Authentication method and device, first node, storage medium and computer program product

By pre-storing authentication information in the first node and generating unified authentication information, the problem of increased development costs caused by differences in authentication logic among sub-nodes in the network architecture is solved, and automated encapsulation and communication security are achieved.

CN121125152APending Publication Date: 2025-12-12CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510796783.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-13
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

In the network architecture, the authentication logic used by each sub-node is different, which requires customized development for each sub-node, increasing development costs.

Method used

The first node pre-stores authentication information, generates unified authentication information based on the information of the second node to be requested, and carries it in the interface call request, thus shielding the differences in authentication logic among the various second nodes and achieving automated encapsulation.

Benefits of technology

It reduces development costs, ensures the communication security of the network system, and eliminates the need for customized development for each child node.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125152A_ABST
    Figure CN121125152A_ABST
Patent Text Reader

Abstract

The invention discloses an authentication method and device, a first node, a storage medium and a computer program product, and the first node is connected with one or more second nodes. The method comprises the following steps: a first node queries first information corresponding to a second node to be requested from one or more pieces of pre-stored first information; each piece of first information in the one or more pieces of first information is used for describing authentication information required by one second node, and the authentication information is used for the second node to authenticate the node initiating the interface calling request; generating second information based on the first information corresponding to the to-be-requested second node; the second information represents authentication information corresponding to the second node to be requested; and sending an interface calling request to the to-be-requested second node, wherein the interface calling request carries the second information.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, and particularly relates to an authentication method and device, a first node, a storage medium and a computer program product. BACKGROUND

[0002] In the related art, a center node in a networking architecture sends authentication information to a plurality of child nodes accessing the center node respectively, so as to realize authentication of the child nodes to the center node and further secure communication. However, there are differences between authentication logics used by the child nodes, which leads to the need for customized development of the center node for the authentication logic of each child node, thereby increasing development cost. SUMMARY

[0003] To solve the problems in the related art, the embodiments of the present application provide an authentication method and device, a first node, a storage medium and a computer program product.

[0004] The technical scheme of the embodiments of the present application is implemented as follows:

[0005] The embodiments of the present application provide an authentication method applied to a first node, wherein the first node accesses one or more second nodes; and the method comprises the following steps.

[0006] querying first information corresponding to a second node to be requested from one or more first information pre-stored; each of the one or more first information is used to describe authentication information required by a second node, and the authentication information is used to authenticate a node initiating an interface call request by the second node;

[0007] generating second information based on the first information corresponding to the second node to be requested; the second information represents authentication information corresponding to the second node to be requested;

[0008] sending an interface call request to the second node to be requested, wherein the interface call request carries the second information.

[0009] In the above scheme, the second information is generated based on the first information corresponding to the second node to be requested, comprising:

[0010] determining parameter values corresponding to one or more authentication parameters based on the first information corresponding to the second node to be requested, and generating the second information based on the determined parameter values corresponding to the one or more authentication parameters.

[0011] In the above scheme, the determination of the parameter values corresponding to the one or more authentication parameters comprises:

[0012] For each authentication parameter in the one or more authentication parameters:

[0013] If the first information does not describe the parameter value of the authentication parameter, the parameter value of the authentication parameter is determined based on the parameter type of the authentication parameter described in the first information; and / or,

[0014] If the first information describes the parameter value of the authentication parameter, the parameter value of the authentication parameter is read from the set cache.

[0015] In the above scheme, after determining the parameter value of the authentication parameter, the method further includes:

[0016] The value of the authentication parameter is stored in the specified cache.

[0017] In the above scheme, generating the second information based on the parameter values ​​corresponding to the determined one or more authentication parameters includes:

[0018] When the one or more authentication parameters include one or more first authentication parameters, a signature is generated based on the parameter values ​​corresponding to the determined one or more first authentication parameters to obtain the second information; the first authentication parameters represent authentication parameters used as components of the signature algorithm.

[0019] In the above scheme, generating the second information based on the parameter values ​​corresponding to the determined one or more authentication parameters includes:

[0020] When the one or more authentication parameters include one or more second authentication parameters, the parameter name and parameter value corresponding to the one or more second authentication parameters are generated as the second information; the second authentication parameter represents an authentication parameter that is not used as a component of the signature algorithm.

[0021] In the above scheme, the first information includes one or more of the following fields related to authentication parameters:

[0022] The first field describes the name of the authentication parameter.

[0023] The second field describes the parameter values ​​of the authentication parameters;

[0024] The third field describes the parameter type of the authentication parameter;

[0025] The fourth field describes whether the authentication parameter is a component of the signature algorithm.

[0026] The fifth field describes the signature generation algorithm;

[0027] The sixth field describes the storage path of the first file, which represents the file that the signature generation algorithm depends on when it is invoked.

[0028] The seventh field describes the order in which the signature algorithm components are arranged when forming the signature;

[0029] The eighth field describes whether the authentication parameter value is stored in a designated cache.

[0030] The ninth field describes the storage path of the second file, which is used to determine the value of the authentication parameter when the parameter type of the authentication parameter is an authentication file.

[0031] The tenth field describes the location of the corresponding authentication information encapsulated in the interface call request.

[0032] In the above scheme, the first information includes a first identifier, which represents the identifier of the corresponding second node;

[0033] Correspondingly, retrieving the first information corresponding to the requested second node from one or more pre-stored first information includes:

[0034] Based on the identifier of the second node to be requested, a query is performed in the one or more pieces of first information to obtain the query results;

[0035] If the first identifier in the query result representing a first piece of information matches the identifier of the second node to be requested, then the first piece of information is determined to be the first piece of information corresponding to the second node to be requested.

[0036] In the above scheme, the first information is stored in the first node when the corresponding second node accesses the first node.

[0037] This application embodiment also provides an authentication device, applied to a first node, the first node being connected to one or more second nodes; including:

[0038] The query unit is used to query the first information corresponding to the second node to be requested from one or more pre-stored first information; each of the one or more first information is used to describe the authentication information required by a second node, and the authentication information is used by the second node to authenticate the node that initiates the interface call request.

[0039] The generation unit is configured to generate second information based on the first information corresponding to the second node to be requested; the second information represents the authentication information corresponding to the second node to be requested.

[0040] The sending unit is used to send an interface call request to the second node to be requested, the interface call request carrying the second information.

[0041] This application embodiment also provides a first node, including a first processor and a first communication interface;

[0042] The first processor is configured to query the first information corresponding to the second node to be requested from one or more pre-stored first information; each of the one or more first information is used to describe the authentication information required by a second node, the authentication information being used by the second node to authenticate the node initiating the interface call request; and,

[0043] Based on the first information corresponding to the second node to be requested, second information is generated; the second information represents the authentication information corresponding to the second node to be requested.

