Cross-application account intercommunication processing method and device, equipment and storage medium

By receiving and verifying the target account's interaction credentials on the first server, the security issue of data exchange between different applications is resolved, and dual authentication enhances data security.

CN116743404BActive Publication Date: 2026-05-19TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
TENCENT TECHNOLOGY (SHENZHEN) CO LTD
Filing Date
2022-03-03
Publication Date
2026-05-19

AI Technical Summary

Technical Problem

In the current technology, there is no effective solution to ensure data security when data is exchanged between different applications.

Method used

The first server receives the interaction request from the second application, obtains the first interaction credential of the target account in the second application, and calls the second server corresponding to the second application to verify the validity of the first interaction credential. When the verification is successful, the second interaction credential of the target account in the first application is obtained, and the second application is controlled to output the response result of the first application to the target account based on the second interaction credential.

Benefits of technology

When communicating between different applications, the dual verification of the first and second interaction credentials improves data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116743404B_ABST
    Figure CN116743404B_ABST
Patent Text Reader

Abstract

The application provides a cross-application account intercommunication processing method and device, equipment and a computer readable storage medium; the method is applied to a first server, and the method comprises the following steps: receiving an interaction request of a target account for a first application sent by a second application, the first application being different from the second application; in response to the interaction request, obtaining a first interaction credential of the target account in the second application; calling a second server corresponding to the second application to verify the legality of the first interaction credential, and when the first interaction credential is legal, obtaining a second interaction credential of the target account in the first application; based on the second interaction credential, controlling the second application to output a response result of the first application for the target account. Through the application, the data security can be improved when different applications intercommunicate.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of communication technology, and in particular to a method, apparatus, device, computer-readable storage medium, and computer program product for cross-application account interoperability processing. Background Technology

[0002] With the rapid development of Internet technology, instant messaging applications are increasingly favored by users due to their instant information and user interactivity. Moreover, with the popularization of the Internet and globalization, multimedia interactive applications such as remote work, remote teaching, or live streaming are becoming more and more common, and more and more industries are conducting multimedia conversations through multimedia interactive applications.

[0003] As an open platform, instant messaging applications integrate more multimedia interactive capabilities by cooperating with multimedia interactive applications. This open model also provides multimedia interactive applications with more traffic entry points, achieving a win-win situation for both parties.

[0004] However, the relevant technologies do not yet have an effective solution for ensuring data security when different applications are interoperable. Summary of the Invention

[0005] This application provides a method, apparatus, device, computer-readable storage medium, and computer program product for cross-application account interoperability processing, which can improve the security of interoperable data when data is exchanged between different applications.

[0006] The technical solution of this application embodiment is implemented as follows:

[0007] This application provides a method for cross-application account interoperability processing, applied to a first server, including:

[0008] The system receives an interaction request from a second application targeting a first application, where the first application is different from the second application.

[0009] In response to the interaction request, obtain the first interaction credential of the target account in the second application;

[0010] The second server corresponding to the second application is invoked to verify the legitimacy of the first interaction credential, and if the first interaction credential is valid, the second interaction credential of the target account in the first application is obtained.

[0011] Based on the second interaction credential, the control outputs the response result of the first application to the target account through the second application.

[0012] This application provides a cross-application account interoperability processing device, including:

[0013] The receiving module is used to receive an interaction request from a target account sent by a second application to a first application, wherein the first application is different from the second application;

[0014] The first acquisition module is used to acquire the first interaction credential of the target account in the second application in response to the interaction request;

[0015] The second acquisition module is used to call the second server corresponding to the second application to verify the legitimacy of the first interaction credential, and when the first interaction credential is legitimate, acquire the second interaction credential of the target account in the first application;

[0016] The control module is used to control the output of the response result of the first application to the target account through the second application based on the second interaction credential.

[0017] In the above scheme, the first acquisition module is further configured to respond to the interaction request, detect the second interaction credential of the target account in the first application, and obtain the detection result; when the detection result indicates that the second interaction credential does not exist or the second interaction credential has expired, acquire the first interaction credential of the target account in the second application.

[0018] In the above scheme, the second acquisition module is further configured to send a verification request for the first interaction credential to the second server, so that the second server obtains the creation record of the interaction credential for the target account, and verifies the creator and validity of the first interaction credential based on the creation record, obtains and returns the verification result; receives the verification result returned by the second server, and determines that the first interaction credential is valid when the verification result indicates that the creator of the first interaction credential is the second server and the first interaction credential has not expired.

[0019] In the above scheme, the device further includes: a prompt receiving module, configured to determine that the first interaction credential is invalid when the verification result indicates that the creator of the first interaction credential is not the second server, or that the first interaction credential has expired; and to receive at least one of a rejection response prompt message and an interaction credential re-acquisition prompt message returned by the second server when the first interaction credential is invalid; wherein, the rejection response prompt message is used to prompt the second application to refuse to respond to the interaction request sent by the first application from the target account for the second application; and the interaction credential re-acquisition prompt message is used to prompt the user to re-acquire the first interaction credential of the target account in the second application.

[0020] In the above scheme, the second acquisition module is further configured to, when the interaction request is used to request login to the first application, acquire the account information corresponding to the target account returned by the second server when the first interaction credential is valid; detect the registration status of the target account in the first application based on the account information, and obtain the detection result; and acquire the second interaction credential of the target account in the first application based on the detection result.

[0021] In the above scheme, the second acquisition module is further configured to: when the detection result indicates that the target account has been registered in the first application, issue a second interaction credential for the target account in the first application; when the detection result indicates that the target account has not been registered in the first application, acquire the creation status of the group to which the target account belongs in the first application, and acquire the second interaction credential for the target account in the first application based on the creation status.

[0022] In the above scheme, the second acquisition module is further configured to: control the target account to register in the group of the first application when the creation status indicates that the group to which the target account belongs has been created in the first application; and issue the second interaction credential of the target account in the first application after registration is completed; and control the group to be created in the first application when the creation status indicates that the group to which the target account belongs has not yet been created in the first application, so that after creation is completed, control the target account to register in the group already created in the first application, and issue the second interaction credential of the target account in the first application after registration is completed.

[0023] In the above scheme, the control module is further configured to verify the identity of the target account based on the second interaction credential and obtain a verification result; and, in conjunction with the verification result, control the output of the response result of the first application to the target account through the second application.

[0024] In the above scheme, the control module is further configured to, when the verification result indicates that the target account has the interaction permission to interact with the first application through the second application, control the second application to output the interaction success result of the first application for the target account; and when the verification result indicates that the target account does not have the interaction permission to interact with the first application through the second application, control the second application to output the interaction failure result of the first application for the target account.

[0025] In the above scheme, the control module is further configured to generate a response result of the first application for the target account based on the second interaction credential; and send the response result to the second application via the second server so that the response result can be output by the second application.

[0026] In the above scheme, the device further includes: a data processing module, configured to send the target account's data processing request for the second application to the second server, so that the second server will pass through the second interaction credential carried in the data processing request in the data processing link, verify the identity of the target account based on the passed-through second interaction credential, obtain and return the verification result; and based on the verification result, control the output of the processing result of the second application for the data processing request through the first application.

[0027] In the above scheme, the data processing module is further configured to, when the verification result indicates that the target account has data processing permissions to process data in the second application through the first application, obtain the target data requested to be processed by the data processing request returned by the second server; and control the output of the processing result corresponding to the target data through the first application.

