Group chat method and device responding to service event, equipment and storage medium
By creating groups through virtual job tags and sending and receiving messages through agent, the problem of user information leakage is solved, and efficient collaboration and information security are achieved.
Patent Information
- Application Number
- CN202511121910.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-12
- Publication Date
- 2025-10-17
AI Technical Summary
In areas such as civil aviation production operations, when users need to frequently establish temporary collaborative relationships with strangers, traditional methods lead to personal information leakage and fail to guarantee information security.
By creating a group through virtual job tags, users can send and receive group messages by signing in to the associated tags, avoiding the disclosure of personal account information. Virtual job tags can be used to query the associated employee and object IDs to realize the proxy sending and receiving of messages.
It improves collaboration efficiency while fully protecting user information security and avoiding the disclosure of personal information in groups.
Smart Images

Figure CN120812019A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of communication, in particular to a group chat method and device responding to a service event, equipment and a storage medium. BACKGROUND
[0002] Instant messaging (IM) is a real-time information exchange means relying on network technology, which enables users to exchange information almost instantly. Such a communication system generally adopts a client / server architecture to achieve the purpose of communication. When a user intends to establish a communication link with another user, the client sends a request to the server, and the server is responsible for transferring the request to the corresponding client and building a point-to-point connection. Then, the two clients can directly communicate with each other, thereby realizing the interactive transmission of data. In this communication process, TCP / IP plays a crucial role. Specifically, TCP (Transmission Control Protocol) provides a reliable and connection-oriented communication service, which can ensure that information is transmitted accurately and in the correct order; and IP (Internet Protocol) is responsible for transmitting information from the source address to the target address.
[0003] In some application scenarios, such as in the field of civil aviation production and operation, users need to frequently establish temporary collaboration relationships with different strangers. The traditional solution is to establish a work group for relevant personnel whenever a work project appears. However, in the process of establishing a group, users need to use their real social account to join the group chat, which may lead to user privacy leakage and cannot guarantee the information security of users in the process of realizing business collaboration. SUMMARY
[0004] The purpose of the embodiments of the present application is to provide a group chat method, device, equipment and storage medium responding to a service event, which can build a group for a virtual post label in response to a service event, and users only need to sign in on the associated virtual post label to send and receive group messages through the virtual post label without disclosing personal account information. The embodiments of the present application improve collaboration efficiency while fully guaranteeing the information security of users.
[0005] To achieve the above purpose, the embodiments of the present application provide a group chat method responding to a service event, comprising:
[0006] When a service event is received, a target virtual post label bound to the service event is invoked;
[0007] query a virtual post information table based on the target virtual post label to obtain an associated employee;
[0008] query a virtual object memory mapping table based on the target virtual post label to obtain a virtual object ID;
[0009] issue the target virtual post label to a corresponding instant messaging front end of the associated employee;
[0010] add all the target virtual post labels to a newly created group to obtain a target group;
[0011] when the state of the associated employee on the target virtual post label is a check-in state, forward a target message from a message transmission pool to the instant messaging front end of the associated employee through the target group based on the virtual object ID.
[0012] As an improvement of the above scheme, when the state of the associated employee on the target virtual post label is a check-out state, the target group is stripped from the communication front end of the associated employee.
[0013] As an improvement of the above scheme, the forwarding of the target message from the message transmission pool to the associated employee through the target group based on the virtual object ID comprises:
[0014] determining a target time interval based on the current check-in time and the last check-out time of the associated employee on the target virtual post label;
[0015] extracting an intermediate message from the message transmission pool based on the target time interval;
[0016] when the number of the target virtual post labels associated with the associated employee is 1, regarding the intermediate message as a target message;
[0017] when the number of the target virtual post labels associated with the associated employee is greater than 1, performing a deduplication process on the intermediate message, and regarding the deduplicated intermediate message as the target message.
[0018] As an improvement of the above scheme, when a first employee sends a first message in a first group through a first virtual post label, the method further comprises:
[0019] adding the first message to the message transmission pool;
[0020] querying the virtual object memory mapping table based on the first virtual post label to obtain a first virtual object ID;
[0021] query all virtual object IDs in the first group as the receiver virtual object ID with the first virtual object ID;
[0022] query the virtual object memory mapping table based on the receiver virtual object ID to obtain a receiver virtual post tag;
[0023] obtain a first associated employee in a check-in state on the receiver virtual post tag, and forward the first message to the instant messaging front end of the first associated employee from the message transmission pool.
[0024] As an improvement of the above scheme, the virtual post information table includes a tag master table and a plurality of associated employee information sub-tables, the tag master table is used to store virtual post tag information, and each virtual post tag in the tag master table is associated with an associated employee information sub-table, and the associated employee information sub-table is used to store administrator information and user information.
[0025] As an improvement of the above scheme, the target group is integrated by the following way:
[0026] After receiving the authentication request of the group application, the RSA secret key is used to asymmetrically decrypt the sign ciphertext data to obtain the AES secret key; wherein the authentication request includes data ciphertext data and sign ciphertext data.
