Token code generation method and token code authentication method and system
By setting up an authentication mechanism for update controls and server-side in the token page, the poor experience caused by user misreading and waiting for refresh is solved, and the token code is conveniently refreshed and validated.
Patent Information
- Application Number
- CN202410039826.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-09
- Publication Date
- 2025-07-11
AI Technical Summary
In the prior art, the user inputs multiple times due to misreading when entering the token code, and the user experience is poor due to waiting for the token code to be refreshed.
By setting up token update controls in the token page, users are allowed to manually update the token code, and generate a new token based on the preset token refresh time on the server side for authentication processing, ensuring the matching of user information and key information.
It alleviates users' anxiety during waiting for the token code to be automatically refreshed, improves the user experience, and ensures the smooth progress of identity verification and account login.
Smart Images

Figure CN120301611A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data processing, and in particular, to a method for generating a token code, a method for authenticating a token code, and a system. This application also relates to a device for generating a token code, an authentication device, an electronic device, and a storage medium. Background Art
[0002] With the development of the Internet, in order to maintain the security of the network environment, more and more places begin to use token codes to verify the identities of users. For example, when enterprises manage user accounts for logging in to internal systems and when dealing with Internet account security issues, token codes are required.
[0003] In practical applications, the token code needs to be manually input by the user to complete account login, identity verification, etc. However, limited by the user's manual input of the token code, there will inevitably be situations where the same verification code is incorrectly input multiple times due to the user's misreading of the token code. At this time, if the user does not correct the misreading of the currently displayed token code, they need to wait for the token code to be automatically refreshed and then re-enter the new token code. It can be understood that since the user needs to wait for the refresh of the token code, the waiting process will inevitably result in a poor user experience of the token code function.
[0004] Therefore, how to solve the problem of poor user experience caused by the user waiting for the token code to be refreshed in the prior art has become a technical problem that needs to be urgently solved by those skilled in the art. Summary of the Invention
[0005] In order to solve the above technical problems, this application proposes a method for generating a token code, a method for authenticating a token code, and a system. This application also proposes a device for generating a token code, an authentication device for the token code, an electronic device, and a storage medium.
[0006] In order to achieve the above technical objectives, this application proposes the following technical solutions:
[0007] On the one hand, this application provides a method for generating a token code, which is applied to a target application program and includes:
[0008] Display a token page, where the token page includes an initial token and a token update control;
[0009] In response to a trigger operation for the token update control, update the initial token to a to-be-authenticated token; so that when the server receives an authentication request carrying the to-be-authenticated token and user information, generate a first token according to the key information of the target user and the first authentication time; perform authentication processing on the to-be-authenticated token based on the first token, and when the to-be-authenticated token fails the authentication, obtain a second authentication time that is a target duration later than the first authentication time according to the first authentication time; generate a second token based on the second authentication time and the key information; perform authentication processing on the to-be-authenticated token based on the second token;
[0010] Wherein, the target user is the user indicated by the user information, and the first authentication time is the time point when the authentication request is received or the generation time point of the authentication request; the target duration is a preset token automatic refresh duration.
[0011] In an alternative embodiment of the present application, the step of updating the initial token to a to-be-authenticated token in response to a trigger operation for the token update control includes:
[0012] In response to a first trigger operation for the token update control, obtain a token generation time that is a target duration later than the first time according to the first time;
[0013] Generate the to-be-authenticated token according to the token generation time and the key information, and update the initial token to the to-be-authenticated token;
[0014] Wherein, the first time is the response time point of the target application to the first trigger operation.
[0015] In an alternative embodiment of the present application, the step of displaying the token page includes:
[0016] In response to a second trigger operation for the target application, determine the key information corresponding to the target user; generate the initial token according to the key information and the second time; display a token page including the initial token; wherein the key information corresponding to the target user is stored in the database of the target application; the second time is the response time point of the target application to the second trigger operation;
[0017] Or,
[0018] In response to a third trigger operation for the target application, send a key request to the server, where the key request carries the user information; so that the server, upon receiving the key request, determines key information corresponding to the target user according to the user information; obtain the key information sent by the server; generate the initial token according to the key information and the third time; display a token page including the initial token; where the third time is the response time point of the target application to the third trigger operation or the time point when the target application receives the key information.
[0019] In an alternative embodiment of the present application, the displaying the token page includes:
[0020] Display an identity authentication interface for authenticating the user's identity;
[0021] Obtain first identity authentication information input by the user on the identity authentication interface;
[0022] Determine whether the first identity authentication information is consistent with preset second identity authentication information; where the second identity authentication information corresponds to the target user;
[0023] When the first identity authentication information is consistent with the second identity authentication information, display the token page;
[0024] When the first identity authentication information is inconsistent with the second identity authentication information, display a prompt message indicating an identity authentication error.
[0025] In an alternative embodiment of the present application, the token page further includes: a time calibration control;
[0026] The method further includes:
[0027] In response to a fourth trigger operation for the time calibration control, send a time calibration request carrying the first current time of the target application to the server; so that the server, upon receiving the time calibration request, determines whether the second current time of the server is consistent with the first current time of the target application; when the second current time is inconsistent with the first current time, determine the time difference between the first current time and the second current time, and send the time difference to the target application;
[0028] Receive the time difference returned by the server, and calibrate the time of the target application according to the time difference.
[0029] In an alternative embodiment of the present application, it further includes:
[0030] Generate a third token according to the calibrated first current time and the key information;
[0031] Update the initial token to the third token.
[0032] On the one hand, the present application provides an authentication method for a token code, which is applied to a server and includes:
[0033] Receive an authentication request from a login authentication device, where the authentication request carries user information and a token to be authenticated;
[0034] Generate a first token according to the key information of the target user and the first authentication time; where the target user is the user indicated by the user information, and the first authentication time is the time point when the authentication request is received or the generation time point of the authentication request;
[0035] Perform an authentication process on the token to be authenticated based on the first token, and in the case where the token to be authenticated fails the authentication, obtain a second authentication time that is a target duration later than the first authentication time according to the first authentication time; where the target duration is a preset token automatic refresh duration;
[0036] Generate a second token according to the key information and the second authentication time;
[0037] Perform an authentication process on the token to be authenticated based on the second token.
[0038] In an alternative embodiment of the present application, the generating a first token according to the key information of the target user and the first authentication time includes:
[0039] Determine the key information corresponding to the target user according to the user information;
[0040] Generate the first token according to the key information and the first authentication time.
[0041] In an alternative embodiment of the present application, the generating a second token according to the key information and the second authentication time includes:
[0042] On the basis of the first authentication time, add the target duration 1 to N times respectively to obtain N second authentication times; where N is the upper limit of the number of times of manual refresh of the token code;
[0043] Generate second tokens corresponding to each of the second authentication times one by one according to each of the second authentication times and the key information.
[0044] In an alternative embodiment of the present application, it further includes:
[0045] Receive a key request sent by the target application, where the key request carries the user information;
[0046] Determine the key information corresponding to the target user according to the user information, and send the key information to the target application; so that the target application generates an initial token according to the key information and the third time, and displays a token page including the initial token and a token update control;
[0047] Wherein, the target application is used to send the key request to the server in response to a third trigger operation on the target application; the third time is the time point of the third trigger operation on the target application or the time point when the target application receives the key information.
[0048] In an alternative embodiment of the present application, it further includes:
[0049] Receive a time calibration request sent by the target application, where the time calibration request carries the first current time of the target application;
[0050] Determine whether the second current time of the server is consistent with the first current time of the target application;
[0051] In the case where the second current time is inconsistent with the first current time, determine the time difference between the first current time and the second current time, and send the time difference to the target application; so that the target application calibrates the time of the target application according to the time difference.
[0052] On the one hand, the present application provides a token code generation device, which is applied to a target application and includes:
[0053] A display unit for displaying a token page, where the token page includes an initial token and a token update control;
[0054] An update unit for, in response to a trigger operation on the token update control, updating the initial token to a token to be authenticated; so that when the server receives an authentication request carrying the token to be authenticated and user information, generate a first token according to the key information of the target user and the first authentication time; perform authentication processing on the token to be authenticated based on the first token, and in the case where the token to be authenticated fails the authentication, obtain a second authentication time that is a target duration later than the first authentication time according to the first authentication time; generate a second token based on the second authentication time and the key information; perform authentication processing on the token to be authenticated based on the second token;
[0055] Wherein, the target user is the user indicated by the user information, and the first authentication time is the time point when the authentication request is received or the generation time point of the authentication request; the target duration is a preset token automatic refresh duration.
