Distributed permission interface calling method and system and electronic equipment

By generating and packaging the target authorization file into the application installation package on the management server, the device obtains the authorization file and judges permissions when installing the application, which solves the problem of distributed device interface permission checking and realizes the security and legality checks of the distributed system.

CN120994277APending Publication Date: 2025-11-21FUJIAN WISBO DIGITAL TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510962839.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-14
Publication Date
2025-11-21

AI Technical Summary

Technical Problem

Existing technologies cannot effectively check permissions on distributed device interfaces, leading to an increased risk of data leaks and malicious attacks.

Method used

The management server generates and packages the target authorization file into the application installation package. The device obtains the authorization file when installing the application and checks permissions when calling the interface to ensure that only legitimate applications can access the remote device's interface.

Benefits of technology

It implements permission checks for distributed interfaces, reducing the risk of data leakage and malicious attacks, and ensuring system security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120994277A_ABST
    Figure CN120994277A_ABST
Patent Text Reader

Abstract

The invention discloses a distributed permission interface calling method and system and electronic equipment. The method comprises the steps that home terminal equipment applies for a target authorization file from a management server through a target service corresponding to a target application; the management server packages the target authorization file into an installation package of the target application, and sends the installation package to the home terminal device; the home terminal device installs the target application according to the installation package and reads the target authorization file; and when the home terminal device obtains a call request of the target application for a target interface, judging whether the target authorization file has a corresponding permission, and if yes, sending the call request to the remote device for interface call processing. Calling of the distributed interface by the application is realized, and the permission of calling the interface is checked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of interface permission control technology, and in particular to a distributed permission interface invocation method, system and electronic device. Background Technology

[0002] With the continuous development of multi-device distributed collaboration technology, data interaction and resource sharing between devices are becoming increasingly frequent. Therefore, the importance of system security and data protection is becoming increasingly prominent.

[0003] Access control interface checks are a key means of preventing unauthorized access, data leaks, and malicious attacks. However, access control interface checks are typically applied to fixed interfaces and cannot meet the requirements for checking interfaces on distributed devices. Summary of the Invention

[0004] The technical problem to be solved by the present invention is to provide a method and apparatus for calling a distributed permission interface, so as to realize the permission check of the distributed calling interface.

[0005] To solve the above-mentioned technical problems, the technical solution adopted by the present invention is as follows: A distributed permission interface invocation method, the method comprising: This device requests a target authorization file from the management server through the target service corresponding to the target application; The management server packages the target authorization file into the installation package of the target application and sends the installation package to the local device; The local device installs the target application according to the installation package and reads the target license file; When the local device obtains the target application's call request for the target interface, it determines whether there is a corresponding permission in the target authorization file. If there is, it sends the call request to the remote device for interface call processing.

[0006] To solve the above-mentioned technical problems, another technical solution adopted by the present invention is as follows: A distributed permission interface call system includes a management server, a local device, and a remote device; The local device is configured to request a target authorization file from the management server through the target service corresponding to the target application; The management server is configured to package the target authorization file into the installation package of the target application and send the installation package to the local device; The local device is also configured to install the target application according to the installation package and read the target license file; The local device is also configured to, when obtaining a call request from the target application to the target interface, determine whether there is a corresponding permission in the target authorization file; if so, send the call request to the remote device for interface call processing.

[0007] To solve the above-mentioned technical problems, another technical solution adopted by the present invention is as follows: An electronic device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the computer program to implement the steps of the distributed access control interface invocation method described above.

