Information authentication method and device
By encrypting cookies on the server, the problem that user information in cookies is easily intercepted during communication is solved, and the security of user information is significantly improved.
Patent Information
- Application Number
- CN202111580518.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-22
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2041-12-22
AI Technical Summary
The user information recorded in the cookie is easily intercepted during the communication process, resulting in poor security of the user information.
When the user's identity authentication is passed, the server generates a cookie containing the user's identity information, and encrypts the cookie using the key sent by the client to send the encrypted cookie to the client.
By encrypting cookies, the risk of user information leakage due to cyber attacks and other factors is avoided, and the security of user information contained in cookies is improved.
Smart Images

Figure CN114238919B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to the field of data processing technology. Background Art
[0002] Cookies (data stored on the user's local terminal) are a mechanism for the client to save user identity information. They are used to record user information. When the client sends a login request to the server based on HTTP (Hyper Text Transfer Protocol), HTTP is stateless. Each time a login request reaches the server, the server does not know who the user is or whether he has logged in. In order to achieve automatic login, the client needs to send a cookie to the server, and the server determines the user's identity based on the user information recorded in the cookie, thereby achieving login. Since cookies are easily intercepted during the communication process, the security of the user information recorded in the cookie is poor. Summary of the invention
[0003] The purpose of the embodiment of the present invention is to provide an information authentication method and device to improve the security of user information. The specific technical solution is as follows:
[0004] In a first aspect, an embodiment of the present invention provides an information authentication method, which is applied to a server, and the method includes:
[0005] Receive a first login request sent by a client, wherein the first login request carries a first key and first user identity information;
[0006] authenticating the first user identity information based on the stored user identity information;
[0007] If the authentication is successful, a first cookie including the first user identity information is generated, and the first cookie is encrypted using the first key to obtain a second cookie;
[0008] A first response including the second Cookie and indicating successful user identity authentication is sent to the client.
[0009] In one embodiment of the present invention, in the case of passing the authentication, the method further comprises: storing a first corresponding relationship between the first user identity information and the first key;
[0010] The method further comprises:
[0011] Receiving a second login request sent by the client, wherein the second login request carries a second key and an encrypted third Cookie;
[0012] Decrypting the third Cookie using the second key to obtain the second user identity information contained in the third Cookie;
[0013] Based on the first corresponding relationship, determining whether there is a corresponding relationship between the second key and the second user identity information;
[0014] If yes, the second user identity information is authenticated, and if authenticated, a second response indicating successful user identity authentication is sent to the client.
[0015] In one embodiment of the present invention, the first login request also carries a service identifier, service activation time, and service validity period representing the activation of the periodic automatic login service. After obtaining the encrypted Cookie, the method further includes:
[0016] Storing a second correspondence between the first user identity information and the service activation time and the service validity period;
[0017] The authenticating the second user identity information includes:
[0018] Based on the second corresponding relationship, determine the service activation time and service validity period corresponding to the second user identity information;
[0019] Calculate the service validity period based on the determined service activation time and service validity period;
[0020] It is determined whether the sending time of the second login request is within the service validity period. If yes, it is determined that the second user identity information has been successfully authenticated.
[0021] In one embodiment of the present invention, the method further comprises:
[0022] Receiving a service cancellation request sent by the client, wherein the service cancellation request is used to request cancellation of an activated periodic automatic login service;
[0023] Delete the stored first correspondence relationship and the second correspondence relationship.
[0024] In a second aspect, an embodiment of the present invention provides an information authentication method, which is applied to a client, and the method includes:
[0025] In the case of detecting an operation of requesting to log in to a webpage, generating a first key;
[0026] Sending a first login request to the server, wherein the first login request carries a first key and first user identity information;
[0027] A first response sent by the server and carrying the encrypted first Cookie and indicating successful user identity authentication is received.
[0028] In one embodiment of the present invention, the method further comprises:
[0029] In the case of detecting an operation of re-requesting to log into the webpage after logging out of the webpage, sending a second login request to the server, wherein the second login request carries the first key and the encrypted first Cookie;
[0030] A second response sent by the server indicating successful user identity authentication is received.
[0031] In one embodiment of the present invention, the first login request also carries a service identifier indicating activation of the periodic automatic login service, a service activation time, and a service validity period.
[0032] In a third aspect, an embodiment of the present invention provides an information authentication device, applied to a server, the device comprising:
[0033] A first request receiving module, configured to receive a first login request sent by a client, wherein the first login request carries a first key and first user identity information;
[0034] A first information authentication module, used to authenticate the first user identity information based on the stored user identity information;
[0035] an information encryption module, used to generate a first cookie containing the first user identity information when the authentication is passed, and encrypt the first cookie using the first key to obtain a second cookie;
[0036] The response sending module is used to send a first response containing the second Cookie and indicating successful user identity authentication to the client.
[0037] In one embodiment of the present invention, the above device further includes:
[0038] A first correspondence storage module, used for storing a first correspondence between the first user identity information and the first key after the information encryption module passes the authentication;
[0039] The device also includes:
[0040] A second request receiving module, configured to receive a second login request sent by the client, wherein the second login request carries a second key and an encrypted third Cookie;
[0041] An information decryption module, used to decrypt the third Cookie using the second key to obtain the second user identity information contained in the third Cookie;
[0042] an information determination module, configured to determine whether there is a corresponding relationship between the second key and the second user identity information based on the first corresponding relationship; if yes, execute a second information authentication module,
[0043] The second information authentication module is used to authenticate the second user identity information, and if the authentication is successful, send a second response indicating successful user identity authentication to the client.