[0056] On the one hand, the present application provides an authentication device for a token code, which is applied to a server and includes:
[0057] A receiving unit, configured to receive an authentication request from a login authentication device, where the authentication request carries user information and a token to be authenticated;
[0058] A first generating unit, configured to generate a first token according to the key information of the target user and the first authentication time; wherein, the target user is the user indicated by the user information, and the first authentication time is the time point when the authentication request is received or the generation time point of the authentication request;
[0059] A first authentication unit, configured to perform authentication processing on the token to be authenticated based on the first token, and in the case where the token to be authenticated fails the authentication, obtain a second authentication time that is later than the first authentication time by a target duration according to the first authentication time; wherein, the target duration is a preset token automatic refresh duration;
[0060] A second generating unit, configured to generate a second token according to the key information and the second authentication time;
[0061] A second authentication unit, configured to perform authentication processing on the token to be authenticated based on the second token.
[0062] On the one hand, the present application provides an electronic device, including: a processor; a memory for storing executable instructions of the processor; the processor is configured to execute the above-mentioned token code generation method or token code authentication method by running the instructions in the memory.
[0063] On the one hand, the present application provides a computer storage medium, where the storage medium stores a computer program, and when the computer program is run by a processor, it executes the above-mentioned token code generation method or token code authentication method.
[0064] Compared with the prior art, the present application has the following advantages:
[0065] The present application provides a method for generating a token code, a method for authenticating a token code, and a system. The method for generating a token code includes: displaying a token page, where the token page includes an initial token and a token update control; in response to a trigger operation on the token update control, updating the initial token to a to-be-authenticated token; so that when the server receives an authentication request carrying the to-be-authenticated token and user information, a first token is generated according to the key information of the target user and the first authentication time; performing authentication processing on the to-be-authenticated token based on the first token, and when the to-be-authenticated token fails the authentication, obtaining a second authentication time that is a target duration later than the first authentication time according to the first authentication time; generating a second token based on the second authentication time and the key information; performing authentication processing on the to-be-authenticated token based on the second token; where the target user is the user indicated by the user information, the first authentication time is the time point when the authentication request is received or the generation time point of the authentication request; and the target duration is a preset token automatic refresh duration.
[0066] The method for generating a token code realizes the manual refresh of the token code by setting a token update control, which helps to relieve the anxiety of users during the process of waiting for the automatic refresh of the token code, and improves the user experience of the token code function of the target application. At the same time, in order to enable the token code after manual update to realize the original functions such as identity authentication and account login, the method for generating a token code makes corresponding settings for the token code verification mechanism of the server, so that when the to-be-authenticated token fails the verification of the first token generated based on the first authentication time, the server can update the first authentication time based on the preset token automatic refresh duration to obtain a second authentication time, and regenerate a second token for authenticating the to-be-authenticated token. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0068] Figure 1 It is a schematic structural diagram of the token code authentication system provided by the embodiment of the present application;
[0069] Figure 2 It is a flowchart of the method for generating a token code provided by the embodiment of the present application;
[0070] Figure 3 It is the first flowchart of token code generation provided by the embodiment of the present application;
[0071] Figure 4 The second token code generation flow chart provided by the embodiment of the present application;
[0072] Figure 5 The schematic diagram of the token page provided by the embodiment of the present application;
[0073] Figure 6 The update flow chart of the token code provided by the embodiment of the present application;
[0074] Figure 7 A time calibration flow chart provided by the embodiment of the present application;
[0075] Figure 8 A token code authentication method flow chart provided by the embodiment of the present application;
[0076] Figure 9 The token code authentication flow chart provided by the embodiment of the present application;
[0077] Figure 10 The schematic diagram of the structure of the token code generation device provided by the embodiment of the present application;
[0078] Figure 11 The schematic diagram of the structure of the token code authentication device provided by the embodiment of the present application;
[0079] Figure 12 The schematic diagram of the structure of the electronic device provided by the embodiment of the present application. Detailed implementation manners
[0080] With the development of the Internet, in order to maintain the security of the network environment, more and more places begin to use token codes to verify the identities of users. For example, when enterprises manage the accounts of users logging in to internal systems and the account security issues of the Internet, token codes are required.
[0081] In actual applications, the token code needs to be manually input by the user to complete account login, identity verification, etc. However, limited by the user's manual input of the token code, there will inevitably be situations where the same verification code is incorrectly input multiple times due to the user's misreading of the token code. At this time, if the user does not correct the misreading of the currently displayed token code, they need to wait for the token code to be automatically refreshed and then re-enter the new token code. It can be understood that since the user needs to wait for the refresh of the token code, the waiting process will inevitably result in a poor user experience of the token code function.
[0082] Therefore, how to solve the situation of poor user experience caused by the user waiting for the token code to be refreshed in the prior art has become a technical problem that needs to be urgently solved by those skilled in the art.
[0083] To solve the above technical problems, the present application proposes a method for generating a token code, a method for authenticating a token code, and a system. The present application also proposes a device for generating a token code, a device for authenticating a token code, as well as an electronic device and a storage medium.
[0084] Next, the technical solutions in the embodiments of the present application will be clearly and completely described with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0085] Exemplary System
[0086] To facilitate the understanding of the method for generating a token code and the method for authenticating a token code provided by the present application, the embodiments of the present application first introduce the authentication system for the token code in combination with a specific application scenario.
[0087] Please refer to Figure 1 , Figure 1 , which is a schematic structural diagram of the authentication system for the token code provided by the embodiments of the present application.
[0088] As Figure 1 shown, the authentication system for the token code includes: a target application 101, a server 102, and an authentication device 103.
[0089] The target application 101 refers to a software program running on a computer system or a mobile device, and this software program can generate a temporary and one-time token code to verify the identity of the user. In practical applications, the target application 101 can be installed on various user terminals such as a computer, a smart phone, a tablet computer, an Internet of Things device, and a portable wearable device.
[0090] In the embodiments of the present application, after the target application 101 is opened by the user, a token page will be displayed, and the token page includes an initial token and a token update control.
[0091] The authentication device 103 refers to a device that requires the input of user information and a token code for login. Among them, the user information can be understood as the account information required for the target user to log in to the authentication device 103, and the token code is the token code displayed by the target application 101.
[0092] In an application scenario of the present application, when the target user misidentifies the initial token code displayed by the target application 101 and cannot correct it, the target user can update the initial token to a token to be authenticated (i.e., a new token) by clicking the token update control displayed on the token page of the target application 101, so as to input the token to be authenticated in the authentication device 103.
[0093] For example, assume that the initial token is "123457". Due to subjective factors and inertial thinking, the target user may misidentify the initial token as "123456". In this case, the target user can click the token update control to update the initial token.
[0094] In another application scenario of the present application, when the user needs to log in to multiple authentication devices, but each token displayed in the target application can only be effective for one device. When the target user inputs the initial token into an authentication device and passes the authentication, the target user can update the initial token to a token to be authenticated by clicking the token update control displayed on the token page of the target application 101, so as to complete the login authentication of another authentication device through the token to be authenticated.
[0095] In another application scenario of the present application, assume that the refresh time of the token code is 30 seconds. After the target user opens the target application, the initial token still has 15 seconds to be refreshed, but the target user may not be able to complete the operation of inputting the initial token within 15 seconds. In this case, the target user can click the token update control to update the initial token, so as to obtain a token to be authenticated with the remaining refresh time of 30 seconds.
[0096] In an optional implementation manner of the present application, the initial token in the target application 101 is generated according to the key information of the target user and the second time. Specifically, the second time is the time corresponding to the operation of the target user clicking the icon of the target application. After the user clicks the token update control, the target application will postpone the first time to obtain a token generation time that is later than the first time by a target duration. Then, the target application 101 further generates the token to be authenticated based on the key information and the token generation time. Specifically, the first time is the time of the trigger operation of the user clicking the token update control, and the target duration is a preset automatic token refresh duration.
[0097] Server 102 can be understood as a server for user authentication and authorization. Server 102 can be composed of one or more Radius (Remote Authentication Dial-In User Service) servers to handle tasks such as user authentication and authorization. When the target user attempts to log in to the authentication device 103 by inputting user information and an authentication token generated by the target application, the authentication device 103 will send an authentication request for logging in to the authentication device to Server 102, where the authentication request carries the user information and the authentication token.
