A Cross-Platform Authentication Method and Device Based on 5G Messages
By using encrypted splicing parameters to generate cipher text strings in 5G message applications, the problem of malicious rewritten and repeated registration of client authentication information is solved, and the secure transmission of authentication information and a simplified registration process are realized.
Patent Information
- Application Number
- CN202210761759.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-06-30
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2042-06-30
AI Technical Summary
In 5G messaging applications, the authentication information of the client is transmitted explicitly on the network, which is at risk of malicious modification by criminals, resulting in malicious authentication of the second-party application server. At the same time, the user needs to repeat the registration process when entering the second-party application server for the first time.
Through the first application server splicing parameters, the second application server encrypts the splicing parameters to generate a cryptographic text string, and the client carries the cryptographic text string to access the second application server, thereby solving the problem of malicious rewritten authentication information. At the same time, the registration process is directly completed on the second application server using the cipher text string, avoiding repeated registration.
It effectively prevents the client authentication information from being maliciously rewritten, ensures the security of the second-party application server, and simplifies the user's registration process, avoiding the steps of repeated registration.
Smart Images

Figure CN115002773B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of computers and 5G message applications. Specifically, it relates to a cross-platform authentication method and device based on 5G messages. Background Art
[0002] In 5G message applications, for the existing authentication request initiated by the 5G message application client to the second-party application server, the client first authenticates on the 5G message platform and obtains the authentication information. Then, the client uses the authentication information as a parameter to initiate an access request to the second-party application server. The second-party application server obtains the request parameters and performs an authentication operation. If the authentication is successful, the client is allowed to authenticate the second-party application server. Since the client authentication information is transmitted in plain text over the network when the client initiates the request, there is a problem that the authentication information may be modified by criminals on the client side, maliciously authenticating the second-party application server. The method provided by the present invention, where the first application server splices parameters, the second application server encrypts the spliced parameters to generate a ciphertext string, and the client carries the ciphertext string to access and authenticate the second application server, solves the problem of malicious rewriting of the client authentication information. On the other hand, when entering the second-party application server from 5G messages, users need to register for the first time. It requires short message distribution and user feedback via short messages to complete the registration. The solution of the present invention does not require short message distribution and user feedback via short messages. Instead, it directly completes the registration process on the second application server by decrypting the authentication information of the user on the first application server. This solves the problem of repeated registration on the second application server. Summary of the Invention
[0003] To solve the problem of illegal rewriting of client authentication information in 5G message applications. The method provided by the present invention, where the first application server splices parameters, the second application server encrypts the spliced parameters to generate a ciphertext string, and the client carries the ciphertext string to access the second application server, solves the problem of malicious rewriting of the client authentication information.
[0004] A cross-platform authentication method based on 5G messages includes:
[0005] Responding to a call request from the first application server, the parameters of the call request content include a first application string, and the first application string is generated by the first application server by splicing the request parameters of the client;
[0006] Parsing the call request, performing parameter splicing and calculating to obtain a ciphertext string, and returning the ciphertext string to the first application server. The first application server synchronously transmits the ciphertext string to the client, and the client performs a caching operation on the ciphertext string;
[0007] The client authentication request, the client authentication request parameter is the ciphertext string. For the ciphertext string, perform the authentication operation. If the authentication is successful, determine that the authentication is valid and return a success code. If the authentication fails, return an error code.
[0008] Further, the client is a 5G message card application terminal.
[0009] Further, in response to the first application server call request, where the call request is a synchronous request initiated by the client and passed through the first application server.
[0010] Further, parse the call request, perform parameter splicing and calculate to obtain the ciphertext string. The calculation to obtain the ciphertext string is the ciphertext string obtained by AES encryption calculation, and the AES encryption key is the MD5 calculation value of the first application string.
[0011] Further, the client performs a caching operation on the ciphertext string. The caching operation includes caching the ciphertext string in the client Cookie variable.
[0012] Further, in response to the client authentication request, where the authentication request is initiated from the menu application within the 5G message application terminal.