[0044] The first communication interface is used to send an interface call request to the second node to be requested, and the interface call request carries the second information.

[0045] This application also provides a first node, including: a first processor and a first memory for storing a computer program capable of running on the processor.

[0046] Wherein, when the first processor is used to run the computer program, it executes the steps of any of the above methods.

[0047] This application also provides a storage medium storing a computer program thereon, characterized in that the computer program, when executed by a processor, implements the steps of any of the above methods.

[0048] This application also provides a computer program product, including a computer program, characterized in that, when the computer program is executed by a processor, it implements the steps of any of the above methods.

[0049] In this embodiment, the first node queries one or more pre-stored first information entries to find the first information corresponding to the second node to be requested. The first node is connected to one or more second nodes, and each piece of first information describes the authentication information required by a second node. This authentication information is used by the second node to authenticate the node initiating the interface call request. Then, the first node generates second information based on the first information corresponding to the second node to be requested. Here, the second information represents the authentication information corresponding to the second node to be requested. Afterward, the first node sends an interface call request to the second node to be requested, and the interface call request carries the second information. In the above scheme, the first node can automatically generate the authentication information required by each second node according to the description of the pre-stored first information, and carry the corresponding authentication information when sending the interface call request to the second node. Thus, the first node can generate the authentication information required by each second node based on a unified processing logic, thereby automatically encapsulating the interface call request and shielding the differences in authentication logic between the various second nodes. Compared with related technologies, it eliminates the need for customized development of the first node for the second node, and also ensures communication security in the network system composed of the first and second nodes, thereby reducing development costs. Attached Figure Description

[0050] Figure 1 A schematic diagram illustrating the implementation flow of an authentication method provided in an embodiment of this application;

[0051] Figure 2 A schematic diagram illustrating a node access process provided in an embodiment of this application;

[0052] Figure 3 A flowchart illustrating an authentication method provided for an application embodiment of this application;

[0053] Figure 4 This is a schematic diagram of the structure of an authentication device provided in an embodiment of this application;

[0054] Figure 5 This is a schematic diagram of the hardware structure of a first node provided in an embodiment of this application. Detailed Implementation

[0055] With the development of the Internet industry, many network systems based on network architecture design have emerged at present. For example, privacy computing systems are designed based on a network architecture of transaction platform-multiple delivery platform-multiple privacy computing node mode, or data open systems are designed based on a network architecture of transaction platform-data open management platform-multiple data governance center mode.

[0056] In practical applications, a network architecture may include a central node and multiple child nodes. Child nodes can connect to the central node. For example, in a network architecture of a trading platform-multiple delivery platforms-multiple privacy computing nodes, the trading platform can be understood as the central node, and the delivery platforms and privacy computing nodes can be understood as child nodes.

[0057] In related technologies, the central node in a network architecture sends authentication information to multiple child nodes connected to the central node to achieve authentication of the central node by the child nodes and further secure communication. However, in practical applications, child nodes are usually developed through a multi-party collaborative approach, meaning that multiple developers jointly undertake the development of multiple child nodes. Different developers undertake different child nodes, and the authentication logic set by each developer during the development process may be different. This will lead to differences in the authentication logic used by each child node, which in turn requires customized development of the central node for the authentication logic of each child node to ensure communication security in the corresponding network system, increasing development costs.

[0058] Based on this, in this embodiment, the first node queries one or more pre-stored first information to find the first information corresponding to the second node to be requested; wherein, the first node is connected to one or more second nodes, and each piece of first information in the one or more pieces of first information is used to describe the authentication information required by a second node. The authentication information is used by the second node to authenticate the node initiating the interface call request; then, the first node generates second information based on the first information corresponding to the second node to be requested. Here, the second information represents the authentication information corresponding to the second node to be requested; then, the first node sends an interface call request to the second node to be requested, and the interface call request carries the second information. In the above scheme, the first node can automatically generate the authentication information required by each second node according to the description of the pre-stored first information, and carry the corresponding authentication information when sending the interface call request to the second node. In this way, the first node can generate the authentication information required by each second node based on a unified processing logic, and then automatically encapsulate the interface call request, thereby shielding the differences between the authentication logic of each second node. Compared with related technologies, it is not necessary to customize the first node for the second node, and it can also ensure the communication security in the network system composed of the first node and the second node, thereby reducing the development cost.

[0059] The present application will now be described in further detail with reference to the accompanying drawings and embodiments.

[0060] This application provides an authentication method applied to a first node, which is connected to one or more second nodes, that is, there are one or more second nodes connected to the first node.

[0061] In practical applications, the first node and the second node can form a network to create a network system. The first node can be regarded as the central node in the network architecture corresponding to the network system, and the second node can be regarded as a child node in the network architecture corresponding to the network system.

[0062] See Figure 1 The authentication method provided in this application includes:

[0063] Step 101: Query the first information corresponding to the second node to be requested from one or more pre-stored first information.

[0064] Each of the first pieces of information is used to describe the authentication information required by a second node. The authentication information is used by the second node to authenticate the node that initiates the interface call request.

[0065] In practical applications, the first node can initiate an interface call request to the second node, carrying the authentication information required by the second node in the request. Upon receiving the interface call request, the second node can authenticate the first node based on the authentication information carried in the request, and determine whether to proceed with further communication based on the authentication result, thereby ensuring communication security. For example, the second node can proceed with further communication with the first node if the authentication result indicates successful authentication.

[0066] In practical applications, authentication information can also be described as certification information. Authentication information may include one or more information items, and the data form of the information items in authentication information can be represented as key-value pairs.

[0067] For example, the authentication information may include “username: A” and “authCode: B”, where “username: A” and “authCode: B” can both be understood as information items, and the data form of these two information items in the authentication information is a key-value pair. “username” and “authCode” can both be understood as the key name of the key-value pair, and “A” and “B” can both be understood as the value of the key-value pair.

[0068] Due to the differences in authentication logic among the various second nodes, the authentication information required by different second nodes may differ. For example, the authentication information required by second node A may only include an information field with the key name "username", while the authentication information required by second node B may only include an information field with the key name "authCode". It can be seen that the authentication information required by second node A and second node B is different.

[0069] Here, the first information describes the authentication information required by the corresponding second node. In practical applications, the first information can be pre-entered by the user into the first node. The first node can generate the authentication information required by the corresponding second node based on the first information. The first information can describe the generation method of the authentication information. The first information can also be expressed as authentication description information.

[0070] In practical applications, authentication information can be generated based on one or more authentication parameters. The first information can describe the authentication information required by the corresponding second node by describing these authentication parameters. For example, the first information can describe at least one or more of the following information of the authentication parameters: parameter name, parameter value, and parameter type.

