Data access method and system, electronic device, storage medium and program product
By verifying the authentication information in the client's data access request on the server, ensuring that the client has access rights, solving the problem that data access security cannot be effectively guaranteed in the prior art, and achieving higher data access security.
Patent Information
- Application Number
- PCT/CN2024/088086
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-11-13
- Filing Date
- 2024-04-16
- Publication Date
- 2025-05-22
AI Technical Summary
The existing way of accessing the data system through access tokens cannot effectively ensure the security of data access by user clients, and there are data security risks.
When receiving the client's data access request on the server, the identification information and signature information contained in the authentication information contained in the request are extracted and verified, ensuring that the client has access rights before accessing the data.
It realizes effective authentication of user client access data permissions to prevent users without access permission from accessing data, thereby improving the security of data access.
Smart Images

Figure CN2024088086_22052025_PF_FP_ABST
Abstract
Description
Data access method, system, electronic device, storage medium and program product
[0001] This application claims priority to the Chinese patent application filed with the China Patent Office on November 13, 2023, with application number 2023115075476 and application name “Data access method, system, electronic device, storage medium and program product”. The entire contents of the above application are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of data access technology, and in particular to a data access method, system, electronic device, storage medium, and program product. Background Art
[0003] With the development of computer technology, more and more user clients need to access data systems to obtain data, so system network security certification becomes particularly important.
[0004] In order to improve the security of the system network, most of the current controls on data system access are based on user access rights to prevent malicious intrusions from having a significant impact on the system network security. For example, after a user registers and logs in to a data system, the corresponding user client will obtain a unified access token for accessing the data system. Subsequently, the user client can access all data in the data system based on the access token. Although this method ensures the security of the system network to a certain extent, the data in the data system is huge, and there may be some data that users are not allowed to access, or the data that each user can access may be different. Therefore, the existing method of accessing the entire data system through access tokens cannot guarantee the security of user clients accessing various data, and there are data security risks.
[0005] Summary of the Invention
[0006] The present application provides a data access method, system, electronic device, storage medium and program product for authenticating the user client's access rights to data, thereby preventing user clients without access rights from accessing data, thereby causing data security risks.
[0007] In a first aspect, the present application provides a data access method, which is applied to a server, and the method includes: receiving a data access request for first data sent by a client, the data access request including first authentication information corresponding to the first data, the first authentication information being sent by the server to the client in response to an authentication information acquisition request sent by the client before the data access request, and the first authentication information being generated by the server by signing first identification information corresponding to the first data based on first signature information corresponding to the first data; extracting first identification information and first signature information corresponding to the first data from the first authentication information included in the data access request; generating second signature information based on the first identification information; when the second signature information matches the first signature information, determining that the client has permission to access the first data, and allowing the client to access the first data; when the second signature information does not match the first signature information, determining that the client does not have permission to access the first data, and denying the client access to the first data.
[0008] The data access method provided by the implementation of this application is as follows: the server receives a data access request for first data sent by a client, extracts the first identification information and first signature information of the first data from the first authentication information included in the data access request, generates second signature information based on the first identification information, and determines that the client has the authority to access the first data if the second signature information matches the first signature information, and allows the client to access the first data; if the second signature information does not match the first signature information, denies the client access to the first data. In this way, the client's access rights to any data can be authenticated to prevent users without access rights from accessing the first data, which may lead to data leakage. Therefore, the data access method provided by this application ensures the security of data access.
[0009] In one implementation of the data access method provided by the implementation of the present application, the authentication information acquisition request includes the second identification information of the client, and the first authentication information is sent to the client in response to the authentication information acquisition request sent by the client before the data access request, including: responding to the authentication information acquisition request, determining a target list based on the second identification information included in the authentication information acquisition request, the target list including the identification information and corresponding authentication information of the target data to which the client has access rights, the target data including the first data, the identification information including the first identification information, and the authentication information including the first authentication information; and sending the target list to the client.
[0010] In the implementation of this application, before the client accesses each piece of data, a target list is first determined based on the client's access request to the server, and a target list is generated based on the identification information and signature information of the target data to which the client has access rights, and the target list is sent to the client. In this way, when the client subsequently accesses the data therein, it only needs to provide the authentication information corresponding to the data (i.e., identification information and signature information) so that the server can verify the client's permission to access the data based on the authentication information. In this way, permission management for a single piece of data is achieved, ensuring the security of data access.
[0011] In one implementation of the data access method provided by the implementation of the present application, the second identification information is the user identification information of the first user corresponding to the client, and the target list is determined based on the second identification information included in the authentication information acquisition request, including: authenticating the first user based on the user identification information to obtain an authentication result; when the authentication result is that the authentication is passed, determining the target data to which the first user has access rights, and generating a target list based on the identification information and signature information of the target data.
[0012] In the implementation of the present application, when the client accesses for the first time (that is, when sending an authentication information acquisition request), the first user is first authenticated based on the user identification information of the first user corresponding to the client, so that after the first user passes the authentication, the corresponding target list is provided to the first user.
[0013] In one implementation of the data access method provided in the implementation of the present application, the first signature information is generated based on the first identification information; and the second signature information is generated based on the first identification information.
[0014] In the implementation of the present application, signature information corresponding to each data is generated based on the identification information of each data, so that the client's access rights to each data are verified based on the signature information to ensure the security of the client accessing the data.
[0015] In one implementation of the data access method provided by the implementation of the present application, the method also includes: determining the first user identification information of the first user, where the first user is a user with access rights to the first data; generating first signature information based on the first identification information and the first user identification information; and generating second signature information based on the first identification information and the first user identification information.
[0016] In the implementation of this application, signature information is generated based on the identification information of the data and the identification information of the user with access rights. This can generate unique signature information for each user for the data, preventing other users from accessing the data using the user's signature information, further ensuring the security of data access.
[0017] In one implementation of the data access method provided by the implementation of the present application, the method further includes: if the data access request does not include the first authentication information, determining that the client does not have the authority to access the first data, and denying the client access to the first data.
[0018] In the implementation of the present application, if the access request does not contain authentication information, it means that the client does not have access rights to the data, and the client's access to the data is denied, thereby ensuring the security of data access.