[0013] Further, in response to the client authentication request, the client authentication request parameter is the ciphertext string. Parse the ciphertext string and perform the authentication operation, including decrypting the ciphertext string using the AES algorithm, and the AES decryption key is the MD5 calculation value of the first application string.
[0014] The present invention also provides a 5G message cross-platform authentication device, including:
[0015] A first application server call response module, used to respond to the first application server call request and parse the first application server call parameters;
[0016] An MD5 parameter splicing unit, used to perform the splicing of the first application server request parameters. The parameter splicing includes calculating the MD5 of the request parameters and obtaining a 32-bit MD5 string, splicing the MD5 string with the request parameters, and caching the MD5 string in the server Session variable;
[0017] An AES encryption unit, used to splice the request parameters of the first application server with the MD5 string, perform AES encryption calculation and obtain the ciphertext string;
[0018] A network transmission module, used to establish a network communication connection between the server and the client;
[0019] An authentication module, used to respond to the client authentication request;
[0020] An AES decryption unit for performing AES decryption operations on authentication request parameters.
[0021] Furthermore, there are an AES encryption unit and an AES decryption unit. When performing operations of AES encryption and AES decryption, the key used is the MD5 calculated value of the first application server request parameters.
[0022] Furthermore, the AES decryption operation of the authentication request parameters includes performing AES decryption calculation on the request parameters and determining the result. If the decryption is successful, obtain the MD5 string of the request parameters and compare it with the MD5 string cached by the second application server. If the strings are equal, the authentication request is valid.
[0023] The technical solution of this application provides a method for the first application server to splice parameters, the second application server to encrypt the spliced parameters to generate a ciphertext string, and the client to carry the ciphertext string to access the second application server, which solves the problem that the authentication information of the client on the 5G message platform is maliciously rewritten. On the other hand, it also solves the problem of repeated registration of the second application server. Description of the Drawings
[0024] Figure 1 is a step diagram of a 5G message cross-platform authentication method according to an embodiment of the present invention;
[0025] Figure 2 is a spliced parameter step and data flow diagram of a 5G message cross-platform authentication method according to an embodiment of the present invention;
[0026] Figure 3 is a device structure diagram of a 5G message cross-platform authentication method according to an embodiment of the present invention;
[0027] Figure 4 is a client authentication sequence diagram of a 5G message cross-platform authentication method according to an embodiment of the present invention;
[0028] Figure 5 is a 5G message terminal menu application page diagram of a 5G message cross-platform authentication method according to an embodiment of the present invention; Detailed Embodiment
[0029] The following will describe in detail the specific implementation manners of the present invention with reference to the accompanying drawings of the specification.
[0030] In the 5G message application, there is a need to log in to the second-party application server page after authentication through the 5G message platform page. The existing authentication method is that the client first authenticates on the 5G message platform and obtains authentication information. The client uses the authentication information as a parameter to initiate an access request to the second-party application server. The second-party application server obtains the request parameters and performs the authentication operation. If the authentication is successful, the client is allowed to access the second-party application server. Since the authentication information is transmitted in plain text when the client initiates the request, there is a problem that the authentication information is modified by criminals on the client and the second-party application server is maliciously accessed. The method provided by the present invention comprises the following steps: the first application server splices parameters, the second application server encrypts the spliced parameters to generate a cipher string, and the client carries the cipher string to access the second application server, which solves the problem of malicious rewriting of the client authentication information.
[0031] like Figure 1 As shown, a cross-platform authentication method based on 5G messages provided by the present invention includes the following steps: It should be noted that the first application server described below refers to the 5G message platform authentication server, and on the other hand, the client described below refers to the 5G message client. The 5G message client has a specific environment and is usually a 5G message platform application built by a mobile or telecommunications operator. The 5G message menu displayed on the front end of the user's mobile phone is the short message component of the mobile phone. Figure 5 .
[0032] Step S1100: the client initiates a request for the first application server to call the second application server. The first application server performs parameter concatenation and obtains a first application string, and uses the first application string as a parameter to initiate a request to access the second application server.