[0071] Here, the first node pre-stores one or more pieces of first information. In practical applications, the first node can determine the second node to be requested based on business needs. For example, business needs may include data synchronization needs or work order information synchronization needs, etc. Then, the first node can query the first information corresponding to the second node to be requested from the one or more pieces of pre-stored first information.

[0072] In one embodiment, the first information includes a first identifier, which represents the identifier of the corresponding second node;

[0073] Correspondingly, the first information corresponding to the requested second node is retrieved from one or more pre-stored first information sources, including:

[0074] Based on the identifier of the second node to be requested, a query is performed in one or more pieces of first information to obtain the query results;

[0075] If the first identifier in the query result representing a first piece of information matches the identifier of the second node to be requested, then the first piece of information is identified as the first piece of information corresponding to the second node to be requested.

[0076] In practical applications, when the first node identifies a second node to be requested, it can determine the identifier of the second node by querying a preset identifier mapping relationship. Then, based on the identifier of the second node, it queries one or more pieces of first information. During the query process, the identifier of the second node can be matched with the first identifiers in each piece of first information to obtain the query results. If the query results indicate that the first identifier in a piece of first information matches the identifier of the second node, then that piece of first information is identified as the first information corresponding to the second node to be requested. In this way, the first information corresponding to the second node to be requested can be retrieved efficiently, improving authentication efficiency.

[0077] Step 102: Generate second information based on the first information corresponding to the second node to be requested.

[0078] The second information represents the authentication information corresponding to the second node to be requested.

[0079] Here, the first node generates the authentication information required by the second node based on the first information corresponding to the second node to be requested.

[0080] In practical applications, authentication information can be generated based on one or more authentication parameters. The first information corresponding to the second node to be requested can describe the authentication information required for the second node by describing one or more authentication parameters; the first node can determine one or more authentication parameters based on the first information corresponding to the second node to be requested, and then generate the second information.

[0081] Step 103: Send an interface call request to the second node to be requested.

[0082] The API call request carries a second piece of information.

[0083] In practical applications, the first node can encapsulate the second information within the API call request, enabling the API call request to carry the second information and thus achieving automated encapsulation of the API call request, i.e., automated encapsulation of the communication interface. The second information can be encapsulated in at least one or more of the following locations within the API call request: request URL, request header, and request body.

[0084] The various information items in the second information can be encapsulated in different locations within the API call request. For example, when the second information includes information item 1 and information item 2, information item 1 can be encapsulated in the request header of the API call request, and information item 2 can be encapsulated in the request body of the API call request.

[0085] In practical applications, the first information can describe the location of the corresponding authentication information encapsulated in the interface call request. In other words, the first information corresponding to the second node to be requested can describe the location of the second information encapsulated in the interface call request.

[0086] In this embodiment, the first node can automatically generate the authentication information required by each second node based on the description of the pre-stored first information, and carry the corresponding authentication information when sending the interface call request to the second node. In this way, the first node can generate the authentication information required by each second node based on a unified processing logic, and then automatically encapsulate the interface call request, thereby shielding the differences between the authentication logic of each second node. Compared with related technologies, it does not require customized development of the first node for the second node, and can also ensure the communication security in the network system composed of the first node and the second node, thereby reducing development costs.

[0087] In practical applications, the first node and the second node in this embodiment can be deployed in different network environments, such as government networks or cloud platforms. Even when deployed in a private network environment, the authentication of the first node by the second node can be guaranteed, thereby ensuring communication security.

[0088] The generation method of authentication information will be further explained below.

[0089] In one embodiment, second information is generated based on first information corresponding to the second node to be requested, including:

[0090] Based on the first information corresponding to the second node to be requested, determine the parameter values ​​corresponding to one or more authentication parameters, and generate the second information based on the determined parameter values ​​corresponding to one or more authentication parameters.

[0091] In practical applications, the first piece of information can describe at least one or more of the following information related to the authentication parameters: parameter name, parameter value, and parameter type.

[0092] The parameter values ​​described in the first information can be understood as preset parameter values ​​of the corresponding authentication parameters. The first node can determine the parameter values ​​of the corresponding authentication parameters based on these preset parameter values.

[0093] The parameter type can be understood as the data type of the parameter value corresponding to the authentication parameter. For example, the parameter type may include: signature, timestamp, random number, or authentication file, etc.

[0094] In practical applications, the first node can also determine the parameter names corresponding to one or more authentication parameters based on the first information corresponding to the second node to be requested, and then generate the second information based on the parameter values ​​and parameter names corresponding to the determined one or more authentication parameters.

[0095] In one embodiment, determining parameter values ​​corresponding to one or more authentication parameters includes:

[0096] For each of one or more authentication parameters:

[0097] If the parameter value of the authentication parameter is not described in the first information, the parameter value of the authentication parameter is determined based on the parameter type described in the first information; and / or,

[0098] If the first information describes the parameter value of the authentication parameter, the parameter value of the authentication parameter is read from the set cache.

[0099] In practical applications, when the first node determines the parameter value of the authentication parameter based on the parameter type, it can generate the parameter value corresponding to that parameter type.

[0100] When the authentication parameter is of type signature, the first node can concatenate one or more signature algorithm components corresponding to the authentication parameter to obtain a first string. The signature algorithm components corresponding to the authentication parameter can be combined into the first string based on a set arrangement order. Then, the first node can call the set signature generation algorithm to process the first string to obtain signature type data, that is, to obtain the signature, and determine the signature as the parameter value of the authentication parameter.

[0101] For example, the specified signature generation algorithm may include: Message-Digest Algorithm Version 5 (MD5), Secure Hash Algorithm 256-bit (SHA256), Data Encryption Standard (DES), Advanced Encryption Standard (AES), and custom algorithms. Custom algorithms can be understood as algorithms designed by the developers themselves, which differ from commercially available mature signature generation algorithms.

[0102] When the signature generation algorithm is set to a custom algorithm, the first node can call the custom algorithm based on the call to the set dependency files. The dependency files can be understood as the toolkits that are relied upon when calling the custom algorithm.

[0103] Among them, the signature algorithm components, the set arrangement order, the set signature generation algorithm, and the set dependent files can all be determined based on the description of the first information.

[0104] When the authentication parameter is of type timestamp, the first node can generate timestamp data, that is, generate a timestamp and set the timestamp as the parameter value of the authentication parameter. For example, a timestamp corresponding to the time when the parameter value is determined can be generated and set as the parameter value of the authentication parameter.

[0105] When the authentication parameter is of type random number, the first node can generate a random number sequence and use this random number sequence as the parameter value of the authentication parameter.

