Method and device for dynamically establishing Token between systems
Through the collaboration between the client, server and certificate authentication server, digital certificates and asymmetric key technology are used to dynamically generate tokens, solving the problem of poor dynamicity of tokens between systems and improving communication security and update frequency.
Patent Information
- Application Number
- CN202510377213.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-07-18
AI Technical Summary
In the prior art, the token dynamics between systems are poor, resulting in insufficient communication security and the inability to achieve high-frequency token updates and dynamics.
Through the collaboration between the client and server side and the certificate authentication server, digital certificates and asymmetric key technology are used to dynamically generate tokens, including Token-ID, to ensure the uniqueness and security of parameters during each authentication process.
It realizes dynamic generation and update of tokens between systems, improves communication security, avoids the security risks of static tokens, and supports high-frequency token updates.
Smart Images

Figure CN120337305A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication security technologies, and particularly to a method and device for dynamically establishing a Token between systems. Background Art
[0002] Currently, RESTful APIs (also known as RESTful web services or REST APIs) are widely used in software systems for interaction between systems. A RESTful API is an architectural style of application programming interface (API) that allows one software system to use HTTP / HTTPS to request an interface provided by another software system. RESTful APIs are based on Representational State Transfer (REST), which is an architectural style and a communication method often used in web service development, and has the characteristics of simplicity and efficiency.
[0003] For the interaction between software systems based on RESTful API interfaces, it is necessary to solve the problem of access permission or authentication between systems, that is, the accessed system (server) needs to check the access permissions of the accessing system (client). A common current approach is to use an access token, namely Token, and set this Token in the header parameters of HTTP / HTTPS. The client will include this Token in the header parameters of HTTP / HTTPS in each business interface request of the RESTful API. After receiving the client's request, the server first checks the received Token, and only allows access to the business interface if the check passes. For this Token used as an authentication identifier, in many cases, it is manually configured on the server and the client when the system goes online.
[0004] There are usually two cases for the Token. In the first method, a random string is used. In the second method, the client information (such as system name or identification string, MAC address or IP address, etc.) is encrypted into a ciphertext using an encryption algorithm and key agreed upon by the server and the client, and then the ciphertext is converted into a string through methods such as Base64.
[0005] The above methods of manually setting the initial Token between application systems are difficult to achieve good Token dynamics and cannot guarantee the long-term security of the system. Summary of the Invention
[0006] The purpose of this application is to provide a method and device for dynamically establishing a Token between systems, and through a more secure and dynamic Token generation and update mechanism, to ensure the communication security between application systems.
[0007] To achieve the above purpose, this application provides the following solutions:
[0008] In a first aspect, the present application provides a method for dynamically establishing a Token between systems. The execution entities of the method for dynamically establishing a Token between systems include a client, a server, and a certificate authentication server. The method for dynamically establishing a Token between systems includes:
[0009] The client sends an authentication interface call request to the server. Among them, the authentication interface call request includes a client address, a first random number, a first certificate, and a first temporary public key. The first certificate is a certificate issued by the certificate authentication server to the client.
[0010] After receiving the authentication interface call request, the server sends a certificate authentication request to the certificate authentication server. Among them, the certificate authentication request includes the client address, the first random number, the first certificate, a server address, a second random number, and a second certificate. The second certificate is a certificate issued by the certificate authentication server to the server.
[0011] The certificate authentication server verifies the first certificate and the second certificate according to the certificate authentication request, obtains a certificate authentication result, and sends a certificate authentication response message containing the certificate authentication result to the server.
[0012] When both the first certificate authentication result and the second certificate authentication result in the certificate authentication result are passed, the server generates Token2 and Token-ID2 according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself, and sends an authentication interface call response result to the client. Among them, the authentication interface call response result includes the certificate authentication result, the second temporary public key, and the Token-ID2.
