Interface communication method, device and system

By using the dynamic signature mechanism in interface communication, the client and the server intercept and encrypt the token and key to generate dynamic signatures, solving the problem that the information is reverse decrypted after the request message is intercepted, and improving the security of interface communication.

CN119603074BActive Publication Date: 2025-05-06ZHEJIANG CHINT IOT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510128478.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-05
Publication Date
2025-05-06
Estimated Expiration
2045-02-05

AI Technical Summary

Technical Problem

During interface communication, the client's request message contains a public key. Once the request message is intercepted, the malicious party can use the intercepted public key and signature information to reverse decrypt, bypass security verification, resulting in user privacy leakage and data security issues.

Method used

The client obtains the first verification code and receives the token and key-value pairs returned by the server. Then, the token, key-value pairs and the first verification code are intercepted and encrypted to generate a first dynamic signature. According to the first dynamic signature, token and communication identifier, a first request message is generated and sent to the server. The server receives the request message, parses the dynamic signature and token, verifies its validity, and generates a second dynamic signature based on the key and verification code. When both are consistent, the requested content is executed.

Benefits of technology

Through the dynamic signature mechanism, only part of the token and key information is transmitted. Even if the request message is intercepted, the complete key and token cannot be decrypted in reverse, effectively preventing data leakage and improving the security of interface communication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119603074B_ABST
    Figure CN119603074B_ABST
Patent Text Reader

Abstract

The present application provides an interface communication method, device and system, which belongs to the field of interface communication technology. In the present application, firstly, a token and a key-value pair are received from a server, and a first verification code is obtained. Then, the token, the key-value pair and the first verification code are intercepted and encrypted to generate a first dynamic signature. Finally, according to the first dynamic signature, the token and the communication identifier, a first request message is generated, and the first request message is sent to the server, so that the server verifies the first request message, and executes the request content of the first request message after the verification is passed. Since the token, the key-value pair and the first verification code are intercepted in the process of generating the first dynamic signature, the first dynamic signature will only contain part of the content in the token, the key-value pair and the first verification code. Therefore, even if the first request message is intercepted and cracked, the complete key-value pair and the token cannot be obtained, thereby improving the security of the interface communication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of interface communication technology, and in particular to an interface communication method, device and system. Background Art

[0002] Interface communication, such as API (application programming interface) communication, serves as a bridge for interaction between different software applications or services, allowing developers to implement data exchange and function calls through preset rules and methods. In the process of interface communication between the client and the server, the client first submits account information to the server so that the server can authenticate and return an authorization token based on the account information, thereby ensuring that only authenticated users can access the server's API resources.

[0003] At present, a security verification mechanism is usually set up in the process of interface communication. That is, when requesting interface communication, the client will send a signature containing information such as request parameters together with the public key to the server. The server uses the corresponding private key to verify the signature to confirm the authenticity and integrity of the client request.

[0004] However, since the client's request message contains the public key, once the request message is maliciously intercepted during transmission, the intercepted public key and signature information may be used for reverse decryption, thereby bypassing the security verification mechanism of the interface communication, resulting in user privacy leakage and data security issues. Summary of the invention

[0005] In view of the deficiencies in the prior art, the present application provides an interface communication method, device and system.

[0006] In a first aspect, the present application provides an interface communication method, which is applied to a client, wherein the client is connected to a server for communication, and the method comprises:

[0007] Get the first verification code;

[0008] Receiving a token and a key-value pair from the server; the key-value pair includes a communication identifier and a key corresponding to the communication identifier;

[0009] Intercepting and encrypting the token, the key-value pair and the first verification code to generate a first dynamic signature;

[0010] A first request message is generated according to the first dynamic signature, the token and the communication identifier, and the first request message is sent to the server, so that the server verifies the first request message and executes the request content of the first request message after the verification is passed.

[0011] Optionally, before receiving the token and key-value pair from the server, the method further includes:

[0012] Generate a second request message according to the login request, and send the second request message to the server; the login request includes a login account;

[0013] Receiving a first verification code returned by the server through a third-party system; the first verification code is generated by the server according to the second request message;

[0014] Receiving a second verification code input by the user based on the first verification code, and sending the second verification code and the login account to the server;

[0015] A successful login message is received from the server, and the successful login message is parsed to obtain the token and the key-value pair.

[0016] Optionally, after sending the first request message to the server, the method further includes:

[0017] Deleting the key-value pairs used in the first request message;

[0018] A request feedback message is received from the server, the request feedback message is parsed to obtain a key-value pair, and the key-value pair obtained by parsing the request feedback message is stored.

[0019] Optionally, intercepting and encrypting the token, the key-value pair, and the first verification code to generate a first dynamic signature includes:

[0020] Combine the token, the key-value pair and the first verification code to obtain a first character string;

[0021] Extracting a preset number of characters from the first character string according to a preset rule as a second character string;

[0022] Encrypt the second character string according to a preset first encryption function to obtain a first encrypted character string;

[0023] Using the current time as the timestamp of the first request message, and concatenating the timestamp with the first encrypted string to obtain a second encrypted string;

[0024] The second encrypted string is encrypted according to a preset second encryption function to obtain the first dynamic signature.

