A token processing method, apparatus, device, and storage medium
Patent Information
- Application Number
- CN202410485624.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-04-22
- Publication Date
- 2026-09-18
- Estimated Expiration
- 2044-04-22
AI Technical Summary
[0003]但现有的访问令牌生成一般在请求方的身份认证成功之后,服务端不限制访问令牌的生成数量,也不限制访问令牌的有效时间,且采用固定方式生成访问令牌,增加了访问令牌被非法扩散、恶意囤积、破解或盗用的风险,从而降低了访问令牌的安全性和可靠性
[0020] The technical solution of this invention, upon receiving a token generation request from a requester, determines the current generation time interval based on the current request time of the token generation request and the historical generation time of the requester's historical tokens; integrates the necessary information of historical tokens based on the current generation time interval, the specified generation time interval, and the token validity period to obtain valid token information; obfuscates the valid token information based on at least one generated obfuscation message to obtain obfuscated token information; and encrypts the obfuscated token information to obtain the target token. This technical solution, after successful authentication of the requester, limits the number of access tokens generated by the server upon receiving the token generation request, based on the current request time and the specified generation time interval; it adds the token validity period to the necessary information of historical tokens, limiting the validity period of access tokens and preventing illegal dissemination or malicious hoarding of access tokens; by adding randomly generated obfuscation information to the valid token information, it increases the randomness of the access token generation process, increasing the difficulty of cracking the access token and thus reducing the risk of access token theft; and overall, it improves the security and reliability of the access token.
Smart Images

Figure CN118413358B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of data processing technology, and in particular to a token processing method, apparatus, device, and storage medium. Background Technology
[0002] Access tokens are an important security verification method and are widely used in scenarios such as user authentication and session management.
[0003] However, existing access tokens are generally generated after the requester's identity authentication is successful. The server does not limit the number of access tokens generated, nor does it limit the validity period of the access tokens. In addition, the access tokens are generated in a fixed way, which increases the risk of access tokens being illegally distributed, maliciously hoarded, cracked or stolen, thereby reducing the security and reliability of access tokens. Summary of the Invention
[0004] This invention provides a token processing method, apparatus, device, and storage medium to reduce the risk of access tokens being illegally disseminated, maliciously hoarded, cracked, or stolen, and to improve the security and reliability of access tokens.
[0005] According to one aspect of the present invention, a token processing method is provided, the method being applied to a server, comprising:
[0006] Upon receiving a token generation request from the requester, the current generation time interval is determined based on the current request time of the token generation request and the historical generation time of the requester's historical tokens.
[0007] Based on the current generation time interval, the specified generation time interval, and the token validity period, the necessary information of historical tokens is integrated to obtain valid token information;
[0008] Based on at least one generated obfuscation information, the valid token information is obfuscated to obtain obfuscated token information;
[0009] The obfuscated token information is encrypted to obtain the target token.
[0010] According to another aspect of the present invention, a token processing device is provided, the device being configured on a server, comprising:
[0011] The current generation time interval determination module is used to determine the current generation time interval based on the current request time of the token generation request and the historical generation time of the requester's historical tokens when a token generation request is received from the requester.
[0012] The valid token information determination module is used to integrate the necessary information of historical tokens based on the current generation time interval, the specified generation time interval, and the token validity period to obtain valid token information.
[0013] The obfuscated token information determination module is used to obfuscate the valid token information based on at least one generated obfuscated information to obtain obfuscated token information;
[0014] The target token determination module is used to encrypt the obfuscated token information to obtain the target token.
[0015] According to another aspect of the present invention, an electronic device is provided, the electronic device comprising:
[0016] At least one processor; and
[0017] A memory that is communicatively connected to at least one processor; wherein,
[0018] The memory stores a computer program that can be executed by at least one processor, such that the at least one processor is able to perform the token processing method of any embodiment of the present invention.