[0013] The client generates Token1 and Token-ID1 according to the second temporary public key and the private key corresponding to the first temporary public key, and determines whether the Token-ID1 and the Token-ID2 are the same, obtaining a first determination result. When the first determination result is yes, the client uses the Token1 as the access Token.
[0014] In a second aspect, the present application provides a method for dynamically establishing a Token between systems. The execution entity of the method for dynamically establishing a Token between systems is the client. The method for dynamically establishing a Token between systems includes:
[0015] The client sends an authentication interface call request to the server. Among them, the authentication interface call request includes a client address, a first random number, a first certificate, and a first temporary public key. The first certificate is a certificate issued by the certificate authentication server to the client.
[0016] The client obtains the authentication interface call response result sent by the server, and generates Token1 and Token-ID1 according to the second temporary public key and the private key corresponding to the first temporary public key. Among them, the authentication interface call response result includes a certificate authentication result, the second temporary public key, and the Token-ID2. The certificate authentication result is the result of the certificate authentication server verifying the first certificate and the second certificate according to the certificate authentication request sent by the server. The certificate authentication request includes the client address, the first random number, the first certificate, the server address, the second random number, and the second certificate. The second certificate is the certificate issued by the certificate authentication server to the server.
[0017] The client determines whether the Token-ID1 and Token-ID2 are the same, and obtains a first judgment result.
[0018] When the first judgment result is yes, the client uses the Token1 as the access Token.
[0019] The server is used for:
[0020] After receiving the authentication interface call request, send the certificate authentication request to the certificate authentication server. When both the first certificate authentication result and the second certificate authentication result in the certificate authentication result are passed, generate Token2 and Token-ID2 according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself, and send the authentication interface call response result to the client.
[0021] In a third aspect, the present application provides a method for dynamically establishing a Token between systems. The execution subject of the method for dynamically establishing a Token between systems is the server. The method for dynamically establishing a Token between systems includes:
[0022] After obtaining the authentication interface call request sent by the client, the server sends a certificate authentication request to the certificate authentication server. Among them, the authentication interface call request includes the client address, the first random number, the first certificate, and the first temporary public key. The first certificate is the certificate issued by the certificate authentication server to the client. The certificate authentication request includes the client address, the first random number, the first certificate, the server address, the second random number, and the second certificate. The second certificate is the certificate issued by the certificate authentication server to the server.
[0023] When both the first certificate authentication result and the second certificate authentication result in the certificate authentication result are passed, the server generates Token2 and Token-ID2 based on the first temporary public key and the private key corresponding to the second temporary public key generated by itself, and sends an authentication interface call response result to the client. Among them, the certificate authentication result is the result of the certificate authentication server verifying the first certificate and the second certificate according to the certificate authentication request sent by the server, and the authentication interface call response result includes the certificate authentication result, the second temporary public key, and the Token-ID2;
[0024] The client is used for:
[0025] After obtaining the authentication interface call response result, generate Token1 and Token-ID1 according to the second temporary public key and the private key corresponding to the first temporary public key; determine whether the Token-ID1 and Token-ID2 are the same to obtain a first judgment result; when the first judgment result is yes, use the Token1 as the access token.
[0026] Fourthly, the present application provides a device for dynamically establishing a Token between systems, including:
[0027] A client, a server, and a certificate authentication server;
[0028] The server is connected to the client and the certificate authentication server;
[0029] The client is used for:
[0030] Send an authentication interface call request to the server, where the authentication interface call request includes a client address, a first random number, a first certificate, and a first temporary public key, and the first certificate is a certificate issued by the certificate authentication server to the client;
[0031] After obtaining the authentication interface call response result, generate Token1 and Token-ID1 according to the second temporary public key and the private key corresponding to the first temporary public key; determine whether the Token-ID1 and Token-ID2 are the same to obtain a first judgment result; when the first judgment result is yes, use the Token1 as the access token, where the authentication interface call response result includes the certificate authentication result, the second temporary public key, and the Token-ID2;
[0032] The server is used for:
[0033] After receiving the authentication interface call request, send a certificate authentication request to the certificate authentication server, where the certificate authentication request includes the client address, the first random number, the first certificate, the server address, the second random number, and the second certificate, and the second certificate is the certificate issued by the certificate authentication server to the server side;
[0034] When both the first certificate authentication result and the second certificate authentication result in the certificate authentication result are passed, generate Token2 and Token-ID2 according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself, and send an authentication interface call response result to the client;
[0035] The certificate authentication server is used for:
[0036] Verify the first certificate and the second certificate according to the certificate authentication request, obtain a certificate authentication result, and send a certificate authentication response message containing the certificate authentication result to the server side.
