Account life cycle management method and device, equipment, medium and product
By comparing and updating the account's timestamp field values during the inspection cycle, the problem of unreliable password expiration mechanism caused by unreliable system time is solved, and account life cycle management is achieved independent of system time, improving account security and management efficiency.
Patent Information
- Application Number
- CN202510326938.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-07-08
AI Technical Summary
In the prior art, the password expiration mechanism depends on the accuracy of system time, resulting in the robustness of the password expiration mechanism being affected when facing system time adjustment or server attacks, and the security of the account cannot be effectively guaranteed.
By obtaining the password credentials in the user list every time the check cycle, comparing the timestamp field value with the account life cycle value, sending a logout instruction to the expired password credentials, and cumulatively updating the timestamp field value when it has not expired, and managing it independently of the system time.
It realizes account life cycle management that does not depend on system time, improves account security and the robustness of management mechanisms, improves management efficiency and reliability, and ensures that the account is processed in a timely manner after the end of the life cycle.
Smart Images

Figure CN120277654A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and in particular, to a method, device, equipment, medium and product for managing the account life cycle. Background Art
[0002] In the field of computer security, password expiration refers to setting a valid time period for a user's password. Once this period is exceeded, the user must update their password. The original intention of this mechanism is to strengthen the security protection of the account. By regularly changing the password, the risk of the password being guessed or leaked is effectively reduced, thereby protecting the user's account information. With the wide application of computer technology and the increasing demand for network security, the importance of password management has gradually emerged and become one of the key measures to ensure information security. Summary of the Invention
[0003] The present invention provides a method, device, equipment, medium and product for managing the account life cycle to solve the problems of poor robustness of the account life cycle management mechanism and the resulting poor account security, poor timeliness, efficiency and reliability of account management.
[0004] According to one aspect of the embodiments of the present invention, there is provided a method for managing the account life cycle, which is executed by a server and includes:
[0005] Whenever a preset check period arrives, sequentially obtain the password credentials in the locally stored user list, and compare the value of the timestamp field in each password credential with a preset account life cycle value;
[0006] When it is determined that the value of the current timestamp field in the current password credential being compared is greater than or equal to the account life cycle value, send a logout instruction to the client that logs in using the current password credential;
[0007] When it is determined that the value of the current timestamp field in the current password credential being compared is less than the account life cycle value, accumulate and update the value of the current timestamp field in the current password credential according to the check period.
[0008] According to another aspect of the embodiments of the present invention, there is provided a device for managing the account life cycle, including:
[0009] An expiration comparison module, configured to sequentially obtain the password credentials in the locally stored user list whenever a preset check period arrives, and compare the value of the timestamp field in each password credential with a preset account life cycle value;
[0010] A logout module, configured to send a logout instruction to the client that logs in using the current password credential when it is determined that the value of the current timestamp field in the current password credential being compared is greater than or equal to the account life cycle value;
[0011] An accumulation and update module, configured to, when determining that the value of the current timestamp field in the current password credential currently being compared is less than the account lifecycle value, accumulate and update the value of the current timestamp field in the current password credential according to the check period.
[0012] According to another aspect of the embodiments of the present invention, there is provided an electronic device, including:
[0013] At least one processor; and
[0014] A memory communicatively connected to the at least one processor; wherein,
[0015] The memory stores a computer program executable by the at least one processor, and when the computer program is executed by the at least one processor, the at least one processor is enabled to execute the account lifecycle management method according to any embodiment of the present invention.
[0016] According to another aspect of the embodiments of the present invention, there is provided a computer-readable storage medium storing computer instructions for causing a processor to implement the account lifecycle management method according to any embodiment of the present invention when executed.
[0017] According to another aspect of the embodiments of the present invention, there is also provided a computer program product including computer programs / instructions, and when the computer programs / instructions are executed by a processor, the steps of the method according to any embodiment of the present invention are implemented.
[0018] The technical solution of the embodiments of the present invention, by sequentially obtaining password credentials in the user list for comparison whenever the check period arrives, when the value of the current timestamp field of the current credential is greater than or equal to the account lifecycle value, sending a logout instruction to the corresponding client; when the value of the timestamp field is less than the account lifecycle value, accumulating and updating the value of the current timestamp field according to the check period. By managing the account lifecycle through the preset check period time scale, it is possible to manage the account lifecycle without relying on the system time, avoiding errors in account lifecycle management caused by the modification of the local time, improving the security of the account and the robustness of the account lifecycle management mechanism. The regular check mechanism and the automated management method improve the management efficiency, enhance the management reliability, and ensure that the account can be processed in a timely manner after the end of the lifecycle.