[0019] According to another aspect of the present invention, a computer-readable storage medium is provided, the computer-readable storage medium storing computer instructions for causing a processor to execute and implement the token processing method of any embodiment of the present invention.
[0020] The technical solution of this invention, upon receiving a token generation request from a requester, determines the current generation time interval based on the current request time of the token generation request and the historical generation time of the requester's historical tokens; integrates the necessary information of historical tokens based on the current generation time interval, the specified generation time interval, and the token validity period to obtain valid token information; obfuscates the valid token information based on at least one generated obfuscation message to obtain obfuscated token information; and encrypts the obfuscated token information to obtain the target token. This technical solution, after successful authentication of the requester, limits the number of access tokens generated by the server upon receiving the token generation request, based on the current request time and the specified generation time interval; it adds the token validity period to the necessary information of historical tokens, limiting the validity period of access tokens and preventing illegal dissemination or malicious hoarding of access tokens; by adding randomly generated obfuscation information to the valid token information, it increases the randomness of the access token generation process, increasing the difficulty of cracking the access token and thus reducing the risk of access token theft; and overall, it improves the security and reliability of the access token.
[0021] It should be understood that the description in this section is not intended to identify key or essential features of the embodiments of the present invention, nor is it intended to limit the scope of the invention. Other features of the invention will become readily apparent from the following description. Attached Figure Description
[0022] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0023] Figure 1 This is a flowchart of a token processing method provided in Embodiment 1 of the present invention;
[0024] Figure 2 This is a flowchart of a token processing method provided in Embodiment 2 of the present invention;
[0025] Figure 3 This is a schematic diagram of the structure of a token processing device according to Embodiment 3 of the present invention;
[0026] Figure 4 This is a schematic diagram of the structure of an electronic device that implements the token processing method of this invention. Detailed Implementation
[0027] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0028] It should be noted that the terms "target," "current," "historical," "first," and "second," etc., used in the specification, claims, and accompanying drawings of this invention are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of the invention described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0029] Furthermore, it should be noted that the collection, storage, use, processing, transmission, provision, and disclosure of token generation requests, the current request time of token generation requests, the historical generation time of historical tokens of the requester, the specified generation time interval, the token validity time, and the target usage status and obfuscation identifier of the target token stored locally, etc., in the technical solution of the present invention, all comply with the provisions of relevant laws and regulations and do not violate public order and good morals.
[0030] Example 1
[0031] Figure 1 This is a flowchart of a token processing method provided in Embodiment 1 of the present invention. This embodiment is applicable to the generation and verification of access tokens. The method can be executed by a token processing device, which can be implemented in hardware and / or software and can be configured in an electronic device. Figure 1 As shown, this method is applied to the server side and includes:
[0032] S101. Upon receiving a token generation request from the requester, determine the current generation time interval based on the current request time of the token generation request and the historical generation time of the requester's historical tokens.
[0033] In this context, the requester refers to the party requesting services from the server. A token generation request is an optional request to generate an access token; it includes, but is not limited to, the requester's identity and the current request time. The access token can be a string. The requester's identity is used to uniquely identify the requester; optionally, the requester's identity can be in the form of numbers, letters, or a combination of numbers and letters. The current request time is the time when the requester sends the token generation request to the server. Historical tokens are the most recently generated access tokens before the current request time. Historical generation time is the time when historical tokens were generated. The current generation time interval is the time interval between the current request time and the historical generation time.
[0034] Specifically, after the requester's identity is successfully authenticated and the server receives the token generation request sent by the requester, it obtains the current request time from the token generation request, obtains the historical generation time of the requester's historical tokens from the local cache, and determines the time difference between the current request time and the historical generation time as the current generation time interval.
[0035] S102. Based on the current generation time interval, the specified generation time interval, and the token validity period, integrate the necessary information of the historical tokens to obtain the valid token information.