[0037] According to the specific embodiments provided by the present application, the present application has the following technical effects:
[0038] The present application provides a method and device for dynamically establishing a Token between systems. In this method, the client and the server side perform third-party authentication based on the certificate authentication server, and generate a Token based on the temporary public keys exchanged between the two parties when the certificates of both parties pass, realizing dynamic Token establishment. This process has high security and is convenient to implement because digital certificates and asymmetric key technologies are used. Description of the Drawings
[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0040] Figure 1 It is a timing diagram of a method for dynamically establishing a Token between systems in Embodiment 1 of the present application;
[0041] Figure 2 It is a schematic diagram of the definition of a certificate authentication request in Embodiment 4 of the present application;
[0042] Figure 3 It is a schematic diagram of the definition of a certificate authentication response in Embodiment 4 of the present application;
[0043] Figure 4 It is a schematic diagram of the definition of an authentication result in Embodiment 4 of the present application. Specific Embodiment
[0044] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all of the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without making creative efforts shall fall within the protection scope of the present application.
[0045] Through research, it is found that there are security problems in the way of manually setting the initial Token between application systems: In the first way, a random string is used, which is equivalent to using a shared key between the server and the client. Once the system random string is leaked, there are security problems; although the second way improves security, those who master the system encryption method and encryption key may still form a Token through client information encryption and conversion, and there are also security problems. Moreover, it is difficult to achieve good Token dynamics in both ways, that is, high-frequency Token updates. The inability to update the Token frequently also affects security.
[0046] In response to this, this embodiment provides a method and device for dynamically establishing a Token between systems. Through a more secure and dynamic Token generation and update mechanism, the communication security between application systems can be ensured.
[0047] To make the above objects, features, and advantages of the present application more obvious and understandable, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0048] Embodiment 1
[0049] As Figure 1 shown, this embodiment provides a method for dynamically establishing a Token between systems. The execution subject of the method for dynamically establishing a Token between systems includes a client 101 (the first system), a server 102 (the second system), and a certificate authentication server 103 (AS). The method for dynamically establishing a Token between systems includes:
[0050] S1: The client 101 sends an authentication interface call request to the server 102. Among them, the authentication interface call request includes the client 101 address, a first random number, a first certificate, and a first temporary public key. The first certificate is a certificate issued by the certificate authentication server 103 for the client 101;
[0051] S2: After receiving the authentication interface call request, the server 102 sends a certificate authentication request to the certificate authentication server 103, where the certificate authentication request includes the client 101 address, the first random number, the first certificate, the server address, the second random number, and the second certificate, and the second certificate is the certificate issued by the certificate authentication server 103 to the server 102;
[0052] S3: The certificate authentication server 103 verifies the first certificate and the second certificate according to the certificate authentication request, obtains the certificate authentication result, and sends the certificate authentication response message containing the certificate authentication result to the server 102;
[0053] S4: When both the first certificate authentication result and the second certificate authentication result in the certificate authentication result are passed, the server 102 generates Token2 and Token-ID2 according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself, and sends the authentication interface call response result to the client 101, where the authentication interface call response result includes the certificate authentication result, the second temporary public key, and the Token-ID2;
[0054] S5: The client 101 generates Token1 and Token-ID1 according to the second temporary public key and the private key corresponding to the first temporary public key, and determines whether the Token-ID1 and the Token-ID2 are the same to obtain a first judgment result; when the first judgment result is yes, the client 101 uses the Token1 as the access token.
