Data processing method and device, electronic equipment and storage medium

By identifying and comparing authentication digests in LDAP services, the problem of narrow application scope and low security of fixed digest algorithms in LDAP services is solved, and a wide application and high security data storage is achieved.

CN120342783AActive Publication Date: 2025-07-18CHINA SECURITIES DEPOSITORY & CLEARING CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510804848.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-07-18
Estimated Expiration
2045-06-16

AI Technical Summary

Technical Problem

The password storage strategy used in LDAP services relies on foreign fixed digest algorithms, and its application scope is not wide enough to meet business needs, and its data security is low.

Method used

By receiving the request information sent by the gateway device, obtaining user information and querying the type identification in the authentication field, identifying the first authentication summary and parameters, calling the corresponding authentication calculation model to calculate the second authentication summary, and comparing it with the first authentication summary, obtaining the authentication results, and supporting a variety of national secret algorithms to meet the needs of different authentication services and scenarios.

Benefits of technology

It has achieved a wide range of application and improved the security and accuracy of data storage, meeting the needs of different certification services and scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120342783A_ABST
    Figure CN120342783A_ABST
Patent Text Reader

Abstract

The invention discloses a data processing method and device, electronic equipment and a storage medium, and relates to the technical field of data processing. A specific embodiment of the method comprises the following steps: receiving request information sent by gateway equipment; obtaining user information in the request information, querying a corresponding authentication field, and extracting a type identifier in the authentication field; acquiring a field structure associated with the type identifier to identify a first authentication abstract and an authentication parameter from the authentication field, and acquiring a corresponding authentication calculation model based on the type identifier; and obtaining to-be-authenticated information from the request information, calling the authentication calculation model, calculating a second authentication abstract in combination with the authentication parameters and the to-be-authenticated information, and comparing the second authentication abstract with the first authentication abstract to obtain an authentication result. According to the embodiment, the problems that the password storage strategy commonly used by the LDAP service is realized by relying on a foreign fixed digest algorithm, the application range is not wide enough, the service requirements cannot be met, and the data security is relatively low can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data processing, and in particular, to a method, device, electronic device, and storage medium for data processing. Background Art

[0002] In scenarios of various business processes, considering the requirements of data security and confidentiality, data encryption and security authentication are usually required in business processes. For example, the authentication business process of user information can be implemented through a directory storage service. In related technologies, the LDAP (Lightweight Directory Access Protocol) service is an implementation method of the directory storage service. In the LDAP service, the commonly used password storage policy relies on a fixed digest algorithm from abroad. However, with the development of national cryptographic algorithms, this method not only has a limited application scope and cannot meet business requirements, but also has low data security. Summary of the Invention

[0003] In view of this, embodiments of the present invention provide a method, device, electronic device, and storage medium for data processing, which can solve the problem that the commonly used password storage policy in the LDAP service relies on a fixed digest algorithm from abroad, not only has a limited application scope and cannot meet business requirements, but also has low data security.

[0004] To achieve the above object, according to one aspect of the embodiments of the present invention, a method for data processing is provided.

[0005] A method for data processing according to an embodiment of the present invention includes: receiving request information sent by a gateway device, where the request information is sent by the gateway device after decrypting a request sent by a client; obtaining user information in the request information, querying corresponding authentication fields, and extracting a type identifier in the authentication fields; obtaining a field structure associated with the type identifier to identify a first authentication digest and authentication parameters from the authentication fields, and obtaining a corresponding authentication calculation model based on the type identifier; obtaining information to be authenticated from the request information, invoking the authentication calculation model, calculating a second authentication digest in combination with the authentication parameters and the information to be authenticated, comparing it with the first authentication digest to obtain an authentication result; and sending the authentication result to the client.

[0006] In one embodiment, obtaining a corresponding authentication calculation model based on the type identifier includes: in response to the type identifier belonging to a first type, obtaining a corresponding authentication calculation model based on the type identifier; in response to the type identifier belonging to a second type, obtaining the authentication calculation model corresponding to the second type.

[0007] In yet another embodiment, obtaining the field structure associated with the type identifier includes: identifying whether the type identifier includes a preset flag; in response to the type identifier including the preset flag, determining that the type identifier belongs to a first type and obtaining the field structure associated with the first type; in response to the type identifier not including the preset flag, determining that the type identifier belongs to a second type and obtaining the field structure associated with the second type.

[0008] In yet another embodiment, the method further includes: receiving a storage request for authentication information, obtaining corresponding user information and an authentication password; identifying the type to which the authentication password belongs to determine a corresponding type identifier based on the type, and generating an authentication string based on the authentication password; generating an authentication field based on the field structure associated with the type, the authentication string, and the type identifier to establish a correspondence with the user information in the storage request and store it.