[0036] The specified generation time interval can be preset based on the experience of those skilled in the art or set randomly; this embodiment of the invention does not impose specific limitations on it. The token validity period refers to the time during which the access token can be used after its generation; optionally, the token validity period can be preset based on actual business needs or application scenarios; this embodiment of the invention does not impose specific limitations on it. Necessary information for historical tokens includes, but is not limited to, the requester's identity identifier, the requester's access permissions, the requester's name, and the requester's role. Valid token information refers to information used to verify the access token and the requester's identity.
[0037] Specifically, when the current generation time interval is greater than or equal to the specified generation time interval, the necessary information of historical tokens is integrated based on the token's validity period to obtain valid token information. More specifically, when the current generation time interval is greater than or equal to the specified generation time interval, the token's validity period is added to the necessary information of historical tokens using string concatenation technology to obtain valid token information.
[0038] Optionally, if the current generation time interval is less than the specified generation time interval, the server can retrieve the requester's historical token from the local cache using the requester's identity identifier in the token generation request as the retrieval condition, and return the historical token to the requester instead of regenerating a new access token. This limits the number of access tokens generated to some extent and reduces the waste of resources during the access token generation process.
[0039] S103. Based on at least one generated obfuscation information, obfuscate the valid token information to obtain obfuscated token information.
[0040] Obfuscated information refers to information used to obfuscate valid token information and has no actual meaning; optionally, obfuscated information can be in the form of a string. Obfuscated token information refers to the information obtained after obfuscating valid token information.
[0041] Specifically, at least one obfuscation message can be generated based on a random algorithm; the header and tail positions of the valid token information can be determined; and at least one generated obfuscation message can be inserted into the header or tail position to obtain obfuscated token information.
[0042] For example, if five obfuscated messages are generated based on a random algorithm, after determining the header and tail positions of the valid token information, three obfuscated messages can be randomly selected from the five generated obfuscated messages. These three obfuscated messages can be inserted into the header position in an orderly manner, or they can be inserted into the tail position in an orderly manner. Alternatively, one more obfuscated message can be selected from these three obfuscated messages and inserted into the header position. At the same time, one obfuscated message can be randomly selected from the remaining two obfuscated messages and inserted into the tail position, or the remaining two obfuscated messages can be inserted into the tail position in an orderly manner.
[0043] Understandably, by adding randomly generated obfuscation information to the valid token information, the randomness of the access token generation process can be increased, making it more difficult for the access token to be cracked, thereby reducing the risk of the access token being stolen.
[0044] S104. Encrypt the obfuscated token information to obtain the target token.
[0045] The target token refers to the access token generated based on the token generation request sent by the requester.
[0046] Specifically, the RSA encryption algorithm can be used to encrypt the obfuscated token information to obtain the target token.
[0047] Optionally, the server can also record the target token's generation time and usage status in a local cache, and can also send the target token to the requester. It should be noted that the target token is in an unused state when it is generated.
[0048] The technical solution of this invention, upon receiving a token generation request from a requester, determines the current generation time interval based on the current request time of the token generation request and the historical generation time of the requester's historical tokens; integrates the necessary information of historical tokens based on the current generation time interval, the specified generation time interval, and the token validity period to obtain valid token information; obfuscates the valid token information based on at least one generated obfuscation message to obtain obfuscated token information; and encrypts the obfuscated token information to obtain the target token. This technical solution, after successful authentication of the requester, limits the number of access tokens generated by the server upon receiving the token generation request, based on the current request time and the specified generation time interval; it adds the token validity period to the necessary information of historical tokens, limiting the validity period of access tokens and preventing illegal dissemination or malicious hoarding of access tokens; by adding randomly generated obfuscation information to the valid token information, it increases the randomness of the access token generation process, increasing the difficulty of cracking the access token and thus reducing the risk of access token theft; and overall, it improves the security and reliability of the access token.