[0025] In a second aspect, the present application provides an interface communication method, which is applied to a server, wherein the server is connected to a client for communication, and the method comprises:

[0026] Receiving a first request message from the client, and parsing the first request message to obtain a first dynamic signature, a token, and a communication identifier;

[0027] Verifying the token and the communication identifier, and if the verification is successful, querying the key corresponding to the communication identifier from a preset key-value pair table;

[0028] Obtaining a first verification code, and intercepting and encrypting the token, the communication identifier, the key, and the first verification code to obtain a second dynamic signature;

[0029] When the first dynamic signature is consistent with the second dynamic signature, the request content of the first request message is executed.

[0030] Optionally, before receiving the first request message from the client, the method further includes:

[0031] receiving a second request message, and generating a first verification code according to the second request message;

[0032] Sending the first verification code to the client through a third-party system;

[0033] A second verification code is received from the client, and if the second verification code is consistent with the first verification code, a login success message is sent to the client; the login success message includes the key-value pair.

[0034] Optionally, after executing the request content of the first request message, the method further includes:

[0035] Deleting the key-value pair corresponding to the communication identifier in the first request message from the preset key-value pair table;

[0036] A key-value pair is reselected from the preset key-value pair table, and a request feedback message is generated according to the reselected key-value pair, and the request feedback message is sent to the client.

[0037] Optionally, the obtaining of the first verification code, and intercepting and encrypting the token, the communication identifier, the key, and the first verification code to obtain the second dynamic signature includes:

[0038] Combine the token, the communication identifier, the key and the first verification code to obtain a first character string;

[0039] Extracting a preset number of characters from the first character string according to a preset rule as a second character string;

[0040] Encrypt the second character string according to a preset first encryption function to obtain a first encrypted character string;

[0041] Parsing the first request message to obtain a timestamp of the first request message, and concatenating the timestamp with the first encrypted string to obtain a second encrypted string;

[0042] The second encrypted string is encrypted according to a preset second encryption function to obtain the second dynamic signature.

[0043] In a third aspect, the present application provides an interface communication device, applied to a client, the device comprising:

[0044] A first receiving module, used to receive a token and a key-value pair from a server; the key-value pair includes a communication identifier and a key corresponding to the communication identifier;

[0045] A verification code acquisition module, used to acquire a first verification code;

[0046] A first signature generation module, used to intercept and encrypt the token, the key-value pair and the first verification code to generate a first dynamic signature;

[0047] A communication module is used to generate a first request message according to the first dynamic signature, the token and the communication identifier, and send the first request message to the server, so that the server verifies the first request message and executes the request content of the first request message after the verification is passed.

[0048] In a fourth aspect, the present application provides an interface communication device, applied to a server, the device comprising:

[0049] A second receiving module, used to receive a first request message from the client, and parse the first request message to obtain a first dynamic signature, a token and a communication identifier;

[0050] A verification module, used to verify the token and the communication identifier, and if the verification is successful, query the key corresponding to the communication identifier from a preset key-value pair table;

[0051] A second signature generation module is used to obtain the first verification code, and intercept and encrypt the token, the communication identifier, the key and the first verification code to obtain a second dynamic signature;

[0052] An execution module is used to execute the request content of the first request message when the first dynamic signature is consistent with the second dynamic signature.

[0053] In a fifth aspect, the present application provides an interface communication system, characterized in that it includes a client and a server;

[0054] The client is used to:

[0055] Receiving a token and a key-value pair from the server; the key-value pair includes a communication identifier and a key corresponding to the communication identifier;

[0056] Obtain a first verification code; intercept and encrypt the token, the key-value pair and the first verification code to generate a first dynamic signature;

[0057] Generate a first request message according to the first dynamic signature, the token and the communication identifier, and send the first request message to the server;

[0058] The server is used to:

[0059] Receiving a first request message from the client, and parsing the first request message to obtain a first dynamic signature, a token, and a communication identifier;

[0060] Verifying the token and the communication identifier, and if the verification is successful, querying the key corresponding to the communication identifier from a preset key-value pair table;

[0061] Obtaining a first verification code, and intercepting and encrypting the token, the communication identifier, the key, and the first verification code to obtain a second dynamic signature;

[0062] When the first dynamic signature is consistent with the second dynamic signature, the request content of the first request message is executed.

[0063] In a sixth aspect, in one embodiment, the present application provides a storage medium, wherein the storage medium stores a computer program, and the computer program is loaded by a processor to execute the steps in the interface communication method in any of the above embodiments.