[0044] In one embodiment of the present invention, the first login request also carries a service identifier, service activation time, and service validity period representing the activation of the periodic automatic login service. After obtaining the encrypted Cookie, the device further includes:
[0045] A second corresponding relationship storage module, used for storing a second corresponding relationship between the first user identity information and the service activation time and the service validity period after the information encryption module passes the authentication;
[0046] The second information authentication module includes:
[0047] An information determination submodule, configured to determine, based on the second corresponding relationship, a service activation time and a service validity period corresponding to the second user identity information;
[0048] The time period calculation submodule is used to calculate the service effective time period based on the determined service activation time and service effective time period;
[0049] The information authentication submodule is used to determine whether the sending time of the second login request is within the service validity period. If yes, it is determined that the second user identity information has been successfully authenticated.
[0050] In one embodiment of the present invention, the above device further includes:
[0051] A third request receiving module, configured to receive a service cancellation request sent by the client, wherein the service cancellation request is used to request cancellation of an activated periodic automatic login service;
[0052] The information deletion module is used to delete the stored first corresponding relationship and the second corresponding relationship.
[0053] In a fourth aspect, an embodiment of the present invention provides an information authentication device, which is applied to a client, and the device includes:
[0054] A key generation module, configured to generate a first key when an operation requesting to log in to a web page is detected;
[0055] A first request sending module, configured to send a first login request to a server, wherein the first login request carries a first key and first user identity information;
[0056] The first response receiving module is used to receive a first response sent by the server, which carries an encrypted first Cookie and indicates that the user identity authentication is successful.
[0057] In one embodiment of the present invention, the above device further includes:
[0058] A second request sending module, configured to send a second login request to the server when detecting an operation of re-requesting to log into the webpage after logging out of the webpage, wherein the second login request carries the first key and the encrypted first Cookie;
[0059] The second response receiving module is used to receive a second response sent by the server indicating that the user identity authentication is successful.
[0060] In one embodiment of the present invention, the first login request also carries a service identifier indicating activation of the periodic automatic login service, a service activation time, and a service validity period.
[0061] In a fifth aspect, an embodiment of the present invention provides a server, including a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus;
[0062] Memory, used to store computer programs;
[0063] The processor is used to implement the method steps described in the first aspect when executing the program stored in the memory.
[0064] In a sixth aspect, an embodiment of the present invention provides a client, including a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus;
[0065] Memory, used to store computer programs;
[0066] The processor is used to implement the method steps described in the second aspect when executing the program stored in the memory.
[0067] In a seventh aspect, an embodiment of the present invention provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in the first aspect or the second aspect are implemented.
[0068] As can be seen from the above, when the solution provided in this embodiment is applied for information authentication, since the server generates a Cookie containing the user identity information when the user identity information is authenticated, the Cookie is encrypted using the key sent by the client, and the encrypted Cookie is sent to the client, thereby avoiding the risk of user information leakage due to factors such as network attacks, and improving the security of the user information contained in the Cookie.
[0069] Of course, it is not necessary to achieve all of the advantages described above at the same time to implement any product or method of the present invention. BRIEF DESCRIPTION OF THE DRAWINGS
[0070] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For ordinary technicians in this field, other embodiments can also be obtained based on these drawings.
[0071] Figure 1 A schematic diagram of a flow chart of a first information authentication method provided by an embodiment of the present invention;
[0072] Figure 2 A schematic diagram of a flow chart of a second information authentication method provided by an embodiment of the present invention;
[0073] Figure 3 A schematic diagram of a flow chart of a third information authentication method provided by an embodiment of the present invention;
[0074] Figure 4a A schematic diagram of a fourth information authentication method provided by an embodiment of the present invention;
[0075] Figure 4b A user interface provided by an embodiment of the present invention;
[0076] Figure 5 A schematic diagram of a fifth information authentication method provided by an embodiment of the present invention;
[0077] Figure 6a A signaling interaction diagram of the first information authentication method provided by an embodiment of the present invention;
[0078] Figure 6b A signaling interaction diagram of the first information authentication method provided by an embodiment of the present invention;
[0079] Figure 7 A schematic diagram of the structure of a first information authentication device provided by an embodiment of the present invention;
[0080] Figure 8 A schematic diagram of the structure of a second information authentication device provided by an embodiment of the present invention;
[0081] Fig. 9 A schematic diagram of the structure of a server provided in an embodiment of the present invention;
[0082] Fig.10 A schematic diagram of the structure of a client provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0083] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments in the present invention, all other embodiments obtained by ordinary technicians in this field based on this application belong to the scope of protection of the present invention.
[0084] See also Figure 1 , Figure 1 This is a flow chart of a first information authentication method provided by an embodiment of the present invention. The method is applied to a server and includes the following steps S101-S104.
[0085] Step S101: receiving a first login request sent by a client.
[0086] The first login request is used to request a login webpage. Usually, when accessing a webpage, a user needs to enter a user name and a password in the login page, and can successfully log in to the webpage if the server authenticates the user name and password.
[0087] The first login request carries the first key and the first user identity information.
[0088] The first user identity information is information used to represent the user's identity. The first user identity information may include user login account, login password, user name, client identifier, address of terminal device and other information.
[0089] The first key is: a key used to encrypt Cookie. The first key is a key generated by the client.
[0090] After receiving the first login request, the server may parse the first login request to obtain the first key and the first user identity information.
