An authentication method and device for an open platform
By verifying the first token identification and signature in the open platform, and verifying the authorization signature in the authentication platform, and generating the second token information, the complex access process of the open platform and the authorization code update problems are solved, and an efficient and secure authentication method is achieved.
Patent Information
- Application Number
- CN202010473036.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-05-29
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2040-05-29
AI Technical Summary
The access process of the open platform is complicated, and it may encounter illegal requests that are not updated in time or use old token information requests, which requires an efficient and secure authentication method.
Receive business access requests through the open platform, verify the first token identification and signature, determine its corresponding token, and verify the authorization signature in the authentication platform, generate and send the second token information to simplify the token authorization process and improve security.
Simplifies the token authorization process, avoids authorization code update issues, improves security, reduces pressure on the authentication platform, and prevents illegal requests caused by using old tokens.
Smart Images

Figure CN111639327B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of financial technology (Fintech), and in particular to an authentication method and device for an open platform. Background Art
[0002] With the development of computer technology, more and more technologies (such as distributed architecture, cloud computing or big data) are applied in the financial field. The traditional financial industry is gradually transforming into financial technology, and big data technology is no exception. However, due to the security and real-time requirements of the financial and payment industries, higher requirements are also put forward for big data technology.
[0003] Currently, many large Internet companies provide open platforms, such as Sina Weibo, Tencent WeChat public account open platform, Baidu AI open platform, Taobao open platform of Alibaba, etc. These open platforms have greatly facilitated the access of developers. While providing a complete access system, they also provide services such as computing and storage to developers well, thus bringing infinite value to developers.
[0004] Through analysis, many companies provide open platforms based on the OAuth2.0 protocol, which provides a secure, open and simple standard for the authorization of user resources. Based on the architecture solution of this protocol, first, the service provider will assign a business requester identifier and a business requester secret key to the business requester (Site A). The business requester identifier is used to uniquely identify the identity of the business requester. The main interactions between the business requester and the open platform (Site B) include the following steps:
[0005] Step 1, A uses the business requester identifier and the business requester secret key to access the open platform and requests an authorization code; the open platform Site B receives A's request and verifies the correctness of A's identity.
[0006] Step 2, after the authentication passes, B will issue an authorization code token to the business requester A, and this token has a certain validity period.
[0007] Step 3, after receiving this token, A uses it to obtain an access token for relevant services from the open platform B again. The open platform B will judge the validity of the token and determine whether the business requester has the permission for the relevant service. If it passes, it will issue an access token to the business requester.
[0008] Step 4, after obtaining the access token, A can use this access token to access relevant services.
[0009] As can be seen from the above process, the current access process of the open platform is relatively complex; it may also encounter the situation where the authorization code is not updated in a timely manner, or the old token information is used to request the open platform, resulting in illegal requests. Therefore, there is an urgent need for an efficient and secure authentication method. Summary of the Invention
[0010] This application provides an authentication method and device for an open platform to solve the problem of how to authenticate the open platform efficiently and securely.
[0011] In a first aspect, an embodiment of this application provides an authentication method for an open platform, including:
[0012] The open platform receives a service access request sent by a service requestor. The service access request carries first token information, and the first token information includes a first token identifier and a first token signature.
[0013] After verifying the first token identifier, the open platform determines the first token corresponding to the first token identifier in the authentication platform. The first token is the token corresponding to the first token identifier issued by the authentication platform after verifying the authorization request sent by the service requestor.
[0014] After passing the verification of the first token signature and the first token, the open platform sends the service access request to the corresponding service system.
[0015] In the above solution, it can be seen that the token authorization process can be obtained by the authentication platform based on a single authorization request, eliminating the authorization code process, streamlining the token authorization process, and avoiding the problem of untimely update of the authorization code. At the same time, by introducing the verification of service access requests in the open platform, the pressure on the authentication platform is greatly reduced. Finally, the authentication platform generates the corresponding relationship between the token identifier and the token and sends it to the service requestor, enabling the service requestor to find the corresponding token through the token identifier when making a service access request, avoiding the problem of illegal requests caused by using an old token to request the open platform. In this process, the open platform also verifies the token signature and the token, achieving the efficient and secure authentication of the open platform.
[0016] Optionally, the verification of the first token identifier includes:
[0017] The open platform generates a first verification value according to the first part and the second part of the first token identifier.
[0018] When the current time meets the effective time indicated by the second part of the first token identifier and the first verification value is consistent with the third part of the first token identifier, it is determined that the first token identifier passes the verification.
