Business token verification methods, devices, electronic devices, and readable storage media

CN119853976BActive Publication Date: 2026-08-14CHINA MOBILE INTERNET CO LTD +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-24
Publication Date
2026-08-14

AI Technical Summary

Technical Problem

[0004]本申请实施例提供一种业务令牌的验证方法、装置、电子设备及可读存储介质,能够解决服务端接收到用户在客户端输入令牌后,需要将接收的令牌分别与生成的每个业务环境对应的令牌都进行比对导致令牌的验证效率较低的问题

Benefits of technology

[0013]In this embodiment, the server receives a service token to be verified from the client, and determines the target service environment identifier corresponding to the service token to be verified based on the service token to be verified and the first user key. The server can determine the target service environment based on the target service environment identifier, and thus accurately verify the service token to be verified based on the target service token corresponding to the target service environment. This eliminates the need to compare the service token to be verified with tokens corresponding to multiple service environments, thus improving the verification efficiency of the service token.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119853976B_ABST
    Figure CN119853976B_ABST
Patent Text Reader

Abstract

This application discloses a service token verification method, apparatus, electronic device, and readable storage medium, comprising: receiving a service token to be verified sent by a client; determining a target service environment identifier corresponding to the service token to be verified based on the service token to be verified and a first user key; wherein the target service environment identifier is used to identify a target service environment; and verifying the service token to be verified based on the target service token corresponding to the target service environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application belongs to the field of information technology, and specifically relates to a method, apparatus, electronic device, and readable storage medium for verifying a business token. Background Technology

[0002] In related technologies, after a user enters a token on the client and submits it to the server, since the server includes multiple business environments, the server needs to generate a token for each business environment and compare the generated tokens to see if they contain the token entered by the user on the client. If they do, the token is verified.

[0003] However, after the server receives the token entered by the user on the client, it cannot determine which business environment the user needs to authenticate. Therefore, it needs to compare the received token with the token corresponding to each business environment, resulting in low token verification efficiency. Summary of the Invention

[0004] This application provides a method, apparatus, electronic device, and readable storage medium for verifying business tokens, which can solve the problem that the verification efficiency of tokens is low because the server needs to compare the received token with the token corresponding to each generated business environment after receiving the token entered by the user on the client.

[0005] In a first aspect, embodiments of this application provide a method for verifying a service token, applied to a server. The method includes: receiving a service token to be verified sent by a client; determining a target service environment identifier corresponding to the service token to be verified based on the service token to be verified and a first user key; wherein the target service environment identifier is used to identify a target service environment; and verifying the service token to be verified based on the target service token corresponding to the target service environment.

[0006] Secondly, embodiments of this application provide a method for verifying a business token, applied to a client. The method includes: generating a first random number in response to an input user account and user password; receiving a second random number sent by a server and a business environment identifier corresponding to each business environment; wherein the second random number is generated by the server when the user account and user password are successfully verified; generating a business token to be verified based on the first random number, the second random number, and a target business environment identifier; wherein the target business environment identifier is one of the business environment identifiers corresponding to each business environment; and sending the business token to be verified to the server.

[0007] Thirdly, embodiments of this application provide a service token verification device, which includes: a receiving module for receiving a service token to be verified sent by a client; a determining module for determining a target service environment identifier corresponding to the service token to be verified based on the service token to be verified and a first user key; wherein the target service environment identifier is used to identify a target service environment; and a verification module for verifying the service token to be verified based on the target service token corresponding to the target service environment.

[0008] Fourthly, embodiments of this application provide a business token verification device, which includes: a generation module, configured to generate a first random number in response to an input user account and user password; a receiving module, configured to receive a second random number sent by a server and a business environment identifier corresponding to each business environment; wherein the second random number is generated by the server based on the successful verification of the received user account and user password; the generation module is further configured to generate a business token to be verified based on the first random number, the second random number, and a target business environment identifier; wherein the target business environment identifier is one of the business environment identifiers corresponding to each business environment; and a sending module, configured to send the business token to be verified to the server.

[0009] Fifthly, embodiments of this application provide an electronic device including a processor, a memory, and a program or instructions stored in the memory and executable on the processor. When the program or instructions are executed by the processor, they implement the steps of the method described in the first aspect, or implement the steps of the method described in the second aspect.

[0010] In a sixth aspect, embodiments of this application provide a readable storage medium on which a program or instructions are stored, which, when executed by a processor, implement the steps of the method described in the first aspect, or implement the steps of the method described in the second aspect.

[0011] In a seventh aspect, embodiments of this application provide a chip, the chip including a processor and a communication interface, the communication interface being coupled to the processor, the processor being used to run programs or instructions to implement the steps of the method described in the first aspect, or to implement the steps of the method described in the second aspect.

[0012] Eighthly, embodiments of this application provide a computer program product, the computer program product including a computer program stored on a non-transitory computer-readable storage medium, the computer program including a program or instructions, which, when executed, implement the steps of the method described in the first aspect, or implement the steps of the method described in the second aspect.

