Information processing system, method, apparatus, storage medium, and program product
By assigning tokens and creating protection rules for application services in the firewall service, the problem of high maintenance costs of the authentication system in the application service system is solved, a unified authentication service is achieved, and security maintenance costs are reduced.
Patent Information
- Application Number
- CN202410969559.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-18
- Publication Date
- 2026-01-20
AI Technical Summary
In existing technologies, the authentication system of application service systems is deployed on servers and maintained by developers, resulting in high security maintenance costs.
By providing a unified authentication service in the firewall service, using the first service node to allocate tokens to the target application service, and creating protection rules in the firewall service, access authentication for the application service can be achieved, avoiding the need to deploy and maintain an independent authentication system on the application service side.
It reduces the security maintenance costs of application services, achieves a unified authentication service, and reduces the repetitive development and maintenance work for each application service.
Smart Images

Figure CN121367592A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network security, and in particular to an information processing system, method, device, storage medium and program product. BACKGROUND
[0002] With the development of Internet technology, more and more application services are developed and used. In order to protect the security of the application service, it is necessary to authenticate the user accessing the application service. Authentication refers to verifying whether the user has the right to access the system.
[0003] In the prior art, the application service system develops an independent authentication system to authenticate the users of the system. The authentication system of the application service system is deployed in the server of the system and is maintained by the developer of the system, which has a high security maintenance cost. SUMMARY
[0004] The present application provides an information processing system, method, device, storage medium and program product to provide unified authentication services and reduce the security maintenance cost of application services.
[0005] The present application provides an information processing system, comprising: a target electronic device, a first service node, a second service node providing firewall services and a third service node providing target application services; the target application services use the firewall services;
[0006] The target electronic device is configured to send a token application request for applying for access rights to the target application services to the first service node.
[0007] The first service node is configured to assign a target token to the token application request in response to the token application request, obtain the identification information of the target application services to be accessed from the token application request, return the target token to the target electronic device, so that the target electronic device accesses the target application services based on the target token, and create a target protection rule for the target application services in the firewall services according to the identification information of the target application services, the target token and the pre-configured authentication policy information, so that the firewall services authenticate the access to the target application services based on the target protection rule.
[0008] The present application also provides an information processing method suitable for a service node providing a token application service, comprising:
[0009] In response to a token application request, a target token is assigned to the token application request for applying for access rights to the target application services.
[0010] Obtain identification information of a target application service to be accessed from the token application request;
[0011] Return the target token to a target electronic device that sent the token application request, so that the target electronic device accesses the target application service based on the target token;
[0012] According to the identification information of the target application service, the target token, and pre-configured authentication policy information, create a target protection rule for the target application service in a firewall service used by the target application service, so that the firewall service authenticates access to the target application service based on the target protection rule.
[0013] Embodiments of the present application also provide an information processing method suitable for a target electronic device, comprising:
[0014] Obtain identification information of a target application service to be accessed;
[0015] Based on the identification information of the target application service, generate a token application request for applying for access to the target application service;
[0016] Send the token application request to a service node that provides a token application service, so that the service node allocates a target token in response to the token application request, and triggers the service node to create a target protection rule for the target application service in a firewall service used by the target application service according to the identification information of the target application service, the target token, and pre-configured authentication policy information;
[0017] Obtain the target token, and send an access request to the target application service based on the target token, so that the firewall service authenticates the access request based on the target protection rule and the target token.
[0018] Embodiments of the present application also provide an information processing method suitable for a service node that provides a firewall service, comprising:
[0019] Obtain a protection rule creation request; the protection rule creation request includes identification information of a target application service to be protected, a target token, and authentication policy information; the target application service uses a firewall service;
[0020] According to the identification information of the target application service, the target token, and pre-configured authentication policy information, create a target protection rule for the target application service in the firewall service, so that the firewall service authenticates access to the target application service based on the target protection rule.
[0021] The embodiment of the present application further provides a computing device, comprising a memory and a processor; wherein the memory is used for storing a computer program;
[0022] The processor is coupled to the memory and is used for executing the computer program to execute the steps in the information processing method.
[0023] The embodiment of the present application further provides a computer readable storage medium storing computer instructions, which, when executed by one or more processors, cause the one or more processors to perform the steps in the information processing method.
[0024] The embodiment of the present application further provides a computer program product, comprising a computer program, which, when executed by one or more processors, cause the one or more processors to perform the steps in the information processing method.
[0025] In the embodiment of the present application, the target application service uses the firewall service. A user of the target application service can apply for a token for identifying identity to a first service node providing a token application service. The first service node can create a target protection rule based on the token for authenticating access to the target application service in the firewall service in response to the token application request, so that the firewall service can authenticate access to the target application service based on the token in the target protection rule, and a unified authentication service of the firewall is provided, and it is not necessary to deploy and maintain an authentication system on the target application service side, and the security maintenance cost of the target application service side can be reduced. BRIEF DESCRIPTION OF DRAWINGS
[0026] The accompanying drawings, which are included to provide a further understanding of the present application, constitute a part of the present application and illustrate the illustrative embodiments of the present application and its description, and do not constitute improper limitations to the present application. In the drawings:
[0027] Figure 1 The structural schematic diagram of the information processing system provided by the embodiment of the present application is shown;
[0028] Figure 2 The schematic diagram of the protection rule creation page provided by the embodiment of the present application is shown;
[0029] Figure 3 The schematic diagram of the security detection process provided by the embodiment of the present application is shown;
[0030] Figures 4-6 The flowchart of the information processing method provided by the embodiment of the present application is shown;
[0031] Figure 7 The structural schematic diagram of the computing device provided by the embodiment of the present application is shown. DETAILED DESCRIPTION
[0032] In order to make the objects, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be described clearly and completely below with reference to the embodiments of the present application and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0033] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of the related data need to comply with the relevant laws, regulations and standards of the country and region, and provide corresponding operation portal for the user to choose authorization or refusal.