[0064] To summarize, in the present application, firstly, a token and a key-value pair are received from the server, and a first verification code is obtained. Then, the token, the key-value pair and the first verification code are intercepted and encrypted to generate a first dynamic signature. After the first dynamic signature is generated, a first request message is generated according to the signature, the token and the communication identifier. Since the token, the key-value pair and the first verification code are intercepted in the process of generating the first dynamic signature, the first dynamic signature will only contain part of the content in the token, the key-value pair and the first verification code. Therefore, even if the first request message is intercepted and cracked, the complete key-value pair and the token cannot be obtained, thereby avoiding the first request message from being reversely decrypted and improving the security of the interface communication. BRIEF DESCRIPTION OF THE DRAWINGS

[0065] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For those skilled in the art, other drawings can be obtained based on these drawings without creative work.

[0066] Figure 1 A schematic diagram of an application scenario of an interface communication method in an embodiment of the present application;

[0067] Figure 2 This is a flow chart of an interface communication method of a client in one embodiment of the present application;

[0068] Figure 3 This is a flow chart of a client login method in one embodiment of the present application;

[0069] Figure 4 This is a flow chart of a method for generating a first dynamic signature in one embodiment of the present application;

[0070] Figure 5 This is a flow chart of a server interface communication method in one embodiment of the present application;

[0071] Figure 6 A schematic diagram of an interface communication device of a client in one embodiment of the present application;

[0072] Figure 7 A schematic diagram of an interface communication device of a server in one embodiment of the present application;

[0073] Figure 8 This is a schematic diagram of an electronic device in one embodiment of the present application. DETAILED DESCRIPTION

[0074] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative work are within the scope of protection of this application.

[0075] In the description of the present application, it should be understood that the terms "first" and "second" are used only for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly indicating the number of technical features indicated. Thus, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the present application, the meaning of "multiple" is two or more, unless otherwise clearly and specifically defined. In the present application, the word "exemplary" is used to mean "used as an example, illustration or description". Any embodiment described as "exemplary" in the present application is not necessarily interpreted as being more preferred or more advantageous than other embodiments. In order to enable any technician in the field to implement and use the present application, the following description is given. In the following description, details are listed for the purpose of explanation. It should be understood that a person of ordinary skill in the art can recognize that the present application can also be implemented without using these specific details. In other examples, well-known structures and processes will not be elaborated in detail to avoid unnecessary details that make the description of the present application obscure. Therefore, the present application is not intended to be limited to the embodiments shown, but is consistent with the widest range of principles and features disclosed in the present application.

[0076] The interface communication method in the embodiment of the present application is applied to an interface communication device, and the interface communication device is arranged in an electronic device; the electronic device can be a terminal, such as a mobile phone or a tablet computer, and the electronic device can also be a server, or a service cluster composed of multiple servers.

[0077] like Figure 1 As shown, Figure 1 This is a schematic diagram of an application scenario of the interface communication method in an embodiment of the present application. The application scenario of the interface communication method in an embodiment of the present application includes an electronic device 100, an interface communication device is integrated in the electronic device 100, and a computer-readable storage medium corresponding to the interface communication method is run in the electronic device 100 to execute the steps of the interface communication method.

[0078] Understandably, Figure 1 The electronic devices in the application scenario of the interface communication method shown, or the devices included in the electronic devices, do not constitute limitations on the embodiments of the present application. That is, the number of devices and types of devices included in the application scenario of the interface communication method, or the number of devices and types of devices included in each device, do not affect the overall implementation of the technical solution in the embodiments of the present application, and can all be regarded as equivalent replacements or derivatives of the technical solution claimed to be protected by the embodiments of the present application.

[0079] The electronic device 100 in the embodiment of the present application may be an independent device, or a device network or device cluster composed of devices. For example, the electronic device 100 described in the embodiment of the present application includes but is not limited to a computer, a network host, a single network device, a plurality of network device sets or a cloud device composed of a plurality of devices. The cloud device is composed of a large number of computers or network devices based on cloud computing.

[0080] Those skilled in the art will understand that Figure 1 The application scenario shown in the figure is only an application scenario corresponding to the technical solution of the present application, and does not constitute a limitation on the application scenario of the technical solution of the present application. Other application scenarios may also include Figure 1 More or fewer electronic devices shown in, or electronic device network connection relationships, such as Figure 1 Only one electronic device is shown. It can be understood that the scenario of the interface communication method can also include one or more other electronic devices, which are not specifically limited here. The electronic device 100 can also include a memory for storing information related to the interface communication method.

[0081] In addition, in the application scenario of the interface communication method in the embodiment of the present application, the electronic device 100 may be provided with a display device, or the electronic device 100 may not be provided with a display device and may be connected to an external display device 200 for communication, and the display device 200 is used to output the result of the execution of the interface communication method in the electronic device. The electronic device 100 may access a background database 300, which may be a local memory of the electronic device 100, or may be provided in the cloud, and the background database 300 may store information related to the interface communication method.

[0082] It should be noted that Figure 1 The application scenario of the interface communication method shown is merely an example. The application scenario of the interface communication method described in the embodiment of the present application is intended to more clearly illustrate the technical solution of the embodiment of the present application and does not constitute a limitation on the technical solution provided in the embodiment of the present application.