[0028] In the above scheme, the data processing module is further configured to call the second server to obtain the original data requested for processing by the data processing request, the account identifier of the target account in the second application, and the application identifier of the first application; encrypt the original data, the account identifier, and the application identifier to obtain an encrypted ciphertext result as the target data, and return the target data; receive the target data returned by the second server; decrypt the target data, and when the decryption result indicates that the target data contains the application identifier of the first application and the account identifier of the target account, control the output of the processing result of the second application for the target data through the first application.

[0029] In the above scheme, the data processing module is further configured to concatenate the original data, the account identifier, and the application identifier to obtain full plaintext data; divide the full plaintext data into a target number of plaintext blocks according to the target size blocks; obtain an encryptor and a key for encryption, and encrypt each plaintext block based on the encryptor and the key to obtain a corresponding ciphertext block; and concatenate each ciphertext block to obtain a corresponding ciphertext result.

[0030] This application provides an electronic device, including:

[0031] Memory, used to store executable instructions;

[0032] The processor, when executing executable instructions stored in the memory, implements the cross-application account interoperability processing method provided in the embodiments of this application.

[0033] This application provides a computer-readable storage medium storing executable instructions, which, when executed by a processor, implement the cross-application account interoperability processing method provided in this application.

[0034] This application provides a computer program product, including a computer program or instructions. When the computer program or instructions are executed by a processor, they implement the cross-application account interoperability processing method provided in this application.

[0035] The embodiments of this application have the following beneficial effects:

[0036] By applying the embodiments of this application, when a target account interacts with a first application in a second application, data communication is achieved between the second server corresponding to the second application and the second server corresponding to the first application. The first server obtains the first interaction credential of the target account in the second application and calls the second server to verify the validity of the first interaction credential. When the verification is successful, the second interaction credential of the target account in the first application is obtained, and the response result of the first application to the target account is controlled through the second application based on the second interaction credential. In this way, when different applications communicate with each other, the dual verification of the first and second interaction credentials improves the security of data during communication. Attached Figure Description

[0037] Figure 1 A schematic diagram of the architecture of a cross-application account interoperability processing system provided in an embodiment of this application;

[0038] Figure 2 A schematic diagram of the structure of an electronic device for implementing a cross-application account interoperability processing method, as provided in an embodiment of this application;

[0039] Figures 3A-3E A flowchart illustrating the cross-application account interoperability processing method provided in this application embodiment;

[0040] Figures 4A-4B This is a schematic diagram illustrating the acquisition of the second interactive credential provided in an embodiment of this application;

[0041] Figure 5 A flowchart illustrating the meeting processing method provided in this application embodiment;

[0042] Figure 6 A flowchart illustrating the meeting processing method provided in this application embodiment;

[0043] Figure 7This is a schematic diagram of the cross-application account interoperability processing device provided in an embodiment of this application. Detailed Implementation

[0044] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0045] In the following description, references are made to “some embodiments,” which describe a subset of all possible embodiments. However, it is understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0046] In the following description, the terms “first, second…” are used merely to distinguish similar objects and do not represent a specific ordering of objects. It is understood that “first, second…” may be interchanged in a specific order or sequence where permitted, so that the embodiments of this application described herein can be implemented in an order other than that illustrated or described herein.

[0047] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs. The terminology used herein is for the purpose of describing embodiments of this application only and is not intended to limit this application.

[0048] In the implementation of this application, the collection and processing of relevant data should strictly comply with the requirements of relevant laws and regulations, obtain the informed consent or separate consent of the personal information subject, and carry out subsequent data use and processing within the scope of laws and regulations and the authorization of the personal information subject.

[0049] Before providing a further detailed description of the embodiments of this application, the nouns and terms involved in the embodiments of this application will be explained, and the nouns and terms involved in the embodiments of this application shall be interpreted as follows.

[0050] 1) An application, or application client, is a software application that runs on a terminal and is used to send and receive Internet messages in real time. It is software that users need to download and install on their terminal (e.g., smartphone or computer) to use.

[0051] The first and second applications involved in this application are different applications. For example, the first application can be an instant messaging application, which is a computer program that provides internet social services for group users. The second application can be a multimedia conferencing application, which can provide convenient, easy-to-use, high-definition, smooth, secure and reliable cloud video / audio conferencing services, enabling efficient meetings anytime, anywhere, and has functions such as online document collaboration, real-time screen sharing, and instant text chat. The first and second applications can share accounts and data.

[0052] 2) In response, used to indicate the conditions or states on which the operation performed depends. When the conditions or states on which it depends are met, one or more operations performed may be performed in real time or with a set delay. Unless otherwise specified, there is no restriction on the order in which the multiple operations are performed.

[0053] Based on the above explanation of the nouns and terms used in the embodiments of this application, the cross-application account interoperability processing system provided in the embodiments of this application is described below. See also Figure 1 , Figure 1 This is a schematic diagram of the architecture of a cross-application account interoperability processing system provided in an embodiment of this application. To support an exemplary application, the architecture includes: a first terminal 400-1, a second terminal 400-2, a first server 200-1, and a second server 200-2. The terminals (such as terminal 400-1 and terminal 400-2) may include, but are not limited to, smartphones, tablets, laptops, desktop computers, smart speakers, smart TVs, smartwatches, smart voice interaction devices, smart home appliances, and in-vehicle terminals. The terminals (such as first terminal 400-1 and second terminal 400-2) and servers (such as first server 200-1 and second server 200-2) can be directly or indirectly connected via wired or wireless communication methods, which is not limited herein.

[0054] In some embodiments, the first terminal 400-1 and the second terminal 400-2 can run a computer program to assist in implementing the cross-application account interoperability processing method provided in this application embodiment. The computer program can be a native program or software module in the operating system; it can be a local application (APP), i.e., a program that needs to be installed in the operating system to run; it can also be a mini-program, i.e., a program that only needs to be downloaded to the browser environment to run; or it can be an instant messaging mini-program that can be embedded in any APP. In short, the above-mentioned computer program can be any form of application, module, or plugin.

[0055] For example, the first terminal 400-1 runs the first application 410-1, and the second terminal 400-2 runs the second application 410-2. Alternatively, both the first terminal 400-1 and the second terminal 400-2 run the first application 410-1 and the second application 410-2. The first application 410-1 and the second application 410-2 are different applications. The first server 200-1 is the backend server corresponding to the first application 410-1, and the second server 200-2 is the backend server corresponding to the second application 410-2.

[0056] In practical applications, the target account can send an interaction request for the target account to the first application via the second application 410-2 and the second server 200-2 to the first server 200-1. The first server 200-1 responds to the interaction request, obtains the target account's first interaction credential in the second application, and sends a verification request for the first interaction credential to the second server 200-2. The second server 200-2 verifies the validity of the first interaction credential and returns the verification result to the first server 200-1. If the first interaction credential is valid, the first server 200-1 obtains the target account's second interaction credential in the first application. Based on the second interaction credential, it controls the output of the first application's response result for the target account through the second application.

[0057] After the first application 410-1 obtains the second interaction credential of the target account in the first application 410-1, if the target account requests data processing from the second application 410-2 through the first application 410-1, the target account can send a data processing request for the second application 410-2 to the second server 200-2 through the first server 200-1 via the first application 410-1. The second server 200-2 will pass through the second interaction credential carried in the data processing request in the data processing link, verify the identity of the target account based on the passed-through second interaction credential, obtain and return the verification result to the first server 200-1. Based on the verification result, the first server 200-1 will control the output of the processing result of the second application 410-2 for the data processing request through the first application 410-1.