[0055] As an optional implementation manner, the server 102 generates Token2 and Token-ID2 according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself, specifically including:
[0056] The server 102 performs DH calculation according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself to generate a shared key;
[0057] Generate Token2 and Token-ID2 according to the shared key.
[0058] As an optional implementation manner, generating Token2 and Token-ID2 according to the shared key specifically includes:
[0059] Use the shared key as the password of the HMAC algorithm to perform hash calculation on the authentication result in the certificate authentication response message to obtain a hash calculation value;
[0060] Generate Token2 and Token-ID2 based on the calculated hash value.
[0061] Specifically, use the shared key generated by DH calculation as the password to perform HMAC calculation on the authentication result. The HMAC calculation generates a 512-byte result value. Then, take the first 256 bits of the result value as Token2, and take the last 256 bits of the result value as Token-ID2.
[0062] It should be noted that the generation processes of Token1 and Token-ID1 are the same as those of Token2 and Token-ID2.
[0063] Since for each authentication request, both the client 101 and the server 102 generate new random numbers and ephemeral public keys. These parameters are dynamically changing, ensuring the uniqueness of the input parameters for each authentication process.
[0064] The client 101 and the server 102 perform DH calculation (such as ECDH) by exchanging ephemeral public keys and combining their respective private keys to generate shared keys (K1 and K2). Since different ephemeral public keys are used for each authentication, the shared keys generated by the DH algorithm are also completely dynamic and cannot be reused.
[0065] The shared key is used as the key for the HMAC algorithm to perform hash calculation on the authentication result in the certificate authentication response message, generating a 512-bit hash value. The first 256 bits are used as the Token, and the last 256 bits are used as the Token-ID. Due to the dynamic nature of the shared key, the Tokens and Token-IDs generated each time are different.
[0066] Before each access to the service interface by the client 101, it must re-invoke the authentication interface and submit a new random number, ephemeral public key, and certificate. The server 102 also generates a new random number and ephemeral public key, and completes two-way certificate verification through the certificate authentication server 103 (AS).
[0067] The client 101 and the server 102 independently derive Tokens and Token-IDs based on the dynamically generated shared keys. Even though the generation processes on both sides are independent, due to the mathematical properties of the DH algorithm, the shared keys on both sides are the same. Therefore, the final Token-IDs must be the same. By comparing the consistency of the Token-IDs, it is ensured that the dynamically generated Tokens are valid.
[0068] The Token is only valid during a single authentication process. If subsequent service requests are required, the authentication process must be re-triggered to generate a new Token. Due to the lightweight nature of DH calculation and random number generation, the system can support high-frequency Token updates, thereby enhancing security.
[0069] In summary, the dynamic nature of the Token is jointly ensured by the random number, the dynamic generation of the ephemeral public key, and the derivation of the shared key based on the DH algorithm. Each authentication process generates a unique Token and Token-ID, which cannot be predicted or reproduced from historical data, thus effectively solving the security risks of static Tokens.
[0070] Embodiment 2
[0071] This embodiment provides a method for dynamically establishing a Token between systems. The execution subject of the method for dynamically establishing a Token between systems is the client 101. The method for dynamically establishing a Token between systems includes:
[0072] The client 101 sends an authentication interface call request to the server 102. Among them, the authentication interface call request includes the client 101 address, the first random number, the first certificate, and the first ephemeral public key. The first certificate is the certificate issued by the certificate authentication server 103 to the client 101.