[0009] In yet another embodiment, determining a corresponding type identifier based on the type and generating an authentication string based on the authentication password includes: in response to the authentication password belonging to the first type, obtaining an algorithm identifier associated with the authentication information to determine a corresponding type identifier, and generating an authentication string based on the authentication calculation model associated with the algorithm identifier and the authentication password; in response to the authentication password belonging to the second type, obtaining an associated type flag to determine a corresponding type identifier, and generating an authentication string based on the authentication calculation model associated with the second type and the authentication password.

[0010] In yet another embodiment, the method further includes: in response to a status reporting task, querying the authentication time parameters corresponding to each request message within a preset time period, calculating the processing timeliness of the request message, and obtaining the number of corresponding request messages in the to-be-processed queue to send the number and the processing timeliness to the gateway device.

[0011] In yet another embodiment, sending the authentication result to the client includes: sending the authentication result to the gateway device so that the gateway device encrypts the authentication result and sends it to the client.

[0012] To achieve the above object, according to another aspect of the embodiments of the present invention, there is provided an apparatus for data processing.

[0013] An apparatus for data processing according to an embodiment of the present invention includes: a receiving unit, configured to receive request information sent by a gateway device, where the request information is sent by the gateway device after decrypting a request sent by a client; an extracting unit, configured to obtain user information in the request information, query corresponding authentication fields, and extract a type identifier in the authentication fields; an obtaining unit, configured to obtain a field structure associated with the type identifier, so as to identify a first authentication digest and authentication parameters from the authentication fields, and obtain a corresponding authentication calculation model based on the type identifier; an authentication unit, configured to obtain information to be authenticated from the request information, call the authentication calculation model, calculate a second authentication digest by combining the authentication parameters and the information to be authenticated, and compare the second authentication digest with the first authentication digest to obtain an authentication result; and a sending unit, configured to send the authentication result to the client.

[0014] In one embodiment, the obtaining unit is specifically configured to: in response to the type identifier belonging to a first type, obtain a corresponding authentication calculation model based on the type identifier; in response to the type identifier belonging to a second type, obtain the authentication calculation model corresponding to the second type.

[0015] In another embodiment, the obtaining unit is specifically configured to: identify whether the type identifier includes a preset mark; in response to the type identifier including the preset mark, determine that the type identifier belongs to the first type, and obtain a field structure associated with the first type; in response to the type identifier not including the preset mark, determine that the type identifier belongs to the second type, and obtain a field structure associated with the second type.

[0016] In another embodiment, the receiving unit is further configured to receive a storage request for authentication information, and obtain corresponding user information and an authentication password; the apparatus further includes: a generating unit, configured to identify a type to which the authentication password belongs, so as to determine a corresponding type identifier based on the type, and generate an authentication string based on the authentication password; and a establishing unit, configured to generate an authentication field based on the field structure associated with the type, the authentication string, and the type identifier, so as to establish a corresponding relationship with the user information in the storage request and store it.

[0017] In another embodiment, the generating unit is specifically configured to: in response to the authentication password belonging to the first type, obtain an algorithm identifier associated with the authentication information, so as to determine a corresponding type identifier, and generate an authentication string based on the authentication calculation model associated with the algorithm identifier and the authentication password; in response to the authentication password belonging to the second type, obtain an associated type mark, so as to determine a corresponding type identifier, and generate an authentication string based on the authentication calculation model associated with the second type and the authentication password.

[0018] In yet another embodiment, the device further includes a reporting unit, configured to, in response to a status reporting task, query the authentication time parameters corresponding to each request message within a preset time period, calculate the processing timeliness of the request message, and obtain the number of corresponding request messages in the to-be-processed queue, so as to send the number and the processing timeliness to the gateway device.

[0019] In yet another embodiment, the sending unit is specifically configured to: send the authentication result to the gateway device, so that the gateway device encrypts the authentication result and then sends it to the client.

[0020] To achieve the above object, according to another aspect of the embodiments of the present invention, an electronic device is provided.

[0021] An electronic device according to an embodiment of the present invention includes: one or more processors; a storage device configured to store one or more programs, which when executed by the one or more processors cause the one or more processors to implement the data processing method provided by the embodiments of the present invention.

[0022] To achieve the above object, according to another aspect of the embodiments of the present invention, a computer-readable medium is provided.

[0023] A computer-readable medium according to an embodiment of the present invention stores a computer program thereon, and when the program is executed by a processor, it implements the data processing method provided by the embodiments of the present invention.

[0024] To achieve the above object, according to another aspect of the embodiments of the present invention, a computer program product is provided.

[0025] A computer program product according to an embodiment of the present invention includes a computer program, and when the program is executed by a processor, it implements the data processing method provided by the embodiments of the present invention.