[0019] In the above solution, by extracting the first token to identify information at different positions and the effective time to verify the first token, invalid requests are avoided, the open platform is prevented from being maliciously attacked, and security is improved.
[0020] Optionally, the service access request includes a service requestor identifier, and determining the first token corresponding to the first token identifier in the authentication platform includes:
[0021] Determining a token set corresponding to the service requestor identifier according to the service requestor identifier;
[0022] Determining the first token corresponding to the first token identifier from the token set according to the first token identifier;
[0023] The open platform verifying the first token signature and the first token includes:
[0024] The open platform decrypts the first token signature according to the service requestor identifier to obtain a first hash value, and determines whether the second hash value corresponding to the first token is consistent with the first hash value.
[0025] In the above solution, the secret key assigned by the open platform to the service requestor will not be transmitted over the network, avoiding the risk of the secret key being leaked in the public network. While improving the user experience, security is also improved.
[0026] Optionally, before the open platform verifies through the first token identifier, the method further includes:
[0027] The open platform determines that the service access request is verified by the open platform; otherwise, the open platform forwards the service access request to the authentication platform; the authentication platform is used to determine whether the service access request is verified.
[0028] In the above solution, if the open platform has problems and cannot provide relevant authentication services, the open platform forwards the service access request to the authentication platform to complete the authentication service, realizing the lightweight of the authentication platform; or in order to improve the authentication efficiency and make the authentication services of the open platform or the authentication platform more balanced, the open platform forwards the service access request to the authentication platform to complete the authentication service.
[0029] In a second aspect, an authentication method for an open platform provided by an embodiment of the present application includes:
[0030] The authentication platform receives an authorization request sent by a service requestor, where the authorization request includes a service requestor identifier and an authorization signature; the authorization signature is generated according to the secret key of the service requestor;
[0031] The authentication platform verifies the authorization signature according to the service requestor identifier;
[0032] When the verification is passed and the authorization request has access rights, the authentication platform generates second token information for the authorization request and sends the second token information to the service requestor; the second token information includes a second token identifier and a second token.
[0033] In the above solution, the authentication platform verifies the authorization signature and generates the second token information for the authorization request, improving the security of the verification. At the same time, the authentication platform generates the corresponding relationship between the token identifier and the token and sends it to the service requestor, enabling the service requestor to find the corresponding token through the token identifier when making a service access request, avoiding the problem of illegal requests caused by using an old token to request the open platform, and improving the efficiency of the verification.
[0034] Optionally, after sending the second token information to the service requestor, the method further includes:
[0035] The authentication platform sends the second token information to the open platform; or
[0036] The authentication platform sends the second token information to the open platform based on a fetch request sent by the open platform; the fetch request is sent by the open platform after receiving a service access request.
[0037] In the above solution, the open platform periodically or actively fetches the second token information of the authentication platform, so that the open platform has the relevant service functions of the authentication platform.
[0038] Optionally, the method further includes:
[0039] The authentication platform receives a service access request forwarded by the open platform;
[0040] After verifying the second token identifier in the service access request, the authentication platform determines the second token corresponding to the second token identifier;
[0041] After passing the verification of the second token signature in the service access request and the second token, the authentication platform sends the service access request to the corresponding service system.
[0042] In the above solution, when the open platform is abnormal, the authentication platform performs signature verification, thus ensuring the efficiency and security of the authentication process.
[0043] In a third aspect, an embodiment of the present application provides an authentication device for an open platform, the device includes:
[0044] An obtaining module, configured to receive a service access request sent by a service requestor, where the service access request carries first token information, and the first token information includes a first token identifier and a first token signature;
[0045] A processing module, configured to determine a first token corresponding to the first token identifier in an authentication platform after verifying the first token identifier; the first token is a token corresponding to the first token identifier issued by the authentication platform after verifying an authorization request sent by the service requestor;
[0046] The processing module is further configured to send the service access request to a corresponding service system after passing the verification of the first token signature and the first token.
[0047] Optionally, the processing module is specifically configured to:
[0048] Generate a first verification value according to a first part and a second part of the first token identifier;
[0049] If the current time meets the effective time indicated by the second part of the first token identifier, and the first verification value is consistent with the third part of the first token identifier, it is determined that the first token identifier passes the verification.
[0050] Optionally, the processing module is specifically configured to:
[0051] Determine a token set corresponding to the service requestor identifier according to the service requestor identifier;
[0052] Determine a first token corresponding to the first token identifier from the token set according to the first token identifier;
[0053] Verifying the first token signature and the first token includes:
[0054] According to the service requestor identifier, decrypt the first token signature to obtain a first hash value, and determine whether the second hash value corresponding to the first token is consistent with the first hash value.