[0034] In some embodiments of the present application, in the embodiments of the present application, the target application service uses the firewall service. The user of the target application service can apply for a token for identifying identity to the first service node providing the token application service. The first service node can create a target protection rule for authenticating the access to the target application service based on the token in the firewall service in response to the token application request, so that the firewall service can authenticate the access to the target application service based on the token in the target protection rule, and a unified authentication service of the firewall is provided, without the need to deploy and maintain the authentication system on the target application service side, which can reduce the security maintenance cost of the target application service side.
[0035] The technical solutions provided by the embodiments of the present application will be described in detail below with reference to the accompanying drawings.
[0036] It should be noted that the same reference numerals represent the same objects in the following drawings and embodiments, so once an object is defined in one drawing or embodiment, it does not need to be discussed further in the subsequent drawings and embodiments.
[0037] Figure 1 The structural schematic diagram of the information processing system provided by the embodiments of the present application is shown in FIG. 1. As shown in FIG. 1, the system mainly includes a target electronic device 10, a first service node 20, a second service node 30 providing a firewall service and a third service node 40 providing a target application service. Figure 1
[0038] In the embodiment, the target electronic device 10 refers to a computer device used by a user and having a function of computing, communication and the like required by the user, for example, a mobile phone, a tablet computer, a personal computer or a wearable device, etc. Of course, the target electronic device 10 can also be a server, etc. In the embodiment, for the convenience of understanding and description, the user using the target electronic device 10 is defined as a target user.
[0039] The first service node 20, the second service node 30 and the third service node 40 are server devices providing corresponding services, which can be single server devices, clouded server arrays or virtual machines (VM) running in the clouded server arrays. In addition, the first service node 20, the second service node 30 and the third service node 40 can also refer to other computing devices having corresponding service capabilities, for example, terminal devices (running service programs) such as computers, etc.
[0040] In the embodiment, the second service node 30 can provide a firewall service. The firewall service can provide customized protection rules, that is, a custom protection rule policy function. The third service node 40 can provide a target application service. In the embodiment, the specific implementation form of the target application service provided by the third service node 40 is not limited. Optionally, the target application service can be a test service, a test environment service, an online shopping service, a live broadcast service, a computing service, a storage service or any other service, etc.
[0041] In the embodiment, the service node providing an application service is defined as one third service node 40. The third service node 40 can be one or more. More refers to two or more than two. Accordingly, the multiple third service nodes 40 can provide multiple target application services. Multiple refers to two or more than two.
[0042] In the embodiment, the target application service uses the firewall service to perform security detection on the access to the target application service by the firewall service. In this way, the target application service does not need to develop an authentication function, and the development and maintenance cost of the authentication function on the target application service side can be saved. In the traditional scheme, the target application service respectively deploys an independent authentication system to perform identity authentication on the access to itself. The identity authentication refers to verifying whether a user has the right to access the application service. The technical personnel of the target application service develops and maintains the respective authentication system, and the overall security maintenance and development cost is high.
[0043] In the embodiment, based on the custom protection policy function of the firewall service, the protection rules can be customized in the firewall service for authenticating the access to the target application service. The following will be described in detail.
[0044] To realize the authentication of the access of the firewall service to the target application service, the first service node 20 is added. The first service node 20 can provide a token application service, and of course, can also provide other services, such as a subsequent firewall protection rule configuration service, and the like. The first service node 20 and the second service node 30 can be implemented as independent physical devices, or can be implemented as the same physical device. Based on the token application service provided by the first service node 20, a user can apply for a token from the first service node 20. Specifically, the target electronic device 10 can apply for a token from the first service node 20. Specifically, as shown in FIG. 1, the target electronic device 10 can send a token application request for applying for a right to access the target application service to the first service node 20. The token application request can include identification information of the target application service. The identification information of the target application service refers to information for uniquely identifying an application service, and can be a domain name, a website, an identity (ID), a number, or a name of the target application service, and the like. Generally, the identification information of the target application service is the domain name of the target application service. Figure 1 As shown in step 1, the target electronic device 10 can send a token application request for applying for a right to access the target application service to the first service node 20. The token application request can include identification information of the target application service. The identification information of the target application service refers to information for uniquely identifying an application service, and can be a domain name, a website, an identity (ID), a number, or a name of the target application service, and the like. Generally, the identification information of the target application service is the domain name of the target application service.
[0045] In some embodiments, the first service node 20 can provide a token application page, and the token application page is provided with a button for applying for a token. The target electronic device 10 can display the token application page, and a user can apply for a token from the first service node 20 by clicking the button for applying for a token.
[0046] Of course, the token application page can also be provided with an identification information providing control of the target application service. The control can be a text input box or a selection button, and the like. A user can provide identification information of an application service to be accessed based on the identification information providing control of the target application service, that is, the identification information of the target application service. For example, the identification information providing control of the target application service can be a text input box, and a user can input the identification information of the target application service in the text input box, and the like. For another example, the identification information providing control of the target application service is a selection button, and a user can select a target application service to be accessed through the selection button; and the target electronic device 10 can acquire the identification information of the target application service from pre-stored identification information of an application service in response to a selection operation of the target application service. The pre-stored identification information of the application service includes the identification information of the target application service.
[0047] After the user provides the identification information of the target application service, the button of applying for the token can be clicked to apply for the token to the first service node 20. Correspondingly, the target electronic device 10 can send a token application request to the first service node 20 in response to the triggering operation (such as the clicking operation) of the button of applying for the token. Specifically, the target electronic device 10 can obtain the identification information of the target application service in response to the triggering operation (such as the clicking operation) of the button of applying for the token, and generate the token application request according to the identification information of the target application service. Further, the token application request is sent to the first service node 20.
[0048] Correspondingly, the first service node 20 can receive the token application request, and assign a target token to the token application request in response to the token application request (corresponding to step 2, “assigning a target token”). Figure 1 Specifically, the first service node 20 assigns a target token to the target user corresponding to the token application request in response to the token application request. The target user refers to the user of the target electronic device 10. Specifically, the first service node 20 can generate a random number in response to the token application request. For example, the first service node 20 can generate a random number by a random number generation algorithm in response to the token application request. The random number generation algorithm can be a linear congruential algorithm or a Mersenne Twister algorithm, etc. Alternatively, the first service node 20 can generate a random number by taking the current timestamp as a seed in response to the token application request, etc. Further, the random number can be subjected to Hash calculation to obtain a Hash value of the random number, and the Hash value of the random number is assigned to the target token of the token application request. Specifically, the first service node 20 assigns the Hash value of the random number to the target token of the target user corresponding to the token application request.