[0013] In this embodiment, the server receives a service token to be verified from the client, and determines the target service environment identifier corresponding to the service token to be verified based on the service token to be verified and the first user key. The server can determine the target service environment based on the target service environment identifier, and thus accurately verify the service token to be verified based on the target service token corresponding to the target service environment. This eliminates the need to compare the service token to be verified with tokens corresponding to multiple service environments, thus improving the verification efficiency of the service token. Attached Figure Description

[0014] Figure 1 This is a flowchart illustrating a business token verification method provided in an embodiment of this application; Figure 2 This is a flowchart illustrating another business token verification method provided in an embodiment of this application; Figure 3 This is a flowchart illustrating another business token verification method provided in an embodiment of this application; Figure 4 This is a schematic diagram of the structure of a service token verification device provided in an embodiment of this application; Figure 5 This is a schematic diagram of the structure of another business token verification device provided in an embodiment of this application; Figure 6 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this application. Detailed Implementation

[0015] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0016] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0017] The following description, in conjunction with the accompanying drawings, details the verification method, apparatus, electronic device, and readable storage medium for service tokens provided in this application, through specific embodiments and application scenarios.

[0018] Figure 1 This diagram illustrates a flowchart of a service token verification method provided in an embodiment of this application. This method is applied to a server and can be executed by an electronic device. See also... Figure 1 The method may include the following steps.

[0019] Step 102: Receive the service token to be verified sent by the client.

[0020] The business token to be verified is generated by the client. The client adds the identification information corresponding to the target business environment when generating the business token to be verified, based on the target business environment that needs to be authenticated. This enables the server to analyze and determine the target business environment that needs to be authenticated when it receives the business token to be verified.

[0021] Step 104: Determine the target business environment identifier corresponding to the business token to be verified based on the business token to be verified and the first user key; wherein, the target business environment identifier is used to identify the target business environment.

[0022] The business token to be verified carries identification information about the target business environment. The server analyzes the business token to determine the target business environment identifier, thus knowing the target business environment of the business token the client currently needs to verify. The first user key is generated by the server and is used to assist in determining the target business environment identifier carried by the business token to be verified.

[0023] Step 106: Verify the service token to be verified based on the target service token corresponding to the target service environment.

[0024] In this embodiment, the server receives a service token to be verified from the client, analyzes the service token, and determines the target service environment identifier corresponding to the service token based on the service token and the first user key. The server can determine the target service environment based on the target service environment identifier, and then accurately verify the service token to be verified based on the target service token corresponding to the target service environment. This eliminates the need to compare the service token to be verified with tokens corresponding to multiple service environments, thus improving the verification efficiency of the service token.

[0025] In one implementation, step 104 above, which determines the target business environment identifier corresponding to the business token to be verified based on the business token to be verified and the first user key, includes the following steps.

[0026] Step 1041: Extract the original business token and the target business environment number from the business token to be verified.

[0027] The client-generated business token to be verified carries the original business token and the target business environment number corresponding to the target business environment identifier. In one implementation, based on the generation method of the business token to be verified, the value at the first preset position of the business token to be verified is the original business token, and the value at the second preset position of the business token to be verified is the target business environment number. Thus, the original business token and the target business environment number can be extracted by intercepting the value at the preset position of the business token to be verified.

[0028] Step 1042: Determine the target business environment identifier based on the first user key, the original business token, and the target business environment number.

[0029] In this embodiment, the server analyzes the received service token to be verified, extracts the original service token and the target service environment number carried in the service token to be verified, and then determines the target service environment identifier based on the obtained original service token, target service environment number and first user key. The target service environment identifier can be used to determine the target service environment of the service token to be verified that the client needs to verify. The target service token corresponding to the target service environment is then used to verify the service token to be verified. This eliminates the need to compare the service token to be verified with tokens corresponding to multiple service environments, thus improving the verification efficiency of the service token.

[0030] In one implementation, step 1042 above, which determines the target service environment identifier based on the first user key, the original service token, and the target service environment number, includes the following steps.

[0031] Step 1042a: Concatenate the original service token with the first user key to obtain the first result.

[0032] Step 1042b: Add the values ​​of each bit in the first result after hash processing to obtain the second result.

[0033] The first result after hashing is a hash value of fixed length. By adding up the values ​​of each bit, we can get a numerical value, which is the second result.

[0034] Step 1042c: Perform a modulo operation between the second result and the token length of the original business token to obtain the third result.

[0035] The length of the original business token is a preset value, which can be 6 digits.

[0036] Step 1042d: Determine the target business environment identifier based on the target business environment number and the third result.

[0037] Specifically, based on the target business environment number and the third result, the target business environment identifier is determined to correspond to the method by which the client generates the business token to be verified. In one implementation, the client generates the business token to be verified by concatenating the original business token with a second user key (also generated by the client) to obtain a first result. Then, each bit of the hashed first result is added to obtain a second result. The second result is then moduloed by the length of the original business token to obtain a third result. The target business environment identifier is then subtracted from the third result to obtain the target business environment number. Thus, the server determines the target business environment identifier based on the target business environment number and the third result by adding the third result to the target business environment number.