[0019] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present invention, nor is it used to limit the scope of the present invention. Other features of the present invention will become easily understood through the following description. Description of the Drawings
[0020] To more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0021] Figure 1 is a flowchart of a method for managing the account life cycle provided in Embodiment 1 of the present invention;
[0022] Figure 2 is a flowchart of another method for managing the account life cycle provided in Embodiment 2 of the present invention;
[0023] Figure 3 is a schematic diagram of a management logic process of the account life cycle applicable to the embodiments of the present invention;
[0024] Figure 4 is a schematic diagram of an expiration check module applicable to the embodiments of the present invention;
[0025] Figure 5 is a schematic diagram of a startup thread cycle check logic applicable to the embodiments of the present invention;
[0026] Figure 6 is a schematic diagram of the structure of a device for managing the account life cycle provided in Embodiment 3 of the present invention;
[0027] Figure 7 is a schematic diagram of the structure of an electronic device for implementing the method for managing the account life cycle of the embodiments of the present invention. Detailed implementation manners
[0028] To enable those skilled in the art to better understand the solutions of the present invention, the following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0029] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0030] Embodiment 1
[0031] In the related art, the password expiration mechanism usually relies on the account creation time and a preset expiration time to achieve, and to a certain extent, it can ensure the security of the account. However, since the password expiration mechanism highly depends on the accuracy of the system time, in actual applications, the system time may be affected by various factors, resulting in the failure of the password expiration mechanism. Specifically, in the networked state, if the Network Time Protocol (NTP) server is attacked, the client device may receive incorrect time information, which in turn affects the judgment of password expiration. In the non-networked state, the system time is even more likely to be maliciously modified, and attackers can bypass the password expiration limit by tampering with the local time, making the password expiration mechanism based on the system time no longer reliable. Therefore, when facing system time adjustment or server attack, the robustness of the password expiration mechanism in the related art will be severely affected, and it cannot effectively ensure the security of the account.
[0032] Figure 1 FIG. is a flowchart of a method for managing the account life cycle provided in Embodiment 1 of the present invention. This embodiment is applicable to the situation of managing accounts according to the account life cycle. This method can be executed by a management device for the account life cycle, and the management device for the account life cycle can be implemented in the form of hardware and / or software and is generally configured in the server. As Figure 1 shown, the method includes:
[0033] S110. Whenever the preset inspection period is reached, sequentially obtain the password credentials in the locally stored user list, and compare the value of the timestamp field in each password credential with the preset account life cycle value.
[0034] In the embodiments of the present invention, the user list can be specifically understood as: a data structure that stores all user information, which may include the password credentials of users, and is used to manage and retrieve user information. The system can find the account information of a specific user through the user list for account management and operations. The password credentials can be specifically understood as: information used to verify the identity of users, ensuring that only legitimate users can access system resources, and may include the username, password, and corresponding timestamp, etc. The value of the timestamp field can be specifically understood as: a value that records the usage time of the user password, and the initial value is set to 0. According to the application scenario and system requirements, the value of the timestamp field can be described using different time units, such as the tick time unit. A tick refers to the basic unit of a fixed time interval, used to represent the interval of clock interrupts or the time slice of the system, that is, the operating system clock sends an interrupt signal every tick time interval. The time length of one tick can be set according to the system requirements, such as 1 millisecond or 10 milliseconds, etc.
[0035] The account life cycle value can be specifically understood as: the time length from the creation to the expiration of the account. After this period, the account will be regarded as expired, and it can be used to regularly check the validity of the account to ensure that the account is used within the valid period. The account life cycle is configured in the global configuration file and an initial value is set. For example, when the initial value of the account life cycle is 90 days, it means the account can only exist for 90 days. The setting of the account life cycle value can be dynamically adjusted according to various factors. For example, when it is detected that the activity of a certain account decreases, the system can automatically shorten its life cycle; different account life cycle values can be set according to the user type. For example, new users can be set a shorter life cycle, and old users can be set a longer life cycle; different account life cycle values can be set according to user feedback. For example, when the user feedbacks that the password modification frequency is too frequent, the account life cycle value can be extended.
[0036] Specifically, whenever the preset inspection period is reached, the system obtains the user list from the local storage. Each user has a password credential. The value of the timestamp field in each password credential is compared with the preset account life cycle value to determine the account status. Among them, the inspection period is achieved by setting a fixed sleep time, which can usually be set as a multiple of tick, such as it can be set to several minutes. For example, an inspection is performed every 5 minutes to achieve reasonable use of system resources and avoid affecting system performance due to frequent inspections.
[0037] S120. When it is determined that the current value of the current timestamp field in the currently compared current password credential is greater than or equal to the account life cycle value, send a logout instruction to the client that logs in using the current password credential.
[0038] S130. When it is determined that the value of the current timestamp field in the current password credential being currently compared is less than the account lifecycle value, the value of the current timestamp field in the current password credential is incrementally updated according to the inspection period.
[0039] Specifically, the system compares the value of the timestamp field in each password credential with the preset account lifecycle value. If the value of the timestamp field is greater than or equal to the account lifecycle value, it indicates that the account has expired. The system sends a logout instruction to the client that logs in using this password credential, forcing the user to exit the logged-in state, preventing unauthorized access, and improving the security of the system.
[0040] If the value of the timestamp field is less than the account lifecycle value, it indicates that the account has not expired. The time length of the inspection period is added to the current value of the timestamp field to reflect the usage time of the account password. By periodically updating the value of the timestamp field, the system can accurately track the validity period of the account and ensure that the account is processed in a timely manner after the end of its lifecycle.
[0041] In a specific example, assume that the lifecycle value of an account is 90 days and the current value of the timestamp field is 85 days. When the system checks, it finds that the value of the timestamp field of this account is less than the account lifecycle value, indicating that the account has not expired. The system will add the time length of the inspection period (for example, check once every 5 minutes) to the current value of the timestamp field and update the value of the timestamp field in the password credential.