[0026] One of the above embodiments of the invention has the following advantages or beneficial effects:

[0027] In an embodiment of the present invention, after receiving the request information sent by the gateway device, the corresponding authentication fields can be queried according to the user information therein, the type identifier can be extracted therefrom, so as to obtain the field structure associated with the type identifier, and then the first authentication digest and authentication parameters can be identified from the authentication fields, and the corresponding authentication calculation model can be obtained based on the type identifier; after obtaining the information to be authenticated from the request information, the authentication calculation model can be called, and the second authentication digest can be calculated by combining the authentication parameters and the information to be authenticated, so as to compare with the first authentication digest, and the authentication result can be obtained and sent to the client. In an embodiment of the present invention, different field structures and authentication calculation models can be set according to the type, so that when performing information authentication, the authentication digest and authentication parameters can be identified according to the field structure of the belonging type, and then the authentication digest to be compared can be calculated through the corresponding authentication calculation model and compared. In this way, information authentication can be performed based on a variety of national cryptographic algorithms, meeting the requirements of different authentication services and scenarios, and making the application scope wider; moreover, in an embodiment of the present invention, different field structures can be set for each type to improve the security and accuracy of data storage.

[0028] The further effects of the above non-conventional optional ways will be described below in conjunction with the specific embodiments. BRIEF DESCRIPTION OF THE DRAWINGS

[0029] The drawings are used to better understand the present invention and do not constitute an improper limitation to the present invention. Among them: Figure 1 is a schematic structural diagram of an architecture of a data processing system according to an embodiment of the present invention; Figure 2 is a schematic diagram of a field structure of an authentication field according to an embodiment of the present invention; Figure 3 is a schematic diagram of a main process of a data processing method according to an embodiment of the present invention; Figure 4 is a schematic diagram of another main process of a data processing method according to an embodiment of the present invention; Figure 5 is a schematic diagram of main units of a data processing device according to an embodiment of the present invention; Figure 6 is an exemplary system architecture diagram to which an embodiment of the present invention can be applied; Figure 7 is a schematic structural diagram of a computer system suitable for implementing an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0030] The following describes exemplary embodiments of the present invention with reference to the accompanying drawings. Various details of the embodiments of the present invention are included to facilitate understanding, and they should be considered merely exemplary. Therefore, those of ordinary skill in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present invention. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0031] It should be noted that, without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other. All aspects of data acquisition, transmission, storage, use, processing, etc. in the technical solution of this application comply with the relevant regulations of national laws and regulations. In the embodiments of this application, some industry-existing solutions such as certain software, components, models, etc. may be mentioned, and they should be considered exemplary. Their purpose is only to illustrate the feasibility in the implementation of the technical solution of this application, but it does not mean that the applicant has already or necessarily used this solution.

[0032] An embodiment of the present invention provides a data processing system, which can be used in the processing scenario of data authentication, specifically in the processing scenario of data authentication in the LDAP service.

[0033] In an embodiment of the present invention, taking the processing scenario of data authentication in the LDAP service as an example, Figure 1 The following shows the schematic architecture diagram of a data processing system in an embodiment of the present invention. As Figure 1 shown, the data processing system may include a gateway device and an LDAP server. The number of gateway devices and LDAP servers can be set according to requirements. Each gateway device can establish a data connection with each LDAP server. The LDAP protocol can be pre-configured in the gateway device to facilitate establishing a data connection with the LDAP server. The data processing system can establish a connection with the client through the gateway device. The client can include various types, such as devices for writing data and devices for requesting data authentication. To improve data security, encrypted data transmission can be performed between the client and the gateway device. For example, TLS (Transport Layer Security Protocol) that meets the requirements of national cryptography can be used for encryption. After the client sends the data to the gateway device, the gateway device can decrypt the received data and then transmit it to the LDAP server for subsequent processing.

[0034] Taking the scenario of security authentication for user login as an example, the information required for authentication, such as user passwords, etc., can be stored in the LDAP server. Taking the information required for authentication as the user password as an example, the client for writing the user password can send information such as the user password to the LDAP server through the gateway device. The LDAP server determines the corresponding storage method according to the type of the user password to generate the corresponding authentication field and store it.

[0035] In the embodiments of the present invention, the user password sent by the client can be plaintext information or ciphertext information. To improve data security, it is usually necessary to encrypt and store the plaintext information. To simplify the complexity of data processing, the ciphertext information, which is already encrypted data, can be no longer encrypted. Therefore, in the embodiments of the present invention, different types of user passwords can be processed separately, and the field structures of the corresponding authentication fields for different types can be set.

[0036] For the authentication field, its structure can be as Figure 2 shown, including a type identifier, an authentication digest, and authentication parameters. The type identifier can indicate whether the current corresponding user password is in plaintext processing type or ciphertext processing type. Thus, not only can the field structure of the authentication field be determined, but also the authentication method for the user password can be represented. The authentication digest represents the data after the user password is encrypted during authentication, and it is used for subsequent user password authentication. The authentication parameters represent the parameters required during authentication, specifically, they can be salt values, such as 8-bit strings.