[0098] After receiving the authentication request for logging in to the authentication device, Server 102 will determine the key information corresponding to the target user according to the user information of the target user, and generate a first token according to the key information and the first authentication time; where the first authentication time can be the time point when Server 102 receives the authentication request or the generation time point of the authentication request. In this regard, this application does not make any restrictions.
[0099] Furthermore, after generating the first token, Server 102 will perform authentication processing on the authentication token based on the first token (that is, determine whether the first token is consistent with the authentication token input by the target user). In the case where the authentication token fails to pass the authentication, considering that during the process of the target user viewing the token through the target application 101, there is an operation of clicking the token update control of the target application to update the token, Server 102 will postpone the first authentication time to obtain a second authentication time that is later than the first authentication time by a target duration; and generate a second token based on the second authentication time and the key information, and perform authentication processing on the authentication token based on the second token.
[0100] In an alternative embodiment of this application, if the authentication token still fails to pass the authentication when using the second token for authentication, the upper limit of the number of manual refreshes of the token code (that is, the upper limit of the number of times of updating the token by clicking the token update control in the target application 101) can be considered to determine whether to continue using a similar method of generating the second token to further generate other tokens for authenticating the authentication token. If the upper limit of the number of manual refreshes of the token code is 2 times, then in the case where the second token fails to pass the authentication, a prompt message of authentication failure will be returned to the authentication device 103; if the preset number of token updates is greater than 2, continue to use a similar method of generating tokens to generate other tokens to authenticate the authentication token until the authentication is successful, or stop the authentication when the number of authentication times is equal to the upper limit of the number of manual refreshes of the token code.
[0101] In another alternative embodiment of the present application, when authenticating the token to be authenticated with the first token, if the token to be authenticated fails the authentication, multiple second tokens can also be generated at one time according to the upper limit number of times of manual refresh of the token code, and the token to be authenticated is authenticated with these multiple second tokens. That is, when any one of the multiple second tokens is consistent with the token to be authenticated, it is considered that the token to be authenticated passes the authentication.
[0102] Specifically, the multiple second tokens are generated in the following manner:
[0103] Based on the first authentication time, the target duration is increased by 1 to N times respectively to obtain N second authentication times; where N is the upper limit number of times of manual refresh of the token code; and second tokens corresponding to each second authentication time are generated respectively according to each second authentication time and the key information.
[0104] Exemplary Method 1
[0105] Furthermore, in order to facilitate understanding of the above token code authentication system provided by the embodiments of the present application, the token code authentication system will be introduced in detail below in combination with the token code generation method and the token code authentication method.
[0106] The embodiments of the present application first provide a method for generating a token code. This method is applied to the target application 101 in the above token code authentication system. The target application 101 can be an independent application software, or a lightweight application that can be opened through a certain independent application software, such as an H5 applet. Its implementation entity can be various types of user terminals such as a laptop computer, a tablet computer, a desktop computer, and a mobile device (for example, a mobile phone, a personal digital assistant, a dedicated messaging device).
[0107] Please refer to Figure 2 , Figure 2 which is the flowchart of the token code generation method provided by the embodiments of the present application.
[0108] As Figure 2 shown, the token code generation method includes the following steps S201 to step S202:
[0109] S201, display a token page, and the token page includes an initial token and a token update control.
[0110] The token page can be understood as an interface of the target application. Among them, the initial token can be understood as a token code displayed on the token page, and the token update control can be understood as a button on the token page. Users can interact with this button to update the initial token.
[0111] In the embodiments of the present application, the initial token can be automatically generated by the target application, or can be generated by the server 102 mentioned in the above system embodiments and sent to the target application, and then displayed through the token page of the target application (the servers involved in the method embodiments of the present application can all be understood as the server 102 mentioned in the above system embodiments).
[0112] Therefore, in an alternative embodiment of the present application, the token code can be generated by the target application. The display of the token page includes:
[0113] In response to a second trigger operation for the target application, determine the key information corresponding to the target user;
[0114] Generate the initial token according to the key information and the second time;
[0115] Display a token page including the initial token.
[0116] Among them, the key information corresponding to the target user is stored in the database of the target application; the second time is the response time point of the target application to the second trigger operation.
[0117] The second trigger operation can be understood as the operation of the target user opening the target application in the terminal device; or the operation of the target user inputting an account key and logging in to the target application in the target application; or the operation of the target user opening the token page in the target application.
[0118] It can be understood that the above introduction to the second trigger operation is only to understand the specific meaning of the second trigger operation in combination with specific application scenarios, rather than a limitation on the second trigger operation. In actual applications, the second trigger operation can be set according to the actual application of the target application, and the present application does not make any restrictions on this.
[0119] The key information can be understood as a set of strings or numbers set for the target user for the purpose of encryption, decryption, or verification. In the embodiments of the present application, the role of the key information is to ensure that the generated token code is trustworthy during the verification process, and only those with the correct key can generate a valid token code.
[0120] In practical applications, the key information may be the unique key information matched by the server for the target user when the target user first registers for an account of the target application; or it may be the unique key information matched for the target user based on the user's identity information (such as: employee number, name, etc.).
[0121] In practical applications, the key information may be stored in the target application, or may be sent by the server to the target application when a token code needs to be generated, or obtained by the user manually inputting a string corresponding to the key information, or the user obtains it by scanning a QR code containing the key information. In this regard, the present application does not make any restrictions.
[0122] After the target user opens the target application, the target application will generate and display the initial token in combination with the key information stored in itself corresponding to the target user and the second time.
[0123] In another alternative embodiment of the present application, considering the situation where the key information has not been stored in the target application when the target user first logs in to the target application, or the situation where the target application does not have the function of storing key information, the token display page can also be implemented in the following manner:
[0124] In response to a third trigger operation on the target application, send a key request to the server, where the key request carries the user information; so that when the server receives the key request, it determines the key information corresponding to the target user according to the user information;
[0125] Obtain the key information sent by the server; generate the initial token according to the key information and the third time;
[0126] Display a token page including the initial token; where the third time is the response time point of the target application to the third trigger operation or the time point when the target application receives the key information.
[0127] Similar to the second trigger operation, the third trigger operation can also be understood as the operation of the target user opening the target application in the terminal device; or the operation of the target user inputting an account key in the target application and logging in to the target application; or the operation of the target user opening the token page in the target application. The relevant parts can refer to the introduction of the second trigger operation above and will not be elaborated here.
[0128] After the user performs the third triggering operation, the target application sends a key request to the server. Then, the server determines the key information corresponding to the target user according to the user information carried in the key request, and returns the key information to the target application. After that, the target application combines the key information and the third time to generate an initial token, and returns the initial token to the server for display on the token page.
[0129] In the process of generating the token code, the purpose of combining the time information (such as the second time and the third time) and the key information is to limit the validity period of the token and increase the uniqueness of the token code.
[0130] In practical applications, the process of generating the token code according to the time information and the key information is specifically to use a hash algorithm to process the time information and the key information to obtain the token code.
[0131] To facilitate understanding of the interaction process between the above-mentioned target application and the server and the generation process of the token code, the following is combined with Figure 3 to explain it in detail.
[0132] Please refer to Figure 3 , Figure 3 which is the first token code generation flowchart provided by the embodiment of the present application.
[0133] As Figure 3 shown, Figure 3 it includes a target application 301 and a server 302;
[0134] The target application 301 responds to the third triggering operation for the target application and sends a key request to the server 302, and the key request carries the user information;
[0135] The server 302 receives the key request; determines the key information corresponding to the target user according to the user information; returns the key information to the target application;
[0136] The target application 301 receives the key information; generates an initial token according to the key information and the third time; displays a token page including the initial token.
[0137] In another alternative embodiment of the present application, the token can also be generated by the server and sent to the target application for the target application to display the token.
[0138] Taking the display of the initial token as an example, the display of the token page includes:
[0139] In response to a fifth trigger operation for the target application, send a token request to the server, where the token request carries the user information; so that when the server receives the token request, it determines the key information corresponding to the target user according to the user information, and generates an initial token according to the key information and the fourth time;
[0140] Obtain the initial token sent by the server;
[0141] Display a token page including the initial token, where the fourth time is the generation time of the token request or the response time of the fifth trigger operation.