[0038] In this embodiment, after the server extracts the original business token and the target business environment number from the business token to be verified, it concatenates the original business token with the first user key to obtain a first result, then hashes the first result, adds each bit of the hashed first result to obtain a second result, and then moduloes the second result with the token length of the original business token to obtain a third result. Based on the target business environment number and the third result, the target business environment identifier is determined. Thus, based on the first user key, the original business token, and the target business environment number, the target business environment identifier is determined so that the target business environment of the business token to be verified currently required by the client can be determined through the target business environment identifier.

[0039] In one implementation, step 106 above verifies the service token to be verified based on the target service token corresponding to the target service environment, including the following steps.

[0040] Step 1061: Obtain the target user key corresponding to the target business environment based on the target business environment identifier.

[0041] The server stores different business environment identifiers and user keys under different business environments. Based on the target business environment identifier, the target user key corresponding to the target business environment can be determined, which is used to generate the target business token under the target business environment and verify the business token to be verified.

[0042] Step 1062: Generate business token information corresponding to the target business environment based on the target user key and the timestamp of the target user key.

[0043] One method for generating the business token information corresponding to the target business environment is to concatenate the target user key with its timestamp. The timestamp of the target user key represents the time when the server obtains the target user key based on the target business environment identifier.

[0044] Step 1063: Determine the target service token corresponding to the target service environment based on the target user key and the service token information.

[0045] Specifically, the target user key and service token information can be processed separately using the SM3 hash algorithm to generate hash values ​​corresponding to the target user key and the service token information. Then, the values ​​at corresponding positions of the hash values ​​corresponding to the target user key and the service token information are ORed, and the result is moduloed by a preset token length to obtain the target service token. Furthermore, if the length of the target service token is less than the preset token length, zero-padding is performed to ensure that the length of the target service token meets the preset token length, thus obtaining the final target service token, which is used to verify the service token to be verified.

[0046] Step 1064: Verify the service token to be verified by comparing the value of the target service token with the value of the original service token.

[0047] In this embodiment, after determining the target business environment identifier corresponding to the business token to be verified based on the business token to be verified and the first user key, the server obtains the target user key corresponding to the target business environment based on the target business environment identifier. Then, it generates business token information corresponding to the target business environment based on the target user key and its timestamp. Finally, it determines the target business token corresponding to the target business environment based on the business token information and the target user key. By comparing the value of the target business token with the value of the original business token, the business token to be verified is verified. This achieves accurate verification of the business token to be verified based on the target business token corresponding to the target business environment, without having to compare the business token to be verified with tokens corresponding to multiple business environments, thus improving the verification efficiency of the business token.

[0048] In one implementation, step 1064 above verifies the service token to be verified by comparing the value of the target service token with the value of the original service token. This may include: if the value of the target service token is the same as the value of the original service token, determining that the service token to be verified passes the verification.

[0049] In this embodiment, the server compares the value of the target service token with the value of the original service token. If the value of the target service token is the same as the value of the original service token, the server determines that the service token to be verified has passed the verification. This achieves accurate and efficient verification of the service token to be verified by using the target service token corresponding to the target service environment.

[0050] In one implementation, before receiving the service token to be verified sent by the client in step 102 above, the method further includes the following steps.

[0051] Step 1011: Receive the user account, user password and first random number sent by the client.

[0052] The server receives the user account and password sent by the client and verifies the identity of the user logging in. The client's first random number and the server's second random number are used to generate user keys, including the server's first user key, the client's second user key, and user keys for various business environments on the server.

[0053] Step 1012: If the user account and the user password are successfully verified, generate a second random number.

[0054] If the user account and password verification is successful, the account and password entered by the current user on the client are verified and can proceed to further verification of the business token. The second random number and the first random number are used to generate user keys, including the server's first user key, the client's second user key, and user keys for various business environments on the server.

[0055] Step 1013: Generate the first user key based on the first random number and the second random number.

[0056] In this embodiment, the server receives the user account and password sent by the client to verify the identity of the user logging into the client. If the user account and password are successfully verified, the account and password entered by the current user on the client are verified, and further verification of the business token can be performed. A second random number is generated, and a first user key is generated based on the second random number and the first random number sent by the client. The first user key is stored on the server and used to assist in determining the target business environment identifier carried by the business token to be verified.

[0057] In one implementation, after generating a second random number in step 1012 where the user account and the user password are successfully verified, the method further includes sending the second random number and the business environment identifier corresponding to each business environment to the client.