[0058] The embodiments of this application can be implemented with the help of cloud technology, which refers to a hosting technology that unifies a series of resources such as hardware, software, and network within a wide area network or local area network to realize the computation, storage, processing, and sharing of data.

[0059] Cloud technology is a general term encompassing network technology, information technology, integration technology, management platform technology, and application technology based on the cloud computing business model. It can form resource pools, allowing for on-demand use with flexibility and convenience. Cloud computing technology will become a crucial support. The backend services of cloud computing systems require substantial computing and storage resources.

[0060] As an example, the first server 200-1 and the second server 200-2 can be independent physical servers, or a server cluster or distributed system composed of multiple physical servers. They can also be cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, content delivery networks (CDN), and big data and artificial intelligence platforms, but are not limited to these.

[0061] See Figure 2 , Figure 2 This is a schematic diagram of the structure of an electronic device used to implement a cross-application account interoperability processing method, as provided in an embodiment of this application. In practical applications, the electronic device 500 can be... Figure 1 The server or terminal shown is exemplified by electronic device 500. Figure 1 Taking the server shown as an example, an electronic device implementing the cross-application account interoperability processing method of this application embodiment will be described. The electronic device 500 provided in this application embodiment includes: at least one processor 510, a memory 550, at least one network interface 520, and a user interface 530. The various components in the electronic device 500 are coupled together through a bus system 540. It is understood that the bus system 540 is used to realize the connection and communication between these components. In addition to a data bus, the bus system 540 also includes a power bus, a control bus, and a status signal bus. However, for clarity, in... Figure 2 The general labeled all buses as Bus System 540.

[0062] The processor 510 can be an integrated circuit chip with signal processing capabilities, such as a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor can be a microprocessor or any conventional processor, etc.

[0063] User interface 530 includes one or more output devices 531 that enable the presentation of media content, including one or more speakers and / or one or more visual displays. User interface 530 also includes one or more input devices 532, including user interface components that facilitate user input, such as a keyboard, mouse, microphone, touch screen display, camera, other input buttons and controls.

[0064] The memory 550 may be removable, non-removable, or a combination thereof. Exemplary hardware devices include solid-state storage, hard disk drives, optical disk drives, etc. The memory 550 may optionally include one or more storage devices physically located away from the processor 510.

[0065] The memory 550 may include volatile memory or non-volatile memory, or both. The non-volatile memory may be read-only memory (ROM), and the volatile memory may be random access memory (RAM). The memory 550 described in this application embodiment is intended to include any suitable type of memory.

[0066] In some embodiments, memory 550 is capable of storing data to support various operations, examples of which include programs, modules, and data structures or subsets or supersets thereof, as illustrated below.

[0067] Operating system 551 includes system programs for handling various basic system services and performing hardware-related tasks, such as the framework layer, core library layer, driver layer, etc., for implementing various basic business functions and handling hardware-based tasks;

[0068] The network communication module 552 is used to reach other computing devices via one or more (wired or wireless) network interfaces 520, exemplary network interfaces 520 including: Bluetooth, WiFi, and Universal Serial Bus (USB), etc.

[0069] Presentation module 553 is used to enable the presentation of information (e.g., user interface for operating peripheral devices and displaying content and information) via one or more output devices 531 (e.g., display screen, speaker, etc.) associated with user interface 530.

[0070] The input processing module 554 is used to detect and translate one or more user inputs or interactions from one or more input devices 532.

[0071] In some embodiments, the cross-application account interoperability processing device provided in this application can be implemented in software. Figure 2A cross-application account interoperability processing device 555 stored in memory 550 is shown. It can be software in the form of programs and plug-ins, including the following software modules: receiving module 5551, first acquisition module 5552, second acquisition module 5553, and control module 5554. These modules are logical and can therefore be arbitrarily combined or further split according to the functions they implement. The functions of each module will be described below.

[0072] In other embodiments, the cross-application account interoperability processing device provided in this application can be implemented using a combination of hardware and software. As an example, the cross-application account interoperability processing device provided in this application can be a processor in the form of a hardware decoding processor, which is programmed to execute the cross-application account interoperability processing method provided in this application. For example, the processor in the form of a hardware decoding processor can be one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), or other electronic components.

[0073] Based on the foregoing description of the cross-application account interoperability processing system and electronic device provided in the embodiments of this application, the cross-application account interoperability processing method provided in the embodiments of this application is described below. In some embodiments, the cross-application account interoperability processing method provided in the embodiments of this application can be implemented by a server or a terminal alone, or by a server and a terminal working together. The following description uses a server implementation as an example to illustrate the cross-application account interoperability processing method provided in the embodiments of this application. See also Figure 3A , Figure 3A This is a flowchart illustrating the cross-application account interoperability processing method provided in this application embodiment, which will be combined with... Figure 3A The steps shown are explained.

[0074] In step S101, the first server receives an interaction request from the second application regarding the target account's interaction with the first application.

[0075] The first application differs from the second application. For example, the second application provides internet social services for group users (such as schools and enterprises), while the first application provides multimedia conferencing services.

[0076] In practical applications, when a target account triggers an interactive operation on the first application through the interactive entry point of the second application displayed on the terminal, the second application responds to the interactive operation by generating and sending the target account's interactive request for the first application to the second server corresponding to the second application. The second server then forwards the interactive request to the first server corresponding to the first application.

[0077] For example, the second application displays an access point for the target meeting (created in the first application). When the target account triggers this access point, a login operation for the target meeting in the first application is triggered. In response to this login operation, the second application generates and sends a login request for the target account for the target meeting in the first application to its corresponding second server. The second server then forwards the login request to the first server corresponding to the first application. Similarly, the second application displays an information viewing entry point for the target meeting (created in the first application). When the target account triggers this information viewing entry point, an information viewing operation for the target meeting in the first application is triggered. In response to this information viewing operation, the second application generates and sends a request for the target account to view the information for the target meeting in the first application to its corresponding second server. The second server then forwards the information viewing request to the first server corresponding to the first application.

[0078] In step S102, in response to the interaction request, the first interaction credential of the target account in the second application is obtained.

[0079] In practical applications, since the target account is already logged in on the second application side, it possesses login credentials in the second application. When the first and second applications are set on the same terminal, they can communicate directly. When the second server first receives an interaction request from the target account to the first application, it indicates that the target account has not yet had an interaction record in the first application, and therefore does not possess interaction credentials in the first application. In this case, when the second server receives the interaction request from the target account to the first application, it will issue a temporary first interaction credential to the target account (the validity period can be set, such as 2 minutes) and return the first interaction credential to the second application. The second application will then directly transmit the first interaction credential to the first application, and the first application will then send the first interaction credential to the first server to verify its validity.

[0080] When the first application and the second application are set on different terminals, they cannot communicate directly. When the first server first receives an interaction request from the second application for a target account targeting the first application, it indicates that the target account has not yet had an interaction record in the first application. Therefore, the target account does not have the interaction credentials in the first application. In this case, when the second server receives the interaction request from the target account targeting the first application, the second server will issue a temporary first interaction credential to the target account (the validity period can be set, such as 2 minutes), and encapsulate this first interaction credential into the interaction request to send it to the first server. After receiving the interaction request, the first server retrieves the first interaction credential for the target account in the second application issued by the second server from the interaction request.

[0081] In some embodiments, the first server may respond to an interaction request by obtaining the first interaction credential of the target account in the second application in the following manner: in response to the interaction request, detecting the second interaction credential of the target account in the first application and obtaining a detection result; when the detection result indicates that the second interaction credential does not exist or the second interaction credential has expired, obtaining the first interaction credential of the target account in the second application.