[0037] It should be noted that since the user password can be encrypted based on different algorithms, in the embodiments of the present invention, the algorithm identifier corresponding to each encryption algorithm can be set, and then it can be stored in the authentication field as the type identifier. For the user password ciphertext that does not need to be encrypted repeatedly, a corresponding mark, that is, a preset mark, can be set to determine it as the type identifier. Therefore, in the embodiments of the present invention, through the type identifier in the authentication field, not only can the specific type be determined, but also the encryption algorithm used for authentication can be determined, so as to meet the requirements of adapting to different authentication services and scenarios, and improve the security and accuracy of data storage. Taking the user password as plaintext and the encryption algorithm as SM3 as an example, the format of its authentication field is as Figure 2 shown, where the type identifier can be the algorithm identifier, that is, SM3, the authentication digest is the digest generated based on SM3 and the user password, and the authentication parameter is the salt value used when generating the digest.

[0038] The embodiments of the present invention provide a data processing method, which can be executed by a data processing system, as Figure 3 shown, and this method includes the following steps.

[0039] S301: Receive the request information sent by the gateway device.

[0040] Among them, the request information is sent by the gateway device after decrypting the request sent by the client.

[0041] The client sends a request to the gateway device. The gateway device can decrypt it based on a pre-configured decryption policy, and then send it to the server as the request information. Specifically, it can be Figure 1The LDAP server shown above.

[0042] The request information can represent the information for requesting authentication, and is used to authenticate the information to be authenticated carried in the request information. The request information may include user information, information to be authenticated, and so on. The user information may specifically be a user identifier, and the information to be authenticated may specifically be information that needs to be kept confidential such as a user password.

[0043] S302: Obtain the user information in the request information, query the corresponding authentication field, and extract the type identifier in the authentication field.

[0044] Among them, the authentication field is pre-generated and stored, which may include the data required for authentication, and a corresponding relationship with the user information may be established in advance. Therefore, in this step, the corresponding authentication field can be queried based on the user information.

[0045] In the embodiments of the present invention, the authentication field can set the corresponding field structure according to requirements. Since the field structures corresponding to different types may be different, the type identifier in the authentication field can be extracted first in this step.

[0046] Specifically, the type identifier may specifically be a string constant, whose length can be pre-configured and can be configured at the starting position of the authentication field. Therefore, in this step, a string of a preset length can be extracted from the starting position of the authentication field to be determined as the type identifier.

[0047] It should be noted that the user information can represent the information that uniquely identifies the user, such as the user identifier. In the scenario of user login authentication, the user information can be identification information such as the user login account.

[0048] S303: Obtain the field structure associated with the type identifier, so as to identify the first authentication digest and authentication parameters from the authentication field, and obtain the corresponding authentication calculation model based on the type identifier.

[0049] Among them, the field structure is pre-set. Since the encryption algorithms used for authentication of different types of authentication fields are not necessarily the same, the first authentication digest and authentication parameters can be identified from the authentication field based on the field structure in this step.

[0050] Specifically, for different types, since the implementation methods of their encrypted storage are different, the lengths of the authentication digest and authentication parameters in the corresponding authentication field may vary. In this step, the specific positions of the first authentication digest and authentication parameters in the authentication field can be determined according to the field structure, and then the first authentication digest and authentication parameters can be identified from the authentication field.

[0051] The authentication calculation model represents the calculation model for calculating the authentication digest. Generally, the authentication calculation model is implemented according to the used authentication algorithm. For example, when using SM3 for encryption calculation, the authentication calculation model is the calculation model corresponding to SM3. Since different types use different encryption algorithms, in this step, the corresponding authentication calculation model can be obtained based on the type.

[0052] Specifically, in the embodiments of the present invention, multiple encryption algorithms can be supported. Therefore, the algorithm identifier based on the encryption algorithm represents the type identifier. For the type of ciphertext authentication, a general algorithm can be used for authentication calculation. So, in this step, obtaining the authentication calculation model can be executed as follows: in response to the type identifier belonging to the first type, obtain the corresponding authentication calculation model based on the type identifier; in response to the type identifier belonging to the second type, obtain the authentication calculation model corresponding to the second type.

[0053] The first type can represent the authentication processing type when the information to be authenticated is plaintext, and the second type can represent the authentication processing type when the information to be authenticated is ciphertext. In the first type, the type identifier represents the used encryption algorithm, so the corresponding authentication calculation model can be obtained according to the type identifier; in the second type, a general encryption algorithm can be set, so the authentication calculation model corresponding to the second type can be obtained.

[0054] It should be noted that in some scenarios, the second type usually does not encrypt the information to be authenticated again. Therefore, the authentication calculation model corresponding to the second type can specifically be a model that does not perform data processing, that is, directly use the ciphertext to be stored as the authentication digest.