[0083] Based on the application scenario of the above interface communication method, an embodiment of the interface communication method is proposed.

[0084] First, as Figure 2 As shown, in one embodiment, the present application provides an interface communication method,

[0085] Applied to a client, the client communicates with a server, and the method includes steps S101 to S104, which are described in detail below.

[0086] Step S101: Obtain a first verification code.

[0087] As an example, the first verification code is transmitted in a non-HTTPS manner. As an example, the first verification code may be sent by a third-party system, such as obtaining the first verification code via SMS or email.

[0088] Step S102: Receive a token and a key-value pair from the server.

[0089] The key-value pair includes a communication identifier and a key corresponding to the communication identifier. The life cycle of the key-value pair is less than or equal to the life cycle of the token. That is, multiple different key-value pairs can be accepted during the life cycle of the token, and if the token expires, the key-value pair will be synchronously invalidated. Step S103: intercept and encrypt the token, the key-value pair and the first verification code to generate a first dynamic signature.

[0090] Step S104: Generate a first request message according to the first dynamic signature, token and communication identifier, and send the first request message to the server, so that the server verifies the first request message and executes the request content of the first request message after the verification is passed.

[0091] In the above implementation, first, a token and a key-value pair are received from the server, and a first verification code is obtained. Then, the token, the key-value pair and the first verification code are intercepted and encrypted to generate a first dynamic signature. After the first dynamic signature is generated, a first request message is generated according to the signature, the token and the communication identifier. Since the token, the key-value pair and the first verification code are intercepted in the process of generating the first dynamic signature, the first dynamic signature will only contain part of the content in the token, the key-value pair and the first verification code. Therefore, even if the first request message is intercepted and cracked, the complete key-value pair and the token cannot be obtained, thereby avoiding the first request message from being reversely decrypted, and improving the security of the interface communication.

[0092] Reference Figure 3 As an implementation of the interface communication method, before step S101, it also includes steps S201 to S204, which are described in detail below.

[0093] Step S201: Generate a second request message according to a login request, and send the second request message to the server. The login request includes a login account.

[0094] Step S202: Receive a first verification code returned by the server through a third-party system. The first verification code is generated by the server according to the second request message.

[0095] Step S203: receiving a second verification code input by the user based on the first verification code, and sending the second verification code and the login account to the server.

[0096] Step S204: Receive a successful login message from the server, and parse the successful login message to obtain a token and a key-value pair.

[0097] In the above implementation, a second request message is generated according to the login request, and the second request message is sent to the server. After receiving the second request message from the client, the server generates a first verification code through a third-party system and returns it to the client to ensure the security of the login process. Then, the client receives the second verification code entered by the user according to the first verification code, and sends the second verification code and the login account to the server to verify the user's identity information. Finally, when the user successfully passes the second verification code verification, the login success message returned by the server not only contains the token used for subsequent requests, but also contains the key-value pair used to generate the first dynamic signature, so as to realize subsequent encryption.

[0098] As an implementation of the interface communication method, after step S104, steps S301 and S302 are further included, which are described in detail below.

[0099] Step S301: Delete the key-value pairs used in the first request message.

[0100] Step S302: receiving a request feedback message from the server, parsing the request feedback message to obtain a key-value pair, and storing the key-value pair obtained by parsing the request feedback message.

[0101] Among them, the request feedback message is used to indicate that the first request message is executed successfully. If the request feedback message is not received, it means that the first request message fails to pass the verification of the server and cannot be executed, or the first request message is intercepted and tampered with, resulting in the failure of the first request message verification.

[0102] As an example, as long as the first request message is generated, the key-value pair of the client will be deleted. If the client does not receive a request feedback message from the server after the key-value pair is deleted, it is necessary to re-login in steps S201-S204 to re-acquire the key-value pair.

[0103] In the above implementation, each key-value pair is deleted after being used once, which effectively prevents the used key-value pairs from being reused. After receiving the request feedback message from the server, a new key-value pair is parsed from the request feedback message and stored, so that each key-value pair can be added with a new key-value pair in time after being deleted after being used once to maintain subsequent communications.

[0104] Reference Figure 4 As an implementation of step S103, step S103 may include steps S1031 to S1035, which are described in detail below.

[0105] Step S1031: Combine the token, the key-value pair and the first verification code to obtain a first character string.

[0106] As an example, after the token, the key-value pair and the first verification code are combined, a first string of execution length may be generated by compiling. For example, the first string may be a Base64 string.

[0107] Step S1032: extracting a preset number of characters from the first character string according to a preset rule as a second character string.

[0108] As an example, the preset rules need to be written into the client and the server in advance so that the client and the server can follow the same preset rules to intercept the second string. The preset number can be selected as one-fourth or one-eighth of the number of the first string, and the preset number should not exceed half of the number of characters in the first string to avoid the second string carrying too much information. Taking the preset number of 8-bit characters as an example, it can be stipulated that 8-bit characters are taken from the first string in intervals of 3 characters, 4 characters, 5 characters, and 6 characters in turn to form the second string.