[0091] Step S102: authenticating the first user identity information based on the stored user identity information.
[0092] The stored user identity information includes: user identity information of registered users, which may include the login account, login password, user name and other information of the registered user.
[0093] In one implementation, when authenticating the first user identity information, it can be determined based on the user login account included in the first user identity information whether the above-mentioned user login account is recorded in the stored user identity information. If so, it is determined whether the login password corresponding to the user login account recorded in the stored user identity information is the login password in the first user identity information. If so, the authentication is normal; if not, the authentication fails.
[0094] Step S103: if the authentication is successful, generate a first cookie containing the identity information of the first user, and encrypt the first cookie using the first key to obtain a second cookie.
[0095] In one implementation, the first user identity information may be packaged, a first Cookie may be generated based on the packaged data, and the first Cookie may be encrypted using a preset encryption algorithm using a first key.
[0096] The above-mentioned preset encryption algorithm can be: DES (Data Encryption Standard), AES (Advanced Encryption Standard), MD5 (Message Digest Algorithm5), Hash, etc.
[0097] Step S104: Sending a first response carrying the second Cookie and indicating successful user identity authentication to the client.
[0098] After the server sends the first response to the client, the client may parse the first response, obtain the second cookie carried in the first response, and store the second cookie locally.
[0099] As can be seen from the above, when the solution provided in this embodiment is applied for information authentication, since the server generates a Cookie containing the user identity information when the user identity information is authenticated, the Cookie is encrypted using the key sent by the client, and the encrypted Cookie is sent to the client, thereby avoiding the risk of user information leakage due to factors such as network attacks, and improving the security of the user information contained in the Cookie.
[0100] In the case that the authentication is passed in the above step S102, the following may also be included: Figure 2 Step S204 of the embodiment shown in the figure, based on this, the above method may also include the following Figure 2 Steps S206-S209 of the illustrated embodiment.
[0101] See also Figure 2 , Figure 2 This is a flow chart of a second information authentication method provided by an embodiment of the present invention. The method includes the following steps S201-S209.
[0102] Step S201: receiving a first login request sent by a client.
[0103] The first login request carries the first key and the first user identity information.
[0104] Step S202: authenticating the first user identity information based on the stored user identity information.
[0105] Step S203: if the authentication is successful, generate a first cookie containing the identity information of the first user, and encrypt the first cookie using the first key to obtain a second cookie.
[0106] The above steps S201-S203 are the same as the above steps Figure 1 In the illustrated embodiment, steps S101 - S103 are the same and will not be described in detail herein.
[0107] Step S204: storing a first corresponding relationship between the first user identity information and the first key.
[0108] When the authentication is successful, the server stores the corresponding relationship between the first user identity information and the first key.
[0109] For example, as shown in Table 1, Table 1 shows the corresponding relationship between user identity information and the key.
[0110] Table 1
[0111]
[0112] Specifically, the process of obtaining the second Cookie in the above step S203 and the above step S204 can be executed in parallel, or the above two steps can be executed serially, such as the process of obtaining the second Cookie in step S203 can be executed first, and then step S204 can be executed, or step S204 can be executed first, and then the process of obtaining the second Cookie in step S203 can be executed.
[0113] Step S205: Sending a first response carrying the second Cookie and indicating successful user identity authentication to the client.
[0114] The above step S205 is the same as the above Figure 1 Step S104 in the illustrated embodiment is the same and will not be described in detail here.
[0115] Step S206: receiving a second login request sent by the client.
[0116] After step S205, the user can access the web page through the user interface of the client. After closing the web page, if the user needs to access the web page again, in this case, the client needs to send a login request to the server again, that is, the second login request.
[0117] The second login request carries the second key and the encrypted third Cookie.
[0118] After receiving the second login request, the server may parse the second login request to obtain the second key and the encrypted third Cookie.
[0119] Step S207: Decrypt the third Cookie using the second key to obtain the second user identity information contained in the third Cookie.
[0120] In one implementation, the third Cookie may be decrypted using the second key through a preset decryption algorithm. The preset decryption algorithm may be a decryption algorithm of the encryption algorithm mentioned in the aforementioned step S103.
[0121] Since the Cookie contains the user identity information, after the third Cookie is decrypted using the second key, the second user identity information contained in the third Cookie can be obtained.
[0122] Step S208: Based on the first corresponding relationship, determine whether there is a corresponding relationship between the second key and the second user identity information. If yes, execute step S209.
[0123] The first corresponding relationship mentioned above is: the corresponding relationship between the key and the user identity information.
[0124] In one implementation, the key corresponding to the second user identity information can be determined from the first corresponding relationship, and it is determined whether the determined key is the same as the second key. If so, it indicates that there is a corresponding relationship between the second key and the second user identity information, and step S209 is executed; if not, it indicates that there is no corresponding relationship between the second key and the second user identity information, and the process ends.
[0125] Step S209: authenticating the second user identity information, and if the authentication is successful, sending a second response indicating successful user identity authentication to the client.
[0126] In one implementation, when authenticating the second user identity information, it can be determined based on the user login account included in the second user identity information whether the above-mentioned user login account is recorded in the stored user identity information. If so, it is determined whether the login password corresponding to the user login account recorded in the stored user identity information is the login password in the second user identity information. If so, the authentication is normal; if not, the authentication fails.
[0127] As can be seen from the above, after receiving the second login request, the server first verifies whether there is a correspondence between the second key and the second user identity information. After the verification is passed, the second user identity information is authenticated. In this way, the security of information authentication is improved through two authentications.
