Authentication access method and device for custom signature applied to formation and capacity grading
Through the authentication access method of custom signatures, the target token is generated and verified, which solves the problem of insufficient authentication security and efficiency in the component storage device, and realizes efficient authentication of stateless response.
Patent Information
- Application Number
- CN202510905272.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-02
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2045-07-02
AI Technical Summary
In the authentication mechanism of chemical component capacitance equipment and associated platforms, the prior art has low security and insufficient efficiency, which makes it difficult to adapt to the requirements of dynamic and high concurrency industrial environment. Especially in data interaction in the fields of battery manufacturing and energy management, traditional authentication methods are easily tampered with and difficult to expand.
The authentication access method of custom signature is adopted. The server generates and sends the target token, and the client stores and uses the token for re-access. The server verifies the legitimacy of the token through an encryption algorithm, supports user-defined signatures, and improves security and efficiency.
It realizes efficient and secure authentication access in the ingredient content scenario, and the server does not need to save client or token information, which improves the flexibility and scalability of the system.
Smart Images

Figure CN120433932A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data verification, and particularly to an authentication access method and device for custom signatures applied to chemical formation and grading. Background Art
[0002] With the rapid development of industrial intelligence and cross-system collaboration, the applications of chemical formation and grading equipment and associated platforms in fields such as battery manufacturing and energy management have become increasingly complex. During the battery production process, the chemical formation (activation) and grading (capacity sorting) processes rely on high-frequency data interaction between multiple systems, such as equipment control instructions, process parameter transmission, and real-time status monitoring. In such scenarios, security authentication has become the core requirement for ensuring data integrity and preventing unauthorized operations. Traditional authentication methods based on username and password or fixed sessions are difficult to meet the requirements of dynamic and high-concurrency industrial environments. There is an urgent need for a lightweight, stateless, and tamper-proof authentication mechanism to adapt to the efficient and trusted interaction between distributed systems.
[0003] Currently, HTTP basic authentication, Session-Cookie, or traditional Token solutions are commonly used in the industry, but they all have significant drawbacks: the credentials of HTTP basic authentication are easily intercepted and decoded, resulting in low security; Session-Cookie relies on the server to store the session state, leading to a sharp increase in server resource pressure and difficulty in expansion; traditional Token solutions require the server to maintain the token state, increasing the database query overhead, and lacking an anti-tampering mechanism, making them vulnerable to forgery or replay attacks. In addition, existing technologies lack support for dynamic expiration times and independent verification of client information, and are difficult to adapt to the flexibility and security requirements of chemical formation and grading scenarios. Therefore, it is particularly important to propose a technical solution that can support user-defined signature authentication and improve authentication security and efficiency. Summary of the Invention
[0004] The present invention provides an authentication access method and device for custom signatures applied to chemical formation and grading, which can support user-defined signature authentication and improve authentication security and efficiency.
[0005] To solve the above technical problems, in a first aspect, the present invention discloses an authentication access method for custom signatures applied to chemical formation and grading, the method comprising: When the server detects a first access operation of the client, a payload is generated based on the input information sent by the client, the input information including user information, system information, and expiration time; The server determines the header information of the target token and a preset secret key, the header information including the token type and encryption algorithm of the target token; The server encrypts the header information, the payload, and the secret key according to the encryption algorithm to obtain a signature; The server generates the target token based on the header information, the payload, and the signature, and sends the target token to the client; The client stores the received target token. When the client performs a re - access operation on the server, the client generates an access request corresponding to the re - access operation based on the target token, and sends the access request to the server; The server performs authentication confirmation on the access operation according to the target token in the access request, obtains an authentication result, and responds to the access request according to the authentication result.
[0006] As an optional implementation manner, in the first aspect of the present invention, the server performs authentication confirmation on the access operation according to the target token in the access request, and obtains an authentication result, including: The server analyzes the target token in the access request to obtain the parsed target header information, target payload, and target signature; The server performs encryption processing on the target header information, the target payload, and the secret key according to the encryption algorithm to obtain a verification signature; The server determines whether the verification signature matches the target signature to obtain an authentication result.
[0007] As an optional implementation manner, in the first aspect of the present invention, before the server analyzes the target token in the access request, the method further includes: The server detects whether the access request contains the target token to obtain a detection result; When the detection result indicates that the access request does not contain the target token, the server returns a first error code to the client, and the first error code indicates that the target token is missing in the access request.
[0008] As an optional implementation manner, in the first aspect of the present invention, the method further includes: The server obtains the expiration time in the parsed target payload, and determines whether the target token in the access request has expired and become invalid according to the expiration time, to obtain a judgment result; When the judgment result indicates that the target token has expired and become invalid, the server returns a second error code to the client, and the second error code indicates that the target token has expired and become invalid.
[0009] As an optional implementation manner, in the first aspect of the present invention, the server encrypts the header information, the payload, and the secret key according to the encryption algorithm to obtain a signature, including: The server performs deserialization processing on the payload to obtain a string corresponding to the payload; The server encodes the string corresponding to the payload according to a preset encoding algorithm to obtain an encoded string corresponding to the payload; The server encrypts the header information, the encoded string, and the secret key according to the encryption algorithm to obtain a signature.
[0010] As an optional implementation manner, in the first aspect of the present invention, the server encrypts the header information, the encoded string, and the secret key according to the encryption algorithm to obtain a signature, including: The server encodes the header information according to the encoding algorithm to obtain an encoded string corresponding to the header information; The server determines a target string according to the encoded string corresponding to the payload and the encoded string corresponding to the header information; The server encrypts the target string and the secret key according to the encryption algorithm to obtain a signature.