[0055] Optionally, the processing module is further configured to:
[0056] Before verifying the first token identifier, determine that the service access request is verified by the open platform; otherwise, forward the service access request to the authentication platform; the authentication platform is used to determine whether the service access request passes the verification.
[0057] In a fourth aspect, an embodiment of the present application provides an authentication device for an open platform, and the device includes:
[0058] An acquisition module, configured to receive an authorization request sent by a service requester, where the authorization request includes a service requester identifier and an authorization signature; the authorization signature is generated according to the secret key of the service requester;
[0059] A processing module, configured to verify the authorization signature according to the service requester identifier;
[0060] The processing module is further configured to generate second token information of the authorization request and send the second token information to the service requester when the verification is passed and the authorization request has access rights; the second token information includes a second token identifier and a second token.
[0061] Optionally, the processing module is further configured to:
[0062] After sending the second token information to the service requester, send the second token information to the open platform; or
[0063] Based on a fetch request sent by the open platform, send the second token information to the open platform; the fetch request is sent by the open platform after receiving a service access request.
[0064] Optionally, the processing module is further configured to:
[0065] Receive a service access request forwarded by the open platform;
[0066] After verifying the second token identifier in the service access request, determine the second token corresponding to the second token identifier;
[0067] After verifying the second token signature in the service access request against the second token, send the service access request to the corresponding service system.
[0068] Correspondingly, an embodiment of the present invention further provides a computing device, including:
[0069] A memory, configured to store program instructions;
[0070] A processor, configured to call the program instructions stored in the memory and execute the authentication method of the open platform according to the obtained program.
[0071] Correspondingly, an embodiment of the present invention further provides a computer-readable non-volatile storage medium, including computer-readable instructions, which when read and executed by a computer, cause the computer to execute the authentication method of the open platform. Description of the Drawings
[0072] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0073] Figure 1 It is the system framework of an authentication method for an open platform provided by an embodiment of the present invention;
[0074] Figure 2 It is the schematic flowchart of an authentication method for an open platform provided by an embodiment of the present invention;
[0075] Figure 3 It is the schematic flowchart of an authentication method for an open platform provided by an embodiment of the present invention;
[0076] Figure 4 It is the schematic flowchart of an authorization method for an authentication platform provided by an embodiment of the present invention;
[0077] Figure 5 It is the schematic structural diagram of an authentication device for an open platform provided by an embodiment of the present invention;
[0078] Figure 6 It is the schematic structural diagram of an authentication device for an open platform provided by an embodiment of the present invention. Specific embodiments
[0079] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the following will further describe the present invention in detail with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0080] First, some terms in this application are explained to facilitate understanding by those skilled in the art.
[0081] OAuth: OAuth is a protocol that provides a secure, open, and simple standard for the authorization of user resources. The authorization of OAuth does not allow the service requestor to access the user's account information such as username and password, that is, the service requestor can apply for and obtain the authorization of the user resources without using the user's username and password.
[0082] OPENAPI: That is, Open API, also known as the open platform. The so-called OpenAPI is a common application of service-based websites. The service providers of the websites encapsulate their website services into a series of APIs (Application Programming Interfaces) and open them for third-party developers to use.
[0083] WOPNG: Webank Openapi Platform Next Generation.
[0084] WOPNG-SDK: OPENAPI SDK of the open platform. The SDK encapsulates services related to requesting and obtaining tokens, authentication, etc.
[0085] WOPNG-AUTH: Authentication platform.
[0086] Before introducing the embodiments of the present invention, the prior art is described in combination with specific embodiments as follows to better understand the present invention.
[0087] Take the WeChat public platform as an example below:
[0088] First, the business requestor uses the requestor identification AppID and the corresponding password AppSecret assigned by the WeChat public platform to call the relevant interfaces to obtain the authorization code. Among them, the validity period of the authorization code is 2 hours.
[0089] The business requestor uses the obtained authorization code to apply to the WeChat official account for the relevant token jsapi_ticket. Among them, jsapi_ticket is used to call the WeChat JS interface, and the validity period of the token jsapi_ticket is 7200s.
[0090] After the business requestor obtains the token jsapi_ticket, it can access other services by virtue of the token.
[0091] It should be noted that in the above embodiments, the WeChat official account platform will control the request frequencies of the authorization code and the token jsapi_ticket. At the same time, the business requestor needs to cache the latest obtained authorization code and token jsapi_ticket.