[0073] The client 101 obtains the authentication interface call response result sent by the server 102, and generates Token1 and Token-ID1 according to the second ephemeral public key and the private key corresponding to the first ephemeral public key. Among them, the authentication interface call response result includes the certificate authentication result, the second ephemeral public key, and the Token-ID2. The certificate authentication result is the result of the certificate authentication server 103 verifying the first certificate and the second certificate according to the certificate authentication request sent by the server 102. The certificate authentication request includes the client 101 address, the first random number, the first certificate, the server address, the second random number, and the second certificate. The second certificate is the certificate issued by the certificate authentication server 103 to the server 102.
[0074] The client 101 determines whether the Token-ID1 and Token-ID2 are the same, and obtains a first determination result.
[0075] When the first determination result is yes, the client 101 uses the Token1 as the access Token.
[0076] The server 102 is used for:
[0077] After receiving the authentication interface call request, it sends the certificate authentication request to the certificate authentication server 103. When both the first certificate authentication result and the second certificate authentication result in the certificate authentication result are passed, it generates Token2 and Token-ID2 according to the first ephemeral public key and the private key corresponding to the second ephemeral public key generated by itself, and sends the authentication interface call response result to the client 101.
[0078] Embodiment 3
[0079] This embodiment provides a method for dynamically establishing a Token between systems. The execution entity of the method for dynamically establishing a Token between systems is the server side 102. The method for dynamically establishing a Token between systems includes:
[0080] After obtaining the authentication interface call request sent by the client 101, the server side 102 sends a certificate authentication request to the certificate authentication server 103. Among them, the authentication interface call request includes the client 101 address, the first random number, the first certificate, and the first temporary public key. The first certificate is the certificate issued by the certificate authentication server 103 to the client 101. The certificate authentication request includes the client 101 address, the first random number, the first certificate, the server address, the second random number, and the second certificate. The second certificate is the certificate issued by the certificate authentication server 103 to the server side 102;
[0081] When both the first certificate authentication result and the second certificate authentication result in the certificate authentication result are passed, the server side 102 generates Token2 and Token-ID2 according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself, and sends an authentication interface call response result to the client 101. Among them, the certificate authentication result is the result of the certificate authentication server 103 verifying the first certificate and the second certificate according to the certificate authentication request sent by the server side 102. The authentication interface call response result includes the certificate authentication result, the second temporary public key, and the Token-ID2;
[0082] The client 101 is used for:
[0083] After obtaining the authentication interface call response result, generating Token1 and Token-ID1 according to the second temporary public key and the private key corresponding to the first temporary public key; judging whether the Token-ID1 and Token-ID2 are the same to obtain a first judgment result; when the first judgment result is yes, using the Token1 as the access Token.
[0084] Embodiment 4
[0085] This embodiment provides a device for dynamically establishing a Token between systems, including a first system 101 (client), a second system 102 (server side), and a certificate authentication server 103 (AS). The first system 101 accesses the WEB service provided by the second system 102 through the RESTful API interface of HTTP / HTTPS, Figure 1Shows the Token establishment process among the first system 101 (client), the second system 102 (server), and the certificate authentication server 103 (AS).
[0086] AS 103 adopts the certificate authentication system of the WAPI wireless network system. This system has the functions of certificate issuance and authentication. In the WAPI wireless network system, there are already defined messages for the AS to provide services externally, namely certificate authentication services, including certificate authentication requests and certificate authentication responses, as Figure 2 and Figure 3 shown. Among them, AE (authenticator entity) is the authentication entity, corresponding to the access point AP of the WAPI wireless network, and ASUE (authentication supplicant entity) is the authentication requester entity, corresponding to the terminal STA of the wireless network. Moreover, in the WAPI wireless system, the certificate authentication result is also defined, as Figure 4 shown, where ADDID is the address ID, which is the concatenation of the MAC addresses of ASUE and AE.
[0087] In this embodiment, the first system 101, i.e., the client, is ASUE, and the second system 102, i.e., the server, is AE. AS 103 issues the first certificate to the first system 101 and the second certificate to the second system 102.