[0019] In a second aspect, an embodiment of the present application provides a data access method, which is applied to a client, and the method includes: sending a data access request for first data to a server, so that the server extracts first identification information and first signature information corresponding to the first data from the first authentication information included in the data access request, generates second signature information based on the first identification information, and when the second signature information matches the first signature information, determines that the client has the authority to access the first data, and allows the client to access the first data; when the second signature information does not match the first signature information, determines that the client does not have the authority to access the first data, and denies the client access to the first data, the first authentication information is sent by the server to the client in response to the authentication information acquisition request sent by the client before the data access request, and the first authentication information is generated by the server by signing the first identification information corresponding to the first data based on the first signature information corresponding to the first data.
[0020] On the third aspect, an embodiment of the present application provides a data access method, which is applied to a data access system, the data access system including a server and a client, the method including: the client sends a data access request for first data to the server, the data access request including first authentication information corresponding to the first data, the first authentication information is sent to the client by the server in response to an authentication information acquisition request sent by the client before the data access request, and the first authentication information is generated by the server by signing the first identification information corresponding to the first data according to the first signature information corresponding to the first data; the server receives the data access request, and extracts the first identification information and first signature information corresponding to the first data from the first authentication information included in the data access request; the server generates second signature information based on the first identification information; when the second signature information matches the first signature information, the server determines that the client has the authority to access the first data, and allows the client to access the first data; when the second signature information does not match the first signature information, the server determines that the client does not have the authority to access the first data, and denies the client access to the first data.
[0021] In a fourth aspect, an embodiment of the present application provides a data access system, including a client and a server, wherein the client is used to send a data access request for first data to the server, the data access request including first authentication information corresponding to the first data, the first authentication information is sent to the client by the server in response to an authentication information acquisition request sent by the client before the data access request, and the first authentication information is generated by the server by signing the first identification information corresponding to the first data based on the first signature information corresponding to the first data; the server is used to receive the data access request, extract the first identification information and first signature information corresponding to the first data from the first authentication information included in the data access request; generate second signature information based on the first identification information; if the second signature information matches the first signature information, determine that the client has the authority to access the first data, and allow the client to access the first data; if the second signature information does not match the first signature information, determine that the client does not have the authority to access the first data, and deny the client access to the first data.
[0022] In a fifth aspect, an embodiment of the present application provides an electronic device comprising: a processor, and a memory communicatively connected to the processor; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory to implement the data access method provided by the implementation of the first aspect above, or the data access method provided by the implementation of the second aspect, or the data access method provided by the implementation of the third aspect.
[0023] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are executed by a processor, they are used to implement the data access method provided by the implementation of the first aspect above, or the data access method provided by the implementation of the second aspect, or the data access method provided by the implementation of the third aspect.
[0024] In the seventh aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the data access method provided by the implementation of the first aspect above, or the data access method provided by the implementation of the second aspect, or the data access method provided by the implementation of the third aspect.
[0025] It can be understood that the beneficial effects of the second to seventh aspects can also be found in the relevant description of the first aspect, and will not be repeated here.
[0026] The data access method provided by the implementation of the present application is as follows: after the client sends an authentication information acquisition request to the server, the server feeds back a target list to the client, where the target list includes identification information and authentication information of target data to which the client has access rights. After the client sends a data access request (i.e., a data access request) for certain data (e.g., first data) to the server, the server extracts the identification information and signature information (i.e., the first signature information) corresponding to the data from the authentication information included in the data access request, and generates new signature information (i.e., the second signature information) based on the identification information. If the extracted signature information (i.e., the first signature information) matches the generated signature information (i.e., the second signature information), it indicates that the client has the right to access the data, and the client is allowed to access the data. If the extracted signature information and the generated signature information do not match, it indicates that the client does not have the right to access the data, and the client is denied access to the data.
[0027] Furthermore, in the implementation of the present application, signature information can also be generated based on user identification information (i.e., the first user identification information) so that one user client corresponds to one signature information. In this way, multiple users are prevented from using the same signature information to access data for which they have no permission, thereby preventing data leakage. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the present application and, together with the description, serve to explain the principles of the present application.
[0029] FIG1 is a schematic diagram of the structure of a data access system provided in an embodiment of the present application;
[0030] FIG2 is a flow chart of a data access method corresponding to a server provided in an embodiment of the present application;
[0031] FIG3 is a schematic diagram of a process for obtaining a target list by a server according to an embodiment of the present application;
[0032] FIG4 is a flow chart of a data access method corresponding to a client provided in an embodiment of the present application;
[0033] FIG5 is a flow chart of a data access method corresponding to a data access system provided in an embodiment of the present application;
[0034] FIG6 is a schematic diagram of a process for obtaining a target list by a data access system according to an embodiment of the present application;
[0035] FIG7 is a flow chart of another data access method corresponding to a data access system provided in an embodiment of the present application;
[0036] FIG8 is a schematic structural diagram of an electronic device provided in an embodiment of the present application.
[0037] The above drawings illustrate specific embodiments of the present application, which will be described in more detail below. These drawings and the textual description are not intended to limit the scope of the present application in any way, but rather to illustrate the concepts of the present application to those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION
[0038] Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. In the following description, when referring to the drawings, identical numerals in different figures represent identical or similar elements, unless otherwise indicated. The embodiments described in the following exemplary embodiments are not intended to represent all embodiments consistent with the present application. Rather, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.
[0039] As mentioned above, current access control for data systems is based on user access rights to prevent malicious intrusions from significantly impacting system network security. For example, after a user registers and logs in to a data system, the corresponding user client will obtain a unified access token for that user client to access the data system. Subsequently, the user client can access all resources and data in the data system based on this access token. However, this approach cannot achieve fine-grained control over data access, posing a data security risk. Furthermore, if permission verification is performed based on the user token when reading a single piece of data, access efficiency will be affected.
[0040] Based on this, the implementation of the present application provides a data access system and a data access method, which can be controlled based on access to data (i.e., resources). Each data will be assigned a data ID (i.e., resource ID), and a signature corresponding to the data can be generated based on the data ID. When a user client accesses the server system, a list of data that the user client can access (i.e., a target list) will be returned to the user client. The data list contains the data ID and the corresponding signature, and the data ID and the signature form a signed ID. When the user client subsequently accesses a single piece of data, it only needs to provide the signed ID, and the access permission is verified through the signature to avoid repeated verification of user identification information. This method can control access to each resource, improve data security, and optimize the access efficiency of a single piece of data.
