A user token generation method, a user token verification method and related equipment

By signing the user information twice to generate user tokens, the problem that the server needs to store additional user information during authorization and authentication is solved, and the effect of saving storage and computing resources is achieved.

CN114065266BActive Publication Date: 2025-05-16SHENZHEN PUDU TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111434745.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-29
Publication Date
2025-05-16
Estimated Expiration
2041-11-29

AI Technical Summary

Technical Problem

When authorizing authentication in network applications in prior art, the server needs to store additional user information, resulting in wasted storage and computing resources.

Method used

By signing the user information twice, generating a user token containing the first token and the second token. The server only needs to compare the information of the two tokens to achieve authorization verification without additional storage of user information.

Benefits of technology

It effectively saves storage and computing resources and avoids waste of resources caused by storing user information.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114065266B_ABST
    Figure CN114065266B_ABST
Patent Text Reader

Abstract

The present invention provides a method for generating a user token, including: when receiving user information sent by a client, using a JWT algorithm to sign the user information to obtain a first token; using a preset signature algorithm to sign the user information to obtain a second token; using a preset encoding method to splice the first token and the second token to obtain a user token, and sending the user token to the client; the user information can be signed twice to generate a user token containing a first token and a second token, wherein the first token can carry user information with a small amount of overhead, and the second token is a unique digital summary information of the user information. Since the first token and the second token are both signed by the same user information, the server only needs to compare the two tokens to achieve the authorization verification result, without the need to store user information additionally, which can effectively save resources. The present invention also provides a user token verification method and related equipment, which have the above-mentioned beneficial effects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network applications, and in particular to a user token generation method, a user token verification method, a device, an electronic device and a storage medium. Background Art

[0002] In the field of network applications, in order to avoid security issues such as information leakage, the server usually needs to authorize and authenticate the user. In the related technology, the user first needs to register on the server and save the user information (such as user name and password) to the server. When performing authorization and authentication, the user needs to send the user information to be verified to the server so that the server can verify the identity of the user using the stored user information. However, in the above-mentioned authorization and authentication method, the server needs to store the user information of the user additionally, which not only easily causes a waste of storage resources, but also when performing verification, the server needs to query the stored user information additionally, which also easily leads to a waste of computing resources. Summary of the invention

[0003] The purpose of the present invention is to provide a user token generation method, a user token verification method, a device, an electronic device and a storage medium, which can sign user information twice to generate a user token containing a first token and a second token. Then, the server only needs to compare the information of the two tokens to achieve the authorization verification result, without the need to additionally store user information, which can effectively save storage and computing resources.

[0004] In order to solve the above technical problems, the present invention provides a method for generating a user token, comprising:

[0005] When receiving the user information sent by the client, the user information is signed using the JWT algorithm to obtain a first token;

[0006] Sign the user information using a preset signature algorithm to obtain a second token;

[0007] The first token and the second token are concatenated using a preset encoding method to obtain a user token, and the user token is sent to the client.

[0008] Optionally, the using a JWT algorithm to sign the user information to obtain a first token includes:

[0009] The user information is signed using the JWT algorithm to obtain an initial token; the user information is located in the payload of the initial token;

[0010] The payload is symmetrically encrypted using a preset key, and the encrypted payload is used to update the initial token to obtain the first token.

[0011] Optionally, the step of concatenating the first token and the second token using a preset encoding method to obtain a user token includes:

[0012] Using preset special characters to concatenate the first token and the second token to obtain an initial user token;

[0013] The initial user token is encoded to obtain the user token.

[0014] The present invention also provides a user token verification method, comprising:

[0015] When receiving the user token sent by the client, restoring the user token into the first token and the second token using a preset encoding method;

[0016] Parse the first token using the JWT algorithm to obtain first user information;

[0017] Sign the first user information using a preset signature algorithm to obtain a third token;

[0018] When it is determined that the third token is consistent with the second token, it is determined that the client is authenticated.