[0058] In this embodiment, when the user account and password are successfully verified, the server generates a second random number and sends it to the client. The client then generates a second user key based on this second random number and the first random number it generates. The server also sends business environment identifiers corresponding to various business environments to the client, allowing the client to select the desired target business environment. Based on the target business environment identifier, the first random number, and the second random number, the server generates a business token to be verified. The server analyzes this business token to determine which target business token to use for accurate verification within the target business environment, eliminating the need to compare the business token with tokens from multiple business environments, thus improving verification efficiency.

[0059] Figure 2 This application provides a flowchart illustrating another business token verification method, which is applied to a client and can be executed by an electronic device. See also... Figure 2 The method may include the following steps.

[0060] Step 202: In response to the input user account and user password, generate a first random number.

[0061] Users log in to the client by entering their username and password. The client sends the username and password to the server, which verifies them to confirm the user's identity. A first random number from the client and a second random number from the server are used to generate user keys, including a first user key from the server, a second user key from the client, and user keys for various business environments on the server.

[0062] Step 204: Receive the second random number sent by the server and the business environment identifier corresponding to each business environment.

[0063] The second random number is generated by the server based on the successful verification of the received user account and user password, and is used together with the first random number to generate user keys, including the server's first user key, the client's second user key, and user keys under various business environments of the server.

[0064] Step 206: Generate a service token to be verified based on the first random number, the second random number, and the target business environment identifier.

[0065] The target business environment identifier is one of the business environment identifiers corresponding to each of the various business environments. The generated business token to be verified carries the target business environment identifier, so that the server can analyze the business token to be verified and determine which target business token corresponding to the target business environment should be used to verify the business token to be verified.

[0066] Step 208: Send the business token to be verified to the server.

[0067] In this embodiment, the client generates a first random number in response to the input user account and password, and sends the user account, password, and first random number to the server. The server receives the user account and password from the client to verify the identity of the user logging into the client. If the user account and password verification is successful, a second random number is generated, and the second random number, along with the business environment identifier corresponding to each business environment, is sent to the client. The client receives the second random number and the business environment identifier corresponding to each business environment from the server, and then generates a business token to be verified based on the first random number, the second random number, and the target business environment identifier. The client sends the business token to be verified to the server. The server analyzes the business token to be verified and determines to use the target business token corresponding to the target business environment for accurate verification, without having to compare the business token to be verified with tokens corresponding to multiple business environments, thus improving the verification efficiency of the business token.

[0068] In one implementation, step 206 above generates a service token to be verified based on the first random number, the second random number, and the target business environment identifier, including the following steps.

[0069] Step 2061: Generate a second user key based on the first random number and the second random number.

[0070] The second user key can be generated by hashing the concatenated first and second random numbers.

[0071] Step 2062: Generate the original business token information based on the second user key and the timestamp of the second user key.

[0072] One method for generating the original business token information is to concatenate the second user key with its timestamp. The timestamp of the second user key represents the time when the client generated the second user key.

[0073] Step 2063: Determine the original service token based on the second user key and the original service token information.

[0074] The original business token can be determined by using the SM3 hash algorithm to combine the second user key with the original business token information.

[0075] Step 2064: Determine the service token to be verified based on the second user key, the original service token, and the target service environment number corresponding to the target service environment identifier.

[0076] In this embodiment, the client generates a second user key by generating a first random number and receiving a second random number sent by the server. Then, it generates original service token information by combining the timestamp of the second user key with the first random number. The client determines the original service token based on the original service token information and the second user key. Finally, the client determines the final service token to be verified based on the original service token, the second user key, and the target service environment number corresponding to the target service environment identifier. The service token to be verified carries the target service environment number corresponding to the target service environment identifier, so that the server can accurately verify the service token to be verified by analyzing the service token to be verified and determining that the target service token corresponding to the target service environment can be used.

[0077] In one implementation, step 2063 above, which determines the original service token based on the second user key and the original service token information, may include the following steps.

[0078] Step 2063a: The second user key and the original business token information are processed by the SM3 hash algorithm to generate a first hash value and a second hash value.

[0079] Among them, the SM3 hash algorithm can process second user keys of different lengths and original business token information into hash values ​​of fixed length, so that the generated first hash value and second hash value can be subjected to subsequent OR operation processing.

[0080] Step 2063b: Perform an OR operation between the first hash value and the corresponding position of the second hash value to obtain the first numerical value.

[0081] The first hash value and the second hash value have the same length, which allows for OR operations to be performed on the values ​​at corresponding positions of the first hash value and the second hash value.

[0082] Step 2063c: Perform a remainder operation between the first value and the preset token length to obtain the second value.

[0083] The preset token length is the preset length of the original business token, which can be 6 digits.

[0084] Step 2063d: If the length of the second value is less than the preset token length, the second value is padded with zeros to obtain the original business token.