[0011] As an optional implementation manner, in the first aspect of the present invention, the encoding algorithm includes the Base64Url encoding algorithm, and the encryption algorithm includes the HMACSHA256 algorithm.
[0012] The second aspect of the present invention discloses an authentication access device for a custom signature applied to charge and discharge capacity testing. The device includes a server and a client. The server includes a first generation module, a determination module, an encryption module, and an authentication module. The client includes a storage module and a second generation module, where: The first generation module is configured to generate a payload based on input information sent by the client when detecting a first access operation of the client. The input information includes user information, system information, and an expiration time; The determination module is configured to determine the header information of the target token and a preset secret key. The header information includes the token type and encryption algorithm of the target token; The encryption module is configured to encrypt the header information, the payload, and the secret key according to the encryption algorithm to obtain a signature; The first generation module is further configured to generate the target token according to the header information, the payload, and the signature, and send the target token to the client; The storage module is used to store the received target token; The second generation module is used to generate an access request corresponding to the re - access operation based on the target token when the client performs a re - access operation on the server, and send the access request to the server; The authentication module is used to perform authentication confirmation on the access operation according to the target token in the access request to obtain an authentication result, and respond to the access request according to the authentication result.
[0013] As an optional implementation manner, in the second aspect of the present invention, the manner in which the authentication module performs authentication confirmation on the access operation according to the target token in the access request to obtain an authentication result specifically includes: Parse the target token in the access request to obtain parsed target header information, target payload, and target signature; According to the encryption algorithm, perform encryption processing on the target header information, the target payload, and the secret key to obtain a verification signature; Judge whether the verification signature matches the target signature to obtain an authentication result.
[0014] As an optional implementation manner, in the second aspect of the present invention, the server further includes a detection module, where: The detection module is used to detect whether the access request contains the target token before the authentication module parses the target token in the access request to obtain a detection result; when the detection result indicates that the access request does not contain the target token, the detection module returns a first error code to the client, and the first error code indicates that the target token is missing in the access request.
[0015] As an optional implementation manner, in the second aspect of the present invention, the server further includes an acquisition module and a judgment module, where: The acquisition module is used to acquire the expiration time in the parsed target payload; The judgment module is used to judge whether the target token in the access request has expired and become invalid according to the expiration time to obtain a judgment result; when the judgment result indicates that the target token has expired and become invalid, the judgment module returns a second error code to the client, and the second error code indicates that the target token has expired and become invalid.
[0016] As an optional implementation manner, in the second aspect of the present invention, the manner in which the encryption module performs encryption processing on the header information, the payload, and the secret key according to the encryption algorithm to obtain a signature specifically includes: Deserialize the payload to obtain the string corresponding to the payload; Encode the string corresponding to the payload according to a preset encoding algorithm to obtain the encoded string corresponding to the payload; According to the encryption algorithm, encrypt the header information, the encoded string, and the secret key to obtain a signature.
[0017] As an optional implementation manner, in the second aspect of the present invention, the manner in which the encryption module encrypts the header information, the encoded string, and the secret key according to the encryption algorithm to obtain a signature specifically includes: The server encodes the header information according to the encoding algorithm to obtain the encoded string corresponding to the header information; The server determines a target string according to the encoded string corresponding to the payload and the encoded string corresponding to the header information; The server encrypts the target string and the secret key according to the encryption algorithm to obtain a signature.
[0018] As an optional implementation manner, in the second aspect of the present invention, the encoding algorithm includes the Base64Url encoding algorithm, and the encryption algorithm includes the HMACSHA256 algorithm.
[0019] The third aspect of the present invention discloses another authentication access device for custom signatures applied to cell formation and discharging, and the device includes: A memory storing executable program code; A processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the authentication access method for custom signatures applied to cell formation and discharging disclosed in the first aspect of the present invention.
[0020] The fourth aspect of the present invention discloses a computer storage medium, and the computer storage medium stores computer instructions, which are used to execute the authentication access method for custom signatures applied to cell formation and discharging disclosed in the first aspect of the present invention when being called.
[0021] Compared with the prior art, the embodiments of the present invention have the following beneficial effects: In an embodiment of the present invention, when the server detects the first access operation of the client, it generates a payload based on the input information sent by the client. The server determines the header information of the target token and a preset secret key. According to the encryption algorithm, the server encrypts the header information, the payload, and the secret key to obtain a signature. The server generates a target token based on the header information, the payload, and the signature, and sends the target token to the client. The client stores the received target token. When the client performs a re-access operation on the server, the client generates an access request corresponding to the re-access operation based on the target token, and sends the access request to the server. The server performs authentication confirmation on the access operation according to the target token in the access request to obtain an authentication result, and responds to the access request according to the authentication result. It can be seen that implementing the present invention can support user-defined signature authentication, improve the security and efficiency of authentication, and the server does not need to save client or token information, and can achieve a stateless response. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0023] Figure 1 It is a flowchart showing an authentication access method with a custom signature applied to chemical component separation and capacitance measurement in an embodiment of the present invention; Figure 2 It is a flowchart showing another authentication access method with a custom signature applied to chemical component separation and capacitance measurement in an embodiment of the present invention; Figure 3 It is a structural diagram showing an authentication access device with a custom signature applied to chemical component separation and capacitance measurement in an embodiment of the present invention; Figure 4 It is a structural diagram showing another authentication access device with a custom signature applied to chemical component separation and capacitance measurement in an embodiment of the present invention; Figure 5 It is a structural diagram showing another authentication access device with a custom signature applied to chemical component separation and capacitance measurement in an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0024] To enable those skilled in the art to better understand the solution of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0025] The terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, device, product or terminal that includes a series of steps or units is not limited to the listed steps or units, but optionally further includes steps or units not listed, or optionally further includes other steps or units inherent to these processes, methods, products or terminals.