[0041] In the implementation of the present application, referring to FIG1 , the data access system provided by the implementation of the present application includes a client 100 (ie, the aforementioned user client) and a server 200 .
[0042] Among them, the client 100 is used to send a data access request for the first data to the server 200, and the data access request includes the first authentication information corresponding to the first data. The first authentication information is sent to the client 100 by the server 200 in response to the authentication information acquisition request sent by the client 100 before the data access request, and the first authentication information is generated by the server 200 by signing the first identification information corresponding to the first data based on the first signature information corresponding to the first data.
[0043] The server 200 is used to receive a data access request, extract the first identification information and the first signature information corresponding to the first data from the first authentication information included in the data access request; generate the second signature information based on the first identification information; when the second signature information matches the first signature information, determine that the client 100 has the access right to access the first data, and allow the client 100 to access the first data; when the second signature information does not match the first signature information, determine that the client 100 does not have the access right to access the first data, and deny the client 100 access to the first data.
[0044] In the data access system provided by the implementation method of the present application, the server 200 sends the first authentication information to the client 100 before the client 100 issues a data access request for the data. Subsequently, the client 100 sends a data access request for the first data to the server 200. The server 200 obtains the first identification information and the first signature information in the first authentication information according to the data access request, and generates the second signature information according to the first identification information. If the second signature information matches the first signature information, the server 200 determines that the client 100 has the authority to access the first data, and the server 200 allows the client 100 to access the first data. If the first signature information and the second signature information do not match. The server 200 determines that the client 100 does not have the authority to access the first data, and the server 200 denies the client 100 access to the first data. In this way, by setting authentication information for each data, the client 100 sends an access request carrying the authentication information when accessing the data. After the signature information in the authentication information is verified, the client 100 is allowed to access the data. This not only realizes the control of access rights to the data, but also eliminates the need for repeated verification of user identification information, thereby improving the security of data access and optimizing data access efficiency.
[0045] In the implementation of this application, the client can be a front-end interface of an electronic device, or a first electronic device. The server can be a back-end system of an electronic device, or a second electronic device or a cloud server.
[0046] Next, referring to FIG2 , the implementation of the present application provides a data access method, which is applied to a server 200 and includes the following steps.
[0047] S110, receiving a data access request for the first data sent by the client 100, the data access request including first authentication information corresponding to the first data, the first authentication information is sent by the server 200 to the client 100 in response to the authentication information acquisition request sent by the client 100 before the data access request, and the first authentication information is generated by the server 200 by signing the first identification information corresponding to the first data based on the first signature information corresponding to the first data.
[0048] S120: Extract first identification information and first signature information corresponding to the first data from the first authentication information included in the data access request.
[0049] S130: Generate second signature information according to the first identification information.
[0050] S140 , when the second signature information matches the first signature information, it is determined that the client 100 has the authority to access the first data, and the client 100 is allowed to access the first data.
[0051] S150 , when the second signature information does not match the first signature information, determining that the client 100 does not have the authority to access the first data, and denying the client 100 access to the first data.
[0052] The data access method provided by the implementation of this application is that, upon receiving a data access request sent by the client 100, the server 200 obtains first identification information and first signature information based on the first authentication information included in the data access request, generates second signature information based on the first identification information, and allows the client 100 to access the first data if the second signature information matches the first signature information; otherwise, the client 100 is denied access to the first data if the second signature information does not match the first signature information. In this way, authentication verification of the client 100's access rights to any data can be achieved, preventing users without access rights from accessing the first data, which could lead to data leakage, and ensuring the security of data access.
[0053] Next, in step S110, a data access request for the first data sent by the client 100 is received, the data access request includes first authentication information corresponding to the first data, the first authentication information is sent by the server 200 to the client 100 in response to the authentication information acquisition request sent by the client 100 before the data access request, and the first authentication information is generated by the server 200 by signing the first identification information corresponding to the first data based on the first signature information corresponding to the first data. The technical content is explained.
[0054] In the implementation of the present application, when the client 100 sends a data access request for the first data, the data access request must carry the first authentication information generated based on the first identification information and the first signature information of the first data. Therefore, the server 200 needs to send the first identification information and the first signature information to the client 100 before the data access request.
[0055] In the implementation of this application, when a protected data is generated, a unique data ID is generated according to the system rules when the data enters the system. This ID is not signed. For example, the first data will generate a unique data ID.
[0056] Taking the data as insurance policy data as an example, when an insurance policy is generated, an insurance policy is generated with "policyID=111" as identification information (as an example of the first identification information).
[0057] In the implementation of the present application, the system rules for generating identification information may specifically be numbering according to the order of the data, or numbering according to the characteristics of the data.
[0058] In the implementation of this application, the authentication information acquisition request includes the second identification information of the client 100. Referring to FIG3 , sending the first authentication information to the client in response to the authentication information acquisition request sent by the client before the data access request includes the following steps.
[0059] S111, in response to the authentication information acquisition request, determine a target list based on the second identification information included in the authentication information acquisition request, the target list includes identification information of target data to which the client 100 has access rights and corresponding authentication information, the target data includes first data, the identification information includes first identification information, and the authentication information includes first authentication information.
[0060] Exemplarily, when the server 200 receives the authentication information acquisition request sent by the client 100 , the server 200 acquires the user identification information (as an example of the second identification information) of the user using the client 100 in the authentication information acquisition request.
[0061] In the implementation of the present application, the second identification information may also be device information such as the device number of the client 100, network information such as the network status and network type of the communication connection between the client 100 and the server 200, etc.
[0062] Therefore, in the implementation method of the present application, after the server system (i.e., the server 200) receives the user's query list request (as an example of a request to obtain authentication information), it first performs complex layer-by-layer inspection and filtering based on the user identification information, the device information of the client 100, the network information, etc., and finally obtains an abbreviated information list of the insurance policies that the user is authorized to view (as an example of a target list). When generating the abbreviated information list, it will generate signature information based on the unique data ID of each insurance policy and the signature generation algorithm provided by the insurance policy data management service, and generate a signed ID (as an example of authentication information) based on the signature information and the original data ID (i.e., the data ID) and return it to the client 100.
