Airport pass cloud service platform and method based on pluggable micro-service architecture
The airport pass cloud service platform, based on a pluggable microservice architecture, solves the problems of insufficient informatization and low intelligence in airport pass management, realizes cross-airport data sharing and document mutual recognition, improves management efficiency and security, and supports the digital and intelligent management of airports.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-01-08
- Publication Date
- 2026-04-07
AI Technical Summary
Airport control area access pass management suffers from insufficient system informatization, inconvenient management, and low level of intelligence. It cannot achieve cross-airport data sharing and document mutual recognition, resulting in low management efficiency, numerous security risks, and an inability to achieve precise control and real-time monitoring.
The airport pass cloud service platform adopts a pluggable microservice architecture, including a core support layer, a pluggable microservice layer, an access adaptation layer, and a management and scheduling layer. It realizes cloud application, cloud review, cloud certificate production, cloud verification, and cloud management and control, supports group-level management and cross-airport use, and utilizes blockchain evidence storage services, unified user management, object storage clusters, and log monitoring modules, combined with load balancers and API gateways for request processing and security management.
It enables digital management of the entire lifecycle of airport passes, improving airport operational efficiency and air defense security capabilities, supporting plug-and-play and elastic expansion, and ensuring high availability and security of services.
Smart Images

Figure CN121814834A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of airport microservices, and specifically discloses an airport pass cloud service platform and method based on a pluggable microservice architecture. BACKGROUND
[0002] Currently, there are many problems in the management of airport control area passes, and the trend of group control is obvious. The group has an urgent need for control area pass management, and the group's regional airport lacks system informatization and management, and urgently needs unified group control to solve the problem of insufficient management of small and medium-sized airport passes in the group; it is difficult to use and share data across airports, and it is difficult to recognize each other's certificates. Currently, most airport pass management is managed by the airport pass management unit alone, and certificate holders need to apply for a certificate separately when going to multiple airports, and the certificate cannot be recognized, which brings inconvenience to airline personnel and airport group managers when they need to cross the airport control area; it is difficult to control the certificate holders, and there is a lack of precise control methods. Physical certificates can at most achieve the function of saving access records to the control area, and it is difficult to achieve more precise control of the trajectory of certificate holders entering the control area, and there is a lack of effective means to control certificate holders, especially temporary certificate holders (currently 75% of temporary certificates in airports are paper-based, making it difficult to collect personnel data and requiring manual recording of access records), and digital and mobile internet management means are needed to improve capabilities; the degree of intelligent application is insufficient.
[0003] At present, artificial intelligence technology is developing rapidly, however, the intelligent level of most airport control area access card management systems is seriously insufficient. At present, the access card management of most airports still relies on traditional manual review and simple information input system, and the staff needs to spend a lot of time and energy to review the application materials one by one, which is not only low in efficiency, but also prone to human errors. For the review of the certificate photo, it can only be judged by the naked eye whether it meets the standard, and it is difficult to find the fake photo processed skillfully. In the certificate inspection link, some also mainly rely on manual comparison, especially when checking the temporary access card, in the face of a large number of personnel and frequent access demand, the checking speed is slow and the accuracy is difficult to guarantee, and it is difficult to find security risks such as using and stealing access cards in time. In addition, there is also a lack of intelligent means for the behavior supervision of the certificate holder after entering the control area. It is difficult to monitor the action track of the personnel in real time, analyze the behavior mode, and find abnormal behavior and issue early warning in time. In the face of complex and changeable security situation, the traditional management mode is not up to the task, and it is difficult to effectively guarantee the safety and stability of the airport control area; the offline application mode is backward and the process is complicated and inefficient. Many airports still have the situation of manual offline application of certificates, or manual offline participation in multiple links in the application process; there are also many airports that have access card information management systems but the functions are not perfect or there are function short boards, which causes the certificate application process to have the problems of complicated process, long cycle, low efficiency and poor experience. In view of the above problems, it is urgent to realize convenient, efficient and safe access card management by a digital and intelligent means.
