Data processing method and device, electronic equipment and storage medium

By setting multiple deadline points in the token and updating the version, the frequent login problem caused by the short token expiration time is solved, and data security and user experience are improved.

CN119995905AActive Publication Date: 2025-05-13MASHANG CONSUMER FINANCE CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202311501982.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-10
Publication Date
2025-05-13
Estimated Expiration
2043-11-10

AI Technical Summary

Technical Problem

In the prior art, the expiration time of the token is set too short, resulting in frequent users needing to log in to the system, affecting user experience, and increasing data security risks.

Method used

By setting the first cutoff time point and the second cutoff time point after the first cutoff time point, the first version of the authentication token is generated, and when the processing method of the authentication token is the first processing method, the first cutoff time point is updated to generate the second version of the authentication token until the second cutoff time point arrives.

Benefits of technology

Before the second deadline arrives, the server can update the authentication token multiple versions. The deadlines carried by each version of the authentication token is different, which reduces the probability of the token being cracked, ensures data security, and reduces the frequency of users' re-login.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995905A_ABST
    Figure CN119995905A_ABST
Patent Text Reader

Abstract

Embodiments of the invention provide a data processing method and apparatus, an electronic device and a storage medium, the method comprising: receiving an operation request sent by a client, the operation request carrying an authentication token of a first version, the authentication token of the first version comprising a first deadline point and a second deadline point located after the first deadline point; determining a processing mode of the authentication token according to the first time point, the first deadline and the second deadline; under the condition that the processing mode of the authentication token is the first processing mode, updating the first deadline time point, and generating an authentication token of a second version according to the updated first deadline time point; and the first response data of the operation request is sent to the client, and the first response data carries the authentication token of the second version, so that the data security can be ensured and the re-login frequency can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data processing technology, and in particular to a data processing method, device, electronic device and storage medium. Background Art

[0002] Token technology can be used in identity authentication scenarios. In actual applications, after a user successfully logs into the system, the system server assigns a token to the user. The token carries an expiration date. Each request sent by the user carries the token, which is used for server authentication.

[0003] In order to reduce the risk of token cracking, the time interval between the expiration time and the time when the user successfully logs into the system is usually short, which may cause the user to log in to the system frequently. Summary of the invention

[0004] The embodiments of the present application provide a data processing method, device, electronic device and storage medium to ensure data security and reduce the frequency of re-login.

[0005] In a first aspect, an embodiment of the present application provides a data processing method, which is applied to a server, comprising:

[0006] Receive an operation request sent by a client, where the operation request carries a first version of an authentication token, where the first version of the authentication token includes a first deadline time point and a second deadline time point that is later than the first deadline time point;

[0007] Determining a processing method of the authentication token according to the first time point, the first deadline time point, and the second deadline time point;

[0008] When the processing mode of the authentication token is the first processing mode, updating the first deadline time point, and generating a second version of the authentication token according to the first deadline time point after the update processing;

[0009] Sending first response data of the operation request to the client, where the first response data carries the second version of the authentication token.

[0010] In a second aspect, an embodiment of the present application provides a data processing method, which is applied to a client, including:

[0011] Sending an operation request to a server, wherein the operation request carries a first version of an authentication token, wherein the first version of the authentication token includes a first deadline time point and a second deadline time point that is later than the first deadline time point;

[0012] Receive first response data returned by the server, the first response data carrying the second version of the authentication token; the second version of the authentication token is generated according to the first deadline time point after updating the first deadline time point when the processing method of the authentication token is the first processing method; the processing method of the authentication token is determined by the first time point, the first deadline time point and the second deadline time point.

[0013] In a third aspect, an embodiment of the present application provides a data processing device, which is applied to a server, and the device includes:

[0014] A first receiving unit, configured to receive an operation request sent by a client, wherein the operation request carries a first version of an authentication token, wherein the first version of the authentication token includes a first deadline time point and a second deadline time point that is later than the first deadline time point;

[0015] a determining unit, configured to determine a processing method of the authentication token according to a first time point, the first deadline time point, and the second deadline time point;

[0016] a generating unit, configured to update the first deadline time point when the processing mode of the authentication token is the first processing mode, and generate a second version of the authentication token according to the first deadline time point after the update processing;

[0017] The first sending unit is used to send first response data of the operation request to the client, where the first response data carries the second version of the authentication token.

[0018] In a fourth aspect, an embodiment of the present application provides a data processing device, applied to a client, the device comprising:

[0019] A second sending unit, configured to send an operation request to the server, wherein the operation request carries a first version of the authentication token, wherein the first version of the authentication token includes a first deadline time point and a second deadline time point that is later than the first deadline time point;

[0020] A second receiving unit is used to receive first response data returned by the server, the first response data carrying the second version of the authentication token; the second version of the authentication token is generated according to the first deadline time point after the update processing by updating the first deadline time point when the processing method of the authentication token is the first processing method; the processing method of the authentication token is determined by the first time point, the first deadline time point and the second deadline time point.

[0021] In a fifth aspect, an embodiment of the present application provides an electronic device, comprising: a processor; and a memory configured to store computer-executable instructions, wherein the computer-executable instructions, when executed, cause the processor to execute the data processing method as described in the first aspect or the second aspect.

[0022] In a sixth aspect, an embodiment of the present application provides a computer-readable storage medium for storing computer-executable instructions, which, when executed by a processor, implement the data processing method as described in the first aspect or the second aspect.

[0023] It can be seen that in the embodiment of the present application, by setting a first deadline time point and a second deadline time point that is located after the first deadline time point, and the first version of the authentication token carries the first deadline time point, and the newly generated second version of the authentication token carries the first deadline time point after the update processing, the server can perform multiple version updates on the authentication token before the second deadline time point arrives. Each version of the authentication token carries a different deadline time point, which reduces the probability of each version of the authentication token being cracked, ensures data security, and does not need to trigger re-login before the second deadline time point arrives, thereby reducing the frequency of repeated logins. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the drawings required for use in the embodiments or the prior art descriptions are briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative labor.