[0063] Exemplarily, the resource owner (i.e., the data management service) will develop a signature generation algorithm that receives the data ID as an input parameter and outputs a signature. That is, in the implementation of this application, the signature information is generated based on the identification information. For example, the first signature information is generated based on the first identification information.
[0064] In the implementation of the present application, using a signature generation algorithm to sign data is to encrypt the data based on a secret key to generate encrypted data.
[0065] Furthermore, the first identification information corresponding to the first data is signed according to the first signature information corresponding to the first data to generate the first authentication information.
[0066] In the implementation of this application, the first identification information corresponding to the first data is signed based on the first signature information corresponding to the first data. Specifically, the first signature information and the first identification information may be combined (as an example of signing) to generate the first authentication information. Of course, the first identification information may also be encrypted based on the first signature information (as another example of signing) to generate the first authentication information.
[0067] In the implementation of the present application, through layers of permission filtering, the server 200 learns that the client 100 is allowed to view two insurance policy data with policyIDs 111 and 222 (as examples of target data), and obtains the signature corresponding to each policyID through the above-mentioned signature generation algorithm, splices the signature behind the identification information, and returns it to the client 100. The client 100 obtains the authentication information of the two insurance policies with policyID = '111, aaa' and policyID = '222, bbb'.
[0068] For example, taking the first identification information as policyID=111, the first signature information generated based on the signature generation algorithm is f(111)='aaa'. Furthermore, the first authentication information generated based on 111 and f(111)='aaa' is policyID='111,aaa'.
[0069] Furthermore, a target list is determined based on the second identification information included in the authentication information acquisition request, the target list includes authentication information of target data to which the client 100 has access rights, the target data includes first data, the identification information includes first identification information, and the authentication information includes first authentication information.
[0070] For example, taking the user identification information of the first user corresponding to the client 100 as the second identification information, in the implementation method of the present application, the first user is authenticated based on the user identification information to obtain an authentication result. When the authentication result is that the authentication is passed, the data to which the first user has access rights (as an example of target data) is determined, and a target list is generated based on the identification information and signature information of the target data.
[0071] In the implementation of this application, any information such as user identification information, client device information, network information, etc. can be authenticated, or authentication can be performed one by one based on user identification information, client device information, network information, etc. to obtain the corresponding target data.
[0072] That is, in the implementation method of the present application, when the client 100 sends a request to obtain authentication information, the first user corresponding to the client 100 is first authenticated and authenticated, so as to determine the target data to which the first user has access rights after authenticating that the first user has access rights to the server system, so as to generate a target list.
[0073] The target list includes the data ID (as an example of identification information of the target data) to which the first user corresponding to the client 100 has access rights and the corresponding signed ID (as an example of authentication information of the target data).
[0074] Among them, if the target data includes the first data, the user can initiate an access request for the first data (as an example of a data access request), and the authentication information included in the access request includes the data ID of the first data (as an example of the first identification information) and the signature corresponding to the first data (as an example of the first signature information).
[0075] S112 , sending the target list to the client 100 .
[0076] Exemplarily, after determining the target data to which the client 100 has access rights according to the identification information of the client 100 , the server 200 generates a target list and sends the target list to the client 100 .
[0077] In the implementation of the present application, if the second identification information is the device number of the client 100 and other information, then the device number and other information are used to verify whether the client 100 has the authority to access the server 200 system. If it has the authority, a target list to which the client 100 has access rights is generated based on the device number and other information.
[0078] If the second identification information is network information, then the client 100 is verified to have the authority to access the server system based on the network information. If it has the authority, then a target list to which the client 100 has access rights is generated based on the network information.
[0079] In the implementation of this application, steps S111 and S112 are prerequisite steps for step S110.
[0080] Next, the technical content of extracting the first identification information and the first signature information corresponding to the first data from the first authentication information included in the data access request in step S120 is described.
[0081] In the implementation of this application, after the client 100 receives the target list, if it needs to view the specific and complete information of a certain insurance policy in the target list later, the user only needs to obtain the authentication information of the data with the correct signature information and identification information to issue an access request to the server 200.
[0082] For example, when a user accesses the detailed information of the two insurance policies mentioned above, he needs to use policyID = '111, aaa' or policyID = '222, bbb' respectively.
[0083] In the implementation of this application, after receiving the data access request for the first data, the server 200 extracts the data ID and signature information from the first authentication information. For example, the first data in the first authentication information is taken as the data ID, and the second data is taken as the signature information.
[0084] For example, after the server 200 determines that the client 100 has access rights to the data, the title, introduction, brief description and other information of the data will be displayed on the client interface. When the user clicks on the data, the client 100 will automatically send the authentication information to the server 200 so that the server 200 can verify the access rights of the client 100.
[0085] Next, the technical content of generating the second signature information according to the first identification information in step S130 is described.
[0086] Exemplarily, after the server 200 extracts the first identification information and the first signature information, the second signature information is generated according to the first identification information using the signature generation algorithm used to generate the first signature information.
[0087] For example, after the server 200 receives an access request including policyID='111,aaa', the server 200 uses a signature generation algorithm to sign '111' therein to obtain second signature information.
[0088] In the implementation of this application, the signature generation algorithm can specifically be any one of the signature generation algorithms such as MD5, SHSA1, SHA256, HMAC-SHA1, HMAC-SHA256, RSA, MD5WithRSA, SHA1WithRSA, etc.
[0089] For example, a signature generation algorithm is used to encrypt the identification information of the data.
[0090] It should be noted that the signature generation algorithm for generating the first signature information and the signature generation algorithm for generating the second signature information must be consistent.
[0091] In the implementation of this application, the first signature information is generated based on the first identification information, and the second signature information is also generated based on the first identification information. In this way, the consistency of the second signature information and the first signature information can be verified. Next, the technical content of determining that the client 100 has permission to access the first data and allowing the client 100 to access the first data in step S140 when the second signature information matches the first signature information is explained.