[0008] The beneficial effects of this invention are as follows: by setting the target license files of different types of devices in the management server, the installation of the target license files can be effectively protected; when an application is released, the corresponding target license files are obtained and packaged into an installation package on the local device, so that the local device obtains the corresponding target license files at the same time as installing the application, and when the target application issues a call request to the target interface, the corresponding permissions are checked in the target license file before the call request is sent to the remote device for interface call processing, thereby realizing the application's call to the distributed interface and checking the permissions of the called interface. Attached Figure Description

[0009] Figure 1 This is a flowchart illustrating the steps of a distributed permission interface invocation method in an embodiment of the present invention; Figure 2 This is a sequence diagram of a distributed permission interface invocation method in an embodiment of the present invention; Figure 3 This is a schematic diagram of the structure of a distributed permission interface system in an embodiment of the present invention. Figure 4 This is a schematic diagram of the structure of an electronic device according to an embodiment of the present invention. Detailed Implementation

[0010] To explain in detail the technical content, objectives, and effects of the present invention, the following description is provided in conjunction with the embodiments and accompanying drawings.

[0011] In the related art, for example, in the transaction permission verification scene in the financial payment system, when a payment transaction is performed, the application may need to obtain account information, initiate a transfer, and the like. In order to prevent data leakage and malicious attacks, the application needs to verify the interface call permission of the application when performing these operations, and only the authorized application can obtain the account information or initiate the transfer operation, thereby preventing data leakage and preventing malicious attacks. Therefore, permission interface checking is one of the key means to prevent unauthorized access, data leakage, and malicious attacks. However, the permission interface checking is usually applied to fixed interfaces and cannot meet the checking of distributed device interfaces.

[0012] To solve the above technical problems, the present application provides a distributed permission interface calling method and device, which realizes the checking of the permission of the distributed calling interface, specifically as follows: A distributed permission interface calling method, the method comprising: The local device applies a target authorization file from a management server through a target service corresponding to a target application; The management server packs the target authorization file into an installation package of the target application, and sends the installation package to the local device; The local device installs the target application according to the installation package, and reads the target authorization file; When the local device obtains a calling request of the target application to a target interface, it is judged whether there is a corresponding permission in the target authorization file, if there is, the calling request is sent to the remote device for interface calling processing.

[0013] From the above description, the beneficial effects of the present application are that by setting the target authorization files of different types of devices in the management server, the target authorization files can be effectively protected when installed; when the application is published, the corresponding target authorization file is obtained and packed into an installation package in the local device, so that the local device obtains the corresponding target authorization file when installing the application, and when the target application issues a calling request to the target interface, the calling request is sent to the remote device for interface calling processing after judging whether there is a corresponding permission in the target authorization file, thereby realizing the calling of the application to the distributed interface and checking the permission of the calling interface.

[0014] Further, the target authorization file is applied from the management server through a target service corresponding to a target application, comprising: The management server obtains authorization content according to the target service, and generates the target authorization file by signing the authorization content with a private key; The target authorization file is read, comprising: The local device reads the target authorization file, and verifies the signature of the target authorization file using a preset public key corresponding to the private key, and if the verification is passed, the authorization content is read.

[0015] As described above, the target authorization file is generated by signing the authorization content with the private key after obtaining the authorization content, and the target authorization file is verified by the public key corresponding to the private key when reading the target authorization file, thereby ensuring the security of the target authorization file.

[0016] Further, the authorization content includes an application package name and an application ID. The reading of the target authorization file further includes: The local device determines whether the application package name and the application ID in the authorization content are consistent with the application package name and the application ID of the installed target application, and if they are consistent, the authorization content is saved.

[0017] As described above, the consistency of the application package name and the application ID in the authorization content and the application package name and the application ID of the installed target application is verified to ensure that the permission configuration is not modified.

[0018] Further, the reading of the target authorization file further includes: The local device sends the authorization content to another target local device installed with the target application for verification, and if the verification is successful, the target local device saves the authorization content.

[0019] As described above, the authorization content is sent to another device installed with the target application for verification, which supports distributed verification across devices.