[0128] exist Figure 2 In step S201 of the illustrated embodiment, the first login request may carry not only the first key and the first user identity information, but also a service identifier representing activation of the periodic automatic login service, service activation time, and service validity period.
[0129] The above-mentioned periodic automatic login service refers to a service that can automatically log in to a web page within the login validity period without entering a user account and password.
[0130] When the first login request carries the service identifier indicating activation of the periodic automatic login service, it indicates that the user has selected the periodic automatic login service.
[0131] The above service activation time refers to the time when the above periodic automatic login service is activated.
[0132] The validity period of the above service refers to the period of time during which the user uses the above periodic automatic login service. The validity period of the above service can be: one day, one week, two weeks, one month, three months, six months, one year, etc.
[0133] Based on the above situation, in the above Figure 2 After step 203 of the illustrated embodiment, the following steps may also be included: Figure 3 Step 304 of the embodiment shown is based on the above step S304. Figure 2 When the second user identity information is authenticated in step S209 of the illustrated embodiment, the following steps may be followed: Figure 3 In the illustrated embodiment, steps S310 - S312 are implemented.
[0134] See also Figure 3 , Figure 3This is a flow chart of a third information authentication method provided by an embodiment of the present invention. The method includes the following steps S301-S312.
[0135] Step S301: receiving a first login request sent by a client.
[0136] The first login request carries the first key and the first user identity information.
[0137] Step S302: authenticating the first user identity information based on the stored user identity information.
[0138] Step S303: if the authentication is successful, generate a first cookie containing the identity information of the first user, and encrypt the first cookie using the first key to obtain a second cookie.
[0139] Step S304: storing a first corresponding relationship between the first user identity information and the first key.
[0140] The above steps S301-S304 are the same as the above Figure 2 The steps S201-S204 shown are the same and will not be described in detail here.
[0141] Step S305: storing a second correspondence between the first user identity information and the service activation time and the service validity period.
[0142] In the case of passing the authentication, the server may also store the correspondence between the first user identity information and the service activation time and the service validity period.
[0143] For example, as shown in Table 2, Table 2 shows the corresponding relationship between user identity information, service activation time, and service validity period.
[0144] Table 2
[0145] User identity information Service opening time Service validity period User login account: yy 2021-1-1 24h
[0146] Specifically, the above steps S304 and S305 may be executed in parallel or in series. For example, step S304 may be executed first and then step S305; or step S305 may be executed first and then step S304.
[0147] Step S306: Sending a first response carrying the second Cookie and indicating successful user identity authentication to the client.
[0148] Step S307: receiving a second login request sent by the client.
[0149] The second login request carries the second key and the encrypted third Cookie.
[0150] Step S308: Use the second key to decrypt the third Cookie to obtain the second user identity information contained in the third Cookie.
[0151] Step S309: Based on the first corresponding relationship, determine whether there is a corresponding relationship between the second key and the second user identity information. If yes, execute step S310.
[0152] The above steps S306 to S309 are the same as the above Figure 2 In the illustrated embodiment, steps S205-S208 are the same and will not be described in detail herein.
[0153] Step S310: Based on the second corresponding relationship, determine the service activation time and service validity period corresponding to the second user identity information.
[0154] In one implementation, the service activation time and service validity period corresponding to the second user identity information may be determined from the second corresponding relationship.
[0155] Step S311: Calculate the service validity period based on the determined service activation time and service validity period.
[0156] In one implementation, the time from the service activation time to the time of the service validity period may be calculated, and the time period between the service activation time and the calculated time period may be determined as the service validity period.
[0157] For example: the service activation time is: 2021-1-1, the service validity period is: 24h*30, that is, one month, the service activation time is extended one month later to: 2021-1-30, so the service validity period is: 2021-1-1~2021-1-30.
[0158] Step S312: Determine whether the sending time of the second login request is within the service validity period. If yes, determine that the second user identity information has been successfully authenticated, and send a second response indicating successful user identity authentication to the client.
[0159] When the sending time of the second login request is within the service validity period, it means that it is within the validity period of the automatic login service. In this case, the automatic login service can be provided to the user; when the sending time of the second login request is not within the service validity period, it means that the validity period of the automatic login service has exceeded. In this case, the automatic login service is not provided to the user and the process ends.
[0160] In one implementation, the request sending time obtained by parsing the second login request can be used to determine whether the request sending time is within the service validity period. If so, an automatic login service is provided to the user. If not, the client can be instructed to display a login interface in the user interface so that the user can log in again using the user account and password.
[0161] For example: the request sending time is: 2021-1-28, the service validity period is: 2021-1-30, and the request sending time is within the service validity period. In this case, it means that the second user identity information has successfully passed the authentication, and the user is provided with automatic login service; if the request sending time is 2021-1-31, the above request sending time is not within the service validity period. In this case, the client can be instructed to display the login interface in the user interface, so that the user can log in again using the user account and password.
[0162] From the above, it can be seen that when the sending time of the second login request is within the service validity period, it means that it is within the validity period of the automatic login service. When the sending time of the second login request is not within the service validity period, it means that the validity period of the automatic login service has been exceeded. Therefore, through the sending time of the second login request, it is possible to more accurately judge whether the provided automatic login service is within the service validity period, thereby improving the accuracy of information authentication.
[0163] In one embodiment of the present invention, if the server receives a service cancellation request sent by the client, the stored first corresponding relationship and the second corresponding relationship are deleted.