[0092] In the implementation of this application, the second signature information is matched and verified against the first signature information. If the second signature information matches the first signature information, it indicates that the first identification information and the corresponding first signature information of the first data sent by the client 100 are the same as the first identification information and the first signature information corresponding to the first data previously sent by the server 200. Therefore, the first authentication information has not been tampered with, the client 100 has permission to access the first data, and the client 100 is allowed to access the first data.
[0093] In the implementation of the present application, when the client 100 issues the first access, the server 200 returns the target data in the target list to the client 100. The target data in the target list is the data that the client 100 has access rights to, and the authentication information corresponding to the target data generated based on the identification information and the corresponding signature information is the correct authentication information for the client 100 to access the data. If the client 100 initiates access to a data object (that is, data), when the authentication information is used to access the data object, the identification information in the authentication information needs to be re-signed and verified to prevent the user corresponding to the client 100 from privately changing the authentication information in the access request, such as privately changing the correspondence between the identification information and the signature information to obtain data that the user does not have access rights to. Compared with the method of only determining whether the signature is a previously generated signature, the accuracy of the permission authentication can be improved.
[0094] Next, the technical content of determining that the client 100 does not have the authority to access the first data and denying the client 100 access to the first data in step S150 when the second signature information does not match the first signature information is described.
[0095] In the implementation of this application, the second signature information is matched and verified against the first signature information. If the second signature information does not match the first signature information, it indicates that the first identification information and the corresponding first signature information of the first data sent by the client 100 are not the first identification information and the first signature information corresponding to the first data previously sent by the server 200. Therefore, the first authentication information has been tampered with, the client 100 does not have permission to access the first data, and the client 100 is denied access to the first data.
[0096] For example, after the second signature information is generated, it is compared with 'aaa' in the request. If they match, the client 100 is allowed to access the detailed policy information of the first data. If they do not match, the client 100 is denied access to the detailed policy information of the first data.
[0097] In another implementation of the present application, in step S110 , if the data access request does not include the first authentication information, the server 200 denies the client 100 access to the first data.
[0098] In another implementation of the present application, in step S120, if the server 200 does not obtain the first identification information and / or the first signature information according to the first authentication information included in the data access request, the server 200 denies the client 100 access to the first data.
[0099] For example, if an access request is made using authentication information without attached signature information or with attached signature information that has different verification, the access request will be rejected by the server 200 .
[0100] For example, if policyID='111', policyID='111,ccc', or policyID='333,aaa' is used, the access request will be denied.
[0101] In another implementation of the present application, the first signature information may also be generated in the following manner.
[0102] Exemplarily, the server 200 determines the user (as an example of the first user) corresponding to the client 100 that can access the first data (that is, the first user is a user with access rights to the first data), and generates signature information using a signature generation algorithm based on the user's user identification information (such as user code or user account (such as UserId) and the data ID of the first data. In this way, even for the same data, the signature information of different users is different, preventing a second user who does not have access rights from using the first user's authentication information to access the first data after knowing the first user's authentication information for accessing the first data, thereby ensuring the security of user access to data.
[0103] For example, when receiving the first data, the server 200 determines the user identification information of the user who can access the first data, and generates the first signature information corresponding to each user according to the first identification information of the first data and the user identification information.
[0104] For another example, when the server 200 receives the user's first access request, it obtains the user's user identification information and determines the data list that the user can access. For each piece of data in the data list, the server generates the signature information of the user corresponding to each piece of data based on the data identification information and user identification information of the data.
[0105] That is, user A has the authority to access policy 111, and user B also has the authority to access policy 111, but the policy 111 and signature information generated by user A are not the same as the signature information of policy 111 generated by user B. If user C uses the signature information of user A or user B to access policy 111, user C's access request will be rejected due to incorrect signature information.
[0106] In the implementation of this application, if the first signature information is generated based on the user identification information and the first identification information of the first user, then in step S130, when generating the second signature information, it is also necessary to generate the second signature information based on the first identification information and the first user identification information.
[0107] For example, the server 200 uses a signature generation algorithm to generate the signature information of the first data as f(111)='aaaa'. In this way, when generating the signature information, it can be combined with the user identification information of the user who will be able to perform query or access operations in the future to generate a unique signature information that binds the user and the data ID. In addition, based on 111 and f(111)='aaaa', the first authentication information is generated as policyID='111,aaaa'. In this way, after the exclusive signature information of the user corresponding to each data ID is generated by the signature generation algorithm, the signature information is spliced after the data ID and returned to the client 100. The client 100 then issues an access request based on the authentication information.
[0108] After the client 100 receives the target list, if it needs to view the specific and complete information of a policy in the target list, the user only needs to obtain the authentication information of the data with the correct signature information and identification information to issue an access request to the server 200.
[0109] For example, when a user accesses the detailed information of the two insurance policies mentioned above, he needs to use policyID = '111, aaaa' or policyID = '222, bbbb' respectively.
[0110] Exemplarily, after the first identification information and the first signature information are extracted, the second signature information is generated according to the first identification information and the user identification information using the signature generation algorithm used to generate the first signature information.
[0111] For example, after receiving an access request containing policyID='111,aaaa', server 200 uses a signature generation algorithm to sign '111' and the user identification information to obtain a second signature. The second signature is then matched and verified against the first signature to determine client 100's access permission to the first data based on the matching result.
[0112] The data access method provided by the implementation of the present application is that when the client 100 sends an access request (that is, a request to obtain authentication information), the server 200 feeds back a target list to the client 100, where the target list includes the authentication information of the target data to which the client 100 has access rights. When the client 100 sends an access request for certain data (that is, a data access request), the server 200 determines the identification information and signature information corresponding to the data based on the authentication information included in the access request, and generates new signature information based on the identification information. If the extracted signature information matches the generated signature information, it means that the client 100 has the right to access the data, and the client 100 is allowed to access the data. If the extracted signature information does not match the generated signature information, it means that the client 100 does not have the right to access the data, and the client 100 is denied access to the data.