[0055] In one implementation, in the embodiments of the present invention, a preset identifier can be set to represent the second type. Therefore, if the type identifier includes the preset mark, it can be determined that it belongs to the second type; if the type identifier does not include the preset mark, it can be determined that it belongs to the first type. Furthermore, after determining the type to which the type identifier belongs, the associated field structure and the corresponding authentication calculation model can be obtained. The preset mark can be set according to requirements, for example, set to OA, etc.

[0056] S304: Obtain the information to be authenticated from the request information, call the authentication calculation model, and calculate the second authentication digest by combining the authentication parameters and the information to be authenticated, so as to compare with the first authentication digest to obtain the authentication result.

[0057] Among them, for the information to be authenticated, it can be encrypted and calculated through the authentication calculation model in combination with the authentication parameters to obtain the second authentication digest, and then the authentication result can be obtained by comparing the first authentication digest and the second authentication digest.

[0058] Specifically, if the comparison result of the first authentication digest and the second authentication digest is that they are the same, it can be determined that the authentication result is authentication passed; if the comparison result of the first authentication digest and the second authentication digest is that they are different, it can be determined that the authentication result is authentication failed.

[0059] Taking the authentication calculation model as the SM3 calculation model as an example, the information to be authenticated is specifically the user password, and the authentication parameter can be the string of the last 8 digits in the authentication field. Then, the user password and the 8-digit string can be input into the SM3 calculation model to obtain a calculation result, and then it is compared with the first authentication digest identified in the authentication field to obtain the authentication result.

[0060] S305: Send the authentication result to the client.

[0061] Among them, after obtaining the authentication result, it can be returned to the client. Specifically, it can be first sent to the gateway device, and the gateway device encrypts it again and then sends it to the corresponding client, thereby improving the security of data transmission.

[0062] In another implementation manner, the client can also write authentication information according to requirements for subsequent authentication processing. Therefore, the embodiments of the present invention can also execute: receiving a storage request for authentication information, obtaining the corresponding user information and authentication password; identifying the type to which the authentication password belongs, determining the corresponding type identifier based on the type, and generating an authentication string based on the authentication password; generating an authentication field based on the field structure associated with the type, the authentication string, and the type identifier, establishing a corresponding relationship with the user information in the storage request and storing it.

[0063] In the embodiments of the present invention, the authentication password in the storage request can be identified to determine whether it is in plaintext or ciphertext, and then determine the type to which it belongs, so as to determine the corresponding processing method to generate the authentication field. In this step, the authentication password can be processed to obtain an authentication string, and then the authentication string is stored according to the field structure of the authentication field to generate an authentication field, and then the authentication digest and authentication parameter can be determined.

[0064] It should be noted that the types to which the authentication password belongs can specifically include: the authentication processing type when the authentication password is in plaintext and the authentication processing type when the authentication password is in ciphertext. Therefore, determine whether it is in plaintext or ciphertext, then determine the type to which it belongs, and then determine the storage method.

[0065] Specifically, in the above process, after determining that the authentication password belongs to the first type, it can be said that the authentication password is in plain text, and encryption processing needs to be performed, that is, obtaining the associated algorithm identifier to determine the corresponding type identifier, and generating an authentication string based on the authentication calculation model and the authentication password associated with the algorithm identifier; after determining that the authentication password belongs to the second type, obtaining the associated type tag, that is, the preset tag corresponding to the second type, to determine the corresponding type identifier, and generating an authentication string based on the authentication calculation model and the authentication password associated with the second type.

[0066] It should be noted that after determining that the authentication password belongs to the first type, the associated algorithm identifier can be obtained according to the storage request, that is, the service identifier is stored in the storage request, and the preset algorithm identifier is queried according to the service identifier, or the storage request does not limit the algorithm, then in the embodiment of the present invention, the algorithm identifier can be obtained randomly, or the algorithm identifier can be obtained according to the priority of each algorithm, etc. After determining that the authentication password belongs to the second type, a general algorithm is usually used for processing, that is, the general authentication calculation model associated with the second type.

[0067] It should be noted that a salt value is usually used in the process of generating an authentication field. In the embodiment of the present invention, the salt value can be determined according to the generation requirement and stored according to the field structure.

[0068] In an embodiment of the present invention, different field structures and authentication calculation models can be set according to the type, so that when performing information authentication, the authentication summary and authentication parameters can be identified according to the field structure of the type, and then the authentication summary to be compared can be calculated and compared through the corresponding authentication calculation model. In this way, information authentication can be performed based on a variety of national secret algorithms to meet the needs of different authentication services and scenarios, making the application scope more extensive; and, in an embodiment of the present invention, different field structures can be set for each type to improve the security and accuracy of data storage.

[0069] It should be noted that in Figure 1 In the system architecture shown, the gateway device can establish connections with multiple LDAP servers, so when executing the authentication process in the above embodiment, the gateway device can send the request sent by the client to one or more LDAP servers according to the preset routing policy. For example, the gateway device can determine the LDAP server to which the request information is to be sent according to the operating status of each LDAP server. In order to avoid excessive concentration of request information on some LDAP servers, each LDAP server can report its operating data at regular intervals. The operating data can specifically include the request information to be processed and the response time of the request information. Then, the gateway device can determine the busyness of each LDAP server based on this parameter, so as to determine the LDAP server that will subsequently process the request information according to the busyness.