[0019] Optionally, the using a JWT algorithm to parse the first token to obtain the first user information includes:

[0020] Parsing the first token using the JWT algorithm to obtain a payload in the first token;

[0021] The load is symmetrically decrypted using a preset key to obtain the first user information.

[0022] Optionally, the using a preset encoding method to restore the user token into a first token and a second token includes:

[0023] Decoding the user token to restore the initial user token;

[0024] The user token is split into the first token and the second token according to preset special characters.

[0025] The present invention also provides a user token generation device, comprising:

[0026] A first signature module is used to sign the user information sent by the client using the JWT algorithm to obtain a first token;

[0027] A second signature module, used to sign the user information using a preset signature algorithm to obtain a second token;

[0028] A splicing module is used to splice the first token and the second token using a preset encoding method to obtain a user token, and send the user token to the client.

[0029] The present invention also provides a user token verification device, comprising:

[0030] A restoration module, configured to restore the user token into a first token and a second token by using a preset encoding method when receiving the user token sent by the client;

[0031] A parsing module, used to parse the first token using a JWT algorithm to obtain first user information;

[0032] A signature module, used to sign the first user information using a preset signature algorithm to obtain a third token;

[0033] The verification module is used to determine that the client has passed the verification when it is determined that the third token is consistent with the second token.

[0034] The present invention also provides an electronic device, comprising:

[0035] Memory for storing computer programs;

[0036] A processor for executing the computer program to implement the following steps: when receiving user information sent by a client, signing the user information using a JWT algorithm to obtain a first token; signing the user information using a preset signature algorithm to obtain a second token; concatenating the first token and the second token using a preset encoding method to obtain a user token, and sending the user token to the client; and / or, when receiving a user token sent by a client, restoring the user token into a first token and a second token using a preset encoding method; parsing the first token using a JWT algorithm to obtain first user information; signing the first user information using a preset signature algorithm to obtain a third token; and determining that the client has passed verification when it is determined that the third token is consistent with the second token.

[0037] Optionally, the processor is also used to implement the use of the JWT algorithm to sign the user information when executing the computer program to obtain an initial token; the user information is located in the payload of the initial token; the payload is symmetrically encrypted using a preset key, and the initial token is updated using the encrypted payload to obtain the first token; and / or, is also used to implement the use of the JWT algorithm to parse the first token when executing the computer program to obtain the payload in the first token; the payload is symmetrically decrypted using a preset key to obtain the first user information.

[0038] Optionally, the processor is also used to, when executing the computer program, concatenate the first token and the second token using preset special characters to obtain an initial user token; encode the initial user token to obtain the user token; and / or, when executing the computer program, decode the user token to restore the initial user token; and split the user token into the first token and the second token according to preset special characters.

[0039] The present invention also provides a storage medium, in which computer executable instructions are stored. When the computer executable instructions are loaded and executed by a processor, the user token generation method and / or user token verification method as described above are implemented.

[0040] The present invention provides a method for generating a user token, comprising: when receiving user information sent by a client, signing the user information using a JWT algorithm to obtain a first token; signing the user information using a preset signature algorithm to obtain a second token; splicing the first token and the second token using a preset encoding method to obtain a user token, and sending the user token to the client.

[0041] It can be seen that when the present invention receives the user information sent by the client, it will first use the JWT algorithm and another preset signature algorithm to sign the user information twice to obtain the first token and the second token, wherein the JWT algorithm can load the user information in the first token with less expenditure, and the preset signature algorithm can generate unique digital summary information for the user information. Since the first token and the second token are both signed by the same user information, and the type of the preset signature algorithm is only known by the server, when the server performs authorization verification, it only needs to use the same signature algorithm to re-sign the user information in the first token and compare it with the second token, and it can determine whether the user terminal has tampered with the user token based on whether the comparison results are the same, thereby achieving the effect of authorization verification, without the need to additionally store the user information of the user terminal, and can effectively avoid the waste of storage resources caused by storing user information, and the waste of computing resources caused by additionally querying the stored user information. The present invention also provides a user token verification method, an electronic device and a storage medium, which have the above-mentioned beneficial effects. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying creative work.