[0049] Example 2
[0050] Figure 2 This is a flowchart of a token processing method provided in Embodiment 2 of the present invention. Based on the above embodiments, this embodiment provides an optional implementation scheme for verifying the target token. It should be noted that parts not described in detail in this embodiment can be referred to in the relevant descriptions of other embodiments. For example... Figure 2 As shown, this method is applied to the server side and includes:
[0051] S201. Upon receiving a token generation request from the requester, determine the current generation time interval based on the current request time of the token generation request and the historical generation time of the requester's historical tokens.
[0052] S202. Based on the current generation time interval, the specified generation time interval, and the token validity period, integrate the necessary information of historical tokens to obtain valid token information.
[0053] S203. Based on at least one generated obfuscation information, obfuscate the valid token information to obtain obfuscated token information.
[0054] S204. Encrypt the obfuscated token information to obtain the target token.
[0055] S205. In response to a target access request containing a target token, the target token is processed according to the target usage status and obfuscation identifier of the target token stored locally to obtain valid token information.
[0056] Here, the target access request refers to the access request that the server will process. The target usage status refers to the usage status of the target token; optionally, the target usage status can be unused or used. The obfuscation identifier is used to identify obfuscation information in the target token.
[0057] Specifically, in response to each target access request containing a target token, if the target usage status of the locally stored target token is identified as unused, the target token is decrypted to obtain obfuscated token information. Based on the obfuscation identifier of the locally stored target token, obfuscated information is removed from the obfuscated token information to obtain valid token information. More specifically, in response to each target access request containing a target token, if the target usage status of the locally stored target token is identified as unused, the target token is decrypted using the RSA encryption algorithm to obtain obfuscated token information, and the usage status of the locally stored target token is updated from unused to used. Using the obfuscation identifier of the locally stored target token as a retrieval condition, the position of obfuscated information is located within the obfuscated token information. Based on the position of the obfuscated information, the obfuscated information is removed from the obfuscated token information to obtain valid token information.
[0058] Optionally, in response to each target access request containing a target token, if the target usage status of the locally stored target token is detected as "used", the token verification is determined to have failed, and the requester sending the target access request is provided with a first failure message indicating that the token verification failed.
[0059] Optionally, if decryption fails during the decryption process of the target token, the token verification is determined to have failed, and a second failure message indicating token verification failure is sent back to the requesting party that sent the target access request.
[0060] S206. Verify the target token based on the identity information of the first requester and the token validity period in the valid token information.
[0061] The first requester's identity information refers to the requester's identity information in the valid token information.
[0062] Specifically, if the first requester's identity information in the valid token information matches the second requester's identity information stored locally, the target token is verified based on the target request time of the target access request and the token validity period in the valid token information. Here, the second requester's identity information refers to the requester's identity information stored in the server's local cache. The target request time refers to the time when the requester sends the target access request to the server.
[0063] More specifically, if the identity information of the first requester in the valid token information matches the identity information of the second requester stored locally, and the target request time of the target access request is within the validity period of the token in the valid token information, it means that the target token in the target access request has not expired, and thus the token verification is successful, allowing the requester to proceed with the subsequent access process; if the target request time is not within the validity period of the token, it means that the target token in the target access request has expired, and thus the token verification is failed, and a third failure message indicating token verification failure is sent back to the requester who sent the target access request.
[0064] The technical solution of this invention, after obtaining the target token, responds to a target access request containing the target token by processing the target token according to the target usage status and obfuscation identifier of the target token stored locally to obtain valid token information; and verifies the target token according to the first requester identity information and the token validity time in the valid token information, thereby realizing the verification of the target token, ensuring the security and reliability of the target token, and improving the overall security level of the token application environment.
[0065] Based on the above embodiments, as an optional embodiment of the present invention, it is also possible to: determine the number of response failures to the at least two target access requests including the target token initiated by the same requester; and verify the target token based on the number of response failures.
[0066] The number of failed responses refers to the total number of times the server failed to respond to the target access request. It should be noted that for each target access request received by the server that includes the target token, the initial number of failed responses is zero.
