructions for causing a computer to execute the intelligent agent communication method of the first aspect or any corresponding embodiment described above.
[0016] Fifthly, this application provides a computer program product, including computer instructions for causing a computer to execute the intelligent agent communication method described in the first aspect or any corresponding embodiment thereof.
[0017] The agent communication method provided in this application is applied to an agent server, which is equipped with an agent service bus. The method includes receiving a first authentication request from a first agent through the agent service bus's authentication interface; the first authentication request is characterized by a first format; converting the authentication request through the authentication interface to obtain a second authentication request in a second format; processing the second authentication request through the agent service bus's authentication management module to obtain a first authentication result; the authentication management module is configured to have an agent whitelist group and corresponding resource permission information for the agent whitelist group; the agent whitelist group represents an agent whitelist of the same agent type; if the first authentication result indicates successful authentication, the communication request of the first agent is processed through the agent service bus. This method provides an agent service bus to enable communication between agents. The identity authentication interface in the agent service bus converts the format of identity authentication requests represented by different formats, thereby shielding the problem of poor compatibility between identity systems and solving the problem of identity silos. In addition, the authentication management module of the agent service bus is configured with agent whitelist groups and their corresponding resource permission information, realizing the group sharing of identity whitelists, reducing the identity authentication overhead of similar agents, further improving system scalability, and realizing a high-performance and scalable agent communication system. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the specific embodiments or related technologies of this application, the drawings used in the description of the specific embodiments or related technologies will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0019] Figure 1 This is a schematic diagram illustrating a scenario of intelligent agent communication in related technologies;
[0020] Figure 2 This is a schematic diagram illustrating an application scenario according to an embodiment of this application;
[0021] Figure 3 This is a flowchart illustrating an intelligent agent communication method according to an embodiment of this application;
[0022] Figure 4 This is a flowchart illustrating another intelligent agent communication method according to an embodiment of this application;
[0023] Figure 5 This is a schematic diagram of the intelligent agent identity authentication process according to an embodiment of this application;
[0024] Figure 6This is a schematic diagram of the process of agent registration and subscription according to an embodiment of this application;
[0025] Figure 7 This is a structural block diagram of an intelligent agent communication device according to an embodiment of this application;
[0026] Figure 8 This is a schematic diagram of the hardware structure of an electronic device according to an embodiment of this application. Detailed Implementation
[0027] To make the objectives, technical solutions, and advantages of the embodiments of this application clearer, the technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0028] It is understood that before using the technical solutions disclosed in the various embodiments of this disclosure, users should be informed of the types, scope of use, and usage scenarios of the personal information involved in this disclosure in an appropriate manner in accordance with relevant laws and regulations, and user authorization should be obtained.
[0029] For example, upon receiving a user's active request, a prompt message is sent to the user to explicitly inform them that the requested operation will require the acquisition and use of the user's personal information. This allows the user to independently choose whether to provide personal information to the software or hardware, such as the electronic device, application, server, or storage medium performing the operations of this disclosed technical solution, based on the prompt message.
[0030] As an optional but non-limiting implementation, in response to a user's active request, sending a prompt message to the user can be done via a pop-up window, where the prompt message can be presented in text format. Furthermore, the pop-up window can also include a selection control allowing the user to choose "agree" or "disagree" to provide personal information to the electronic device.
[0031] It is understood that the above notification and user authorization process are merely illustrative and do not constitute a limitation on the implementation of this disclosure. Other methods that comply with relevant laws and regulations may also be applied to the implementation of this disclosure.
[0032] It is understood that the data involved in this technical solution (including but not limited to the data itself, the acquisition or use of the data) shall comply with the requirements of relevant laws, regulations and related provisions.
[0033] In related technologies, the A2A (Agent-to-Agent Protocol) is generally used to realize communication connections between intelligent agents. For example, when intelligent agents from 100 heterogeneous enterprises need to interconnect, the A2A protocol is used to register each intelligent agent in the identity systems of all enterprises.
[0034] For example, such as Figure 1 As shown, agents communicate point-to-point. If Agent-01 needs to communicate with Agent-04 through Agent-06, Agent-01 needs to establish communication connections with each of them. The communication connections for other agents are similar. In the A2A protocol, agents use structured metadata files (AgentCards) as their "digital business cards" to enable dynamic capability discovery, secure interaction, and standardized collaboration in multi-agent systems. Specifically, an AgentCard is a JSON metadata document published by the A2A server, describing the corresponding agent's identity, capabilities, skills, server endpoints, authentication requirements, etc.