[0043] Figure 1 A flowchart of a method for generating a user token provided by an embodiment of the present invention;

[0044] Figure 2 A flowchart of a user token verification method provided by an embodiment of the present invention;

[0045] Figure 3 A structural block diagram of a user token generation device provided by an embodiment of the present invention;

[0046] Figure 4 A structural block diagram of a user token verification device provided by an embodiment of the present invention. DETAILED DESCRIPTION

[0047] In order to make the purpose, technical solution and advantages of the embodiments of the present invention clearer, the technical solution in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0048] In the related art, the user terminal first needs to register on the server side and save the user information (such as user name and password) to the server side. When performing authorization and authentication, the user terminal needs to send the user information to be verified to the server side, so that the server side can verify the identity of the user terminal using the stored user information. However, in the above-mentioned authorization and authentication method, the server side needs to additionally store the user information of the user terminal, which not only easily causes a waste of storage resources, but also when performing verification, the server side needs to additionally query the stored user information, which also easily causes a waste of computing resources. In view of this, the present invention provides a user token generation method, which can sign the user information twice to generate a user token containing a first token and a second token, and then the server side only needs to compare the information of the two tokens to achieve the authorization verification result, without the need to additionally store user information, which can effectively save storage and computing resources. Please refer to Figure 1 , Figure 1 A flowchart of a method for generating a user token provided by an embodiment of the present invention, the method may include:

[0049] S101. When receiving user information sent by a client, use the JWT algorithm to sign the user information to obtain a first token.

[0050] JWT (JSON Web Token, a network token based on JSON format) is an open standard based on JSON designed to transmit statements between network application environments. It has a relatively compact structure and can load user information with relatively low overhead. Therefore, in the embodiments of the present invention, a token generated by the JWT algorithm will be used to load user information. It should be noted that the embodiments of the present invention do not limit the specific process of signing using the JWT algorithm, and reference may be made to the relevant technologies of JWT. The embodiments of the present invention also do not limit the specific user information, such as user name, user ID, etc., which can be selected according to actual application requirements.

[0051] Furthermore, in the token generated by JWT, user information is usually loaded in plain text, which can easily lead to user information leakage. In order to improve the security and reliability of the first token, the embodiment of the present invention can also add an encryption step in the process of signing using the JWT algorithm. The embodiment of the present invention does not limit whether the first token is encrypted as a whole or whether the part of the first token that carries the user information (i.e., the payload of the first token) is encrypted. When the overall encryption can meet the application requirements, the first token can be encrypted as a whole; if it is necessary to improve the encryption efficiency, the payload part of the first token can also be encrypted. In the embodiment of the present invention, in order to quickly encrypt the first token, the part of the first token that carries the user information is encrypted.

[0052] Furthermore, the embodiment of the present invention does not limit the method used to encrypt the payload of the first token. Preferably, since symmetric encryption uses a single key for encryption, it can effectively improve encryption security. Therefore, the embodiment of the present invention will use symmetric encryption to encrypt the payload.

[0053] In one possible scenario, the user information is signed using the JWT algorithm to obtain a first token, including:

[0054] Step 11: Use the JWT algorithm to sign the user information and obtain the initial token; the user information is located in the payload of the initial token;

[0055] Step 12: Use a preset key to symmetrically encrypt the payload, and use the encrypted payload to update the initial token to obtain a first token.

[0056] It should be noted that the embodiments of the present invention do not limit the specific symmetric encryption method, for example, it can be AES (Advanced Encryption Standard), DES (Data Encryption Standard), etc., which can be selected according to actual application requirements. It should be emphasized that the preset key of the symmetric encryption is only controlled by the server.

[0057] S102: Sign the user information using a preset signature algorithm to obtain a second token.