[0092] Take the first-generation open platform (WOP) of WeBank as an example again:
[0093] First, when the first-generation open platform of WeBank is used to access the business requestor, the business requestor will be assigned an identity identification AppID and the corresponding AppSecret. The business requestor uses the AppID and AppSecret to apply to the authentication platform (WOP-AUTH) for obtaining authorization.
[0094] Then, the service requester applies for the relevant sign_ticket token to the authentication platform (WOP-AUTH) by carrying the obtained authorization code. After successfully obtaining the sign_ticket token, the service requester can use the token for subsequent service requests.
[0095] As can be seen from the above content, obtaining the sign_ticket token requires two steps of requests, that is, first obtaining the authorization code and then obtaining the token. The process is complex, resulting in an increase in the complexity of the service requester's access.
[0096] At the same time, the above process adopts a centralized authentication mode, strongly relying on the authentication platform AUTH. All authentication and authorization requests need to pass through AUTH, with a heavy dependence on AUTH.
[0097] In addition, there is a risk of exposure of the AppSecret on the public network, and there is a problem that it is not safe to transmit the AppSecret in plain text.
[0098] Based on this, the present invention cancels the step of obtaining the authorization code. However, in order to ensure security, a method of calculating signatures and authentication is adopted to ensure that the information is not rewritten or tampered with.
[0099] An embodiment of the present invention provides an authentication method for an open platform. The authentication method for the open platform provided by the embodiment of the present invention can be applied to a system architecture as Figure 1 shown. The system architecture includes a service requester 100, an open platform 200, an authentication platform 300, and a service system 400.
[0100] Among them, the open platform 200 is used to receive the service access request sent by the service requester 100.
[0101] The open platform 200 is used to determine the first token corresponding to the first token identifier in the authentication platform 300 after verifying the first token identifier.
[0102] It should be noted that the first token is the token corresponding to the first token identifier issued by the authentication platform 300 after verifying the authorization request sent by the service requester 100.
[0103] After passing the signature and verification of the first token, the open platform 200 sends the service access request to the corresponding service system 400.
[0104] Further, before the open platform 200 receives a service access request sent by the service requestor 100, the authentication platform 300 is configured to receive an authorization request sent by the service requestor 100, verify the authorization signature based on the service requestor identifier, generate second token information for the authorization request, and send the second token information to the service requestor 100 when the verification is successful and the authorization request has access rights.
[0105] It should be noted that Figure 1 This is only an example of the system architecture of the embodiments of the present application, and the present application does not make specific limitations thereto.
[0106] Based on this, in the embodiments of the present application, as Figure 2 shown, the service requestor accesses the subsystem, usually the open platform, and by integrating the WOPNG-SDK provided by WOPNG, it has the relevant services of the open platform. The WOPNG-SDK interacts with the WOPNG-AUTH background server of the authentication platform to update the configuration information.
[0107] It should be noted that the open platform does not need to understand the internal execution process of the authentication platform AUTH, and only needs to call the corresponding interface.
[0108] Further, the service requestor accesses the load balancer through the two-way authentication HTTPS method, and the load balancer forwards the service request to each open platform according to the configured routing. The WOPNG-SDK encapsulates and forwards the authentication and authorization related requests to the authentication platform, so that the authentication platform proxies the open platform to complete the relevant authentication and authorization services.
[0109] Based on the system architecture shown above, Figure 3 FIG. is a schematic flow chart corresponding to an authentication method for an open platform provided by an embodiment of the present invention. As Figure 3 shown, the method includes:
[0110] Step 301, the open platform receives a service access request sent by the service requestor.
[0111] It should be noted that the service access request carries first token information, and the first token information includes a first token identifier and a first token signature.
[0112] Step 302, after the open platform verifies the first token identifier, it determines the first token corresponding to the first token identifier in the authentication platform.
[0113] It should be noted that the first token is the token corresponding to the first token identifier issued by the authentication platform after verifying an authorization request sent by the service requestor.
[0114] Step 303: After the open platform passes the signature and verification of the first token, it sends the service access request to the corresponding service system.
[0115] In the embodiment of the present application, in step 301, when obtaining the first token information, the existing GET method is replaced with the POST method.
[0116] It should be noted that both POST and GET submit data to the server and obtain data from the server.
[0117] In the above solution, Get is insecure because the data is placed in the request URL during transmission; all operations of Post are invisible to the user, improving the security of the authentication process.
[0118] In step 302, the open platform generates a first verification value according to the first part and the second part of the first token identifier.
[0119] If the current time meets the effective time indicated by the second part of the first token identifier and the first verification value is consistent with the third part of the first token identifier, it is determined that the first token identifier passes the verification.