[0035] The aforementioned communication methods involve high configuration complexity, and in cross-enterprise scenarios, the compatibility of different identity systems is low, easily leading to identity silos. Furthermore, different enterprises may use different communication protocols, resulting in inconsistent data formats during communication, which incurs high semantic understanding costs between agents and affects the effectiveness of communication between them.
[0036] Based on this, embodiments of this application provide an agent communication method applied to an agent server, the agent server being deployed with an agent service bus; the method includes receiving a first identity authentication request from a first agent through the identity authentication interface of the agent service bus, the first identity authentication request being represented by a first format; converting the identity authentication request through the identity authentication interface to obtain a second identity authentication request in a second format; processing the second identity authentication request through the authentication management module of the agent service bus to obtain a first authentication result, the authentication management module being configured to have an agent whitelist group and resource permission information corresponding to the agent whitelist group, the agent whitelist group being used to represent an agent whitelist of the same agent type; if the first authentication result indicates successful authentication, then processing the communication request of the first agent through the agent service bus.
[0037] This method provides an agent service bus to enable communication between agents. The identity authentication interface in the agent service bus converts the format of identity authentication requests represented by different formats, thereby shielding the problem of poor compatibility between identity systems and solving the problem of identity silos. In addition, the authentication management module of the agent service bus is configured with agent whitelist groups and their corresponding resource permission information, realizing the group sharing of identity whitelists, reducing the identity authentication overhead of similar agents, further improving system scalability, and realizing a high-performance and scalable agent communication system.
[0038] For the purposes of the following description, the terms used in the embodiments of this application are explained as follows:
[0039] Client Agent: This refers to an application, service, or other intelligent agent from which a user requests an operation or information from a remote intelligent agent. The client agent initiates communication using the A2A protocol.
[0040] Remote Agent (Server Agent): An intelligent agent or system used to implement an HTTP endpoint of the A2A protocol. It receives requests from client agents, processes tasks, and returns results or status updates. From the client agent's perspective, the remote agent operates as a black-box system; that is, the client does not need to know its internal workings, memory, or tools.
[0041] Agent Service Bus: A bus used to provide mutual trust services for agents.
[0042] Identity authentication interface: Provides a unified Agent to Agent identity authentication interface, shielding the API incompatibility issues in heterogeneous identity systems.
[0043] Abstract Protocol: A unified A2A communication protocol across platforms, establishing interface specifications.
[0044] Registration Service Module: Provides Agents with service registration and subscription capabilities, and manages Agent online and offline status.
[0045] Authentication Management Module: By sharing identity whitelists in groups, the overhead of identity authentication for the same type of agent is reduced, further improving system scalability.
[0046] Resource Management Module: Provides resource protection capabilities, restricts the access domain of client agents to remote agents, and ensures secure and controllable permissions.
[0047] Permission Service Module: As an identity authentication proxy for the Agent, it is responsible for initiating resource access requests to the resource owner and returning permissions to the Agent, thus shielding the poor compatibility issues between heterogeneous identity systems and solving the problem of identity silos.
[0048] Token service module: Used to request a temporary token from the resource owner and return it to the client agent, avoiding the security risks of long-term permissions.
[0049] As one optional application scenario in the embodiments of this application, such as Figure 2 As shown, intelligent agents that need to communicate communicate through an intelligent agent communication bus. This bus is configured with an authentication interface, an abstract protocol, a registration service module, an authentication management module, a resource management module, a permission service module, and a token service module. Therefore, intelligent agents do not need to establish point-to-point communication connections; instead, they connect uniformly through the intelligent agent communication bus. That is, each intelligent agent registers and / or subscribes to the intelligent agent communication bus, and communication and interaction between the two parties can be achieved through this bus.
[0050] It should be noted that, Figure 2 The agent communication bus shown can be deployed on a single server, or it can be deployed through a distributed system to achieve system expansion. In a distributed system, a central controller can be set up to manage all agent communication buses, or the agent communication buses can be managed through hash calculation, etc. There are no restrictions on the management method of agent communication buses in a distributed system; the specific configuration can be based on actual needs.
[0051] According to an embodiment of this application, an embodiment of an intelligent agent communication method is provided. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Furthermore, although a logical order is shown in the flowchart, in some cases, the steps shown or described may be executed in a different order than that shown here.
[0052] This embodiment provides an agent communication method applied to an agent server, which is equipped with an agent service bus. Figure 3 This is a flowchart of an intelligent agent communication method according to an embodiment of this application, such as... Figure 3 As shown, the process includes the following steps:
[0053] Step S301: Receive the first identity authentication request from the first intelligent agent through the identity authentication interface of the intelligent agent service bus.
[0054] The first identity authentication request is represented by the first format.