[0004] Therefore, the present application provides an airport access card cloud service platform and method based on a pluggable micro-service architecture, which builds a cloud service platform based on a micro-service architecture, develops a digital access card, and builds an airport control area digital access card large model knowledge platform, so as to realize intelligent and digital management of access card certificates for personnel in the airport control area, realize cloud application, cloud review, cloud approval, cloud certificate, cloud inspection and cloud management and control, realize digitalization of certificates, cloudization of application and intelligentization of supervision, have the ability of group management and control and cross-airport use, and truly realize digital and intelligent management of the whole life cycle of the airport control area access card, and improve the operation efficiency of the airport and the air defense security guarantee capability. SUMMARY
[0005] The present application aims to provide an airport access card cloud service platform and method based on a pluggable micro-service architecture, and solves the problem of how to improve the intelligent management level of the airport and further improve the operation efficiency of the airport and the air defense security guarantee capability. The specific scheme is as follows: The airport pass cloud service platform based on the pluggable micro-service architecture comprises a core support layer, a pluggable micro-service layer, an access adaptation layer and a management and scheduling layer. The core support layer is used for deploying a plurality of containerized cluster nodes and completing initialization of the airport pass service and providing operation support. The initialized airport pass service is used for distributing instances of each service module in the plurality of containerized cluster nodes, and the service module comprises a distributed registration configuration center, a unified authentication gateway process service, a blockchain storage service, unified user management, an object storage cluster and a log monitoring module. The pluggable micro-service layer is used for encapsulating business functions of the airport pass service into independent pluggable plugins. The business functions of the airport pass service comprise personnel pass whole life cycle management, vehicle pass whole life cycle management, internal field driving license whole life cycle management, role permission management and digital pass management. The access adaptation layer is used for defining an access protocol of an airport terminal and realizing unified access and routing forwarding of external requests. The management and scheduling layer is used for plug-and-play and whole life cycle management and control of the independent pluggable plugins. The management and scheduling layer is also used for elastic expansion of the containerized cluster based on resource monitoring data.
[0006] Further, the access adaptation layer is configured with a load balancer and an API gateway. The load balancer is used for distributing external requests, balancing the load of the containerized cluster nodes and guaranteeing the processing efficiency of the requests. The API gateway serves as a unified entrance of the external requests, realizes standardized processing of the requests and supports standardized docking of the terminal and the cloud service. The standardized processing of the requests comprises request routing forwarding, identity verification, permission checking and illegal request interception.
[0007] Further, the management and scheduling layer is configured with a plugin registration center, a resource monitoring module and a dynamic expansion module. The plugin registration center is used for compatibility checking and registration of the independent pluggable plugins. The API gateway cooperates with the plugin registration center to realize the plug-and-play function of the independent pluggable plugins. The dynamic expansion module is used for elastic expansion of the containerized cluster based on received cluster resource data.
[0008] Further, the initial deployment number of the containerized cluster nodes of the core support layer is 3. The resource monitoring unit in the dynamic expansion module collects the memory occupation of the containerized cluster in real time. When the total memory occupation is greater than or equal to 100%, the dynamic expansion mechanism is triggered. Two containerized cluster nodes are automatically added each time and the deployment resources of the independent pluggable plugins are redistributed.
[0009] Further, the service monitoring layer is further included. The service monitoring layer is used for guaranteeing stable operation of the micro-service and comprises a distributed link tracking module and a fault tolerance protection module. The distributed link tracking module is used for recording the request flow path among the micro-services. The fault tolerance protection module is configured with a fuse mechanism and a degradation strategy. The fault tolerance protection module is used for avoiding single service failure diffusion and guaranteeing the availability of the airport pass service.