[0120] In a possible implementation manner, the first part, the second part, and the third part of the first token identifier are judged by extracting the information at the set position.
[0121] It should be noted that the set positions of the first part, the second part, and the third part are not limited, and the present application does not make specific limitations on this.
[0122] For example, first, the format of the first token identifier is defined, and relevant check bits are added. The service access request corresponding to the first token identifier that fails the verification is directly returned as an illegal request.
[0123] In addition, a lifetime is defined for the first token identifier. For the service access request corresponding to the first token identifier whose survival time exceeds the lifetime, it is directly returned that the request has expired, thereby reminding the service requestor to update the token.
[0124] In a possible implementation manner, the lifetime of the first token identifier is defined by the effective time indicated by the second part.
[0125] Specifically, during verification, first, it is judged whether the first token identifier is legal. In a possible implementation manner, the first 16 bits of the first token identifier are extracted, and then 13 - bit salt value is concatenated for one - time MD5 calculation. It is judged whether the first four bits of this MD5 value are consistent with the last 4 - bit check bits of the first token identifier. If they are consistent, it means that the first token identifier is legal.
[0126] It should be noted that the MD5 Message-Digest Algorithm is a widely used cryptographic hash function for ensuring the integrity and consistency of information transmission. In the embodiments of the present application, encryption algorithms such as SHA and DES can also be used, or other first token identifiers with a lifetime can be designed through symmetric encryption and decryption. The present application does not make specific limitations on this.
[0127] For example, the first token identifier is 5DAD5FA6SGDA3G8Y3277.
[0128] It can be seen that the first token identifier consists of a first part of a preset number of random strings (in this embodiment, an 8-bit random string 5DAD5FA6 is optional), a second part of a preset number of creation times (in this embodiment, an 8-bit creation time SGDA3G8Y is optional), and a third part of a preset number of values calculated by a preset algorithm (in this embodiment, a 4-bit value 3277 after MD5 calculation).
[0129] Furthermore, calculate the md5 of the first token identifier, that is, perform MD5 calculation on the random 8-bit characters in the first part + the 8-bit creation time in the second part + the 13-bit salt value. If the last four digits of the calculation result are 3277, it means that the first token identifier is legal.
[0130] Secondly, determine whether the first token identifier has expired. In one possible implementation, by extracting the 9th to 17th bit strings of the first token identifier, it can be determined whether the token has expired.
[0131] For example, in the above example, if it is determined that the 8-bit creation time SGDA3G8Y has not expired, the verification passes.
[0132] It should be noted that in order to avoid the time consumption of business access requests during network transmission, the open platform has a 10-minute redundancy for expired first token identifiers to prevent the token from being valid when sent and invalid when received by the authentication platform due to time differences.
[0133] In the embodiments of the present application, since the salt value is confidential and unique, the verification rule is also secure. In addition, after verifying the legality of the first token identifier, illegal requests are effectively avoided, such as malicious attacks on the public network, and the first token identifiers generated by malicious attacks are directly rejected.
[0134] The above solution avoids invalid requests, prevents the open platform from being maliciously attacked, and improves security.
[0135] In step 302, the business access request includes a business requestor identifier, and a token set corresponding to the business requestor identifier is determined according to the business requestor identifier;
[0136] Determine the first token corresponding to the first token identifier from the token set according to the first token identifier.
[0137] For example, the authentication platform generates different tokens for service requester A at different time points, namely ticket1, ticket2, ticket3, ticket4, and ticket5. According to the information of the first token identifier ticketID1, the token ticket3 with the same creation time information is found from the 5 tokens. Then ticket3 is the first token corresponding to the first token identifier.
[0138] As can be seen from the above, the first token identifier is used to identify which ticket participates in the verification signature this time. The open platform caches the tickets obtained from the authentication platform through the SDK, reducing the dependence on the single point of failure of the authentication platform. At the same time, the open platform avoids strong dependence on the database through caching. The open platform integrates the SDK and caches each ticket, thus having the function of signature verification.
[0139] In step 303, the open platform decrypts the signature of the first token according to the service requester identifier to obtain the first hash value, and determines whether the second hash value corresponding to the first token is consistent with the first hash value.
[0140] It should be noted that the first hash value is obtained by decrypting the signature of the first token with the public key of the requester.
[0141] Furthermore, before the open platform obtains the service access request, this application provides the authorization process of the authentication platform as Figure 4 shown.
[0142] As Figure 4 shown:
[0143] Step 401, the authentication platform receives the authorization request sent by the service requester.
[0144] It should be noted that the authorization request includes the service requester identifier and the authorization signature; the authorization signature is generated according to the private key of the service requester.