[0088] The first system 101 transfers the first certificate through the RESTful API-style authentication interface provided by the second system 102, requests the AS for certificate authentication by the second system 102, and transfers the certificate authentication result to the first system 101 through the response of the authentication interface;
[0089] The first system 101 and the second system 102 also exchange random numbers and ephemeral public keys through the authentication interface;
[0090] The first system 101 and the second system 102 respectively generate a Token and a Token-ID based on the result of the DH calculation when the certificate authentication result is passed. Among them, the second system 102 also transfers the Token-ID through the response of the authentication interface;
[0091] The first system 101 determines whether the Token application is successful according to the comparison of the Token-ID.
[0092] The authentication interface includes the client 101 request parameters (i.e., the authentication interface call request), and the client 101 request parameters at least include the address of the client 101, a random number, a digital certificate, and a temporary public key; the response of the authentication interface includes return parameters, and the return parameters at least include an authentication result and an authentication result signature; if the verification results of both certificates in the authentication result are passed, the return parameters also include the temporary public key of the server side 102 and a Token-ID (i.e., the authentication interface call response result).
[0093] Table 1 is the parameter description table of the authentication interface, and this authentication interface is defined as follows:
[0094] ① Service provider: The second system 102
[0095] ② Service requester: The first system 101
[0096] ③ Request address: https: / / server IP / authapi ④ Request method: POST
[0097] ⑤ Request parameters:
[0098]
[0099] ⑥ Return parameters:
[0100]
[0101] Table 1 Parameter description table of the authentication interface
[0102]
[0103]
[0104] The client 101 is used for:
[0105] Sending an authentication interface call request to the server side 102, where the authentication interface call request includes the client 101 address, a first random number, a first certificate, and a first temporary public key, and the first certificate is the certificate issued by the certificate authentication server 103 to the client 101;
[0106] After obtaining the response result of the authentication interface call, generate Token1 and Token-ID1 according to the second temporary public key and the private key corresponding to the first temporary public key; determine whether the Token-ID1 and Token-ID2 are the same to obtain a first determination result; when the first determination result is yes, use the Token1 as the access token, where the authentication interface call response result includes the certificate authentication result, the second temporary public key, and the Token-ID2;
[0107] The server side 102 is used for:
[0108] After receiving the authentication interface call request, send a certificate authentication request to the certificate authentication server 103, where the certificate authentication request includes the client 101 address, the first random number, the first certificate, the server address, the second random number, and the second certificate, and the second certificate is the certificate issued by the certificate authentication server 103 to the server side 102;
[0109] When both the first certificate authentication result and the second certificate authentication result in the certificate authentication result are passed, generate Token2 and Token-ID2 according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself, and send the authentication interface call response result to the client 101;
[0110] The certificate authentication server 103 is used for:
[0111] Verify the first certificate and the second certificate according to the certificate authentication request, obtain the certificate authentication result, and send the certificate authentication response message containing the certificate authentication result to the server side 102.
[0112] As Figure 1 shown, the interaction and processing process between the first system 101, the second system 102, and the AS specifically includes:
[0113] S1: Before the first system 101 accesses the service interface of the second system 102, generate a first random number as the client 101 random number, and send the client 101 address, the first random number, the first certificate, and the temporary public key to the second system 102 by calling the authentication interface;
[0114] S2: When the second system 102 processes the call request of the first system 101 to the authentication interface, it generates a second random number, and then sends an authentication request to the AS. The authentication request includes the client 101 address, the first random number, the first certificate, the server address, the second random number, and the second certificate. Among them, ADDID in the authentication request is formed by concatenating the client 101 address and the server address, the AE challenge is the second random number, the ASUE challenge is the first random number, the certificate of ASUEE uses the first certificate, and the certificate of AE uses the second certificate;
[0115] S3: When the AS processes the authentication request, it verifies the first certificate and the second certificate, forms an authentication result and an authentication result signature, and sends an authentication response to the second system 102, which includes the authentication result and the authentication result signature.