[0082] In practical applications, after receiving an interaction request, the first server first checks whether the second interaction credential of the target account exists in the first application. Only when the second login credential does not exist or the second interaction credential is invalid will the first interaction credential be obtained and subsequent operations be performed.

[0083] In step S103, the second server corresponding to the second application is invoked to verify the legitimacy of the first interaction credential, and if the first interaction credential is valid, the second interaction credential of the target account in the first application is obtained.

[0084] In some embodiments, see Figure 3B , Figure 3B This is a flowchart illustrating the cross-application account interoperability processing method provided in the embodiments of this application. Figure 3A In step S103, it can be done through Figure 3B The steps S1031A to S1032A shown are implemented as follows: In step S1031A, a verification request for the first interaction credential is sent to the second server so that the second server can obtain the creation record of the interaction credential for the target account, and verify the creator and validity of the first interaction credential based on the creation record, and obtain and return the verification result; In step S1032A, the verification result returned by the second server is received, and when the verification result indicates that the creator of the first interaction credential is the second server and the first interaction credential has not expired, the first interaction credential is determined to be valid.

[0085] Here, when the legitimacy of the first interaction credential needs to be verified, the first server sends a verification request for the first interaction credential to the second server. The verification request carries the account identifier of the target account and the first interaction credential to be verified. When the second server receives the verification request, it obtains the creation record of the interaction credential for the target account based on the account identifier of the target account. The creation record contains the interaction credential created by the second server for the target account. In obtaining the creation record, the second server matches the first interaction credential to be verified with the interaction credential of the target account recorded in the creation record. When the match is successful, it can be determined that the first interaction credential was created by the second server. Next, it further verifies whether the first interaction credential has expired. When the first interaction credential has not expired, it is determined that the first interaction credential is legitimate.

[0086] In some embodiments, when the verification result indicates that the creator of the first interaction credential is not the second server, or the first interaction credential has expired, the first interaction credential is determined to be invalid; the first server receives at least one of a rejection response message or an interaction credential reacquisition message returned by the second server when the first interaction credential is invalid; wherein, the rejection response message is used to prompt the second application to refuse to respond to the interaction request sent by the first application for the target account to the second application; the interaction credential reacquisition message is used to prompt the user to reacquire the first interaction credential of the target account in the second application.

[0087] Here, when the second server matches the first interaction credential to be verified with the interaction credential of the target account recorded in the creation record, if at least one of the following conditions is met: the first interaction credential is not found in the creation record or the first interaction credential has expired, the first interaction credential is considered invalid. In this case, the second server can return a rejection response message to the first server. Based on the rejection response message, the first server refuses to respond to the interaction request sent by the second application from the target account to the first application, and the first server cannot obtain the second interaction credential of the target account in the first application. At the same time, the second server can also refuse to respond to the interaction request sent by the first application from the target account to the second application, meaning that no interaction operation can be performed between the two applications. In addition, when the first interaction credential is invalid, the second server can reissue a temporary interaction credential to the target account and return a new interaction credential retrieval message to the first server. Based on the new interaction credential retrieval message, the first server can retrieve the newly issued first interaction credential of the target account in the second application from the second server to perform the aforementioned validity verification on the new first interaction credential.

[0088] In some embodiments, see Figure 3C , Figure 3CThis is a flowchart illustrating the cross-application account interoperability processing method provided in the embodiments of this application. Figure 3A In step S103, the second interaction credential of the target account in the first application is obtained, which can be achieved through... Figure 3C The steps S1031B to S1033B shown are implemented as follows: In step S1031B, when the interaction request is used to request login to the first application, the account information of the corresponding target account returned by the second server when the first interaction credential is valid is obtained; in step S1032B, the registration status of the target account in the first application is detected based on the account information, and the detection result is obtained; in step S1033B, based on the detection result, the second interaction credential of the target account in the first application is obtained.

[0089] In some embodiments, see Figure 4A , Figure 4A This is a schematic diagram illustrating the acquisition of the second interactive credential provided in an embodiment of this application. Figure 3C In step S1033B, based on the detection results, the second interaction credential of the target account in the first application is obtained, which can be achieved through... Figure 4A The steps S201 to S202 shown are implemented as follows: In step S201, when the detection result indicates that the target account has been registered in the first application, a second interaction credential for the target account in the first application is issued; In step S202, when the detection result indicates that the target account has not been registered in the first application, the creation status of the group to which the target account belongs in the first application is obtained, and the second interaction credential for the target account in the first application is obtained based on the creation status.

[0090] In some embodiments, see Figure 4B , Figure 4B This is a schematic diagram illustrating the acquisition of the second interactive credential provided in an embodiment of this application. Figure 4A In step S202, the second interaction credential of the target account in the first application is obtained based on the creation status, which can be achieved through... Figure 4B The steps S2021 to S2022 shown are implemented as follows: In step S2021, when the creation status indicates that the group to which the target account belongs has been created in the first application, the target account is controlled to register in the group in the first application, and a second interaction credential for the target account in the first application is issued after registration is completed; In step S2022, when the creation status indicates that the group to which the target account belongs has not yet been created in the first application, the group is controlled to be created in the first application, so that after creation is completed, the target account is controlled to register in the group already created in the first application, and a second interaction credential for the target account in the first application is issued after registration is completed.

[0091] Here, after the second server verifies the first interaction credential, it obtains the target account's account information and returns it to the first server. The first server checks the target account's registration status in the first application based on the target account's account information. If the target account has already registered in the first application, it directly issues the target account's second interaction credential in the first application. If the target account has not yet registered in the first application, it further determines the creation status of the group to which the target account belongs (such as the enterprise or school to which it belongs) in the first application. If the group to which the target account belongs has already been created in the first application, it controls the target account to register in the group in the first application and issues the target account's second interaction credential in the first application after registration is completed. If the group to which the target account belongs has not yet been created in the first application, it first creates the group to which the target account belongs in the first application, so that after creation, it controls the target account to register in the group already created in the first application and issues the target account's second interaction credential in the first application after registration is completed.

[0092] In step S104, based on the second interaction credential, the control outputs the response result of the first application to the target account through the second application.

[0093] In some embodiments, see Figure 3D , Figure 3D This is a flowchart illustrating the cross-application account interoperability processing method provided in the embodiments of this application. Figure 3A In step S104, based on the second interaction credential, the control outputs the response result of the first application to the target account through the second application. Figure 3D The steps S1041A to S1042A shown are implemented as follows: In step S1041A, the identity of the target account is verified based on the second interaction credential, and a verification result is obtained; In step S1042A, based on the verification result, the response result of the first application for the target account is controlled to be output through the second application.

[0094] In some embodiments, the first server may combine the verification result to control the output of the first application's response result to the target account through the second application in the following manner: when the verification result indicates that the target account has the interaction permission to interact with the first application through the second application, the server controls the output of the first application's interaction success result to the target account through the second application; when the verification result indicates that the target account does not have the interaction permission to interact with the first application through the second application, the server controls the output of the first application's interaction failure result to the target account through the second application.

[0095] Here, after obtaining the second interaction credential of the target account in the first application, the identity of the target account is verified based on the second interaction credential. Depending on the verification result, the second application outputs different response results for the target account in the first application. Taking the interaction request for joining the target meeting in the first application as an example, when the verification result indicates that the target account has the interaction permission to interact with the first application through the second application (the permission to join the target meeting in the first application through the second application), the second application outputs a successful joining result for the target meeting in the first application, such as controlling the jump from the second application to the first application and controlling the target account to join the target meeting through the first application; when the verification result indicates that the target account has the interaction permission to interact with the first application without using the second application (the permission to join the target meeting in the first application through the second application), the second application outputs a joining failure result that the target account is not allowed to join the target meeting in the first application.