[0164] The first corresponding relationship is: the corresponding relationship between the first user identity information and the first key, and the second corresponding relationship is: the corresponding relationship between the first user identity information and the service activation time and the service validity period.
[0165] The service cancellation request is used to request the cancellation of the activated automatic login service. In this case, the server deletes the first correspondence and the second correspondence. Even if the client sends an encrypted cookie later, the server cannot authenticate the user identity information in the cookie based on the locally stored correspondence, thereby successfully avoiding the continued provision of the automatic login service.
[0166] Corresponding to the above-mentioned information authentication method applied to the server, an embodiment of the present invention provides an information authentication method applied to the client.
[0167] See also Figure 4a , Figure 4aThis is a flow chart of a fourth information authentication method provided by an embodiment of the present invention. The method is applied to a client and includes the following steps S401-S403.
[0168] Step S401: when an operation of requesting to log in to a web page is detected, a first key is generated.
[0169] If a user needs to access a web page, the login page of the web page needs to be displayed in the user interface of the client. After the user enters the user account and password in the login page, clicks the login button, indicating a request to log in to the web page. If the client detects a click operation on the login button, it indicates that the user requests to log in to the web page.
[0170] Specifically, the first key may be generated according to the following two implementation modes.
[0171] In a first implementation manner, a preset number of characters may be randomly selected from preset characters, and the selected characters may be arranged and combined to serve as the first key.
[0172] For example: the preset characters are: a, b, c, ..., x, y, z, 1, 2, 3, ..., 9. The client can randomly select 10 characters from the preset characters, such as a, c, o, t, y, z, 1, 2, 5, 8, 9, and arrange and combine the selected characters to obtain a1c2o5t8y9z as the first key.
[0173] In a second implementation, a key is randomly selected from preset keys as the first key. The preset key may be a pre-generated key.
[0174] Step S402: Send a first login request to the server.
[0175] The first login request is used to request a login webpage. The first login request carries a first key and first user identity information.
[0176] In one implementation, the client may send a first login request to the server based on the Http protocol.
[0177] The client user interface can also provide an option to enable the automatic login service and the service activation period, such as Figure 4b As shown, Figure 4b A user interface is shown.
[0178] exist Figure 4bThe user interface shown is a login interface, which includes a user name input box, a static password and a dynamic password input box, an application dynamic password button, a selection box indicating whether to activate the automatic login service, and an input box for the validity period of the automatic login service. When the user checks the "Select automatic login service" selection box, it means that the user needs to activate the automatic login service, and when the user enters the service validity period within the validity period, it means that the user determines the validity period of the automatic login service.
[0179] If the client detects the above operations performed by the user in the user interface, it can obtain an identifier representing whether the user has activated the automatic login service, as well as the validity period of the service, and determine the activation time of the automatic login service for the user based on the time when the user performs the operation. Based on this, in one embodiment of the present invention, the above first login request can also carry a service identifier representing the activation of the periodic automatic login service, the service activation time, and the validity period of the service.
[0180] Step S403: receiving a first response sent by the server, which carries the encrypted first Cookie and indicates successful user identity authentication.
[0181] The client receives the first response, indicating that the user identity information has been successfully authenticated. On this basis, the client can jump to the web page to be logged in in the user interface of the client.
[0182] After receiving the first response, the client may parse the first response, obtain the encrypted first Cookie, and store the first Cookie locally.
[0183] As can be seen from the above, after detecting the operation of requesting to log in to the web page, the client generates a first key and sends a first login request containing the first key and the first user identity information to the server. The server can then use the first key to encrypt the Cookie containing the first user identity information when the first user identity information is authenticated. The client receives the encrypted first Cookie, thereby improving the security of the user identity information in the Cookie.
[0184] In the aforementioned Figure 4a After the embodiment shown, the following may also be included Figure 5 Steps S504-S505 of the illustrated embodiment. Figure 5 , Figure 5 This is a flowchart of a fifth information authentication method provided by an embodiment of the present invention. The method includes the following steps S501-S505.
[0185] Step S501: when an operation of requesting to log in to a web page is detected, a first key is generated.
[0186] Step S502: Send a first login request to the server.
[0187] The first login request carries the first key and the first user identity information.
[0188] Step S503: receiving a first response sent by the server, which carries the encrypted first Cookie and indicates successful user identity authentication.
[0189] The above steps S501-S503 are the same as the above Figure 4a In the illustrated embodiment, steps S401 - S403 are the same and will not be described in detail herein.
[0190] Step S504: When an operation of re-requesting to log in to the webpage after logging out of the webpage is detected, a second login request is sent to the server.
[0191] Since in the above step S503, after receiving the first response, the client can jump to the web page to be logged in in the user interface, when the user exits the current web page and needs to re-enter the login web page, it is necessary to re-send a login request to the server, that is, the above-mentioned second login request.
[0192] The second login request carries the first key and the encrypted first Cookie.
[0193] Step S505: Receive a second response sent by the server indicating successful user identity authentication.
[0194] When the second response sent by the server is received, it means that the server has successfully authenticated the user identity information contained in the first Cookie. In this case, you can jump to the web page to be logged in in the user interface again.
[0195] The following is combined with the following Figure 6a , Figure 6b The signaling diagram specifically illustrates the above information authentication process.
[0196] See also Figure 6a , Figure 6a A signaling interaction diagram of the first information authentication method provided in an embodiment of the present invention.