[0106] When the authentication parameter type is an authentication file, the first node can obtain the authentication file based on the set authentication file path and set the authentication file as the parameter value of the authentication parameter. The set authentication file path can be determined based on the description of the first information.

[0107] In practical applications, when the first node reads the parameter value of the authentication parameter from the set cache, if the reading result indicates that the parameter value of the authentication parameter exists in the set cache, the first node can determine the read parameter value as the parameter value of the authentication parameter; if the reading result indicates that the parameter value of the authentication parameter does not exist in the set cache, the first node can determine the parameter value described in the first information as the parameter value of the authentication parameter.

[0108] In this embodiment, based on the description of the parameter value of the authentication parameter in the first information, the parameter value of the authentication parameter is determined by selecting the parameter type of the authentication parameter and / or the parameter value described in the first information, which increases the flexibility of determining the parameter value of the authentication parameter, thereby increasing the flexibility of authentication.

[0109] Furthermore, in the embodiments of this application, when the parameter value of the authentication parameter is described in the first information, the parameter value of the authentication parameter is read from the set cache first, which improves the efficiency of determining the parameter value and thus improves the efficiency of authentication.

[0110] In one embodiment, after determining the value of the authentication parameter, the authentication method provided in this application further includes:

[0111] Store the value of the authentication parameter in the designated cache.

[0112] In practical applications, if the first information description requires caching of the authentication parameter, the parameter value of the authentication parameter can be stored in a designated cache, thereby increasing the flexibility in determining the authentication parameter.

[0113] In practical applications, the first node may determine one or more authentication parameters based on the first information corresponding to the second node to be requested. These parameters may include one or more first authentication parameters and / or one or more second authentication parameters.

[0114] The first authentication parameter can characterize the authentication parameter used as a component of the signature algorithm. That is, the first authentication parameter can be used to generate a signature, and then used to determine the parameter value of the second authentication parameter whose parameter type is signature. For example, the parameter value of the first authentication parameter can be used as a component of the signature algorithm. The parameter value of the second authentication parameter can be used to generate the second information.

[0115] In one embodiment, generating second information based on parameter values ​​corresponding to one or more determined authentication parameters includes:

[0116] When one or more authentication parameters include one or more second authentication parameters, the parameter names and parameter values ​​corresponding to the one or more second authentication parameters are generated as second information; the second authentication parameters represent authentication parameters that are not used as components of the signature algorithm.

[0117] In practical applications, each second authentication parameter can correspond to an information item in the second information. When the data of the information item in the second information is in the form of a key-value pair, the key name of the key-value pair can be represented as the parameter name of the corresponding second authentication parameter, and the key value of the key-value pair can be represented as the parameter value of the corresponding second authentication parameter.

[0118] In one embodiment, generating second information based on parameter values ​​corresponding to one or more determined authentication parameters includes:

[0119] In the case where one or more authentication parameters include one or more first authentication parameters, a signature is generated based on the parameter values ​​corresponding to the determined one or more first authentication parameters to obtain second information; the first authentication parameters characterize the authentication parameters used as components of the signature algorithm.

[0120] In practical applications, the first node can generate one or more signatures based on one or more first authentication parameters, and each signature can be generated based on a portion of the first authentication parameters.

[0121] For example, suppose the first information description has four first authentication parameters, namely first authentication parameter 1, first authentication parameter 2, first authentication parameter 3 and first authentication parameter 4. Based on these first authentication parameters, two signatures, namely signature 1 and signature 2, can be determined. Signature 1 can be generated based on the determined first authentication parameter 1 and first authentication parameter 2, and signature 2 can be generated based on the determined first authentication parameter 3 and first authentication parameter 4.

[0122] After generating one or more signatures, the first node can determine the parameter value of a corresponding second authentication parameter based on each generated signature, and then determine an information item in the second information based on the second authentication parameter.

[0123] In practical applications, the parameter type of the second authentication parameter corresponding to the signature generated by the first node can be a signature. When a signature generated by the first node corresponds to a second authentication parameter, the parameter values ​​of one or more first authentication parameters used to generate the signature can be regarded as one or more signature algorithm components corresponding to the second authentication parameter. That is, one or more first authentication parameters used to generate the signature correspond to the second authentication parameter.

[0124] The parameter name of the second authentication parameter, which is of the signature type, can be the same as the parameter name of the corresponding one or more first authentication parameters.

[0125] For example, suppose the first information description has four first authentication parameters and two second authentication parameters. The four first authentication parameters are designated as First Authentication Parameter 1, First Authentication Parameter 2, First Authentication Parameter 3, and First Authentication Parameter 4, and the two second authentication parameters are designated as Second Authentication Parameter 1 and Second Authentication Parameter 2. The parameter names for First Authentication Parameter 1, First Authentication Parameter 2, and Second Authentication Parameter 1 are all "Name 1," and the parameter names for First Authentication Parameter 3, First Authentication Parameter 4, and Second Authentication Parameter 2 are all "Name 2." Based on this, the first node can... The authentication parameter 1 and the first authentication parameter 2 generate signature 1, and then signature 1 is determined as the parameter value of the second authentication parameter 1. Also, signature 2 can be generated based on the first authentication parameter 3 and the first authentication parameter 4, and then signature 2 is determined as the parameter value of the second authentication parameter 2. Then, the first node can generate the parameter name and parameter value of the second authentication parameter 1 as an information item in the second information, such as information item 1. The first node can also generate the parameter name and parameter value of the second authentication parameter 2 as another information item in the second information, such as information item 2, thereby generating the second information.

[0126] In practical applications, if there is no second authentication parameter corresponding to one or more first authentication parameters in the authentication parameters described in the first information, an information item in the second information can be directly generated based on the signature.

[0127] In this embodiment, the first node determines the parameter values ​​of one or more authentication parameters based on the first information corresponding to the second node to be requested, and then determines the second information based on these authentication parameters. That is, the authentication information required by the second node is determined. In other words, the first node can generate the authentication information required by each second node based on a unified processing logic, and then automatically encapsulate the interface call request, thereby shielding the differences between the authentication logic of each second node. Compared with related technologies, it does not require customized development of the first node for the second node, and can also ensure the communication security in the network system composed of the first node and the second node, thereby reducing development costs.

[0128] Furthermore, the embodiments of this application divide the authentication parameters into first authentication parameters and second authentication parameters. Based on this, even for more complex authentication parameters, they can be uniformly generated based on the first information. For example, when the parameter type of the second authentication parameter is a signature, the corresponding first authentication parameter can be determined according to the description of the first information, and then the parameter value of the second authentication parameter can be generated based on these first authentication parameters to obtain the second information. This ensures the uniformity and flexibility of the authentication parameter generation logic. On this basis, the first node can shield the differences between the authentication logic of each second node when generating authentication information, reducing development costs.