[0109] Step S1033: Encrypt the second character string according to a preset first encryption function to obtain a first encrypted character string.

[0110] As an example, the preset first encryption function may be the SHA256 encryption algorithm, which is used to generate a 256-bit (64-character) hash value for input of any length. In SHA256, even changes in individual characters will result in completely different hash results, and thus a completely different first encrypted string will be obtained.

[0111] Step S1034: Use the current time as the timestamp of the first request message, and concatenate the timestamp and the first encrypted string to obtain a second encrypted string.

[0112] As an example, since the time interval between generating the first dynamic signature and generating the first request message is very short, the current moment of generating the first dynamic signature is used as the timestamp of the first request message. On the one hand, the timestamp can be added to the first dynamic signature, and on the other hand, after using the current moment as the timestamp of the first request message, the server can obtain the timestamp easily, so that the server can verify the first dynamic signature.

[0113] Step S1035: Encrypt the second encrypted string according to a preset second encryption function to obtain a first dynamic signature.

[0114] As an example, the preset second encryption function may be an MD5 (Message-Digest Algorithm 5) encryption algorithm. The MD5 hash algorithm maps data of any length into a ciphertext of a fixed length, usually 128 bits.

[0115] It should be noted that although the SHA256 encryption algorithm and the MD5 encryption algorithm are both one-way encryption algorithms, they are still likely to be cracked. Therefore, by intercepting a preset number of characters from the first string as the second string according to a preset rule, the first dynamic signature only contains partial characters of the token, key-value pair and the first verification code. Even if they are cracked, the complete token, key-value pair and the first verification code cannot be decrypted.

[0116] In the above implementation, by combining the token, the key-value pair and the first verification code, a first string containing multiple verification information is formed, which ensures the comprehensiveness of the basic information of the first dynamic signature. Then, a certain number of characters are intercepted from the first string according to the preset rules as the second string, so that the complete token, key-value pair and first verification code are not transmitted. The second string is encrypted using the preset first encryption function to obtain the first encrypted string, and the current moment is used as the timestamp, and it is spliced ​​with the first encrypted string to obtain the second encrypted string, which increases the timeliness of the first dynamic signature. Finally, the second encrypted string is encrypted using the preset second encryption function to obtain the first dynamic signature. In the whole process, only part of the characters of the first string are intercepted, avoiding the transmission of the complete token, key-value pair and first verification code, and adding the timestamp verification. Then, through the encryption of the first encryption function and the second encryption function, even if the first dynamic signature is intercepted, it cannot be reversely decrypted to obtain valid information.

[0117] Reference Figure 5 In the second aspect, the present application provides an interface communication method, which is applied to a server, and the server is connected to a client for communication. The method includes steps S401 to S404, which are described in detail below.

[0118] Step S401: receiving a first request message from a client, and parsing the first request message to obtain a first dynamic signature, a token, and a communication identifier.

[0119] Step S402: verify the token and the communication identifier. If the verification is successful, query the key corresponding to the communication identifier from the preset key-value pair table.

[0120] The preset key-value pair table may be obtained by random generation. As an example, the verification of the communication identifier may include querying whether the communication representation exists in the preset key-value pair table, and if so, the communication identifier verification is passed.

[0121] As an example, since the key corresponding to the communication identifier is encrypted into the first dynamic signature, and the first dynamic signature only transmits part of the token, the first dynamic signature and the communication identifier, the server cannot verify it by reverse decryption. Therefore, the server can only obtain the key corresponding to the communication identifier by querying the preset key-value pair.

[0122] Step S403: Obtain the first verification code, and intercept and encrypt the token, communication identifier, key and the first verification code to obtain a second dynamic signature.

[0123] As an example, the client and the server use the same processing method to process the first verification code, and encrypt the token, the communication identifier, the key and the first verification code.

[0124] Step S404: When the first dynamic signature and the second dynamic signature are consistent, the request content of the first request message is executed.

[0125] In the above implementation, the server obtains the dynamic signature, token and communication identifier by parsing the first request message, and verifies the validity of the token and communication identifier using a preset key-value pair table. Subsequently, the server uses the queried key and the first verification code to generate a second dynamic signature by intercepting and encrypting. Since the first dynamic signature cannot be reversely decrypted, the second dynamic signature can only be obtained by intercepting and encrypting it on the server in the same way as the client, and then comparing it with the first dynamic signature. Only when the two are completely consistent, the server will execute the operation in the first request message, thereby ensuring the reliability and security of communication between the server and the client.

[0126] As a further implementation of the interface communication method, steps S501 to S503 are also included before step S401, which are described in detail below.

[0127] Step S501: receiving a second request message, and generating a first verification code according to the second request message.

[0128] Step S502: Send the first verification code to the client through a third-party system.