[0026] Referring to "embodiment" herein means that a specific feature, structure or characteristic described in conjunction with the embodiment may be included in at least one embodiment of the present invention. The occurrence of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0027] The present invention discloses an authentication access method and device for custom signatures applied to charge and capacity testing, which can support user-defined signature authentication, improve authentication security and efficiency, and the server does not need to save client or token information, and can achieve a stateless response. The following will be described in detail respectively.
[0028] Embodiment 1 Please refer to Figure 1 , Figure 1 is a schematic flowchart of an authentication access method for custom signatures applied to charge and capacity testing disclosed in an embodiment of the present invention. Among them, Figure 1 The described authentication access method for custom signatures applied to charge and capacity testing can be applied to an authentication access device for custom signatures applied to charge and capacity testing. Among them, the authentication access device for custom signatures applied to charge and capacity testing can include an intelligent server or an intelligent platform for authentication verification. The intelligent server includes a local server or a cloud server, and the embodiments of the present invention do not make limitations. As Figure 1 shown, the authentication access method for custom signatures applied to charge and capacity testing can include the following operations: When the server detects the first access operation of the client, it generates a payload based on the input information sent by the client.
[0029] In an embodiment of the present invention, optionally, a user can access the server through the client. When the user first accesses the server through the client, the user needs to log in or register a user account on the client. For example, when the user registers an account on the client, the user will input user information, which may include information such as user ID, user code, user name, login password, etc. When the user first accesses the server through the client, that is, when the server detects the first access operation of the client, the client will send input information to the server. The input information may include user information, system information, and expiration time. Among them, the user information may include one or more combinations of information such as user ID, user code, user name, login password, etc. The system information may include system name and / or system version. The expiration time may be set by the user or automatically set by the client, and the present invention does not make a limitation.
[0030] In an embodiment of the present invention, optionally, in an embodiment of the present invention, the code for generating the payload may be as follows: JWTPayload jWTPayload = new JWTPayload { UserId = theUser.Id, UserCode = theUser.UserName, UserName = theUser.RealName, StorerName= theStorer.StorerName, SystemName= theStorer.SystemName, SystemVersion= theStorer.SystemVersion, Expire=DateTime.Now.AddHours(Convert.ToDouble(theUser.ExpireTimes)) } 102. The server determines the header information of the target token and the preset secret key.
[0031] In an embodiment of the present invention, optionally, the target token may include a JSON Web Token (JWT) token, which can be used to transfer the authenticated identity information between the identity provider and the service provider to implement authentication access. The JWT may include three parts: a header, a payload, and a signature. Among them, the header is used to record the token type and the signature algorithm, that is, the header information includes the token type and the encryption algorithm of the target token. The payload can be used to carry the stored data, including user code, user name, expiration time, etc. The signature is used to prevent tampering and ensure security. The signature can be calculated or a user-defined string, which is not limited in the present invention.
[0032] In an embodiment of the present invention, optionally, the preset secret key may be a string customized on the server side, such as ZeqpzEqpzeQpzeqP, or the content of an electronic encryption dog. That is, the server reads the ciphertext of the encryption dog and decrypts it to obtain the secret key, which is not limited in the present invention.
[0033] 103. The server encrypts the header information, the payload, and the secret key according to the encryption algorithm to obtain the signature.
[0034] In an embodiment of the present invention, optionally, the server may encrypt the header information, the payload, and the secret key according to the encryption algorithm to obtain the signature. Specifically, the header information and the payload can be encoded, and then the encoded header information and payload are calculated according to the encryption algorithm to obtain the signature. The signature can also be a user-defined fixed string, which is not limited in the present invention.
[0035] 104. The server generates a target token based on the header information, the payload, and the signature, and sends the target token to the client.
[0036] In an embodiment of the present invention, optionally, the server may combine the header information, the payload, and the signature to generate the target token, or generate the target token by means of function call. Specifically: public static string GetToken(string payloadJsonStr, string secret) { string payloadBase64Url = payloadJsonStr.Base64UrlEncode();stringsign=$"{_headerBase64Url}.{payloadBase64Url}".ToHMACSHA256String(secret); return $"{_headerBase64Url}.{payloadBase64Url}.{sign}"; } 105. The client stores the received target token. When the client performs a re - access operation on the server, the client generates an access request corresponding to the re - access operation based on the target token and sends the access request to the server.
[0037] In an embodiment of the present invention, optionally, after receiving the target token sent by the server, the client stores the received target token. Specifically, the client can store the target token in localStorage, sessionStorage or Cookie. When the client performs a re - access operation on the server, that is, when it detects that the user logs in to the server through the client, requests data from the server or performs a specific operation on the server and other access operations, the client can generate an access request corresponding to the access operation based on the target token. Specifically, the client can attach the target token in the Authorization header to generate the access request. The client sends the access request to the server to implement the access operation on the server, and the present invention does not make a limitation.