[0049] Since the Hash function is usually one-way, it means that it is computationally infeasible to reverse the original random number from the Hash value, which increases the security of the target token. On the other hand, the random number can be very large, while the length of the Hash value is fixed, so using the Hash value of the random number as the target token can save the resources required for storing and transmitting the token.
[0050] Further, the first service node 20 can return the target token to the target electronic device 10 (corresponding to step 3). Figure 1 In the embodiments of the present application, the specific implementation manner of the first service node 20 returning the target token to the target electronic device 10 is not limited. In some embodiments, the first service node 20 can directly return the target token to the target electronic device 10; or encapsulate the target token as a message body to obtain a response message, and return the response message to the target electronic device 10, so as to return the target token to the target electronic device 10.
[0051] In some embodiments, the message header can comprise information for marking the user identity, such as Cookie data. The Cookie data is text data sent to the client by the server, and is a small text data stored in the local terminal (such as a browser) of the user for marking the user identity, session tracking, storing user preference settings or other browsing information. It is sent to the client (browser) by the server through the Hypertext Transfer Protocol (HTTP) response, and is returned to the server by the client in the subsequent HTTP request, so as to achieve state management.
[0052] Since the message header can comprise information for marking the user identity, the first service node 20 can generate a response message indicating that the electronic device sets the target token as the identity marking information. The identity marking information is the information for marking the user identity in the message header. For example, the identity marking information can be Cookie data. Accordingly, the first service node 20 can generate a response message indicating that the electronic device sets the target token as Cookie data. Specifically, the first service node 20 can set the target token as the specific content of "Set-Cookie" in the message header of the response message, to obtain the response message. The "Set-Cookie" is used to indicate that the electronic device sets the specific content (here, the target token) as Cookie data. Since the information for marking the user identity comprised in the message header and the field in the message header indicating that the electronic device sets the target token as the identity marking information are the standard fields of the protocol followed by the message, such as Cookie data and "Set-Cookie", setting the target token as the specific content of the field indicating that the electronic device sets the target token as the identity marking information does not need to change the standard protocol followed by the message, nor the message format, and can reduce the workload.
[0053] Further, the first service node 20 can return the response message to the target electronic device 10. Since the target token is carried in the response message, returning the response message to the target electronic device 10 also achieves returning the target token to the target electronic device 10. Accordingly, the first service node 20 can obtain the target token from the response message, and set the target token as the identity marking information for saving in response to the response message. For example, for the embodiment in which the identity marking information is Cookie data, the first service node 20 can obtain the specific content of "Set-Cookie" from the message header of the response message; the specific content comprises the target token; further, the first service node 20 can set the target token as Cookie data for saving.
[0054] After the target electronic device 10 obtains the target token, the target user can access the target application service based on the target token. Accordingly, when accessing the target application service, the target electronic device 10 can send an access request to the target application service based on the target token. Specifically, the target electronic device 10 can carry the target token in the access request, and send the access request carrying the target token to the target application service. Specifically, the target electronic device 10 can encapsulate the target token as identity mark information into the packet header of the access request in response to the access demand for the target application service, to obtain the access request. For example, the target electronic device 10 can encapsulate the target token as Cookie data into the packet header of the access request in response to the access demand for the target application service, to obtain the access request, and send the access request to the target application service.
[0055] In order to implement the authentication of the firewall service to the access of the accessed application service, it is also necessary to configure a corresponding protection rule for each application service in the firewall service. Specifically, the first service node 20 can also obtain the identification information of the target application service to be accessed by the target user from the foregoing token application request (corresponding to step 4), and create a target protection rule for the target application service in the firewall service according to the identification information of the target application service, the target token, and the pre-configured authentication policy information (corresponding to step 5). Figure 1 Figure 1 Step 4), and create a target protection rule for the target application service in the firewall service according to the identification information of the target application service, the target token, and the pre-configured authentication policy information (corresponding to step 5). The authentication policy information is information for describing the policy of how to authenticate, which can be information in the form of text data or code, etc.
[0056] In some embodiments, the firewall service can provide a protection rule creation interface, such as an application programming interface (API). Accordingly, the first service node 20 can invoke the protection rule creation interface, and create a target protection rule for the target application service in the firewall service through the protection rule creation interface according to the identification information of the target application service, the target token, and the pre-configured authentication policy information.
[0057] In some embodiments, the authentication policy information includes an authenticated target action and a logical condition corresponding to the target action. The target action refers to a processing action of the access request, which is generally blocking or passing. Blocking refers to blocking the access request from accessing the target application service, and passing refers to allowing the access request to access the target application service. The logical condition corresponding to the target action is a logical condition that needs to be met to execute the target action, which can be "contains", "does not contain", "contains any value", "contains all values", "does not contain any value", or "does not contain all values", etc.
[0058] Accordingly, the target protection rule can be created in the firewall service through the protection rule creation interface, and the identification information of the protected object is set as the identification of the target application service, the execution action is set as the target action, and the authentication condition is set as the logical condition and the target token. The target protection rule is used to authenticate the target application service, and the target action is performed on the access request if the access request meets the authentication condition. For example, the target application service is a test environment service, i.e., a test environment is provided for a user, the target action is blocking, the logical condition is "not containing", and the target protection rule can be: if the access request to the test environment service does not contain the target token, the access request is blocked.
[0059] In this embodiment, the target protection rule for authenticating the access to the target application service is created in the firewall service through the protection rule creation interface provided by the firewall service, and the target application service does not need to be modified, so that the security maintenance cost of the target application service side can be reduced.