[0055] When authentication is required, the first agent sends a first authentication request to the agent service bus. The authentication interface of the agent service bus then receives the first authentication request. The information carried in the first authentication request includes the first agent's identity information, etc.
[0056] Since the first authentication request originates from the first agent, the protocol used for communication by the first agent determines the data format of the first authentication request. As described above, different agents may use different data formats. In this embodiment, a first format is used to represent the first authentication request.
[0057] Step S302: Convert the format of the first identity authentication request through the identity authentication interface to obtain the second identity authentication request in the second format.
[0058] The data format representing the corresponding authentication request differs for different agents. For example, agent 1 uses data format 1, agent 2 uses data format 2, and agent 3 uses data format 3.
[0059] For the intelligent agent service bus, regardless of the data format used to represent the received authentication request, it is uniformly converted into a second format. This data format conversion masks the differences between data formats.
[0060] Step S303: The second identity authentication request is processed through the authentication management module of the intelligent agent service bus to obtain the first authentication result.
[0061] The authentication management module is configured to have a whitelist of intelligent agents and the resource permission information corresponding to the whitelist of intelligent agents. The whitelist of intelligent agents is used to represent the whitelist of intelligent agents of the same type.
[0062] The authentication management module is configured with a whitelist of intelligent agents and their resource permission information. Specifically, registered intelligent agents are grouped according to their type, resulting in a whitelist of agents of the same type. "Same type" means that these agents have similar functions, attributes, and authentication rules. For example, all temperature sensor agents need to meet the same security standards, and all data processing agents belong to the same service cluster. In other words, the authentication management module manages the identity authentication of intelligent agents based on a federated mechanism.
[0063] As described above, agents of the same type are characterized by similar attributes and unified authentication rules. The authentication management module, through whitelist grouping and sharing, enables the authentication results of these agents to be recognized across multiple entities within the federation, thereby reducing redundant work and resource waste. By configuring agent whitelist groups and their resource permission information, the authentication management module can reduce duplicate authentication; that is, one authentication, multiple entity recognition.
[0064] For example, in Figure 1 In the application scenario shown, if similar intelligent agents need to connect to multiple independent entities, they must complete identity authentication separately in each entity, resulting in repetitive operations and high overhead. However, through the authentication management module of the intelligent agent bus, the identity whitelist of similar intelligent agents is grouped into a unified group and shared within the federation.
[0065] Once an agent completes authentication with an entity within the federation and is added to the corresponding agent whitelist group, other entities within the federation will directly recognize the authentication result of that group based on the federation trust relationship, without requiring the agent to repeat the authentication process with other entities.
[0066] Furthermore, whitelists of agents of the same type are integrated into a shared group, which is uniformly maintained by the authentication management module of the agent service bus. When adding or deleting an agent, only one operation is needed in the corresponding agent whitelist group to achieve automatic synchronization of all entities, avoiding repetitive work and reducing management overhead.
[0067] The core of identity authentication is verifying the validity of credentials, including but not limited to verifying the legality of the agent's digital certificate and signature. This process consumes computing resources such as CPU and memory. For similar agents across entities, a federated whitelist of similar agents is assigned a unified trust identifier, such as a trusted credential based on a consortium blockchain. When an agent accesses other entities, the receiving party does not need to re-perform a full verification; it only needs to verify whether the agent is in a shared group and whether the group's trust identifier is valid to recognize its identity.
[0068] The authentication management module processes the second identity authentication request by querying the agent whitelist to obtain the corresponding first authentication result. If the agent is found in the agent whitelist, it indicates that an agent of the same type exists, and the first authentication result indicates successful authentication. If the agent is not found, it indicates that no agent of the same type exists in the agent whitelist, and the second identity authentication request needs to be authenticated separately.
[0069] The resource permission information of the agent whitelist group is used to characterize the access rights of agents within the group. The types of resources include, but are not limited to, data resources, functional resources, hardware resources, and service resources. The specific resource type corresponding to each case is determined based on the actual business scenario, and no restrictions are imposed here.
[0070] Step S304: If the first authentication result indicates that the authentication is successful, then the communication request of the first intelligent agent is processed through the intelligent agent service bus.
[0071] If the second identity authentication request is approved in the authentication management module, it indicates that an agent of the same type has already been authenticated. At this point, based on the federation mechanism, the first agent can also be considered authenticated. Therefore, the communication requests of the first agent can be processed through the intelligent service bus. In other words, after successful authentication, the first agent can interact with the corresponding remote agent.
[0072] Furthermore, during the information interaction with the remote intelligent agent, since the resource permission information of the whitelist group of the intelligent agent to which it belongs can be obtained in step S303, the first intelligent agent can only perform information interaction within the scope of the corresponding resource permission information.