[0142] Similar to the second trigger operation, the fifth trigger operation can also be understood as the operation of the target user opening the target application in the terminal device; or the operation of the target user inputting an account key and logging in to the target application in the target application; or the operation of the target user opening the token page in the target application. For the relevant parts, reference can be made to the introduction of the second trigger operation above and will not be elaborated here.
[0143] For the convenience of understanding the interaction process between the above-mentioned target application and the server and the generation process of the token code, the following will be combined with Figure 4 to elaborate on it in detail.
[0144] Please refer to Figure 4 , Figure 4 which is the second token code generation flow chart provided by the embodiment of the present application.
[0145] As Figure 4 shown, Figure 4 it includes a target application 401 and a server 402.
[0146] In response to a fifth trigger operation for the target application 402, the target application 401 sends a token request to the server, where the token request carries the user information;
[0147] After receiving the token request, the server 402 determines the key information corresponding to the target user according to the user information; and generates an initial token according to the key information and the fourth time, and sends the initial token to the target application.
[0148] The target application 401 receives the initial token and displays a token page including the initial token.
[0149] S202. In response to a trigger operation on the token update control, update the initial token to a token to be authenticated, so that when the server receives an authentication request carrying the token to be authenticated and user information, generate a first token according to the key information and the first authentication time of the target user, perform authentication processing on the token to be authenticated based on the first token, and when the token to be authenticated fails the authentication, obtain a second authentication time that is a target duration later than the first authentication time according to the first authentication time, generate a second token based on the second authentication time and the key information, and perform authentication processing on the token to be authenticated based on the second token; wherein, the target user is the user indicated by the user information, the first authentication time is the time point when the authentication request is received or the generation time point of the authentication request; the target duration is a preset token automatic refresh duration.
[0150] For the convenience of understanding the operation of updating the initial token through the token update control, please refer to Figure 5 , Figure 5 which is the schematic diagram of the token page provided by the embodiment of the present application.
[0151] As Figure 5 shown, the token page includes: an initial token 501 and a token update control 502.
[0152] In the actual application process, the target user can update the initial token 501 by clicking the token update control 502.
[0153] In an alternative embodiment of the present application, the generation of the token to be authenticated and the update of the initial token can be implemented by a target application. Specifically, the step of updating the initial token to a token to be authenticated in response to a trigger operation on the token update control includes:
[0154] In response to a first trigger operation on the token update control, obtain a first token generation time that is a target duration later than the first time according to the first time;
[0155] Generate the token to be authenticated according to the first token generation time and the key information; wherein, the first time is the response time of the target application to the first trigger operation.
[0156] The first trigger operation can be understood as the operation of the target user clicking the token update control 502.
[0157] In the actual application process, the validity period of each token code corresponds to the automatic refresh duration of the token code. After the token code is automatically refreshed, the original token code will become invalid. In this case, within the time range of the automatic refresh duration, the token codes generated by combining time and key information are all the same.
[0158] To achieve manual update of the token code, after the user performs the first trigger operation, a target duration can be added to the first time to obtain the token generation time. Then, using the token generation time and the key information, the to-be-authenticated token is generated, and the initial token is updated to the to-be-authenticated token.
[0159] In another alternative embodiment of the present application, the generation process of the to-be-authenticated token can be implemented by the server. Specifically, the updating the initial token to the to-be-authenticated token in response to the trigger operation for the token update control includes:
[0160] In response to the first trigger operation for the token update control, a token update request is sent to the server; so that when the server receives the token update request, according to the fifth time, a second token generation time that is later than the fifth time by the target duration is obtained; according to the second token generation time and the key information, a to-be-authenticated token is generated;
[0161] Receive the to-be-authenticated token sent by the server, and update the initial token to the to-be-authenticated token;
[0162] Wherein, the fifth time is the time when the server receives the token update request, or the generation time of the token update request.
[0163] In an alternative embodiment of the present application, the token update request carries the user information of the target user, so that the server can obtain the key information corresponding to the target user based on the user information.
[0164] Further, please refer to Figure 6 , Figure 6 which is the update flowchart of the token code provided by the embodiment of the present application.
[0165] As Figure 6 described, Figure 6 it includes the target application 601 and the server 602.
[0166] The target application 601, in response to the trigger operation for the token update control, sends a token update request to the server 602;
[0167] The server 602 receives the token update request, obtains a second token generation time that is a target duration later than the fifth time according to the fifth time, generates a token to be authenticated according to the second token generation time and the key information, and sends the token to be authenticated to the target application;
[0168] The target application 601 receives the token to be authenticated and updates the initial token to the token to be authenticated.
[0169] In another alternative embodiment of the present application, considering the security of the token code displayed in the target application, the identity information of the user can also be authenticated before the token page has been in an inactive state for a long time and / or before the token page is displayed.
[0170] Specifically, the displaying of the token page includes:
[0171] Displaying an identity authentication interface for authenticating the user's identity;
[0172] Obtaining first identity authentication information input by the user on the identity authentication interface;
[0173] Determining whether the first identity authentication information is consistent with preset second identity authentication information; wherein the second identity authentication information corresponds to the target user
[0174] When the first identity authentication information is consistent with the second identity authentication information, displaying the token page;
[0175] When the first identity authentication information is inconsistent with the second identity authentication information, displaying a prompt message indicating an identity authentication error.
[0176] Among them, the identity authentication interface can be understood as an interface that identifies information such as the user's fingerprint, gesture, face, etc.
[0177] The first identity authentication information can be understood as information such as the fingerprint, gesture input by the user on the identity authentication interface, or the face image scanned through the scanning function of the identity authentication interface, etc., which can be used to identify the identity of the target user.
[0178] The second identity authentication information can then be understood as the fingerprint, gesture or face image pre-input by the user when registering the account of the target application or enabling the identity authentication function to indicate their own identity.
[0179] In another alternative embodiment of the present application, considering that the server will need to generate a token code and the server needs to verify the token code input to the authentication device, therefore, the time of the server needs to be consistent with the time of the target application.
[0180] In order to timely correct the time in the target application when there is a deviation in the time in the target application, the token page further includes: a time calibration control.
[0181] Please refer to Figure 5 , Figure 5 which also includes: a time calibration control 503.
[0182] The method further includes:
[0183] In response to a fourth trigger operation on the time calibration control 503, sending a time calibration request carrying the first current time of the target application to the server; so that when the server receives the time calibration request, it determines whether the second current time of the server is consistent with the first current time of the target application; when the second current time is inconsistent with the first current time, determining the time difference between the first current time and the second current time, and sending the time difference to the target application;
[0184] Receiving the time difference returned by the server, and calibrating the time of the target application according to the time difference.
[0185] Further, when the second current time is inconsistent with the first current time, the time difference between the first current time and the second current time can be based on subtracting the second current time from the first current time. When the time difference is negative, it indicates that the time of the target application is slower. After the target application receives the time difference, it can adjust the time forward based on the time difference. When the time difference is positive, it indicates that the time of the target application is faster. After the target application receives the time difference, it can adjust the time backward based on the time difference.
[0186] To facilitate understanding of the above time calibration process, the following introduces it in combination with the interaction between the target application and the server.
[0187] Please refer to Figure 7 , Figure 7 which is a time calibration flowchart provided by an embodiment of the present application.
[0188] As Figure 7 shown, Figure 7 it includes a target application 701 and a server 702.
[0189] The target application 701, in response to a fourth trigger operation on the time calibration control, sends a time calibration request carrying the first current time of the target application to the server 702.
[0190] The fourth triggering operation can be understood as the triggering action of the user clicking the time calibration control. That is, in the actual application process, after the time calibration control in the target application 701 is clicked by the user, the target application 701 sends a time calibration request carrying the first current time of the target application to the server 702. In another alternative embodiment of the present application, in order to prevent the user from ignoring the problem that the time of the target application 701 is inconsistent with that of the server 702 and the user forgets to click the time calibration control, resulting in the token code finally displayed by the target application 701 being unable to pass the verification, after the target application 701 displays the token page, the fourth triggering operation automatically sends a time calibration request to the server 702 by the target application 701.
[0191] After receiving the time calibration request, the server 702 determines whether the first current time is consistent with the second current time of the server 702; and in the case of inconsistency, determines the time difference between the first current time and the second current time, and returns the time difference to the target application.
[0192] The target application 702 calibrates the time of the target application according to the time difference.
[0193] Furthermore, after the target application completes time calibration, it is also necessary to update the token code on its token page to ensure the correspondence between the token code and the time.