[0038] 106. The server performs authentication and confirmation on the access operation according to the target token in the access request, obtains an authentication result, and responds to the access request according to the authentication result.
[0039] In an embodiment of the present invention, optionally, the server can perform authentication and confirmation on the access operation according to the target token in the access request, obtain an authentication result, and respond to the access request according to the authentication result. For example, when the authentication result indicates that the access operation is legal, the server can authorize the client to perform the access operation, and the present invention does not make a limitation.
[0040] It can be seen that in the implementation Figure 1The described authentication access method for custom signatures applied to charge and capacity testing can generate a payload based on the input information sent by the client when the server detects the first access operation of the client. The server determines the header information of the target token and the preset secret key, and according to the encryption algorithm, encrypts the header information, payload, and secret key to obtain a signature. The server generates the target token based on the header information, payload, and signature, and sends the target token to the client, which can support user-defined signature authentication, improve the security and accuracy of authentication. The client stores the received target token. When the client performs a re-access operation on the server, the client generates an access request corresponding to the re-access operation based on the target token and sends the access request to the server. The server authenticates the access operation based on the target token in the access request to obtain an authentication result and responds to the access request according to the authentication result, which can support user-defined signature authentication, improve the security and efficiency of authentication, and the server does not need to save client or Token information, and can achieve a stateless response.
[0041] In an optional embodiment, the server encrypts the header information, payload, and secret key according to the encryption algorithm to obtain the signature, which may include the following operations: The server deserializes the payload to obtain the string corresponding to the payload; The server encodes the string corresponding to the payload according to the preset encoding algorithm to obtain the encoded string corresponding to the payload; The server encrypts the header information, encoded string, and secret key according to the encryption algorithm to obtain the signature.
[0042] In this optional embodiment, optionally, the server can deserialize the payload to obtain the string corresponding to the payload, and then encode the string corresponding to the payload according to the preset encoding algorithm to obtain the encoded string corresponding to the payload. The preset encoding algorithm may include the Base64Url encoding algorithm. Specifically: public static string Base64UrlEncode(this string text) { var plainTextBytes = Encoding.UTF8.GetBytes(text); var base64 = Convert.ToBase64String(plainTextBytes).Replace('+','-').Replace(' / ', '_').TrimEnd('='); return base64; } In this optional embodiment, optionally, the server can encrypt the header information, the encoded string, and the secret key according to an encryption algorithm to obtain a signature. The encryption algorithm can include the HMACSHA256 algorithm. Specifically: public static string ToHMACSHA256String(this string text, stringsecret) { secret = secret ?? ""; byte[] keyByte = Encoding.UTF8.GetBytes(secret); byte[] messageBytes = Encoding.UTF8.GetBytes(text); using (var hmacsha256 = new HMACSHA256(keyByte)) { byte[] hashmessage = hmacsha256.ComputeHash(messageBytes); return Convert.ToBase64String(hashmessage).Replace('+', '-').Replace(' / ', '_').TrimEnd('='); } } It can be seen that implementing this optional embodiment can enable the server to deserialize the payload to obtain the string corresponding to the payload, the server encodes the string corresponding to the payload according to a preset encoding algorithm to obtain the encoded string corresponding to the payload, and the server encrypts the header information, the encoded string, and the secret key according to the encryption algorithm to obtain a signature, which can improve the accuracy and reliability of authentication through the signature.
[0043] In another optional embodiment, the operations for the server to encrypt the header information, the encoded string, and the secret key according to the encryption algorithm to obtain a signature can include the following: The server encodes the header information according to the encoding algorithm to obtain the encoded string corresponding to the header information; The server determines the target string based on the encoded string corresponding to the payload and the encoded string corresponding to the header information; The server encrypts the target string and the secret key according to the encryption algorithm to obtain a signature.
[0044] In this optional embodiment, optionally, the server encodes the header information according to the encoding algorithm to obtain an encoded string corresponding to the header information. Specifically, the header information can be converted into an encoded string through the Base64Url encoding algorithm. The encoding algorithm includes the Base64Url encoding algorithm, and the encryption algorithm includes the HMACSHA256 algorithm. The server determines the target string based on the encoded string corresponding to the payload and the encoded string corresponding to the header information. Specifically, the server can concatenate the encoded string corresponding to the payload and the encoded string corresponding to the header information. For example: text = base64UrlEncode(header) + "." + base64UrlEncode(payload) where text represents the target string, base64UrlEncode(header) represents the encoded string corresponding to the header information, and base64UrlEncode(payload) represents the encoded string corresponding to the payload. Then, according to the encryption algorithm, the target string and the secret key are encrypted to obtain a signature. Specifically: public static string ToHMACSHA256String(this string text, string secret) { secret = secret?? ""; byte[] keyByte = Encoding.UTF8.GetBytes(secret); byte[] messageBytes = Encoding.UTF8.GetBytes(text); using (var hmacsha256 = new HMACSHA256(keyByte)) { byte[] hashmessage = hmacsha256.ComputeHash(messageBytes); return Convert.ToBase64String(hashmessage).Replace('+', '-').Replace(' / ', '_').TrimEnd('='); } } It can be seen that implementing this optional embodiment can encode the header information according to the encoding algorithm to obtain the encoded string corresponding to the header information, determine the target string based on the encoded string corresponding to the payload and the encoded string corresponding to the header information, and encrypt the target string and the secret key according to the encryption algorithm to obtain the signature, which can improve the security and reliability of the determined signature, and can customize the secret key to improve the flexibility of determining the signature, thereby improving the accuracy and reliability of authentication and authorization through the signature.
