Data processing method, apparatus, device, and medium

By generating and binding dynamic signature tokens to authenticate smart security devices, the problem of ID and key leakage during device identity authentication is solved, thereby improving authentication security and the uniqueness of device identity.

CN121509121BActive Publication Date: 2026-04-10ANSJER ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-14
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

In the current process of device identity authentication for smart security devices, the fixed device ID and device key are easily leaked, resulting in low authentication security.

Method used

By receiving requests from user devices, a dynamic signature token is generated and bound to a specific device ID. The dynamic signature token is then used for authentication to ensure the legitimacy of the device identity and the validity of its permissions, thus preventing the authentication of unauthorized devices.

Benefits of technology

It improves the security of device authentication, prevents attackers from impersonating legitimate devices to perform authentication, and enhances the security of the authentication process and the uniqueness of device identity.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121509121B_ABST
    Figure CN121509121B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of data processing, and discloses a data processing method, device, equipment and medium, which comprises the following steps: receiving a first request sent by a first user equipment, wherein the first request comprises a user authentication token, a first user equipment ID and a second user equipment SN, the second user equipment is a to-be-verified equipment; generating a dynamic signature token based on the first request and information of a server, wherein the dynamic signature token is used for authenticating the second user equipment; and sending the dynamic signature token to the first user equipment. The security of the generated dynamic signature token can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data processing, and in particular to a data processing method, device, equipment and medium. BACKGROUND

[0002] With the rapid development of Internet of Things (IoT) technology, intelligent security devices represented by IPC (network camera) have been widely used in home and commercial environments. These devices usually need to be connected to the IoT platform in the cloud to realize remote access, cloud storage, message pushing and device management and other functions. The whole process from the factory to the end user, and then to the successful connection of the cloud service is called "device booting" or device access. The security and convenience of this process are directly related to the stability and reliability of the whole system and the final user experience. The backend service plays a key role in connecting users, devices and cloud platforms in this process, and is responsible for handling identity authentication and other processes.

[0003] At present, the most common device identity process usually relies on a unique DeviceId and DeviceSecret burned in the device at the factory. However, the fixed DeviceId and DeviceSecret are easy to be leaked, and after the leakage, other devices can be verified through the ID and key, resulting in low security of the authentication process. SUMMARY

[0004] The present application provides a data processing method, device, computer equipment and medium to solve the technical problem of low security of user identity authentication process.

[0005] In a first aspect, a data processing method is provided, comprising:

[0006] receiving a first request sent by a first user device, wherein the first request includes a user authentication token, a first user device ID and a second user device SN, wherein the second user device is a device to be verified;

[0007] generating a dynamic signature token based on the first request and information of the server, wherein the dynamic signature token is used to authenticate the second user device;

[0008] sending the dynamic signature token to the first user device.

[0009] In a second aspect, a data processing device is provided, comprising:

[0010] receive a first request sent by a first user equipment, wherein the first request comprises a user authentication token, a first user equipment ID and a second user equipment SN, wherein the second user equipment is a device to be verified;

[0011] generate a dynamic signature token based on the first request and information of a server, wherein the dynamic signature token is used for authenticating the second user equipment;

[0012] send the dynamic signature token to the first user equipment.

[0013] In a third aspect, a computer device is provided, which comprises a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor implements the steps of the above data processing method when executing the computer program.

[0014] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program, and the computer program implements the steps of the above data processing method when executed by a processor.

[0015] In the above data processing method, device, computer device and storage medium, the first request sent by the first user equipment is received, wherein the first request comprises a user authentication token, a first user equipment ID and a second user equipment SN, wherein the second user equipment is a device to be verified; a dynamic signature token is generated based on the first request and information of a server, wherein the dynamic signature token is used for authenticating the second user equipment; and the dynamic signature token is sent to the first user equipment, thereby realizing the binding of the dynamic signature token with two specific device IDs. Even if a leak occurs, when an attacker initiates a request from his device, i.e. a device other than the first device and the second device, the server verifies that the device IDs do not match, the request is immediately rejected for authentication, the security of the generated dynamic signature token is improved, and the security of the authentication process is improved. BRIEF DESCRIPTION OF DRAWINGS

[0016] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the following will briefly introduce the drawings needed to be used in the description of the embodiments of the present application. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.

[0017] Figure 1 is a flowchart of a data processing method in an embodiment of the present application;

[0018] Figure 2 isFigure 1 is a specific implementation flowchart of step S20 in the embodiment of the present application;

[0019] Figure 3 is another flowchart of a data processing method in an embodiment of the present application;

[0020] Figure 4 is a structural diagram of a data processing device in an embodiment of the present application;

[0021] Figure 5 is a structural diagram of a computer device in an embodiment of the present application;

[0022] Figure 6 is another structural diagram of a computer device in an embodiment of the present application. DETAILED DESCRIPTION

[0023] The technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some of the embodiments of the present application, but not all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.

[0024] The scheme implemented by the data processing method, device, computer device and storage medium provided by the embodiments of the present application can achieve the following. A first request sent by a first user equipment is received, wherein the first request includes a user authentication token, a first user equipment ID and a second user equipment SN, wherein the second user equipment is a device to be verified. A dynamic signature token is generated based on the first request and information of the server, wherein the dynamic signature token is used to authenticate the second user equipment. The dynamic signature token is sent to the first user equipment, so as to bind the dynamic signature token with two specific device IDs. Even if there is a leak, when an attacker initiates a request from his device, i.e. a device other than the first device and the second device, the server verifies that the device IDs do not match, the request is immediately rejected for authentication, the security of the generated dynamic signature token is improved, and the security of the authentication process is improved.