[0194] Specifically, the method further includes:
[0195] Generating a third token according to the calibrated first current time and the key information;
[0196] Updating the initial token to the third token.
[0197] It can be understood that in the embodiments of the present application, the generation process of the third token can also be implemented by the server. That is, when the server determines that the first current time is inconsistent with the second current time, the server generates the third token based on the second current time and the key information, and returns the time difference and the third token to the target application together for the target application to complete time calibration and update the token code.
[0198] In an alternative embodiment of the present application, during the online generation of the token code, considering that network latency may cause the token code displayed on the token page to expire quickly, and the user may not be able to input the token code in the authentication device that needs to be authenticated in time. Therefore, in an alternative embodiment of the present application, the method further includes the following steps S1 to S3:
[0199] Step S1, obtain the network latency;
[0200] The network latency can be understood as the time difference between a first time point and a second time point. Among them, in the case where the token code is generated by the server, the first time point can be understood as the time point when the server receives the key request (i.e., the third time); the second time point can be understood as the time point when the target application receives the token code generated by the server and displays the token code.
[0201] Step S2, when the network latency is greater than a first preset latency, generate a first refresh gain value according to the latency difference between the network latency and the first preset latency; the latency difference is positively correlated with the first refresh gain value;
[0202] The first preset latency can be understood as a latency threshold set based on the time length for the user to input the token code in the authentication device that needs to be authenticated, so as to ensure that the user still has sufficient time to complete the input of the token code in the case of network latency. In an alternative embodiment of the present application, the first preset latency is less than the target duration (i.e., the time length of the first preset latency is less than the time length for the target application to automatically refresh the token code), and the first preset latency can be half or one-fourth of the target duration. In this regard, the present application does not make any restrictions.
[0203] Furthermore, when the network latency is greater than the first preset latency, it means that before the token code displayed on the token page is automatically refreshed, the user may not be able to complete the input of the token code into the device that needs to be authenticated. In this case, the target application will automatically extend the refresh time of the token code, and the user can complete the input of the token code in the authentication device.
[0204] The first refresh gain value can be understood as the extended time for the refresh time of the token code.
[0205] For example, assume that the time of the network latency is 10 seconds and the time of the first preset latency is 8 seconds. Then, according to the latency difference between the network latency and the first preset latency, the generated first refresh gain value is 2n seconds, where n is a positive number greater than 1.
[0206] Step S3: Obtain a new target duration based on the first brush additional gain value and the target duration, and update the tokens displayed on the token page based on the new target duration.
[0207] That is, on the basis of the target duration, add the first brush additional gain value as the new token code refresh duration in the target application program, so as to avoid the problem that due to network latency, the user cannot enter the token code in time in the authentication device that needs authentication.
[0208] Furthermore, in order to ensure that the token code entered by the user can pass the server authentication, in the embodiment of the present application, when the target application program updates the target duration to a new target duration based on the network latency, the target application program also needs to send the new target duration to the server, so that the server dynamically adjusts the token for authenticating the to-be-authenticated token at the server end.
[0209] Correspondingly, in the case of network latency and during the process that the server authenticates the to-be-authenticated token based on the first token, if the to-be-authenticated token fails the authentication, the server needs to obtain a fourth authentication time that is later than the first authentication time and is the new target duration based on the first authentication time; and generate a fourth token based on the fourth authentication time and the key information; and authenticate the to-be-authenticated token based on the fourth token.
[0210] It should be noted that the content done by the server in the case of the above network latency is basically the same as the content done by the server in step S202, except that the target duration in step S202 is modified to the new target duration. For the relevant parts, refer to the introduction of step S202 above and will not be elaborated here.
[0211] Exemplary Method 2
[0212] When updating the token code on the token page by clicking the token update control, it is also necessary to ensure that the updated token code can pass the server authentication.
[0213] In order to enable the updated token code to be verified and passed, the embodiment of the present application also involves a method for authenticating the token code.
[0214] The implementation entity of this method is the server mentioned in the above system embodiment and method embodiment.
[0215] Please refer to Figure 8 , Figure 8 which is a flowchart of a method for authenticating a token code provided by an embodiment of the present application.
[0216] As Figure 8As shown, the authentication method of the token code includes the following steps S801 to S805:
[0217] S801, receiving an authentication request for logging in to the authentication device, where the authentication request carries user information and a token to be authenticated.
[0218] The authentication request of the login authentication device can be understood as a request for the user to log in to the authentication device. When the user logs in to the authentication device, the user needs to enter the user information required for logging in to the authentication device (such as, work number, login account of the authentication device, etc.) and the token code displayed in the target application on the login page of the authentication device, and after clicking the "Login" control on the login page, send an authentication request carrying the user information and the token to be authenticated to the server for the server to confirm whether the token to be authenticated is correct.
[0219] S802, generating a first token based on the key information of the target user and the first authentication time; where the target user is the user indicated by the user information, and the first authentication time is the time point when the authentication request is received or the generation time point of the authentication request.
[0220] After the server receives the authentication request, the server will first determine the key information corresponding to the target user according to the user information, so that the target user can generate a first token based on the key information and the first authentication time.
[0221] S803, performing authentication processing on the token to be authenticated based on the first token, and in the case where the token to be authenticated fails the authentication, obtaining a second authentication time that is a target duration later than the first authentication time according to the first authentication time; where the target duration is a preset token automatic refresh duration.
[0222] In the process of implementation, the authentication of the token to be authenticated based on the first token means comparing whether the token to be authenticated is the same as the first token.
[0223] It can be understood that in the case where the token to be authenticated is the initial token, that is, after the target application displays the initial token and the target user does not click the token update control to update the initial token, based on the token automatic refresh mechanism that the token codes generated at different times within the valid time of the token code are the same, the first token and the token to be authenticated should be the same.
[0224] However, if the authentication - pending token is obtained by updating the initial token by triggering the token update control, since the generation time of the authentication - pending token is later than the token generation time of the first - time target time (where the first time is the time point when the target application responds to the trigger of the token update control), and this time is not within the valid time of the initial token code, the first token is not consistent with the authentication - pending token.
[0225] In this case, it is necessary to adjust the first token. That is, when the authentication - pending token fails the authentication, according to the first authentication time, obtain a second authentication time that is a target duration later than the first authentication time, and perform the following steps S804 and S805.
[0226] S804, generate a second token according to the key information and the second authentication time.
[0227] S805, perform an authentication process on the authentication - pending token based on the second token.
[0228] In an alternative embodiment of the present application, considering that the target user may trigger the token update control multiple times within a short period, if the step of authenticating the authentication - pending token based on the second token still fails, the method similar to steps S803 to S805 above can be continued to generate other tokens to authenticate the authentication - pending token until the number of authentication attempts is equal to the upper limit of the manual refresh of the token code, or the authentication is passed before the upper limit of the manual refresh of the token code is reached.
[0229] For example, assume that the upper limit of the manual refresh of the token code is 3. If the authentication of the authentication - pending token by the first token fails, the server adds the target time to the first authentication time to obtain the second authentication time; generates a second token according to the second authentication time and the key information; and performs a second authentication on the authentication - pending token by the second token. If the second authentication is passed, a successful authentication prompt message is returned to the authentication device;
[0230] If the second authentication fails, the server adds the target time to the second authentication time to obtain the third authentication time; generates token 3 according to the third authentication time and the key information; and performs a third authentication on the authentication - pending token by token 3. If the third authentication is passed, a successful authentication prompt message is returned to the authentication device; if the third authentication fails, a failed authentication prompt message is returned to the server.
[0231] In another alternative embodiment of the present application, when authenticating the token to be authenticated with the first token, if the token to be authenticated fails the authentication, multiple second tokens can also be generated at one time according to the upper limit number of times of manual refresh of the token code, and the token to be authenticated is authenticated with these multiple second tokens. That is, if any one of the multiple second tokens is consistent with the token to be authenticated, it is considered that the token to be authenticated passes the authentication.
[0232] Specifically, the multiple second tokens are generated in the following manner:
[0233] Based on the first authentication time, the target duration is increased by 1 to N times respectively to obtain N second authentication times; where N is the upper limit number of times of manual refresh of the token code; and second tokens corresponding to each second authentication time are generated respectively according to each second authentication time and the key information.