[0058] The embodiment of the present invention will use another signature algorithm to sign the user information for the second time to obtain a second token, wherein the second token is the unique digital digest information (Digital Digest) of the user information. The embodiment of the present invention does not limit the specific preset signature algorithm, which can be either a JWT algorithm or other different types of signature algorithms. In order to improve the security of the signature, the embodiment of the present invention will use other signature algorithms different from the JWT algorithm. Since the type of the preset signature algorithm is only known by the server, the security of the second token can be effectively guaranteed. Furthermore, other signature algorithms can be hash algorithms such as MD5 (Message-Digest Algorithm), SHA1 (Secure Hash Algorithm1), etc., which can be set according to actual application requirements. The embodiment of the present invention does not limit the specific process of signing, and the relevant technology can be referred to according to the preset signature algorithm actually selected.

[0059] S103: Use a preset encoding method to concatenate the first token and the second token to obtain a user token, and send the user token to the client.

[0060] The embodiments of the present invention do not limit the specific preset encoding method. For example, when the length of the first token and the second token is fixed and the user token can be split according to the token length, the first token and the second token can be directly connected, and the connected initial user token can be encoded; or the first token and the second token can be spliced ​​using preset special characters to obtain the initial user token, and the initial user token can be encoded. Considering that special characters can effectively improve the parsing and extraction efficiency, in the embodiments of the present invention, the first token and the second token are spliced ​​using preset special characters to obtain the initial user token, and the initial user token is encoded to obtain the user token. It should be noted that the embodiments of the present invention do not limit the specific preset special characters, and can be set according to actual application requirements.

[0061] In one possible scenario, using a preset encoding method to concatenate the first token and the second token to obtain a user token may include:

[0062] Step 21: Use preset special characters to concatenate the first token and the second token to obtain an initial user token;

[0063] Step 22: Encode the initial user token to obtain a user token.

[0064] It should be noted that the embodiment of the present invention does not limit the specific encoding method. For example, the BASE64 protocol may be used for encoding, or other encoding protocols may be used. For details, please refer to the relevant technology of the encoding protocol.

[0065] Based on the above embodiment, when the present invention receives the user information sent by the client, it will first use the JWT algorithm and another preset signature algorithm to sign the user information twice to obtain the first token and the second token, wherein the JWT algorithm can load the user information in the first token with a small cost, and the preset signature algorithm can generate a unique digital summary information for the user information. Since the first token and the second token are both signed by the same user information, and the type of the preset signature algorithm is only known by the server, when the server performs authorization verification, it only needs to use the same signature algorithm to re-sign the user information in the first token and compare it with the second token, and it can determine whether the user terminal has tampered with the user token based on whether the comparison results are the same, thereby achieving the effect of authorization verification, without the need to additionally store the user information of the user terminal, and can effectively avoid the waste of storage resources caused by storing user information, and the waste of computing resources caused by additional queries of stored user information.

[0066] Based on the above embodiment, the verification method of the user token provided by the embodiment of the present invention will be introduced below. Figure 2 , Figure 2 A flowchart of a user token verification method provided by an embodiment of the present invention, the method may include:

[0067] S201. When a user token sent by a client is received, the user token is restored into a first token and a second token using a preset encoding method.

[0068] It should be noted that the embodiment of the present invention does not limit the method of restoring the user token to the first token and the second token. It can be understood that the restoration method corresponds to the encoding method, and reference can be made to the introduction in the above embodiment. Since the preset encoding method preferably uses preset special characters to concatenate the first token and the second token to obtain the initial user token, and encodes the initial user token, the corresponding restoration process is the inverse process of the above encoding process.

[0069] In one possible case, restoring the user token to the first token and the second token using a preset encoding method may include:

[0070] Step 31: Decode the user token to restore the initial user token;

[0071] Step 32: Split the user token into a first token and a second token according to preset special characters.

[0072] It should be noted that the protocol used for decoding and the preset special characters for splitting the user token can all be referred to the above embodiments, and will not be described in detail here.

[0073] S202: parse the first token using the JWT algorithm to obtain first user information.