[0045] Embodiment 2 Please refer to Figure 2 , Figure 2 which is a schematic flowchart of an authentication access method for a custom signature applied to charge and discharge capacity testing. Among them, Figure 2 the described authentication access method for a custom signature applied to charge and discharge capacity testing can be applied to an authentication access device for a custom signature applied to charge and discharge capacity testing. Among them, the authentication access device for a custom signature applied to charge and discharge capacity testing can include an intelligent server or an intelligent platform for authentication verification. The intelligent server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. As Figure 2 shown, the authentication access method for a custom signature applied to charge and discharge capacity testing can include the following operations: 201. When the server detects the first access operation of the client, generate a payload based on the input information sent by the client.
[0046] 202. The server determines the header information of the target token and the preset secret key.
[0047] 203. The server encrypts the header information, payload, and secret key according to the encryption algorithm to obtain the signature.
[0048] 204. The server generates a target token based on the header information, payload, and signature, and sends the target token to the client.
[0049] 205. The client stores the received target token. When the client performs a re-access operation on the server, the client generates an access request corresponding to the re-access operation based on the target token, and sends the access request to the server.
[0050] In the embodiments of the present invention, for other descriptions of steps 201-step 205, please refer to the detailed descriptions of steps 101-step 105 in Embodiment 1 of the present invention, which will not be repeated in the embodiments of the present invention.
[0051] 206. The server parses the target token in the access request to obtain the parsed target header information, target payload, and target signature.
[0052] In an embodiment of the present invention, optionally, the server parses the target token in the access request to obtain the parsed target header information, target payload, and target signature. Specifically: / / / Obtain the data in the Token / / / / / / <typeparam name="T">Generic< / typeparam> / / / <param name="token"> token / / / <returns>< / returns> public static T GetPayload <t>(string token) { if (token.IsNullOrEmpty()) return default; return token.Split('.')[1].Base64UrlDecode().ToObject <t>(); } 207. The server encrypts the target header information, the target payload, and the secret key according to the encryption algorithm to obtain a verification signature.
[0053] In an embodiment of the present invention, optionally, the server encrypts the target header information, the target payload, and the secret key according to the encryption algorithm to obtain a verification signature. Specifically: public static bool CheckToken(string token, string secret) { var items = token.Split('.'); var oldSign = items[2]; string newSign = $"{items[0]}.{items[1]}".ToHMACSHA256String(secret); return oldSign == newSign; } 208. The server determines whether the verification signature matches the target signature to obtain an authentication result, and responds to the access request according to the authentication result.
[0054] In an embodiment of the present invention, optionally, the server determines whether the verification signature matches the target signature to obtain an authentication result. Specifically: public override async Task OnActionExecuting(ActionExecutingContext context) { if (context.ContainsFilter <nocheckjwtattribute>()) return; try { var req = context.HttpContext.Request; string token = req.GetToken(); if (!JWTHelper.CheckToken(token, JWTHelper.JWTSecret)) { context.Result = Error("token verification failed!", _errorCode + 1); return; } } catch (Exception ex) { context.Result = Error(ex.Message, _errorCode); } await Task.CompletedTask; } It can be seen that when implementing Figure 2 the authentication access method of the custom signature applied to the charging and discharging capacity testing, when the server detects the first access operation of the client, it generates a payload based on the input information sent by the client. The server determines the header information of the target token and the preset secret key. The server encrypts the header information, payload, and secret key according to the encryption algorithm to obtain a signature. The server generates a target token based on the header information, payload, and signature and sends the target token to the client, which can support user-defined signature authentication, improve the security and accuracy of authentication. The client stores the received target token. When the client performs a re-access operation on the server, the client generates an access request corresponding to the re-access operation based on the target token and sends the access request to the server. The server analyzes the target token in the access request to obtain the analyzed target header information, target payload, and target signature. According to the encryption algorithm, the server encrypts the target header information, target payload, and secret key to obtain a verification signature, and judges whether the verification signature matches the target signature to obtain an authentication result, which improves the accuracy and reliability of authentication and authorization, and further enhances the system security. It can support user-defined signature authentication, improve the security and efficiency of authentication, and the server does not need to save the client or Token information, and can achieve a stateless response.
[0055] In an optional embodiment, before the server parses the target token in the access request, the authentication access method for the custom signature applied to the formation and grading can further include the following operations: The server detects whether the access request contains a target token and obtains a detection result; When the detection result indicates that the access request does not contain a target token, the server returns a first error code to the client, and the first error code indicates that the target token is missing in the access request.
[0056] In this optional embodiment, optionally, the server can detect whether the access request contains a target token and obtain a detection result. When the detection result indicates that the access request does not contain a target token, the server returns a first error code to the client, and the first error code indicates that the target token is missing in the access request. Specifically: public override async Task OnActionExecuting(ActionExecutingContext context) { if (context.ContainsFilter <nocheckjwtattribute>()) return; try { var req = context.HttpContext.Request; string token = req.GetToken(); if (token.IsNullOrEmpty()) { context.Result = Error("missing token", _errorCode); return; } } catch (Exception ex) { context.Result = Error(ex.Message, _errorCode); } await Task.CompletedTask; } It can be seen that the implementation of this optional embodiment can detect whether the target token is included in the access request through the server to obtain a detection result. When the detection result indicates that the access request does not contain the target token, the server returns a first error code to the client. The first error code indicates that the target token is missing in the access request, thereby improving the accuracy of authentication and being able to provide a token missing reminder, making it easier for users to understand the error situation and improving user experience.