[0129] The first piece of information will be explained further below.

[0130] In one embodiment, the first information includes one or more of the following fields related to authentication parameters:

[0131] The first field describes the name of the authentication parameter;

[0132] The second field describes the parameter values ​​of the authentication parameters;

[0133] The third field describes the parameter type of the authentication parameters;

[0134] The fourth field describes whether the authentication parameter is a component of the signature algorithm.

[0135] The fifth field describes the signature generation algorithm.

[0136] The sixth field describes the storage path of the first file, which represents the file that the signature generation algorithm depends on when it is invoked.

[0137] The seventh field describes the order in which the signature algorithm components are arranged when forming the signature.

[0138] The eighth field describes whether the authentication parameter values ​​are stored in the specified cache.

[0139] The ninth field describes the storage path of the second file, which is used to determine the value of the authentication parameter when the parameter type of the authentication parameter is authentication file.

[0140] The tenth field describes the location of the corresponding authentication information encapsulated in the API call request.

[0141] In practical applications, the first information may also include an eleventh field, which can be used to identify the corresponding authentication parameters.

[0142] In practical applications, the first information can describe the corresponding authentication parameters through one or more fields, and these fields can be added, deleted, or modified according to business needs.

[0143] For example, suppose the third field can support three values, such as value 1 corresponding to the MD5 algorithm, value 2 corresponding to the SHA256 algorithm, and value 3 corresponding to the DES algorithm. Based on this, if a signature generation algorithm needs to be added in actual application, for example, if the authentication information corresponding to the second node needs to include a signature generated based on the AES algorithm, then the values ​​of the third field can be expanded, for example, by adding value 4, corresponding to the newly added signature generation algorithm.

[0144] Thus, based on the fields in the first information, the flexibility of determining authentication parameters can be improved, thereby improving the flexibility of generating authentication information.

[0145] In one embodiment, the first information is stored in the first node when the corresponding second node accesses the first node.

[0146] In practical applications, see Figure 2 The connection of the second node to the first node can mainly include the following steps:

[0147] Step 1: Initiate an access request for the second node to the first node.

[0148] In practical applications, the first user can enter the basic information of the second node on the first interface of the first node to initiate an access request for the second node to the first node.

[0149] The first user can be understood as a user on the second node side, such as the administrator, maintenance personnel, or developers of the second node.

[0150] Basic information can be used by the first node to review the second node and determine whether to approve the second node's access application. For example, basic information may include at least one or more of the following: Internet Protocol (IP) address, port, access method, and qualification documents. The access method can be understood as the access approach, such as direct access or leased line access. The relevant qualification documents can be used to prove the security status of the second node; for example, the relevant qualification documents may include security certificates or encryption packages.

[0151] Step 2: The first node performs an access test on the second node.

[0152] In practical applications, the second node can be assessed to determine whether it has the corresponding data processing capabilities. If the assessment result indicates that the second node has the corresponding data processing capabilities, step 3 is executed.

[0153] For example, if the second node is a data delivery node, the first node can determine whether the second node has data delivery capability through access assessment, and then execute step 3 if the judgment result indicates that the second node has data delivery capability.

[0154] Step 3: The first node reviews the second node based on the basic information to determine whether to approve the second node's access application.

[0155] In practical applications, the first node's review of the second node based on basic information can also be described as the first node approving the access of the second node.

[0156] The first node can automatically review and process basic information based on set rules to obtain review results; for example, the set rules can include at least one or more of the following: data compliance in basic information, IP address connectivity, and verification of relevant supporting documents.

[0157] The first node can also output basic information to its second interface. The second user then reviews the basic information on the first interface and inputs the review result back to the first node, allowing the first node to obtain the review result. The second user can be understood as a user on the first node's side, such as the first node's administrator, operations personnel, or developers.

[0158] The first node's review result on the basic information can also be understood as the first node's review result on the second node.

[0159] In practical applications, if the review result indicates that the review has failed, the first node can disregard the access application from the second node and return to the first interface, so that the first user can re-enter the basic information and then re-initiate the access application from the second node to the first node.

[0160] If the audit result indicates that the audit has passed, the first node can continue to step 4 through the access application of the second node.

[0161] Step 4: Enter the first information corresponding to the second node.

[0162] In practical applications, the first node can provide a third interface so that the first user can input the first information corresponding to the second node in the third interface.

[0163] After receiving the first information input by the first user, the first node can improve the first information. For example, it can automatically generate an identifier for the authentication parameters described in the first information and add the identifier to the first information, and / or automatically generate an identifier for the corresponding second node or obtain the identifier of the second node generated in the past and add the identifier to the first information. Then, the first node can store the improved first information in the first node.

[0164] It should be noted that the first interface, the second interface, and the third interface mentioned above can be different states of the same interface, or they can be different interfaces. The first user in steps 1 and 3 can be understood as the user on the second node side, which can be the same user or different users.

[0165] Here, when the second node connects to the first node, storing the first information corresponding to the second node in the first node ensures that when the first node sends an interface call request to the second node, the first node already has the first information corresponding to the second node pre-stored in the first node, thus avoiding interface call request failure and ensuring communication stability.

[0166] The present application will be further described in detail below with reference to application examples.

[0167] This application provides an authentication method for a central node that has one or more child nodes connected to it.

[0168] Here, the central node is equivalent to the first node in this embodiment, and the child node is equivalent to the second node in this embodiment. In practical applications, the child node can also be described as a sub-platform.

[0169] See Figure 3 The authentication method provided in the application embodiments of this application can mainly include the following steps:

[0170] Step 1: The central node determines the child nodes to be requested.

[0171] In practical applications, the central node can determine the child node to which the interface call request is to be sent from the child nodes that have been connected to the central node based on business needs, and determine the identifier of the child node.

[0172] Step 2: The central node retrieves the authentication description information based on the identifier of the child node.

[0173] In practical applications, the central node can retrieve the authentication description information corresponding to the requested child node from one or more pre-stored authentication description information based on the child node's identifier. The authentication description information is equivalent to the first information in the embodiments of this application.

[0174] Step 3: The central node determines one or more authentication parameters based on the authentication description information corresponding to the child node to be requested, and then generates authentication information based on the determined authentication parameters.

[0175] In practical applications, the authentication information generated by the central node based on the authentication description information corresponding to the child node to be requested can be understood as the authentication information required by the child node, which is equivalent to the second information in the embodiments of this application.

[0176] In practical applications, the processing performed by the first node when determining each authentication parameter can mainly include the following steps:

[0177] Step 31: Determine whether the authentication parameter is used as a component of the signature algorithm based on the authentication description information, and obtain the judgment result.