[0074] Similarly, the process of parsing the first user information from the first token is also the opposite of the process of signing using the JWT algorithm. For example, when the first user information is stored in the payload of the first token in plain text, the payload of the first token can be directly retrieved; when the first user information is stored in the payload in a symmetrically encrypted form, after the payload is retrieved, the payload must be symmetrically decrypted to obtain the first user information. In an embodiment of the present invention, since the use of encrypted form to save user information to the first token can improve its security, the payload must also be symmetrically decrypted when parsing the first token.

[0075] In one possible scenario, parsing the first token using the JWT algorithm to obtain the first user information may include:

[0076] Step 41: parse the first token using the JWT algorithm to obtain the payload in the first token;

[0077] Step 42: Use the preset key to symmetrically decrypt the payload to obtain the first user information.

[0078] It should be noted that the specific process of symmetric decryption corresponds to symmetric encryption. Please refer to the above-mentioned limited description of symmetric encryption, which will not be repeated here.

[0079] S203: Sign the first user information using a preset signature algorithm to obtain a third token.

[0080] After obtaining the first user information, the client can re-sign the first user information using the same preset signature algorithm as in the token generation phase, and compare it with the second token. If the comparison results are the same, it means that the client is safe and the verification can be determined to be successful; if the comparison results are different, it means that the client has tampered with the user information or the second token, which means that the client is not safe and the verification can be determined to be unsuccessful.

[0081] S204: When it is determined that the third token is consistent with the second token, it is determined that the client has passed the verification.

[0082] Based on the above embodiment, since the first token and the second token in the user token are signed by the same user information, and the type of the preset signature algorithm is only known by the server, when performing authorization verification, the server only needs to use the same signature algorithm to re-sign the user information in the first token and compare it with the second token. It can be determined whether the user terminal has tampered with the user token based on whether the comparison results are the same, thereby achieving the effect of authorization verification. There is no need to additionally store the user information of the user terminal, which can effectively avoid the waste of storage resources caused by storing user information, and the waste of computing resources caused by additional queries on the stored user information.

[0083] The user token generating device, user token verifying device, electronic device and storage medium provided in the embodiments of the present invention are introduced below. The user token generating device, user token verifying device, electronic device and storage medium described below can be referenced to each other with the user token generating method and user token verifying method described above.

[0084] Please refer to Figure 3 , Figure 3 A structural block diagram of a user token generation device provided by an embodiment of the present invention, the device may include:

[0085] The first signature module 301 is used to sign the user information using the JWT algorithm when receiving the user information sent by the client to obtain a first token;

[0086] The second signature module 302 is used to sign the user information using a preset signature algorithm to obtain a second token;

[0087] The concatenation module 303 is used to concatenate the first token and the second token using a preset encoding method to obtain a user token, and send the user token to the client.

[0088] Optionally, the first signature module 301 may include:

[0089] The JWT signature submodule is used to sign the user information using the JWT algorithm to obtain the initial token; the user information is located in the payload of the initial token;

[0090] The encryption update submodule is used to symmetrically encrypt the payload using a preset key, and use the encrypted payload to update the initial token to obtain a first token.

[0091] Optionally, the splicing module 303 may include:

[0092] A concatenation submodule, used for concatenating the first token and the second token using preset special characters to obtain an initial user token;

[0093] The encoding submodule is used to encode the initial user token to obtain a user token.

[0094] Please refer to Figure 4 , Figure 4 A structural block diagram of a user token verification device provided by an embodiment of the present invention, the device may include:

[0095] The restoring module 401 is used to restore the user token into the first token and the second token by using a preset encoding method when receiving the user token sent by the client;

[0096] A parsing module 402 is used to parse the first token using a JWT algorithm to obtain first user information;

[0097] The signature module 403 is used to sign the first user information using a preset signature algorithm to obtain a third token;

[0098] The verification module 404 is used to determine that the client has passed the verification when it is determined that the third token is consistent with the second token.