[0010] The airport pass cloud service method based on a pluggable microservice architecture, applied to the aforementioned airport pass cloud service platform, includes: Step 1, receiving the target airport's request for airport pass service activation; the activation request includes basic functional requirements and personalized requirements; Step 2, selecting plugins matching the airport pass service activation requirements from the plugin registration center; the plugins include general plugins and customized plugins; general plugins include personnel pass full lifecycle management plugins, role and permission management plugins, digital pass management plugins, and data encryption plugins; customized plugins include vehicle pass full lifecycle management plugins, in-field driver's license full lifecycle management plugins, and airport local business system integration plugins; and deploying instructions are initiated through the management and scheduling layer, and the core support layer deploys the general plugins and customized plugins to the cloud in a containerized manner. Cluster nodes; Step 3: Distribute the airport configuration of the target airport to the deployed plugins through the distributed registration and configuration center; the airport configuration includes the interface address, access key and permission rules. The core support layer establishes a communication connection with the plugin through the API gateway; Step 4: After the plugin runs, the memory usage data of the containerized cluster is collected in real time through the resource monitoring module, and the containerized cluster is elastically scaled based on the memory usage data; Step 5: After the plugin is deployed and passes the health check, the API gateway of the access adaptation layer opens the access channel of the target airport. The API gateway works with the distributed registration and configuration center to realize the plug-and-play of the plugin and enable the airport pass service; Step 6: If the target airport needs to add a service module, repeat steps 2 to 4 to deploy the corresponding new plugin; if the service function needs to be disabled, disable the corresponding plugin through the management scheduling layer.
[0011] Furthermore, it also includes building encrypted access tunnels through zero-trust VPNs to encrypt and protect communication between airport terminals and cloud services; and filtering external access requests through web application firewalls; data filtering includes traffic filtering, illegal request interception, and security auditing.
[0012] Furthermore, it also includes enabling a service monitoring mechanism, recording the request flow path between microservices and plugins through a distributed tracing module; when a single plugin or service call fails, the faulty unit is automatically isolated through a fault tolerance protection module, and the default response of the airport pass service is returned.
[0013] Furthermore, the distributed registration and configuration center is Nacos; API gateway parameters are managed uniformly through Nacos, and when a plugin version is upgraded or the configuration is changed, the configuration is updated synchronously to the corresponding containerized cluster node through Nacos; API gateway parameters include API version, permission parameters, and plugin configuration rules.
[0014] Furthermore, the initial deployment of containerized cluster nodes is 3. The resource monitoring unit collects the memory usage of the containerized cluster in real time. When the total memory usage is ≥100%, the dynamic expansion module automatically adds 2 containerized cluster nodes and redistributes the plugins to the newly added containerized cluster nodes.
[0015] The present invention has the following advantages and beneficial effects: This invention, based on cloud-based microservices, further employs a pluggable microservice architecture, ensuring that the cloud-based access platform can be deployed lightweight and efficiently to meet the customized needs of different airports. Pluggable microservices are an advanced form of microservice architecture, the core of which is that services can be "plug and play, seamlessly replaced" like plug-and-play modules. Attached Figure Description
[0016] Figure 1 This is an exemplary schematic diagram of the airport pass cloud service platform based on a pluggable microservice architecture provided by the present invention. Figure 2 This is an exemplary flowchart of the airport pass cloud service method based on a pluggable microservice architecture provided by the present invention. Detailed Implementation
[0017] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. The components of the embodiments of the present invention described and shown in the accompanying drawings can generally be arranged and designed in various different configurations.
[0018] To achieve end-to-end decoupling of the airport control area digital pass system and build a highly available, secure, modular, and scalable system service, the system adopts a microservice architecture as its foundation. The system functions are decomposed into independent microservices for deployment, and each microservice can create multiple instances during actual operation. Combined with containerization technology, these instances are deployed on multiple nodes of the container cluster during actual deployment. If a single server node fails, it will not affect the normal operation of the system. Figure 1 This is an exemplary schematic diagram of an airport pass cloud service platform based on a pluggable microservice architecture provided by the present invention. The microservices employ the aforementioned modular encapsulation of business functions based on a microservice architecture, breaking down core business capabilities into independent service units. For example... Figure 1As shown, microservices include service governance and configuration, service monitoring, application gateways, pluggable microservices, and RESTful APIs. Specifically, the airport pass cloud service platform based on the pluggable microservice architecture includes not only basic storage modules, process engine modules, and AI computing power modules, but also a front-end interaction layer, a core support layer, a pluggable microservice layer, an access adaptation layer, a management and scheduling layer, and development management tools.