[0073] The agent communication method provided in this embodiment enables communication connections between agents by providing an agent service bus. The identity authentication interface in the agent service bus converts the format of identity authentication requests represented by different formats, thereby shielding the problem of poor compatibility between identity systems and solving the problem of identity silos. In addition, the authentication management module of the agent service bus is configured with agent whitelist groups and their corresponding resource permission information, realizing the group sharing of identity whitelists, reducing the identity authentication overhead of similar agents, further improving system scalability, and realizing a high-performance and scalable agent communication system.
[0074] In some optional implementations, the authentication management module is used to inherit agent information from the registration service module of the agent service bus, and to inherit agent resource permission information from the resource management module of the agent service bus. The agent information represents the correspondence between agent identifiers and agent types, and the agent resource permission information represents the correspondence between agent types and resource permissions.
[0075] Based on this, the authentication management module is used to aggregate agent information and agent resource permission information to obtain agent whitelist groups and corresponding resource permission information.
[0076] For the authentication management module, the configured agent whitelist groups and their resource permission information are obtained by aggregating and processing data inherited from the registration service module and resource management module of the agent service bus, respectively. Specifically, as described above, the registration service module provides agents with service registration and subscription capabilities, and manages the online and offline status of agents. Accordingly, the registration service module maintains information on registered or subscribed agents, where agent information represents the correspondence between agent identifiers and agent types. That is, different agents have unique agent identifiers for differentiation, while different agents may belong to the same agent type, which is used for subsequent agent whitelist group division.
[0077] In addition, the resource management module provides resource protection capabilities, namely, maintaining agent resource permission information. Agent resource permission information represents the correspondence between agent type and resource permissions; that is, which permissions an agent of a given type has for which resources.
[0078] The authentication management module can periodically or according to preset time constraints communicate and interact with the registration service module and the resource management module respectively to obtain the latest agent information and agent resource permission information, thereby updating the agent whitelist group and its resource permission information maintained locally by the authentication management module.
[0079] The registration service module manages the online registration of intelligent agents, the resource management module manages the resource permissions of intelligent agents, and the authentication management module aggregates the intelligent agent information from the registration service module and the intelligent agent resource permission information from the resource management module to form intelligent agent whitelist groups and their corresponding resource permission information. In other words, the whitelist of identities is shared by group through information integration, thereby reducing the identity authentication overhead of intelligent agents of the same type.
[0080] In some optional implementations, agent information and agent resource permission information are aggregated to obtain agent whitelist groups and corresponding resource permission information for agent whitelist groups, including:
[0081] Step a1: Aggregate agent information according to agent type to obtain a whitelist of agents of the same agent type and determine the agent whitelist group.
[0082] Step a2: Aggregate the resource permission information of the intelligent agent according to the intelligent agent type to obtain the resource permission information corresponding to the intelligent agent whitelist group.
[0083] As described above, the authentication management module obtains agent information from the identity authentication module and agent resource permissions from the resource management module, aggregating the obtained information from the perspective of agent type. Specifically, the authentication management module can aggregate agent information by processing it according to agent type to obtain an agent whitelist of the same agent type, thus obtaining an agent whitelist group. The aggregation of resource permission information is also processed from the perspective of agent type, obtaining resource permission information of the same agent type. Furthermore, since the agent whitelist of the same agent type is already obtained after aggregating the agent information, the resource permission information corresponding to the agent whitelist group is obtained by aggregating it with the resource permission information of the same agent type.
[0084] By aggregating at two levels, we can obtain the whitelist of intelligent agents and their corresponding resource permission information, which can ensure the accuracy of the aggregation results in the registration service module.
[0085] This embodiment provides an agent communication method applied to an agent server, which is equipped with an agent service bus. Figure 4 This is a flowchart of an intelligent agent communication method according to an embodiment of this application, such as... Figure 4 As shown, the process includes the following steps:
[0086] Step S401: Receive the first identity authentication request from the first intelligent agent through the identity authentication interface of the intelligent agent service bus.
[0087] The first authentication request is represented by a first format. See details. Figure 3 Step S301 of the illustrated embodiment will not be described again here.
[0088] Step S402: The first authentication request is converted into a second authentication request in a second format using the authentication interface. See details... Figure 3 Step S302 of the illustrated embodiment will not be described again here.
[0089] Step S403: The second identity authentication request is processed through the authentication management module of the intelligent agent service bus to obtain the first authentication result.
[0090] The authentication management module is configured to have a whitelist of intelligent agents and the resource permission information corresponding to the whitelist of intelligent agents. The whitelist of intelligent agents is used to represent the whitelist of intelligent agents of the same type.