[0099] Optionally, the parsing module 402 may include:

[0100] A JWT parsing submodule, used to parse the first token using a JWT algorithm to obtain a payload in the first token;

[0101] The decryption submodule is used to symmetrically decrypt the payload using a preset key to obtain the first user information.

[0102] Optionally, the restoration module 401 may include:

[0103] A decoding submodule, used to decode the user token and restore the initial user token;

[0104] The splitting submodule is used to split the user token into a first token and a second token according to preset special characters.

[0105] The present invention also provides an electronic device, comprising:

[0106] Memory for storing computer programs;

[0107] A processor is used to implement, when executing a computer program, the following steps: when receiving user information sent by a client, signing the user information using a JWT algorithm to obtain a first token; signing the user information using a preset signature algorithm to obtain a second token; concatenating the first token and the second token using a preset encoding method to obtain a user token, and sending the user token to the client; and / or, when executing a computer program, restoring the user token into a first token and a second token using a preset encoding method; parsing the first token using a JWT algorithm to obtain first user information; signing the first user information using a preset signature algorithm to obtain a third token; and when it is determined that the third token is consistent with the second token, determining that the client has passed the verification.

[0108] Optionally, the processor is also used to implement the use of the JWT algorithm to sign user information when executing a computer program to obtain an initial token; the user information is located in the payload of the initial token; the payload is symmetrically encrypted using a preset key, and the initial token is updated using the encrypted payload to obtain a first token; and / or, is also used to implement the use of the JWT algorithm to parse the first token when executing a computer program to obtain the payload in the first token; the payload is symmetrically decrypted using a preset key to obtain the first user information.

[0109] Optionally, the processor is also used to, when executing a computer program, concatenate the first token and the second token using preset special characters to obtain an initial user token; encode the initial user token to obtain a user token; and / or, is also used to, when executing a computer program, decode the user token to restore the initial user token; and split the user token into a first token and a second token according to preset special characters.

[0110] An embodiment of the present invention also provides a storage medium having a computer program stored thereon. When the computer program is executed by a processor, the steps of the user token generation method, the user token verification method, or the combination of the user token generation method and the user token verification method of any of the above-mentioned embodiments are implemented.

[0111] Since the embodiments of the storage medium part correspond to the embodiments of the user token generation method and the user token verification method part, the embodiments of the storage medium part please refer to the description of the embodiments of the user token generation method and the user token verification method part, which will not be repeated here.

[0112] The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part description.

[0113] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present invention.

[0114] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0115] The above is a detailed introduction to a user token generation method, a user token verification method, a device, an electronic device and a storage medium provided by the present invention. Specific examples are used herein to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only used to help understand the method of the present invention and its core idea. It should be pointed out that for ordinary technicians in this technical field, without departing from the principles of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the scope of protection of the claims of the present invention.

Claims

1. A method for generating a user token, characterized in that: Applied to the server, the method includes: When receiving the user information sent by the client, the user information is signed using the JWT algorithm to obtain a first token; Sign the user information using a preset signature algorithm to obtain a second token; the type of the preset signature algorithm is controlled by the server; Using a preset encoding method to concatenate the first token and the second token to obtain a user token, and sending the user token to the client; The using the JWT algorithm to sign the user information to obtain a first token includes: The user information is signed using the JWT algorithm to obtain an initial token; the user information is located in the payload of the initial token; The load is symmetrically encrypted using a preset key, and the encrypted load is used to update the initial token to obtain the first token; the preset key for symmetrical encryption is mastered by the server.

2. The method for generating a user token according to claim 1, characterized in that: The step of using a preset encoding method to concatenate the first token and the second token to obtain a user token includes: Using preset special characters to concatenate the first token and the second token to obtain an initial user token; The initial user token is encoded to obtain the user token.