[0019] The front-end interaction layer receives user requests and includes a user access module and a front-end interaction module. The user access module provides a unified access point across multiple terminals, supporting different roles such as airport staff and maintenance personnel to access the platform through designated terminals, including PCs, mobile devices, and application terminals. The front-end interaction module enables visual interaction between users and the platform, supporting functions such as inputting operation commands, displaying business data, and querying processing progress, including web pages, Android apps, and iOS apps.
[0020] The core support layer deploys multiple containerized cluster nodes and initializes the airport pass service, providing operational support. Initializing the airport pass service involves distributing instances of each service module across multiple containerized cluster nodes. These service modules include a distributed registration and configuration center (such as Nacos), a unified authentication gateway process service (such as Spring Cloud Gateway), a blockchain evidence storage service, unified user management, an object storage cluster, and a log monitoring module (such as ELK). For example, the core support layer is responsible for the full lifecycle management and collaborative scheduling of microservices. Service governance uses Nacos as the microservice registry center, enabling automatic service registration, discovery, and health monitoring, supporting dynamic service configuration and version management, and ensuring a smooth transition for service iterations. An API gateway is used as the unified interface entry point to implement functions such as request routing, permission verification, rate limiting and circuit breaking, and log auditing, effectively managing external access risks. The core support layer may include service governance and configuration modules, which may include Nacos service registration, Nacos service discovery, and Nacos unified configuration. The distributed registration and configuration center is used to implement the registration, discovery, dynamic configuration, and health status monitoring of microservices and plugins, supporting the collaborative operation of the service cluster. The unified authentication gateway process service provides a unified request access point, enabling routing, identity authentication, permission verification, rate limiting, circuit breaking, and log auditing to ensure secure and efficient service access. The blockchain evidence storage service encrypts and stores critical data such as pass processing data, permission change records, and plugin operation logs, ensuring data immutability and traceability. Unified user management manages the identity information, assigns roles, controls permissions, and authorizes authentication for airport personnel, supporting a tiered access mechanism. The object storage cluster stores pass image files, business attachments, system logs, and other data resources, providing highly available and scalable data storage support. The log monitoring module collects, stores, and analyzes the operation logs of various services and plugins, enabling abnormal behavior alerts and fault tracing.
[0021] In some embodiments, the initial deployment number of containerized cluster nodes of the core support layer in the cloud is 3. The resource monitoring unit in the dynamic expansion module collects the memory usage of the containerized cluster in real time. When the total memory usage is ≥100%, the dynamic expansion mechanism is triggered, and 2 containerized cluster nodes are automatically added each time and the deployment resources of independent pluggable plugins are reallocated.
[0022] The pluggable microservice layer encapsulates the business functions of the airport pass service into independent pluggable plugins. Developed according to standardized interface protocols, these plugins are submitted to the plugin registry center for compatibility verification and registration. The airport pass service's business functions include core airport pass business functions such as full lifecycle management of personnel passes, full lifecycle management of vehicle passes, full lifecycle management of in-flight driver's licenses, role and permission management, digital pass management, distributed task scheduling, front-end microservices, and pass AI algorithms. The pluggable microservice architecture can be expanded according to the actual needs of different airports, providing independent service units that meet the interface specifications of specific airports. It allows for flexible integration, removal, or replacement without modifying the overall system architecture or other service code, enabling dynamic expansion or replacement of functions. The full lifecycle management of personnel passes automates the entire process of application, review, issuance, annual inspection, modification, loss reporting, and cancellation of airport personnel passes. The full lifecycle management of vehicle passes automates the entire process of application, approval, issuance, expiration reminders, annual inspection, and cancellation of in-flight vehicle passes. Airport in-flight driver's license lifecycle management is used to manage the application, examination, issuance, annual review, renewal, and cancellation of airport in-flight driver's licenses, meeting the specific needs of airport in-flight driving. Role and permission management defines role types for different positions in the airport, assigns corresponding operation permissions and data access scopes, and achieves fine-grained permission control. Digital pass management enables the generation, issuance, verification, status update, and expiration control of digital passes, supporting online pass usage scenarios. Distributed task scheduling performs distributed scheduling and execution monitoring of system scheduled tasks (such as pass expiration reminders, data synchronization, and log cleanup) to ensure reliable task operation. Front-end microservices encapsulate independent front-end functional modules (such as approval process components and data visualization components), supporting independent deployment, updates, and iterations of front-end functions. Pass AI algorithms provide intelligent capabilities such as facial recognition, document information OCR recognition, and risk behavior warnings, improving the efficiency and security control level of pass business processing.