[0057] In another optional embodiment, the authentication access method applied to the custom signature of the componentized content may further include the following operations: The server obtains the expiration time in the parsed target payload, and determines whether the target token in the access request has expired based on the expiration time, and obtains the judgment result; When the determination result indicates that the target token has expired, the server returns a second error code to the client, where the second error code indicates that the target token has expired.
[0058] In this optional embodiment, optionally, the server can obtain the expiration time in the parsed target payload and determine whether the target token in the access request has expired based on the expiration time to obtain a judgment result. Specifically, the server can determine whether the expiration time in the payload exceeds the current system time. When the expiration time in the payload exceeds the current system time, it indicates expiration and invalidation. The server returns a second error code to the client, and the second error code indicates that the target token has expired and is invalid. Specifically: public override async Task OnActionExecuting(ActionExecutingContext context) { if (context.ContainsFilter <nocheckjwtattribute>()) return; try { var req = context.HttpContext.Request; string token = req.GetToken(); var payload = JWTHelper.GetPayload <jwtpayload>(token); if (payload.Expire < DateTime.Now) { context.Result = Error("token expired!", _errorCode + 2); return; } } catch (Exception ex) { context.Result = Error(ex.Message, _errorCode); } await Task.CompletedTask; } It can be seen that implementing this optional embodiment can obtain the expiration time in the parsed target payload through the server, and determine whether the target token in the access request has expired and become invalid based on the expiration time, obtaining a judgment result. When the judgment result indicates that the target token has expired and become invalid, the server returns a second error code to the client, and the second error code indicates that the target token has expired and become invalid, improving the authentication accuracy, and being able to perform token expiration reminder, facilitating the user to understand the error situation and improving the user experience.
[0059] Embodiment III Please refer to Figure 3 , Figure 3 which is a schematic structural diagram of an authentication access device for custom signatures applied to cell formation and capacitance measurement. Among them, Figure 3 The authentication access device for custom signatures applied to cell formation and capacitance measurement described can include an intelligent server or an intelligent platform for authentication verification. The intelligent server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. As Figure 3 shown, the authentication access device for custom signatures applied to cell formation and capacitance measurement can include a server 30 and a client 40. The server 30 includes a first generation module 301, a determination module 302, an encryption module 303, and an authentication module 304. The client 40 includes a storage module 401 and a second generation module 402, where: The first generation module 301 is used to generate a payload based on the input information sent by the client 40 when detecting the first access operation of the client 40. The input information includes user information, system information, and an expiration time; The determination module 302 is used to determine the header information of the target token and a preset secret key. The header information includes the token type and encryption algorithm of the target token; An encryption module 303, configured to encrypt the header information, payload, and secret key according to an encryption algorithm to obtain a signature; A first generation module 301 is further configured to generate a target token based on the header information, payload, and signature, and send the target token to the client 40; A storage module 401 is configured to store the received target token; A second generation module 402 is configured to, when the client 40 performs a re-access operation on the server 30, generate an access request corresponding to the re-access operation based on the target token, and send the access request to the server 30; An authentication module 304 is configured to authenticate the access operation according to the target token in the access request to obtain an authentication result, and respond to the access request according to the authentication result.
[0060] It can be seen that when implementing Figure 3 the authentication access device for the custom signature applied to the charging and discharging can, when the server detects the first access operation of the client, generate a payload based on the input information sent by the client, the server determines the header information of the target token and the preset secret key, the server encrypts the header information, payload, and secret key according to the encryption algorithm to obtain a signature, the server generates a target token based on the header information, payload, and signature, and sends the target token to the client, which can support user-defined signature authentication, improve the security and accuracy of authentication. The client stores the received target token. When the client performs a re-access operation on the server, the client generates an access request corresponding to the re-access operation based on the target token and sends the access request to the server. The server authenticates the access operation according to the target token in the access request to obtain an authentication result, and responds to the access request according to the authentication result, which can support user-defined signature authentication, improve the security and efficiency of authentication, and the server does not need to save the client or Token information, and can achieve a stateless response.
[0061] In an optional embodiment, as Figure 4 shown, the specific manner for the authentication module 304 to authenticate the access operation according to the target token in the access request to obtain an authentication result includes: Parse the target token in the access request to obtain the parsed target header information, target payload, and target signature; Encrypt the target header information, target payload, and secret key according to the encryption algorithm to obtain a verification signature; Determine whether the verification signature matches the target signature to obtain an authentication result.
[0062] It can be seen that when implementing Figure 4 When the authentication access device with a custom signature applied to the charging and discharging capacity detection detects the first access operation of the client by the server, it generates a payload based on the input information sent by the client. The server determines the header information of the target token and the preset secret key. According to the encryption algorithm, the server encrypts the header information, the payload, and the secret key to obtain a signature. The server generates a target token based on the header information, the payload, and the signature, and sends the target token to the client. It can support user-defined signature authentication, improve the security and accuracy of authentication. The client stores the received target token. When the client performs a re-access operation on the server, the client generates an access request corresponding to the re-access operation based on the target token, and sends the access request to the server. By parsing the target token in the access request by the server, the parsed target header information, target payload, and target signature are obtained. According to the encryption algorithm, the target header information, the target payload, and the secret key are encrypted to obtain a verification signature. It is determined whether the verification signature matches the target signature to obtain an authentication result, improving the accuracy and reliability of the authentication and verification, and further enhancing the system security. It can support user-defined signature authentication, improve the security and efficiency of authentication, and the server does not need to save client or Token information, and can achieve a stateless response.