[0129] Step S503: receiving a second verification code from the client, and if the second verification code is consistent with the first verification code, sending a login success message to the client. The login success message includes a key-value pair.

[0130] In the above implementation, after receiving the second request message, the server generates a first verification code and sends it to the client through a third-party system. When the client receives the verification code and enters it correctly, the server verifies the entered second verification code. Only when the second verification code is completely consistent with the first verification code, the server will send a login success message containing a key-value pair to the client to transmit the necessary key-value pairs in the subsequent interface communication to the client.

[0131] As a further implementation of the interface communication method, step S404 also includes steps S601 and S602, which are described in detail below.

[0132] Step S601: deleting the key-value pair corresponding to the communication identifier in the first request message from the preset key-value pair table.

[0133] As an example, since the key-value pair is used once, after the first request message is executed successfully, the key-value pair in the first request message will not appear again. At this time, the corresponding key-value pair in the preset key-value pair table is synchronously deleted to prevent the key-value pair from being used again.

[0134] As an example, each randomly generated preset key-value pair table may contain 100 key-value pairs. After each request is executed, the corresponding key-value pair is deleted from the preset key-value pair table until the number of key-value pairs contained in the preset key-value pair table is zero or less than the preset value, and then the preset key-value pair table is regenerated.

[0135] Step S602: reselect a key-value pair from the preset key-value pair table, generate a request feedback message according to the reselected key-value pair, and send the request feedback message to the client.

[0136] In the above implementation, the first request message is successfully executed, and the key-value pair corresponding to the communication identifier of the request message is deleted from the preset key-value pair table, ensuring that each key-value pair can only be used once, effectively preventing the potential risk of repeated use, thereby avoiding security issues caused by malicious use of key-value pairs. Then, the server will re-select a new key-value pair from the preset key-value pair table, and generate a request feedback message based on the new key-value pair, and send it to the client. This makes it so that each client request will use a new key-value pair, so even if a key-value pair is intercepted or leaked, it cannot be used in subsequent communications, thereby further improving the security of interface communications.

[0137] As an implementation of step S403, step S403 may include steps S4031 to S4035, which are described in detail below.

[0138] Step S4031: Combine the token, the communication identifier, the key and the first verification code to obtain a first character string.

[0139] Step S4032: extracting a preset number of characters from the first character string according to a preset rule as a second character string.

[0140] Step S4033: Encrypt the second character string according to a preset first encryption function to obtain a first encrypted character string.

[0141] Step S4034: Parse the first request message to obtain the timestamp of the first request message, and concatenate the timestamp and the first encrypted string to obtain a second encrypted string.

[0142] Step S4035: Encrypt the second encrypted string according to a preset second encryption function to obtain a second dynamic signature.

[0143] As an example, the implementation methods of steps S4031-S4035 are similar to those of steps S1031-S1035, and are not described here. The difference from steps S1031-S1035 is the method of obtaining the timestamp. In step S4034, the first request message is parsed to obtain the timestamp of the first request message, which is the time when the first dynamic signature is generated in step S1034, thereby achieving consistency of the timestamps in the process of generating the first dynamic signature and the second dynamic signature.

[0144] In a third aspect, the present application provides an interface communication device, which is applied to a client, and the device includes a first receiving module, a verification code acquisition module, a first signature generation module and a communication module.

[0145] The first receiving module is used to receive a token and a key-value pair from the server, wherein the key-value pair includes a communication identifier and a key corresponding to the communication identifier.

[0146] The verification code acquisition module is used to obtain a first verification code.

[0147] The first signature generation module is used to intercept and encrypt the token, the key-value pair and the first verification code to generate a first dynamic signature.

[0148] The communication module is used to generate a first request message according to the first dynamic signature, the token and the communication identifier, and send the first request message to the server, so that the server verifies the first request message and executes the request content of the first request message after the verification is passed.

[0149] In a fourth aspect, the present application provides an interface communication device, which is applied to a server, and the device includes a second receiving module, a verification module, a second signature generation module and an execution module.

[0150] The second receiving module is used to receive a first request message from a client, and parse the first request message to obtain a first dynamic signature, a token and a communication identifier.

[0151] The verification module is used to verify the token and the communication identifier. If the verification is successful, the key corresponding to the communication identifier is queried from the preset key-value pair table.

[0152] The second signature generation module is used to obtain the first verification code, and intercept and encrypt the token, the communication identifier, the key and the first verification code to obtain a second dynamic signature.

[0153] The execution module is used to execute the request content of the first request message when the first dynamic signature and the second dynamic signature are consistent.

[0154] In a fifth aspect, the present application provides an interface communication system, characterized in that it includes a client and a server.

[0155] The client is used to:

[0156] Receive a token and a key-value pair from the server. The key-value pair includes a communication identifier and a key corresponding to the communication identifier.

[0157] Obtain a first verification code. Intercept and encrypt the token, the key-value pair, and the first verification code to generate a first dynamic signature.

[0158] A first request message is generated according to the first dynamic signature, the token and the communication identifier, and the first request message is sent to the server.