3. A user token verification method, characterized in that: Applied to the server, the method includes: When receiving the user token sent by the client, restoring the user token into the first token and the second token using a preset encoding method; Parse the first token using the JWT algorithm to obtain first user information; Signing the first user information using a preset signature algorithm to obtain a third token; the type of the preset signature algorithm is controlled by the server; When it is determined that the third token is consistent with the second token, determining that the client has passed the verification; The using the JWT algorithm to parse the first token to obtain the first user information includes: Parsing the first token using the JWT algorithm to obtain a payload in the first token; The load is symmetrically decrypted using a preset key to obtain the first user information; the preset key for symmetrical encryption is mastered by the server.

4. The user token verification method according to claim 3, characterized in that: The method of restoring the user token to the first token and the second token by using a preset encoding method includes: Decoding the user token to restore the initial user token; The user token is split into the first token and the second token according to preset special characters.

5. A user token generation device, characterized in that: Applied to the server, the device comprises: A first signature module is used to sign the user information sent by the client using the JWT algorithm to obtain a first token; A second signature module is used to sign the user information using a preset signature algorithm to obtain a second token; the type of the preset signature algorithm is mastered by the server; A splicing module, used for splicing the first token and the second token using a preset encoding method to obtain a user token, and sending the user token to the client; The first signature module comprises: A JWT signature submodule is used to sign the user information using the JWT algorithm to obtain an initial token; the user information is located in the payload of the initial token; The encryption update submodule is used to symmetrically encrypt the load using a preset key, and use the encrypted load to update the initial token to obtain the first token; the preset key for symmetric encryption is mastered by the server.

6. A user token verification device, characterized in that: Applied to the server, the device comprises: A restoration module, configured to restore the user token into a first token and a second token by using a preset encoding method when receiving the user token sent by the client; A parsing module, used to parse the first token using a JWT algorithm to obtain first user information; A signature module, used to sign the first user information using a preset signature algorithm to obtain a third token; the type of the preset signature algorithm is mastered by the server; A verification module, configured to determine that the client has passed the verification when it is determined that the third token is consistent with the second token; The parsing module comprises: A JWT parsing submodule, configured to parse the first token using the JWT algorithm to obtain a payload in the first token; The decryption submodule is used to symmetrically decrypt the load using a preset key to obtain the first user information; the preset key for symmetrical encryption is mastered by the server.

7. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to execute the computer program to implement, when receiving user information sent by a client, signing the user information using a JWT algorithm to obtain a first token; Sign the user information using a preset signature algorithm to obtain a second token; The type of the preset signature algorithm is controlled by the server; Using a preset encoding method to concatenate the first token and the second token to obtain a user token, and sending the user token to the client; and / or, for implementing, when executing the computer program, restoring the user token into the first token and the second token by using a preset encoding method when receiving the user token sent by the client; Parse the first token using the JWT algorithm to obtain first user information; Sign the first user information using a preset signature algorithm to obtain a third token; The type of the preset signature algorithm is controlled by the server; When it is determined that the third token is consistent with the second token, determining that the client has passed the verification; The processor is further configured to use the JWT algorithm to sign the user information when executing the computer program to obtain an initial token; The user information is located in the payload of the initial token; Symmetrically encrypt the payload using a preset key, and use the encrypted payload to update the initial token to obtain the first token; The preset key for symmetric encryption is controlled by the server; and / or, further configured to implement, when executing the computer program, parsing the first token using the JWT algorithm to obtain the payload in the first token; Symmetrically decrypting the payload using a preset key to obtain the first user information; The preset key for symmetric encryption is controlled by the server.

8. The electronic device according to claim 7, characterized in that: The processor is further configured to, when executing the computer program, concatenate the first token and the second token using preset special characters to obtain an initial user token; and encode the initial user token to obtain the user token; and / or, further used to decode the user token and restore the initial user token when executing the computer program; The user token is split into the first token and the second token according to preset special characters.

9. A storage medium, characterized in that: The storage medium stores computer executable instructions, which, when loaded and executed by a processor, implement the user token generation method described in any one of claims 1 to 2 and / or the user token verification method described in any one of claims 3 to 4.

Citation Information

Patent Citations

  • Terminal safety communication method and system for emergency field

    CN110932844A