[0027] The AES secret key is used to decrypt the data ciphertext data to obtain authentication information; wherein the authentication information includes ssoToken, authentication application identifier and timestamp information.
[0028] The authentication information is judged for legality, and an authentication result is output.
[0029] As an improvement of the above scheme, the authentication request is generated by the instant messaging front end in the following way:
[0030] The authentication information is received by the group application login service jsApi request, and the authentication information is encapsulated by JSON data to obtain authentication information JSON data;
[0031] The authentication information JSON is encrypted by the AES secret key to generate the data ciphertext data;
[0032] The AES secret key is asymmetrically encrypted by the RSA public key to generate the sign ciphertext data.
[0033] To achieve the above purpose, the embodiment of the application further provides a group chat device responding to a service event, comprising:
[0034] A virtual job tag acquisition module, configured to retrieve a target virtual job tag bound to a service event upon receiving the service event;
[0035] An associated employee query module is used to query the virtual position information table based on the target virtual position tag to obtain associated employees;
[0036] A virtual object ID query module is used to query the virtual object memory mapping table based on the target virtual position label to obtain the virtual object ID;
[0037] A virtual job label issuing module, configured to issue the target virtual job label to the corresponding instant messaging front end of the associated employee;
[0038] A group creation module is used to add all the target virtual job tags to a newly created group to obtain a target group;
[0039] The message updating module is used to forward the target message from the message sending and receiving pool to the instant messaging front end of the associated employee through the target group based on the virtual object ID when the status of the associated employee on the target virtual position tag is the signed-in status.
[0040] To achieve the above-mentioned objectives, an embodiment of the present invention further provides a group chat device that responds to a service event, comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the group chat method that responds to a service event as described in any of the above embodiments is implemented.
[0041] To achieve the above-mentioned purpose, an embodiment of the present invention further provides a computer-readable storage medium, wherein the computer-readable storage medium includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the group chat method in response to a service event as described in any of the above embodiments.
[0042] Compared with the prior art, the group chat method, device, equipment and storage medium for responding to a service event provided by the embodiment of the application have the following advantages: when a service event is received, a target virtual post label bound with the service event is called; virtual post information table is queried based on the target virtual post label to obtain associated employees; virtual object memory mapping table is queried based on the target virtual post label to obtain a virtual object ID; the target virtual post label is sent to an instant messaging front end of the associated employees; all the target virtual post labels are added to a newly created group to obtain a target group; when the state of the associated employees on the target virtual post label is a check-in state, a target message is forwarded from a message transmission pool to the instant messaging front end of the associated employees through the target group based on the virtual object ID. The embodiment of the application can realize proxy transmission of group chat messages through virtual post labels by building a group for the virtual post label and associating relevant personnel through the virtual post label, without displaying personal information of the relevant personnel in the group, so that the information security of the relevant personnel can be fully ensured while responding to service events efficiently. BRIEF DESCRIPTION OF DRAWINGS
[0043] Figure 1 is a flowchart of a group chat method for responding to a service event provided by an embodiment of the application;
[0044] Figure 2 is a group diagram based on a virtual post label provided by an embodiment of the application;
[0045] Figure 3 is a flowchart of a group chat method for responding to a service event provided by another embodiment of the application;
[0046] Figure 4 is a flowchart of a login-free security authentication provided by an embodiment of the application;
[0047] Figure 5 is a structural schematic diagram of a group chat device for responding to a service event provided by an embodiment of the application;
[0048] Figure 6 is a structural schematic diagram of a group chat device for responding to a service event provided by an embodiment of the application. DETAILED DESCRIPTION
[0049] The technical solutions in the embodiments of the application will be described clearly and completely below with reference to the drawings in the embodiments of the application. Obviously, the described embodiments are only part of the embodiments of the application, rather than all the embodiments of the application. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor fall within the protection scope of the application.
[0050] In the description of the present application, it needs to be understood that the terms "center", "upper", "lower", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like indicate the orientation or positional relationship shown in the drawings, which are only for the convenience of describing the present application and simplifying the description, and do not indicate or imply that the devices or elements referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation of the present application.
[0051] The terms "first", "second" are only for descriptive purposes, and cannot be understood as indicating or implying relative importance or implicitly indicating the number of the technical features referred to. Therefore, the features defined with "first", "second" can explicitly or implicitly include one or more of the features. In the description of the present application, unless otherwise specified, the meaning of "a plurality of" is two or more.
[0052] In the description of the present application, it needs to be explained that, unless otherwise explicitly specified and limited, the terms "mounting", "connection", "connection" should be understood broadly, for example, it can be fixed connection, or detachable connection, or integral connection; it can be mechanical connection, or electrical connection; it can be directly connected, or indirectly connected through intermediate medium, or the communication inside two elements. For those skilled in the art, the specific meaning of the above terms in the present application can be understood according to the specific circumstances.