[0096] In some embodiments, see Figure 3E , Figure 3E This is a flowchart illustrating the cross-application account interoperability processing method provided in the embodiments of this application. Figure 3A In step S104, based on the second interaction credential, the control outputs the response result of the first application to the target account through the second application. Figure 3E The steps S1041B to S1042B shown are implemented as follows: In step S1041B, based on the second interaction credential, a response result of the first application for the target account is generated; in step S1041B, the response result is sent to the second application via the second server so that the response result can be output by the second application.

[0097] Here, the first server generates the response result corresponding to the interaction request of the first application for the target account based on the second interaction credential, and then forwards the response result to the second server. The second server then feeds back the response result to the second application, so that the second application can output the response result.

[0098] In some embodiments, the first server may also send a data processing request from the target account to the second application to the second server, so that the second server will pass through the second interaction credential carried in the data processing request in the data processing link, verify the identity of the target account based on the passed-through second interaction credential, obtain and return the verification result; based on the verification result, control the output of the processing result of the second application for the data processing request through the first application.

[0099] In practical applications, the data processing chain can include multiple sub-servers, meaning multiple sub-servers exist under the second server. Different sub-servers correspond to different data processing tasks. For example, sub-server 1 might be responsible for retrieving user A's data, while sub-server 2 might be responsible for viewing company A's basic information. After receiving a data retrieval request forwarded by the first server, the second server transmits the target account's second interaction credential carried in the data processing request throughout the entire data processing chain (i.e., all sub-servers). This allows the sub-server corresponding to the requested data processing task to verify the target account's identity based on the second interaction credential. Thus, when retrieving user data from the second application through the first application, using the second interaction credential to further verify the user's identity prevents unauthorized users from obtaining data they shouldn't, thereby improving data security.

[0100] In some embodiments, the first server may control the output of the processing result of the second application for the data processing request through the first application based on the verification result in the following manner: when the verification result indicates that the target account has the data processing permission to process data in the second application through the first application, the first server obtains the target data requested for processing by the data processing request returned by the second server; and controls the output of the processing result of the corresponding target data through the first application.

[0101] Here, when the verification result indicates that the target account does not have the data processing permission to process data in the second application through the first application (i.e., verification fails), it will not be allowed to request the processing of user data from the second application through the first application.

[0102] In some embodiments, the first server may obtain the target data requested for processing by the data processing request returned by the second server in the following manner: calling the second server to obtain the original data requested for processing by the data processing request, the account identifier of the target account in the second application, and the application identifier of the first application; encrypting the original data, the account identifier, and the application identifier to obtain the encrypted ciphertext result, which is then returned as the target data; receiving the target data returned by the second server; the first server may control the output of the processing result corresponding to the target data through the first application in the following manner: decrypting the target data, and when the decryption result indicates that the target data contains the application identifier of the first application and the account identifier of the target account, controlling the output of the processing result of the second application for the target data through the first application.

[0103] Here, to ensure the security and relevance of user data—for example, data provided to user 1 cannot be used by user 2 who does not have the necessary permissions, and data provided to application B cannot be used by application A who does not have the necessary permissions—the second server, after obtaining the raw data requested in the data processing request, also obtains the target account's account identifier and the first application's application identifier. It then combines these two identifiers to encrypt the raw data. When the target account belongs to a group, the corresponding group identifier is also obtained, and encryption is performed based on the group identifier to obtain a ciphertext result. This ciphertext result is then transmitted between different applications. Because application identifiers are used during encryption, the same account identifier belongs to different identity identifiers (different users) in different applications (different application identifiers). Therefore, different applications cannot deduce more user information by combining identity identifiers, thus preventing user data leakage.

[0104] In some embodiments, the first server may invoke the second server to encrypt the original data, account identifier, and application identifier to obtain the encrypted ciphertext result by concatenating the original data, account identifier, and application identifier to obtain the full plaintext data; dividing the full plaintext data into a target number of plaintext blocks according to the target size; obtaining the encryptor and key for encryption, and encrypting each plaintext block based on the encryptor and key to obtain the corresponding ciphertext block; and concatenating the ciphertext blocks to obtain the corresponding ciphertext result.

[0105] In practice, when the second server encrypts the original data, account identifier, and application identifier, it first concatenates these elements to obtain the full plaintext data. Then, it breaks the plaintext data into a target number of plaintext blocks of a specific size (e.g., 128 bits). It then obtains the encryptor and key used for encryption and encrypts each plaintext block to obtain the corresponding ciphertext block. Finally, it concatenates these ciphertext blocks to obtain the final ciphertext result. This increases the data length compared to the original data. For example, if the user identifier was 8 bytes before encryption, the encrypted account identifier is 32 bytes. The encrypted account identifier has four times the address space of the original, making it difficult for malicious users to deduce more user data by traversing the user list, thus preventing data leakage and improving data security.

[0106] It is understood that, in the embodiments of this application, the data related to target accounts, target data, etc. are essentially user-related data. When the embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions.

[0107] The following will describe an exemplary application of the embodiments of this application in a real-world application scenario. Taking a computer program that provides internet social services to group users (such as schools, enterprises, etc.) and a computer program that provides multimedia conferencing services as examples, the cross-application account interoperability processing method provided by the embodiments of this application will be further described using application scenarios such as a target account requesting to log in to a meeting in the first application through the second application and a target account requesting to process (such as obtaining) user data in the second application through the first application.

[0108] In the application scenario where the target account requests to log in to a meeting within the first application via a second application, see [link to application]. Figure 5 , Figure 5 The flowchart illustrating the meeting processing method provided in this application embodiment, taking the coordinated implementation of a first application, a second application, a first server, and a second server as an example, includes:

[0109] Step 201: In response to the login operation of the target account for the target meeting in the first application, the second application sends a login request of the target account for the target meeting in the first application to the second server.

[0110] Step 202: The second server responds to the login request and returns temporary login credentials for the target account in the second application to the second application.

[0111] Here, since the target account is logged in on the second application side but not on the first application side, the target account has login credentials in the second application but not in the first application. When the second server receives a login request from the target account for the target meeting in the first application, the second server issues a temporary login credential (i.e., the first interaction credential mentioned above, the validity period of which can be set, such as 2 minutes) to the target account and returns the temporary login credential to the second application.

[0112] Step 203: The second application sends the target account's temporary login credentials from the second application to the first application.

[0113] Here, since the second application and the first application can be set up on the same terminal, in this case, the second application can directly transfer the temporary login credentials of the target account in the second application to the first application.

[0114] Step 204: The first application sends the target account's temporary login credentials from the second application to the first server.

[0115] Step 205: The first server sends a verification request for the temporary login credentials to the second server.

[0116] Step 206: The second server responds to the verification request, verifies the validity of the temporary login credentials, and obtains the verification result.

[0117] Here, in response to the verification request, the second server obtains the creation record of the login credentials for the target account, and performs a validity verification on the temporary login credentials of the target account in the second application based on the creation record. For example, it verifies whether the temporary login credentials were issued by itself and whether they have expired. When the verification result indicates that the temporary login credentials were issued by itself and have not expired, it determines that the temporary login credentials are valid.