[0025] Figure 1 A schematic diagram of an implementation environment of a data processing method provided in an embodiment of the present application;

[0026] Figure 2 A processing flow chart of a data processing method provided in an embodiment of the present application;

[0027] Figure 3 A processing flow chart of a second data processing method provided in an embodiment of the present application;

[0028] Figure 4 A processing flow chart of a third data processing method provided in an embodiment of the present application;

[0029] Figure 5 A processing flow chart of a fourth data processing method provided in an embodiment of the present application;

[0030] Figure 6 A schematic diagram of a data processing device provided in an embodiment of the present application;

[0031] Figure 7 A schematic diagram of another data processing device provided in an embodiment of the present application;

[0032] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0033] In order to enable those skilled in the art to better understand the technical solutions in the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments of the present application, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present application.

[0034] The data processing method provided in one or more embodiments of this specification may be applicable to the implementation environment of the data processing method, such as Figure 1 As shown, the implementation environment at least includes a server 101 for processing data and a terminal device 102 for sending an operation request and receiving first response data.

[0035] The server 101 may be a single server, or a server cluster consisting of a plurality of servers, or one or more cloud servers in a cloud computing platform, for processing data.

[0036] The terminal device 102 may be a mobile phone, a personal computer, a tablet computer, an e-book reader, a device for information interaction based on VR (Virtual Reality, virtual reality technology), a vehicle-mounted terminal, an IoT device, a wearable smart device, a laptop computer, a desktop computer, etc.; the terminal device 102 may be configured with a client of an application, and the specific form of the client may be an application, a subroutine within an application, a service module within an application, or a web program; the client may send an operation request and receive first response data.

[0037] In this implementation environment, during the data processing process, the server 101 first receives an operation request sent by the terminal device 102, the operation request carries a first version of an authentication token, the first version of the authentication token includes a first deadline time point and a second deadline time point that is located after the first deadline time point; then, according to the first time point, the first deadline time point and the second deadline time point, a processing method of the authentication token is determined; then, when the processing method of the authentication token is the first processing method, the first deadline time point is updated, and a second version of the authentication token is generated according to the first deadline time point after the updated processing; finally, first response data of the operation request is sent to the terminal device 102, the first response data carries the second version of the authentication token. In this way, by setting a first deadline time point and a second deadline time point that is after the first deadline time point, and the first version of the authentication token carries the first deadline time point, and the newly generated second version of the authentication token carries the first deadline time point after the update processing, the server can perform multiple version updates on the authentication token before the second deadline time point arrives. Each version of the authentication token carries a different deadline time point, which reduces the probability of each version of the authentication token being cracked, ensures data security, and does not need to trigger re-login before the second deadline time point arrives, thereby reducing the frequency of repeated logins.

[0038] This specification provides a data processing method embodiment:

[0039] In actual applications, after a user successfully logs into the system, the system server assigns a token to the user. The token carries the validity period generated by the backend when the token is assigned. The validity period can be determined by the time point when the user successfully logs into the system and the pre-configured token validity period. The server responds to the request when it detects that the token is carried in the request and determines that the token has not expired. After the token expires, the user needs to log in to the system again.

[0040] When configuring the token validity period, if the token validity period is greater than the preset time length threshold, it can be regarded as a long token validity period, in which case the data security of the token is low; if the token validity period is less than or equal to the preset time length threshold, it can be regarded as a short token validity period, in which case the user may need to log in to the system frequently, resulting in a poor experience. In order to solve the above problems, an embodiment of the present application provides a data processing method.

[0041] Figure 2 A processing flow chart of a data processing method provided in an embodiment of the present application. Figure 2 The data processing method provided in this embodiment is applied to the server, and specifically includes steps S202 to S208.

[0042] Step S202: receiving an operation request sent by a client, the operation request carrying a first version of an authentication token, the first version of the authentication token including a first deadline time point and a second deadline time point that is later than the first deadline time point.

[0043] The operation request sent by the client may be a request sent from the client to the server triggered by any operation issued by the user after successfully logging into the system.

[0044] For example, data query requests, form submission requests, page refresh requests, and so on.

[0045] The first version of the authentication token can be the first token assigned to the user by the server when the user successfully logs in to the system, or it can be the Nth token assigned to the user after the user successfully logs in, where N can be a natural number greater than 1.

[0046] When the first version of the authentication token is the first token assigned by the server to the user when the user successfully logs into the system, before step S202 is executed, the data processing method may further include the following steps: when determining a successful login, sending the first version of the authentication token to the client.

[0047] After the server sends the first version of the authentication token to the client, the client may store the first version of the authentication token, and any operation request sent by the client carries the first version of the authentication token.

[0048] The first version of the authentication token can be a token generated by the server based on the jwt (JSON Web Token) specification.

[0049] In actual applications, the first version of the authentication token can be a string.

[0050] JWT is an open standard for securely transmitting information between network applications. It uses a compact, self-contained way to represent information, usually for authentication and authorization. The design goal of JWT is to ensure the integrity and security of information while being easy to use and transmit.

[0051] The first deadline time point may represent a version expiration time, and the service expiration time is used to trigger the server to update the token version.

[0052] The second deadline time point can represent the jwt expiration time, and the jwt expiration time is used to trigger the server to notify the client of the token validity.

[0053] Exemplarily, the first deadline time point may be represented by overdueTime, and the second deadline time point may be represented by expireDate.

[0054] Among them, overdueTime indicates that the version has expired. If this time is exceeded, the information carried by the first version of the authentication token can still be parsed through the jwt specification. expireDate is a built-in field in the jwt specification, indicating the expiration time of jwt. Once this time is exceeded, the information carried by the first version of the authentication token cannot be fully parsed.

[0055] The first deadline time point may be determined by the time point of successfully logging into the system and the pre-configured version validity period.

[0056] When the first version of the authentication token is the first token allocated by the server to the user when the user successfully logs into the system, the first deadline time point can be determined in the following manner: taking the time point of successful system login as the starting time, and determining the first deadline time point based on the starting time and the version validity period.

[0057] The second deadline time point can be determined by the time point of successful login to the system and the pre-configured jwt validity period.

[0058] Specifically, the time point of successfully logging into the system is taken as the starting time, and the second deadline time point is determined based on the starting time and the valid duration of the jwt.