[0234] For example, assuming that the upper limit number of times of manual refresh of the token code is 3, if the authentication of the token to be authenticated with the first token fails, the server can increase the first authentication time by 1 time, 2 times, and 3 times respectively to obtain authentication time a, authentication time b, and authentication time c; and generate token a according to authentication time a and the key information; generate token b according to authentication time b and the key information; generate token c according to authentication time c and the key information; and at the same time, determine whether any one of tokens a, b, and c is consistent with the token to be authenticated; if so, it means that the token to be authenticated passes the authentication, and if not, it means that the token to be authenticated fails the authentication.
[0235] To facilitate understanding of the above authentication process of the token code, the following is combined with Figure 9 to introduce this process in detail.
[0236] Please refer to Figure 9 , Figure 9 which is the token code authentication flow chart provided by the embodiment of the present application.
[0237] As Figure 9 shown, Figure 9 it includes an authentication device 901 and a server 902;
[0238] After the target user inputs the token to be authenticated and user information, in response to the user's login trigger operation, the authentication device 901 sends an authentication request for logging in to the authentication device to the server 902, and the authentication request carries the user information and the token to be authenticated;
[0239] Server 902 receives an authentication request from a login authentication device; determines key information corresponding to the target user according to the user information; generates a first token according to the key information of the target user and the first authentication time; performs authentication processing on the token to be authenticated based on the first token, and when the token to be authenticated fails the authentication, obtains a second authentication time that is a target duration later than the first authentication time according to the first authentication time; generates a second token according to the key information and the second authentication time; and performs authentication processing on the token to be authenticated based on the second token.
[0240] In an alternative embodiment of the present application, the server is further capable of receiving a key request sent by a target application and returning the key information corresponding to the target user to the target application.
[0241] Specifically, the method further includes:
[0242] Receiving a key request sent by a target application, where the key request carries the user information;
[0243] Determining key information corresponding to the target user according to the user information, and sending the key information to the target application; so that the target application generates an initial token according to the key information and a third time, and displays a token page including the initial token and a token update control.
[0244] Wherein, the target application is used to send the key request to the server in response to a third trigger operation on the target application; the third time is the response time point of the target application to the third trigger operation or the time point when the target application receives the key information.
[0245] In an alternative embodiment of the present application, the server is further capable of receiving a time calibration request sent by the target application to assist the target application in calibrating the time.
[0246] Specifically, the method further includes:
[0247] Receiving a time calibration request sent by a target application, where the time calibration request carries the first current time of the target application;
[0248] Judging whether the second current time of the server is consistent with the first current time of the target application;
[0249] In the case where the second current time is inconsistent with the first current time, determine the time difference between the first current time and the second current time, and send the time difference to the target application; so that the target application calibrates the time of the target application according to the time difference.
[0250] It should be noted that the process of the above server receiving the key request and returning the key information to the target application, and the process of the server receiving the time calibration request to help the target application calibrate the time are basically the same as the processes of obtaining the key information of the target application and time calibration mentioned in Embodiment 1 of the method of the present application. In addition, the server in Embodiment 2 of the method of the present application is basically related to the server provided in Embodiment 1 of the method. For the related parts, refer to the relevant introduction in Embodiment 1 of the method, and details are not described here again.
[0251] In an optional implementation manner of the present application, in the case of network delay and the target application updates the token displayed on the token page based on the steps S1 to S3 mentioned above, in order to ensure that the token refreshed by the user by clicking the token update control can still pass the authentication, the method further includes:
[0252] Obtain a new target duration;
[0253] During the process of authenticating the token to be authenticated based on the first token, in the case where the token to be authenticated fails to pass the authentication, the server needs to obtain a fourth authentication time that is later than the first authentication time according to the first authentication time and the new target duration.
[0254] Generate a fourth token based on the fourth authentication time and the key information;
[0255] Authenticate the token to be authenticated based on the fourth token. It should be noted that the process of the above server generating the fourth token based on the new target duration is basically the same as the server described in steps S1 to S3 in Embodiment 1 of the method of the present application. For the related parts, refer to the introduction in Embodiment 1 of the method, and details are not described here again.
[0256] Based on the above authentication system for the token code, the method for generating the token code, and the method for authenticating the token code, it can be seen that in this application, the manual refresh of the token code is achieved by setting a token update control, which helps to alleviate the anxiety of users during the process of waiting for the automatic refresh of the token code, improves the user experience of the token code function of the target application. At the same time, in order to enable the token code after manual update to implement the original functions such as identity authentication and account login, the method for generating the token code makes corresponding settings for the token code verification mechanism of the server, so that when the token to be authenticated fails to pass the verification of the first token generated based on the first authentication time, the server can update the first authentication time based on the preset token automatic refresh duration to obtain a second authentication time, and regenerate a second token for authenticating the token to be authenticated.
[0257] Exemplary Device 1
[0258] Similar to the above method for generating the token code, this application also provides a device for generating the token code. Please refer to Figure 10 , Figure 10 which is a schematic structural diagram of the device for generating the token code provided by the embodiment of this application.
[0259] As Figure 10 shown, the device for generating the token code is applied to a target application and includes:
[0260] A display unit 1001, configured to display a token page, where the token page includes an initial token and a token update control;
[0261] An update unit 1002, configured to, in response to a trigger operation on the token update control, update the initial token to a token to be authenticated; so that when the server receives an authentication request carrying the token to be authenticated and user information, generate a first token according to the key information and the first authentication time of the target user; perform an authentication process on the token to be authenticated based on the first token, and when the token to be authenticated fails to pass the authentication, obtain a second authentication time that is a target duration later than the first authentication time according to the first authentication time; generate a second token based on the second authentication time and the key information; and perform an authentication process on the token to be authenticated based on the second token;
[0262] wherein, the target user is the user indicated by the user information, and the first authentication time is the time point when the authentication request is received or the generation time point of the authentication request; the target duration is the preset token automatic refresh duration.
[0263] In an alternative embodiment of the present application, the updating of the initial token to a token to be authenticated in response to a triggering operation on the token update control includes:
[0264] In response to a first triggering operation on the token update control, obtaining a token generation time that is a target duration later than the first time according to the first time;
[0265] Generating the token to be authenticated according to the token generation time and the key information, and updating the initial token to the token to be authenticated;
[0266] Wherein, the first time is the response time point of the target application to the first triggering operation.
[0267] In an alternative embodiment of the present application, the displaying of the token page includes:
[0268] In response to a second triggering operation on the target application, determining the key information corresponding to the target user; generating the initial token according to the key information and the second time; displaying a token page including the initial token; wherein, the key information corresponding to the target user is stored in the database of the target application; the second time is the response time point of the target application to the second triggering operation;
[0269] Or,
[0270] In response to a third triggering operation on the target application, sending a key request to the server, the key request carrying the user information; so that the server, in case of receiving the key request, determines the key information corresponding to the target user according to the user information; obtaining the key information sent by the server; generating the initial token according to the key information and the third time; displaying a token page including the initial token; wherein, the third time is the response time point of the target application to the third triggering operation or the time point when the target application receives the key information.
[0271] In an alternative embodiment of the present application, the displaying of the token page includes:
[0272] Displaying an identity authentication interface for authenticating the user identity;
[0273] Obtaining first identity authentication information input by the user on the identity authentication interface;
[0274] Judging whether the first identity authentication information is consistent with the second identity authentication information preset by the target user;
[0275] When the first identity authentication information is consistent with the second identity authentication information, display the token page;
[0276] When the first identity authentication information is inconsistent with the second identity authentication information, display a prompt message indicating an identity authentication error.
[0277] In an alternative embodiment of the present application, the token page further includes: a time calibration control;
[0278] The device is further configured to:
[0279] In response to a fourth trigger operation on the time calibration control, send a time calibration request carrying the first current time of the target application to the server; so that when the server receives the time calibration request, it determines whether the second current time of the server is consistent with the first current time of the target application; when the second current time is inconsistent with the first current time, determine the time difference between the first current time and the second current time, and send the time difference to the target application;
[0280] Receive the time difference returned by the server, and calibrate the time of the target application according to the time difference.
[0281] In an alternative embodiment of the present application, the device is further configured to:
[0282] Generate a third token according to the calibrated first current time and the key information;
[0283] Update the initial token to the third token.
[0284] Exemplary Device 2
[0285] Similar to the above token code authentication method, the present application also provides a token code authentication device, please refer to Figure 11 , Figure 11 which is a schematic structural diagram of the token code authentication device provided by the embodiments of the present application.