[0067] Specifically, for each target access request including a target token initiated by the requester, if the target access request is not responded to by the server, it is stored in a local waiting queue. After a preset waiting time, if the target access request still has not been responded to by the server, it continues to be stored in the local waiting queue, and the number of response failures is recorded. This process is repeated until the number of response failures reaches a threshold, at which point the token verification is determined to have failed, and a fourth failure message indicating token verification failure is sent back to the requester who sent the target access request. This ensures that when the server receives at least two target access requests containing target tokens, only one target access request will be responded to by the server.
[0068] It should be noted that the preset waiting time and response failure number threshold can be preset or set randomly according to actual business needs, and the embodiments of the present invention do not impose specific limitations on them.
[0069] Example 3
[0070] Figure 3 This is a schematic diagram of a token processing device according to Embodiment 3 of the present invention. This embodiment is applicable to the generation and verification of access tokens. The device can be implemented in hardware and / or software and can be configured in an electronic device. Figure 3 As shown, the device is configured on the server side and includes:
[0071] The current generation time interval determination module 301 is used to determine the current generation time interval based on the current request time of the token generation request and the historical generation time of the requester's historical tokens when a token generation request is received from the requester.
[0072] The valid token information determination module 302 is used to integrate the necessary information of historical tokens based on the current generation time interval, the specified generation time interval, and the token validity time to obtain valid token information;
[0073] The obfuscated token information determination module 303 is used to obfuscate the valid token information based on at least one generated obfuscated information to obtain obfuscated token information;
[0074] The target token determination module 304 is used to encrypt the obfuscated token information to obtain the target token.
[0075] The technical solution of this invention, upon receiving a token generation request from a requester, determines the current generation time interval based on the current request time of the token generation request and the historical generation time of the requester's historical tokens; integrates the necessary information of historical tokens based on the current generation time interval, the specified generation time interval, and the token validity period to obtain valid token information; obfuscates the valid token information based on at least one generated obfuscation message to obtain obfuscated token information; and encrypts the obfuscated token information to obtain the target token. This technical solution, after successful authentication of the requester, limits the number of access tokens generated by the server upon receiving the token generation request, based on the current request time and the specified generation time interval; it adds the token validity period to the necessary information of historical tokens, limiting the validity period of access tokens and preventing illegal dissemination or malicious hoarding of access tokens; by adding randomly generated obfuscation information to the valid token information, it increases the randomness of the access token generation process, increasing the difficulty of cracking the access token and thus reducing the risk of access token theft; and overall, it improves the security and reliability of the access token.
[0076] Optionally, the valid token information determination module 302 is specifically used for:
[0077] If the current generation time interval is greater than or equal to the specified generation time interval, the necessary information of the historical tokens is integrated according to the token validity time to obtain the valid token information.
[0078] Optionally, the obfuscation token information determination module 303 is specifically used for:
[0079] Determine the header and footer positions of valid token information;
[0080] Insert at least one generated obfuscation message into the header or tail of the message to obtain obfuscation token information.
[0081] Optionally, the device may also include:
[0082] The target token processing module is used to respond to a target access request containing a target token, and process the target token according to the target usage status and obfuscation identifier of the target token stored locally to obtain valid token information;
[0083] The first token verification module is used to verify the target token based on the identity information of the first requester and the token validity period in the valid token information.
[0084] Optional, the target token processing module is specifically used for:
[0085] If the target token stored locally is found to be in an unused state, the target token is decrypted to obtain obfuscated token information.
[0086] Based on the obfuscation identifier of the target token stored locally, the obfuscation information in the obfuscated token information is removed to obtain the valid token information.
[0087] Optionally, the first token verification module is specifically used for:
[0088] If the identity information of the first requester in the valid token information is consistent with the identity information of the second requester stored locally, then the target token is verified according to the target request time of the target access request and the token validity time in the valid token information.
[0089] Optionally, the device may also include:
[0090] The response failure count determination module is used to determine the number of response failures for at least two target access requests that include a target token, when the same requester has initiated at least two target access requests.