[0059] The valid period of jwt can be much longer than the valid period of the version. Specifically, the difference between the valid period of jwt and the valid period of the version can be greater than the preset period threshold.

[0060] For example, the version is valid for 10 minutes and the jwt is valid for 24 hours.

[0061] The first cut-off time point is before the second cut-off time point.

[0062] It should be noted that the serial numbers such as “first” and “second” appearing in this specification can be used to distinguish two similar features and have no actual meaning, which will not be elaborated below.

[0063] In a specific implementation, the data processing method also includes: receiving a token expiration instruction; the token expiration instruction carries a first user identifier; based on the first user identifier, querying and processing the correspondence between the stored user identifier and the version identifier to obtain the latest version identifier of the first user identifier; replacing the latest version identifier with a preset expiration identifier.

[0064] The server may store a correspondence between the user identifier and the version identifier, and based on the correspondence, the version identifier of the latest version of the authentication token of each successfully logged-in user may be determined.

[0065] The token invalidation instruction carries a first user identifier, which may be a user identifier of a user who has successfully logged into the system.

[0066] Each user ID can represent a unique corresponding user in the system.

[0067] According to the first user identifier, query processing is performed in the stored correspondence between user identifiers and version identifiers to obtain the version identifier corresponding to the first user identifier, and the version identifier is determined as the latest version identifier of the first user identifier.

[0068] The preset expiration mark can indicate that the token corresponding to the first user identifier is invalid.

[0069] After the latest version identifier is replaced by the preset invalid identifier, in the stored correspondence between the user identifier and the version identifier, the first user identifier corresponds to the preset invalid identifier.

[0070] In a specific implementation, the first version of the authentication token also includes a second user identifier and a first version identifier; after receiving an operation request sent by the client, the data processing method also includes: according to the second user identifier, query processing is performed in the correspondence between the stored user identifier and the version identifier to obtain the latest version identifier of the second user identifier; if the first version identifier is inconsistent with the latest version identifier of the second user identifier, a third response data of the operation request is sent to the client, and the third response data carries a token expiration identifier.

[0071] Exemplarily, the first version identifier may be represented by a version field.

[0072] According to the second user identifier, query processing is performed in the stored correspondence between user identifiers and version identifiers to obtain the version identifier corresponding to the second user identifier, and the version identifier is determined as the latest user identifier of the second user identifier.

[0073] The correspondence between the user ID and the version ID may be stored in a database on the server side, or in other designated storage areas.

[0074] Determine whether the latest version identifier of the second user identifier is consistent with the second version identifier: if the latest version identifier of the second user identifier is consistent with the second version identifier, continue to execute step S204; if the latest version identifier of the second user identifier is inconsistent with the second version identifier, send the third response data of the operation request to the client, and the third response data carries the token expiration identifier.

[0075] The token expiration identifier is used to notify the client that the token has expired. When the client receives the token expiration identifier, it will jump to the login page so that the user can log in again.

[0076] By maintaining the version identifier stored in the database, the server can forcibly invalidate the token carried in the operation request sent by the client without considering the first deadline time point and the second deadline time point.

[0077] Specifically, after receiving each operation request from the client, the server needs to compare the version numbers first. If the version numbers are consistent, the token can be used for authentication. Furthermore, the server does not need to change the token stored by the client, nor does it need to modify the token carried in the operation request. It only needs to modify the version identifier stored locally to make the token stored by the client no longer usable.

[0078] In addition, after the user successfully logs into the system, the server of the system can also perform abnormal behavior detection processing according to the received instruction carrying the second user identifier of the user to obtain the detection result. In the case where the detection result indicates that the user has abnormal behavior, the server can query the corresponding relationship between the stored user identifier and the version identifier according to the second user identifier, obtain the version identifier corresponding to the second user identifier, and determine the version identifier as the latest version identifier of the second user identifier; and replace the latest version identifier with a preset invalid identifier.

[0079] Furthermore, after the server receives the operation request sent by the client and carrying the first version identifier and the second user identifier, the server can perform query processing in the correspondence between the stored user identifier and the version identifier based on the second user identifier, and obtain the latest version identifier of the second user identifier, that is, the preset expiration identifier; if the first version identifier is inconsistent with the preset expiration identifier, the server sends the third response data of the operation request to the client, and the third response data carries the token expiration identifier.

[0080] When the detection result indicates that the user has abnormal behavior, the server may also generate abnormal behavior alarm information; the abnormal behavior alarm information is used to alert the service provider of the system that the user who logged into the system has abnormal behavior.

[0081] Considering the possibility that users may inadvertently disclose their passwords in actual applications, after successfully logging into the system using the password of a legitimate user, a person pretending to be a user may perform some abnormal behaviors that harm the interests of the legitimate user. For example, user A may sneak a peek at user B's commonly used password, successfully log into user B's account in the system using that password, and deliberately delete the form data filled in by the user in batches.

[0082] In this case, by replacing the identifier, the server can force the user's token to become invalid when suspicious user behavior is detected, so as to trigger the user to log in again. Taking into account that the original password login method is no longer safe in the event of a password leak, the server can also add the login method switching identifier to the third response data when the detection result indicates that the user has abnormal behavior, and send the third response data of the operation request to the client, and the third response data carries the token expiration identifier and the login method switching identifier. When the client receives the token validity identifier, it can jump to the login page so that the user can log in again. When the client receives the login method switching identifier, it can switch the password login method originally used to a more secure login method, such as face recognition login method, fingerprint recognition login method, and so on. By triggering the user to log in again after switching the login method, the user's account security can be improved.

[0083] Step S204: determining a processing method of the authentication token according to the first time point, the first deadline time point, and the second deadline time point.

[0084] The first time point may be the time point when step S204 is executed, that is, the current time point.

[0085] Determine the processing method of the authentication token according to the first time point, the first deadline time point and the second deadline time point, and determine the target time zone where the first time point is located in multiple preset time zones according to the first time point, the first deadline time point and the second deadline time point; and determine the processing method corresponding to the target time zone as the processing method of the authentication token.

[0086] Each of the plurality of preset time zones may be determined by a first cutoff time point and a second cutoff time point.