[0053] Referring to Figure 1 , the flowchart of the group chat method provided by an embodiment of the present application in response to a service event, comprising steps S1-S6:
[0054] S1, when receiving a service event, calling a target virtual post label bound with the service event;
[0055] S2, querying the virtual post information table based on the target virtual post label to obtain associated employees;
[0056] S3, querying the virtual object memory mapping table based on the target virtual post label to obtain a virtual object ID;
[0057] S4, issuing the target virtual post label to the instant messaging front end of the corresponding associated employee;
[0058] S5, adding all the target virtual post labels to a newly created group to obtain a target group;
[0059] S6, when the state of the associated employee on the target virtual post tag is a check-in state, forwarding a target message to the instant messaging front end of the associated employee through the target group from a messaging pool based on the virtual object ID.
[0060] It is worth noting that the execution subject of the group chat method according to the service event described in the embodiments of the present application is the instant messaging back end. Further, in order to facilitate explanation, the following embodiments explain the present application with task coordination in the civil aviation field as an application scenario. It is worth noting that the method described in the present application can also be applied to other scenarios, which are not limited herein.
[0061] In step S1, when a service event is received, a target virtual post tag bound to the service event is invoked. It is worth noting that in the embodiments of the present application, different virtual posts are set to realize the association between service events and staff. For example, the name of each virtual post can be spliced by the horizontal "civil aviation station information" and the vertical "business function information". Further, in the embodiments of the present application, a corresponding virtual post tag is also set for each virtual post. In the process of data processing and conversion, the proxy sending and receiving of messages for the associated employee is realized through the virtual post tag. It can be understood that the target virtual post tag is a virtual post tag bound to the current service event, and the number of target virtual post tags is generally greater than 1. Further, each virtual post tag (including the target virtual post tag) has an associated employee. The associated employee (in other application scenarios, the "associated employee" can also be referred to as "associated personnel") includes two types of administrators and users. The administrator has the right to manage the information of the virtual post tag, such as setting the user, while the user has the right to check in / out the virtual post tag. Further, the mapping relationship between the virtual post tag and the associated employee is stored in the virtual post information table. Therefore, in step S2, the virtual post information table is queried based on the target virtual post tag to obtain the associated employee.
[0062] As one of the optional implementation manners, the virtual post information table includes a tag master table and a plurality of associated employee information sub-tables. The tag master table is used to store virtual post tag information, and each virtual post tag in the tag master table is associated with an associated employee information sub-table. The associated employee information sub-table is used to store administrator information and user information.
[0063] It can be understood that the virtual post tag is stored in the form of a data table (virtual post information table), wherein the tag table (tag master table) is the main table of the virtual post tag information, and the configured personnel information is associated with the sub-table (associated employee information sub-table) to complete the arrangement of the virtual post.
[0064] Further, in step S3, the virtual object ID (Identity Document) is obtained by querying the virtual object memory mapping table based on the target virtual post label. The virtual object ID mapping is established for each virtual post label in advance in the embodiment of the application to realize the sending and receiving of messages. It should be noted that the virtual object ID in the embodiment of the application only has the message sending and receiving capability and cannot be logged in to the independent instant messaging front end through SSO (Single Sign On) identity authentication.
[0065] It can be understood that the order of step S2 and step S3 can be exchanged, that is, the virtual object ID can be queried first, and then the associated employee is queried, which is not limited herein.
[0066] Further, in step S4, the target virtual post label is issued to the instant messaging front end of the corresponding associated employee. It should be noted that the user can view all the virtual post labels that can be checked through the personal center virtual post check-in portal of the instant messaging front end, and can select one or more virtual post labels for check-in.
[0067] Further, in step S5, all the target virtual post labels are added to a newly created group to obtain a target group. It should be noted that the virtual post label is grouped in the embodiment of the application, so that the associated employee only needs to check in on the associated virtual post label, and can send and receive group messages through the virtual post label without publicly disclosing the personal account information in the group, so that the information security of the user is further ensured while the collaboration efficiency is improved.
[0068] Referring to Figure 2 is a group diagram based on a virtual post label provided by an embodiment of the application. By Figure 3 It can be seen that in the group, the instant messaging back end encapsulates the virtual object ID and maps it to the virtual post label, so that the virtual post is added to the group chat as a tagged virtual person, and the user communicates and collaborates in the group with the checked-in virtual post label. In the group chat, the user can only see the information of the virtual post label, and the information between the users is not visible to each other. For example, user 1 and user 2 check in virtual post label A and virtual post label B respectively, in the group, the user can only see the information of virtual post label A and virtual post label B, and cannot see user 1 and user 2, thereby solving the problem of personal information security protection when strangers collaborate for transactions. Further, Figure 2It can also be seen that the group is established based on the service event, that is, when the service event occurs, the virtual post tags A-D bound to the service event are obtained, and the virtual post tags A-D are grouped, so that the group can be quickly and automatically built in response to the service event, thereby improving the cooperation efficiency, and after the group is built, the event notification can be directly forwarded to the group to realize message sharing. It is worth noting that although Figure 2 In the above embodiment, each virtual post tag corresponds to only one user, but in other embodiments, one virtual post tag can also be associated with multiple users, that is, multiple users can share one virtual post tag for message sending and receiving, and each user can independently check in and check out the virtual post tag.