[0060] In addition to the protection rule creation interface, the firewall service can also provide a protection rule modification interface and a protection rule query interface. The protection rule (such as the target protection rule) set in the firewall service can be modified through the protection rule modification interface provided by the firewall service. The protection rules in the firewall service can be queried through the protection rule query interface.
[0061] In other embodiments, the firewall service can provide a protection rule creation page, i.e., the second service node 30 can provide the protection rule creation page, and the technical personnel of the first service node 20 can create the target protection rule through the protection rule creation page. Specifically, as shown in Figure 2 the user of the first service node 20 can select or fill in the authentication condition, such as the matching field, the logical condition, and the token, on the protection rule creation page, and can also select or fill in the target action. Of course, the user can also select the protection type through the protection rule creation page. The protection type can be ACL access control or CC attack protection. Among them, ACL is Access Control List (ACL), and CC is Challenge Collapsar. For example, in Figure 2 the selected protection type is "ACL access control". Figure 2 the target protection rule set in the protection rule creation page is: if the Cookie data of the access request to the target application service does not contain any value in the token, the access request is blocked.
[0062] The second service node 30 providing the firewall service can acquire a protection rule creation request. The protection rule creation request can be acquired by the second service node 30 through a protection rule creation interface or through a protection rule creation page. The protection rule creation request includes identification information of a target application service to be protected, a target token of a target user, and detection policy information. Further, the second service node 30 can create a target protection rule of the target application service in the firewall service according to the identification information of the target application service, the target token, and pre-configured authentication policy information.
[0063] Specifically, the authentication policy information includes a target action after authentication and a logical condition corresponding to the target action. Accordingly, the second service node 30 can create a target protection rule of the protected object in the firewall service, with the identification information of the target application service as the identification of the protected object, the target action as the execution action, and the logical condition and the target token as the authentication condition.
[0064] The creation method of the protection rule shown in the above embodiments is only exemplary and does not constitute a limitation. The foregoing embodiments create a token-based protection rule for the target application service in the firewall service. When a user accesses the target application service, the firewall service can authenticate the user's access to the target application service based on the token (such as the target token).
[0065] Specifically, the second service node 30 can acquire an access request for the target application service through the firewall service (corresponding to step 6); and detect whether the access request carries a token included in the protection rule in the firewall service (corresponding to step 7). Figure 1 If the access request carries the token included in the protection rule in the firewall service, it is determined that the user issuing the access request has access authority of the target application service (corresponding to step 7). Further, the access request can be allowed to access the target application service (corresponding to step 8). Figure 1 Figure 1
[0066] The protection rule in the firewall service can include the target protection rule created in the foregoing embodiments, and the token included in the protection rule can include the foregoing target token.
[0067] For the foregoing embodiment in which the token is identity information in the message header, the firewall service can detect whether the identity information of the access request contains the token included in the protection rule in the firewall service; if the identity information of the access request contains the token included in the protection rule in the firewall service, it is determined that the user sending the access request has the access right to the target application service. For example, for the embodiment in which the token is Cookie data, the firewall service can detect whether the Cookie data of the access request contains the token included in the protection rule in the firewall service; if the Cookie data of the access request contains the token included in the protection rule in the firewall service, it is determined that the user sending the access request has the access right to the target application service.
[0068] In the embodiment of the application, the target application service uses the firewall service. A user of the target application service can apply for a token for identifying identity to a first service node providing a token application service. The first service node can create a target protection rule for authenticating access to the target application service based on the token in the firewall service in response to the token application request, so that the firewall service can authenticate access to the target application service based on the token in the target protection rule, and a unified authentication service of the firewall is provided, without the need to deploy and maintain an authentication system on the side of the target application service, thereby reducing the security maintenance cost on the side of the target application service. Especially for multiple target application services, unified authentication at the application layer is performed by the firewall service, without the need to deploy an independent authentication system for each application service, thereby reducing the security maintenance cost on the side of the application service.
[0069] It is worth noting that, in addition to providing a unified authentication service, the firewall service can also provide an allowlist detection service and an attack detection service. The allowlist detection service refers to a network security mechanism that can limit the users, generally source IP addresses, in a computer or network that can access the target application service. Only trusted source IP addresses can be allowed to access the target application service, and source IP addresses not included in the allowlist are considered unsafe and their access requests are rejected to access the target application service. Attack detection refers to identifying malicious features of access requests, returning normal and safe access requests to the service node providing the target application service after cleaning and filtering the access requests, and avoiding problems such as abnormal performance of the server of the target application service caused by malicious intrusion.
[0070] The following takes the target application service as an example to illustrate the application in combination with the foregoing description. Figure 3 The security detection process of the second service node 30 is exemplarily described.
[0071] As described above, the firewall service can provide a unified authentication service for the target application service. Figure 3As shown, the pre-created target protection rule is: if the Cookie data of the access request does not contain a correct token, then reject the access to the test environment. It is assumed that the network areas allowed to join the network whitelist are the office network and the Virtual Private Network (VPN) corresponding to the office network, and the users in the office network and the VPN apply for tokens to the first service node. The test environment uses the firewall service for security detection and protection. When the user accesses the test environment, the user can send an access request to the test environment through the electronic device. For example, as shown in Figure 3 the user's electronic device can send an access request to the test environment through a computer-side browser, a mobile phone browser, a script, or an Application (APP) for testing. The second service node providing the firewall service can obtain the access request through the firewall service and obtain the source IP address of the access request; then, through the firewall service, it is detected whether the source IP address of the access request is in the IP address recorded in the network whitelist (i.e. Figure 3 the network whitelist detection); if the source IP address of the access request is not in the IP address recorded in the network whitelist, the access request is rejected to access the test environment.