[0118] Step 207: When the verification result indicates that the temporary login credential is valid, the second server returns the account information to the first server.

[0119] The account information includes the target account's account information and the account information of the group to which the target account belongs (such as the company or school it belongs to).

[0120] Step 208: The first server issues login credentials for the target account in the first application based on the account information.

[0121] Here, after the second server verifies the temporary login credential, it obtains the target account's account information and checks the target account's registration status in the first application based on the target account's account information. If the target account has already registered in the first application, it directly issues the target account's login credential in the first application (i.e., the aforementioned second interaction credential). If the target account has not yet registered in the first application, it further determines the creation status of the group to which the target account belongs (such as the enterprise or school to which it belongs) in the first application. If the group to which the target account belongs has already been created in the first application, it controls the target account to register in the group in the first application and issues the target account's login credential in the first application after registration is completed. If the group to which the target account belongs has not yet been created in the first application, it first creates the group in the first application so that after creation, it controls the target account to register in the group already created in the first application and issues the target account's login credential in the first application after registration is completed.

[0122] Step 209: The first server sends the login credentials of the target account in the first application to the first application.

[0123] Step 210: The first application, based on login credentials, allows the target account to log in to the target meeting.

[0124] Here, after the first application obtains the login credentials of the target account in the first application, it can allow the target account to log in to the target meeting in the first application or further log in to other meetings in the first application. At this time, the login result can be output through the second application.

[0125] After the first application obtains the target account's login credentials within the first application, if it requests processing (such as retrieving) user data from the second application via the first application, it can use the login credentials from the first application to verify the target account's identity, thereby improving data security. In the application scenario where the target account requests processing of user data in the second application via the first application, see [link to relevant documentation]. Figure 6 , Figure 6 The flowchart illustrating the meeting processing method provided in this application embodiment, taking the coordinated implementation of a first application, a second application, a first server, and a second server as an example, includes:

[0126] Step 301: In response to the target account's data processing operation on the second application, the first application sends the target account's data processing request on the second application to the first server.

[0127] The data processing request carries the login credentials of the target account in the first application.

[0128] Step 302: The first server forwards the data processing request to the second server.

[0129] Step 303: The second server transmits the login credentials carried in the data processing request through the data processing link.

[0130] In practical applications, the data processing chain may include multiple sub-servers, each corresponding to a different data processing business. For example, sub-server 1 may be responsible for obtaining relevant data of user A, while sub-server 2 may be responsible for viewing the basic information of enterprise A. After receiving the data acquisition request forwarded by the first server, the second server will transmit the login credentials of the target account carried in the data processing request in the first application throughout the entire data processing chain (i.e., all sub-servers) so that the sub-server corresponding to the data processing business requested by the data processing request can verify the identity of the target account.

[0131] Step 304: The second server verifies the identity of the target account based on the transparently transmitted login credentials and obtains the verification result.

[0132] Step 305: When the verification result indicates that the target account has the data processing permission to process data in the second application through the first application, the second server obtains the original data requested to be processed by the data processing request, the account identifier of the target account in the second application, and the application identifier of the first application.

[0133] Here, when the verification result indicates that the target account does not have the data processing permission to process data in the second application through the first application (i.e., verification fails), it will not be allowed to request the processing of user data from the second application through the first application.

[0134] Step 306: The second server encrypts the original data, account identifier, and application identifier to obtain the encrypted ciphertext result.

[0135] Here, to ensure the security and relevance of user data—for example, data provided to user 1 cannot be used by user 2 who does not have the necessary permissions, and data provided to application B cannot be used by application A who does not have the necessary permissions—the second server, after obtaining the raw data requested in the data processing request, also obtains the target account's identifier and the first application's application identifier. It then combines these identifiers to encrypt the raw data. When the target account belongs to a group, the corresponding group identifier is also obtained, and encryption is performed based on the group identifier to obtain a ciphertext result. This ciphertext result is then transmitted between different applications. Because application identifiers are used during encryption, the same account identifier belongs to different identity identifiers in different applications (with different application identifiers). Therefore, different applications cannot deduce more user information by combining identity identifiers, thus preventing user data leakage.

[0136] In practice, the second server encrypts the original data, account identifier, and application identifier using the following method to obtain the encrypted ciphertext: The original data, account identifier, and application identifier are concatenated to obtain the full plaintext data; the full plaintext data is then divided into a target number of plaintext blocks according to a target size (e.g., 128 bits); an encryptor and key are obtained, and each plaintext block is encrypted using the encryptor and key to obtain the corresponding ciphertext block; finally, the ciphertext blocks are concatenated to obtain the corresponding ciphertext result. This increases the data length; for example, if the account identifier is 8 bytes before encryption, it becomes 32 bytes after encryption. The encrypted account identifier has four times the address space of the original account identifier, making it difficult for malicious users to deduce more user data by traversing the user list, thus preventing user data leakage and improving data security.

[0137] Step 307: The second server returns the encrypted result to the first server.

[0138] Step 308: The first server decrypts the encrypted result, and when the decryption result indicates that the target data contains the application identifier of the first application and the account identifier of the target account, the server controls the output of the processing result of the second application on the target data through the first application.

[0139] Here, after verification based on login credentials, a second verification is performed based on the decryption result. Only when the decryption result indicates that the target data contains the application identifier of the first application and the account identifier of the target account, the processing result of the second application for the target data is controlled through the first application. For example, the original data of the second application requested by the first application is provided to the first application for display. In this way, when data is exchanged between different applications, the security of the data is improved through dual verification.

[0140] The following description continues to illustrate the exemplary structure of the cross-application account interoperability processing device 555 provided in the embodiments of this application as a software module. In some embodiments, see [link to relevant documentation]. Figure 7 , Figure 7 This is a schematic diagram of the structure of the cross-application account interoperability processing device provided in the embodiments of this application, stored in Figure 2 The software modules in the cross-application account interoperability processing device 555 of the memory 550 may include:

[0141] The receiving module 5551 is used to receive an interaction request from a target account sent by a second application to a first application, wherein the first application is different from the second application;

[0142] The first acquisition module 5552 is used to acquire the first interaction credential of the target account in the second application in response to the interaction request;

[0143] The second acquisition module 5553 is used to call the second server corresponding to the second application to verify the legitimacy of the first interaction credential, and when the first interaction credential is legitimate, acquire the second interaction credential of the target account in the first application;

[0144] The control module 5554 is used to control the output of the response result of the first application to the target account through the second application based on the second interaction credential.

[0145] In some embodiments, the first acquisition module is further configured to, in response to the interaction request, detect the second interaction credential of the target account in the first application and obtain a detection result; when the detection result indicates that the second interaction credential does not exist or the second interaction credential has expired, acquire the first interaction credential of the target account in the second application.

[0146] In some embodiments, the second acquisition module is further configured to send a verification request for the first interaction credential to the second server, so that the second server obtains the creation record of the interaction credential for the target account, and verifies the creator and validity of the first interaction credential based on the creation record, obtains and returns a verification result; receives the verification result returned by the second server, and determines that the first interaction credential is valid when the verification result indicates that the creator of the first interaction credential is the second server and the first interaction credential has not expired.

[0147] In some embodiments, the apparatus further includes: a prompt receiving module, configured to determine that the first interaction credential is invalid when the verification result indicates that the creator of the first interaction credential is not the second server, or that the first interaction credential has expired; and to receive at least one of a rejection response prompt message and an interaction credential reacquisition prompt message returned by the second server when the first interaction credential is invalid; wherein the rejection response prompt message is configured to prompt the second application to refuse to respond to the interaction request sent by the first application from the target account for the second application; and the interaction credential reacquisition prompt message is configured to prompt the user to reacquire the first interaction credential of the target account in the second application.