[0091] Specifically, step S403 includes:
[0092] Step S4031: The authentication management module parses the second identity authentication request to obtain the first agent type of the first agent.
[0093] As described above, the first identity authentication request is processed through the identity authentication interface of the intelligent agent service bus to obtain an identity authentication request represented by a unified data format, i.e., a second identity authentication request in a second format. Based on this, the authentication management module parses the second identity authentication request to obtain the first intelligent agent type of the first intelligent agent.
[0094] In step S4032, the authentication management module queries the agent whitelist group based on the first agent type.
[0095] The authentication management module maintains a whitelist of agent groups corresponding to agent types. The first agent type obtained through parsing is used to query the agent whitelist group to obtain the corresponding query results.
[0096] Step S4033: If the first agent type exists in the agent whitelist group, then the authentication is successful.
[0097] Step S4034: If the first agent type is not found in the agent whitelist group, then the authentication fails.
[0098] If the first agent type can be found in the agent whitelist, the representation authentication is successful; otherwise, the representation authentication fails.
[0099] Step S404: If the first authentication result indicates successful authentication, then the communication request of the first intelligent agent is processed through the intelligent agent service bus. See details... Figure 3 Step S304 of the illustrated embodiment will not be described again here.
[0100] In the agent communication method provided in this embodiment, after receiving the second identity authentication request, the authentication management module first searches in the agent whitelist group. If it can find the request, it means that an agent of the same type has already been registered and authenticated, so there is no need to repeat the authentication process, thereby saving the overhead of identity authentication.
[0101] In some alternative implementations, the above-described agent communication method further includes:
[0102] Step b1: If the first authentication result indicates that the authentication failed, the second identity authentication request is sent to the resource management module of the intelligent agent service bus through the permission service module of the intelligent agent service bus.
[0103] In step b2, the resource management module determines the resource permissions of the first intelligent agent based on the second identity authentication request and feeds it back to the permission service module.
[0104] Step b3: The permission service module requests and obtains an access token from the security credential module of the agent service bus.
[0105] Step b4: The permission service module feeds back the resource permissions and access token of the first intelligent agent to the first intelligent agent.
[0106] For the first agent that fails authentication in the authentication management module, authentication needs to be performed using the permission service module, resource management module, and security credential module in the agent service bus. Specifically, the permission service module obtains the second identity authentication request and sends it to the resource management module to obtain the protected resource range corresponding to the first agent. Accordingly, the permission service module can determine the range of protected resources that the first agent can access.
[0107] Furthermore, the permission service module requests short-term access rights from the security credential module. The security credential module can request authentication from a heterogeneous authentication system and return the obtained access token to the permission service module. Correspondingly, the permission service module returns the resource permissions and their corresponding access token to the first agent. Subsequently, the first agent can access the protected resources through the access token and the agent service bus.
[0108] If identity authentication fails through the agent whitelist group, an identity authentication process is provided to facilitate normal communication between agents.
[0109] For example, such as Figure 5 As shown, the client agent first sends an authentication request to the authentication management module of the agent service bus. The authentication management module then queries the agent whitelist group according to the federation mechanism and returns authentication results of the same type. If a result is found, the authentication result is successful; otherwise, the authentication result is unsuccessful.
[0110] For agents that fail authentication, an authentication request is sent to the permission service module of the agent service bus. The permission service module obtains the scope of accessible resources through interaction with the resource management module and an access token through interaction with the security credential module. The permission service module then sends the scope of accessible resources and the access token back to the client agent, which can then access the corresponding resources using the access token.
[0111] In some alternative implementations, the above-described agent communication method further includes:
[0112] Step c1: After the second agent goes online, the registration service module of the agent service bus receives the online registration request of the second agent and registers the second agent online.
[0113] Step c2: The authorization service module of the agent service bus receives the registration and authentication of the second agent and sends the registration and authentication result back to the second agent.
[0114] The second intelligent agent includes an intelligent agent with remote intelligent agent functions. After the second intelligent agent goes online, it initiates an online registration request to the registration service module of the intelligent agent service bus. Accordingly, the registration service module registers the second intelligent agent online.
[0115] Specifically, the registration service module requests resource metadata from the resource management module. The resource management module updates its maintained resource metadata table and returns a success message to the registration service module. Upon receiving the success message, the registration service module generates a service uniform resource locator and returns a success message to itself.
[0116] Furthermore, the second agent initiates registration and authentication with the permission service module, and the permission service module returns a success message to the second agent.
[0117] The registration service module handles the online registration of intelligent agents in a unified manner, enabling unified management of intelligent agents on the server side.