[0113] Furthermore, in the implementation of the present application, signature information can also be generated based on user identification information / client device information / network information, so that one user / client corresponds to one signature. In this way, even if different users have the right to access the same data, since the signature information of the data obtained by each user is different, multiple users can be prevented from using the same signature to access data for which they have no permission, resulting in data leakage.
[0114] The data access system provided by the implementation method of this application performs data access control based on the signature information corresponding to the data ID. It generates a unique data ID for each protected data and uses a signature generation algorithm to take the data ID as input and output a signature. When a user requests access to a data list (i.e., issues an authentication information acquisition request), the server returns a data list (i.e., a target list) and includes the original data ID and the signed ID (i.e., authentication information) in each data. When the user subsequently requests access to a single piece of data, the signed ID is provided. After receiving the access request, the server extracts the original data ID and signature information (i.e., the first signature information) from the signed ID, and uses the original data ID and the signature generation algorithm to regenerate the signature information (i.e., the second signature information) and match it with the extracted signature information. Only when the signature information matches will the user's access request to the data be approved. In this way, the access rights to a single piece of data can be controlled to ensure the security of data access.
[0115] In another implementation of the present application, the data access method provided by the implementation of the present application can also be applied to the client 100. The client 100 sends a data access request for the first data to the server 200, so that the server 200 extracts the first identification information and the first signature information corresponding to the first data from the first authentication information included in the data access request, generates the second signature information based on the first identification information, and when the second signature information matches the first signature information, determines that the client 100 has the authority to access the first data, and allows the client 100 to access the first data. When the second signature information does not match the first signature information, determines that the client 100 does not have the authority to access the first data, and denies the client 100 access to the first data. The first authentication information is sent to the client 100 by the server 200 in response to the authentication information acquisition request sent by the client 100 before the data access request, and the first authentication information is generated by the server 200 by signing the first identification information corresponding to the first data based on the first signature information corresponding to the first data.
[0116] In the implementation of the present application, the client 100 issues a request to access the first data (i.e., a data access request), and the data access request includes first authentication information. The server 200 determines the first identification information and the first signature information based on the first authentication information included in the data access request, and generates the second signature information based on the first identification information. If the second signature information matches the first signature information, the client 100 accesses the first data. If the second signature information does not match the first signature information, the client 100 does not access the first data.
[0117] For example, referring to FIG4 , the data access method provided by the implementation of the present application, the client 100 specifically performs the following steps.
[0118] S210 , the client 100 sends an authentication information acquisition request to the server 200 , where the authentication information acquisition request includes the second identification information of the client 100 .
[0119] S220, the client 100 receives a target list, wherein the target list is determined based on the second identification information included in the authentication information acquisition request by the server 200, the target list includes authentication information of target data to which the client 100 has access rights, the target data includes first data, the identification information includes first identification information, and the authentication information includes first authentication information.
[0120] S230 , the client 100 sends a data access request for the first data, so that the server 200 determines whether the client 100 has the authority to access the first data.
[0121] In the implementation of the present application, the client 100 sends a request for accessing a target list (i.e., an authentication information acquisition request), and the server 200 determines the target data that the client 100 has access rights to based on the identification information of the client 100 to generate a target list. The server 200 sends the target list to the client 100, and the client 100 receives the target list. Subsequently, the client 100 sends a data access request for the first data, so that the server 200 determines the first identification information and the first signature information based on the first authentication information included in the data access request. After generating the second signature information based on the first identification information, if the second signature information matches the first signature information, the client 100 accesses the first data; if the second signature information does not match the first signature information, the client 100 does not access the first data.
[0122] In the implementation of the present application, steps S210 to S230 may refer to the technical solutions of the aforementioned steps S110 to S150 and the aforementioned steps S111 to S112.
[0123] In another implementation of the present application, referring to FIG5 , the data access method provided in the implementation of the present application can also be applied to a data access system. The data access method includes the following steps.
[0124] S310, the client 100 sends a data access request for the first data to the server 200, the data access request includes first authentication information corresponding to the first data, the first authentication information is sent to the client 100 by the server 200 in response to the authentication information acquisition request sent by the client 100 before the data access request, and the first authentication information is generated by the server 200 by signing the first identification information corresponding to the first data based on the first signature information corresponding to the first data.
[0125] S320: The server 200 receives the data access request and extracts the first identification information and the first signature information corresponding to the first data from the first authentication information included in the data access request.
[0126] S330, the server 200 generates second signature information according to the first identification information.
[0127] S340 , when the second signature information matches the first signature information, the server 200 determines that the client 100 has the authority to access the first data, and allows the client 100 to access the first data.
[0128] S350 , when the second signature information does not match the first signature information, the server 200 determines that the client 100 does not have the authority to access the first data, and denies the client 100 access to the first data.
[0129] In the implementation of the present application, the client 100 sends a request to the server 200 to access the first data (i.e., a data access request). The server 200 determines the first identification information and the first signature information based on the first authentication information included in the data access request. After generating the second signature information based on the first identification information, if the second signature information matches the first signature information, the client 100 is allowed to access the first data. If the second signature information does not match the first signature information, the client 100 is denied access to the first data.
[0130] In the implementation of this application, steps S310 to S350 may refer to the technical solutions of the aforementioned steps S110 to S150.
[0131] In the implementation of the present application, referring to FIG6 , the target list of target data consisting of the first identification information and the first signature information is obtained in the following manner.
[0132] S311 , the client 100 sends an authentication information acquisition request to the client 100 , where the authentication information acquisition request includes the second identification information of the client 100 .
[0133] S312, the server 200 determines a target list based on the second identification information included in the authentication information acquisition request, the target list includes authentication information of target data to which the client 100 has access rights, the target data includes first data, the identification information includes first identification information, and the authentication information includes first authentication information.
[0134] S313 , the server 200 sends the target list to the client 100 .
[0135] In the implementation of the present application, the client 100 sends a request for accessing a target list (i.e., a request for obtaining authentication information) to the server 200. The server 200 determines the target data to which the client 100 has access rights based on the identification information of the client 100 to generate a target list. The server 200 sends the target list to the client 100, and the client 100 receives the target list so that it can subsequently access the data in the target list based on the authentication information in the target list.
[0136] In the implementation of this application, steps S311 to S313 can refer to the technical solutions of the aforementioned steps S111 to S112.