[0145] Step 402, the authentication platform verifies the authorization signature according to the service requester identifier.
[0146] Step 403, when the authentication platform verifies and the authorization request has access rights, it generates the second token information of the authorization request and sends the second token information to the service requester.
[0147] It should be noted that the second token information includes the second token identifier and the second token.
[0148] In the embodiment of the present application, in the authorization process of the authentication platform, the authentication platform generates the second token information of the authorization request and sends the second token information to the service requester. In the authentication process of the open platform, the open platform receives the first token information sent by the service requester. If the data is not tampered with during the sending process by the service requester, the first token information is consistent with the second token information. If tampering occurs, the first token information is inconsistent with the second token information.
[0149] In step 401, the authorization request sent by the service requester is the service requester identifier and the authorization signature, which makes the AppSecret assigned by the authentication platform to the service requester not transmitted over the network, avoiding the risk of AppSecret leakage in the public network. At the same time, this solution uses AppSecret to generate the authorization signature, so that the authentication platform can verify the authorization signature, improving both the user experience and security.
[0150] In the embodiment of the present application, in step 403, the authentication platform determines whether the authorization request has access rights, that is, it realizes the access control of ACL (Access Control Lists).
[0151] Furthermore, the above authorization is implemented by the authentication platform. When the service is normal, the ACL access control verification and authentication are all carried out on the open platform.
[0152] It should be noted that in the prior art, all ACL authentications for business access requests are carried out via the authentication platform, resulting in a strong dependence on the authentication platform. The services provided by the authentication platform become heavier, so that the quality of the ACL services provided by the authentication platform affects the quality of the entire authentication service. At the same time, if the authentication platform service is unavailable, all ACL authentication service requests will be unavailable.
[0153] In the embodiment of the present application, first, the open platform obtains the ACL access control list corresponding to the service requester identifier from the authentication platform and caches it locally. If the list has not been cached locally, the WOPNG-SDK will automatically pull it once from the authentication platform. For the case where the ACL list already exists locally, direct authentication is performed, effectively intercepting illegal requests.
[0154] Furthermore, the authentication platform sends the second token information to the open platform; or
[0155] The authentication platform sends the second token information to the open platform based on the acquisition request sent by the open platform; the acquisition request is sent by the open platform after receiving the business access request.
[0156] In the embodiments of the present application, considering the distributed deployment of nodes, multiple nodes may be deployed on the open platform. If the corresponding token is not found in the cache of the current node, an authentication platform will be requested to obtain it once, and at the same time, the open platform will cache the obtained token.
[0157] In the embodiments of the present application, before the open platform verifies the first token identifier, the open platform determines that the service access request is verified by the open platform; otherwise, the open platform forwards the service access request to the authentication platform; the authentication platform is used to determine whether the service access request is verified.
[0158] As can be seen from the above solution, since the signature verification service of the existing technology access channels all goes through the authentication platform, it strongly depends on the authentication platform, and the services provided by the authentication platform become heavier. In the embodiments of the present application, the open platform, like the authentication platform, has a signature verification function. Under normal circumstances, all signature verifications are completed by the open platform. This reduces the AUTH request pressure.
[0159] Furthermore, the authentication platform receives the service access request forwarded by the open platform;
[0160] After the authentication platform verifies the second token identifier in the service access request, it determines the second token corresponding to the second token identifier;
[0161] After the authentication platform passes the verification of the second token signature and the second token in the service access request, it sends the service access request to the corresponding service system.
[0162] As can be seen from the above content, the embodiments of the present application also support downgrade switching, that is, if there is a problem with the open platform and it cannot provide relevant authentication services, the open platform will forward the service access request to the authentication platform to complete the authentication service.
[0163] In the embodiments of the present application, each service access request that needs to be signature-verified carries a first token identifier, so that the open platform knows to use the corresponding cached token for calculating the signature. If the signatures on both sides are inconsistent, the first token identifier used can be determined first, which is convenient for problem analysis and solution. In the existing technology, the signature is calculated based on the latest token. In actual production, it often happens that a user's service access request uses an old token for signature verification request, resulting in complex and difficult problem analysis and positioning. The present application effectively reduces the difficulty of problem analysis and troubleshooting through the first token identifier.
[0164] In the above solution, the open platform has cancelled the step of obtaining the authorization code. The service requester no longer needs to go through the steps of first obtaining the authorization code and locally caching the authorization code. Instead, the user can directly obtain the token by calculating a signature sign using the AppID and AppSecret information applied for on the open platform. After the service requester obtains the token, it can carry the first token identifier in subsequent requests for subsequent business processing procedures. If problems such as authentication failure occur, the first token used for calculating the signature can be determined through the first token identifier. At the same time, the AppSecret assigned by the open platform to the service requester will not be transmitted over the network, avoiding the risk of AppSecret leakage in the public network. While improving the user experience, it also enhances security.