[0072] If the source IP address of the access request exists in the IP address recorded in the network whitelist, the second service node 30 can authenticate the user based on the token in the firewall (corresponding to Figure 3 token authentication). Specifically, it can be detected through the firewall service whether the Cookie data of the access request contains a correct token. For example, it can be detected whether the Cookie data of the access request carries the token contained in the protection rule in the firewall service. If the Cookie data of the access request carries the token contained in the protection rule in the firewall service, it is determined that the Cookie data of the access request contains a correct token. If the Cookie data of the access request does not carry the token contained in the protection rule in the firewall service, it is determined that the Cookie data of the access request does not contain a correct token. Further, if it is detected that the Cookie data of the access request contains a correct token, the access request can be subjected to attack detection. The access request subjected to attack detection can access the test environment (corresponding to Figure 3 attack detection). If it is detected that the Cookie data of the access request does not contain a correct token, the access request is rejected to access the test environment.
[0073] In addition to the information processing system provided by the foregoing embodiments, the embodiments of the present application also provide an information processing method. The information processing method provided by the embodiments of the present application is exemplarily described below from the perspective of a user's electronic device, a first service node providing a token application service, and a second service node providing a firewall service.
[0074] Figure 4 A flowchart of the information processing method provided by the embodiments of the present application is shown in FIG. 4. The information processing method is applicable to a target electronic device. As shown in FIG. 4, the method mainly includes the following steps. Figure 4
[0075] 401. Obtain identification information of a target application service to be accessed.
[0076] 402. Based on the identification information of the target application service, generate a token application request for applying for a right to access the target application service.
[0077] 403. Send the token application request to the first service node providing the token application service, so that the first service node assigns a target token in response to the token application request, and triggers the first service node to create a target protection rule for the target application service in a firewall service used by the target application service according to the identification information of the target application service, the target token, and preconfigured authentication policy information.
[0078] 404. Obtain the target token, and send an access request to the target application service based on the target token, so that the firewall service authenticates the access request based on the target protection rule and the target token.
[0079] Figure 5 A flowchart of another information processing method provided by the embodiments of the present application is shown in FIG. 5. The information processing method is applicable to the foregoing first service node. As shown in FIG. 5, the method mainly includes the following steps. Figure 5
[0080] 501. In response to a token application request, assign a target token to the token application request; the token application request is used to apply for a right to access a target application service.
[0081] 502. From the token application request, obtain identification information of the target application service to be accessed.
[0082] 503. Return the target token to a target electronic device sending the token application request, so that the target electronic device accesses the target application service based on the target token.
[0083] 504. According to the identification information of the target application service, the target token and the pre-configured authentication policy information, a target protection rule of the target application service is created in a firewall service used by the target application service, so that the firewall service authenticates the access of the target application service based on the target protection rule.
[0084] Figure 6 Another flowchart of an information processing method is provided in the embodiments of the present application. The information processing method is applicable to the second service node providing the firewall service. As shown in the figure, the method mainly includes: Figure 6
[0085] 601. A protection rule creation request is obtained. The protection rule creation request includes: identification information of a target application service to be protected, a target token and authentication policy information. The target application service uses a firewall service.
[0086] 602. According to the identification information of the target application service, the target token and the pre-configured authentication policy information, a target protection rule of the target application service is created in a firewall service, so that the firewall service authenticates the access of the target application service based on the target protection rule.
[0087] In the embodiments, the second service node can provide the firewall service. The firewall service can provide customized protection rules, that is, the function of customizing protection rules.
[0088] In the embodiments, the target application service uses the firewall service, and the firewall service performs security detection on the access of the target application service. In this way, the target application service does not need to develop a firewall, and the development and maintenance cost of the firewall on the target application service side can be saved. In the embodiments, based on the function of customizing protection rules of the firewall service, the protection rule can be customized in the firewall service, and used to authenticate the access of the target application service. Details are described below.
[0089] In order to realize the authentication of the access of the target application service by the firewall service, the first service node is added. The first service node can provide a token application service, and of course, can also provide other services, such as a service of configuring protection rules in the firewall and the like. Based on the token application service provided by the first service node, a user can apply for a token from the first service node. To be exact, an electronic device of the user can apply for a token from the first service node. Specifically, a token application request for applying for the right to access the target application service can be sent to the first service node. The token application request can include: identification information of the target application service.
[0090] In some embodiments, the first service node can provide a token application page, and a button for applying a token is arranged on the token application page. The electronic device can display the token application page, and the user can apply for a token from the first service node by clicking the button for applying a token.
[0091] Of course, the token application page can also be provided with an identification information providing control of the target application service. The control can be a text input box or a selection button, etc. The user can provide the identification information of the application service to be accessed based on the identification information providing control of the target application service, i.e., the identification information of the target application service. For example, the identification information providing control of the target application service can be a text input box, and the user can input the identification information of the target application service in the text input box, etc. For another example, the identification information providing control of the target application service is a selection button, and the user can select the target application service to be accessed through the selection button; the electronic device can obtain the identification information of the target application service from the pre-stored identification information of the application service in response to the selection operation of the target application service. The pre-stored identification information of the application service includes the identification information of the target application service.
[0092] After the user provides the identification information of the target application service, the button for applying a token can be clicked to apply for a token from the first service node. Correspondingly, the electronic device can send a token application request to the first service node in response to the triggering operation (such as a click operation) of the button for applying a token. Specifically, the electronic device can obtain the identification information of the target application service in step 401, for example, in response to the triggering operation (such as a click operation) of the button for applying a token. Further, in step 403, a token application request is generated based on the identification information of the target application service. The token application request is used to apply for the permission to access the target application service. Further, in step 403, the token application request can be sent to the first service node providing the token application service.
[0093] Accordingly, the first service node can receive the token application request, and in step 501, assign a target token to the token application request in response to the token application request. Wherein, the target user refers to the user of the electronic device. Specifically, a random number can be generated in response to the token application request. Further, the random number can be subjected to a Hash calculation to obtain a Hash value of the random number, and the Hash value of the random number can be assigned to the token application request as the target token. Wherein, since the Hash function is usually one-way, it means that it is computationally infeasible to reverse the original random number from the Hash value, which increases the security of the target token. On the other hand, the random number can be very large, while the length of the Hash value is fixed, so using the Hash value of the random number as the target token can save the resources required for storing and transmitting the token. Further, in step 503, the target token can be returned to the target electronic device. Accordingly, in step 404, the target electronic device can obtain the target token. In the embodiments of the present application, the specific implementation manner of the first service node returning the target token to the target electronic device is not limited. In some embodiments, the target token can be returned directly to the target electronic device; or the target token is packet-encapsulated as a message body to obtain a response message; and the response message is returned to the target electronic device, so as to return the target token to the target electronic device.