[0020] Further, the call request includes an application package name of the target application and an interface permission level. The determination of whether the target authorization file includes a permission corresponding to the target interface includes: The authorization content corresponding to the target application is obtained according to the application package name. The interface permission level corresponding to the authorization content and the target interface is obtained. It is determined whether the interface permission level is not less than the interface permission level, and if so, the call request is sent to the remote device for interface call processing.

[0021] As described above, by comparing the interface permission level with the interface permission level, the call request can only be obtained within the interface permission level to obtain part of the authorization, thereby realizing the division of the permission level of each interface supporting distributed call.

[0022] Further, the method further comprises: establishing a distributed connection between the local device and the remote device; sending, by the remote device, the stored configuration list to the local device; verifying, by the local device, the configuration list, and saving the configuration list after successful verification.

[0023] As described above, by synchronizing the device permission configuration list after establishing a distributed connection between the local device and the remote device, the target application of the local device calls the distributed interface, and the interface permission is checked by the local device.

[0024] Further, the local device further comprises: acquiring, by the management server, an operating system type corresponding to the target application, and acquiring the target authorization file according to the operating system type and the target service.

[0025] As described above, the target authorization file is acquired according to the operating system type and the target service, so that different permissions can be set for applications under different operating systems.

[0026] Further, the method further comprises: receiving, by the local device, an update request of the target application, acquiring an update authorization file from the management server according to the update request, and updating the target authorization file according to the update authorization file.

[0027] As described above, by updating the target authorization file of the target application, the operation permission of the target application can be updated in time.

[0028] Further, the update authorization file comprises a first version number, and the target authorization file comprises a second version number. The updating of the target authorization file according to the update authorization file comprises: if the second version number is different from the first version number, the update authorization file is used as a new target authorization file.

[0029] As described above, when updating the target authorization file, if the second version number is different from the first version number, it means that the permission of the target application on the management server is adjusted, and by updating the target authorization file, it is avoided that the current permission of the target application exceeds the updated permission.

[0030] Another embodiment of the present application provides a distributed permission interface calling system, comprising a management server, a local device and a remote device; the local device is configured to apply for a target authorization file from the management server through a target service corresponding to a target application; the management server is configured to package the target authorization file into an installation package of the target application and send the installation package to the local device; the local device is further configured to install the target application according to the installation package and read the target authorization file; and the local device is further configured to, when obtaining a calling request of the target application to a target interface, judge whether there is a corresponding permission in the target authorization file, and if so, send the calling request to the remote device for interface calling processing.

[0031] Another embodiment of the present application provides an electronic device, comprising a memory, a processor and a computer program stored in the memory and executable on the processor, and each step of the distributed permission interface calling method is implemented when the processor executes the computer program.

[0032] The distributed permission interface calling method, system and electronic device provided by the present application can be applied to distributed devices of different systems such as Android system and OpenHarmony system, and through strict checking of the permissions supporting distributed calling interfaces in the devices, it can be ensured that only legal devices and applications can access corresponding resources and functions, thereby reducing the security risk, which will be described below through a specific embodiment: Please refer to Figure 1 A distributed permission interface calling method applied to a distributed system, the distributed system comprising a management server, a local device and a remote device; wherein after the local device and the remote device establish a distributed connection, the local device sends its local configuration file to the remote device, and the remote device saves (device ID, device permission configuration list) mapping table data after successfully verifying the configuration file. The method comprises: S1, the local device applies for a target authorization file from the management server through a target service corresponding to a target application; that is, a configuration interface permission list is generated for devices of different system types on the management server, such as lightweight system, small system, standard system according to the function integration situation of the system, and Android system, OpenHarmony system and the like according to the platform, and the permission list is as shown in Table 1: Table 1. Permission list

[0033] Different interface permissions are configured in one authorization file; the target application calling the distributed interface needs to apply for the authorization file from the management server; the authorization content divides the permissions of the interfaces supporting the distributed call into levels, including but not limited to: application package name, application appID (application signature certificate fingerprint), interface permission list, and interface permission level in the interface permission list; when the application is granted the distributed interface call permission, the distributed interface with the corresponding permission level is allowed to be called, as shown in Table 2 below: Table 2. Permission content list

[0034] The management server obtains the authorization content according to the target service and the operating system type, signs the authorization content by a private key to generate the target authorization file; that is, the permission configuration is uniformly signed by the management service platform, and the permission configuration is bound with the appID (i.e. application signature certificate fingerprint) of the application, so that the permission configuration cannot be replaced or tampered. At the same time, each application applies for the permission of the corresponding service interface according to the service used by the application, so that the target authorization file applied for by different applications is different.