[0070] Therefore, in the embodiments of the present invention, the LDAP server may further execute: in response to a status reporting task, query the authentication time parameters corresponding to each request message within a preset time period, calculate the processing efficiency of the request message, and obtain the number of corresponding request messages in the to-be-processed queue, so as to send the number and the processing efficiency to the gateway device. The status reporting task may be pre-configured and periodically triggered. The authentication time parameters may include the start time and the end time for processing the request message, and thus the average processing duration for processing the request message within the preset time period, that is, the processing efficiency, may be calculated. The to-be-processed queue is pre-configured and may be used to store the request messages to be processed.

[0071] Next, in combination with Figure 1 the embodiments shown below, the data processing method in the embodiments of the present invention will be specifically described. As Figure 4 shown below, the method includes the following steps.

[0072] S401: Receive the request message sent by the gateway device.

[0073] S402: Obtain the user information in the request message, query the corresponding authentication field, and extract the type identifier in the authentication field.

[0074] S403: Identify whether the type identifier includes a preset flag; in response to the type identifier including the preset flag, determine that the type identifier belongs to the first type, and obtain the field structure associated with the first type; in response to the type identifier not including the preset flag, determine that the type identifier belongs to the second type, and obtain the field structure associated with the second type.

[0075] S404: Identify the first authentication digest and the authentication parameters from the authentication field according to the field structure.

[0076] S405: In response to the type identifier belonging to the first type, obtain the corresponding authentication calculation model based on the type identifier; in response to the type identifier belonging to the second type, obtain the authentication calculation model corresponding to the second type.

[0077] S406: Obtain the information to be authenticated from the request message, call the authentication calculation model, calculate the second authentication digest in combination with the authentication parameters and the information to be authenticated, and compare it with the first authentication digest to obtain the authentication result.

[0078] S407: Send the authentication result to the client.

[0079] It should be noted that the data processing principle in the embodiments of the present invention is the same as the corresponding data processing principle in the Figure 3 embodiments shown, and will not be elaborated here.

[0080] To solve the problems existing in the prior art, the embodiments of the present invention provide a data processing device 500, asFigure 5 As shown, the device 500 includes: a receiving unit 501, configured to receive request information sent by a gateway device, where the request information is sent after the gateway device decrypts a request sent by a client; an extracting unit 502, configured to obtain user information in the request information, query corresponding authentication fields, and extract a type identifier in the authentication fields; an obtaining unit 503, configured to obtain a field structure associated with the type identifier, so as to identify a first authentication digest and authentication parameters from the authentication fields, and obtain a corresponding authentication calculation model based on the type identifier; an authentication unit 504, configured to obtain information to be authenticated from the request information, call the authentication calculation model, calculate a second authentication digest by combining the authentication parameters and the information to be authenticated, and compare the second authentication digest with the first authentication digest to obtain an authentication result; and a sending unit 505, configured to send the authentication result to the client.

[0081] It should be understood that the implementation manner of the embodiments of the present invention is the same as that of the embodiments Figure 3 shown, and will not be described herein again.

[0082] In one embodiment, the obtaining unit 503 is specifically configured to: in response to the type identifier belonging to a first type, obtain a corresponding authentication calculation model based on the type identifier; and in response to the type identifier belonging to a second type, obtain an authentication calculation model corresponding to the second type.

[0083] In another embodiment, the obtaining unit 503 is specifically configured to: identify whether the type identifier includes a preset flag; in response to the type identifier including the preset flag, determine that the type identifier belongs to the first type, and obtain a field structure associated with the first type; and in response to the type identifier not including the preset flag, determine that the type identifier belongs to the second type, and obtain a field structure associated with the second type.

[0084] In another embodiment, the receiving unit 501 is further configured to receive a storage request for authentication information, and obtain corresponding user information and an authentication password; the device 500 further includes: a generating unit, configured to identify a type to which the authentication password belongs, so as to determine a corresponding type identifier based on the type, and generate an authentication string based on the authentication password; and a establishing unit, configured to generate an authentication field based on the field structure associated with the type, the authentication string, and the type identifier, and establish a corresponding relationship with the user information in the storage request and store it.

[0085] In another embodiment, the generating unit is specifically used to: in response to the authentication password belonging to the first type, obtain the algorithm identifier associated with the authentication information to determine the corresponding type identifier, and generate an authentication string based on the authentication calculation model associated with the algorithm identifier and the authentication password; in response to the authentication password belonging to the second type, obtain the associated type tag to determine the corresponding type identifier, and generate an authentication string based on the authentication calculation model associated with the second type and the authentication password.