[0094] In other embodiments, the message header can contain information for marking the user identity, such as Cookie data. Since the message header can contain information for marking the user identity, a response message indicating that the electronic device sets the target token as the identity marking information can be generated. Wherein, the identity marking information is the information for marking the user identity in the message header.
[0095] Further, the response message can be returned to the target electronic device. Since the target token is carried in the response message, returning the response message to the target electronic device also realizes returning the target token to the target electronic device. Accordingly, the target electronic device can obtain the target token from the response message, and in response to the response message, set the target token as the identity marking information for saving.
[0096] After the target electronic device obtains the target token, the target user can access the target application service based on the target token. Accordingly, when accessing the target application service, the target electronic device can send an access request to the target application service based on the target token. Specifically, the target token can be carried in the access request, and the access request carrying the target token can be sent to the target application service. Specifically, in response to the access demand for the target application service, the target token can be encapsulated into the message header of the access request as the identity marking information to obtain the access request.
[0097] In order to realize the authentication of the firewall service to the access of the application service, the firewall service also needs to configure a corresponding protection rule for each application service. Specifically, for the first service node, in step 502, the identification information of the target application service to be accessed can be obtained from the aforementioned token application request, and in step 504, a target protection rule for the target application service can be created in the firewall service according to the identification information of the target application service, the target token, and the pre-configured authentication policy information. The authentication policy information is information for describing the policy of how to authenticate, which can be text data or code form information, etc.
[0098] In some embodiments, the firewall service can provide a protection rule creation interface, such as an application programming interface. Accordingly, the protection rule creation interface can be called, and a target protection rule for the target application service can be created in the firewall service through the protection rule creation interface according to the identification information of the target application service, the target token, and the pre-configured authentication policy information.
[0099] In some embodiments, the authentication policy information includes a target action after authentication and a logical condition corresponding to the target action. The target action refers to a processing action for an access request, which is generally blocking or passing. Accordingly, the protection rule creation interface can be used to create a target protection rule in the firewall service, in which the identification of the protected object is the identification information of the target application service, the execution action is the target action, and the authentication condition is the logical condition and the target token. The target protection rule is used to authenticate the target application service, and the target action is performed on the access request if the access request meets the authentication condition.
[0100] For the second service node providing the firewall service, in step 601, a protection rule creation request can be obtained. The protection rule creation request can be obtained by the second service node through the protection rule creation interface, or through the protection rule creation page. The protection rule creation request includes the identification information of the target application service to be protected, the target token, and the detection policy information. Further, in step 602, a target protection rule for the target application service can be created in the firewall service according to the identification information of the target application service, the target token, and the pre-configured authentication policy information.
[0101] Specifically, the authentication policy information includes a target action after authentication and a logical condition corresponding to the target action. Accordingly, a target protection rule can be created in the firewall service, in which the identification of the protected object is the identification information of the target application service, the execution action is the target action, and the authentication condition is the logical condition and the target token.
[0102] The creation of the protection rule shown in the above embodiments is only exemplary and does not constitute a limitation. The foregoing embodiments create a token-based protection rule for the target application service in the firewall service. When a user accesses the target application service, the firewall service can authenticate the user's access to the target application service based on the token (such as the target token).
[0103] Specifically, the firewall service can obtain an access request for the target application service; and in the firewall service, it is detected whether the access request carries a token included in a protection rule in the firewall service; if the access request carries the token included in the protection rule in the firewall service, it is determined that the user sending the access request has access permission to the target application service.
[0104] The protection rule in the firewall service can include the target protection rule created in the foregoing embodiments, and the token included in the protection rule can include the foregoing target token.
[0105] For the foregoing embodiment in which the token is used as identity marking information in the packet header, in the firewall service, it is detected whether the identity marking information of the access request contains a token included in a protection rule in the firewall service; if the identity marking information of the access request contains the token included in the protection rule in the firewall service, it is determined that the user sending the access request has access permission to the target application service.
[0106] In the embodiments of the present application, the target application service uses the firewall service. A user of the target application service can apply for a token for identifying identity to a first service node providing a token application service, and the first service node can create a target protection rule for authenticating access to the target application service based on a token in the firewall service in response to the token application request, so that the firewall service can authenticate access to the target application service based on the token in the target protection rule, providing unified authentication service of the firewall, without the need for the target application service side to deploy and maintain an authentication system, which can reduce the security maintenance cost of the target application service side. Especially for the case of multiple target application services, unified authentication at the application layer is performed by the firewall service, without the need for each application service to deploy an independent authentication system, which can reduce the security maintenance cost of the application service side.
[0107] It should be noted that the execution subject of each step of the method provided in the above embodiments can be the same device, or the method can also have different devices as the execution subject. For example, the execution subject of steps 401 and 402 can be device A; for another example, the execution subject of step 401 can be device A, and the execution subject of step 402 can be device B; and the like.
[0108] In addition, in some of the processes described in the foregoing embodiments and accompanying drawings, a plurality of operations are included in a specific order, but it should be clear that the operations can be executed in the order in which they appear in this document or in parallel, and the serial numbers of the operations, such as 401, 402, etc., are only used to distinguish different operations, and the serial numbers themselves do not represent any execution order. In addition, these processes can include more or fewer operations, and the operations can be executed in sequence or in parallel.
[0109] Accordingly, the embodiments of the present application also provide a computer readable storage medium storing computer instructions, which, when executed by one or more processors, cause the one or more processors to perform the steps of the information processing method provided by the foregoing embodiments.
[0110] The embodiments of the present application also provide a computer program product, which includes a computer program, and when the computer program is executed by one or more processors, causes the one or more processors to perform the steps of the information processing method provided by the foregoing embodiments. In the embodiments of the present application, the specific implementation form of the computer program product is not limited. In some embodiments, the computer program product can be implemented as an application (APP), a computer client, a website, a webpage, a plug-in, or a software as a service (SaaS) service, etc.