[0091] The second token verification module is used to verify the target token based on the number of response failures.
[0092] The token processing device provided in the embodiments of the present invention can execute the token processing method provided in any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing each token processing method.
[0093] Example 4
[0094] Figure 4 A schematic diagram of an electronic device 10 that can be used to implement embodiments of the present invention is shown. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smartphones, wearable devices (e.g., helmets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely illustrative and are not intended to limit the implementation of the invention described and / or claimed herein.
[0095] like Figure 4As shown, the electronic device 10 includes at least one processor 11 and a memory, such as a read-only memory (ROM) 12 or a random access memory (RAM) 13, communicatively connected to the at least one processor 11. The memory stores computer programs executable by the at least one processor. The processor 11 can perform various appropriate actions and processes based on the computer program stored in the ROM 12 or loaded from storage unit 18 into the RAM 13. The RAM 13 can also store various programs and data required for the operation of the electronic device 10. The processor 11, ROM 12, and RAM 13 are interconnected via a bus 14. An input / output (I / O) interface 15 is also connected to the bus 14.
[0096] Multiple components in electronic device 10 are connected to I / O interface 15, including: input unit 16, such as keyboard, mouse, etc.; output unit 17, such as various types of displays, speakers, etc.; storage unit 18, such as disk, optical disk, etc.; and communication unit 19, such as network card, modem, wireless transceiver, etc. Communication unit 19 allows electronic device 10 to exchange information / data with other devices through computer networks such as the Internet and / or various telecommunications networks.
[0097] Processor 11 can be a variety of general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. Processor 11 performs the various methods and processes described above, such as token processing methods.
[0098] In some embodiments, the token processing method may be implemented as a computer program tangibly contained in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 10 via ROM 12 and / or communication unit 19. When the computer program is loaded into RAM 13 and executed by processor 11, one or more steps of the token processing method described above may be performed. Alternatively, in other embodiments, processor 11 may be configured to execute the token processing method by any other suitable means (e.g., by means of firmware).
[0099] Various embodiments of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-a-chip (SoCs), payload-programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments may include implementations in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which may be a dedicated or general-purpose programmable processor, capable of receiving data and instructions from a storage system, at least one input device, and at least one output device, and transmitting data and instructions to the storage system, the at least one input device, and the at least one output device.
[0100] Computer programs used to implement the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when executed by the processor, the computer programs cause the functions / operations specified in the flowcharts and / or block diagrams to be performed. The computer programs may be executed entirely on a machine, partially on a machine, or as a standalone software package, partially on a machine and partially on a remote machine, or entirely on a remote machine or server.
[0101] In the context of this invention, a computer-readable storage medium can be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, apparatus, or device. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination thereof. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0102] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user provides input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including sound input, voice input, or tactile input).
[0103] The systems and technologies described herein can be implemented in computing systems that include backend components (e.g., as data servers), or computing systems that include middleware components (e.g., application servers), or computing systems that include frontend components (e.g., user computers with graphical user interfaces or web browsers through which users can interact with implementations of the systems and technologies described herein), or any combination of such backend, middleware, or frontend components. The components of the system can be interconnected via digital data communication of any form or medium (e.g., communication networks). Examples of communication networks include local area networks (LANs), wide area networks (WANs), blockchain networks, and the Internet.
[0104] A computing system can include clients and servers. Clients and servers are generally located far apart and typically interact through communication networks. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or cloud host, which is a hosting product within the cloud computing service system to address the shortcomings of traditional physical hosts and VPS services, such as high management difficulty and weak business scalability.
[0105] It should be understood that the various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in this invention can be executed in parallel, sequentially, or in different orders, as long as the desired result of the technical solution of this invention can be achieved, and this is not limited herein.
[0106] The specific embodiments described above do not constitute a limitation on the scope of protection of this invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of this invention should be included within the scope of protection of this invention.