[0165] Based on the same inventive concept, Figure 5 Exemplarily, an authentication device for an open platform provided by an embodiment of the present invention is shown. This device can be the process of the authentication method for the open platform.
[0166] The device for obtaining the tag includes:
[0167] An obtaining module 501, configured to receive a service access request sent by a service requester, where the service access request carries first token information, and the first token information includes a first token identifier and a first token signature;
[0168] A processing module 502, configured to determine a first token corresponding to the first token identifier in the authentication platform after verifying the first token identifier; the first token is the token corresponding to the first token identifier issued after the authentication platform verifies an authorization request sent by the service requester;
[0169] The processing module 502 is further configured to send the service access request to the corresponding service system after verifying the first token signature against the first token.
[0170] Optionally, the processing module 502 is specifically configured to:
[0171] Generate a first verification value according to a first part and a second part of the first token identifier;
[0172] If the current time meets the effective time indicated by the second part of the first token identifier and the first verification value is consistent with the third part of the first token identifier, it is determined that the first token identifier is verified.
[0173] Optionally, the processing module 502 is specifically configured to:
[0174] Determine a token set corresponding to the service requester identifier according to the service requester identifier;
[0175] Determine a first token corresponding to the first token identifier from the token set according to the first token identifier;
[0176] Verify the signature of the first token and the first token, including:
[0177] According to the service requester identifier, decrypt the signature of the first token to obtain a first hash value, and determine whether the second hash value corresponding to the first token is consistent with the first hash value.
[0178] Optionally, the processing module 502 is further configured to:
[0179] Before verifying through the first token identifier, determine that the service access request is verified by the open platform; otherwise, forward the service access request to the authentication platform; the authentication platform is used to determine whether the service access request is verified.
[0180] Based on the same inventive concept, Figure 6 Exemplarily shows an authentication device of an open platform provided by an embodiment of the present invention, and the device can be a process of an authentication method of an open platform.
[0181] An obtaining module 601 is configured to receive an authorization request sent by a service requester, where the authorization request includes a service requester identifier and an authorization signature; the authorization signature is generated according to a secret key of the service requester;
[0182] A processing module 602 is configured to verify the authorization signature according to the service requester identifier;
[0183] The processing module 602 is further configured to generate second token information of the authorization request and send the second token information to the service requester when the verification is passed and the authorization request has access rights; the second token information includes a second token identifier and a second token.
[0184] Optionally, the processing module 602 is further configured to:
[0185] After sending the second token information to the service requester, send the second token information to the open platform; or
[0186] Based on a fetch request sent by the open platform, send the second token information to the open platform; the fetch request is sent by the open platform after receiving a service access request.
[0187] Optionally, the processing module 602 is further configured to:
[0188] Receive a service access request forwarded by an open platform;
[0189] After verifying the second token identifier in the service access request, determine the second token corresponding to the second token identifier;
[0190] After passing the verification of the second token signature in the service access request and the second token, send the service access request to the corresponding service system.
[0191] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the specified functions in one process Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0192] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implement the specified functions in one process Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0193] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the specified functions in one process Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0194] Although the preferred embodiments of the present invention have been described, those skilled in the art can make additional changes and modifications to these embodiments once they learn the basic creative concepts. Therefore, the appended claims are intended to be construed to include the preferred embodiments and all changes and modifications falling within the scope of the present invention.
[0195] Obviously, those skilled in the art can make various modifications and variations to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these modifications and variations.
Claims
1. An authentication method for an open platform, characterized in that, it includes: The open platform receives a service access request sent by a service requestor, and the service access request carries first token information, and the first token information includes a first token identifier and a first token signature; After the open platform verifies and passes the first token identifier, it determines the first token corresponding to the first token identifier in the authentication platform; The first token is the token corresponding to the first token identifier issued by the authentication platform after verifying and passing the authorization request sent by the service requestor; After the open platform verifies and passes the first token signature and the first token, it sends the service access request to the corresponding service system; The first token identifier is composed of a first part of a preset-bit random string, a second part of a preset-bit creation time, and a third part of a preset-bit preset algorithm calculation value; The verification and passing of the first token identifier includes: The open platform generates a first verification value according to the first part and the second part of the first token identifier; When the current time conforms to the effective time indicated by the second part of the first token identifier, and the first verification value is consistent with the third part of the first token identifier, it is determined that the first token identifier is verified and passed; The service access request includes a service requestor identifier, and the determining of the first token corresponding to the first token identifier in the authentication platform includes: Determining a token set corresponding to the service requestor identifier according to the service requestor identifier; Determining the first token corresponding to the first token identifier from the token set according to the first token identifier; The open platform verifies the first token signature and the first token, including: The open platform decrypts the first token signature according to the service requestor identifier to obtain a first hash value, and determines whether the second hash value corresponding to the first token is consistent with the first hash value.