[0111] Figure 7 The structural schematic diagram of the computing device provided by the embodiments of the present application is shown in FIG. 7. As shown in the figure, the computing device includes a memory 70a and a processor 70b. The memory 70a is configured to store a computer program. Figure 7 The processor 70b is coupled to the memory 70a and is configured to execute the computer program to perform the steps of the information processing method provided by the foregoing embodiments. For the specific implementation of each step, please refer to the related description of the foregoing embodiments, which will not be repeated here.
[0112] The processor 70b is coupled to the memory 70a and is configured to execute the computer program to perform the steps of the information processing method provided by the foregoing embodiments. For the specific implementation of each step, please refer to the related description of the foregoing embodiments, which will not be repeated here.
[0113] In some optional implementations, as shown in FIG. 7, the computing device can further include optional components such as a communication component 70c, a power supply component 70d, a display component 70e, and an audio component 70f. Figure 7 Figure 7 In some optional implementations, as shown in FIG. 7, the computing device can further include optional components such as a communication component 70c, a power supply component 70d, a display component 70e, and an audio component 70f. Figure 7 Figure 7 In some optional implementations, as shown in FIG. 7, the computing device can further include optional components such as a communication component 70c, a power supply component 70d, a display component 70e, and an audio component 70f.
[0114] In addition, Figure 7 The components in the dashed box are optional components, not mandatory components, and can be determined according to the product form of the computing device. The computing device in the embodiment can be implemented as a terminal device such as a desktop computer, a notebook computer, a mobile phone or an Internet of Things device; or a server device such as a traditional server, a cloud server or a server cluster.
[0115] In the embodiment of the present application, the memory is used to store a computer program and can be configured to store other various data to support the operation on the device where it is located. Among them, the processor can execute the computer program stored in the memory to realize the corresponding control logic. The memory can be realized by any type of volatile or non-volatile storage device or their combination, such as Static Random-Access Memory (SRAM), Electrically Erasable Programmable Read Only Memory (EEPROM), Erasable Programmable Read Only Memory (EPROM), Programmable Read Only Memory (PROM), Read Only Memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk.
[0116] In the embodiment of the present application, the processor can be any hardware processing device that can execute the above method logic. Optionally, the processor can be a Central Processing Unit (CPU), a Graphics Processing Unit (GPU) or a Microcontroller Unit (MCU); or a Field-Programmable Gate Array (FPGA), a Programmable Array Logic (PAL), a General Array Logic (GAL), a Complex Programmable Logic Device (CPLD) and the like programmable devices; or an Advanced RISC Machines (ARM) or a System on Chip (SoC) and the like, but is not limited thereto.
[0117] In embodiments of the present disclosure, the communication component is configured to facilitate wired or wireless communication between the device in which it is located and other devices. The device in which the communication component is located can access wireless networks based on communication standards, such as Wireless Fidelity (WiFi), 2G or 3G, 4G, 5G, or a combination thereof. In an example embodiment, the communication component receives broadcast signals or broadcast-related information from an external broadcast management system via a broadcast channel. In an example embodiment, the communication component can also be implemented based on Near Field Communication (NFC) technology, Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra Wide Band (UWB) technology, Bluetooth (BT) technology, or other technologies.
[0118] In embodiments of the present disclosure, the display component can include a Liquid Crystal Display (LCD) and a Touch Panel (TP). If the display component includes a touch panel, the display component can be implemented as a touch screen to receive input signals from a user. The touch panel includes one or more touch sensors to sense a touch, a slide, and a gesture on the touch panel. The touch sensor can not only sense a boundary of a touch or a slide action, but also detect a duration and a pressure related to a touch or a slide operation.
[0119] In embodiments of the present disclosure, the power supply component is configured to provide power to various components of the device in which it is located. The power supply component can include a power management system, one or more power sources, and other components associated with generating, managing, and distributing power to the device in which the power supply component is located.
[0120] In embodiments of the present disclosure, the audio component can be configured to output and / or input audio signals. For example, the audio component includes a microphone (MIC) configured to receive an external audio signal when the device in which the audio component is located is in an operational mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signal can be further stored in a memory or transmitted via the communication component. In some embodiments, the audio component also includes a speaker for outputting audio signals. For example, for a device with a language interaction function, voice interaction with a user can be implemented through the audio component, etc.
[0121] It should be noted that the terms "first", "second", etc. in the present text are used to distinguish different messages, devices, modules, etc., and do not represent a sequence order, nor limit the "first" and "second" to be different types.
[0122] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, Compact Disc Read-Only Memory (CD-ROM), optical storage, etc.) containing computer-usable program code.
[0123] The present application is described with reference to flowcharts and / or block diagrams of methods, apparatus (systems) and computer program products according to embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, as well as combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions, which are executed via the processor of the computer or other programmable data processing apparatus, generate a means for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that implements the functions specified in the flowcharts and / or block diagrams.
[0124] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including instruction apparatus, which implements the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that implements the functions specified in the flowcharts and / or block diagrams.
[0125] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable data processing apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable data processing apparatus provide a process for implementing the functions specified in the flowcharts and / or block diagrams. Figure 1 one or more flows and / or blocks Figure 1 an apparatus that implements the functions specified in the flowcharts and / or block diagrams.
[0126] In a typical configuration, a computing device includes one or more processors (CPUs, etc.), input / output interfaces, network interfaces, and memories.
[0127] Memory can include non-persistent memory and / or volatile memory, Random-Access Memory (RAM), and / or non-volatile memory, e.g., read-only memory (ROM), or flash memory, in a computer-readable medium. Memory is an example of computer-readable media.
[0128] The storage media of the computer is a readable storage medium, which can also be referred to as a readable medium. The readable storage medium includes permanent and non-permanent, removable and non-removable media, which can realize information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules or other data. Examples of the storage media of the computer include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital video disc (DVD) or other optical storage, magnetic cassette, disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information that can be accessed by a computing device. According to the definition herein, the computer-readable medium does not include transitory media, such as modulated data signals and carriers.