[0042] The technical solution of the embodiment of the present invention, by successively obtaining the password credentials in the user list for comparison whenever the inspection period arrives. When the value of the current timestamp field of the current credential is greater than or equal to the account lifecycle value, a logout instruction is sent to the corresponding client; when the value of the timestamp field is less than the account lifecycle value, the current timestamp field value is incrementally updated according to the inspection period. By managing the account lifecycle through the preset inspection period time scale, it is possible to manage the account lifecycle without relying on the system time, avoiding errors in account lifecycle management caused by the modification of the local time, improving the security of the account and the robustness of the account lifecycle management mechanism. The regular inspection mechanism and automated management method improve the management efficiency, enhance the management reliability, and ensure that the account can be processed in a timely manner after the end of its lifecycle.
[0043] Further, on the basis of the above embodiments, after incrementally updating the value of the current timestamp field in the current password credential according to the inspection period, it may further include:
[0044] Compare the value of the current timestamp field in the current password credential with a preset notification threshold;
[0045] When the value of the current timestamp field is greater than or equal to the notification threshold, check whether the notification array contains the user account corresponding to the current password credential;
[0046] If not, send an event notification instruction to the client that logs in using the current password credential, and add the user account corresponding to the current password credential to the notification array;
[0047] If so, abandon the operation of sending the event notification instruction.
[0048] In the embodiments of the present invention, the notification threshold can be specifically understood as: a preset time value used to determine whether an account is about to expire, so as to determine when to send a notification of upcoming expiration to the user, thereby reminding the user to update the account information in time. When the value of the timestamp field in the current password credential is greater than or equal to the notification threshold, the system will consider that the account is about to expire. The notification threshold is configured in the global configuration file and an initial value is set. For example, the initial value of the threshold is 30 days, which means that an event notification is sent when the remaining time is less than 30 days. The notification array can be specifically understood as: an array used to store the user accounts that have received the notification of upcoming expiration. By checking the notification array, the system can avoid sending the notification of upcoming expiration to the same user multiple times, thereby reducing interference to the user. The event notification can be specifically understood as: a notification message sent by the system to the client, such as in the form of a pop-up window or an email, etc., used to inform the user that their account is about to expire.
[0049] Specifically, the system compares the value of the timestamp field in the current password credential with the preset notification threshold. When the value of the timestamp field in the current password credential is greater than or equal to the notification threshold, the system will check whether the notification array already contains the user account corresponding to the current password credential. If the notification array does not contain the user account corresponding to the current password credential, the system will send an event notification instruction to the client that logs in using this password credential, informing the user that their account is about to expire, and the user can perform corresponding password update operations according to the usage situation. At the same time, the system will add this user account to the notification array to prevent subsequent notifications. If the notification array already contains the user account corresponding to the current password credential, the system will not send an event notification instruction to the client. By timely reminding the user that the account is about to expire, the user can take measures in advance, such as updating the password, to avoid the inconvenience caused by the expiration of the account. By checking the notification array, the system can avoid sending the notification of upcoming expiration to the same user multiple times, reduce interference to the user, improve the user experience, and improve the efficiency and reliability of the system through an automated notification method.
[0050] Further, based on the above embodiments, the method for managing the account life cycle may further include:
[0051] Whenever a registration password credential sent by a new client is detected, after adding a timestamp field to the registration password credential, add the registration password credential to the user list; wherein, the value of the added timestamp field is initialized to 0.
[0052] In the embodiments of the present invention, the registration password credential can be specifically understood as: information provided by a user during the registration process for identity verification, which may include a username, a password, and a timestamp.
[0053] Specifically, by adding a timestamp field initialized to 0 to the registration password credential, the system can record the usage time of each account password, thereby managing the life cycle of the account. By adding the registration password credential to the user list, the system can quickly retrieve and manage user information, improving the system's response speed and user experience.
[0054] Embodiment Two
[0055] Figure 2 FIG. is a flowchart of another method for managing the life cycle of an account provided in Embodiment Two of the present invention. This embodiment is a refinement of the method for managing the life cycle of an account in the above embodiment. The method for managing the life cycle of an account may specifically further include: whenever an updated password credential sent by an existing client is detected, add a timestamp field to the updated password credential; wherein, the value of the added timestamp field is initialized to 0; identify a historical password credential in the user list that belongs to the same client as the updated password credential, and replace the historical password credential in the user list with the updated password credential.
[0056] Correspondingly, as Figure 2 shown, the method includes:
[0057] S210. Whenever a preset check period arrives, sequentially obtain the password credentials in the locally stored user list, and compare the value of the timestamp field in each password credential with a preset account life cycle value.
[0058] S220. When it is determined that the value of the current timestamp field in the current password credential being compared is greater than or equal to the account life cycle value, send a logout instruction to the client that logs in using the current password credential.
[0059] S230. When it is determined that the value of the current timestamp field in the current password credential being compared is less than the account life cycle value, cumulatively update the value of the current timestamp field in the current password credential according to the check period.
[0060] S240. Whenever an updated password credential sent by an existing client is detected, add a timestamp field to the updated password credential.
[0061] Wherein, the value of the added timestamp field is initialized to 0.
[0062] In the embodiments of the present invention, updating the password credential can be specifically understood as: when a user updates the password, a new password credential generated by the system, which may include the user's account information and the new password, as well as a timestamp field for recording the usage duration of the new password.
[0063] S250. Identify the historical password credential in the user list that belongs to the same client as the updated password credential, and replace the historical password credential in the user list with the updated password credential.