[0087] In a specific implementation method, a processing method for the authentication token is determined based on a first time point, a first deadline time point, and a second deadline time point, including: if the first time point is the same as the first deadline time point, or the first time point is after the first deadline time point and before the second deadline time point, then the processing method for the authentication token is determined to be the first processing method; the first processing method is used to update the version of the authentication token; if the first time point is before the first deadline time point, then the processing method for the authentication token is determined to be the second processing method; the second processing method is used to keep the authentication token unchanged; if the first time point is the same as the second deadline time point, or the first time point is after the second deadline time point, then the processing method for the authentication token is determined to be the third processing method; the third processing method is used to invalidate the authentication token.

[0088] Exemplarily, the first time point can be represented by T, the first deadline time point can be represented by overdueTime, and the second deadline time point can be represented by expireDate.

[0089] In the case where T = overdueTime, the processing method of the authentication token can be determined as the first processing method. T = overdueTime means that T is the same as overdueTime.

[0090] In the case where overdueTime < T < expireDate, the processing method of the authentication token can be determined as the first processing method. overdueTime < T < expireDate means that T is after overdueTime and before expireDate.

[0091] In the case where T < overdueTime, the processing method of the authentication token can be determined as the second processing method. T < overdueTime means that T is before overdueTime.

[0092] In the case where T = expireDate, the processing method of the authentication token can be determined as the third processing method. T = expireDate means that T is the same as expireDate.

[0093] In the case where T > expireDate, the processing method of the authentication token can be determined as the third processing method. T > expireDate means that T is after expireDate.

[0094] In the case where the first time point is the same as the first deadline time point, or the first time point is after the first deadline time point and before the second deadline time point, it can be determined that the token is valid, and the current version of the token has expired and needs to be updated, and then the processing method of the authentication token is determined as the first processing method.

[0095] The first processing method can be a processing method for updating the version of the current version of the authentication token.

[0096] In the case where the first time point is before the first deadline time point, it can be determined that the token is valid, and the current version of the token has not expired and does not need to be updated, and then the processing method of the authentication token is determined as the second processing method.

[0097] The second processing method can be a processing method that does not perform any operation on the current version of the authentication token.

[0098] When the first time point is the same as the second deadline time point, or when the first time point is after the second deadline time point, it can be determined that the token is invalid, and then the processing method of the authentication token is determined to be the third processing method.

[0099] The third processing method may be a preset processing method used when the token expires.

[0100] In a specific implementation, after determining the processing method of the authentication token based on the first time point, the first deadline time point and the second deadline time point, the data processing method also includes: when the processing method of the authentication token is the third processing method, sending second response data of the operation request to the client, the second response data carries a token expiration flag.

[0101] The token expiration flag is used to notify the client that the token is invalid. It should be noted that the token expiration is not only the first version of the authentication token, but also the entire token of the user corresponding to the first version of the authentication token is invalid. When the client receives the token expiration flag, it will jump to the login page so that the user can log in again.

[0102] In addition, when the token is invalid, the server fails to parse the first version of the authentication token. As a result, the server can determine that the user who issued the operation request does not have the operation authority for the operation request. Therefore, the second response data can be response data rejecting the operation request.

[0103] Step S206: When the processing mode of the authentication token is the first processing mode, the first deadline time point is updated, and a second version of the authentication token is generated according to the first deadline time point after the update process.

[0104] The updating process of the first deadline time point may be to use the first deadline time point as the starting time, and to extend the starting time based on a preset time length to obtain the updated first deadline time point.

[0105] For example, the first deadline time point is time point T1, the preset time length is T2, and the first deadline time point after the update process is time point T1', where T1'=T1+T2.

[0106] Generating the second version of the authentication token according to the first deadline time point after the update process may be to replace the first deadline time point in the first version of the authentication token by the first deadline time point after the update process to obtain the second version of the authentication token.

[0107] For example, the first version of the authentication token includes a first expiration time point T1 and a second expiration time point T2, and the second version of the authentication token includes an updated first expiration time point T1' and a second expiration time point T2.

[0108] In a specific implementation, the first deadline time point is updated, including: determining a first time length according to the first time point and the first deadline time point; determining a number of extensions according to the first time length and a preset time length; and updating the first deadline time point according to the number of extensions and the preset time length.

[0109] The preset duration is the length of each custom-configured extension. Considering data security, the preset duration can be less than or equal to the custom-configured duration threshold. For example, if the duration threshold is 15 minutes, the preset duration is 10 minutes.

[0110] Determining the first time length according to the first time point and the first cut-off time point may be determining the difference between the first time point and the first cut-off time point as the first time length.

[0111] The number of extensions is determined according to the first time length and the preset time length. The number of extensions may be determined by performing a quotient calculation on the first time length and the preset time length to obtain a calculation result, and then determining the number of extensions based on the calculation result.

[0112] When the calculation result is not an integer, you can add one digit to the calculation result to get the number of extensions.

[0113] For example, the first time length is 50 minutes, and the preset time length is 20 minutes. The quotient calculation is performed based on 50 minutes and 20 minutes, and the calculation result is 2.5. When the calculation result is not an integer, it is automatically rounded up to 3, and the number of extensions is determined to be 3.

[0114] The first deadline time point is updated according to the number of extensions and the preset duration. The first deadline time point may be taken as the starting time, the total extension duration is determined based on the number of extensions and the preset duration, and the extension is performed based on the starting time and the total extension duration to obtain the first deadline time point after the update.

[0115] In actual applications, the server can only discover that the first deadline time point has expired and a version update is required when it receives an operation request sent by the client. Therefore, during the version update process, the first deadline time point needs to be postponed to after the first time point. The number of extensions can be one or more, and the number of extensions can be determined by the first time point and the first deadline time point.

[0116] The first deadline time point is updated according to the number of extensions and the preset duration, and the time point after extension can be determined according to the number of extensions and the preset duration; the time point after extension is compared with the second deadline time point; if the first deadline time point after extension is before the second deadline time point, the time point after extension is determined as the first deadline time point after update processing; if the time point after extension is equal to the second deadline time point, the first deadline time point after update processing is determined according to the second deadline time point; if the time point after extension is after the second deadline time point, the first deadline time point after update processing is determined according to the second deadline time point.