[0035] S2, the management server packs the target authorization file into the installation package of the target application, and sends the installation package to the local device; for example, before the application is released, the developer applies for the authorization file from the management server, and the authorization file after the application is packaged into the application installation package; if the platform to which the application belongs is an Android platform, the authorization file is packaged into an apk installation package and saved in the assets path; if the platform to which the application belongs is an OpenHarmony platform, the authorization file is packaged into a hap installation package and saved in the rawfile path, so that the permission configuration is installed with the application to the device; after the application is installed to the device, the distributed service module in the device uniformly loads and verifies, or adopts the distributed verification mode across devices.

[0036] S3, the local device installs the target application according to the installation package, and reads the target authorization file. When the local device installs the target application, the distributed service module in the local device scans the installed application list, reads the authorization file of the target application, verifies the signature of the target authorization file by using the preset public key corresponding to the private key, and reads the authorization content if the verification is passed; for example, the application package name and the application ID in the authorization content are detected to check whether they are consistent with the application package name and the application ID of the installed target application; if they are consistent, the authorization content is saved; if they are not consistent, the verification is not passed.

[0037] The remote device sends a configuration list stored by the remote device to the local device after the distributed connection is established between the local device and the remote device, and the local device verifies the configuration list and saves the configuration list after the verification is successful. In an optional embodiment, the following steps 1 to 4 are included. 1. The local device and the remote device establish a distributed connection and synchronize the device permission configuration list. 2. When the target application is installed on the local device, the local device checks the authorization file of the target application, and saves the authorization file after the verification is passed.

[0038] 3. When the target application of the local device requests to call the distributed interface of the remote device, the local device checks the permission list in the authorization file of the target application (i.e., the permission in the authorization file saved in step 2) and the permission configuration list of the remote device (i.e., the configuration list saved in step 1), and sends the calling request to the remote device after the check is passed.

[0039] 4. The remote device processes the distributed interface calling request and returns the result.

[0040] When the application is updated, the local device receives an update request of the target application, applies for an update authorization file from the management server according to the update request, and updates the target authorization file according to the update authorization file. The update authorization file includes a first version number, and the target authorization file includes a second version number. If the second version number is different from the first version number, the update authorization file is used as a new target authorization file. In other optional embodiments, the target authorization file of the target application in the device can also be updated by issuing an update command by the management server.

[0041] S4. When the local device obtains a calling request of the target application to a target interface, it is judged whether the target authorization file includes a permission corresponding to the target interface. If yes, the calling request is sent to the remote device for interface calling processing.

[0042] In an optional embodiment, the judgment is performed by the following steps: S41. Obtain the authorization content corresponding to the target application based on the application package name; for example, when the application calls the distributed interface, the distributed service module in the local device obtains the package name of the target application from the application management service through the identity UID of the target application; wherein, the application management service is a service in the device responsible for managing application installation packages, providing capabilities such as information query, installation, update, uninstallation and package information storage of installation packages; on the Android platform, the application management service is PackageManagerService, abbreviated as PMS; on the OpenHarmony platform, the application management service is BundleManagerService, abbreviated as BMS.

[0043] S42. Obtain the interface permission level corresponding to the authorized content and the target interface; In actual applications, the distributed service module searches for the permission configuration list of the device based on the device ID, and searches for its authorized content based on the package name to obtain information such as the interface permission level.