[0069] From the above, it can be seen that the user opens / closes the message sending and receiving function of the virtual post tag through the check-in / check-out mode. Therefore, the instant messaging backend also needs to monitor the check-in / check-out state of the virtual post tag, and include the checked-in virtual post tag in the message sending and receiving pool, and distribute and schedule the messages with virtual post cooperation relationship.
[0070] For example, in step S6, when the state of the associated employee on the target virtual post tag is a check-in state, the target message is forwarded to the instant messaging front end of the associated employee through the target group from the message sending and receiving pool based on the virtual object ID.
[0071] It can be understood that after the user (associated employee) checks in on the virtual post tag, the corresponding group chat information can be seen on the instant messaging front end.
[0072] Compared with the prior art, the virtual post tag is grouped, and the relevant personnel are associated through the virtual post tag, so that the group chat message can be sent and received through the virtual post tag without displaying the personal information of the relevant personnel in the group, thereby efficiently responding to the service event while fully protecting the information security of the relevant personnel.
[0073] As one of the optional embodiments, in step S6, the forwarding of the target message to the associated employee through the target group from the message sending and receiving pool based on the virtual object ID includes:
[0074] determining a target time interval based on the current check-in time and the last check-out time of the associated employee on the target virtual post tag;
[0075] extracting intermediate messages from the message sending and receiving pool based on the target time interval;
[0076] when the number of the target virtual post tags associated with the associated employee is 1, the intermediate messages are taken as target messages;
[0077] When the number of the target virtual post tags associated with the associated employee is greater than 1, the intermediate message is de-duplicated, and the de-duplicated intermediate message is taken as the target message.
[0078] It can be understood that the user can check in and check out the associated virtual post tag according to actual needs. When the user checks out, the instant messaging front end removes the session related to the virtual post tag from the session list of the checked-out employee to keep the interface clean, that is, the user no longer receives new messages after checking out, and therefore, when the user checks in again, the user needs to be updated with newly generated session messages, specifically, the target time interval needs to be determined, and the message needs to be extracted based on the target time interval. Further, in some scenarios, a user can be associated with multiple virtual post tags, and multiple virtual post tags can join the same group, therefore, in order to avoid repeated presentation of the same message, the intermediate message also needs to be de-duplicated.
[0079] As one of the optional embodiments, when the state of the associated employee on the target virtual post tag is a check-out state, the target group is peeled off from the communication front end of the associated employee.
[0080] For example, when a work task is completed or when an employee needs to temporarily leave a post, the virtual post can be checked out on the instant messaging front end, at this time, the instant messaging front end removes the session related to the virtual post tag from the session list of the checked-out employee to keep the interface clean, and also avoids unnecessary interference.
[0081] As one of the optional embodiments, when the first employee sends a first message in the first group through the first virtual post tag, the method further comprises:
[0082] adding the first message to the message transmission pool;
[0083] querying the virtual object memory mapping table based on the first virtual post tag to obtain a first virtual object ID;
[0084] querying all virtual object IDs in the first group together with the first virtual object ID as receiver virtual object IDs;
[0085] querying the virtual object memory mapping table based on the receiver virtual object ID to obtain a receiver virtual post tag;
[0086] obtaining a first associated employee in a check-in state on the receiver virtual post tag, and forwarding the first message from the message transmission pool to the instant messaging front end of the first associated employee.
[0087] It is worth mentioning that the user can not only receive group messages through the check-in virtual post label, but also send messages in the group through the virtual post label. In the embodiment of the present application, the first employee sends a first message in the first group through the first virtual post label as an example to illustrate the message sending method. It is worth mentioning that, due to the inconsistent check-in status of different virtual post labels, for example, when the first virtual post label sends information in the first group as a message sender, there may be no employee in the check-in state on the second virtual post label as a message receiver, so it is necessary to set up a message exchange pool to cache messages, and therefore the first message in the embodiment of the present application can also be stored in the message exchange pool first.
[0088] Further, in order to realize the forwarding of the message, it is also necessary to map the virtual post label to a virtual object ID, that is, map the first virtual post label to a first virtual object ID, so as to query all virtual object IDs in the first group based on the first virtual object ID, that is, the receiver virtual object ID, and then map the receiver virtual post label based on the receiver virtual object ID, that is, all virtual post labels in the first group except the first virtual post label. Further, the first associated employee in the check-in state on the first virtual post label is obtained, and the first message is forwarded to the first associated employee, so that the first associated employee can see the new conversation message (that is, the first message) of the first group on the instant messaging front end.
[0089] Further, in order to more clearly understand the group chat method in response to the service event, the following will be illustrated with a specific example. Referring to Figure 3 is a flowchart of the group chat method in response to the service event provided by another embodiment of the present application. By Figure 3 It can be seen that the embodiment of the present application further provides a virtual post management dispatch center, which is used for virtual post arrangement distribution and dispatch and service event binding dispatch.