[0086] In another embodiment, the device 500 also includes: a reporting unit, which is used to respond to the status reporting task, query the authentication time parameters corresponding to each request information within a preset time period, calculate the processing time of the request information, and obtain the number of corresponding request information in the queue to be processed, so as to send the number and the processing time to the gateway device.

[0087] In yet another embodiment, the sending unit 505 is specifically configured to send the authentication result to the gateway device, so that the gateway device encrypts the authentication result and then sends it to the client.

[0088] It should be understood that the manner of implementing the embodiments of the present invention is different from the Figure 3 , 4 The method of the illustrated embodiment is the same and will not be repeated here.

[0089] In an embodiment of the present invention, different field structures and authentication calculation models can be set according to the type, so that when performing information authentication, the authentication summary and authentication parameters can be identified according to the field structure of the type, and then the authentication summary to be compared can be calculated and compared through the corresponding authentication calculation model. In this way, information authentication can be performed based on a variety of national secret algorithms to meet the needs of different authentication services and scenarios, making the application scope more extensive; and, in an embodiment of the present invention, different field structures can be set for each type to improve the security and accuracy of data storage.

[0090] According to an embodiment of the present invention, the embodiment of the present invention further provides an electronic device and a readable storage medium.

[0091] The electronic device of an embodiment of the present invention comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the one processor, and the instructions are executed by the at least one processor so that the at least one processor executes the data processing method provided by the embodiment of the present invention.

[0092] Figure 6 An exemplary system architecture 600 is shown to which the data processing method or data processing apparatus according to the embodiment of the present invention can be applied.

[0093] As shown Figure 6 in FIG. 2, the system architecture 600 may include terminal devices 601, 602, 603, a network 604, and a server 605. The network 604 serves as a medium for providing a communication link between the terminal devices 601, 602, 603 and the server 605. The network 604 may include various connection types, such as wired, wireless communication links, or fiber optic cables, etc.

[0094] Users can use the terminal devices 601, 602, 603 to interact with the server 605 via the network 604 to receive or send messages, etc. Various client applications may be installed on the terminal devices 601, 602, 603.

[0095] The terminal devices 601, 602, 603 may be various electronic devices with a display screen and supporting web browsing, including but not limited to smartphones, tablets, laptop computers, and desktop computers, etc.

[0096] The server 605 may be a server that provides various services. The server may analyze and process data such as product information query requests received, and feedback the processing results (such as product information - only for example) to the terminal devices.

[0097] It should be noted that the data processing method provided by the embodiments of the present invention is generally executed by the server 605. Correspondingly, the data processing device is generally disposed in the server 605.

[0098] It should be understood Figure 6 that the numbers of terminal devices, networks, and servers in FIG. 2 are merely illustrative. According to the implementation requirements, there may be any number of terminal devices, networks, and servers.

[0099] Next, referring to Figure 7 FIG. 3, there is shown a schematic structural diagram of a computer system 700 suitable for implementing the embodiments of the present invention. Figure 7 The computer system shown is merely an example and should not impose any limitation on the functions and usage scope of the embodiments of the present invention.

[0100] As shown Figure 7 in FIG. 3, the computer system 700 includes a central processing unit (CPU) 701, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 702 or the program loaded from the storage section 708 into the random access memory (RAM) 703. In the RAM 703, various programs and data required for the operation of the system 700 are also stored. The CPU 701, ROM 702, and RAM 703 are connected to each other via a bus 704. The input / output (I / O) interface 705 is also connected to the bus 704.

[0101] The following components are connected to the I / O interface 705: an input part 706 including a keyboard, a mouse, etc.; an output part 707 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc. and a speaker, etc.; a storage part 708 including a hard disk, etc.; and a communication part 709 including a network interface card such as a LAN card, a modem, etc. The communication part 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the I / O interface 705 as needed. A removable medium 711, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 710 as needed so that a computer program read from it is installed into the storage part 708 as needed.

[0102] Specifically, according to the embodiments disclosed in the present invention, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present invention include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from a network through the communication part 709, and / or installed from the removable medium 711. When the computer program is executed by a central processing unit (CPU) 701, the above-mentioned functions defined in the system of the present invention are executed.

[0103] It should be noted that the computer-readable medium shown in the present invention can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the above two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present invention, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present invention, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which the computer-readable program code is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wireless, wire, optical cable, RF, etc., or any suitable combination of the above.

[0104] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram can represent a unit, a program segment, or a part of code, and the above unit, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, and the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0105] The units involved in the embodiments of the present invention can be implemented in software or in hardware. The described units can also be provided in a processor. For example, it can be described as: a processor includes a receiving unit, an extracting unit, an obtaining unit, an authenticating and sending unit. Among them, the names of these units do not constitute a limitation to the unit itself in some cases. For example, the receiving unit can also be described as "a unit with receiving function".