[0063] In another optional embodiment, as Figure 4 shown, the server 30 further includes a detection module 305, where: The detection module 305 is configured to detect whether the access request contains a target token before the authentication module 304 parses the target token in the access request, and obtain a detection result; when the detection result indicates that the access request does not contain a target token, the detection module 305 returns a first error code to the client 40, and the first error code indicates that the target token is missing in the access request.
[0064] It can be seen that implementing Figure 4 the authentication access device with a custom signature applied to the charging and discharging capacity detection can detect whether the access request contains a target token by the server, obtain a detection result. When the detection result indicates that the access request does not contain a target token, the server returns a first error code to the client, and the first error code indicates that the target token is missing in the access request, improving the authentication accuracy, and can perform a token missing reminder, facilitating the user to understand the error situation and improving the user experience.
[0065] In yet another optional embodiment, as Figure 4 shown, the server 30 further includes an acquisition module 306 and a judgment module 307, where: The acquisition module 306 is configured to acquire the expiration time in the parsed target payload; A judgment module 307 is configured to judge whether the target token in the access request has expired and become invalid according to the expiration time, and obtain a judgment result; when the judgment result indicates that the target token has expired and become invalid, the judgment module 307 returns a second error code to the client 40, and the second error code indicates that the target token has expired and become invalid.
[0066] It can be seen that implementing Figure 4 the authentication access device for the custom signature applied to the chemical component capacity test can obtain the expiration time in the parsed target payload through the server, and judge whether the target token in the access request has expired and become invalid according to the expiration time, and obtain a judgment result. When the judgment result indicates that the target token has expired and become invalid, the server returns a second error code to the client, and the second error code indicates that the target token has expired and become invalid, which improves the authentication accuracy, and can perform token expiration reminder, facilitating the user to understand the error situation and improving the user experience.
[0067] In another optional embodiment, as Figure 4 shown, the specific manner in which the first generation module 301 encrypts the header information, the payload, and the secret key according to the encryption algorithm to obtain the signature includes: Perform deserialization processing on the payload to obtain the string corresponding to the payload; Perform encoding processing on the string corresponding to the payload according to the preset encoding algorithm to obtain the encoded string corresponding to the payload; According to the encryption algorithm, encrypt the header information, the encoded string, and the secret key to obtain the signature.
[0068] In this optional embodiment, the encoding algorithm includes the Base64Url encoding algorithm, and the encryption algorithm includes the HMACSHA256 algorithm.
[0069] It can be seen that implementing Figure 4 the authentication access device for the custom signature applied to the chemical component capacity test can perform deserialization processing on the payload through the server to obtain the string corresponding to the payload, the server performs encoding processing on the string corresponding to the payload according to the preset encoding algorithm to obtain the encoded string corresponding to the payload, and the server encrypts the header information, the encoded string, and the secret key according to the encryption algorithm to obtain the signature, which can improve the accuracy and reliability of authentication and verification through the signature.
[0070] In another optional embodiment, as Figure 4 shown, the specific manner in which the encryption module 303 encrypts the header information, the encoded string, and the secret key according to the encryption algorithm to obtain the signature includes: The server performs encoding processing on the header information according to the encoding algorithm to obtain the encoded string corresponding to the header information; The server determines a target string based on the encoded string corresponding to the payload and the encoded string corresponding to the header information; The server encrypts the target string and the secret key according to an encryption algorithm to obtain a signature.
[0071] It can be seen that implementing Figure 4 the authentication access device for custom signature applied to charge and discharge capacity testing can encode the header information according to an encoding algorithm to obtain an encoded string corresponding to the header information, determine a target string based on the encoded string corresponding to the payload and the encoded string corresponding to the header information, encrypt the target string and the secret key according to an encryption algorithm to obtain a signature, which can improve the security and reliability of the determined signature, and can customize the secret key to improve the flexibility of determining the signature, thereby improving the accuracy and reliability of authentication and authorization through the signature.
[0072] Embodiment 4 Please refer to Figure 5 , Figure 5 which is a schematic structural diagram of another authentication access device for custom signature applied to charge and discharge capacity testing disclosed in an embodiment of the present invention. As Figure 5 shown, the authentication access device for custom signature applied to charge and discharge capacity testing may include: A memory 501 storing executable program code; A processor 502 coupled to the memory 501; The processor 502 calls the executable program code stored in the memory 501 and executes the steps in the authentication access method for custom signature applied to charge and discharge capacity testing described in Embodiment 1 or Embodiment 2 of the present invention.
[0073] Embodiment 5 An embodiment of the present invention discloses a computer storage medium storing computer instructions, which are used to execute the steps in the authentication access method for custom signature applied to charge and discharge capacity testing described in Embodiment 1 or Embodiment 2 of the present invention when the computer instructions are called.
[0074] Embodiment 6 An embodiment of the present invention discloses a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to cause a computer to execute the steps in the authentication access method for custom signature applied to charge and discharge capacity testing described in Embodiment 1 or Embodiment 2.
[0075] The device embodiments described above are merely illustrative. The modules described as separate components may or may not be physically separated. The components shown as modules may or may not be physical modules, that is, they may be located in one place or distributed to multiple network modules. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.