[0085] In this embodiment, the client processes the generated second user key and the original service token information using the SM3 hash algorithm to generate a first hash value corresponding to the second user key and a second hash value corresponding to the original service token information. This ensures that the second user key and the original service token information are processed into hash values ​​of the same length. Then, the values ​​at corresponding positions of the first hash value and the second hash value are ORed to obtain a first value with the same length as the first hash value and the second hash value. The first value is then moduloed by a preset token length to obtain a second value. If the length of the second value is less than the preset token length, the second value is padded with zeros to obtain the original service token. This determines the original service token, which serves as the core part of the service token to be verified. The target environment service number corresponding to the target service environment identifier is then added to form the service token to be verified. This allows the server to analyze the service token to determine whether the target service token corresponding to the target service environment can be used to accurately verify the service token to be verified.

[0086] Figure 3 This illustration shows a flowchart of another business token verification method provided in an embodiment of this application. This method is applied to both the client and server sides. (See also...) Figure 3 The method may include the following steps.

[0087] Step 301: In response to the user's input username and password, the client generates a random seed a and sends the username, password, and random seed a to the server.

[0088] The random seed 'a' can be generated using the MD5 algorithm.

[0089] Step 302: The server receives the user account, user key, and random seed a, verifies the user account and user key, and generates random seed b if the verification is successful.

[0090] Step 303: The server concatenates random seed a and random seed b, and uses the concatenated a and b to generate the first user key through the SM3 hash algorithm and stores it.

[0091] Step 304: The server sends the random seed b and the business environment identifier corresponding to each business environment to the client.

[0092] The business environment identifier for each business environment can be represented by the numbers 0-9.

[0093] Step 305: The client concatenates random seed a and random seed b, and uses the concatenated a and b to generate a second user key through the SM3 hash algorithm.

[0094] Step 306: Concatenate the second user key and the current timestamp to generate the original business token information.

[0095] This can be generated using JSON Web Tokens (JWT).

[0096] Step 307: Using the second user key as the key and the original business token information as the value, process them using the SM3 hash algorithm to obtain their corresponding hash values.

[0097] Step 308: Perform an OR operation on each bit of the hash value and then perform a remainder operation with the preset token length to obtain the original business token.

[0098] The default token length can be 6 characters.

[0099] In cases where the length of the obtained original business token is less than the preset token length, zeros are added to the front of the original business token to make the token length of the original business token the preset token length.

[0100] Step 309: Concatenate the second user key with the obtained original business token to obtain result 1.

[0101] For example, if the second user key is 19badaa78a3aced541e4f6c15fc12ade, the generated original business token is 007788, and the result 1 is 00778819badaa78a3aced541e4f6c15fc12ade.

[0102] Step 310: Add up the values ​​of each bit of the hash result 1 to get result 2.

[0103] For example, the hash value of result 1 is 002700, and the hash value of result 2 is 0+0+2+7+0+0 = 9.

[0104] Step 311: Perform a modulo operation between result 2 and the token length of the original business token to obtain result 3.

[0105] For example, result 2 is 45, the token length of the original business token is 6, and result 3 is 45 % 6 = 3.

[0106] Step 312: Subtract the result 3 from the target business environment identifier to obtain the target business environment number corresponding to the target business environment identifier.

[0107] For example, if the target business environment identifier is 6, the target business environment number is 6-3 = 3.

[0108] Step 313: Append the target business environment number to the original business token to obtain the business token to be verified.

[0109] For example, the target business environment number is 3, the original business token is 007788, and the final business token to be verified is 3007788.

[0110] Steps 305 to 313 above are the steps for the client to generate a business token to be verified.

[0111] Step 314: The user enters the business token to be verified in the output window of the client, and the client sends the business token to be verified to the server.

[0112] In one alternative implementation, users can log in to applications in different business environments from a single client by entering a business token generated based on different business environment identifiers. This improves the efficiency of server-side verification of business tokens, enhances user experience, and reduces client development costs, eliminating the need to install a corresponding client for each business environment.

[0113] Step 315: The server extracts the original business token and the target business environment number from the business token to be verified.

[0114] For example, if the business token to be verified is 3007788, extract 007788 as the original business token and extract 3 as the target business environment number.

[0115] Step 316: Concatenate the first user key with the original business token to obtain result 1.

[0116] For example, if the first user key is 19badaa78a3aced541e4f6c15fc12ade and the original business token is 007788, the result 1 is 00778819badaa78a3aced541e4f6c15fc12ade.

[0117] Step 317: Add up the values ​​of each bit of the hash result 1 to get result 2.

[0118] For example, the hash value of result 1 is 002700, and the hash value of result 2 is 0+0+2+7+0+0 = 9.

[0119] Step 318: Perform a modulo operation between result 2 and the token length of the original business token to obtain result 3.

[0120] For example, result 2 is 45, the token length of the original business token is 6, and result 3 is 45 % 6 = 3.

[0121] Step 319: Add the result 3 to the target business environment number to obtain the target business environment identifier.

[0122] The target business environment identifier is hidden within the business token to be verified and can only be obtained using a second user key, which improves the security of the target business environment identifier.

[0123] For example, if the target business environment number is 3, the result 3 is 3, and the target business environment identifier is 3+3 = 6.