[0090] For example, the user or the system can import the name and avatar of the virtual post label and other information through the virtual post management dispatch center to complete the label basic data reserve, and further, the virtual post management dispatch center. In addition, each virtual post label is also configured with a label administrator and a label user for subsequent check-in, check-out and information management of the virtual post label, and further, the virtual post label is stored in the form of a virtual post information table.
[0091] Further, by Figure 3It can be seen that the virtual post dispatch center subscribes to service events from the business system, that is, when a service event occurs, the business system notifies the virtual post dispatch center of the service event, and the virtual post dispatch center binds the service event with the corresponding virtual post label based on the pre-set mapping relationship, and synchronizes the distribution information of the virtual post label and the service event distribution scheduling information to the instant messaging backend. It can be understood that the service event notification of the business system can run through the entire process, and is not limited before the binding of the service event and the virtual post label, wherein the service event includes operation and maintenance guarantee events, emergency disposal events, agile research and development events, conference events, service care events, precise marketing events and other operation events, etc.
[0092] Further, the instant messaging backend is used to execute the group chat method for responding to service events according to the embodiments of the application, and is specifically used to realize virtual post label mapping virtual object ID, virtual post label state monitoring, and message transmission based on virtual post label, etc., and specific reference is made to the above-mentioned embodiments, and again no further description is made.
[0093] Further, the instant messaging front end is used to realize user check-in and check-out of the virtual post. Specifically, after the instant messaging front end checks in the virtual post label by calling the "virtual post data check-in interface", the instant messaging backend monitors the check-in state of the user to the virtual post label and processes the message distribution of the message pool, for example, when the user checks in the virtual post label, it is further verified whether the virtual post is in the service period, if yes, it can join the virtual post collaboration group and obtain the service event notification. Further, after checking in, the instant messaging front end will automatically roam to receive the historical messages associated with the virtual post label. Moreover, the employees who check in the same virtual post label will share the messages of the virtual post label, and further, the latest conversation of the checked-in virtual post label can be displayed on top to ensure that important information will not be missed. Further, the embodiments of the application also provide simultaneous check-in of multiple virtual post labels to realize message transmission of multiple virtual post labels, so that work collaboration becomes more flexible and convenient.
[0094] Further, when the work task is completed, or when the employee needs to temporarily leave the post, only the check-out operation of the virtual post in the instant messaging front end is needed. Then, the instant messaging front end checks out by calling the "virtual post check-out interface". Further, after checking out, the instant messaging backend records the check-out state of the user to the virtual post label, and processes the information stripping of the virtual post message pool.
[0095] Further, the following illustrates the fields used by the embodiments of the application when exchanging data.
[0096] It can be understood that the virtual post management dispatch center can realize the setting of the virtual post label, and the setting of the virtual post label is shown in Table 1.
[0097] Table 1 Setting of virtual post label
[0098]
[0099]
[0100] Further, when the virtual post label is bound through the service event, the data can be defined as shown in Table 2.
[0101] Table 2 Service event binding virtual post label
[0102]
[0103] Further, when the virtual post label is distributed, the data can be defined as shown in Table 3.
[0104] Table 3 Virtual post label distribution
[0105] Field Field Description Data Example UserId User account 202647 labelGroup Check-in virtual post label set -labelName Virtual post label name A city on-site rescue
[0106] Further, when the group is established based on the service event, the data can be defined as shown in Table 4.
[0107] Table 4 Group establishment
[0108]
[0109] It can be understood that after the instant messaging backend receives the virtual post label distribution information of the virtual post management dispatch center, the virtual post label will be mapped to the virtual object ID based on the virtual object memory mapping table, so that the virtual post label has the message transmission capability, and the virtual object memory mapping table can be defined as shown in Table 5.
[0110] Table 5 Virtual object memory mapping table
[0111] Field Field Description Data Example vuserId Virtual object ID 123456 labelName Virtual post label name Guangzhou on-site rescue
[0112] Further, the embodiments of the present application not only can realize automatic group building based on virtual post labels, but also realize group collaboration application integrated security login-free authentication capability in some embodiments, so as to ensure the security data exchange between group business messages and business systems while improving the convenience. Specifically, in the embodiments of the present application, the user does not need to manually log in before using the group application through the group, that is, does not need to manually input the username and password, and the instant messaging front end and the instant messaging back end can automatically interact with the group application to complete the security authentication, so that the user can safely and conveniently exchange data between the group collaboration messages and the business system through the group application, including but not limited to one-key reporting, schedule distribution and task reporting functions.
[0113] As one of the optional embodiments, the target group integrates the group application in the following manner:
[0114] After receiving the authentication request of the group application, the sign ciphertext data is decrypted by using the RSA secret key to obtain the AES secret key; wherein the authentication request includes data ciphertext data and sign ciphertext data.
[0115] The data ciphertext data is decrypted by using the AES secret key to obtain the authentication information; wherein the authentication information includes ssoToken, authentication application identifier and timestamp information.
[0116] The legality of the authentication information is discriminated, and the authentication result is output.