[0033] In this embodiment, the client initiates a request to call the second application server from the first application server, executes the first application server to authenticate the client, and the first application server obtains 5G card information from the client request parameters, and the 5G card information includes the client phone number and SIM card identification information. The first application server performs 5G message platform authentication based on the client phone number and SIM card identification information. If the authentication is successful, the first application server assigns a unique Session identifier to the client. And the SIM card identification information, client phone number, and Session identifier are used as parameters to initiate a call request to the second application server.
[0034] It should be noted that in this step, the access request initiated by the client to the first application server and synchronously calling the second application server is a synchronous operation, and step S1200 is performed.
[0035] Step S1200: The second application server responds to the request of the first application server, performs parameter splicing and calculation to obtain the ciphertext string, the second application server returns the ciphertext string to the first application server, the first application server transparently transmits the ciphertext string to the client, and the client performs a caching operation on the ciphertext string.
[0036] It should be noted here that the detailed steps of performing parameter splicing and calculation to obtain the ciphertext string are as follows:
[0037] S2100: The first application server receives the 5G message card information of the client. The card information includes the client's phone number and the client's SIM card identification information. The first application server performs authentication on the 5G message platform based on the client's phone number and SIM card identification information. If the authentication is successful, a Session identifier is assigned as the current client access session, and step S2200 is entered.
[0038] S2200: The first application server performs a string concatenation operation on the client's phone number, SIM card identification information, and Session identifier, and each field is separated by the identifier "&". The first application string is obtained. The first application server uses the first application string as a parameter to initiate a call request to the second application server, and enters step S2250.
[0039] S2250: The second application server responds to the call request of the first application server. The first application server obtains the above first application string from the request parameters, performs MD5 calculation on the first application string to generate a 32-bit MD5 string. In this embodiment, the MD5 calculation is implemented using a PHP script, and it can also be implemented by calling a Python script through the system of PHP. This is not limited here. Enter step S2300.
[0040] S2300: The second application server concatenates the above first application string and the MD5 string, and the concatenation character continues to be connected using the identifier "&" to obtain the plaintext string, and enters step S2400.
[0041] S2400: Use the AES encryption library to encrypt the above plaintext string to obtain the ciphertext string. The AES encryption function requires a key string as the encryption parameter. In this embodiment, the above MD5 string is used as the key of the AES encryption function. After performing the AES encryption calculation, the ciphertext string is obtained. Further, a mapping relationship is established between the ciphertext string and the above MD5 string and cached in the Session variable of the second application server.
[0042] In this embodiment, the built-in PHP function openssl_encrypt is used to encrypt the string, and the key parameter of openssl_encrypt is the above-mentioned MD5 string. The openssl_encrypt function calculates the cipher string based on the MD5 string value as the AES algorithm key, and returns the cipher string as a response result to the first application server, and enters step S2500.
[0043] S2500: The first application server obtains the returned encrypted string and synchronously returns the encrypted string to the client that initiated the request. The client receives the encrypted string and performs a cache operation, and stores the encrypted string in the client cache through the JS script setCookie function, and enters step S1300.
[0044] S1300: The client initiates an authentication request to access the second server, and uses the secret string obtained in step S2500 as a parameter for the authentication request to access the second server. The authentication request to access the second server here is initiated from the menu application in the 5G message application terminal. The second application server responds to the client authentication request and obtains the above secret string from the request parameters. According to the secret string, the MD5 string in step S2400 is obtained from the Session variable of the second application server, and step S1400 is performed.
[0045] S1400: The second application server performs AES decryption calculation according to the cipher string. The second application server obtains the cipher string according to the parameters of the client authentication request and uses the MD5 string obtained in step S1300 as the key for decryption calculation. If the AES decryption is successful, the decryption result string is obtained, and the parameter list is decomposed from the decryption result string, including the client phone number, SIM card identification information, and MD5 string.