[0159] The server is used to:

[0160] A first request message is received from a client, and the first request message is parsed to obtain a first dynamic signature, a token, and a communication identifier.

[0161] The token and the communication identifier are verified. If the verification is successful, the key corresponding to the communication identifier is queried from the preset key-value pair table.

[0162] The first verification code is obtained, and the token, the communication identifier, the key and the first verification code are intercepted and encrypted to obtain a second dynamic signature.

[0163] When the first dynamic signature and the second dynamic signature are consistent, the request content of the first request message is executed.

[0164] In a sixth aspect, in one embodiment, the present application provides an electronic device, such as Figure 8 As shown, it shows the structure of the electronic device involved in this application, specifically:

[0165] The electronic device may include components such as a processor 401 with one or more processing cores, a memory 402 with one or more computer-readable storage media, a power supply 403, and an input unit 404. Those skilled in the art will appreciate that Figure 8 The structure of the electronic device shown in the figure does not constitute a limitation on the electronic device, and may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.

[0166] The processor 401 is the control center of the electronic device, which uses various interfaces and lines to connect various parts of the entire electronic device, and executes various functions of the electronic device and processes data by running or executing software programs and / or modules stored in the memory 402, and calling data stored in the memory 402, so as to monitor the electronic device as a whole. Optionally, the processor 401 may include one or more processing cores; preferably, the processor 401 may integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, user interface and computer programs, etc., and the modem processor mainly processes wireless communications. It is understandable that the above-mentioned modem processor may not be integrated into the processor 401.

[0167] The memory 402 can be used to store software programs and modules. The processor 401 executes various functional applications and data processing by running the software programs and modules stored in the memory 402. The memory 402 may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, a computer program required for at least one function (such as a sound playback function, an image playback function, etc.), etc.; the data storage area may store data created according to the use of the server, etc. In addition, the memory 402 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage devices. Accordingly, the memory 402 may also include a memory controller to provide the processor 401 with access to the memory 402.

[0168] The electronic device also includes a power supply 403 for supplying power to each component. Preferably, the power supply 403 can be logically connected to the processor 401 through a power management system, so as to manage charging, discharging, power consumption and other functions through the power management system. The power supply 403 can also include one or more DC or AC power supplies, recharging systems, power failure detection circuits, power converters or inverters, power status indicators and other arbitrary components.

[0169] The electronic device may further include an input unit 404, which may be used to receive input digital or character information and generate keyboard, mouse, joystick, optical or trackball signal input related to user settings and function control.

[0170] A person of ordinary skill in the art will appreciate that all or part of the steps in any of the methods of the above embodiments may be completed by a computer program, or by controlling related hardware through a computer program. The computer program may be stored in a computer-readable storage medium and loaded and executed by a processor.

[0171] In a seventh aspect, in one embodiment, the present application provides a storage medium storing a plurality of computer programs, which can be loaded by a processor to execute the steps in the above-mentioned interface communication method.

[0172] It will be appreciated by those skilled in the art that any reference to memory, storage, database or other medium used in the embodiments provided herein may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in a variety of forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink), DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).

[0173] Since the computer program stored in the storage medium can execute the steps in the interface communication method in any one of the embodiments provided in the present application, the beneficial effects that can be achieved by the interface communication method in any one of the embodiments provided in the present application can be achieved. Please refer to the previous embodiments for details and will not be repeated here.

[0174] The specific implementation of the above operations can be found in the previous embodiments, which will not be described in detail here.

[0175] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, please refer to the detailed description of other embodiments above, and will not be repeated here.

[0176] The interface communication method, device and system provided by the present application are introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea; at the same time, for technical personnel in this field, according to the idea of ​​the present application, there will be changes in the specific implementation method and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

[0177] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

Claims

1. An interface communication method, characterized in that: Applied to a client, the client is connected to a server for communication, and the method includes: Generate a second request message according to the login request, and send the second request message to the server; Receiving a first verification code returned by the server through a third-party system; Get the first verification code; Receiving a token and a key-value pair from the server; the key-value pair includes a communication identifier and a key corresponding to the communication identifier; Intercepting and encrypting the token, the key-value pair and the first verification code to generate a first dynamic signature; A first request message is generated according to the first dynamic signature, the token and the communication identifier, and the first request message is sent to the server, so that the server verifies the first request message and executes the request content of the first request message after the verification is passed.

2. The interface communication method according to claim 1, characterized in that: The login request includes a login account; The first verification code is generated by the server according to the second request message; Before receiving the token and key-value pair from the server, the method further includes: Receiving a second verification code input by the user based on the first verification code, and sending the second verification code and the login account to the server; A successful login message is received from the server, and the successful login message is parsed to obtain the token and the key-value pair.

3. The interface communication method according to claim 2, characterized in that: After sending the first request message to the server, the method further includes: Deleting the key-value pairs used in the first request message; A request feedback message is received from the server, the request feedback message is parsed to obtain a key-value pair, and the key-value pair obtained by parsing the request feedback message is stored.