[0064] In the embodiments of the present invention, the historical password credential can be specifically understood as: the old password credential used by the user before updating the password, which may include the user's account information and the old password, as well as a timestamp field for recording the usage duration of the old password. The historical password credential records the user's historical password information for verification when needed.
[0065] Specifically, whenever an updated password credential sent by an existing client is detected, the system adds a timestamp field with an initial value of 0 to the updated password credential to record the usage duration of the new password. Then, the system searches for the historical password credential in the user list that belongs to the same client as the updated password credential, and replaces the historical password credential in the user list with the updated password credential to ensure that the user list in the system always contains the latest password information.
[0066] The technical solution of the embodiments of the present invention initializes the timestamp field when updating the password credential, so that the system can manage the lifecycle of the account again according to the preset check cycle time scale, can manage the lifecycle of the account without relying on the system time, avoids the error of account lifecycle management caused by the modification of the local time, and improves the security of the account and the robustness of the account lifecycle management mechanism. The regular check mechanism and the automated management method improve the management efficiency, enhance the management reliability, and ensure that the account can be processed in time after the lifecycle ends. By automatically replacing the historical password credential in the user list, the security of the account is enhanced, the accuracy and consistency of password management are ensured, the interference to the user is reduced, and the user experience is optimized.
[0067] Further, on the basis of the above embodiments, after detecting the updated password credential sent by an existing client, it may further include:
[0068] Detect whether the target user account corresponding to the existing client is stored in the notification array;
[0069] If so, delete the target user account from the notification array.
[0070] In the embodiments of the present invention, the target user account can be specifically understood as: the user account corresponding to the current client, that is, the account used by the current client.
[0071] Specifically, when an update password credential sent by an existing client is detected, the system checks whether the notification array already contains the target user account corresponding to the current client to determine whether a notification of upcoming expiration has been sent to this client during the past account lifecycle management process. If the notification array indeed contains the target user account corresponding to the current client, the system deletes this account from the notification array. By timely updating the notification array, it is ensured that after the password is updated, the system can send a notification again when the password usage duration exceeds the notification threshold next time, ensuring the accuracy of the regular check mechanism and the automated management method, improving the user experience and the efficiency of account management, enhancing the reliability of management, and ensuring that the account can be processed in a timely manner after the end of its lifecycle.
[0072] Optionally, based on the above embodiments, the method for managing the account lifecycle is executed by an expiration check component in the server, and this component may include:
[0073] A thread processing sub-component for traversing the user list, checking whether the value of the current timestamp field in the current password credential being compared is greater than or equal to the account lifecycle. If so, it sends a logout instruction to the client logging in using the current password credential; if not, it accumulatively updates the value of the current timestamp field in the current password credential according to the check period and calls the notification expiration sub-component;
[0074] A notification expiration sub-component, in response to the call of the thread processing sub-component, is used to check whether the value of the current timestamp field in the current password credential is greater than or equal to a preset notification threshold and whether the notification array contains the user account corresponding to the current password credential after accumulatively updating the value of the current timestamp field in the current password credential according to the check period. If the value of the current timestamp field in the current password credential is greater than or equal to the preset notification threshold and the notification array does not contain the user account corresponding to the current password credential, it calls the notification registration sub-component;
[0075] A notification registration sub-component for registering to listen for the broadcast event of upcoming expiration, and in response to the call of the notification expiration sub-component, sending an event notification instruction to the client logging in using the current password credential;
[0076] A user adding sub-component for adding the user account corresponding to the current password credential to the notification array after sending an event notification instruction to the client logging in using the current password credential;
[0077] The deletion registration sub-component is used to cancel the registration of the broadcast event that is about to expire after adding the user account corresponding to the current password credential to the notification array;
[0078] The deletion user sub-component is used to detect whether the target user account corresponding to the existing client is stored in the notification array when it is detected that the existing client has sent an updated password credential. If so, the target user account is deleted from the notification array.
[0079] In the embodiments of the present invention, the expiration check component can be specifically understood as an independent module or function for checking whether the account password has expired. The sub-component can be specifically understood as a smaller part within the component, which can be a module or function for implementing a specific function or task of the component.
[0080] Specifically, the thread processing sub-component is used to periodically check whether the user credential has expired and send a logout instruction when it expires, ensuring that the account is processed in a timely manner after the end of its life cycle and preventing unauthorized access. Through the notification expiration sub-component and the notification registration sub-component, the system can notify the user in a timely manner when the account is about to expire. By adding the user sub-component and the deletion registration sub-component, the accuracy and consistency of the notification array are ensured, avoiding duplicate notifications and resource waste, and reducing interference to users. By deleting the user sub-component, the notification array is updated in a timely manner, ensuring that after the password is updated, the system can send a notification again when the password usage duration exceeds the notification threshold next time, ensuring the accuracy of the periodic check mechanism and the automated management method, improving the user experience and the efficiency of account management, enhancing the reliability of management, and ensuring that the account can be processed in a timely manner after the end of its life cycle.