[0197] Figure 6a It includes a Portal server and a Radius server. The above two servers are two virtual servers on the same electronic device for implementing different functions. The Portal server is used to receive and process data sent by the client, and the Radius server is used to authenticate user identity information.
[0198] Figure 6aThe information authentication process shown is: the process of authenticating the user identity information for the first time. Figure 6a The following steps S610-S617 are included.
[0199] Step S610: the client sends a login request to the server, wherein the login request includes user identity information, a key, a service identifier representing activation of a periodic automatic login service, service activation time, service validity period, etc.
[0200] Step S611: after receiving the login request, the Portal server sends an information authentication request to the Radius server. The information authentication request carries user identity information, service activation time, and service validity period.
[0201] Step S612: The Radius server authenticates the user identity information, and after the authentication is passed, stores the corresponding relationship between the user identity information and the service activation time and the service validity period.
[0202] Step S613: Send a response indicating successful authentication to the Portal server.
[0203] Step S614: After receiving the response sent by the Radius server, the Portal server stores the corresponding relationship between the user identity information and the service activation time, service validity period, and key.
[0204] Step S615: The Portal server generates a Cookie containing the user identity information, and encrypts the Cookie using a key.
[0205] Step S616: Send a successful authentication response to the client, carrying the encrypted Cookie information.
[0206] Step S617: After receiving the above response, the client parses the above response to obtain the encrypted Cookie, and jumps to the web page to be logged in in the user interface.
[0207] See also Figure 6b , Figure 6b A signaling interaction diagram of the second information authentication method provided in an embodiment of the present invention.
[0208] Figure 6b The information authentication process shown is a process of authenticating the user identity information within the effective time period of the automatic login service. Figure 6b The following steps S620-S629 are included.
[0209] Step S620: The client sends a login request to the server, wherein the login request includes the encrypted Cookie and key.
[0210] Step S621: After receiving the login request, the Portal server uses the key to decrypt the encrypted Cookie to obtain the user identity information.
[0211] Step S622: The Portal server verifies the user identity information based on the locally stored key and identity information, and after the verification is successful, executes step S623.
[0212] Step S623: The Portal server determines the service activation time and service validity period corresponding to the user identity information based on the correspondence between the locally stored identity information and the service activation time and service validity period.
[0213] Step S624: Send an information authentication request including the above user identity information, login request sending time, service activation time and service validity period to the Radius server.
[0214] Step S625: The Radius server authenticates the user identity information.
[0215] Specifically, when performing authentication, Radius can determine the service validity period based on the service activation time and the service validity period. If it is determined that the login request is sent within the above-mentioned valid period, a response of successful authentication containing information including the password of the user's login account is sent to the Portal server. If it is determined that the login request is sent not within the above-mentioned valid period, a response of failed authentication is sent to the Portal server.
[0216] Step S626: After receiving the successful authentication response from the Radius server, the Portal server sends the password of the user login account to the client.
[0217] Step S627: The client jumps to the web page to be logged in on the user interface based on the above password.
[0218] Step S628: After receiving the information authentication failure response sent by the Radius server, the Portal server sends an information authentication failure response to the client.
[0219] Step S629: The client displays a login interface on the user interface based on the above response.
[0220] Corresponding to the above-mentioned information authentication method applied to a server, an embodiment of the present invention further provides an information authentication device applied to a server.
[0221] See also Figure 7 , Figure 7This is a schematic diagram of the structure of a first information authentication device provided in an embodiment of the present invention, which is applied to a server. The device includes the following modules 701-704.
[0222] A first request receiving module 701 is configured to receive a first login request sent by a client, wherein the first login request carries a first key and first user identity information;
[0223] A first information authentication module 702, configured to authenticate the first user identity information based on the stored user identity information;
[0224] The information encryption module 703 is used to generate a first cookie containing the first user identity information when the authentication is passed, and encrypt the first cookie using the first key to obtain a second cookie;
[0225] The response sending module 704 is used to send a first response containing the second Cookie and indicating successful user identity authentication to the client.
[0226] As can be seen from the above, when the solution provided in this embodiment is applied for information authentication, since the server generates a Cookie containing the user identity information when the user identity information is authenticated, the Cookie is encrypted using the key sent by the client, and the encrypted Cookie is sent to the client, thereby avoiding the risk of user information leakage due to factors such as network attacks, and improving the security of the user information contained in the Cookie.
[0227] In one embodiment of the present invention, the above device further includes:
[0228] A first correspondence storage module, used for storing a first correspondence between the first user identity information and the first key after the information encryption module 703 passes the authentication;
[0229] The device also includes:
[0230] A second request receiving module, configured to receive a second login request sent by the client, wherein the second login request carries a second key and an encrypted third Cookie;
[0231] An information decryption module, used to decrypt the third Cookie using the second key to obtain the second user identity information contained in the third Cookie;
[0232] an information determination module, configured to determine whether there is a corresponding relationship between the second key and the second user identity information based on the first corresponding relationship; if yes, execute a second information authentication module,
[0233] The second information authentication module is used to authenticate the second user identity information, and if the authentication is successful, send a second response indicating successful user identity authentication to the client.
[0234] As can be seen from the above, after receiving the second login request, the server first verifies whether there is a correspondence between the second key and the second user identity information. After the verification is passed, the second user identity information is authenticated. In this way, the security of information authentication is improved through two authentications.