[0178] If the judgment result indicates that the authentication parameter is used as a component of the signature algorithm, the authentication parameter is determined and step 32 is executed. In this case, the authentication parameter is equivalent to the first authentication parameter in the embodiment of this application. For ease of understanding, the authentication parameter will be referred to as the first authentication parameter in the following text.

[0179] If the determination result indicates that the authentication parameter is not used as a component of the signature algorithm, the authentication parameter is determined, and then step 33 is executed. In this case, the authentication parameter is equivalent to the second authentication parameter in the embodiment of this application. For ease of understanding, the authentication parameter will be referred to as the second authentication parameter below.

[0180] In practical applications, when determining authentication parameters, the central node can determine the parameter value. Specifically, the central node can first check whether the authentication description information describes the parameter value. If the authentication description information does not describe the parameter value, the central node determines the parameter value based on the parameter type described in the authentication description information; that is, it fills in the parameter value according to the parameter type.

[0181] If the authentication description information does not describe the parameter value of the authentication parameter, the central node can read the parameter value of the authentication parameter from the set cache. That is, it reads the cache information. If the reading result indicates that the parameter value of the authentication parameter exists in the set cache, the central node can determine the read parameter value as the parameter value of the authentication parameter. If the reading result indicates that the parameter value of the authentication parameter does not exist in the set cache, the central node can determine the parameter value described in the authentication description information as the parameter value of the authentication parameter.

[0182] After determining the value of the authentication parameter, the central node can determine whether to cache the authentication parameter based on the authentication description information, that is, whether to enable caching of the authentication parameter. If caching of the authentication parameter is enabled, the value of the authentication parameter can be stored in the set cache.

[0183] In practical applications, the storage space corresponding to the cache can be provided by the caching system used for caching.

[0184] Step 32: Generate a signature based on the determined parameter value of the first authentication parameter.

[0185] In practical applications, the central node can generate a signature based on the determined value of the first authentication parameter and the values ​​of other first authentication parameters related to it. For example, the other first authentication parameters related to the first authentication parameter can have the same parameter name as the first authentication parameter.

[0186] During the signature generation process, the first node can concatenate the parameter values ​​of one or more first authentication parameters according to the set arrangement order to obtain a string. Then, it calls the set signature generation algorithm to process the string to obtain a signature, and then determines the signature as the parameter value of the corresponding second authentication parameter.

[0187] If the signature generation algorithm is set to a custom algorithm, the first node can invoke the custom algorithm by calling the specified dependency files.

[0188] In practical applications, the set sorting order, the set signature generation algorithm, and the set dependent files can all be determined based on the authentication description information.

[0189] Step 33: Add the parameter name and parameter value of the second authentication parameter to the API call request.

[0190] In practical applications, a key-value pair can be generated based on each second authentication parameter, and the key-value pair can be added to the interface call request based on the set addition position, so that the interface call request carries the authentication information corresponding to the child node to be requested.

[0191] In practical applications, the designated addition location can be determined based on the authentication description information.

[0192] Step 4: The central node sends an interface call request to the child node to be requested.

[0193] In practical applications, after receiving an interface call request, the child node can authenticate the central node based on the authentication information carried in the interface call request to determine whether to proceed with subsequent communication, thereby ensuring communication security.

[0194] In practical applications, the authentication description information in the application embodiments of this application may include one or more fields related to authentication parameters. For example, the fields included in the authentication description information can be seen in Table 1.

[0195] Table 1

[0196]

[0197]

[0198] In practical applications, these fields can be added, deleted, or modified according to business needs.

[0199] In the application embodiments of this application, the central node can automatically generate the authentication information required by each child node based on the pre-stored authentication description information, and carry the corresponding authentication information when sending interface call requests to the child nodes. In this way, the central node can generate the authentication information required by each child node based on a unified processing logic, and then automatically encapsulate the interface call requests, thereby shielding the differences between the authentication logic of each child node. Compared with related technologies, it does not require customized development of the first node for the child nodes, and can also ensure the communication security in the network system composed of the central node and the child nodes, thereby reducing development costs.

[0200] Based on the embodiments described above, this application also provides an authentication device applied to a first node, which has one or more second nodes connected to it. See [link to relevant documentation]. Figure 4 The authentication device includes:

[0201] The query unit 41 is used to query the first information corresponding to the second node to be requested from one or more pre-stored first information; each of the one or more first information is used to describe the authentication information required for a second node, and the authentication information is used by the second node to authenticate the node that initiates the interface call request.

[0202] The generation unit 42 is used to generate second information based on the first information corresponding to the second node to be requested; the second information represents the authentication information corresponding to the second node to be requested.

[0203] Sending unit 43 is used to send an interface call request to the second node to be requested, the interface call request carrying the second information.

[0204] In one embodiment, the generation unit 42 generates second information based on the first information corresponding to the second node to be requested, including:

[0205] Based on the first information corresponding to the second node to be requested, determine the parameter values ​​corresponding to one or more authentication parameters, and generate the second information based on the determined parameter values ​​corresponding to the one or more authentication parameters.

[0206] In one embodiment, the generation unit 42 determines parameter values ​​corresponding to one or more authentication parameters, including:

[0207] For each of the one or more authentication parameters:

[0208] If the first information does not describe the parameter value of the authentication parameter, the parameter value of the authentication parameter is determined based on the parameter type of the authentication parameter described in the first information; and / or,

[0209] If the first information describes the parameter value of the authentication parameter, the parameter value of the authentication parameter is read from the set cache.

[0210] In one embodiment, the authentication device further includes a storage unit, which is used to store the parameter value of the authentication parameter in the set cache after the generation unit 42 determines the parameter value of the authentication parameter.

[0211] In one embodiment, the generation unit 42 generates the second information based on the parameter values ​​corresponding to the determined one or more authentication parameters, including:

[0212] When the one or more authentication parameters include one or more first authentication parameters, a signature is generated based on the parameter values ​​corresponding to the determined one or more first authentication parameters to obtain the second information; the first authentication parameters represent authentication parameters used as components of the signature algorithm.

[0213] In one embodiment, the generation unit 42 generates the second information based on the parameter values ​​corresponding to the determined one or more authentication parameters, including:

[0214] When the one or more authentication parameters include one or more second authentication parameters, the parameter name and parameter value corresponding to the one or more second authentication parameters are generated as the second information; the second authentication parameter represents an authentication parameter that is not used as a component of the signature algorithm.

[0215] In one embodiment, the first information includes one or more of the following fields related to authentication parameters:

[0216] The first field describes the name of the authentication parameter.

[0217] The second field describes the parameter values ​​of the authentication parameters;

[0218] The third field describes the parameter type of the authentication parameter;

[0219] The fourth field describes whether the authentication parameter is a component of the signature algorithm.