[0124] Step 320: Concatenate the first user key and the current timestamp to generate the target business token information.

[0125] Step 321: Based on the target business environment identifier, obtain the target user key corresponding to the target business environment, use the target user key as the key and the target business token information as the value, and process them using the SM3 hash algorithm to obtain the corresponding hash value.

[0126] Step 322: Perform an OR operation on each bit of the hash value and then perform a remainder operation with the length of the original business token to obtain the target business token.

[0127] In cases where the length of the target business token is less than the length of the original business token, zeros are added to the front of the target business token to make its length match that of the original business token.

[0128] Step 323: Compare the value of the target business token with the value of the original business token. If the value of the target business token is the same as the value of the original business token, the business token to be verified is determined to have passed the verification.

[0129] When the business token to be verified is successfully verified, the user can log in and use the services provided by the server in the target business environment.

[0130] Steps 315 to 323 described above are the steps for the server to verify the business token to be verified. At least some of these steps correspond to the steps described above for the client to generate the business token to be verified.

[0131] In this embodiment, the client generates a service token to be verified carrying a target service environment identifier for the target service environment. After receiving the service token to be verified, the server analyzes the service token to determine the target service environment identifier corresponding to the service token to be verified. Through the target service environment identifier, the target service environment of the service token to be verified that the client needs to verify can be determined. Thus, the target service token corresponding to the target service environment is used to verify the service token to be verified. There is no need to compare the service token to be verified with tokens corresponding to multiple service environments, which improves the verification efficiency of the service token.

[0132] It should be noted that the execution entity of the service token verification method provided in this application embodiment can be a service token verification device, or a control module in the service token verification device for executing the service token verification method. This application embodiment uses the execution of the service token verification method by a service token verification device as an example to illustrate the service token verification device provided in this application embodiment.

[0133] Figure 4 A schematic diagram of the structure of a business token verification device provided in an embodiment of this application is shown. Figure 4 As shown, the device 400 includes: a receiving module 41, a determining module 42, and a verification module 43.

[0134] The receiving module 41 is used to receive a service token to be verified sent by the client; the determining module 42 is used to determine the target service environment identifier corresponding to the service token to be verified based on the service token to be verified and the first user key; wherein the target service environment identifier is used to identify the target service environment; and the verifying module 43 is used to verify the service token to be verified based on the target service token corresponding to the target service environment.

[0135] In one implementation, the determining module 42 described above may include an extraction unit and a determining unit, wherein the extraction unit is used to extract the original service token and the target service environment number from the service token to be verified; and the determining unit is used to determine the target service environment identifier based on the first user key, the original service token, and the target service environment number.

[0136] In one implementation, the aforementioned determining unit can be specifically used to concatenate the original service token with the first user key to obtain a first result; add the values ​​of each bit in the hashed first result to obtain a second result; perform a modulo operation on the second result and the token length of the original service token to obtain a third result; and determine the target service environment identifier based on the target service environment number and the third result.

[0137] In one implementation, the verification module 43 described above can be used to obtain the target user key corresponding to the target business environment based on the target business environment identifier; generate business token information corresponding to the target business environment based on the target user key and the timestamp of the target user key; determine the target business token corresponding to the target business environment based on the target user key and the business token information; and verify the business token to be verified by comparing the value of the target business token with the value of the original business token.

[0138] In one implementation, the verification module 43 described above can be used to determine that the service token to be verified passes verification if the value of the target service token is the same as the value of the original service token.

[0139] In one implementation, the aforementioned apparatus 400 may further include a generation module, configured to receive a user account, a user password, and a first random number sent by the client; generate a second random number if the user account and the user password are successfully verified; and generate the first user key based on the first random number and the second random number.

[0140] In one implementation, the device 400 described above may further include a sending module for sending the second random number and the service environment identifier corresponding to each service environment to the client.

[0141] Figure 5 A schematic diagram of another business token verification device provided in an embodiment of this application is shown. Figure 5 As shown, the device 500 includes: a generation module 51, a receiving module 52, and a sending module 53.

[0142] The system includes a generation module 51, which generates a first random number in response to the input user account and password; a receiving module 52, which receives a second random number sent by the server and a business environment identifier corresponding to each business environment; wherein the second random number is generated by the server based on the successful verification of the received user account and password; the generation module 51 is further configured to generate a business token to be verified based on the first random number, the second random number, and the target business environment identifier; wherein the target business environment identifier is one of the business environment identifiers corresponding to each business environment; and a sending module 53, which sends the business token to be verified to the server.

[0143] In one implementation, the generation module 51 described above can be used to generate a second user key based on the first random number and the second random number; generate original service token information based on the second user key and the timestamp of the second user key; determine the original service token based on the second user key and the original service token information; and determine the service token to be verified based on the second user key, the original service token, and the target service environment number corresponding to the target service environment identifier.