[0286] As Figure 11 shown, the token code authentication device includes:
[0287] A receiving unit 1101, configured to receive an authentication request from a login authentication device, where the authentication request carries user information and a token to be authenticated;
[0288] The first generation unit 1102 is configured to generate a first token according to the key information of the target user and the first authentication time; wherein, the target user is the user indicated by the user information, and the first authentication time is the time point when the authentication request is received or the generation time point of the authentication request;
[0289] The first authentication unit 1103 is configured to perform authentication processing on the token to be authenticated based on the first token, and obtain a second authentication time that is a target duration later than the first authentication time according to the first authentication time when the token to be authenticated fails the authentication; wherein, the target duration is a preset token automatic refresh duration;
[0290] The second generation unit 1104 is configured to generate a second token according to the key information and the second authentication time;
[0291] The second authentication unit 1105 is configured to perform authentication processing on the token to be authenticated based on the second token.
[0292] In an alternative embodiment of the present application, the generating the first token according to the key information of the target user and the first authentication time includes:
[0293] Determine the key information corresponding to the target user according to the user information;
[0294] Generate the first token according to the key information and the first authentication time.
[0295] In an alternative embodiment of the present application, the generating the second token according to the key information and the second authentication time includes:
[0296] On the basis of the first authentication time, add the target duration 1 to N times respectively to obtain N second authentication times; wherein, N is the upper limit number of times for manual refresh of the token code;
[0297] Generate second tokens corresponding to each of the second authentication times one by one according to each of the second authentication times and the key information.
[0298] In an alternative embodiment of the present application, the device is further configured to:
[0299] Receive a key request sent by a target application, where the key request carries the user information;
[0300] Determine the key information corresponding to the target user according to the user information, and send the key information to the target application; so that the target application generates an initial token according to the key information and a third time, and displays a token page including the initial token and a token update control;
[0301] Wherein, the target application is used to send the key request to the server in response to a third trigger operation for the target application; the third time is the time point when the target application performs the third trigger operation or the time point when the target application receives the key information.
[0302] In an alternative embodiment of the present application, the device is further configured to:
[0303] Receive a time calibration request sent by a target application, where the time calibration request carries a first current time of the target application;
[0304] Determine whether the second current time of the server is consistent with the first current time of the target application;
[0305] In the case where the second current time is inconsistent with the first current time, determine the time difference between the first current time and the second current time, and send the time difference to the target application; so that the target application calibrates the time of the target application according to the time difference.
[0306] This embodiment provides a token code generation device and a token code authentication device, which belong to the same inventive concept as the token code generation method and the token code authentication method provided in the above embodiments of the present application, and can execute the token code generation method and the token code authentication method provided in any of the above embodiments of the present application, and have corresponding functional modules and beneficial effects for executing the token code generation method and the token code authentication method. For technical details not described in detail in this embodiment, reference may be made to the specific processing content of the token code generation method and the token code authentication method provided in the above embodiments of the present application, which will not be elaborated here.
[0307] It should be understood that the units in the above device can be implemented in the form of a processor calling software. For example, the device includes a processor, the processor is connected to a memory, instructions are stored in the memory, and the processor calls the instructions stored in the memory to implement any of the above methods or the functions of each unit of the device. The processor can be a general-purpose processor, such as a CPU or a microprocessor, etc., and the memory can be a memory inside the device or a memory outside the device. Alternatively, the units in the device can be implemented in the form of hardware circuits. By designing the hardware circuits, the functions of some or all of the units can be realized. The hardware circuits can be understood as one or more processors. For example, in one implementation, the hardware circuit is an ASIC, and through the design of the logical relationship of the components in the circuit, the functions of some or all of the above units are realized. Again, for example, in another implementation, the hardware circuit can be implemented through a PLD. Taking FPGA as an example, it can include a large number of logic gate circuits, and the connection relationship between the logic gate circuits is configured through a configuration file, so as to realize the functions of some or all of the above units. All the units of the above device can be all implemented in the form of a processor calling software, or all implemented in the form of hardware circuits, or part implemented in the form of a processor calling software, and the remaining part implemented in the form of hardware circuits.
[0308] In the embodiments of the present application, a processor is a circuit with the ability to process signals. In one implementation, the processor can be a circuit with the ability to read and execute instructions, such as a CPU, a microprocessor, a GPU, or a DSP, etc. In another implementation, the processor can realize certain functions through the logical relationship of hardware circuits, and the logical relationship of the hardware circuits is fixed or can be reconfigured. For example, the processor is a hardware circuit implemented by an ASIC or a PLD, such as an FPGA, etc. In a reconfigurable hardware circuit, the process of the processor loading a configuration document to realize the configuration of the hardware circuit can be understood as the process of the processor loading instructions to realize the functions of some or all of the above units. In addition, it can also be a hardware circuit designed for artificial intelligence, which can be understood as a type of ASIC, such as an NPU, a TPU, a DPU, etc.
[0309] It can be seen that each unit in the above device can be one or more processors (or processing circuits) configured to implement the above methods, such as: CPU, GPU, NPU, TPU, DPU, microprocessor, DSP, ASIC, FPGA, or a combination of at least two of these processor forms.
[0310] In addition, all or part of the units in the above device can be integrated together or can be implemented independently. In one implementation, these units are integrated together and implemented in the form of an SOC. The SOC may include at least one processor for implementing any of the above methods or implementing the functions of each unit of the device. The types of the at least one processor can be different, for example, including a CPU and an FPGA, a CPU and an artificial intelligence processor, a CPU and a GPU, etc.
[0311] Exemplary Electronic Device
[0312] Another embodiment of this application also proposes an electronic device. Please refer to Figure 12 , Figure 12 , which is a schematic structural diagram of the electronic device provided by the embodiment of this application.
[0313] As Figure 12 shown, the electronic device includes:
[0314] a memory 200 and a processor 210;
[0315] Among them, the memory 200 is connected to the processor 210 and is used to store programs;
[0316] The processor 210 is used to implement the method for generating a token code and the method for authenticating a token code disclosed in any of the above embodiments by running the program stored in the memory 200.
[0317] Specifically, the above electronic device may further include: a bus, a communication interface 220, an input device 230, and an output device 240.
[0318] The processor 210, the memory 200, the communication interface 220, the input device 230, and the output device 240 are interconnected through the bus. Among them:
[0319] The bus may include a path for transmitting information between various components of the computer system.
[0320] The processor 210 may be a general-purpose processor, such as a general-purpose central processing unit (CPU), a microprocessor, etc., or may be an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the solution of the present invention. It may also be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0321] The processor 210 may include a main processor and may also include a baseband chip, a modem, etc.
[0322] The memory 200 stores a program for implementing the technical solution of the present invention, and may also store an operating system and other critical services. Specifically, the program may include program code, and the program code includes computer operation instructions. More specifically, the memory 200 may include a read-only memory (ROM), other types of static storage devices that can store static information and instructions, a random access memory (RAM), other types of dynamic storage devices that can store information and instructions, a disk memory, a flash memory, and so on.
[0323] The input device 230 may include devices for receiving data and information input by a user, such as a keyboard, a mouse, a camera, a scanner, a light pen, a voice input device, a touch screen, a pedometer, or a gravity sensor, etc.
[0324] The output device 240 may include devices for allowing information to be output to a user, such as a display screen, a printer, a speaker, etc.
[0325] The communication interface 220 may include devices of any transceiver type for communicating with other devices or communication networks, such as Ethernet, a radio access network (RAN), a wireless local area network (WLAN), etc.
[0326] The processor 210 executes the program stored in the memory 200 and calls other devices, and can be used to implement each step of any one of the token code generation method and the token code authentication method provided in the above embodiments of the present application.
[0327] Exemplary Computer Program Product and Storage Medium
[0328] In addition to the above methods and devices, an embodiment of the present application may also be a computer program product, which includes computer program instructions. When the computer program instructions are run by a processor, the processor is caused to execute the steps in the token code generation method and the token code authentication method according to various embodiments of the present application described in the "Exemplary Method" section of the present specification.
[0329] The computer program product may be written in any combination of one or more programming languages for programming code to perform the operations of the embodiments of the present application. The programming languages include object-oriented programming languages, such as Java, C++, etc., and also include conventional procedural programming languages, such as the "C" language or similar programming languages. The program code may be executed entirely on a user computing device, partially on a user device, executed as a stand-alone software package, partially on a user computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0330] In addition, an embodiment of the present application may also be a storage medium storing a computer program, and the computer program is executed by a processor to perform the steps in the method for generating a token code and the method for authenticating a token code according to various embodiments of the present application described in the above "Exemplary Method" section of this specification.