[0081] Specific application scenarios
[0082] For ease of understanding, the specific application scenarios applicable to each embodiment of the present disclosure will now be described. In the field of computer security, password expiration refers to a mechanism in which a user must change their password after a preset time period to enhance the security of the account and reduce the risk of the password being guessed or leaked. With the popularization of computer technology and the growth of network security requirements, password management has become increasingly important. Traditional password expiration is achieved by the account creation time and the expiration time, so this solution is affected by the system time adjustment for judgment. When the network time protocol server is attacked in the online state or the system time is modified in the offline state, the expiration mechanism becomes unstable. To solve the above problems, the embodiments of the present invention propose a method for managing the life cycle of an account, which can specifically include:
[0083] This function is implemented by adding a tick accumulation thread to peripheral_user_auth. Among them, peripheral_user_auth is a module or function related to user authentication, which is used to process user authentication requests or manage user access permissions, and belongs to the background service for verifying user identities or permissions. The accumulation thread refers to a thread specifically used for accumulation counting, which is used to count the usage time of passwords. When obtaining account information, it will calculate whether the account has expired by checking tickTime and return the corresponding result.
[0084] 1. When a registered user is detected, add the tickTime field to the corresponding registered password credential
[0085] When a registered password credential sent by a new client is detected, add the tickTime field (equivalent to the timestamp above) to the data of the registered password credential and initialize it to 0.
[0086] 2. Regularly check tickTime
[0087] The thread in the ExpiredChecker module regularly checks whether the value of the tickTime field exceeds the notification threshold and whether it has expired according to the preset check period. Among them, the regular check period is implemented by sleeping for a fixed preset period value (such as 5 minutes) in the code. Among them, the account life cycle value and the notification threshold are configured in a global configuration file and preset initial values are set for them respectively. For example, the initial value of the account life cycle can be set to 90 days, indicating that the account can only exist for 90 days; the initial value of the notification threshold can be set to 30 days, indicating that a system event broadcast notification is made when the remaining time is less than 30 days. Among them, the ExpiredChecker module is a module or function used to check and manage expired passwords.
[0088] 3. When the account has not expired, refresh tickTime
[0089] After each regular expiration check by the thread in the ExpiredChecker module, if the value of the tickTime field is less than the account life cycle value (that is, when the account has not expired), it will refresh the tickTime (that is, add the preset period value to the current tickTime field value) and rewrite it to the local data again. After updating the tickTime field, the thread will rewrite the data of the credential to the local storage to ensure data persistence, so that the latest state of the credential can be retained even if the system restarts or a failure occurs.
[0090] 4. When the account is about to expire, make a broadcast notification
[0091] If the remaining time of the account (i.e., the difference between the account life cycle value of the current account and the tickTime field value in its credential) is less than the notification threshold, it indicates that the account is about to expire. A system event is broadcast to notify the remaining time of the account, and the userid (user identifier) of the current user is recorded through the notification array to prevent multiple notifications.
[0092] 5. After the account password is updated, update the notification array
[0093] After the account updates the password, ensure that tickTime can send notifications again after exceeding the notification threshold next time by actively deleting the userid in the notification array.
[0094] 6. When the account has expired, stop updating user information
[0095] If the expiration time has been exceeded, the tickTime of the password credential is not refreshed (i.e., tickTime is greater than or equal to the life cycle).
[0096] Figure 3 It is a schematic diagram of a management logic process for an account life cycle applicable to an embodiment of the present invention. As Figure 3 shown, when the detection thread starts (Start), the thread processor (ThreadHandler) loads user data from the local storage of user authentication data (userauth), such as reading the user list from the local storage, and performs a detection operation every 5 minutes, that is, regularly wakes up the check thread and executes the subsequent check logic. The expired check module (ExpiredChecker) traverses the user list (userList) to check the expiration status of each user. For each user, the single-user expired check module (ExpiredCheckerSingle) checks the expiration status of a single user to determine whether the remaining time of the user is less than the notification threshold (for example, the notification threshold can be set to 30 days). If the remaining time is less than the notification threshold (such as remainingTime < 30 days), the expired notification method (NotifyExpired) of ExpiredChecker is called to notify the user, for example, by sending a notification or an email to remind the user. In addition, when the tickTime field value is less than the account life cycle value, the expired update module (UpdateExpired) updates the user information, refreshes the tickTime, and redrops it to userauth. After a check is completed, the process returns to ThreadHandler to continue the next 5-minute detection cycle to achieve cyclic detection.
[0097] The ExpiredChecker module (equivalent to the expired check component mentioned above) is a module that monitors and manages the password expiration period of user accounts. It determines when to remind users that their passwords are about to expire or have already expired by tracking the usage time of users' passwords. Figure 4 It is a schematic diagram of an expired check module applicable to the embodiments of the present invention, as Figure 4 shown, and specifically may include:
[0098] 1. Provide Start (start) and Stop (stop) methods to start and stop the ThreadHandler thread respectively;
[0099] 2. Provide RegisterExpiredCallback (register expired feedback) and UnRegisterExpiredCallback (unregister expired feedback) methods to register and unregister the broadcast event listening for expiration respectively.
[0100] 3. Provide the NotifyExpired method to trigger the upcoming expiration notice check.
[0101] 4. Provide AddUserId (add user ID) and DelUserId (delete user ID) to record the user ID (Identification) respectively, prevent duplicate sending of the upcoming expiration broadcast, and delete the user ID to realize the re - management of the account life cycle after the user updates the password and send the upcoming expiration broadcast when it is about to expire.
[0102] 5. Provide the ThreadHandler method to traverse the user list, check the expiration time of each user, and manage the account life cycle.
[0103] Correspondingly, Figure 5 It is a schematic diagram of a start - up thread cycle check logic applicable to the embodiments of the present invention, as Figure 5 shown, and the process of starting the thread for cycle check can be:
[0104] 1. Create a loop with the condition that the ThreadHandler thread is running (running). If the ThreadHandler thread is not running, the process ends.