[0144] In one implementation, the generation module 51 described above can be used to process the second user key and the original service token information respectively using the SM3 hash algorithm to generate a first hash value and a second hash value; perform an OR operation on the corresponding positions of the first hash value and the second hash value to obtain a first value; perform a remainder operation on the first value and a preset token length to obtain a second value; and if the length of the second value is less than the preset token length, pad the second value with zeros to obtain the original service token.

[0145] The verification device for the service token in this application embodiment can be a device, or it can be a component, integrated circuit, or chip in a terminal. The device can be a mobile electronic device, for example, a mobile phone, tablet computer, laptop computer, PDA, in-vehicle electronic device, wearable device, ultra-mobile personal computer (UMPC), netbook, or personal digital assistant (PDA), etc. Non-mobile electronic devices can be servers, network attached storage (NAS), personal computers (PCs), televisions (TVs), ATMs, or self-service machines, etc. This application embodiment does not make specific limitations.

[0146] The verification device for the service token in this application embodiment can be a device with an operating system. This operating system can be Android, iOS, or other possible operating systems; this application embodiment does not specifically limit the specific operating system used.

[0147] The service token verification device provided in this application embodiment can achieve Figures 1 to 3 The various processes implemented in the method embodiments shown will not be described again here to avoid repetition.

[0148] This application also provides an electronic device for performing the above-described business token verification method. Figure 6 This is a schematic diagram of the structure of an electronic device to implement the various embodiments of this application. The electronic device can vary significantly due to differences in configuration or performance, and may include a processor 601, a communications interface 602, a memory 603, and a communication bus 604. The processor 601, communications interface 602, and memory 603 communicate with each other via the communication bus 604. The processor 601 can call a computer program stored in the memory 603 and executable on the processor 601 to perform the various steps of the above-described business token verification method embodiments, achieving the same technical effect. To avoid repetition, further details are omitted here.

[0149] It should be noted that the electronic devices in the embodiments of this application include: servers, terminals, or other devices besides terminals.

[0150] The above electronic device structure does not constitute a limitation on the electronic device. An electronic device may include more or fewer components than illustrated, or combine certain components, or arrange them differently. For example, an input unit may include a Graphics Processing Unit (GPU) and a microphone, and a display unit may use a liquid crystal display (LCD), organic light-emitting diode (OLED), or other similar display panels. User input units include at least one of a touch panel and other input devices. A touch panel is also called a touchscreen. Other input devices may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be elaborated further here.

[0151] Memory can be used to store software programs and various data. Memory can primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area can store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, memory can include volatile memory or non-volatile memory, or both. Non-volatile memory can be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous linked dynamic random access memory (Synchlink DRAM, SLDRAM), and direct memory bus RAM (DRRAM).

[0152] The processor may include one or more processing units; optionally, the processor integrates an application processor and a modem processor, wherein the application processor mainly handles operations related to the operating system, user interface, and applications, while the modem processor mainly handles wireless communication signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into the processor.

[0153] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described business token verification method embodiments and achieve the same technical effect. To avoid repetition, they will not be described again here.

[0154] The processor is the processor in the electronic device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.

[0155] This application embodiment also provides a chip, which includes a processor and a communication interface. The communication interface is coupled to the processor. The processor is used to run programs or instructions to implement the various processes of the above-described business token verification method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0156] It should be understood that the chip mentioned in the embodiments of this application may also be referred to as a system-on-a-chip, system chip, chip system, or system-on-a-chip, etc.

[0157] This application also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes programs or instructions. When the programs or instructions are executed, they implement the various processes of the above-described business token verification method embodiments and can achieve the same technical effect. To avoid repetition, they will not be described again here.

[0158] It should be noted that, in this document, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element. Furthermore, it should be noted that the scope of the methods and apparatuses in the embodiments of this application is not limited to performing functions in the order shown or discussed, but may also include performing functions substantially simultaneously or in the reverse order, depending on the functions involved. For example, the described methods may be performed in a different order than described, and various steps may be added, omitted, or combined. Additionally, features described with reference to certain examples may be combined in other examples.

[0159] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in the various embodiments of this application.

[0160] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

Claims

1. A method for verifying a business token, characterized in that, Applied to the server side, including: Receive the pending verification business token sent by the client; Based on the service token to be verified and the first user key, the target service environment identifier corresponding to the service token to be verified is determined; wherein, the target service environment identifier is used to identify the target service environment; The service token to be verified is verified based on the target service token corresponding to the target business environment. The step of determining the target service environment identifier corresponding to the service token to be verified based on the service token to be verified and the first user key includes: Extract the original business token and the target business environment number from the business token to be verified; The target business environment identifier is determined based on the first user key, the original business token, and the target business environment number; The step of determining the target service environment identifier based on the first user key, the original service token, and the target service environment number includes: The original service token is concatenated with the first user key to obtain the first result; Add each bit of the hashed first result to obtain the second result; The second result is moduloed by the length of the original business token to obtain the third result; The target business environment identifier is determined based on the target business environment number and the third result.