[0137] In the implementation of the present application, as shown in FIG7 , when the server 200 receives an access request to the system from the client 100 (i.e., an authentication information acquisition request), it first generates a target list of target data to which the client has access rights based on the identification information of the client 100, and feeds the target list back to the client 100 (see steps S311 to S313). Subsequently, when the client 100 issues an access request to a certain data in the target list (i.e., a data access request), the server obtains the identification information and signature information of the data based on the authentication information included in the data access request, and verifies the signature information to determine the client 100's access rights to the data (see steps S310 to S350).
[0138] S311 , the client 100 sends an authentication information acquisition request to the client 100 , where the authentication information acquisition request includes the second identification information of the client 100 .
[0139] S312, the server 200 determines a target list based on the second identification information included in the authentication information acquisition request, the target list includes authentication information of target data to which the client 100 has access rights, the target data includes first data, the identification information includes first identification information, and the authentication information includes first authentication information.
[0140] S313, the server 200 sends the target list to the client 100. S310, the client 100 sends a data access request for the first data to the server 200, the data access request includes first authentication information, and the first authentication information is generated based on the first signature information and the first identification information of the first data.
[0141] S310, the client 100 sends a data access request for the first data to the server 200, the data access request includes first authentication information corresponding to the first data, the first authentication information is sent to the client 100 by the server 200 in response to the authentication information acquisition request sent by the client 100 before the data access request, and the first authentication information is generated by the server 200 by signing the first identification information corresponding to the first data based on the first signature information corresponding to the first data.
[0142] S320: The server 200 receives the data access request and extracts the first identification information and the first signature information corresponding to the first data from the first authentication information included in the data access request.
[0143] S330, the server 200 generates second signature information according to the first identification information.
[0144] S340 , when the second signature information matches the first signature information, the server 200 determines that the client 100 has the authority to access the first data, and allows the client 100 to access the first data.
[0145] S350 , when the second signature information does not match the first signature information, the server 200 determines that the client 100 does not have the authority to access the first data, and denies the client 100 access to the first data.
[0146] The data access method provided by the implementation of this application can finely control access to each data resource, providing efficient access efficiency for legitimate users while ensuring data security. Moreover, the granularity of data access control reaches the resource level. In addition, in the implementation of this application, by using the signed ID (i.e., authentication information), repeated permission verification is avoided for a single piece of data, thereby optimizing access efficiency.
[0147] For example, when a user queries for the first time without a data ID, there will be API (Application Programming Interface) permissions, institutional permissions, and other multiple dimensions of permission control. It is necessary to go through layers of filtering in various subsystems on the server to obtain a series of data IDs that the user has access to all selected target data, and sign them when returning them to the user, and return the data ID and signature information to the user together. When subsequent users use the signed ID to access data, they only need to use a simple verification using the signature generation algorithm. If the signature matches, it can be determined that the data ID was obtained by the previous user through complex permission verification, rather than filled in privately, because the signed ID filled in privately cannot obtain the correct signature information. In this way, when accessing data, there is no need to go through multiple layers of verification, which optimizes the access efficiency of a single piece of data.
[0148] The data access method provided by the implementation of this application is not only used in the insurance field to control access to policy data, but can also be applied to any other field, such as any field that requires data security protection, to achieve access control to data through the data access method provided by the implementation of this application.
[0149] The data access method provided by the implementation of the present application can also be applied to an electronic device, which includes a data access system, or includes a server 200, or includes a client 100. The data access method is implemented by the electronic device based on a processor to implement the data access method executed by the server 200 or the client 100 or the data access system.
[0150] Please refer to Figure 8, which is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. As shown in Figure 8, the electronic device may include: a transceiver 121, a processor 122, and a memory 123.
[0151] The processor 122 executes the computer-executable instructions stored in the memory, so that the processor 122 implements the solutions in the above embodiments. The processor 122 can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, or discrete hardware components.
[0152] The memory 123 is connected to the processor 122 via a system bus and communicates with the processor 122. The memory 123 is used to store computer program instructions.
[0153] By way of example and not limitation, the memory 123 may include a hard disk drive (HDD), a floppy disk drive, flash memory, an optical disk, a magneto-optical disk, a magnetic tape, or a universal serial bus (USB) drive, or a combination of two or more of these. Where appropriate, the memory 123 may include removable or non-removable (or fixed) media. Where appropriate, the memory 123 may be inside or outside the integrated gateway device. In a specific embodiment, the memory 123 is a non-volatile solid-state memory. In a specific embodiment, the memory 123 includes a read-only memory (ROM). Where appropriate, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM), or flash memory, or a combination of two or more of these.
[0154] The transceiver 121 may be used to obtain tasks to be executed and configuration information of the tasks to be executed.
[0155] The system bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, among others. The system bus can be divided into an address bus, a data bus, a control bus, and so on. For ease of illustration, the diagram uses only one thick line, but this does not imply that there is only one bus or only one type of bus. Transceivers are used to enable communication between the database access device and other computers (e.g., clients, read-write libraries, and read-only libraries). Memory may include random access memory (RAM) and non-volatile memory.
[0156] The electronic device provided in the embodiment of the present application may be the terminal device of the above embodiment.
[0157] In other implementations of the present application, the aforementioned load unit may also be a load balancing device, the front-end unit may be an external front-end device, and the application service unit may be a data access application device. Therefore, the data access system in the implementation of the present application may also be composed of multiple electronic devices, each of which works in conjunction to implement the above-mentioned data access method.
[0158] An embodiment of the present application also provides a chip for executing instructions, which is used to execute the technical solution of the data access method in the above embodiment.
[0159] An embodiment of the present application further provides a computer-readable storage medium, in which computer instructions are stored. When the computer instructions are executed on a computer, the computer executes the technical solution of the data access method of the above embodiment.
[0160] In some possible implementations, various aspects of the method provided in the present application may also be implemented in the form of a program product, which includes program code. When the program product is run on a computer device, the program code is used to enable the computer device to execute the steps of the method according to the various exemplary implementations of the present application described above in this specification. For example, the computer device may execute the data access method described in the embodiments of the present application.