2. The method according to claim 1, characterized in that, Before the open platform verifies and passes the first token identifier, the method further includes: The open platform determines that the service access request is verified by the open platform; otherwise, the open platform forwards the service access request to the authentication platform; the authentication platform is used to determine whether the service access request is verified and passed.
3. An authentication method for an open platform, characterized in that, it includes: The authentication platform receives an authorization request sent by a service requestor, and the authorization request includes a service requestor identifier and an authorization signature; The authorization signature is generated according to the secret key of the service requestor; The authentication platform verifies the authorization signature according to the service requestor identifier; When the authentication platform verifies and passes and the authorization request has access rights, it generates second token information for the authorization request and sends the second token information to the service requestor; the second token information includes a second token identifier and a second token; The second token identifier is used for the open platform to verify the service access request of the service requestor. The second token identifier is composed of a first part of a preset bit random string, a second part of a preset bit creation time, and a third part of a preset bit preset algorithm calculated value.
4. The method according to claim 3, wherein, after sending the second token information to the service requester, the method further includes: the authentication platform sending the second token information to the open platform; or the authentication platform sending the second token information to the open platform based on a fetch request sent by the open platform; the fetch request is sent by the open platform after receiving a service access request.
5. The method according to claim 3 or 4, wherein, the method further includes: the authentication platform receiving a service access request forwarded by the open platform; the authentication platform determining a second token corresponding to the second token identifier after verifying the second token identifier in the service access request; the authentication platform sending the service access request to a corresponding service system after passing the verification of the second token signature in the service access request and the second token.
6. An authentication device for an open platform, wherein, it includes: an acquisition module, configured to receive a service access request sent by a service requester, where the service access request carries first token information, and the first token information includes a first token identifier and a first token signature; a processing module, configured to determine a first token corresponding to the first token identifier in the authentication platform after verifying the first token identifier; the first token is the token corresponding to the first token identifier issued by the authentication platform after passing the verification of an authorization request sent by the service requester; the processing module is further configured to send the service access request to a corresponding service system after passing the verification of the first token signature and the first token; the first token identifier is composed of a first part of a preset bit random string, a second part of a preset bit creation time, and a third part of a preset bit preset algorithm calculated value; the processing module verifying the first token identifier specifically includes: generating a first verification value according to the first part of the first token identifier and the second part of the first token identifier; determining that the first token identifier passes the verification if the current time conforms to the effective time indicated by the second part of the first token identifier and the first verification value is consistent with the third part of the first token identifier; the service access request includes a service requester identifier, and the processing module determining the first token corresponding to the first token identifier in the authentication platform specifically includes: determining a token set corresponding to the service requester identifier according to the service requester identifier; determining a first token corresponding to the first token identifier from the token set according to the first token identifier; the processing module verifying the first token signature and the first token specifically includes: decrypting the first token signature according to the service requester identifier to obtain a first hash value, and determining whether the second hash value corresponding to the first token is consistent with the first hash value.
7. An authentication device for an open platform, It is characterized in that including: an obtaining module, configured to receive an authorization request sent by a service requester, where the authorization request includes a service requester identifier and an authorization signature; the authorization signature is generated according to the secret key of the service requester; a processing module, configured to verify the authorization signature according to the service requester identifier; the processing module is further configured to generate second token information of the authorization request and send the second token information to the service requester when the verification is passed and the authorization request has access rights; the second token information includes a second token identifier and a second token; the second token identifier is used for the open platform to verify the service access request of the service requester; the second token identifier is composed of a first part of a preset-bit random string, a second part of a preset-bit creation time, and a third part of a preset-bit preset algorithm calculated value.
8. A computing device It is characterized in that including: a memory, configured to store program instructions; a processor, configured to call the program instructions stored in the memory and execute the method according to any one of claims 1 to 5 according to the obtained program.
9. A computer-readable non-volatile storage medium It is characterized in that including computer-readable instructions, when a computer reads and executes the computer-readable instructions, the computer is caused to execute the method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Security management method and device for open platform, computer equipment and storage medium
CN110175466A