[0046] S1500: The second application server responds to the client request, parses the cipher string, and performs authentication. The second application server decomposes the MD5 string in the parameter list and checks whether it is equal to the MD5 string in the session cache of the second application server. If they are equal, it is determined that the client's authentication request to access the second application server is valid, and the client is allowed to continue to access the second application server. If they are not equal, an error code is returned to the client and the cause of the error is prompted.
[0047] In this embodiment, the AES decryption function uses the openssl_decrypt function of the PHP language to complete the AES decryption operation. The MD5 string is cached to the Session variable by the PHP script setSession function, and the function getSession is executed according to the MD5 string in the Session variable.
[0048] This embodiment also provides a call sequence diagram of the cross-platform authentication method based on 5G messages. See the appendix Figure 4 As shown in the figure, the client initiates a second application call request to the first application server, and the first application server splices the request parameters and organizes the access URL of the second application server to initiate a second application service access request. The second application server responds to the first application server, extracts the request parameters, performs MD5 calculation to obtain a 32-bit key MD5 string, caches it in the second application server Session, performs AES encryption operation according to the key MD5 string to obtain a ciphertext string, and returns it to the client cache via the first application server. The client uses the ciphertext string as a parameter to initiate a second application server authentication request. The second application server obtains the ciphertext string, performs AES decryption to obtain a plaintext string list, extracts the MD5 string in the plaintext string and compares it with the MD5 string cached in the second application server. If they are equal, the second application server authentication request initiated by the client is valid, and an authentication success code is returned to the client. The success code returned in this embodiment is 200. If the authentication is invalid, an authentication failure code -101 is returned to the client.
[0049] Correspondingly, this embodiment also provides a cross-platform authentication device based on 5G messages. See the appendix Figure 3 . It includes:
[0050] P3100: The first application server call response module is used to respond to the request of the client to call the second application server by the first application server, parse the first application server call parameters, perform parameter splicing, call the MD5 parameter splicing unit to obtain the MD5 string, call the AES encryption unit to obtain the ciphertext string and send it to the first application server, and the first application server calls the second application server to return the ciphertext string and send it to the client.
[0051] P3150: The MD5 parameter splicing unit is used to perform the splicing of the first server request parameters and perform MD5 calculation to obtain a 32-bit MD5 string.
[0052] P3160: The AES encryption unit is used to splice the request parameters of the first application server and the MD5 string, perform AES encryption calculation and obtain the ciphertext string.
[0053] P3200: The network transmission module is used to establish a network communication connection between the first application server and the second application server, and establish a network link between the client and the second application server.
[0054] P3300: The client authentication module is used to respond to the second application server authentication request initiated by the client. It decomposes the client request parameters and obtains the ciphertext string, submits the ciphertext string to the AES decryption sub-module to obtain the plaintext string, extracts the MD5 string from the plaintext string and compares it with the MD5 string in the Session variable. If they are equal, the authentication is valid.
[0055] P3350: The AES decryption unit is used for the AES decryption operation of the ciphertext string obtained by the authentication module. This module takes the corresponding MD5 string from the second application server Session variable list as the key to perform the AES decryption operation.
[0056] The technical solution of this application provides a method for the first application server to splice parameters, the second application server to encrypt the spliced parameters to generate a ciphertext string, and the client to carry the ciphertext string to access the second application server, which solves the problem that the client authentication information of the 5G message platform is maliciously rewritten. On the other hand, it also solves the problem of repeated registration in the registration process of the second application server for the 5G message source.
[0057] The specific embodiments of the present invention disclosed above are only for illustration. However, the present invention is not limited thereto, and any changes that can be conceived by those skilled in the art should fall within the protection scope of the present invention.