[0117] As one of the optional embodiments, the authentication request is generated by the instant messaging front end in the following manner:
[0118] The login-free service jsApi request of the group application is received, and the authentication information is encapsulated by using JSON data to obtain authentication information JSON data;
[0119] The authentication information JSON is encrypted by using the AES secret key to generate the data ciphertext data;
[0120] The AES secret key is asymmetrically encrypted by using the RSA public key to generate the sign ciphertext data.
[0121] It is worth mentioning that in the embodiment of the application, the instant messaging front end exposes open capability jsAPI through webview JSbridge technology, the API (Application Programming Interface) can realize a secure channel for exchanging local authentication information and group application data, the local authentication information is extracted and assembled into a JSON object through a user object generated after the user normally logs in and successfully authenticates, so as to facilitate subsequent parsing and authentication of group application authorization, and the JSON data needs to be checked through a secure authentication strategy, and the checking rules specifically include processing of the following information: the url field is used to identify whether the group application is a legal application, and the non-application will be listed in the suspected attack interception strategy to discard the request and record, the deviceID is used to identify whether it is a legal instant messaging front end, and the illegal instant messaging will be listed in the suspected attack interception strategy to discard the request and record, the ssoToken belongs to the authentication summary of the login user by the instant messaging back end, and is authenticated through the effective period, personnel state and other information recorded by redis, and the createTime is used to judge the validity of the request, and the authentication information of the request exceeding 5 minutes will be listed in the suspected replay attack interception strategy to discard the request and record.
[0122] Referring to Figure 4 , is a flowchart of the free login security authentication provided by an embodiment of the application. In order to facilitate understanding, the following explains and describes the way of implementing free login security authentication by the embodiment of the application through an example, including steps T1-T9.
[0123] T1, the group application is uploaded to the instant messaging directory front end through the mobile management platform;
[0124] T2, the instant messaging front end receives the free login service jsApi request of the uploaded group application, and encapsulates the authentication information into JSON data, wherein the authentication information includes device ID, whether it is a leader, user account, instant messaging authentication token, device type, authentication application identifier and timestamp and the like;
[0125] T3, the instant messaging front end encrypts the authentication information JSON data through an AES secret key to generate data ciphertext data, realizing fast generation of ciphertext of large data volume string;
[0126] T4, the AES secret key is asymmetrically encrypted through an RSA public key to generate sign ciphertext data, realizing fast generation of ciphertext of small data;
[0127] T5, after the group application obtains the data ciphertext data and the sign ciphertext data, it can request the backend service authentication forwarding interface to deliver the authentication information (data ciphertext data and sign ciphertext data);
[0128] T6, the group application backend forwards the authentication information (data ciphertext data and sign ciphertext data) to the instant messaging backend.
[0129] T7, after the instant messaging backend receives the data ciphertext data and the sign ciphertext data, the instant messaging backend performs asymmetric decryption on the sign ciphertext data by using the RSA secret key held by the instant messaging backend, and the plaintext obtained by the decryption is the AES secret key, and then the instant messaging backend uses the AES secret key to decrypt the data ciphertext data, obtains the authentication information of the legal user, and judges whether the user is valid and the source is legal by using the ssoToken, the authentication application identifier and the timestamp information in the authentication information, and then returns the authentication result to the group application backend.
[0130] T8, the group application backend generates the business token information according to the authentication result of the instant messaging backend, and the group application backend performs local persistence and subsequent business request authentication.
[0131] T9, after the group application passes through the login-free process, the group application can obtain user information and virtual post label group business information to perform subsequent one-key reporting, schedule distribution and task reporting and other virtual post collaboration.
[0132] Compared with the prior art, the embodiment of the application realizes login-free security authentication by innovatively improving the AES (Advanced Encryption Standard) and RSA encryption and decryption mechanism. Specifically, the current AES encryption and decryption is fast, but since it is symmetric encryption, the secret key needs to be held by both parties at the same time. Once the secret key is leaked, data leakage will occur and the source of the leakage cannot be traced. RSA belongs to asymmetric encryption, and the public key and the private key are held by both parties. The secret key of each other cannot independently complete the encryption and decryption of data, which to some extent avoids the problem of secret key leakage. However, the encryption is extremely slow and cannot meet the encryption scene of long text data. In order to balance the efficiency and security of the encryption and decryption process, the instant messaging front end randomly generates an AES secret key (short in length and high in content complexity) in the embodiment of the application, and quickly symmetrically encrypts the long text authentication information data. At this time, the instant messaging backend does not directly hold the AES secret key, but the instant messaging front end encrypts the authentication information data by using the AES secret key randomly generated in the current request by the RSA asymmetric encryption public key to generate the sign ciphertext. When the data and the sign ciphertext are transmitted to the instant messaging backend through the group application front and back ends, the backend can obtain the AES secret key by decrypting the sign with the RSA private key held by the backend. The secret key is only valid for this request and cannot be reused, which compensates for the shortcomings of the AES secret key. Since the AES secret key is short in length and high in content complexity, the RSA decryption speed is also greatly improved, which not only guarantees the security of the authentication request, but also ensures the performance of the concurrent processing of the request.