[0117] By determining the first deadline time point after the update process according to the second deadline time point, the first deadline time point after the update process can be located before the second deadline time point.

[0118] For example, the first deadline time point is T1, the second deadline time point is T2, the number of extensions is 3, the preset duration is 10 minutes, and the extended time point T1' can be a time point 30 minutes after T1. If T1'<T2, T1' is determined as the first deadline time point after the update process; if T1'=T2, the time point T2' representing 1 minute before T2 can be determined as the first deadline time point after the update process; if T1'>T2, T2' can be determined as the first deadline time point after the update process.

[0119] In a specific implementation, the first version of the authentication token also includes a first version identifier; generating a second version of the authentication token based on the first deadline time after the update process includes: updating the first version identifier to obtain the second version identifier; replacing the first version identifier in the first version of the authentication token with the second version identifier, and replacing the first deadline time point in the first version of the authentication token with the first deadline time point after the update process to obtain the second version of the authentication token.

[0120] The first version identifier is updated to obtain the second version identifier, and the first version identifier may be incremented by one to obtain the second version identifier.

[0121] For example, the first version is identified as 1, and the second version is identified as 2.

[0122] The first version of the authentication token may include a first version identifier, a first deadline time point, and a second deadline time point. The first version identifier in the first version of the authentication token is replaced by the second version identifier, and the first deadline time point in the first version of the authentication token is replaced by the first deadline time point after the update processing, so as to obtain a second version of the authentication token. The second version of the authentication token may include the second version identifier, the first deadline time point after the update processing, and the second deadline time point.

[0123] For example, the first version of the authentication token includes the first version identifier "1", the first deadline time point T1 and the second deadline time point T2, and the second version of the authentication token includes the second version identifier "2", the updated first deadline time point T1' and the second deadline time point T2.

[0124] Step S208: Send first response data of the operation request to the client, where the first response data carries the second version of the authentication token.

[0125] The first response data may be response data of receiving the operation request.

[0126] Before step S208 is executed, the first response data may be generated in the following manner: generating initial response data representing the received operation request, and generating the first response data based on the initial response data and the second version of the authentication token.

[0127] Based on the initial response data and the second version of the authentication token, the first response data is generated. The first response data can be obtained by adding an additional field to the output JSON structure of the initial response data based on the second version of the authentication token.

[0128] For example, the initial response data is:

[0129]

[0130] The first response data is:

[0131]

[0132]

[0133] Among them, "extra" represents the additional field, "accessToken" represents the token field, and "eyJ0eXAiOiJKV1QiLCJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMDAxMCIsIm92ZXJkdWVEYXRlIjoiMjAyMy0wNy0xOSAxNTo1MTowOSIsImlzcyI6InNha1VyYTIwMjAiLCJleHAiOjE2OTIyNTg2NjAsImlhdCI6MTY4OTU4NDY2MSwidmVyc2lvbiI6IjIifQ.vptYPW0Za3Adez1ez6DtF4OaouklV3Q7sJWtohMVefs" is the second version of the authentication token.

[0134] In such Figure 2In the embodiment shown, first, an operation request sent by a client is received, the operation request carries a first version of an authentication token, the first version of the authentication token includes a first deadline time point and a second deadline time point located after the first deadline time point; then, according to the first time point, the first deadline time point and the second deadline time point, a processing method of the authentication token is determined; then, in the case where the processing method of the authentication token is the first processing method, the first deadline time point is updated, and a second version of the authentication token is generated according to the first deadline time point after the updated processing; finally, the first response data of the operation request is sent to the client, and the first response data carries the second version of the authentication token. In this way, by setting the first deadline time point and the second deadline time point located after the first deadline time point, and the first version of the authentication token carries the first deadline time point, and the newly generated second version of the authentication token carries the first deadline time point after the updated processing, the server can perform multiple version updates on the authentication token before the second deadline time point arrives, and each version of the authentication token carries a different deadline time point, which reduces the probability of each version of the authentication token being cracked, ensures data security, and does not need to trigger re-login before the second deadline time point arrives, reducing the frequency of repeated logins.

[0135] Based on the same technical concept as the data processing method provided by the aforementioned method embodiment, the embodiment of the present application also provides another data processing method applied to a client. Figure 3 A processing flow chart of the second data processing method provided in an embodiment of the present application.

[0136] Step S302: Send an operation request to the server, where the operation request carries a first version of the authentication token, where the first version of the authentication token includes a first deadline time point and a second deadline time point that is later than the first deadline time point.

[0137] Step S304, receiving the first response data returned by the server, the first response data carrying the second version of the authentication token; the second version of the authentication token is generated according to the first deadline time point after the update processing when the processing method of the authentication token is the first processing method, and the first deadline time point is updated; the processing method of the authentication token is determined by the first time point, the first deadline time point and the second deadline time point.

[0138] In a specific implementation, after receiving the first response data returned by the server, the data processing method also includes: performing field detection processing based on the first response data to obtain a field detection result; when it is determined according to the field detection result that the first response data includes additional fields, extracting a second version of the authentication token from the additional fields; and replacing the stored first version of the authentication token with the second version of the authentication token.

[0139] Performing field detection processing according to the first response data to obtain a field detection result may be detecting whether the first response data includes an additional field.

[0140] If it is determined that the first response data includes an additional field, extract the second version of the authentication token from the additional field; and replace the stored first version of the authentication token with the second version of the authentication token.

[0141] After the stored first version of the authentication token is replaced by the second version of the authentication token, any operation request sent by the client to the server carries the second version of the authentication token, and the second version of the authentication token is used for authentication by the server.

[0142] If it is determined that the first response data does not include the additional field, no operation is performed.

[0143] Since the technical concept is the same, the description in this embodiment is relatively simple, and the relevant parts may refer to the corresponding description of the method embodiment provided above.

[0144] Based on the same technical concept as the data processing method provided by the aforementioned method embodiment, the embodiment of the present application also provides another data processing method. Figure 4 A processing flow chart of the third data processing method provided in an embodiment of the present application.

[0145] Step S402: User login is successful.

[0146] Step S404: the backend issues a token to the frontend.