[0105] 2. Record the current system running duration, calculate the difference from the last running time, and start the ExpiredChecker check.
[0106] 3. In ExpiredChecker, traverse the userList and check whether the credentials of each user have expired. The process of the corresponding method ExpiredCheckerSignal is as follows:
[0107] (1) If the current tickTime has expired, this ExpiredCheckerSignal ends, and the thread sleeps for a period of time and then starts checking again.
[0108] (2) If the current tickTime has not expired, start the UpdateExpired module, update the accumulated difference of the expired user information (the preset check cycle value) to tickTime and refresh tickTime.
[0109] (3) If the current remaining time (that is, the difference between the account life cycle value of the current account and the tickTime field value in its credentials) is greater than or equal to the upcoming expiration threshold (notification threshold), then ExpiredCheckerSignal ends.
[0110] (4) If the current remaining time is less than the upcoming expiration threshold and has not been notified (the corresponding user ID does not exist in the notification array), then start the NotifyExpired module, trigger the upcoming expiration broadcast notification, and record the user ID.
[0111] When implementing the management function of the account life cycle, the interaction process between each module can specifically include:
[0112] 1. When the UserAuthService (User Authentication Service) starts, register a broadcast notification listener with UserAuth. Among them, the user authentication service can include function authentication services such as user login, registration, and password reset. User authentication refers to the verification process of the user's identity, which can include the verification of the username and password.
[0113] 2. When the UserAuthService stops, unregister the broadcast notification listener from UserAuth.
[0114] 3. When the UserAuth service starts, start the check thread in the ExpiredChecker module.
[0115] 4. When the UserAuth service stops, stop the check thread in the ExpiredChecker module.
[0116] 5. When the checking thread in the ExpiredChecker module periodically checks whether the user credentials (including the user password) have expired, if there is no tickTime field in the credentials, the value of the tickTime field with an initial value of 0 is added. If the credentials have not expired, the tickTime is refreshed. If the credentials have expired, this detection is skipped.
[0117] 6. When the checking thread in the ExpiredChecker module periodically checks that the user credentials are about to expire, if they are about to expire and the current user ID is not in the notification array, a notification message is triggered to the UserAuthService service, and the UserAuthService service sends a broadcast event and records the user ID to prevent duplicate notifications.
[0118] 7. When the user updates the credentials, the user ID recorded in UserAuth is cleared.
[0119] 8. When obtaining the valid status of the credentials, an active check is triggered on whether the account is about to expire.
[0120] The account lifecycle management method proposed in the embodiment of the present invention determines whether the password has expired by accumulating whether the user usage time exceeds a fixed duration, and notifies the user by broadcasting an event when the remaining time is less than a certain fixed threshold duration, to prompt that the password is about to expire and require the user to modify the password, solving the strong coupling relationship between the password expiration time and the system time. By periodically refreshing the tick in the password for statistics, it has no direct relationship with the system time, thus solving this problem to ensure the security of the user expiration mechanism.
[0121] Embodiment III
[0122] Figure 6 It is a schematic structural diagram of an account lifecycle management device provided in Embodiment III of the present invention. As Figure 6 shown, the device includes: an expiration comparison module 610, a logout module 620, and an accumulation and update module 630, where:
[0123] The expiration comparison module 610 is used to, whenever a preset check period arrives, sequentially obtain the password credentials in the locally stored user list, and compare the value of the timestamp field in each password credential with the preset account lifecycle value;
[0124] The logout module 620 is used to, when it is determined that the value of the current timestamp field in the current password credential being compared is greater than or equal to the account lifecycle value, send a logout instruction to the client that logs in using the current password credential;
[0125] An accumulation and update module 630, configured to, when determining that the value of the current timestamp field in the current password credential being currently compared is less than the account lifecycle value, accumulate and update the value of the current timestamp field in the current password credential according to the check period.
[0126] The technical solution of the embodiment of the present invention is that, by obtaining the password credentials in the user list in sequence whenever the check period arrives and comparing them, when the value of the current timestamp field of the current credential is greater than or equal to the account lifecycle value, a logout instruction is sent to the corresponding client; when the value of the timestamp field is less than the account lifecycle value, the value of the current timestamp field is accumulated and updated according to the check period. By managing the account lifecycle through the preset check period time scale, it is possible to manage the account lifecycle without relying on the system time, avoiding errors in account lifecycle management caused by the modification of the local time, improving the security of the account and the robustness of the account lifecycle management mechanism. The regular check mechanism and the automated management method improve the management efficiency, enhance the management reliability, and ensure that the account can be processed in a timely manner after the end of its lifecycle.
[0127] Further, on the basis of the above embodiments, the apparatus for managing the account lifecycle may further include: a notification comparison module, an array check module, a notification sending module, and a discard execution module, where:
[0128] The notification comparison module is configured to, after accumulating and updating the value of the current timestamp field in the current password credential according to the check period, compare the value of the current timestamp field in the current password credential with a preset notification threshold;
[0129] The array check module is configured to, when the value of the current timestamp field is greater than or equal to the notification threshold, check whether the notification array contains the user account corresponding to the current password credential;
[0130] The notification sending module is configured to, if not, send an event notification instruction to the client that logs in using the current password credential, and add the user account corresponding to the current password credential to the notification array;
[0131] The discard execution module is configured to, if so, discard the operation of sending the event notification instruction.