[0129] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or apparatus that includes a list of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the above-mentioned element.
[0130] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application can have various modifications and changes. Any modification, equivalent replacement, improvement, etc. within the spirit and principle of the present application shall be included in the scope of claims of the present application.
Claims
1. An information processing system characterized by comprising: The method comprises the steps of: an electronic device, a first service node providing a token application service, a second service node providing a firewall service, and a third service node providing a target application service; the target application service uses the firewall service; the electronic device sends a token application request for applying for a right to access the target application service to the first service node; the first service node allocates a target token for the token application request in response to the token application request; obtain the identification information of the target application service to be accessed from the token application request; return the target token to the electronic device, so that the electronic device accesses the target application service based on the target token; and create a target protection rule for the target application service in the firewall service according to the identification information of the target application service, the target token, and pre-configured authentication policy information, so that the firewall service authenticates the access to the target application service based on the target protection rule.
2. An information processing method for a service node that provides a token application service, characterized by, The method comprises the steps of: allocate a target token for a token application request in response to the token application request; the token application request is used to apply for a right to access the target application service; obtain the identification information of the target application service to be accessed from the token application request; return the target token to the target electronic device that sends the token application request, so that the target electronic device accesses the target application service based on the target token; create a target protection rule for the target application service in the firewall service used by the target application service according to the identification information of the target application service, the target token, and pre-configured authentication policy information, so that the firewall service authenticates the access to the target application service based on the target protection rule.
3. The method of claim 2, wherein, The method comprises the steps of: generate a response message indicating that the electronic device sets the target token as identity marker information; the identity marker information is information used to mark the identity of a user in a packet header; return the response message to the target electronic device to return the target token to the target electronic device.
4. The method of claim 2, wherein, The method comprises the steps of: call a protection rule creation interface provided by the firewall service; create a target protection rule for the target application service in the firewall service according to the identification information of the target application service, the target token, and pre-configured authentication policy information through the protection rule creation interface, so that the firewall service authenticates the access to the target application service based on the target protection rule.
5. The method of claim 4, wherein, The authentication policy information comprises: a target action after authentication and a logical condition corresponding to the target action; The creating, by the protection rule creating interface, of a target protection rule in the firewall service, the identification information of the protected object being the identification information of the target application service, the execution action being the target action, and the authentication condition being the logical condition and the target token, so that the firewall service authenticates access to the target application service based on the target protection rule. The creating, by the protection rule creating interface, of a target protection rule in the firewall service, the identification information of the protected object being the identification information of the target application service, the execution action being the target action, and the authentication condition being the logical condition and the target token, so that the firewall service authenticates access to the target application service based on the target protection rule.
6. The method according to any one of claims 2-5, characterized in that, The allocation of the target token in response to the token application request includes: Generating a random number in response to the token application request; Hashing the random number to obtain a hash value of the random number; The hash value of the random number is allocated as the target token to the token application request.
7. An information processing method suitable for a target electronic device, characterized by, It includes: Obtaining the identification information of the target application service to be accessed; Based on the identification information of the target application service, a token application request for applying for access to the target application service is generated; Sending the token application request to a service node providing a token application service, so that the service node allocates a target token in response to the token application request, and triggers the service node to create a target protection rule for the target application service in a firewall service used by the target application service according to the identification information of the target application service, the target token and the pre-configured authentication policy information; Obtaining the target token to send an access request to the target application service based on the target token, so that the firewall service authenticates the access request based on the target protection rule and the target token.
8. The method of claim 7, wherein, The obtaining of the target token includes: Obtaining a response message returned by the service node, the response message indicating that the electronic device sets the target token as identity marking information; the identity marking information is information in a packet header used to mark the identity of a user; wherein the electronic device is an electronic device that sends the token application request to the service node; Obtaining the target token from the response message, and setting the target token as the identity marking information for saving in response to the response message.
9. The method of claim 8, wherein, It also includes: Generating an access request with the target token as identity marking information; Sending the access request to the target application service, so that the firewall service authenticates the access request based on the target protection rule and the target token.
10. An information processing method for a service node that provides a firewall service, characterized by, It includes: Obtaining a protection rule creating request; The protection rule creating request includes: identification information of a target application service to be protected, a target token and pre-configured authentication policy information; the target application service uses a firewall service; According to the identification information of the target application service, the target token and the authentication policy information, a target protection rule of the target application service is created in the firewall service, so that the firewall service authenticates the access to the target application service based on the target protection rule.
11. The method of claim 10, wherein, The authentication policy information includes a target action after authentication and a logical condition corresponding to the target action. According to the identification information of the target application service, the target token and the authentication policy information, a target protection rule of the target application service is created in the firewall service, so that the firewall service authenticates the access to the target application service based on the target protection rule. In the firewall service, a target protection rule is created, in which the protected object is the identification information of the target application service, the execution action is the target action, and the authentication condition is the target token and the logical condition, so that the firewall service authenticates the access to the target application service based on the target protection rule.
12. The method of claim 10, wherein, Further comprising: An access request for the target application service is obtained through the firewall service; In the firewall service, it is detected whether the access request carries a token contained in a protection rule in the firewall service; the protection rule contains the target protection rule; the token contained in the protection rule contains the target token; If the access request carries the token contained in the protection rule in the firewall service, it is determined that the electronic device issuing the access request has the access right of the target application service.
13. A computing device, comprising: Comprising: A memory and a processor; wherein the memory is configured to store a computer program; The processor is coupled to the memory and is configured to execute the computer program to perform the steps in the method of any one of claims 2-12.
14. A computer readable storage medium having stored thereon computer instructions, wherein, When the computer instructions are executed by one or more processors, the one or more processors are caused to perform the steps in the method of any one of claims 2-12.
15. A computer program product, characterised in that, The computer program is included, and when the computer program is executed by one or more processors, the one or more processors are caused to perform the steps in the method of any one of claims 2-12.