[0118] In some alternative implementations, the above-described agent communication method further includes:
[0119] Step d1: Receive the subscription request from the third agent through the registration service module of the agent service bus. The subscription request carries the identifier of the agent to be subscribed.
[0120] In step d2, the registration service module feeds back the Uniform Resource Locator (URL) corresponding to the agent identifier to be subscribed to to the third agent, which then uses the URL to obtain the subscription message.
[0121] For agents with client-side agent functionality, they need to subscribe to the registration service module of the agent service bus to obtain the subscription information of the corresponding remote agent. Specifically, the third agent sends a subscription request carrying the agent's identifier to the registration service module. The registration service module then returns the corresponding agent's Uniform Resource Locator (URL) to the third agent, which can subsequently obtain the subscription information of the corresponding remote agent through this URL.
[0122] By uniformly processing subscription requests from intelligent agents through the registration service module, unified management of client-side intelligent agents can be achieved, thereby ensuring communication and interaction between client-side and server-side intelligent agents.
[0123] For example, such as Figure 6As shown, remote agents register for online service through the registration service module, while client agents subscribe through the same module. Specifically, the remote agent initiates an online registration service with the registration service module, which then requests resource metadata from the resource management module. Correspondingly, the resource management module updates its maintained resource metadata table and sends the update completion information back to the registration service module. The registration service module generates a corresponding Uniform Resource Locator (URL) and sends it back to the remote agent. The remote agent then initiates registration authentication with the permission service module and receives a success message from it.
[0124] The client agent initiates a subscription request to the registration service module and obtains the service's Uniform Resource Locator (URL) in return. Subsequently, the client agent uses the URL to make service calls and retrieves the subscription information from the remote agent.
[0125] As a specific application embodiment of this application, the communication process involves a client agent and a remote agent. After going online, the remote agent initiates a registration request to the registration service module to obtain a service uniform resource locator (URI); the client agent initiates a subscription request to the registration service module to obtain the URI, and subsequently uses the URI to obtain the subscription message of the remote agent.
[0126] In addition, if a client agent wants to interact with other remote agents, it needs to perform identity authentication. First, it needs to perform federated authentication through the authentication management module. If the authentication is successful, it can communicate through the agent service bus. If the authentication fails, it needs to perform identity authentication in conjunction with the permission service module, the security credential module, and the resource management module. Only after identity authentication can it interact with other remote agents.
[0127] This embodiment also provides an intelligent agent communication device for implementing the above embodiments and preferred embodiments; details already described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that implements a predetermined function. Although the device described in the following embodiments is preferably implemented in software, hardware implementation, or a combination of software and hardware, is also possible and contemplated.
[0128] This embodiment provides an intelligent agent communication device applied to an intelligent agent server. The intelligent agent server is equipped with an intelligent agent service bus, such as... Figure 7 As shown, it includes:
[0129] The first receiving module 701 is used to receive a first identity authentication request from a first intelligent agent through the identity authentication interface of the intelligent agent service bus. The first identity authentication request is represented by a first format.
[0130] The format conversion module 702 is used to convert the format of the first identity authentication request through the identity authentication interface to obtain the second identity authentication request in the second format.
[0131] The first authentication module 703 is used to process the second identity authentication request through the authentication management module of the intelligent agent service bus to obtain the first authentication result. The authentication management module is configured to have an intelligent agent whitelist group and the resource permission information corresponding to the intelligent agent whitelist group. The intelligent agent whitelist group is used to represent the same intelligent agent type.
[0132] The communication processing module 704 is used to process the communication request of the first intelligent agent through the intelligent agent service bus if the first authentication result indicates that the authentication is successful.
[0133] In some optional implementations, the authentication management module is used to inherit agent information from the registration service module of the agent service bus and agent resource permission information from the resource management module of the agent service bus; the agent information is used to represent the correspondence between agent identifier and agent type; the agent resource permission information is used to represent the correspondence between agent type and resource permission.
[0134] The authentication management module is used to aggregate agent information and agent resource permission information to obtain agent whitelist groups and corresponding resource permission information.
[0135] In some optional implementations, the authentication management module specifically includes:
[0136] The first aggregation unit is used to aggregate agent information according to agent type, obtain an agent whitelist under the same agent type, and determine the agent whitelist group.
[0137] The second aggregation unit is used to aggregate the resource permission information of intelligent agents according to the type of intelligent agent, so as to obtain the resource permission information corresponding to the whitelist group of intelligent agents.
[0138] In some alternative implementations, the first authentication module 703 includes:
[0139] The parsing unit is used by the authentication management module to parse the second identity authentication request and obtain the first agent type of the first agent.
[0140] The query unit is used by the authentication management module to query the agent whitelist group based on the first agent type.