[0132] Further, on the basis of the above embodiments, the apparatus for managing the account lifecycle may further include: a registration credential module, where:
[0133] The registration credential module is configured to, whenever a registration password credential sent by a new client is detected, after adding a timestamp field to the registration password credential, add the registration password credential to the user list; wherein, the value of the added timestamp field is initialized to 0.
[0134] Further, based on the above embodiments, the account life cycle management device may further include: an update credential module and a replace credential module, where:
[0135] The update credential module is configured to add a timestamp field to the update password credential whenever an update password credential sent by an existing client is detected; wherein, the value of the added timestamp field is initialized to 0;
[0136] The replace credential module is configured to identify a historical password credential in the user list that belongs to the same client as the update password credential, and use the update password credential to replace the historical password credential in the user list.
[0137] Optionally, based on the above embodiments, the update credential module may include: an account detection sub-module and an account deletion sub-module, where:
[0138] The account detection sub-module is configured to detect whether a target user account corresponding to the existing client is stored in the notification array after detecting an update password credential sent by an existing client;
[0139] The account deletion sub-module is configured to, if so, delete the target user account from the notification array.
[0140] Optionally, based on the above embodiments, the account life cycle management device is configured in an expiration check component in the server, and this component may include:
[0141] The thread processing sub-component is configured to traverse the user list, check whether the value of the current timestamp field in the current password credential being compared is greater than or equal to the account life cycle. If so, send a logout instruction to the client logging in using the current password credential; if not, accumulate and update the value of the current timestamp field in the current password credential according to the check period, and call the notification expiration sub-component;
[0142] The notification expiration sub-component, in response to the call of the thread processing sub-component, is configured to, after accumulating and updating the value of the current timestamp field in the current password credential according to the check period, check whether the value of the current timestamp field in the current password credential is greater than or equal to a preset notification threshold, and whether the notification array contains a user account corresponding to the current password credential. If the value of the current timestamp field in the current password credential is greater than or equal to the preset notification threshold, and the notification array does not contain a user account corresponding to the current password credential, then call the notification registration sub-component;
[0143] The notification registration sub-component is configured to register a broadcast event for listening for expiration soon, and in response to the call of the notification expiration sub-component, send an event notification instruction to the client logging in using the current password credential;
[0144] Add a user sub-component, which is used to add the user account corresponding to the current password credential to the notification array after sending an event notification instruction to the client that logs in using the current password credential;
[0145] Delete the registration sub-component, which is used to cancel the registration of listening for the broadcast event that is about to expire after adding the user account corresponding to the current password credential to the notification array;
[0146] Delete the user sub-component, which is used to detect whether the target user account corresponding to the existing client is stored in the notification array when it is detected that the existing client has sent an updated password credential. If so, the target user account is deleted from the notification array.
[0147] The management device for the account life cycle provided by the embodiments of the present invention can execute the management method for the account life cycle provided by any embodiment of the present invention, and has the corresponding functional modules and beneficial effects for executing the method.
[0148] In the technical solution of the present disclosure, the collection, storage, use, processing, transmission, provision, and disclosure of the user's personal information and other processing all comply with the provisions of relevant laws and regulations and do not violate public order and good customs.
[0149] Embodiment 4
[0150] Figure 7 Fig. shows a schematic structural diagram of an electronic device 10 that can be used to implement the embodiments of the present invention. The electronic device is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or claimed herein.
[0151] As Figure 7As shown, the electronic device 10 includes at least one processor 11 and a memory communicatively connected to the at least one processor 11, such as read-only memory (ROM) 12, random access memory (RAM) 13, etc. Among them, the memory stores a computer program executable by the at least one processor. The processor 11 can execute various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 into the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, ROM 12, and RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.
[0152] Multiple components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disc, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.
[0153] The processor 11 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the processor 11 include but are not limited to a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as the method for managing the account lifecycle, that is:
[0154] Whenever the preset inspection period is reached, sequentially obtain the password credentials in the locally stored user list, and compare the value of the timestamp field in each password credential with the preset account lifecycle value;
[0155] When it is determined that the value of the current timestamp field in the current password credential being compared is greater than or equal to the account lifecycle value, send a logout instruction to the client that logs in using the current password credential;
[0156] When it is determined that the value of the current timestamp field in the current password credential being compared is less than the account lifecycle value, accumulatively update the value of the current timestamp field in the current password credential according to the inspection period.
[0157] In some embodiments, the method for managing the account lifecycle can be implemented as a computer program tangibly embodied in a computer-readable storage medium, such as storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the method for managing the account lifecycle described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to execute the method for managing the account lifecycle by any other suitable means (e.g., by means of firmware).
[0158] The various embodiments of the systems and techniques described above in this document can be implemented in digital electronic circuitry, integrated circuit systems, field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems-on-chip (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special-purpose or general-purpose programmable processor that receives data and instructions from a storage system, at least one input device, and at least one output device, and transmits the data and instructions to the storage system, the at least one input device, and the at least one output device.