[0076] Through the specific descriptions of the above embodiments, those skilled in the art can clearly understand that each implementation can be achieved by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solution, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium. The storage medium includes read-only memory (ROM), random access memory (RAM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), one-time programmable read-only memory (OTPROM), electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc memories, magnetic disk memories, tape memories, or any other computer-readable medium that can be used to carry or store data.
[0077] Finally, it should be noted that: The authentication access method and device for custom signatures applied to component sorting and grading disclosed in the embodiments of the present invention only disclose the preferred embodiments of the present invention, and are only used to illustrate the technical solutions of the present invention, rather than limiting them; Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; And these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.< / jwtpayload> < / nocheckjwtattribute> < / nocheckjwtattribute> < / nocheckjwtattribute> < / t> < / t>
Claims
1. An authentication access method for a custom signature applied to a component, characterized in that: The method comprises: When the server detects the client's first access operation, it generates a payload based on the input information sent by the client, which includes user information, system information, and expiration time; The server determines header information of the target token and a preset secret key, wherein the header information includes a token type and an encryption algorithm of the target token; The server encrypts the header information, the payload, and the secret key according to the encryption algorithm to obtain a signature; The server generates the target token according to the header information, the payload and the signature, and sends the target token to the client; The client stores the received target token, and when the client performs a re-access operation on the server, the client generates an access request corresponding to the re-access operation based on the target token, and sends the access request to the server; The server authenticates and confirms the access operation according to the target token in the access request, obtains an authentication result, and responds to the access request according to the authentication result.
2. The authentication access method for custom signatures applied to content-based content according to claim 1, characterized in that: The server authenticates and confirms the access operation according to the target token in the access request, and obtains an authentication result, including: The server parses the target token in the access request to obtain the parsed target header information, target payload, and target signature; The server encrypts the target header information, the target payload, and the secret key according to the encryption algorithm to obtain a verification signature; The server determines whether the verification signature matches the target signature and obtains an authentication result.
3. The authentication access method for custom signatures applied to content-based content according to claim 2, characterized in that: Before the server parses the target token in the access request, the method further includes: The server detects whether the access request contains the target token and obtains a detection result; When the detection result indicates that the access request does not include the target token, the server returns a first error code to the client, where the first error code indicates that the target token is missing from the access request.
4. The authentication access method for custom signatures applied to content-based content according to claim 2 or 3, characterized in that: The method further comprises: The server obtains the expiration time in the parsed target payload, and determines whether the target token in the access request has expired based on the expiration time, thereby obtaining a determination result; When the judgment result indicates that the target token is expired, the server returns a second error code to the client, where the second error code indicates that the target token is expired.
5. The authentication access method for custom signatures applied to content-based content according to any one of claims 1 to 3, characterized in that: The server encrypts the header information, the payload, and the secret key according to the encryption algorithm to obtain a signature, including: The server performs deserialization processing on the payload to obtain a character string corresponding to the payload; The server encodes the character string corresponding to the payload according to a preset encoding algorithm to obtain an encoded character string corresponding to the payload; The server encrypts the header information, the encoded string and the secret key according to the encryption algorithm to obtain a signature.
6. The authentication access method for custom signatures applied to content-based content according to claim 5, characterized in that: The server encrypts the header information, the encoded string, and the secret key according to the encryption algorithm to obtain a signature, including: The server encodes the header information according to the encoding algorithm to obtain an encoded character string corresponding to the header information; The server determines a target string according to the encoded string corresponding to the payload and the encoded string corresponding to the header information; The server encrypts the target character string and the secret key according to the encryption algorithm to obtain a signature.
7. The authentication access method for custom signatures applied to content-based content according to claim 5, characterized in that: The encoding algorithm includes the Base64Url encoding algorithm, and the encryption algorithm includes the HMACSHA256 algorithm.
8. An authentication access device for customized signatures applied to content composition, characterized in that: The device includes a server and a client, wherein the server includes a first generation module, a determination module, an encryption module, and an authentication module, and the client includes a storage module and a second generation module, wherein: The first generating module is configured to generate a payload based on input information sent by the client upon detecting the first access operation by the client, wherein the input information includes user information, system information, and expiration time; The determining module is used to determine header information of a target token and a preset secret key, wherein the header information includes a token type and an encryption algorithm of the target token; The encryption module is configured to encrypt the header information, the payload, and the secret key according to the encryption algorithm to obtain a signature; The first generating module is further configured to generate the target token according to the header information, the payload, and the signature, and send the target token to the client; The storage module is used to store the received target token; The second generating module is configured to generate an access request corresponding to the re-access operation based on the target token when the client performs a re-access operation on the server, and send the access request to the server; The authentication module is configured to authenticate and confirm the access operation according to the target token in the access request, obtain an authentication result, and respond to the access request according to the authentication result.
9. An authentication access device for customized signatures applied to content composition, characterized in that: The device comprises: a memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the authentication access method for custom signatures applied to content-fragmented content according to any one of claims 1 to 7.
10. A computer storage medium, characterized in that The computer storage medium stores computer instructions, which, when called, are used to execute the authentication access method for custom signatures applied to content-fragmented content according to any one of claims 1 to 7.
Citation Information
Patent Citations
Data processing method and device for formation and capacity grading equipment based on RPC (Remote Procedure Call)
CN117640713A
Method and Apparatus for the Protection of Computer System Account Credentials
US20130061302A1