[0161] The program product may employ any combination of one or more readable media. The readable medium may be a readable signal medium or a readable storage medium. The readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or component, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0162] The implementation method of the present application also provides a computer program product, which includes a computer program stored in a computer-readable storage medium. At least one processor can read the computer program from the computer-readable storage medium, and when at least one processor executes the computer program, it can implement the technical solution of the data access method in the above embodiment.
[0163] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices, and computer program products according to the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable information processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable information processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0164] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable information processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0165] These computer program instructions can also be loaded onto a computer or other programmable information processing device so that a series of operating steps are executed on the computer or other programmable device to produce computer-implemented processing, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0166] Those skilled in the art will readily appreciate other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present invention that follow the general principles of this application and include common knowledge or customary techniques in the art that are not disclosed herein.
[0167] It will be understood that the present application is not limited to the exact construction that has been described above and shown in the drawings, and that various modifications and changes may be made without departing from the scope thereof.
Claims
1. A data access method, characterized in that: Applied to the server, the method includes: receiving a data access request for first data sent by a client, the data access request including first authentication information corresponding to the first data, the first authentication information being sent by the server to the client in response to an authentication information acquisition request sent by the client before the data access request, and the first authentication information being generated by the server by signing first identification information corresponding to the first data according to first signature information corresponding to the first data; extracting the first identification information and the first signature information corresponding to the first data from the first authentication information included in the data access request; Generate second signature information according to the first identification information; When the second signature information matches the first signature information, determining that the client has permission to access the first data, and allowing the client to access the first data; When the second signature information does not match the first signature information, it is determined that the client does not have the authority to access the first data, and the client is denied access to the first data.
2. The data access method according to claim 1, characterized in that: The authentication information acquisition request includes the second identification information of the client, and sending the first authentication information to the client in response to the authentication information acquisition request sent by the client before the data access request, comprises: In response to the authentication information acquisition request, determining a target list according to the second identification information included in the authentication information acquisition request, the target list including identification information of target data for which the client has access rights and corresponding authentication information, the target data including the first data, the identification information including the first identification information, and the authentication information including the first authentication information; The target list is sent to the client.
3. The data access method according to claim 2, characterized in that: The second identification information is user identification information of a first user corresponding to the client, and determining the target list according to the second identification information included in the authentication information acquisition request includes: Performing authentication processing on the first user according to the user identification information to obtain an authentication result; When the authentication result is that the authentication is passed, the target data to which the first user has access rights is determined, and the target list is generated according to the identification information and signature information of the target data.
4. The data access method according to any one of claims 1 to 3, characterized in that: The first signature information is generated according to the first identification information; The second signature information is generated according to the first identification information.
5. The data access method according to any one of claims 1 to 3, characterized in that: The method further comprises: Determine first user identification information of a first user, where the first user is a user having access authority to the first data; The first signature information is generated according to the first identification information and the first user identification information; The second signature information is generated according to the first identification information and the first user identification information.
6. The data access method according to any one of claims 1 to 5, characterized in that: The method further comprises: If the data access request does not include the first authentication information, it is determined that the client does not have the authority to access the first data, and the client is denied access to the first data.
7. A data access method, characterized in that: Applied to a client, the method comprises: Send a data access request for the first data to the server, so that the server receives the data included in the data access request from The first identification information and the first signature information corresponding to the first data are extracted from the first authentication information, and the second signature information is generated according to the first identification information. When the second signature information matches the first signature information, it is determined that the client has the authority to access the first data, and the client is allowed to access the first data. When the second signature information does not match the first signature information, it is determined that the client does not have the authority to access the first data, and the client is denied access to the first data. The first authentication information is sent to the client by the server in response to an authentication information acquisition request sent by the client before the data access request, and the first authentication information is generated by the server by signing the first identification information corresponding to the first data according to the first signature information corresponding to the first data.
8. A data access method, characterized in that: Applied to a data access system, the data access system includes a server and a client, and the method includes: The client sends a data access request for first data to the server, the data access request includes first authentication information corresponding to the first data, the first authentication information is sent to the client by the server in response to an authentication information acquisition request sent by the client before the data access request, and the first authentication information is generated by the server by signing first identification information corresponding to the first data according to first signature information corresponding to the first data; The server receives the data access request, and extracts the first identification information and the first signature information corresponding to the first data from the first authentication information included in the data access request; The server generates second signature information according to the first identification information; When the second signature information matches the first signature information, the server determines that the client has the authority to access the first data, and allows the client to access the first data; When the second signature information does not match the first signature information, the server determines that the client does not have the authority to access the first data and denies the client access to the first data.
9. A data access system, characterized in that: It includes client and server, among which, The client is used to send a data access request for first data to the server, the data access request includes first authentication information corresponding to the first data, the first authentication information is sent to the client by the server in response to an authentication information acquisition request sent by the client before the data access request, and the first authentication information is generated by the server by signing first identification information corresponding to the first data according to first signature information corresponding to the first data; The server is used to receive the data access request, extract the first identification information and the first signature information corresponding to the first data from the first authentication information included in the data access request; generate second signature information according to the first identification information; if the second signature information matches the first signature information, determine that the client has the authority to access the first data, and allow the client to access the first data; if the second signature information does not match the first signature information, determine that the client does not have the authority to access the first data, and deny the client access to the first data.
10. An electronic device, characterized in that: include: A processor, and a memory communicatively connected to the processor; The memory stores computer-executable instructions; The processor executes the computer-executable instructions stored in the memory to implement the data access method according to any one of claims 1 to 6, or to implement the data access method according to claim 7.
11. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, which, when executed by a processor, are used to implement the data access method according to any one of claims 1 to 6, or to implement the data access method according to claim 7.
12. A computer program product, characterized in that It comprises a computer program, which, when executed by a processor, implements the data access method according to any one of claims 1 to 6, or implements the data access method according to claim 7.
Citation Information
Patent Citations
Multi-platform interconnection cloud connector system
CN115987547A
Data access method and system, electronic equipment, storage medium and program product
CN117499122A
Token-based fine granularity access control system and method for application server
CN1633084A
Access method to an on line service by means of access tokens and secure elements restricting the use of these access tokens to their legitimate owner
WO2017042400A1