[0159] The computer program for implementing the method of the present invention can be written in any combination of one or more programming languages. These computer programs can be provided to the processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the computer program is executed by the processor, the functions / operations specified in the flowchart and / or block diagram are implemented. The computer program can be executed entirely on the machine, partially on the machine, as a stand-alone software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0160] In the context of the present invention, a computer-readable storage medium can be a tangible medium that can contain or store a computer program for use by or in connection with an instruction execution system, apparatus, or device. The computer-readable storage medium can include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, the computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0161] To provide for interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0162] The systems and techniques described herein can be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: local area network (LAN), wide area network (WAN), blockchain network, and the Internet.
[0163] A computing system may include a client and a server. The client and the server are generally far from each other and usually interact via a communication network. The client-server relationship is created by computer programs running on respective computers and having a client-server relationship with each other. The server can be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in the cloud computing service system, solving the defects of difficult management and weak business scalability existing in traditional physical hosts and VPS services.
[0164] It should be understood that various forms of processes shown above can be used, with steps reordered, added, or deleted. For example, the steps described in the present invention can be executed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved, and no limitation is imposed herein.
[0165] The above specific embodiments do not constitute a limitation on the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations, and substitutions can be made according to design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention shall be included within the protection scope of the present invention.
Claims
1. A method for managing the account life cycle, characterized in that, Executed by the server, including: Whenever the preset check period is reached, sequentially obtain the password credentials in the locally stored user list, and compare the value of the timestamp field in each password credential with the preset account lifecycle value; When it is determined that the value of the current timestamp field in the currently compared current password credential is greater than or equal to the account lifecycle value, send a logout instruction to the client that logs in using the current password credential; When it is determined that the value of the current timestamp field in the currently compared current password credential is less than the account lifecycle value, accumulatively update the value of the current timestamp field in the current password credential according to the check period.
2. The method according to claim 1, wherein After accumulatively updating the value of the current timestamp field in the current password credential according to the check period, it further includes: Compare the value of the current timestamp field in the current password credential with the preset notification threshold; When the value of the current timestamp field is greater than or equal to the notification threshold, check whether the notification array contains the user account corresponding to the current password credential; If not, send an event notification instruction to the client that logs in using the current password credential, and add the user account corresponding to the current password credential to the notification array; If so, abandon the operation of sending the event notification instruction.
3. The method according to claim 1 or 2, characterized in that, The method further includes: Whenever a registered password credential sent by a new client is detected, after adding a timestamp field to the registered password credential, add the registered password credential to the user list; wherein, the value of the added timestamp field is initialized to 0.
4. The method according to claim 1 or 2, characterized in that, The method further includes: Whenever an updated password credential sent by an existing client is detected, add a timestamp field to the updated password credential; wherein, the value of the added timestamp field is initialized to 0; Identify the historical password credential in the user list that belongs to the same client as the updated password credential, and replace the historical password credential in the user list with the updated password credential.
5. The method according to claim 4, characterized in that, After detecting an updated password credential sent by an existing client, it further includes: Detect whether the target user account corresponding to the existing client is stored in the notification array; If so, delete the target user account from the notification array.
6. The method according to any one of claims 1-5, characterized in that, The method is executed by an expiration check component in the server, and the component includes: A thread processing sub-component for traversing the user list, checking whether the value of the current timestamp field in the currently compared current password credential is greater than or equal to the account lifecycle. If so, send a logout instruction to the client that logs in using the current password credential; if not, accumulatively update the value of the current timestamp field in the current password credential according to the check period, and call the notification expiration sub-component; Notify the expired sub-component, in response to the call of the thread processing sub-component, after accumulating and updating the value of the current timestamp field in the current password credential according to the inspection period, check whether the value of the current timestamp field in the current password credential is greater than or equal to the preset notification threshold, and whether the notification array contains the user account corresponding to the current password credential. If the value of the current timestamp field in the current password credential is greater than or equal to the preset notification threshold and the notification array does not contain the user account corresponding to the current password credential, then call the notification registration sub-component; The notification registration sub-component is used to register to listen for the broadcast event of imminent expiration, and in response to the call of the notification expiration sub-component, send an event notification instruction to the client that logs in using the current password credential; The add user sub-component is used to add the user account corresponding to the current password credential to the notification array after sending the event notification instruction to the client that logs in using the current password credential; The delete registration sub-component is used to cancel the registration of listening for the broadcast event of imminent expiration after adding the user account corresponding to the current password credential to the notification array; The delete user sub-component is used to detect whether the target user account corresponding to the existing client is stored in the notification array when it is detected that the password credential has been updated by the existing client. If so, delete the target user account from the notification array.
7. A management device for the account life cycle, characterized in that Configured on the server side, including: The expiration comparison module is used to sequentially obtain the password credentials in the locally stored user list whenever the preset inspection period arrives, and compare the value of the timestamp field in each password credential with the preset account life cycle value; The logout module is used to send a logout instruction to the client that logs in using the current password credential when it is determined that the value of the current timestamp field in the current password credential being compared is greater than or equal to the account life cycle value; The accumulation update module is used to accumulate and update the value of the current timestamp field in the current password credential according to the inspection period when it is determined that the value of the current timestamp field in the current password credential being compared is less than the account life cycle value.
8. An electronic device, characterized in that, The electronic device includes: At least one processor; and A memory communicatively connected to the at least one processor; wherein, The memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the account life cycle management method according to any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer instructions, and the computer instructions are used to implement the account life cycle management method according to any one of claims 1-6 when executed by a processor.
10. A computer program product, characterized in that, The computer program product includes a computer program, and the computer program implements the account life cycle management method according to any one of claims 1-6 when executed by a processor.