[0116] S4: When the second system 102 processes the response result, it first checks the verification results of the first certificate and the second certificate in the authentication result. When both results are passed, it generates a second temporary public key, performs a DH calculation based on the first temporary public key and the private key corresponding to the second temporary public key to generate a shared key K2, and generates Token2 and Token-ID2 based on K2. Finally, it sends a response to the authentication interface to the first system 101, which includes the return parameter; if the verification results of the first certificate and the second certificate in the authentication result are both passed, the return parameter includes the second temporary public key and Token-ID2;
[0117] S5: After receiving the return parameter of the authentication interface, the first system 101 checks the verification results of the first certificate and the second certificate in the authentication result. When both results are passed, it performs a DH calculation based on the second temporary public key and the private key corresponding to the first temporary public key to generate a shared key K1, and generates Token1 and Token-ID1 based on K1. Then it compares Token-ID2 extracted from the return parameter of the authentication interface with Token-ID1. If Token-ID2 and Token-ID1 are the same, the first system 101 considers the dynamic Token request successful, and uses Token1 as the access Token for subsequent service requests.
[0118] In this embodiment, the client 101 application system and the server 102 application system perform third-party authentication based on the certificate authentication server 103, and generate a Token based on the temporary public keys exchanged between the two parties when the certificates of both parties pass, realizing the establishment of a dynamic Token. This process uses digital certificates and asymmetric key technologies, which is highly secure and convenient to implement.
[0119] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the various technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0120] Specific examples are used in this article to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A method for dynamically establishing a Token between systems, characterized in that The execution entities of the method for dynamically establishing Tokens between systems include a client, a server, and a certificate authentication server. The method for dynamically establishing Tokens between systems includes: The client sends an authentication interface call request to the server. Among them, the authentication interface call request includes the client address, a first random number, a first certificate, and a first temporary public key. The first certificate is a certificate issued by the certificate authentication server to the client; After receiving the authentication interface call request, the server sends a certificate authentication request to the certificate authentication server. Among them, the certificate authentication request includes the client address, the first random number, the first certificate, the server address, a second random number, and a second certificate. The second certificate is a certificate issued by the certificate authentication server to the server; The certificate authentication server verifies the first certificate and the second certificate according to the certificate authentication request, obtains a certificate authentication result, and sends a certificate authentication response message containing the certificate authentication result to the server; When both the first certificate authentication result and the second certificate authentication result in the certificate authentication result are passed, the server generates Token2 and Token-ID2 according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself, and sends an authentication interface call response result to the client. Among them, the authentication interface call response result includes the certificate authentication result, the second temporary public key, and the Token-ID2; The client generates Token1 and Token-ID1 according to the second temporary public key and the private key corresponding to the first temporary public key, and judges whether the Token-ID1 and the Token-ID2 are the same, obtaining a first judgment result; when the first judgment result is yes, the client uses the Token1 as the access Token.
2. The method for dynamically establishing a Token between systems according to claim 1, wherein The server generates Token2 and Token-ID2 according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself, specifically including: The server performs DH calculation according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself to generate a shared key; Generate Token2 and Token-ID2 according to the shared key.
3. The method for dynamically establishing a Token between systems according to claim 2, wherein Generate Token2 and Token-ID2 according to the shared key, specifically including: Use the shared key as the password of the HMAC algorithm to perform a hash calculation on the certificate authentication result in the certificate authentication response message to obtain a hash calculation value; Generate Token2 and Token-ID2 according to the hash calculation value.