[0147] The backend can be a server. The token can refer to Figure 2 The first version of the authentication token in the embodiment. The front end can be a client.

[0148] Step S406: The front end carries the token in all subsequent requests.

[0149] Each operation request sent by the frontend to the backend carries the token.

[0150] Step S408, when the backend finds that the service expiration time has expired, it automatically adds new token information to the output parameter structure and increases the user's token version number by one at the database level.

[0151] The service expiration time can be the first deadline time point. The output parameter structure can refer to Figure 2 The output parameter json structure of the initial response data of the embodiment. The new token information can be the second version of the authentication token.

[0152] In step S410, the front end finds that the back end has returned a new token, replaces the previous token, and carries the new token in subsequent requests.

[0153] The front end replaces the locally stored first version of the authentication token with the second version of the authentication token.

[0154] Each operation request sent by the front end to the back end carries the second version of the authentication token.

[0155] Step S412: When a service expiration time expires, it is found that the token expiration time has also expired, and the front end jumps to the login page.

[0156] Step S414: the user logs in again.

[0157] Since the technical concept is the same, the description in this embodiment is relatively simple, and the relevant parts may refer to the corresponding description of the method embodiment provided above.

[0158] Based on the same technical concept as the data processing method provided by the aforementioned method embodiment, the embodiment of the present application also provides another data processing method. Figure 5 A processing flow chart of the fourth data processing method provided in an embodiment of the present application.

[0159] Step S502: User login is successful.

[0160] Step S504: the backend issues a token to the frontend.

[0161] The backend can be a server. The token can refer to Figure 2 The first version of the authentication token in the embodiment. The front end can be a client.

[0162] Step S506: the backend updates the version number of the user's token to 1.

[0163] Step S508: The user will carry the token in all subsequent requests.

[0164] Each operation request sent by the frontend to the backend carries the token.

[0165] Step S506 and step S508 can be processed in parallel by establishing and executing asynchronous tasks. For example, the backend calls the first thread to execute step S506; the backend calls the second thread to execute step S508.

[0166] The first thread and the second thread are two different threads.

[0167] For another example, the backend executes step S506 in the first process; and the backend executes step S508 in the second process.

[0168] The first process and the second process are two different processes.

[0169] Step S510: Check whether the version number of the token in the request body matches the token version number in the database.

[0170] If yes, execute step S512; if no, execute step S520.

[0171] The version number of the token in the request body can be the first version identifier in the first version of the authentication token carried by the operation request. The token version number in the database can be the latest version identifier of the user identifier obtained by querying the corresponding relationship between the user identifier and the version identifier stored locally in the backend based on the user identifier carried in the operation request.

[0172] Step S512: In the first request, the backend finds that the service expiration time has expired but the token expiration time has not expired.

[0173] The first request is the first operation request sent by the front-end to the back-end after successful login. The service expiration time can be the first deadline time point. The token expiration time can be the second deadline time point.

[0174] Step S514: the backend adds new token information to the current output parameter at the filter level.

[0175] The current output parameters can be referenced Figure 2 The output parameter json structure of the initial response data of the embodiment. The new token information can be the second version of the authentication token.

[0176] Step S516: the backend updates the version number of the user's database token to 2.

[0177] Step S518, the front end finds that the return result from the back end contains a new token.

[0178] The new token is the second version of the authentication token.

[0179] Step S516 and step S518 can be processed in parallel by establishing and executing asynchronous tasks.

[0180] Step S520: In the first request, if the backend finds that the token expiration time has expired, it returns a specific identifier to the frontend.

[0181] Specific identification can be found at Figure 2 Token validity identification in the embodiment.

[0182] Step S522: the front end jumps to the login page according to the specific identifier.

[0183] Since the technical concept is the same, the description in this embodiment is relatively simple, and the relevant parts may refer to the corresponding description of the method embodiment provided above.

[0184] In the above-mentioned embodiment, a data processing method applied to a server is provided. Correspondingly, based on the same technical concept, an embodiment of the present application also provides a data processing device, which is described below in conjunction with the accompanying drawings.

[0185] Figure 6 A schematic diagram of a data processing device provided in an embodiment of the present application.

[0186] This embodiment provides a data processing device 600, which is applied to a server, and includes:

[0187] A first receiving unit 602 is configured to receive an operation request sent by a client, where the operation request carries a first version of an authentication token, where the first version of the authentication token includes a first deadline time point and a second deadline time point that is later than the first deadline time point;

[0188] A determining unit 604, configured to determine a processing method of the authentication token according to the first time point, the first deadline time point, and the second deadline time point;

[0189] A generating unit 606, configured to update the first deadline time point when the processing mode of the authentication token is the first processing mode, and generate a second version of the authentication token according to the first deadline time point after the update processing;

[0190] The first sending unit 608 is configured to send first response data of the operation request to the client, where the first response data carries the second version of the authentication token.

[0191] Optionally, when determining the processing method of the authentication token according to the first time point, the first deadline time point, and the second deadline time point, the determining unit 604 performs the following steps:

[0192] If the first time point is the same as the first deadline time point, or the first time point is after the first deadline time point and before the second deadline time point, then determining that the processing method of the authentication token is the first processing method; the first processing method is used to update the version of the authentication token;

[0193] If the first time point is before the first deadline time point, determining that the processing method of the authentication token is a second processing method; the second processing method is used to keep the authentication token unchanged;

[0194] If the first time point is the same as the second deadline time point, or the first time point is after the second deadline time point, then the processing method of the authentication token is determined to be a third processing method; the third processing method is used to invalidate the authentication token.

[0195] Optionally, the first sending unit 608 is further configured to:

[0196] When the processing mode of the authentication token is the third processing mode, second response data of the operation request is sent to the client, and the second response data carries a token expiration mark.

[0197] Optionally, the first version of the authentication token further includes a first version identifier; the generating unit 606 performs the following steps when generating the second version of the authentication token according to the first deadline after the update process:

[0198] Updating the first version identifier to obtain a second version identifier;

[0199] The second version authentication token is obtained by replacing the first version identifier in the first version authentication token with the second version identifier, and replacing the first expiration time point in the first version authentication token with the first expiration time point after the update processing.