[0220] The fifth field describes the signature generation algorithm;

[0221] The sixth field describes the storage path of the first file, which represents the file that the signature generation algorithm depends on when it is invoked.

[0222] The seventh field describes the order in which the signature algorithm components are arranged when forming the signature;

[0223] The eighth field describes whether the authentication parameter value is stored in a designated cache.

[0224] The ninth field describes the storage path of the second file, which is used to determine the value of the authentication parameter when the parameter type of the authentication parameter is an authentication file.

[0225] The tenth field describes the location of the corresponding authentication information encapsulated in the interface call request.

[0226] In one embodiment, the first information includes a first identifier, which represents the identifier of the corresponding second node;

[0227] Correspondingly, the query unit 41 queries the first information corresponding to the requested second node from one or more pre-stored first information, including:

[0228] Based on the identifier of the second node to be requested, a query is performed in the one or more pieces of first information to obtain the query results;

[0229] If the first identifier in the query result representing a first piece of information matches the identifier of the second node to be requested, then the first piece of information is determined to be the first piece of information corresponding to the second node to be requested.

[0230] In one embodiment, the first information is stored in the first node when the corresponding second node accesses the first node.

[0231] In practical applications, the query unit 41, the generation unit 42, the sending unit 43, and the storage unit can be implemented by the processor in the authentication device.

[0232] It should be noted that the authentication device provided in the above embodiments is only illustrated by the division of the above program modules. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. In addition, the authentication device and authentication method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process can be found in the method embodiments, which will not be repeated here.

[0233] Based on the hardware implementation of the above program modules, and in order to implement the method of the embodiments of this application, this application also provides a first node, see [link to relevant documentation]. Figure 5 The first node includes:

[0234] The first communication interface 1 is capable of exchanging information with other devices;

[0235] The first processor 2 is connected to the first communication interface 1 to enable information interaction with other devices. When running a computer program, it executes the methods provided by one or more technical solutions in the above embodiments. The computer program is stored in the first memory 3.

[0236] Specifically, the first processor 2 is configured to query the first information corresponding to the second node to be requested from one or more pre-stored first information; each of the one or more first information is used to describe the authentication information required by a second node, and the authentication information is used by the second node to authenticate the node initiating the interface call request; and

[0237] Based on the first information corresponding to the second node to be requested, second information is generated; the second information represents the authentication information corresponding to the second node to be requested.

[0238] The first communication interface 1 is used to send an interface call request to the second node to be requested, and the interface call request carries the second information.

[0239] In one embodiment, the first processor 2 generates second information based on the first information corresponding to the requested second node, including:

[0240] Based on the first information corresponding to the second node to be requested, determine the parameter values ​​corresponding to one or more authentication parameters, and generate the second information based on the determined parameter values ​​corresponding to the one or more authentication parameters.

[0241] In one embodiment, the first processor 2 determines parameter values ​​corresponding to one or more authentication parameters, including:

[0242] For each of the one or more authentication parameters:

[0243] If the first information does not describe the parameter value of the authentication parameter, the parameter value of the authentication parameter is determined based on the parameter type of the authentication parameter described in the first information; and / or,

[0244] If the first information describes the parameter value of the authentication parameter, the parameter value of the authentication parameter is read from the set cache.

[0245] In one embodiment, after determining the value of the authentication parameter, the first processor 2 is further configured to:

[0246] The value of the authentication parameter is stored in the specified cache.

[0247] In one embodiment, the first processor 2 generates the second information based on the parameter values ​​corresponding to the determined one or more authentication parameters, including:

[0248] When the one or more authentication parameters include one or more first authentication parameters, a signature is generated based on the parameter values ​​corresponding to the determined one or more first authentication parameters to obtain the second information; the first authentication parameters represent authentication parameters used as components of the signature algorithm.

[0249] In one embodiment, the first processor 2 generates the second information based on the parameter values ​​corresponding to the determined one or more authentication parameters, including:

[0250] When the one or more authentication parameters include one or more second authentication parameters, the parameter name and parameter value corresponding to the one or more second authentication parameters are generated as the second information; the second authentication parameter represents an authentication parameter that is not used as a component of the signature algorithm.

[0251] In one embodiment, the first information includes one or more of the following fields related to authentication parameters:

[0252] The first field describes the name of the authentication parameter.

[0253] The second field describes the parameter values ​​of the authentication parameters;

[0254] The third field describes the parameter type of the authentication parameter;

[0255] The fourth field describes whether the authentication parameter is a component of the signature algorithm.

[0256] The fifth field describes the signature generation algorithm;

[0257] The sixth field describes the storage path of the first file, which represents the file that the signature generation algorithm depends on when it is invoked.

[0258] The seventh field describes the order in which the signature algorithm components are arranged when forming the signature;

[0259] The eighth field describes whether the authentication parameter value is stored in a designated cache.

[0260] The ninth field describes the storage path of the second file, which is used to determine the value of the authentication parameter when the parameter type of the authentication parameter is an authentication file.

[0261] The tenth field describes the location of the corresponding authentication information encapsulated in the interface call request.

[0262] In one embodiment, the first information includes a first identifier, which represents the identifier of the corresponding second node;

[0263] Correspondingly, the first processor 2 queries one or more pre-stored pieces of first information to retrieve the first information corresponding to the requested second node, including:

[0264] Based on the identifier of the second node to be requested, a query is performed in the one or more pieces of first information to obtain the query results;

[0265] If the first identifier in the query result representing a first piece of information matches the identifier of the second node to be requested, then the first piece of information is determined to be the first piece of information corresponding to the second node to be requested.

[0266] In one embodiment, the first information is stored in the first node when the corresponding second node accesses the first node.

[0267] It should be noted that the specific processing procedure of the first communication interface 1 can be understood by referring to the above method.

[0268] Of course, in practical applications, the various components in the first node are coupled together through bus system 4. It can be understood that bus system 4 is used to implement communication between these components. In addition to the data bus, bus system 4 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 5 The general will label all buses as Bus System 4.

[0269] The first memory 3 in this embodiment is used to store various types of data to support operations in the first node. Examples of such data include any computer program used for operations on the first node.

[0270] The methods disclosed in the embodiments of this application can be applied to the first processor 2, or implemented by the first processor 2. The first processor 2 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware or by instructions in the form of software in the first processor 2. The first processor 2 may be a general-purpose processor, a DSP, or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 2 can implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of this application. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the methods disclosed in the embodiments of this application can be directly reflected as being executed by a hardware decoding processor, or being executed by a combination of hardware and software modules in the decoding processor. The software modules may be located in a storage medium, which is located in the first memory 3. The first processor 2 reads the information in the first memory 3 and completes the steps of the aforementioned method in combination with its hardware.