[0141] The authentication pass unit is used to indicate that authentication is successful if the first agent type exists in the agent whitelist group.
[0142] The authentication failure unit is used to indicate that authentication has failed if the first agent type is not found in the agent whitelist group.
[0143] In some alternative implementations, the smart communication device further includes:
[0144] The first sending module is used to send a second identity authentication request to the resource management module of the agent service bus through the permission service module of the agent service bus if the first authentication result indicates that the authentication has failed.
[0145] The first feedback module is used by the resource management module to determine the resource permissions of the first intelligent agent based on the second identity authentication request and then feed it back to the permission service module.
[0146] The acquisition module is used by the permission service module to request and obtain an access token from the security credential module of the intelligent agent service bus.
[0147] The second feedback module is used by the permission service module to feed back the resource permissions and access tokens of the first intelligent agent to the first intelligent agent.
[0148] In some alternative implementations, the smart communication device further includes:
[0149] The first receiving module is used to receive the online registration request of the second intelligent agent through the registration service module of the intelligent agent service bus after the second intelligent agent goes online, and to register the second intelligent agent online.
[0150] The second receiving module is used to receive the registration and authentication of the second intelligent agent through the permission service module of the intelligent agent service bus, and to feed back the registration and authentication results to the second intelligent agent.
[0151] In some alternative implementations, the smart communication device further includes:
[0152] The subscription module is used to receive subscription requests from third-party intelligent agents through the registration service module of the intelligent agent service bus. The subscription request carries the identifier of the intelligent agent to be subscribed.
[0153] The third feedback module is used by the registration service module to feed back the Uniform Resource Locator (URL) corresponding to the agent identifier to be subscribed to to the third agent. The third agent is then used to obtain the subscription message through the URL.
[0154] The intelligent communication device provided in this disclosure can execute the intelligent communication method provided in any embodiment of this disclosure, and has the corresponding functional modules and beneficial effects for executing the method. Further functional descriptions of the various modules and units described above are the same as in the corresponding embodiments described above, and will not be repeated here.
[0155] Figure 8This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure.
[0156] The following is a detailed reference. Figure 8 The diagram illustrates a structural schematic suitable for implementing an electronic device according to embodiments of the present disclosure. The electronic device may include a processor (e.g., a central processing unit, graphics processor, etc.) 801, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 802 or a program loaded from memory 808 into random access memory (RAM) 803. The RAM 803 also stores various programs and data required for the operation of the electronic device. The processor 801, ROM 802, and RAM 803 are interconnected via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0157] Typically, the following devices can be connected to I / O interface 805: input devices 806 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 807 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; memory devices 808 including, for example, magnetic tapes, hard disks, etc.; and communication devices 809. Communication device 809 allows electronic devices to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 8 Electronic devices with various devices are shown, but it should be understood that it is not required to implement or have all of the devices shown, and more or fewer devices may be implemented or have instead.
[0158] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 809, or installed from a memory 808, or installed from a ROM 802. When the computer program is executed by the processor 801, it performs the functions defined in the intelligent agent communication method of embodiments of this disclosure.
[0159] Figure 8 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.
[0160] This application also provides a computer-readable storage medium. The methods described in this application can be implemented in hardware or firmware, or implemented as recordable on a storage medium, or implemented as computer code downloaded over a network and originally stored on a remote storage medium or a non-transitory machine-readable storage medium and then stored on a local storage medium. Thus, the methods described herein can be processed by software stored on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. The storage medium can be a magnetic disk, optical disk, read-only memory, random access memory, flash memory, hard disk, or solid-state drive, etc.; further, the storage medium can also include combinations of the above types of memory. It is understood that computers, processors, microprocessor controllers, or programmable hardware include storage components capable of storing or receiving software or computer code. When the software or computer code is accessed and executed by the computer, processor, or hardware, the intelligent agent communication method shown in the above embodiments is implemented.
[0161] A portion of this application can be applied as a computer program product, such as computer program instructions, which, when executed by a computer, can invoke or provide the methods and / or technical solutions according to this application through the operation of the computer. Those skilled in the art will understand that the forms in which computer program instructions exist in a computer-readable medium include, but are not limited to, source files, executable files, installation package files, etc. Correspondingly, the ways in which computer program instructions are executed by a computer include, but are not limited to: the computer directly executing the instructions, or the computer compiling the instructions and then executing the corresponding compiled program, or the computer reading and executing the instructions, or the computer reading and installing the instructions and then executing the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium accessible to a computer.
[0162] Although embodiments of this application have been described in conjunction with the accompanying drawings, those skilled in the art can make various modifications and variations without departing from the spirit and scope of this application, and all such modifications and variations fall within the scope defined by the appended claims.