[0200] Optionally, the first receiving unit 602 is further configured to:

[0201] Receiving a token expiration instruction; the token expiration instruction carries a first user identifier;

[0202] The data processing device 600 further includes:

[0203] A query unit, configured to perform query processing in the stored correspondence between user identifiers and version identifiers according to the first user identifier, to obtain the identifier of the latest version of the first user identifier;

[0204] The replacement unit is used to replace the latest version identifier with a preset expiration identifier.

[0205] Optionally, the first version of the authentication token further includes a second user identifier and a first version identifier; and the query unit is further configured to:

[0206] According to the second user identifier, query processing is performed in the corresponding relationship between the stored user identifier and the version identifier to obtain the latest version identifier of the second user identifier;

[0207] The first sending unit 608 is further configured to:

[0208] If the first version identifier is inconsistent with the latest version identifier of the second user identifier, third response data of the operation request is sent to the client, and the third response data carries the token expiration identifier.

[0209] Optionally, the generating unit 606 performs the following steps when updating the first deadline time point:

[0210] Determine a first time length according to the first time point and the first cut-off time point;

[0211] Determining the number of extensions according to the first time length and the preset time length;

[0212] The first deadline time point is updated according to the number of extensions and the preset duration.

[0213] The data processing device provided in the embodiment of the present application includes: a first receiving unit, used to receive an operation request sent by a client, the operation request carries a first version of an authentication token, the first version of the authentication token includes a first deadline time point and a second deadline time point located after the first deadline time point; a determination unit, used to determine a processing method for the authentication token according to the first time point, the first deadline time point and the second deadline time point; a generation unit, used to update the first deadline time point when the processing method of the authentication token is the first processing method, and generate a second version of the authentication token according to the first deadline time point after the update; a first sending unit, used to send first response data of the operation request to the client, the first response data carrying the second version of the authentication token. In this way, by setting a first deadline time point and a second deadline time point that is after the first deadline time point, and the first version of the authentication token carries the first deadline time point, and the newly generated second version of the authentication token carries the first deadline time point after the update processing, the server can perform multiple version updates on the authentication token before the second deadline time point arrives. Each version of the authentication token carries a different deadline time point, which reduces the probability of each version of the authentication token being cracked, ensures data security, and does not need to trigger re-login before the second deadline time point arrives, thereby reducing the frequency of repeated logins.

[0214] In the above-mentioned embodiment, a data processing method applied to a client is provided. Correspondingly, based on the same technical concept, an embodiment of the present application also provides a data processing device, which will be described below in conjunction with the accompanying drawings.

[0215] Figure 7 A schematic diagram of another data processing device provided in an embodiment of the present application.

[0216] This embodiment provides a data processing device 700, which is applied to a client and includes:

[0217] The second sending unit 702 is used to send an operation request to the server, where the operation request carries a first version of the authentication token, where the first version of the authentication token includes a first deadline time point and a second deadline time point that is later than the first deadline time point;

[0218] The second receiving unit 704 is used to receive the first response data returned by the server, the first response data carrying the second version of the authentication token; the second version of the authentication token is generated according to the first deadline time point after the update processing by updating the first deadline time point when the processing method of the authentication token is the first processing method; the processing method of the authentication token is determined by the first time point, the first deadline time point and the second deadline time point.

[0219] Optionally, the data processing device 700 further includes:

[0220] a detection unit, configured to perform field detection processing according to the first response data to obtain a field detection result;

[0221] an extraction unit, configured to extract the second version of the authentication token from the additional field if it is determined according to the field detection result that the first response data includes an additional field;

[0222] A replacement unit is used to replace the stored authentication token of the first version with the authentication token of the second version.

[0223] The data processing device provided in the embodiment of the present application includes: a second sending unit, used to send an operation request to the server, the operation request carries a first version of the authentication token, the first version of the authentication token includes a first deadline time point and a second deadline time point located after the first deadline time point; a second receiving unit, used to receive the first response data returned by the server, the first response data carries the second version of the authentication token; the second version of the authentication token is generated according to the first deadline time point after the update processing by updating the first deadline time point when the processing mode of the authentication token is the first processing mode; the processing mode of the authentication token is determined by the first time point, the first deadline time point and the second deadline time point. In this way, by setting the first deadline time point and the second deadline time point located after the first deadline time point, and the first version of the authentication token carries the first deadline time point, the newly generated second version of the authentication token carries the first deadline time point after the update processing, so that the server can perform multiple version updates on the authentication token before the second deadline time point arrives, and each version of the authentication token carries a different deadline time point, which reduces the probability of each version of the authentication token being cracked, ensures data security, and does not need to trigger re-login before the second deadline time point arrives, reducing the frequency of repeated logins.

[0224] Corresponding to the data processing method described above, based on the same technical concept, an embodiment of the present application further provides an electronic device, which is used to execute the data processing method provided above. Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application.

[0225] like Figure 8 As shown, the electronic device may have relatively large differences due to different configurations or performances, and may include one or more processors 801 and memory 802, and the memory 802 may store one or more storage applications or data. Among them, the memory 802 may be a temporary storage or a permanent storage. The application stored in the memory 802 may include one or more modules (not shown in the figure), and each module may include a series of computer executable instructions in the electronic device. Furthermore, the processor 801 can be configured to communicate with the memory 802 to execute a series of computer executable instructions in the memory 802 on the electronic device. The electronic device may also include one or more power supplies 803, one or more wired or wireless network interfaces 804, one or more input / output interfaces 805, one or more keyboards 806, etc.

[0226] In a specific embodiment, the electronic device includes a memory and one or more programs, wherein the one or more programs are stored in the memory, and the one or more programs may include one or more modules, and each module may include a series of computer executable instructions for the electronic device, and the one or more programs configured to be executed by one or more processors include the following computer executable instructions:

[0227] Receive an operation request sent by a client, where the operation request carries a first version of an authentication token, where the first version of the authentication token includes a first deadline time point and a second deadline time point that is later than the first deadline time point;

[0228] Determining a processing method of the authentication token according to the first time point, the first deadline time point, and the second deadline time point;

[0229] When the processing mode of the authentication token is the first processing mode, updating the first deadline time point, and generating a second version of the authentication token according to the first deadline time point after the update processing;

[0230] Sending first response data of the operation request to the client, where the first response data carries the second version of the authentication token.