[0148] In some embodiments, the second acquisition module is further configured to, when the interaction request is used to request login to the first application, acquire account information corresponding to the target account returned by the second server when the first interaction credential is valid; detect the registration status of the target account in the first application based on the account information, and obtain a detection result; and acquire the second interaction credential of the target account in the first application based on the detection result.

[0149] In some embodiments, the second acquisition module is further configured to: when the detection result indicates that the target account has been registered in the first application, issue a second interaction credential for the target account in the first application; when the detection result indicates that the target account has not been registered in the first application, acquire the creation status of the group to which the target account belongs in the first application, and acquire the second interaction credential for the target account in the first application based on the creation status.

[0150] In some embodiments, the second acquisition module is further configured to: control the target account to register in the group of the first application when the creation status indicates that the group to which the target account belongs has been created in the first application; and issue a second interaction credential for the target account in the first application after registration is completed; and control the group to be created in the first application when the creation status indicates that the group to which the target account belongs has not yet been created in the first application, so that after creation is completed, control the target account to register in the group already created in the first application; and issue a second interaction credential for the target account in the first application after registration is completed.

[0151] In some embodiments, the control module is further configured to verify the identity of the target account based on the second interaction credential, and obtain a verification result; and, in conjunction with the verification result, control the output of the response result of the first application to the target account through the second application.

[0152] In some embodiments, the control module is further configured to, when the verification result indicates that the target account has the interaction permission to interact with the first application through the second application, control the second application to output a successful interaction result of the first application for the target account; and when the verification result indicates that the target account does not have the interaction permission to interact with the first application through the second application, control the second application to output a failed interaction result of the first application for the target account.

[0153] In some embodiments, the control module is further configured to generate a response result of the first application for the target account based on the second interaction credential; and send the response result to the second application via the second server so that the response result can be output by the second application.

[0154] In some embodiments, the apparatus further includes: a data processing module, configured to send a data processing request from the target account to the second application to the second server, so that the second server transmits the second interaction credential carried in the data processing request through the data processing link, verifies the identity of the target account based on the transmitted second interaction credential, obtains and returns a verification result; and controls the output of the processing result of the second application for the data processing request through the first application based on the verification result.

[0155] In some embodiments, the data processing module is further configured to, when the verification result indicates that the target account has data processing permissions to process data in the second application through the first application, obtain the target data requested to be processed by the data processing request returned by the second server; and control the output of the processing result corresponding to the target data through the first application.

[0156] In some embodiments, the data processing module is further configured to: call the second server to obtain the original data requested for processing by the data processing request, the account identifier of the target account in the second application, and the application identifier of the first application; encrypt the original data, the account identifier, and the application identifier to obtain an encrypted ciphertext result as the target data, and return the target data; receive the target data returned by the second server; decrypt the target data, and when the decryption result indicates that the target data contains the application identifier of the first application and the account identifier of the target account, control the output of the processing result of the second application for the target data through the first application.

[0157] In some embodiments, the data processing module is further configured to concatenate the original data, the account identifier, and the application identifier to obtain full plaintext data; divide the full plaintext data into a target number of plaintext blocks according to a target size; obtain an encryptor and a key for encryption, and encrypt each plaintext block based on the encryptor and the key to obtain a corresponding ciphertext block; and concatenate each ciphertext block to obtain a corresponding ciphertext result.

[0158] This application provides a computer program product or computer program that includes computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium and executes the computer instructions, causing the computer device to perform the cross-application account interoperability processing method described in this application embodiment.

[0159] This application provides a computer-readable storage medium storing executable instructions. When these executable instructions are executed by a processor, they cause the processor to execute the cross-application account interoperability processing method provided in this application, for example... Figure 3A The method shown.

[0160] In some embodiments, the computer-readable storage medium may be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, flash memory, magnetic surface memory, optical disk, or CD-ROM; or it may be a variety of devices including one or any combination of the above-mentioned memories.

[0161] In some embodiments, executable instructions may take the form of a program, software, software module, script, or code, written in any form of programming language (including compiled or interpreted languages, or declarative or procedural languages), and may be deployed in any form, including as a standalone program or as a module, component, subroutine, or other unit suitable for use in a computing environment.

[0162] As an example, executable instructions may, but do not necessarily, correspond to files in a file system. They may be stored as part of a file that holds other programs or data, for example, in one or more scripts in a Hyper Text Markup Language (HTML) document, in a single file dedicated to the program in question, or in multiple collaborating files (e.g., a file that stores one or more modules, subroutines, or code sections).

[0163] As an example, executable instructions can be deployed to execute on a single computing device, or on multiple computing devices located in one location, or on multiple computing devices distributed across multiple locations and interconnected via a communication network.

[0164] The above description is merely an embodiment of this application and is not intended to limit the scope of protection of this application. Any modifications, equivalent substitutions, and improvements made within the spirit and scope of this application are included within the scope of protection of this application.

Claims

1. A method for cross-application account interoperability processing, characterized in that, Applied to a first server, the method includes: The system receives an interaction request from a second application targeting a first application, where the first application is different from the second application. In response to the interaction request, a temporary first interaction credential of the target account in the second application is obtained, and the validity period of the first interaction credential is preset. The second server corresponding to the second application is invoked to verify the legitimacy of the first interaction credential, and if the first interaction credential is valid, the second interaction credential of the target account in the first application is obtained; Based on the second interaction credential, the control outputs the response result of the first application to the target account through the second application; Send the target account's data processing request for the second application to the second server, so that the second server will pass through the second interaction credential carried by the data processing request in all sub-servers of the data processing link, verify the identity of the target account based on the passed-through second interaction credential, and return the verification result to the first server; When the verification result indicates that the target account has data processing permissions to process data in the second application through the first application, the target data returned by the second server is obtained; wherein, the target data is obtained by the second server through encryption processing based on the data processing request; When the decryption result of the target data indicates that the target data contains the application identifier of the first application and the account identifier of the target account, the first application is controlled to output the processing result corresponding to the target data.

2. The method as described in claim 1, characterized in that, The step of obtaining a temporary first interaction credential for the target account in the second application in response to the interaction request includes: In response to the interaction request, the second interaction credential of the target account in the first application is detected, and the detection result is obtained; When the detection result indicates that the second interaction credential does not exist or the second interaction credential has expired, a temporary first interaction credential for the target account in the second application is obtained.

3. The method as described in claim 1, characterized in that, The step of calling the second server corresponding to the second application to verify the validity of the first interaction credential includes: A verification request for the first interaction credential is sent to the second server, so that the second server obtains the creation record of the interaction credential for the target account, and verifies the creator and timeliness of the first interaction credential based on the creation record, and obtains and returns the verification result. The system receives the verification result returned by the second server, and determines that the first interaction credential is valid when the verification result indicates that the creator of the first interaction credential is the second server and the first interaction credential has not expired.

4. The method as described in claim 3, characterized in that, The method further includes: When the verification result indicates that the creator of the first interaction credential is not the second server, or that the first interaction credential has expired, the first interaction credential is determined to be invalid. Receive at least one of the following: a rejection response message or a message indicating that the interaction credential should be re-acquired when the first interaction credential is invalid; The rejection response message is used to prompt the second application to refuse to respond to the interaction request sent by the first application from the target account to the second application. The prompt message for re-acquiring the interaction credential is used to prompt the user to re-acquire the temporary first interaction credential of the target account in the second application.