[0133] The security of the sign ciphertext data and the data ciphertext data is also guaranteed by the innovative mixed encryption mode of RSA and AES, that is, even if there is a leak, an attacker cannot decrypt the sign ciphertext data because the attacker cannot hold the private key of RSA, and cannot decrypt the data ciphertext data to obtain the authentication information for replay attack since the sign ciphertext data cannot be decrypted to obtain the AES secret key. The method provided in the embodiment of the application guarantees the high efficiency of ciphertext generation and the security of ciphertext transmission. Multiple systems cooperate in security management and control, such as the group application backend and the instant messaging backend in the same intranet, which control access permissions through a whitelist (the whitelist refers to an access IP and a registration access key and an access secret key required for request authentication). An attacker in the external network cannot initiate a fake authentication request without breaking into the intranet, and cannot fake an authentication request without knowing the access key and the secret key after breaking into the intranet.
[0134] Referring to Figure 5 The embodiment of the application also provides a group chat device 10 responding to a service event, comprising:
[0135] A virtual post label acquisition module 11 is configured to call a target virtual post label bound to the service event when the service event is received;
[0136] An associated employee query module 12 is configured to query a virtual post information table based on the target virtual post label to obtain an associated employee;
[0137] A virtual object ID query module 13 is configured to query a virtual object memory mapping table based on the target virtual post label to obtain a virtual object ID;
[0138] A virtual post label issuing module 14 is configured to issue the target virtual post label to a corresponding instant messaging front end of the associated employee;
[0139] A group building module 15 is configured to add all the target virtual post labels to a newly built group to obtain a target group;
[0140] A message updating module 16 is configured to, when a state of the associated employee on the target virtual post label is a check-in state, forward a target message from a message transceiver pool to the instant messaging front end of the associated employee through the target group based on the virtual object ID.
[0141] The group chat device for responding to a service event provided by the embodiment of the present application can implement all process steps of the group chat method for responding to a service event described in the above embodiment, the functions of each module and unit in the device, and the technical effects achieved are respectively the same as the functions of the group chat method for responding to a service event described in the above embodiment and the technical effects achieved, and the specific implementation manner will not be described here.
[0142] Referring to Figure 6 The embodiment of the present application also provides a group chat device 20 for responding to a service event, which comprises a processor 21, a memory 22, and a computer program stored in the memory 22 and configured to be executed by the processor 21, wherein the processor 21 implements steps in the above group chat method embodiments for responding to a service event, such as steps S1-S6 described in the above embodiment, when executing the computer program; or the processor 21 implements the functions of each module in the above device embodiments when executing the computer program. Figure 1
[0143] The group chat device for responding to a service event can be a desktop computer, a notebook computer, a palm computer, a cloud server, and the like. The group chat device for responding to a service event can include, but is not limited to, a processor and a memory. Those skilled in the art can understand that the schematic diagram is only an example of the group chat device for responding to a service event, and does not constitute a limitation on the group chat device for responding to a service event, and can include more or fewer components than the diagram, or combine certain components, or different components, for example, the group chat device for responding to a service event can also include an input and output device, a network access device, a bus, and the like.
[0144] The processor can be a central processing unit (CPU), and can also be other general-purpose processors, digital signal processors (DSP), application specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, and the like. The general-purpose processor can be a microprocessor or the processor can also be any conventional processor and the like, and the processor is a control center of the group chat device for responding to a service event, and connects each part of the group chat device for responding to a service event through various interfaces and lines.
[0145] The memory can be configured to store the computer programs and / or modules, and the processor realizes various functions of the group chat device responding to the service event by running or executing the computer programs and / or modules stored in the memory and calling data stored in the memory. The memory can mainly include a program storage area and a data storage area, wherein the program storage area can store an operating system, at least one application required by a function, and the like; and the data storage area can store data created according to use of the controller and the like. In addition, the memory can include a high-speed random access memory, and can also include a nonvolatile memory, for example, a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card, at least one disk storage device, a flash memory device, or other volatile solid-state memory devices.
[0146] The modules integrated in the group chat device responding to the service event can be stored in a computer readable storage medium if they are realized in the form of software function units and sold or used as independent products. Based on this understanding, all or part of the processes in the above-mentioned embodiment methods can also be completed by a computer program instructing related hardware, and the computer program can be stored in a computer readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned various method embodiments can be realized. The computer program includes computer program code, which can be in the form of source code, object code, an executable file, or some intermediate form, etc. The computer readable medium can include any entity or device capable of carrying the computer program code, a recording medium, a U disk, a mobile hard disk, a magnetic disk, an optical disk, a computer memory, a read-only memory (ROM), a random access memory (RAM), an electrical carrier signal, a telecommunication signal, and a software distribution medium, etc.