[0023] The access adaptation layer defines the access protocol for airport terminals, enabling unified access and routing of external requests. It is configured with a load balancer (such as NGINX) and an API gateway, defining the access protocol (HTTP / HTTPS, MQTT) for airport terminals to achieve standardized integration between terminals and cloud services. The load balancer distributes external requests, balancing the load across containerized cluster nodes and ensuring efficient request processing, including multiple ELBs. The API gateway serves as the unified entry point for external requests, implementing standardized request processing and supporting standardized integration between terminals and cloud services. Standardized request processing includes request routing, authentication, permission verification, and illegal request interception. The API gateway can include multiple application gateways and microservice units. Application gateways can include multiple gateways, serving as the unified entry point for exposed services in the service architecture. They include login entry points for users, developers, and maintenance personnel, unifying the access of external requests (such as client-side requests and third-party systems), and forwarding traffic to corresponding microservices through routing rules, achieving simplified interaction of "one entry point managing multiple services." Request authentication, permission verification, and illegal request interception ensure secure service access. Requests are authenticated and permissions are verified to block unauthorized requests, ensuring secure service access. External systems do not need to directly interface with multiple microservices; they only need to interact with the gateway, reducing inter-service dependencies and improving architectural flexibility. The microservice unit's functions include an authentication center, rate limiting, and Swagger.
[0024] In some embodiments, microservices interact with each other and with external systems via RESTful APIs. RESTful APIs provide features such as interface standardization, service governance support, and pluggable microservice adaptation. They employ HTTP verbs and resource path mapping for business operations, ensuring clear and readable interface semantics. Combined with Nacos service registration and discovery, dynamic API routing is implemented (automatic switching to a backup instance when a service goes offline); and API versions, permissions, and parameter rules are managed through Nacos unified configuration, ensuring configuration consistency. Figure 1 The pluggable microservice layer (such as distributed task scheduling, role and permission management, and full lifecycle management of access permits) needs to expose core functions through Restful API to support external systems (such as front-end and third-party platforms) to call on demand and realize plug-and-play service.
[0025] The management and scheduling layer is used for plug-and-play and full lifecycle management of independent pluggable plugins. It also enables elastic scaling of the containerized cluster based on resource monitoring data. The management and scheduling layer is configured with a plugin registry, a resource monitoring module, and a dynamic scaling module. The plugin registry performs compatibility checks and registration for independent pluggable plugins. The API gateway works with the plugin registry to enable plug-and-play functionality for independent pluggable plugins. The dynamic scaling module performs elastic scaling of the containerized cluster based on received cluster resource data. For example, when the management and scheduling layer is enabled, the plugin registry, resource monitoring module, and dynamic scaling module are started, and parameters such as the memory load threshold (100%) and the number of scaling nodes (2 per instance) are configured. The deployment process for pluggable microservices is divided into requirement submission, plugin selection and deployment, configuration synchronization, resource monitoring and scaling, service activation, and subsequent adjustments.