Claims
1. A method for intelligent agent communication, characterized in that, Applied to an agent server, the agent server is deployed with an agent service bus, including: The first identity authentication request of the first intelligent agent is received through the identity authentication interface of the intelligent agent service bus, and the first identity authentication request is represented by a first format. The first identity authentication request is converted into a second identity authentication request in a second format through the identity authentication interface. The authentication management module of the intelligent agent service bus processes the second identity authentication request to obtain the first authentication result. The authentication management module is configured to have an intelligent agent whitelist group and resource permission information corresponding to the intelligent agent whitelist group. The intelligent agent whitelist group is used to represent the intelligent agent whitelist of the same intelligent agent type. If the first authentication result indicates that the authentication is successful, then the communication request of the first intelligent agent is processed through the intelligent agent service bus.
2. The method according to claim 1, characterized in that, The authentication management module is used to inherit agent information from the registration service module of the agent service bus and agent resource permission information from the resource management module of the agent service bus; the agent information is used to represent the correspondence between agent identifier and agent type; the agent resource permission information is used to represent the correspondence between agent type and resource permission. The authentication management module is used to aggregate the agent information and the agent resource permission information to obtain the agent whitelist group and the corresponding resource permission information of the agent whitelist group.
3. The method according to claim 2, characterized in that, The aggregation of the agent information and the agent resource permission information to obtain the agent whitelist group and the corresponding resource permission information includes: Aggregate the agent information according to the agent type to obtain an agent whitelist under the same agent type, and determine the agent whitelist group; The resource permission information of the intelligent agent is aggregated according to the intelligent agent type to obtain the resource permission information corresponding to the intelligent agent whitelist group.
4. The method according to claim 1, characterized in that, The authentication management module through the intelligent agent service bus processes the second identity authentication request to obtain a first authentication result, including: The authentication management module parses the second identity authentication request to obtain the first agent type of the first agent; The authentication management module queries the intelligent agent whitelist group based on the first intelligent agent type; If the first agent type exists in the agent whitelist group, it indicates that the authentication is successful; If the first agent type is not found in the agent whitelist group, it indicates that the authentication has failed.
5. The method according to claim 1, characterized in that, Also includes: If the first authentication result indicates that the authentication failed, the second identity authentication request will be sent to the resource management module of the intelligent agent service bus through the permission service module of the intelligent agent service bus. The resource management module determines the resource permissions of the first intelligent agent based on the second identity authentication request and feeds it back to the permission service module; The permission service module requests and obtains an access token from the security credential module of the intelligent agent service bus. The permission service module feeds back the resource permissions of the first intelligent agent and the access token to the first intelligent agent.
6. The method according to claim 1, characterized in that, Also includes: After the second intelligent agent goes online, the registration service module of the intelligent agent service bus receives the online registration request of the second intelligent agent and registers the second intelligent agent online. The authorization service module of the agent service bus receives the registration and authentication of the second agent and sends the registration and authentication result back to the second agent.
7. The method according to claim 1, characterized in that, Also includes: The registration service module of the intelligent agent service bus receives a subscription request from a third intelligent agent, and the subscription request carries the identifier of the intelligent agent to be subscribed to. The registration service module feeds back the Uniform Resource Locator (URL) corresponding to the identifier of the agent to be subscribed to to the third agent, which then uses the URL to obtain the subscription message.
8. An intelligent agent communication device, characterized in that, Applied to an agent server, the agent server is deployed with an agent service bus, including: The first receiving module is configured to receive a first identity authentication request from a first intelligent agent through the identity authentication interface of the intelligent agent service bus, wherein the first identity authentication request is characterized by a first format. The format conversion module is used to convert the format of the first identity authentication request through the identity authentication interface to obtain a second identity authentication request in a second format. The first authentication module is used to process the second identity authentication request through the authentication management module of the intelligent agent service bus to obtain the first authentication result. The authentication management module is configured to have an intelligent agent whitelist group and resource permission information corresponding to the intelligent agent whitelist group. The intelligent agent whitelist group is used to represent the same intelligent agent type. The communication processing module is used to process the communication request of the first intelligent agent through the intelligent agent service bus if the first authentication result indicates that the authentication is successful.
9. An electronic device, characterized in that, include: A memory and a processor are communicatively connected, the memory stores computer instructions, and the processor executes the computer instructions to perform the intelligent agent communication method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions for causing the computer to perform the agent communication method according to any one of claims 1 to 7.
11. A computer program product, characterized in that, Includes computer instructions for causing a computer to perform the agent communication method according to any one of claims 1 to 7.