[0147] Compared with the prior art, the group chat device, the equipment and the storage medium for responding to a service event provided by the embodiment of the application can, when receiving a service event, call a target virtual post label bound with the service event, query a virtual post information table based on the target virtual post label to obtain an associated employee, query a virtual object memory mapping table based on the target virtual post label to obtain a virtual object ID, issue the target virtual post label to an instant messaging front end of the associated employee, add all the target virtual post labels to a newly created group to obtain a target group, and when a state of the associated employee on the target virtual post label is a check-in state, forward a target message from a message transceiving pool to the instant messaging front end of the associated employee through the target group based on the virtual object ID. The embodiment of the application can build a group for a virtual post label, associate relevant personnel through the virtual post label, realize proxy transceiving of group chat messages through the virtual post label, and does not need to display personal information of the relevant personnel in the group, so that the information security of the relevant personnel can be fully ensured while efficiently responding to the service event.
[0148] The above is the preferred embodiment of the application. It should be noted that, for those skilled in the art, without departing from the principle of the application, several improvements and refinements can be made, which are also considered to be within the protection scope of the application.
Claims
1. A group chat method in response to a service event, characterized in that: include: Upon receiving a service event, retrieving a target virtual position tag bound to the service event; Querying the virtual position information table based on the target virtual position tag to obtain associated employees; Querying a virtual object memory mapping table based on the target virtual position tag to obtain a virtual object ID; Sending the target virtual position label to the corresponding instant messaging front-end of the associated employee; Add all the target virtual job tags to a newly created group to obtain a target group; When the status of the associated employee on the target virtual position tag is a signed-in status, based on the virtual object ID, the target message is forwarded from the message sending and receiving pool to the instant messaging front end of the associated employee through the target group.
2. The group chat method in response to a service event according to claim 1, wherein: When the status of the associated employee on the target virtual position tag is a sign-out status, the target group is separated from the communication front end of the associated employee.
3. The group chat method in response to a service event according to claim 1, wherein: The forwarding of the target message from the message sending and receiving pool to the associated employee through the target group based on the virtual object ID includes: Determine a target time interval based on the current check-in time and the most recent check-out time of the associated employee on the target virtual position tag; Extracting intermediate messages from the message sending and receiving pool based on the target time interval; When the number of the target virtual position tags associated with the associated employee is 1, taking the intermediate message as the target message; When the number of the target virtual position tags associated with the associated employee is greater than 1, deduplication processing is performed on the intermediate message, and the deduplicated intermediate message is used as the target message.
4. The group chat method in response to a service event according to claim 1, wherein: When the first employee sends a first message in the first group using the first virtual position tag, the method further includes: Adding the first message to the message sending and receiving pool; Querying the virtual object memory mapping table based on the first virtual position tag to obtain a first virtual object ID; Querying all virtual object IDs in the first group that are the same as the first virtual object ID as recipient virtual object IDs; Query the virtual object memory mapping table based on the recipient virtual object ID to obtain the recipient virtual position label; A first associated employee whose status on the recipient's virtual position tag is a signed-in status is obtained, and the first message is forwarded from the message sending and receiving pool to the instant messaging front end of the first associated employee.
5. The group chat method in response to a service event according to claim 1, wherein: The virtual position information table includes a label main table and several associated employee information sub-tables. The label main table is used to store virtual position label information, and each virtual position label in the label main table is associated and mapped with one of the associated employee information sub-tables. The associated employee information sub-table is used to store administrator information and user information.
6. The group chat method in response to a service event according to claim 1, wherein: The target group is integrated into the group application in the following ways: After receiving the authentication request from the group application, the RSA key is used to asymmetrically decrypt the sign ciphertext data to obtain the AES key; wherein the authentication request includes the data ciphertext data and the sign ciphertext data; Decrypt the data ciphertext using the AES key to obtain authentication information; wherein the authentication information includes ssoToken, authentication application identifier and timestamp information; The authentication information is subjected to a legality judgment, and an authentication result is output.
7. The group chat method in response to a service event according to claim 6, wherein: The authentication request is generated by the instant messaging front end in the following manner: Receive the jsApi request for the free login service of the group application, and encapsulate the authentication information into JSON data to obtain authentication information JSON data; The authentication information JSON data is encrypted using an AES key to generate the data ciphertext data; The AES secret key is asymmetrically encrypted using the RSA public key to generate the sign ciphertext data.
8. A group chat device that responds to a service event, characterized in that: include: A virtual job tag acquisition module, configured to retrieve a target virtual job tag bound to a service event upon receiving the service event; An associated employee query module is used to query the virtual position information table based on the target virtual position tag to obtain associated employees; A virtual object ID query module is used to query the virtual object memory mapping table based on the target virtual position label to obtain the virtual object ID; A virtual job label issuing module, configured to issue the target virtual job label to the corresponding instant messaging front end of the associated employee; A group creation module is used to add all the target virtual job tags to a newly created group to obtain a target group; The message updating module is used to forward the target message from the message sending and receiving pool to the instant messaging front end of the associated employee through the target group based on the virtual object ID when the status of the associated employee on the target virtual position tag is the signed-in status.
9. A group chat device that responds to a service event, characterized in that: The system comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, the group chat method in response to a service event according to any one of claims 1 to 7 is implemented.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute the group chat method in response to a service event according to any one of claims 1 to 7.