Claims
1. A token processing method, characterized in that, Applied to the server side, including: Upon receiving a token generation request from the requester, the current generation time interval is determined based on the current request time of the token generation request and the historical generation time of the requester's historical tokens. The current generation time interval is the time interval between the current request time and the historical generation time. Based on the current generation time interval, the specified generation time interval, and the token validity period, the necessary information of the historical tokens is integrated to obtain the valid token information; Based on at least one generated obfuscation information, the valid token information is obfuscated to obtain obfuscated token information; The obfuscated token information is encrypted to obtain the target token; The step involves integrating necessary historical token information based on the current generation time interval, the specified generation time interval, and the token validity period to obtain valid token information, including: If the current generation time interval is greater than or equal to the specified generation time interval, the necessary information of the historical tokens is integrated according to the token validity time to obtain the valid token information; If the current generation time interval is less than the specified generation time interval, the requester's historical token is retrieved from the local cache using the requester's identity identifier in the token generation request as the retrieval condition, and the historical token is returned to the requester.
2. The method according to claim 1, characterized in that, The step of obfuscating the valid token information based on at least one generated obfuscation message to obtain obfuscated token information includes: Determine the header and trailer positions of the valid token information; At least one generated obfuscation message is inserted into the header or tail of the message to obtain obfuscation token information.
3. The method according to claim 1, characterized in that, The method further includes: In response to a target access request containing the target token, the target token is processed according to the target usage status and obfuscation identifier of the target token stored locally to obtain valid token information; The target token is verified based on the identity information of the first requester and the token validity period in the valid token information.
4. The method according to claim 3, characterized in that, Based on the target usage status and obfuscation identifier of the target token stored locally, the target token is processed to obtain valid token information, including: If the target token stored locally is found to be in an unused state, the target token is decrypted to obtain obfuscated token information. Based on the obfuscation identifier of the target token stored locally, the obfuscation information in the obfuscated token information is removed to obtain the valid token information.
5. The method according to claim 3, characterized in that, The step of verifying the target token based on the first requester's identity information and the token's validity period in the valid token information includes: If the first requester identity information in the valid token information matches the second requester identity information stored locally, then the target token is verified based on the target request time of the target access request and the token validity time in the valid token information.
6. The method according to claim 3, characterized in that, The method further includes: If at least two target access requests containing the target token are received from the same requester, determine the number of times the response to the at least two target access requests fails; The target token is verified based on the number of failed responses.
7. A token processing device, characterized in that, The configuration is on the server side, including: The current generation time interval determination module is used to determine the current generation time interval based on the current request time of the token generation request and the historical generation time of the historical tokens of the requester when a token generation request is received from the requester. The current generation time interval is the time interval between the current request time and the historical generation time. The valid token information determination module is used to integrate the necessary historical token information of the historical tokens based on the current generation time interval, the specified generation time interval, and the token validity time to obtain valid token information; The obfuscated token information determination module is used to obfuscate the valid token information based on at least one generated obfuscated information to obtain obfuscated token information; The target token determination module is used to encrypt the obfuscated token information to obtain the target token; The valid token information determination module is specifically used for: If the current generation time interval is greater than or equal to the specified generation time interval, the necessary information of the historical tokens is integrated according to the token validity time to obtain the valid token information; If the current generation time interval is less than the specified generation time interval, the requester's historical token is retrieved from the local cache using the requester's identity identifier in the token generation request as the retrieval condition, and the historical token is returned to the requester.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor to enable the at least one processor to perform the token processing method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions that cause a processor to execute the token processing method according to any one of claims 1-6.
Citation Information
Patent Citations
Token verification method, device and equipment and storage medium
CN111934876A
Communication method and system for preventing replay attack, electronic device and storage medium
CN112437046A
Access request processing method, device and system
CN117335993A
Systems and methods using short-lived proxy token values obfuscating a stable long-lived token value
US9413756B1