[0026] The development management tools provide the resource support and management tools needed for the entire process of platform development, deployment, and operation and maintenance, supporting rapid system iteration and stable operation and maintenance. These tools can include the basic virtualization resources provided by the cloud platform and the development management layer. Basic virtualization resources can include the Cloud Container Engine (CCE) (Docker), Elastic Compute Service (ECS) cloud servers, and a cloud bastion host. The CCE (Docker) cloud server's functions include image repository, compute node cluster management, cluster deployment, and service management. ECS cloud servers can include elastic cloud servers and server management. The cloud bastion host's functions can include online operation and maintenance and policy management. The development management layer is used to achieve full-process development management, including requirements integration, code management, packaging and deployment, quality inspection, and testing verification, improving R&D efficiency. The development management layer's functions can include requirements management, code repository, online deployment, online packaging, quality access control, and test management.
[0027] In some embodiments, an access control layer and a web application protection layer are also included. The access control layer constructs an encrypted access tunnel through a zero-trust VPN to encrypt and protect the communication between the airport terminal and the cloud service. The web application protection layer filters external access requests through a web application firewall; data filtering includes traffic filtering, illegal request interception, and security auditing.
[0028] In some embodiments, a service monitoring layer is also included. This layer ensures the stable operation of microservices and includes a distributed tracing module, a fault tolerance protection module, a service monitoring module, and a log center. The distributed tracing module records the request flow path between microservices, quickly locating issues such as "cross-service call timeouts" and "service dependency failures," addressing the operational pain points of "black-box calls." The fault tolerance protection module is configured with a circuit breaker mechanism and degradation strategies. It prevents the spread of single-service failures and ensures the availability of the airport pass service. For example, by monitoring service metrics such as CPU, memory, network, and response time in real time, and using alert mechanisms (such as email, SMS, and visual dashboards) to provide early warnings of service anomalies, it prevents the spread of failures. Circuit breaking automatically isolates faulty services when service calls fail, preventing a "snowball effect," and degradation strategies (such as returning default values) ensure the availability of core business operations. Logs from each microservice are centrally collected, and log storage, searching, and analysis are implemented using technologies such as ELK, providing data support for troubleshooting and performance optimization. The service monitoring module is used to collect real-time operational metrics (CPU, memory, response time, etc.) of microservices and plugins, enabling anomaly alerts and visualized status monitoring. The log center is used to centrally collect, store, and retrieve operational logs from all service and plugin layers, supporting troubleshooting, performance optimization, and compliance auditing.
[0029] The airport pass cloud service platform based on a pluggable microservice architecture provided by this invention achieves lightweight isolation and rapid scaling through containerized deployment. The cloud service deployment is divided into an architecture deployment process and a pluggable microservice deployment process, taking a new airport as an example. The architecture deployment process includes the deployment of the microservice core support layer, plugin service registration, access layer adaptation, and the activation of the management and scheduling layer.
[0030] This invention also provides a cloud service method for airport access passes based on a pluggable microservice architecture, such as... Figure 2 As shown, the process of the airport pass cloud service method based on a pluggable microservice architecture provided by the present invention may include the following steps: Step 1, Request Submission: Receive the target airport's request to activate the airport pass service; activation requests include basic functional requirements and personalized requirements (such as integration with the local baggage check-in system).
[0031] Step 2, Plugin Selection and Deployment: Select plugins that match the airport pass service activation requirements from the plugin registry center; plugins include general plugins and customized plugins; general plugins include personnel pass full lifecycle management plugins, role and permission management plugins, digital pass management plugins, and data encryption plugins; customized plugins include vehicle pass full lifecycle management plugins, in-field driver's license full lifecycle management plugins, and airport local business system integration plugins; deploy commands are initiated through the management and scheduling layer, and the core support layer deploys the general plugins and customized plugins to the cloud containerized cluster nodes.
[0032] Step 3, Configuration Synchronization: The airport configuration of the target airport is distributed to the deployed plugins through the distributed registration configuration center; the airport configuration includes the interface address, access key and permission rules, and the core support layer establishes a communication connection with the plugins through the API gateway.
[0033] Step 4, Resource Monitoring and Scaling: After the plugin runs, the resource monitoring module collects real-time memory usage data of the containerized cluster (8% new memory usage per node) and elastically scales up the containerized cluster based on this data. For example, if the initial deployment of the containerized cluster nodes is 3, the resource monitoring unit collects real-time memory usage data. When the total memory usage is ≥100%, the dynamic scaling module automatically adds 2 new containerized cluster nodes and redistributes the plugin to the newly added nodes.