5. The method as described in claim 1, characterized in that, The step of obtaining the second interaction credential of the target account in the first application includes: When the interaction request is used to request login to the first application, the account information corresponding to the target account returned by the second server when the first interaction credential is valid is obtained; The registration status of the target account in the first application is detected based on the account information, and the detection result is obtained; Based on the detection results, the second interaction credential of the target account in the first application is obtained.

6. The method as described in claim 5, characterized in that, The step of obtaining the second interaction credential of the target account in the first application based on the detection result includes: When the detection result indicates that the target account has been registered in the first application, a second interaction credential for the target account in the first application is issued. When the detection result indicates that the target account has not yet been registered in the first application, the creation status of the group to which the target account belongs in the first application is obtained, and the second interaction credential of the target account in the first application is obtained based on the creation status.

7. The method as described in claim 6, characterized in that, The step of obtaining the second interaction credential of the target account in the first application based on the creation status includes: When the creation status indicates that the group to which the target account belongs has been created in the first application, control the target account to register in the group in the first application, and issue the second interaction credential of the target account in the first application after registration is completed; When the creation status indicates that the group to which the target account belongs has not yet been created in the first application, control the creation of the group in the first application, so that after the creation is completed, control the target account to register in the group already created in the first application, and issue the second interaction credential of the target account in the first application after the registration is completed.

8. The method as described in claim 1, characterized in that, The step of controlling the output of the response result of the first application to the target account through the second application based on the second interaction credential includes: Based on the second interaction credential, the identity of the target account is verified, and a verification result is obtained; Based on the verification results, the system controls the output of the response results from the first application to the target account via the second application.

9. The method as described in claim 8, characterized in that, The step of combining the verification results and controlling the output of the response result of the first application to the target account through the second application includes: When the verification result indicates that the target account has the interaction permission to interact with the first application through the second application, the system controls the output of the interaction success result of the first application for the target account through the second application. When the verification result indicates that the target account does not have the interaction permission to interact with the first application through the second application, the system controls the output of the interaction failure result of the first application for the target account through the second application.

10. The method as described in claim 1, characterized in that, The step of controlling the output of the response result of the first application to the target account through the second application based on the second interaction credential includes: Based on the second interaction credential, a response result from the first application for the target account is generated; The response result is sent to the second application via the second server, so that the response result can be output by the second application.

11. The method as described in claim 1, characterized in that, The step of obtaining the target data returned by the second server includes: The system calls the second server to obtain the original data requested by the data processing request, the account identifier of the target account in the second application, and the application identifier of the first application. The system encrypts the original data, the account identifier, and the application identifier to obtain the encrypted ciphertext result, which is then used as the target data, and the system returns the target data.

12. The method as described in claim 11, characterized in that, The encryption process involving the original data, the account identifier, and the application identifier to obtain the encrypted ciphertext result includes: The original data, the account identifier, and the application identifier are concatenated to obtain the full plaintext data. The full plaintext data is divided into a target number of plaintext blocks according to the target size. Obtain the encryptor and key used for encryption, and encrypt each plaintext block based on the encryptor and key to obtain the corresponding ciphertext block; The ciphertext blocks are concatenated to obtain the corresponding ciphertext result.

13. A cross-application account interoperability processing device, characterized in that, The device includes: The receiving module is used to receive an interaction request from a target account sent by a second application to a first application, wherein the first application is different from the second application; The first acquisition module is used to respond to the interaction request and acquire a temporary first interaction credential of the target account in the second application, wherein the validity period of the first interaction credential is preset. The second acquisition module is used to call the second server corresponding to the second application to verify the legitimacy of the first interaction credential, and when the first interaction credential is legitimate, acquire the second interaction credential of the target account in the first application; The control module is used to control the output of the response result of the first application to the target account through the second application based on the second interaction credential; The data processing module is used to send the target account's data processing request for the second application to the second server, so that the second server will pass through the second interaction credential carried by the data processing request in all sub-servers of the data processing link, verify the identity of the target account based on the passed-through second interaction credential, and return the verification result to the first server. The data processing module is further configured to obtain target data returned by the second server when the verification result indicates that the target account has data processing permissions to process data in the second application through the first application; wherein the target data is obtained by the second server through encryption processing based on the data processing request; When the decryption result of the target data indicates that the target data contains the application identifier of the first application and the account identifier of the target account, the first application is controlled to output the processing result corresponding to the target data.

14. The apparatus according to claim 13, characterized in that, The first acquisition module is further configured to, in response to the interaction request, detect the second interaction credential of the target account in the first application and obtain a detection result; When the detection result indicates that the second interaction credential does not exist or the second interaction credential has expired, a temporary first interaction credential for the target account in the second application is obtained.

15. The apparatus according to claim 13, characterized in that, The second acquisition module is further configured to send a verification request for the first interaction credential to the second server, so that the second server can obtain the creation record of the interaction credential for the target account, and verify the creator and timeliness of the first interaction credential based on the creation record, and obtain and return the verification result; The system receives the verification result returned by the second server, and determines that the first interaction credential is valid when the verification result indicates that the creator of the first interaction credential is the second server and the first interaction credential has not expired.

16. The apparatus of claim 15, further comprising: The prompt receiving module is used to determine that the first interaction credential is invalid when the verification result indicates that the creator of the first interaction credential is not the second server or the first interaction credential has expired. Receive at least one of the following: a rejection response message or a message indicating that the interaction credential should be re-acquired when the first interaction credential is invalid; The rejection response message is used to prompt the second application to refuse to respond to the interaction request sent by the first application from the target account to the second application. The prompt message for re-acquiring the interaction credential is used to prompt the user to re-acquire the temporary first interaction credential of the target account in the second application.

17. The apparatus according to claim 13, characterized in that, The second acquisition module is further configured to acquire, when the interaction request is used to request login to the first application, the account information corresponding to the target account returned by the second server when the first interaction credential is valid; The registration status of the target account in the first application is detected based on the account information, and the detection result is obtained; Based on the detection results, the second interaction credential of the target account in the first application is obtained.

18. The apparatus according to claim 17, characterized in that, The second acquisition module is further configured to issue a second interaction credential for the target account in the first application when the detection result indicates that the target account has been registered in the first application; When the detection result indicates that the target account has not yet been registered in the first application, the creation status of the group to which the target account belongs in the first application is obtained, and the second interaction credential of the target account in the first application is obtained based on the creation status.

19. The apparatus according to claim 18, characterized in that, The second acquisition module is further configured to control the target account to register in the group of the first application when the creation status indicates that the group to which the target account belongs has been created in the first application, and to issue the second interaction credential of the target account in the first application after the registration is completed; When the creation status indicates that the group to which the target account belongs has not yet been created in the first application, control the creation of the group in the first application, so that after the creation is completed, control the target account to register in the group already created in the first application, and issue the second interaction credential of the target account in the first application after the registration is completed.

20. An electronic device, characterized in that, include: Memory, used to store executable instructions; A processor, when executing executable instructions stored in the memory, implements the cross-application account interoperability processing method according to any one of claims 1 to 12.

21. A computer-readable storage medium, characterized in that, It stores executable instructions for use by a processor to implement the cross-application account interoperability processing method as described in any one of claims 1 to 12.

22. A computer program product, comprising a computer program or instructions, characterized in that, When the computer program or instructions are executed by the processor, they implement the cross-application account interoperability processing method according to any one of claims 1 to 12.