[0044] S43. Determine whether the interface permission level is not lower than the interface permission level. If so, send the call request to the remote device for interface call processing. That is, when the authorization content contains the authorization level corresponding to the interface permission declared in the permission configuration list of the device to which the interface belongs, the interface permission check passes, and then the relevant processing flow of the interface call is carried out, and the interface call request is sent to the distributed service module of the remote device for interface call processing.

[0045] This document provides an example of applying the aforementioned distributed permission interface invocation method to a specific application scenario. For instance, it illustrates how a smart POS payment application can be invoked by a smart cash register's ordering application. Figure 2 As shown: Before executing the call, the ordering application needs to be downloaded to the smart POS machine: T01. The local device requests a target authorization file from the management server based on the target business corresponding to the target application; that is, the smart POS machine requests an authorization file related to the ordering service from the management server based on the ordering service to be executed by the ordering application. For example, the interface permission list in the authorization file includes: [interface A, permission aaa], [interface B, permission aab]; where interface A is the interface used for QR code payment.

[0046] T02. The management server packages the target authorization file into the installation package of the target application and sends the installation package to the local device; the management server packages the above interface permission list: [interface A, permission aaa], [interface B, permission aab] into the installation package of the ordering application and sends the installation package to the smart cash register.

[0047] T03, The terminal device installs the target application according to the installation package, and reads the target authorization file; the intelligent cash register completes the installation of the ordering application according to the installation package, and reads the interface permission list [interface A, permission aaa], [interface B, permission aab] in the authorization file.

[0048] T1, When the application needs to call a remote distributed interface, the device ID (i.e. the ID of the remote device) and the interface call request are sent; when the ordering application of the intelligent cash register generates an order and needs to call the scan code payment interface of the payment application on the intelligent POS, the ID corresponding to the intelligent POS and the interface call request are sent; for example, the scan code payment interface is interface A.

[0049] T2, After the terminal device receives the interface call request and the device ID, the permission configuration list of the device is found according to the device ID; that is, the intelligent cash register obtains the interface permission list of the intelligent POS corresponding to the ID of the intelligent POS, which is: [interface A, permission aaa], [interface B, permission bbb].

[0050] T3, The terminal device reads the authorization file of the application, and verifies the signature of the authorization file using the preset public key to check the authorization information. The intelligent cash register reads the authorization file of the ordering application and checks it.

[0051] T4, The terminal device reads the application signature certificate fingerprint to check whether the appID of the authorization information is consistent with the certificate fingerprint; if they are consistent, T5 is executed. The intelligent cash register reads the application signature certificate fingerprint of the ordering application to check whether the appID of the authorization information is consistent with the certificate fingerprint.

[0052] T5, Check whether the authorization information exists in the interface permission corresponding to the authorization level declared in the permission configuration list of the device calling the interface; that is, after the intelligent cash register receives the call request for the scan code payment interface and the ID corresponding to the intelligent POS, it needs to check whether the ordering application has the payment permission; in the intelligent cash register, the interface permission list of the application authorization file of the ordering application is: [interface A, permission aaa], [interface B, permission aab]; that is, there is an authorization level corresponding to interface A.

[0053] T6, The terminal device sends a call request to the remote device; the intelligent cash register sends the call request to the payment application of the intelligent POS.

[0054] T7, After the remote device processes the request, the result is fed back to the application of the terminal device; the application further processes the fed-back result. The payment application completes the scan code payment, and then returns the payment result to the ordering application of the intelligent cash register.

[0055] Please refer to Figure 3The application discloses a distributed permission interface calling system, which comprises a management server, a local device and a remote device.

[0056] Please refer to Figure 4 The electronic device comprises a memory, a processor, and a computer program stored in the memory and capable of running on the processor, and the processor implements each step of the distributed permission interface calling method in Embodiment I when executing the computer program.