[0235] In one embodiment of the present invention, the first login request also carries a service identifier, service activation time, and service validity period representing the activation of the periodic automatic login service. After obtaining the encrypted Cookie, the device further includes:
[0236] A second correspondence storage module, used for storing a second correspondence between the first user identity information and the service activation time and the service validity period after the information encryption module 703 passes the authentication;
[0237] The second information authentication module includes:
[0238] An information determination submodule, configured to determine, based on the second corresponding relationship, a service activation time and a service validity period corresponding to the second user identity information;
[0239] The time period calculation submodule is used to calculate the service effective time period based on the determined service activation time and service effective time period;
[0240] The information authentication submodule is used to determine whether the sending time of the second login request is within the service validity period. If yes, it is determined that the second user identity information has been successfully authenticated.
[0241] From the above, it can be seen that when the sending time of the second login request is within the service validity period, it means that it is within the validity period of the automatic login service. When the sending time of the second login request is not within the service validity period, it means that the validity period of the automatic login service has been exceeded. Therefore, through the sending time of the second login request, it is possible to more accurately judge whether the provided automatic login service is within the service validity period, thereby improving the accuracy of information authentication.
[0242] In one embodiment of the present invention, the above device further includes:
[0243] A third request receiving module, configured to receive a service cancellation request sent by the client, wherein the service cancellation request is used to request cancellation of an activated periodic automatic login service;
[0244] The information deletion module is used to delete the stored first corresponding relationship and the second corresponding relationship.
[0245] The service cancellation request is used to request the cancellation of the activated automatic login service. In this case, the server deletes the first correspondence and the second correspondence. Even if the client sends an encrypted cookie later, the server cannot authenticate the user identity information in the cookie based on the locally stored correspondence, thereby successfully avoiding the continued provision of the automatic login service.
[0246] Corresponding to the above-mentioned information authentication method applied to the client, an embodiment of the present invention further provides an information authentication device applied to the client.
[0247] See also Figure 8 , Figure 8 The second information authentication device provided by the embodiment of the present invention is applied to a client, and the device includes the following modules 801-803.
[0248] The key generation module 801 is used to generate a first key when an operation of requesting to log in to a web page is detected;
[0249] A first request sending module 802, configured to send a first login request to a server, wherein the first login request carries a first key and first user identity information;
[0250] The first response receiving module 803 is used to receive a first response sent by the server, which carries the encrypted first Cookie and indicates that the user identity authentication is successful.
[0251] As can be seen from the above, after detecting the operation of requesting to log in to the web page, the client generates a first key and sends a first login request containing the first key and the first user identity information to the server. The server can then use the first key to encrypt the Cookie containing the first user identity information when the first user identity information is authenticated. The client receives the encrypted first Cookie, thereby improving the security of the user identity information in the Cookie.
[0252] In one embodiment of the present invention, the above device further includes:
[0253] A second request sending module, configured to send a second login request to the server when detecting an operation of re-requesting to log into the webpage after logging out of the webpage, wherein the second login request carries the first key and the encrypted first Cookie;
[0254] The second response receiving module is used to receive a second response sent by the server indicating that the user identity authentication is successful.
[0255] In one embodiment of the present invention, the first login request also carries a service identifier indicating activation of the periodic automatic login service, a service activation time, and a service validity period.
[0256] The embodiment of the present invention also provides a server, such as Fig. 9 As shown, it includes a processor 901, a communication interface 902, a memory 903 and a communication bus 904, wherein the processor 901, the communication interface 902, and the memory 903 communicate with each other through the communication bus 904.
[0257] Memory 903, used for storing computer programs;
[0258] The processor 901 is used to implement the above-mentioned information authentication method applied to the server when executing the program stored in the memory 903.
[0259] The communication bus mentioned in the above server can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0260] The communication interface is used for communication between the above server and other devices.
[0261] The memory may include a random access memory (RAM) or a non-volatile memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.
[0262] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0263] The embodiment of the present invention also provides a client, such as Fig.10 As shown, it includes a processor 1001, a communication interface 1002, a memory 1003 and a communication bus 1004, wherein the processor 1001, the communication interface 1002, and the memory 1003 communicate with each other through the communication bus 1004.
[0264] Memory 1003, used for storing computer programs;
[0265] The processor 1001 is used to implement the above-mentioned information authentication method applied to the client when executing the program stored in the memory 1003.
[0266] The communication bus mentioned by the client above may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. The communication bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, only one thick line is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0267] The communication interface is used for communication between the above-mentioned client and other devices.
[0268] The memory may include a random access memory (RAM) or a non-volatile memory (NVM), such as at least one disk memory. Optionally, the memory may also be at least one storage device located away from the aforementioned processor.
[0269] The above-mentioned processor can be a general-purpose processor, including a central processing unit (CPU), a network processor (NP), etc.; it can also be a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0270] In another embodiment of the present invention, a computer-readable storage medium is provided, in which a computer program is stored. When the computer program is executed by a processor, the steps of the above-mentioned information authentication method applied to a server or a client are implemented.
[0271] In another embodiment of the present invention, a computer program product including instructions is provided, which, when executed on a computer, enables the computer to execute the above-mentioned information authentication method applied to a server or a client.
[0272] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware or any combination thereof. When implemented by software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the process or function described in the embodiment of the present invention is generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from a website site, computer, server or data center to another website site, computer, server or data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more available media integrated. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk Solid State Disk (SSD)), etc.
[0273] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
[0274] Each embodiment in this specification is described in a related manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.
[0275] The above description is only a preferred embodiment of the present invention and is not intended to limit the protection scope of the present invention. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention are included in the protection scope of the present invention.