2. The method according to claim 1, characterized in that, The step of verifying the service token to be verified based on the target service token corresponding to the target service environment includes: Based on the target business environment identifier, obtain the target user key corresponding to the target business environment; Based on the target user key and the timestamp of the target user key, generate the business token information corresponding to the target business environment; Based on the target user key and the service token information, determine the target service token corresponding to the target service environment; The business token to be verified is verified by comparing the value of the target business token with the value of the original business token.

3. The method according to claim 2, characterized in that, The step of verifying the service token to be verified by comparing the value of the target service token with the value of the original service token includes: If the value of the target service token is the same as the value of the original service token, the service token to be verified is determined to have passed verification.

4. The method according to claim 1, characterized in that, Before receiving the service token to be verified sent by the client, the method further includes: Receive the user account, user password, and first random number sent by the client; If the user account and the user password are successfully verified, a second random number is generated; The first user key is generated based on the first random number and the second random number.

5. The method according to claim 4, characterized in that, If the user account and the user password are successfully verified, after generating a second random number, the method further includes: The second random number and the business environment identifier corresponding to each business environment are sent to the client.

6. A method for verifying a business token, characterized in that, Applied to the client side, including: In response to the entered username and password, generate a first random number; The server receives a second random number and a business environment identifier corresponding to each business environment; wherein the second random number is generated by the server based on the successful verification of the received user account and user password. A service token to be verified is generated based on the first random number, the second random number, and the target service environment identifier; wherein, the target service environment identifier is one of the service environment identifiers corresponding to each service environment; Send the business token to be verified to the server; The step of generating a service token to be verified based on the first random number, the second random number, and the target service environment identifier includes: Generate a second user key based on the first random number and the second random number; The original business token information is generated based on the second user key and the timestamp of the second user key; The original service token is determined based on the second user key and the original service token information; The service token to be verified is determined based on the second user key, the original service token, and the target service environment number corresponding to the target service environment identifier.

7. The method according to claim 6, characterized in that, The step of determining the original service token based on the second user key and the original service token information includes: The second user key and the original business token information are processed using the SM3 hash algorithm to generate a first hash value and a second hash value. The first hash value is ORed with the corresponding value of the second hash value to obtain the first value. The second value is obtained by taking the remainder of the first value and the preset token length. If the length of the second value is less than the preset token length, the second value is padded with zeros to obtain the original business token.

8. A verification device for a business token, characterized in that, include: The receiving module is used to receive the business token to be verified sent by the client; The determining module is used to determine the target business environment identifier corresponding to the business token to be verified based on the business token to be verified and the first user key; wherein, the target business environment identifier is used to identify the target business environment; The verification module is used to verify the service token to be verified based on the target service token corresponding to the target service environment; The determining module includes: an extraction unit, used to extract the original service token and the target service environment number from the service token to be verified; and a determining unit, used to determine the target service environment identifier based on the first user key, the original service token, and the target service environment number. The determining unit is specifically used for: concatenating the original service token with the first user key to obtain a first result; adding each bit of the hashed first result to obtain a second result; performing a remainder operation between the second result and the token length of the original service token to obtain a third result; and determining the target service environment identifier based on the target service environment number and the third result.

9. A verification device for a business token, characterized in that, include: The generation module is used to generate a first random number in response to the input user account and password; The receiving module is used to receive a second random number sent by the server and a business environment identifier corresponding to each business environment; wherein, the second random number is generated by the server based on the successful verification of the received user account and user password; The generation module is further configured to generate a service token to be verified based on the first random number, the second random number, and the target business environment identifier; wherein the target business environment identifier is one of the business environment identifiers corresponding to each business environment; The sending module is used to send the business token to be verified to the server. The generation module is specifically used for: generating a second user key based on the first random number and the second random number; generating original service token information based on the second user key and the timestamp of the second user key; determining the original service token based on the second user key and the original service token information; and determining the service token to be verified based on the second user key, the original service token, and the target service environment number corresponding to the target service environment identifier.

10. An electronic device, characterized in that, It includes a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein when the program or instructions are executed by the processor, they implement the steps of the service token verification method as described in any one of claims 1 to 5, or implement the steps of the service token verification method as described in any one of claims 6 to 7.

11. A readable storage medium, characterized in that, The readable storage medium stores a program or instructions that, when executed by a processor, implement the steps of the service token verification method as described in any one of claims 1 to 5, or implement the steps of the service token verification method as described in any one of claims 6 to 7.

12. A computer program product, characterized in that, The computer program product includes a computer program stored on a non-transitory computer-readable storage medium, the computer program including programs or instructions that, when executed, implement the steps of the business token verification method as described in any one of claims 1 to 5, or implement the steps of the business token verification method as described in any one of claims 6 to 7.

Citation Information

Patent Citations

  • Information verification method, related device, equipment and storage medium

    CN112733107A

  • Verification method and device of verification code token, electronic equipment and storage medium

    CN114143027A