[0231] An embodiment of a computer-readable storage medium provided in this specification is as follows:

[0232] Corresponding to the data processing method described above, based on the same technical concept, an embodiment of the present application also provides a computer-readable storage medium.

[0233] The computer-readable storage medium provided in this embodiment is used to store computer-executable instructions. When the computer-executable instructions are executed by a processor, the following process can be implemented:

[0234] Receive an operation request sent by a client, where the operation request carries a first version of an authentication token, where the first version of the authentication token includes a first deadline time point and a second deadline time point that is later than the first deadline time point;

[0235] Determining a processing method of the authentication token according to the first time point, the first deadline time point, and the second deadline time point;

[0236] When the processing mode of the authentication token is the first processing mode, updating the first deadline time point, and generating a second version of the authentication token according to the first deadline time point after the update processing;

[0237] Sending first response data of the operation request to the client, where the first response data carries the second version of the authentication token.

[0238] It should be noted that the embodiment of the computer-readable storage medium in this specification and the embodiment of the data processing method applied to the server in this specification are based on the same inventive concept. Therefore, the specific implementation of this embodiment can refer to the implementation of the corresponding method mentioned above, and the repeated parts will not be repeated.

[0239] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0240] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the embodiments of the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, this specification may adopt the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0241] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable device to generate a machine, so that the instructions executed by the processor of the computer or other programmable device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0242] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable device to work in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0243] These computer program instructions may also be loaded onto a computer or other programmable device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0244] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0245] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0246] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.

[0247] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0248] Embodiments of the present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. One or more embodiments of the present specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communications network. In a distributed computing environment, program modules may be located in local and remote computer storage media, including storage devices.

[0249] Each embodiment in this specification is described in a progressive manner, and the same or similar parts between the embodiments can be referred to each other, and each embodiment focuses on the differences from other embodiments. In particular, for the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0250] The above description is only an embodiment of this document and is not intended to limit this document. For those skilled in the art, this document may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of this document should be included in the scope of the claims of this document.

Claims

1. A data processing method, applied to a server, characterized in that: include: Receive an operation request sent by a client, where the operation request carries a first version of an authentication token, where the first version of the authentication token includes a first deadline time point and a second deadline time point that is later than the first deadline time point; Determining a processing method of the authentication token according to the first time point, the first deadline time point, and the second deadline time point; When the processing mode of the authentication token is the first processing mode, updating the first deadline time point, and generating a second version of the authentication token according to the first deadline time point after the update processing; Sending first response data of the operation request to the client, where the first response data carries the second version of the authentication token.

2. The method according to claim 1, characterized in that The determining, according to the first time point, the first deadline time point, and the second deadline time point, a processing method of the authentication token includes: If the first time point is the same as the first deadline time point, or the first time point is after the first deadline time point and before the second deadline time point, then determining that the processing method of the authentication token is the first processing method; the first processing method is used to update the version of the authentication token; If the first time point is before the first deadline time point, determining that the processing method of the authentication token is a second processing method; the second processing method is used to keep the authentication token unchanged; If the first time point is the same as the second deadline time point, or the first time point is after the second deadline time point, then the processing method of the authentication token is determined to be a third processing method; the third processing method is used to invalidate the authentication token.

3. The method according to claim 2, characterized in that After determining the processing method of the authentication token according to the first time point, the first deadline time point, and the second deadline time point, the method further includes: When the processing mode of the authentication token is the third processing mode, second response data of the operation request is sent to the client, and the second response data carries a token expiration mark.

4. The method according to claim 1, characterized in that: The first version of the authentication token also includes a first version identifier; and the step of generating the second version of the authentication token according to the first deadline after the update process includes: Updating the first version identifier to obtain a second version identifier; The second version authentication token is obtained by replacing the first version identifier in the first version authentication token with the second version identifier, and replacing the first expiration time point in the first version authentication token with the first expiration time point after the update processing.

5. The method according to claim 1, characterized in that The method further comprises: Receiving a token expiration instruction; the token expiration instruction carries a first user identifier; According to the first user identifier, query processing is performed in the corresponding relationship between the stored user identifiers and version identifiers to obtain the latest version identifier of the first user identifier; The latest version identifier is replaced by a preset invalid identifier.

6. The method according to claim 1, characterized in that The first version of the authentication token also includes a second user identifier and a first version identifier; after receiving the operation request sent by the client, the method further includes: According to the second user identifier, query processing is performed in the corresponding relationship between the stored user identifier and the version identifier to obtain the latest version identifier of the second user identifier; If the first version identifier is inconsistent with the latest version identifier of the second user identifier, third response data of the operation request is sent to the client, and the third response data carries the token expiration identifier.

7. The method according to claim 1, characterized in that The updating process of the first cut-off time point includes: Determine a first time length according to the first time point and the first cut-off time point; Determining the number of extensions according to the first time length and the preset time length; The first deadline time point is updated according to the number of extensions and the preset duration.

8. A data processing device, applied to a server, characterized in that: include: A first receiving unit, configured to receive an operation request sent by a client, wherein the operation request carries a first version of an authentication token, wherein the first version of the authentication token includes a first deadline time point and a second deadline time point that is later than the first deadline time point; a determining unit, configured to determine a processing method of the authentication token according to a first time point, the first deadline time point, and the second deadline time point; a generating unit, configured to update the first deadline time point when the processing mode of the authentication token is the first processing mode, and generate a second version of the authentication token according to the first deadline time point after the update processing; The first sending unit is used to send first response data of the operation request to the client, where the first response data carries the second version of the authentication token.

9. An electronic device, characterized in that: The device comprises: A processor; and a memory configured to store computer executable instructions, which, when executed, cause the processor to perform the data processing method according to any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium is used to store computer-executable instructions, and the computer-executable instructions, when executed by a processor, implement the data processing method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Login verification processing method, system and device

    CN109379192A

  • Token-based authentication method and device

    CN111294337A

  • Network card firmware updating method and system

    CN112783526A

  • Token updating method and device

    CN112836204A

  • Authentication token refresh

    US20210377248A1