Claims
1. An information authentication method, characterized in that: Applied to a server, the method comprises: Receive a first login request sent by a client, wherein the first login request carries a first key and first user identity information; authenticating the first user identity information based on the stored user identity information; If the authentication is successful, a first cookie including the first user identity information is generated, and the first cookie is encrypted using the first key to obtain a second cookie; Sending a first response to the client, which includes the second Cookie and indicates that the user identity authentication is successful; In the case of passing the authentication, the method further comprises: storing a first corresponding relationship between the first user identity information and the first key; The method further comprises: Receiving a second login request sent by the client, wherein the second login request carries a second key and an encrypted third Cookie; Decrypting the third Cookie using the second key to obtain the second user identity information contained in the third Cookie; Based on the first corresponding relationship, determining whether there is a corresponding relationship between the second key and the second user identity information; If yes, the second user identity information is authenticated, and if authenticated, a second response indicating successful user identity authentication is sent to the client.
2. The method according to claim 1, characterized in that The first login request also carries a service identifier, service activation time, and service validity period for activating a periodic automatic login service. After obtaining the encrypted Cookie, the method further includes: Storing a second correspondence between the first user identity information and the service activation time and the service validity period; The authenticating the second user identity information includes: Based on the second corresponding relationship, determine the service activation time and service validity period corresponding to the second user identity information; Calculate the service validity period based on the determined service activation time and service validity period; It is determined whether the sending time of the second login request is within the service validity period. If yes, it is determined that the second user identity information has been successfully authenticated.
3. The method according to claim 2, characterized in that The method further comprises: Receiving a service cancellation request sent by the client, wherein the service cancellation request is used to request cancellation of an activated periodic automatic login service; Delete the stored first correspondence relationship and the second correspondence relationship.
4. An information authentication method, characterized in that: Applied to a client, the method comprises: In the case of detecting an operation of requesting to log in to a webpage, generating a first key; Sending a first login request to the server, wherein the first login request carries a first key and first user identity information; Receiving a first response sent by the server that carries the encrypted first Cookie and indicates successful user identity authentication; In case of receiving the first response, the method further comprises: Sending a second login request to the server, wherein the second login request carries a second key and an encrypted third Cookie; If the authentication is successful, a second response sent by the server and carrying an encrypted third Cookie indicating successful user identity authentication is received.
5. The method according to claim 4, characterized in that The method further comprises: In the case of detecting an operation of re-requesting to log into the webpage after logging out of the webpage, sending a second login request to the server, wherein the second login request carries the first key and the encrypted first Cookie; A second response sent by the server indicating successful user identity authentication is received.
6. The method according to claim 4 or 5, characterized in that: The first login request also carries a service identifier indicating activation of the periodic automatic login service, a service activation time, and a service validity period.
7. An information authentication device, characterized in that: Applied to a server, the device comprises: A first request receiving module, configured to receive a first login request sent by a client, wherein the first login request carries a first key and first user identity information; A first information authentication module, used to authenticate the first user identity information based on the stored user identity information; an information encryption module, used to generate a first cookie containing the first user identity information when the authentication is passed, and encrypt the first cookie using the first key to obtain a second cookie; A response sending module, used for sending a first response including the second Cookie and indicating successful user identity authentication to the client; A first correspondence storage module, used for storing a first correspondence between the first user identity information and the first key after the information encryption module passes the authentication; A second request receiving module, configured to receive a second login request sent by the client, wherein the second login request carries a second key and an encrypted third Cookie; An information decryption module, used to decrypt the third Cookie using the second key to obtain the second user identity information contained in the third Cookie; an information determination module, configured to determine whether there is a corresponding relationship between the second key and the second user identity information based on the first corresponding relationship; if yes, execute a second information authentication module, The second information authentication module is used to authenticate the second user identity information, and if the authentication is successful, send a second response indicating successful user identity authentication to the client.
8. The device according to claim 7, characterized in that The first login request also carries a service identifier, a service activation time, and a service validity period, indicating that the regular automatic login service is activated. After obtaining the encrypted Cookie, the device further includes: A second corresponding relationship storage module, used for storing a second corresponding relationship between the first user identity information and the service activation time and the service validity period after the information encryption module passes the authentication; The second information authentication module includes: An information determination submodule, configured to determine, based on the second corresponding relationship, a service activation time and a service validity period corresponding to the second user identity information; The time period calculation submodule is used to calculate the service effective time period based on the determined service activation time and service effective time period; The information authentication submodule is used to determine whether the sending time of the second login request is within the service validity period. If yes, it is determined that the second user identity information has been successfully authenticated.
9. The device according to claim 8, characterized in that The device also includes: A third request receiving module, configured to receive a service cancellation request sent by the client, wherein the service cancellation request is used to request cancellation of an activated periodic automatic login service; The information deletion module is used to delete the stored first corresponding relationship and the second corresponding relationship.
10. A server, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, for implementing the method steps described in any one of claims 1 to 3 when executing a program stored in a memory.
11. A client, characterized in that: It includes a processor, a communication interface, a memory and a communication bus, wherein the processor, the communication interface and the memory communicate with each other through the communication bus; Memory, used to store computer programs; A processor, for implementing the method steps described in any one of claims 4 to 6 when executing a program stored in a memory.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method steps described in any one of claims 1-3 or 4-6 are implemented.
Citation Information
Patent Citations
Single sign on method, application client side, browser, terminal and server
CN104753855A