[0057] In conclusion, the distributed permission interface calling method, system and electronic device provided by the application can effectively protect the target authorization file by setting the target authorization file of different types of devices in the management server; when publishing an application, the corresponding target authorization file is obtained and packaged into an installation package, so that the local device can obtain the corresponding target authorization file when installing the application, and the target authorization file is verified and saved in the local device; when the target application sends a calling request to the target interface, the calling request is sent to the remote device for interface calling processing after judging whether the corresponding permission exists in the target authorization file, so that the permission of the distributed calling interface is checked.

[0058] The above-mentioned embodiments are merely examples of the application, and do not limit the patent scope of the application, and any equivalent transformation or direct or indirect application in the related technical field based on the content of the specification and drawings is also included in the patent protection scope of the application.

Claims

1. A method for invoking a distributed permission interface, characterized in that, The method includes: This device requests a target authorization file from the management server through the target service corresponding to the target application; The management server packages the target authorization file into the installation package of the target application and sends the installation package to the local device; The local device installs the target application according to the installation package and reads the target license file; When the local device obtains the target application's call request for the target interface, it determines whether there is a corresponding permission in the target authorization file. If there is, it sends the call request to the remote device for interface call processing.

2. The distributed permission interface invocation method according to claim 1, characterized in that, The step of requesting the target authorization file from the management server through the target business corresponding to the target application includes: The management server obtains the authorized content based on the target service, and signs the authorized content using a private key to generate the target authorization file; The reading of the target authorization file includes: The local device reads the target authorization file and uses a preset public key corresponding to the private key to verify the signature of the target authorization file. If the verification is successful, the authorization content is read.

3. The distributed permission interface invocation method according to claim 2, characterized in that, The authorized content includes the application package name and the application ID; After reading the target authorization file, the following is included: The local device determines whether the application package name and application ID in the authorized content are consistent with the application package name and application ID of the installed target application. If they are consistent, the authorized content is saved.

4. The distributed permission interface invocation method according to claim 2, characterized in that, The call request includes the target application's application package name and the interface permission level; The step of determining whether the target authorization file contains permissions corresponding to the target interface includes: Obtain the authorization content corresponding to the target application based on the application package name; Obtain the interface permission level corresponding to the authorized content and the target interface; Determine whether the interface permission level is not lower than the interface permission level. If so, send the call request to the remote device for interface call processing.

5. The distributed permission interface invocation method according to claim 1, characterized in that, Also includes: A distributed connection is established between the local device and the remote device; The remote device sends its stored configuration list to the local device; The local device verifies the configuration list and saves it after successful verification.

6. The distributed permission interface invocation method according to claim 1, characterized in that, The process of the local device requesting the target authorization file from the management server through the target service corresponding to the target application also includes: The management server obtains the operating system type corresponding to the target application, and obtains the target authorization file based on the operating system type and the target business.

7. The distributed permission interface invocation method according to claim 1, characterized in that, Also includes: The local device receives the update request of the target application, requests an update authorization file from the management server according to the update request, and updates the target authorization file according to the update authorization file.

8. A distributed permission interface invocation method according to claim 7, characterized in that, The updated license file includes a first version number, and the target license file includes a second version number; The step of updating the target license file according to the updated license file includes: If the second version number is different from the first version number, then the updated license file will be used as the new target license file.

9. A distributed permission interface invocation system, characterized in that, This includes management servers, local devices, and remote devices; The local device is configured to request a target authorization file from the management server through the target service corresponding to the target application; The management server is configured to package the target authorization file into the installation package of the target application and send the installation package to the local device; The local device is also configured to install the target application according to the installation package and read the target license file; The local device is also configured to, when obtaining a call request from the target application to the target interface, determine whether there is a corresponding permission in the target authorization file. If so, send the call request to the remote device for interface call processing.

10. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements each step of the distributed permission interface invocation method as described in any one of claims 1-8.