[0034] Step 5, Service Activation: After the plugin is deployed and passes the health check, the API gateway of the access adaptation layer opens the access channel of the target airport. Through the API gateway and the distributed registration and configuration center, the plugin can be used plug and play, and the digital airport pass service is activated.
[0035] Step 6, Subsequent Adjustments: If the target airport needs to add a service module, repeat steps 2 to 4 to deploy the corresponding new plugin; if the service function needs to be disabled, disable the corresponding plugin through the management and scheduling layer without stopping the overall service.
[0036] In some embodiments, the business data, permission change data, and plugin operation logs of the airport pass service are encrypted and stored using a blockchain-based evidence storage service.
[0037] In some embodiments, the system also includes constructing an encrypted access tunnel via a zero-trust VPN to encrypt and protect the communication between the airport terminal and the cloud service; and filtering external access requests via a web application firewall; the data filtering includes traffic filtering, illegal request interception, and security auditing.
[0038] In some embodiments, a service monitoring mechanism is also included, which records the request flow path between microservices and plugins through a distributed tracing module; when a single plugin or service call fails, the faulty unit is automatically isolated through a fault tolerance protection module, and the default response of the airport pass service is returned.
[0039] In some embodiments, the distributed registration configuration center is Nacos; API gateway parameters are managed uniformly through Nacos, and when a plugin version is upgraded or its configuration is changed, the configuration is synchronously updated to the corresponding containerized cluster node through Nacos; API gateway parameters include API version, permission parameters, and plugin configuration rules.
[0040] The above are merely preferred embodiments of the present invention and are not intended to limit the present invention. Various modifications and variations can be made to the present invention by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.
Claims
1. An airport pass cloud service platform based on a pluggable microservice architecture, characterized in that: It includes a core support layer, a pluggable microservice layer, an access adaptation layer, and a management and scheduling layer; The core support layer is used to deploy multiple containerized cluster nodes and complete the initialization of the airport pass service, providing operational support. Initializing the airport pass service involves distributing instances of each service module across multiple containerized cluster nodes. The service modules include a distributed registration configuration center, a unified authentication gateway process service, a blockchain evidence storage service, a unified user management system, an object storage cluster, and a log monitoring module. The pluggable microservice layer is used to encapsulate the business functions of the airport pass service as independent pluggable plugins; the business functions of the airport pass service include full lifecycle management of personnel passes, full lifecycle management of vehicle passes, full lifecycle management of in-field driver's licenses, role and permission management, and digital pass management. The access adaptation layer is used to define the access protocol of airport terminals, enabling unified access and routing forwarding of external requests; The management and scheduling layer is used to perform plug-and-play and full lifecycle management of independent pluggable components; The management and scheduling layer is also used to elastically scale containerized clusters based on resource monitoring data.
2. The airport pass cloud service platform based on a pluggable microservice architecture as described in claim 1, characterized in that, The access adaptation layer is configured with a load balancer and an API gateway; Load balancers are used to distribute external requests, balance the load on containerized cluster nodes, and ensure the efficiency of request processing. As a unified entry point for external requests, the API gateway enables standardized processing of requests and supports standardized integration between terminals and cloud services. Standardized request processing includes request routing and forwarding, authentication, permission verification, and illegal request interception.
3. The airport pass cloud service platform based on a pluggable microservice architecture as described in claim 1, characterized in that, The management and scheduling layer is configured with a plugin registration center, a resource monitoring module, and a dynamic expansion module; The plugin registry is used to perform compatibility checks and register independent pluggable plugins; The API gateway, in conjunction with the plugin registry center, enables plug-and-play functionality for independent, pluggable plugins. The dynamic scaling module is used to elastically scale up the containerized cluster based on the received cluster resource data.