[0106] As another aspect, the present invention also provides a computer-readable medium, which can be included in the device described in the above embodiments; or it can exist alone without being assembled into the device. The above computer-readable medium carries one or more programs. When the above one or more programs are executed by the device, the device is caused to execute the data processing method provided by the present invention.

[0107] As another aspect, the present invention also provides a computer program product, including a computer program, and the program realizes the data processing method provided by the embodiments of the present invention when executed by a processor.

[0108] The above specific embodiments do not limit the protection scope of the present invention. Those skilled in the art should understand that various modifications, combinations, sub-combinations and substitutions can occur depending on design requirements and other factors. Any modifications, equivalent substitutions and improvements made within the spirit and principle of the present invention shall be included within the protection scope of the present invention.

Claims

1. A method for data processing, characterized in that, including: Receiving request information sent by a gateway device, where the request information is sent by the gateway device after decrypting a request sent by a client; Obtaining user information in the request information, querying corresponding authentication fields, and extracting type identifiers in the authentication fields; Obtaining a field structure associated with the type identifier to identify a first authentication digest and authentication parameters from the authentication fields, and obtaining a corresponding authentication calculation model based on the type identifier; Obtaining information to be authenticated from the request information, invoking the authentication calculation model, calculating a second authentication digest in combination with the authentication parameters and the information to be authenticated, and comparing it with the first authentication digest to obtain an authentication result; Sending the authentication result to the client.

2. The method according to claim 1, wherein Obtaining a corresponding authentication calculation model based on the type identifier includes: In response to the type identifier belonging to a first type, obtaining a corresponding authentication calculation model based on the type identifier; in response to the type identifier belonging to a second type, obtaining the authentication calculation model corresponding to the second type.

3. The method according to claim 1 or 2, characterized in that, Obtaining a field structure associated with the type identifier includes: Identifying whether the type identifier includes a preset mark; In response to the type identifier including a preset mark, determining that the type identifier belongs to the first type and obtaining the field structure associated with the first type; in response to the type identifier not including a preset mark, determining that the type identifier belongs to the second type and obtaining the field structure associated with the second type.

4. The method according to claim 1, wherein The method further includes: Receiving a storage request for authentication information, and obtaining corresponding user information and an authentication password; Identifying the type to which the authentication password belongs to determine a corresponding type identifier based on the type, and generating an authentication string based on the authentication password; Generating an authentication field based on the field structure associated with the type, the authentication string, and the type identifier to establish a correspondence with the user information in the storage request and store it.

5. The method according to claim 4, characterized in that, Determining a corresponding type identifier based on the type, and generating an authentication string based on the authentication password includes: In response to the authentication password belonging to the first type, obtaining an algorithm identifier associated with the authentication information to determine a corresponding type identifier, and generating an authentication string based on the authentication calculation model associated with the algorithm identifier and the authentication password; in response to the authentication password belonging to the second type, obtaining an associated type mark to determine a corresponding type identifier, and generating an authentication string based on the authentication calculation model associated with the second type and the authentication password.

6. The method according to claim 1, wherein The method further includes: In response to a status reporting task, querying authentication time parameters corresponding to each request information within a preset time period, calculating the processing efficiency of the request information, and obtaining the number of corresponding request information in the to-be-processed queue to send the number and the processing efficiency to the gateway device.

7. The method according to claim 1, wherein Sending the authentication result to the client includes: Sending the authentication result to the gateway device so that the gateway device encrypts the authentication result and sends it to the client.

8. A data processing device, characterized in that, including: A receiving unit for receiving request information sent by a gateway device, where the request information is sent by the gateway device after decrypting a request sent by a client; An extraction unit, configured to obtain user information in the request information, query corresponding authentication fields, and extract type identifiers in the authentication fields; An acquisition unit, configured to obtain a field structure associated with the type identifier, so as to identify a first authentication digest and authentication parameters from the authentication fields, and obtain a corresponding authentication calculation model based on the type identifier; An authentication unit, configured to obtain information to be authenticated from the request information, call the authentication calculation model, calculate a second authentication digest in combination with the authentication parameters and the information to be authenticated, and compare it with the first authentication digest to obtain an authentication result; A sending unit, configured to send the authentication result to the client.

9. An electronic device, characterized in that, Comprising: One or more processors; A storage device, configured to store one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1-7.

10. A computer-readable medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, the method according to any one of claims 1-7 is implemented.

11. A computer program product, comprising a computer program, characterized in that, When the program is executed by a processor, the method according to any one of claims 1-7 is implemented.

Citation Information

Patent Citations

  • Method and device for remembering log in information, log in control method and device

    CN106685973A

  • Multi-client collaborative authentication method and device for feature recognition, equipment and medium

    CN113259136A

  • Multiple authentication support in a shared environment

    US20120054357A1

  • Analysis system for test artifact generation

    US20120272206A1

  • Object-based security system

    US6330677B1