[0331] For the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present application is not limited by the described action sequence, because according to the present application, certain steps may be in other sequences or performed simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present application.
[0332] It should be noted that the embodiments in this specification are all described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For device embodiments, since they are basically similar to the method embodiments, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiments.
[0333] The steps in the methods of the embodiments of the present application can be adjusted, combined, and deleted according to actual needs, and the technical features recorded in each embodiment can be replaced or combined.
[0334] The modules and sub-modules in the devices and terminals in the embodiments of the present application can be combined, divided, and deleted according to actual needs.
[0335] In several embodiments provided by the present application, it should be understood that the disclosed terminals, devices, and methods can be implemented in other ways. For example, the terminal embodiments described above are only illustrative. For example, the division of modules or sub-modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple sub-modules or modules can be combined or integrated into another module, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of devices or modules can be in an electrical, mechanical, or other form.
[0336] The modules or sub-modules described as separate components may or may not be physically separated. The components as modules or sub-modules may or may not be physical modules or sub-modules, that is, they can be located in one place, or distributed to multiple network modules or sub-modules. Some or all of the modules or sub-modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0337] In addition, each functional module or sub-module in each embodiment of the present application may be integrated into a processing module, or each module or sub-module may exist physically alone, or two or more modules or sub-modules may be integrated into one module. The above-mentioned integrated modules or sub-modules may be implemented in the form of hardware, or may be implemented in the form of software functional modules or sub-modules.
[0338] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0339] The steps of the method or algorithm described in combination with the embodiments disclosed herein can be directly implemented by hardware, a software unit executed by a processor, or a combination of the two. The software unit can be placed in a random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, register, hard disk, removable disk, CD-ROM, or any other form of storage medium well-known in the technical field.
[0340] Finally, it should also be noted that in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
[0341] The foregoing description of the disclosed embodiments enables those skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Thus, the present application is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for generating a token code, characterized in that, Applied to a target application, including: Display a token page, where the token page includes an initial token and a token update control; In response to a trigger operation on the token update control, update the initial token to a token to be authenticated; so that when the server receives an authentication request carrying the token to be authenticated and user information, generate a first token according to the key information of the target user and the first authentication time; perform authentication processing on the token to be authenticated based on the first token, and when the token to be authenticated fails the authentication, obtain a second authentication time that is a target duration later than the first authentication time according to the first authentication time; generate a second token based on the second authentication time and the key information; perform authentication processing on the token to be authenticated based on the second token; Wherein, the target user is the user indicated by the user information, and the first authentication time is the time point when the authentication request is received or the generation time point of the authentication request; the target duration is a preset token automatic refresh duration.
2. The method according to claim 1, wherein The step of updating the initial token to a token to be authenticated in response to a trigger operation on the token update control includes: In response to a first trigger operation on the token update control, obtain a token generation time that is a target duration later than the first time according to the first time; Generate the token to be authenticated according to the token generation time and the key information, and update the initial token to the token to be authenticated; Wherein, the first time is the response time point of the target application to the first trigger operation.
3. The method according to claim 1, wherein The step of displaying the token page includes: In response to a second trigger operation on the target application, determine the key information corresponding to the target user; generate the initial token according to the key information and the second time; display a token page including the initial token; wherein, the key information corresponding to the target user is stored in the database of the target application; the second time is the response time point of the target application to the second trigger operation; Or, In response to a third trigger operation on the target application, send a key request to the server, where the key request carries the user information; so that when the server receives the key request, determine the key information corresponding to the target user according to the user information; obtain the key information sent by the server; generate the initial token according to the key information and the third time; display a token page including the initial token; wherein, the third time is the response time point of the target application to the third trigger operation or the time point when the target application receives the key information.
4. The method according to claim 1, wherein The step of displaying the token page includes: Display an identity authentication interface for authenticating the user's identity; Obtain the first identity authentication information input by the user on the identity authentication interface; Judge whether the first identity authentication information is consistent with the preset second identity authentication information; wherein, the second identity authentication information corresponds to the target user. When the first authentication information is consistent with the second authentication information, display the token page; When the first authentication information is inconsistent with the second authentication information, display a prompt message indicating an authentication error.
5. The method according to claim 1, wherein The token page further includes: a time calibration control; The method further includes: In response to a fourth trigger operation on the time calibration control, send a time calibration request carrying the first current time of the target application to the server; so that when the server receives the time calibration request, determine whether the second current time of the server is consistent with the first current time of the target application; when the second current time is inconsistent with the first current time, determine the time difference between the first current time and the second current time, and send the time difference to the target application; Receive the time difference returned by the server, and calibrate the time of the target application according to the time difference.
6. The method according to claim 5, wherein It further includes: Generate a third token according to the calibrated first current time and the key information; Update the initial token to the third token.
7. A method for authenticating a token code, characterized in that, Applied to a server, it includes: Receive an authentication request from a login authentication device, where the authentication request carries user information and a token to be authenticated; Generate a first token according to the key information and the first authentication time of the target user; where the target user is the user indicated by the user information, and the first authentication time is the time point when the authentication request is received or the generation time point of the authentication request; Perform an authentication process on the token to be authenticated based on the first token, and when the token to be authenticated fails the authentication, obtain a second authentication time that is a target duration later than the first authentication time according to the first authentication time; where the target duration is a preset token automatic refresh duration; Generate a second token according to the key information and the second authentication time; Perform an authentication process on the token to be authenticated based on the second token.
8. The method according to claim 7, wherein The generating a first token according to the key information and the first authentication time of the target user includes: Determine the key information corresponding to the target user according to the user information; Generate the first token according to the key information and the first authentication time.
9. The method according to claim 7, wherein The generating a second token according to the key information and the second authentication time includes: On the basis of the first authentication time, add the target duration 1 to N times respectively to obtain N second authentication times; where N is the upper limit of the number of times of manual refresh of the token code; Generate second tokens corresponding to each of the second authentication times one by one according to each second authentication time and the key information.
10. The method according to claim 7, characterized in that, It further includes: Receive a key request sent by the target application, where the key request carries the user information; Determine the key information corresponding to the target user according to the user information, and send the key information to the target application; to enable the target application to generate an initial token according to the key information and the third time, and display a token page including the initial token and a token update control; wherein, the target application is configured to send the key request to the server in response to a third trigger operation on the target application; the third time is the time point when the target application responds to the third trigger operation or the time point when the target application receives the key information.
11. The method according to claim 7, characterized in that Further included are: receiving a time calibration request sent by a target application, the time calibration request carrying a first current time of the target application; judging whether a second current time of the server is consistent with the first current time of the target application; in the case where the second current time is inconsistent with the first current time, determining a time difference between the first current time and the second current time, and sending the time difference to the target application; to enable the target application to calibrate the time of the target application according to the time difference.
12. An authentication system for a token code, comprising: A target application, a server, and an authentication device; the target application is configured to display a token page, the token page including an initial token and a token update control; in response to a trigger operation on the token update control, updating the initial token to a to-be-authenticated token; the authentication device is configured to send an authentication request for logging in to the authentication device to the server, wherein the authentication request carries user information and the to-be-authenticated token; the server is configured to receive the authentication request; generate a first token according to a key of the target user and a first authentication time, wherein the target user is the user indicated by the user information, and the first authentication time is the time point when the authentication request is received or the generation time point of the authentication request; perform an authentication process on the to-be-authenticated token based on the first token, and in the case where the to-be-authenticated token fails to pass the authentication, obtain a second authentication time that is a target duration later than the first authentication time according to the first authentication time, wherein the target duration is a preset token automatic refresh duration; generate a second token according to the key information and the second authentication time; perform an authentication process on the to-be-authenticated token based on the second token.
13. An electronic device, characterized in that, Included are: a processor; a memory for storing executable instructions of the processor; the processor is configured to execute the method for generating a token code or the method for authenticating a token code according to any one of claims 1-11 above by running the instructions in the memory.
14. A computer storage medium, characterized in that, The storage medium stores a computer program, and when the computer program is run by the processor, it executes the method for generating a token code or the method for authenticating a token code according to any one of claims 1-11 above.