[0271] In an exemplary embodiment, the first node may be implemented by one or more ASICs, DSPs, PLDs, CPLDs, FPGAs, general-purpose processors, controllers, MCUs, microprocessors, or other electronic components to perform the aforementioned method.

[0272] It is understood that the first memory 3 in the embodiments of this application can be volatile memory or non-volatile memory, or both. The non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), ferromagnetic random access memory (FRAM), flash memory, magnetic surface memory, optical disc, or compact disc read-only memory (CD-ROM); the magnetic surface memory can be disk storage or magnetic tape storage. The volatile memory can be random access memory (RAM), which is used as an external cache. By way of example, but not limitation, many forms of RAM are available, such as Static Random Access Memory (SRAM), Synchronous Static Random Access Memory (SSRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate Synchronous Dynamic Random Access Memory (DDRSDRAM), Enhanced Synchronous Dynamic Random Access Memory (ESDRAM), SyncLink Dynamic Random Access Memory (SLDRAM), and Direct Rambus Random Access Memory (DRRAM).The memories described in the embodiments of this application are intended to include, but are not limited to, these and any other suitable types of memories.

[0273] In an exemplary embodiment, this application also provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, such as a first memory 3 storing a computer program, which can be executed by a first processor 2 to complete the steps described in the aforementioned method.

[0274] In an exemplary embodiment, this application also provides a computer program product, including a computer program that can be executed by a first processor 2 to perform the steps described in the foregoing method.

[0275] It should be noted that terms such as "first" and "second" are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0276] In this document, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. Additionally, the term "one or more" in this document refers to any combination of at least two of any one or more elements from a set of A, B, and C. For example, including at least one of A, B, and C can represent including any one or more elements selected from the set of A, B, and C.

[0277] Furthermore, the technical solutions described in the embodiments of this application can be combined arbitrarily without conflict.

[0278] The above description is merely a preferred embodiment of this application and is not intended to limit the scope of protection of this application.

Claims

1. An authentication method, characterized in that, Applied to a first node, which is connected to one or more second nodes; the method includes: The first information corresponding to the second node to be requested is retrieved from one or more pre-stored first information; each of the one or more first information is used to describe the authentication information required for a second node, and the authentication information is used by the second node to authenticate the node that initiates the interface call request. Based on the first information corresponding to the second node to be requested, second information is generated; the second information represents the authentication information corresponding to the second node to be requested. Send an interface call request to the second node to be requested, the interface call request carrying the second information.

2. The method according to claim 1, characterized in that, The step of generating second information based on the first information corresponding to the second node to be requested includes: Based on the first information corresponding to the second node to be requested, determine the parameter values ​​corresponding to one or more authentication parameters, and generate the second information based on the determined parameter values ​​corresponding to the one or more authentication parameters.

3. The method according to claim 2, characterized in that, Determining the parameter values ​​corresponding to one or more authentication parameters includes: For each of the one or more authentication parameters: If the first information does not describe the parameter value of the authentication parameter, the parameter value of the authentication parameter is determined based on the parameter type of the authentication parameter described in the first information; and / or, If the first information describes the parameter value of the authentication parameter, the parameter value of the authentication parameter is read from the set cache.

4. The method according to claim 3, characterized in that, After determining the value of the authentication parameter, the method further includes: The value of the authentication parameter is stored in the specified cache.

5. The method according to any one of claims 2 to 4, characterized in that, The step of generating the second information based on the parameter values ​​corresponding to the determined one or more authentication parameters includes: When the one or more authentication parameters include one or more first authentication parameters, a signature is generated based on the parameter values ​​corresponding to the determined one or more first authentication parameters to obtain the second information; the first authentication parameters represent authentication parameters used as components of the signature algorithm.

6. The method according to any one of claims 2 to 4, characterized in that, The step of generating the second information based on the parameter values ​​corresponding to the determined one or more authentication parameters includes: When the one or more authentication parameters include one or more second authentication parameters, the parameter name and parameter value corresponding to the one or more second authentication parameters are generated as the second information; the second authentication parameter represents an authentication parameter that is not used as a component of the signature algorithm.

7. The method according to claim 1, characterized in that, The first information includes one or more of the following fields related to authentication parameters: The first field describes the name of the authentication parameter. The second field describes the parameter values ​​of the authentication parameters; The third field describes the parameter type of the authentication parameter; The fourth field describes whether the authentication parameter is a component of the signature algorithm. The fifth field describes the signature generation algorithm; The sixth field describes the storage path of the first file, which represents the file that the signature generation algorithm depends on when it is invoked. The seventh field describes the order in which the signature algorithm components are arranged when forming the signature; The eighth field describes whether the authentication parameter value is stored in a designated cache. The ninth field describes the storage path of the second file, which is used to determine the value of the authentication parameter when the parameter type of the authentication parameter is an authentication file. The tenth field describes the location of the corresponding authentication information encapsulated in the interface call request.

8. The method according to claim 1, characterized in that, The first information includes a first identifier, which represents the identifier of the corresponding second node; Correspondingly, retrieving the first information corresponding to the requested second node from one or more pre-stored first information includes: Based on the identifier of the second node to be requested, a query is performed in the one or more pieces of first information to obtain the query results; If the first identifier in the query result representing a first piece of information matches the identifier of the second node to be requested, then the first piece of information is determined to be the first piece of information corresponding to the second node to be requested.

9. The method according to claim 1, characterized in that, The first information is stored in the first node when the corresponding second node connects to the first node.

10. An authentication device, characterized in that, Applied to a first node, which is connected to one or more second nodes; including: The query unit is used to query the first information corresponding to the second node to be requested from one or more pre-stored first information; each of the one or more first information is used to describe the authentication information required by a second node, and the authentication information is used by the second node to authenticate the node that initiates the interface call request. The generation unit is configured to generate second information based on the first information corresponding to the second node to be requested; the second information represents the authentication information corresponding to the second node to be requested. The sending unit is used to send an interface call request to the second node to be requested, the interface call request carrying the second information.

11. A first node, characterized in that, Includes a first processor and a first communication interface; The first processor is configured to query the first information corresponding to the second node to be requested from one or more pre-stored first information; each of the one or more first information is used to describe the authentication information required by a second node, and the authentication information is used by the second node to authenticate the node that initiates the interface call request. as well as, Based on the first information corresponding to the second node to be requested, generate the second information; The second information represents the authentication information corresponding to the second node to be requested; The first communication interface is used to send an interface call request to the second node to be requested, and the interface call request carries the second information.

12. A first node, characterized in that, include: A first processor and a first memory for storing computer programs capable of running on the processor. Wherein, when the first processor is used to run the computer program, it performs the steps of the method according to any one of claims 1 to 9.

13. A storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 9.

14. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 9.