4. The interface communication method according to claim 1, characterized in that: The intercepting and encrypting the token, the key-value pair and the first verification code to generate a first dynamic signature includes: Combine the token, the key-value pair and the first verification code to obtain a first character string; Extracting a preset number of characters from the first character string according to a preset rule as a second character string; Encrypt the second character string according to a preset first encryption function to obtain a first encrypted character string; Using the current time as the timestamp of the first request message, and concatenating the timestamp with the first encrypted string to obtain a second encrypted string; The second encrypted string is encrypted according to a preset second encryption function to obtain the first dynamic signature.

5. An interface communication method, characterized in that: Applied to a server, the server is connected to a client for communication, and the method includes: Receiving a first request message from the client, and parsing the first request message to obtain a first dynamic signature, a token, and a communication identifier; Verifying the token and the communication identifier, and if the verification is successful, querying the key corresponding to the communication identifier from a preset key-value pair table; Obtaining a first verification code, and intercepting and encrypting the token, the communication identifier, the key, and the first verification code to obtain a second dynamic signature; When the first dynamic signature is consistent with the second dynamic signature, the request content of the first request message is executed.

6. The interface communication method according to claim 5, characterized in that: Before receiving the first request message from the client, the method further includes: receiving a second request message, and generating a first verification code according to the second request message; Sending the first verification code to the client through a third-party system; A second verification code is received from the client, and if the second verification code is consistent with the first verification code, a login success message is sent to the client; the login success message includes the key-value pair.

7. The interface communication method according to claim 5, characterized in that: After executing the request content of the first request message, the method further includes: Deleting the key-value pair corresponding to the communication identifier in the first request message from the preset key-value pair table; A key-value pair is reselected from the preset key-value pair table, and a request feedback message is generated according to the reselected key-value pair, and the request feedback message is sent to the client.

8. The interface communication method according to claim 5, characterized in that: The obtaining of the first verification code, and intercepting and encrypting the token, the communication identifier, the key, and the first verification code to obtain a second dynamic signature includes: Combine the token, the communication identifier, the key and the first verification code to obtain a first character string; Extracting a preset number of characters from the first character string according to a preset rule as a second character string; Encrypt the second character string according to a preset first encryption function to obtain a first encrypted character string; Parsing the first request message to obtain a timestamp of the first request message, and concatenating the timestamp with the first encrypted string to obtain a second encrypted string; The second encrypted string is encrypted according to a preset second encryption function to obtain the second dynamic signature.

9. An interface communication device, characterized in that: Applied to a client, the device comprises: A first receiving module, used to receive a token and a key-value pair from a server; the key-value pair includes a communication identifier and a key corresponding to the communication identifier; A verification code acquisition module, used to generate a second request message according to the login request, and send the second request message to the server; receive the first verification code returned by the server through the third-party system; and obtain the first verification code; A first signature generation module, used to intercept and encrypt the token, the key-value pair and the first verification code to generate a first dynamic signature; A communication module is used to generate a first request message according to the first dynamic signature, the token and the communication identifier, and send the first request message to the server, so that the server verifies the first request message and executes the request content of the first request message after the verification is passed.

10. An interface communication device, characterized in that: Applied to the server, the device comprises: A second receiving module, used to receive a first request message from a client, and parse the first request message to obtain a first dynamic signature, a token and a communication identifier; A verification module, used to verify the token and the communication identifier, and if the verification is successful, query the key corresponding to the communication identifier from a preset key-value pair table; A second signature generation module is used to obtain the first verification code, and intercept and encrypt the token, the communication identifier, the key and the first verification code to obtain a second dynamic signature; An execution module is used to execute the request content of the first request message when the first dynamic signature is consistent with the second dynamic signature.

11. An interface communication system, characterized in that: Including client and server; The client is used to: Receiving a token and a key-value pair from the server; the key-value pair includes a communication identifier and a key corresponding to the communication identifier; Generate a second request message according to the login request, and send the second request message to the server; receive a first verification code returned by the server through a third-party system; and obtain the first verification code; Intercepting and encrypting the token, the key-value pair and the first verification code to generate a first dynamic signature; Generate a first request message according to the first dynamic signature, the token and the communication identifier, and send the first request message to the server; The server is used for; Receiving a first request message from the client, and parsing the first request message to obtain a first dynamic signature, a token, and a communication identifier; Verifying the token and the communication identifier, and if the verification is successful, querying the key corresponding to the communication identifier from a preset key-value pair table; Obtaining a first verification code, and intercepting and encrypting the token, the communication identifier, the key, and the first verification code to obtain a second dynamic signature; When the first dynamic signature is consistent with the second dynamic signature, the request content of the first request message is executed.

Citation Information

Patent Citations

  • Request sending and verifying method, device and equipment

    CN111541542A

  • Short password verification method and verification system, electronic equipment and storage medium

    CN116244670A