4. The airport pass cloud service platform based on a pluggable microservice architecture as described in claim 3, characterized in that, The initial deployment of the containerized cluster nodes in the core support layer is 3. The resource monitoring unit in the dynamic expansion module collects the memory usage of the containerized cluster in real time. When the total memory usage is ≥100%, the dynamic expansion mechanism is triggered, automatically adding 2 containerized cluster nodes each time and reallocating the deployment resources of independent pluggable plugins.
5. The airport pass cloud service platform based on a pluggable microservice architecture as described in claim 1, characterized in that, It also includes a service monitoring layer, which is used to ensure the stable operation of microservices, including a distributed tracing module and a fault tolerance protection module; The distributed tracing module is used to record the request flow path between microservices; The fault-tolerant protection module is equipped with a circuit breaker mechanism and a degradation strategy. The fault-tolerant protection module is used to prevent the spread of a single service failure and ensure the availability of the airport pass service.
6. A method for providing airport pass cloud services based on a pluggable microservice architecture, applicable to the airport pass cloud service platform based on a pluggable microservice architecture as described in any one of claims 1-5, characterized in that, include: Step 1: Receive the target airport's request to activate the airport pass service; Activation requirements include basic functional requirements and personalized requirements; Step 2: Select plugins that match the airport pass service activation requirements from the plugin registration center. Plugins include general plugins and customized plugins. General plugins include plugins for full lifecycle management of personnel passes, plugins for role and permission management, plugins for digital pass management, and plugins for data encryption. Customized plugins include plugins for full lifecycle management of vehicle passes, plugins for full lifecycle management of in-field driver's licenses, and plugins for integration with local airport business systems. Deployment instructions are initiated through the management and scheduling layer, and the core support layer deploys the general plugins and customized plugins to the cloud containerized cluster nodes. Step 3: Distribute the airport configuration of the target airport to the deployed plugins through the distributed registration and configuration center; the airport configuration includes the interface address, access key and permission rules, and the core support layer establishes a communication connection with the plugins through the API gateway; Step 4: After the plugin runs, the memory usage data of the containerized cluster is collected in real time through the resource monitoring module, and the containerized cluster is elastically scaled up based on the memory usage data. Step 5: After the plugin is deployed and passes the health check, the API gateway of the access adaptation layer opens the access channel of the target airport. The API gateway works with the distributed registration and configuration center to enable the plug-and-play functionality of the plugin and enable the airport pass service. Step 6: If the target airport needs to add a service module, repeat steps 2 to 4 to deploy the corresponding new plugin; if the service function needs to be disabled, disable the corresponding plugin through the management and scheduling layer.
7. The airport pass cloud service method based on a pluggable microservice architecture according to claim 6, characterized in that, It also includes building encrypted access tunnels through zero-trust VPNs to encrypt and protect communications between airport terminals and cloud services; Filter external access requests using a web application firewall; Data filtering includes traffic filtering, illegal request blocking, and security auditing.
8. The airport pass cloud service method based on a pluggable microservice architecture according to claim 6, characterized in that, This also includes enabling a service monitoring mechanism, which records the request flow paths between microservices and plugins through a distributed tracing module; When a single plugin or service call fails, the faulty unit is automatically isolated by the fault tolerance protection module, and the default response of the airport pass service is returned.
9. The airport pass cloud service method based on a pluggable microservice architecture according to claim 6, characterized in that, The distributed registration and configuration center is Nacos; API gateway parameters are managed uniformly through Nacos, and when the plugin version is upgraded or the configuration is changed, the configuration is updated synchronously to the corresponding containerized cluster node through Nacos. API gateway parameters include API version, permission parameters, and plugin configuration rules.
10. The airport pass cloud service method based on a pluggable microservice architecture according to claim 6, characterized in that, The initial deployment of containerized cluster nodes is 3. The resource monitoring unit collects the memory usage of the containerized cluster in real time. When the total memory usage is ≥100%, the dynamic expansion module automatically adds 2 containerized cluster nodes and redistributes the plugins to the newly added containerized cluster nodes.
Citation Information
Patent Citations
Micro-service routing and management system plug-in
CN113726662A
Method and system for realizing micro-service plug-in gateway
CN117997773A
Pluggable modules for terminal services
US20090183225A1