4. A method for dynamically establishing a Token between systems, characterized in that The execution entity of the method for dynamically establishing Tokens between systems is the client. The method for dynamically establishing Tokens between systems includes: The client sends an authentication interface call request to the server. Among them, the authentication interface call request includes the client address, a first random number, a first certificate, and a first temporary public key. The first certificate is a certificate issued by the certificate authentication server to the client; The client obtains the response result of the authentication interface call sent by the server, and generates Token1 and Token-ID1 according to the second temporary public key and the private key corresponding to the first temporary public key. Among them, the response result of the authentication interface call includes the certificate authentication result, the second temporary public key, and the Token-ID2. The certificate authentication result is the result of the certificate authentication server verifying the first certificate and the second certificate according to the certificate authentication request sent by the server. The certificate authentication request includes the client address, the first random number, the first certificate, the server address, the second random number, and the second certificate. The second certificate is the certificate issued by the certificate authentication server to the server; The client determines whether Token-ID1 and Token-ID2 are the same, and obtains a first determination result; When the first determination result is yes, the client uses Token1 as the access token; The server is used for: After receiving the authentication interface call request, send the certificate authentication request to the certificate authentication server. When both the first certificate authentication result and the second certificate authentication result in the certificate authentication result are passed, generate Token2 and Token-ID2 according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself, and send the response result of the authentication interface call to the client.
5. A method for dynamically establishing a Token between systems, characterized in that, The execution subject of the method for dynamically establishing Tokens between systems is the server. The method for dynamically establishing Tokens between systems includes: After obtaining the authentication interface call request sent by the client, the server sends a certificate authentication request to the certificate authentication server. Among them, the authentication interface call request includes the client address, the first random number, the first certificate, and the first temporary public key. The first certificate is the certificate issued by the certificate authentication server to the client. The certificate authentication request includes the client address, the first random number, the first certificate, the server address, the second random number, and the second certificate. The second certificate is the certificate issued by the certificate authentication server to the server; When both the first certificate authentication result and the second certificate authentication result in the certificate authentication result are passed, the server generates Token2 and Token-ID2 according to the first temporary public key and the private key corresponding to the second temporary public key generated by itself, and sends the response result of the authentication interface call to the client. Among them, the certificate authentication result is the result of the certificate authentication server verifying the first certificate and the second certificate according to the certificate authentication request sent by the server. The response result of the authentication interface call includes the certificate authentication result, the second temporary public key, and the Token-ID2; The client is used for: After obtaining the response result of the authentication interface call, generate Token1 and Token-ID1 according to the second ephemeral public key and the private key corresponding to the first ephemeral public key; determine whether Token-ID1 and Token-ID2 are the same to obtain a first determination result; when the first determination result is yes, use Token1 as the access token.
6. A device for dynamically establishing a Token between systems, characterized in that, The apparatus for dynamically establishing a token between systems includes: a client, a server, and a certificate authentication server; the server is connected to the client and the certificate authentication server; the client is configured to: send an authentication interface call request to the server, where the authentication interface call request includes a client address, a first random number, a first certificate, and a first ephemeral public key, and the first certificate is a certificate issued by the certificate authentication server to the client; after obtaining the response result of the authentication interface call, generate Token1 and Token-ID1 according to the second ephemeral public key and the private key corresponding to the first ephemeral public key; determine whether Token-ID1 and Token-ID2 are the same to obtain a first determination result; when the first determination result is yes, use Token1 as the access token, where the response result of the authentication interface call includes the certificate authentication result, the second ephemeral public key, and Token-ID2; the server is configured to: after receiving the authentication interface call request, send a certificate authentication request to the certificate authentication server, where the certificate authentication request includes the client address, the first random number, the first certificate, a server address, a second random number, and a second certificate, and the second certificate is a certificate issued by the certificate authentication server to the server; when both the first certificate authentication result and the second certificate authentication result in the certificate authentication result are passed, generate Token2 and Token-ID2 according to the first ephemeral public key and the private key corresponding to the second ephemeral public key generated by itself, and send the response result of the authentication interface call to the client; the certificate authentication server is configured to: verify the first certificate and the second certificate according to the certificate authentication request, obtain a certificate authentication result, and send a certificate authentication response message including the certificate authentication result to the server.