Claims
1. A cross-platform authentication method based on 5G messages. It is characterized in that The method comprises: The client initiates a request for the first application server to call the second application server; the first application server performs an authentication operation on the client; the first application server obtains 5G card information from the client request parameters, the 5G card information includes the client phone number and SIM card identification information, and the first application server performs a 5G message platform authentication operation according to the client phone number and SIM card identification information; if the authentication is successful, the first application server assigns a unique Session identifier to the client and uses the first application string generated by splicing the SIM card identification information, the client phone number, and the Session identifier as a parameter to initiate a call request to the second application server; wherein the first application server is a 5G message platform authentication server; The second application server responds to the call request of the first application server; parses the call request, performs MD5 calculation on the first application string to generate a 32-bit MD5 string and caches it in the second application server Session, performs concatenation of the first application string and the MD5 string, calculates and obtains a password string and returns the password string to the first application server, and the first application server synchronously and transparently transmits the password string to the client; the client performs a cache operation on the password string; The second application server responds to the client authentication request, the client authentication request parameters are consistent with the ciphertext string, parses the ciphertext string, performs the authentication operation, and if the authentication is successful, determines that the authentication is valid and returns a success code; if the authentication fails, returns an error code.
2. According to claim 1, the cross-platform authentication method based on 5G messages, It is characterized in that The client is a 5G message card application terminal.
3. According to claim 1, the cross-platform authentication method based on 5G messages, It is characterized in that The calling request of the first application server is a synchronous request from the first application server in response to the calling request of the client.
4. According to claim 1, the cross-platform authentication method based on 5G messages, It is characterized in that The calling request is parsed, parameter concatenation is performed and a cipher string is obtained by calculation, wherein the cipher string obtained by calculation is a cipher string obtained by AES encryption calculation, and the AES encryption key is the MD5 calculated value of the first application string.
5. According to claim 1, the cross-platform authentication method based on 5G messages, It is characterized in that The client performs a cache operation on the password string, and the cache operation includes caching the password string in a client Cookie variable.
6. According to claim 1, the cross-platform authentication method based on 5G messages, It is characterized in that The response client authentication request, wherein the authentication request is initiated from a menu application in the 5G message application terminal.
7. According to claim 1, the cross-platform authentication method based on 5G messages, It is characterized in that The client authentication request parameter is the ciphertext string. Parse the ciphertext string and perform the authentication operation, including decrypting the ciphertext string using the AES algorithm, and the AES decryption key is the MD5 calculated value of the first application string.
8. A cross-platform authentication device based on 5G messaging Characterized in that It includes: A second application server response first application server call module, which is used to respond to a first application server call request and parse the first application server call parameters; Before responding to the first application server call request, the client initiates a request for the first application server to call the second application server; Perform the authentication operation of the first application server on the client; the first application server obtains 5G card information from the client request parameters. The 5G card information includes the client phone number and SIM card identification information. The first application server performs the 5G messaging platform authentication operation according to the client phone number and SIM card identification information; if the authentication is successful, the first application server assigns a unique Session identifier to the client and uses the first application string generated by splicing the SIM card identification information, the client phone number, and the Session identifier as a parameter to initiate a second application server call request; wherein the first application server is a 5G messaging platform authentication server; The MD5 parameter splicing unit is used to perform the splicing of the first application server request parameters. The parameter splicing includes the MD5 calculation of the request parameters and obtaining a 32-bit MD5 string. The MD5 string is spliced with the request parameters and the MD5 string is cached in the server Session variable; The AES encryption unit is used to splice the request parameters of the first application server with the MD5 string, perform AES encryption calculation and obtain the ciphertext string; The network transmission module is used to establish a network communication connection between the server and the client; The authentication module is used to respond to the client authentication request; The AES decryption unit is used for the AES decryption operation of the authentication request parameters.
9. The cross-platform authentication device based on 5G messaging according to claim 8 Characterized in that The key used by the AES encryption unit when performing the AES encryption operation is the MD5 calculated value of the first application server request parameters; the key used by the AES decryption unit when performing the AES decryption operation is the MD5 calculated value of the first application server request parameters.
10. The cross-platform authentication device based on 5G messaging according to claim 8 Characterized in that The AES decryption operation of the authentication request parameters includes performing the AES decryption calculation of the request parameters to obtain the decryption result. If the decryption is successful, obtain the MD5 string of the request parameters and compare it with the MD5 string cached in the second application server. If the strings are equal, the authentication request is valid.
Citation Information
Patent Citations
Request authentication method and related equipment
CN111130798A