[0025] The computer device can include a terminal device, which can include a smartphone, a tablet computer, a notebook computer, a desktop computer, a personal digital assistant, a wearable device, etc., or a server, which can be a standalone server or a cloud server providing cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, content delivery networks (CDN), and basic cloud computing services such as big data and artificial intelligence platforms. The data processing method of the present application can be applied in the field of Internet of Things, the field of finance, and other fields requiring verification.

[0026] The present application will be described in detail below through specific embodiments.

[0027] Please refer to Figure 1 , Figure 1 A flowchart of a data processing method provided by an embodiment of the present application includes the following steps:

[0028] S10: receiving a first request sent by a first user device, wherein the request includes a user authentication token, a first user device ID, and a second user device SN, wherein the second user device is a device to be verified.

[0029] Specifically, in the present embodiment, the first user device can be a smartphone or a tablet computer held by a user, which mainly functions as an interface for user interaction, and obtains the second user device SN, communicates with the backend management server through API, initiates a device addition request, and transmits network configuration information and a key token to the Internet of Things device, i.e., the second user device, through near field communication (such as Bluetooth, sound waves, or generating a two-dimensional code for device reverse scanning). The backend server is the execution subject of the present application.

[0030] The second user device is a device to be verified, i.e., an Internet of Things device.

[0031] Specifically, the unique serial number of the Internet of Things device, i.e., the second user device SN, can be obtained by scanning the two-dimensional code on the Internet of Things device through the network camera of the first user device. After obtaining the second user device, an HTTPS POST request, i.e., the first request, can be initiated to the specified API endpoint (for example, / api / v1 / device / onboarding / initiate) of the backend management server, wherein the first request sent by the first user device includes the user authentication token and the first user device ID in addition to the second device SN.

[0032] The backend management server receives the first request sent by the first user device.

[0033] S20: generating a dynamic signature token based on the first request and information of the server, wherein the dynamic signature token is used for authenticating the second user equipment.

[0034] After receiving the first request, a dynamic signature token can be generated based on the information contained in the first request and the information of the server. The server is the backend management server. The information of the server can include the related information of the master key of the server, the validity period of the token defined by the server, and the identification information of the server. The dynamic signature token is used for authenticating the second user equipment.

[0035] In some embodiments of the application, as shown in Figure 2 A scheme for generating a dynamic signature token is provided, and in S20, that is, the process of generating a dynamic signature token based on the first request and the information of the server, specifically includes the following steps S21-S22:

[0036] S21, obtaining first connection information based on the user authentication token, the first user equipment ID, the second user equipment SN and the information of the server;

[0037] S22, generating a session key based on the information of the server and the second device terminal SN;

[0038] S23, generating a dynamic signature token based on the first connection information and the session key.

[0039] In this step S21, first, based on the user authentication token, the first user equipment ID, the second user equipment SN and the information of the server, the first connection information is obtained.

[0040] In some embodiments of the application, a scheme for obtaining first connection information is provided, and in S21, that is, the process of obtaining first connection information based on the user authentication token, the first user equipment ID, the second user equipment SN and the information of the server, specifically includes the following steps:

[0041] Based on a preset algorithm, a token header is constructed;

[0042] Based on the first user equipment ID, the second user equipment SN and the information of the server, a token payload is constructed;

[0043] The user authentication token is verified based on the token header and the token payload;

[0044] If the verification is passed, the token header and the token payload are encoded to obtain the encoded token header and the token payload;

[0045] The encoded token header and the token payload are connected to obtain the first connection information.

[0046] First, the validity of the user authentication token is verified, i.e., the validity of the user_auth_token is verified, so as to confirm the legitimacy of the identity and the validity of the authority before each operation performed by the user that requires authority. Specifically, Token is extracted: Token is extracted from the request header (for example: Bearer eyJhbGciOiJ...). If not in the standard location, it can also be obtained from the Cookie or custom header, but the standard header is safer. And check if the Token exists, the format is as expected (for example, the JWT should be composed of three parts, separated by a dot). If not as expected, the user_auth_token is considered invalid. In the case of meeting the expectations, the signature of the header and the payload part of the Token is recalculated using the pre-configured key or public key, and the signature of the Token is compared with the signature of the Token. Specifically, based on the preset algorithm, the token header is constructed, i.e., the header of the Token is recalculated, first determine the metadata, the metadata includes (1) typ, the type of the token, the standard JWT can be used in the embodiment. (2) The algorithm of signature or encryption, the embodiment can use HS256, HMAC using SHA-256. The determined metadata is assembled into a standard JSON object, and the JSON object is serialized into a compact, no extra space string, such as assembled into: {"alg":"HS256","typ":"DYN-TKN"}. The token header is obtained.

[0047] Further, the token payload is constructed based on the first user equipment ID and the second user equipment SN. First, standard fields are defined, including (1) target user identification, i.e., the first user equipment ID, such as defining the field as: "aud": "151511307913827315916282254", which specifies that the target user of this token is a specific user with the ID "151511307913827315916282254", ensuring that the token cannot be misused on the resources of other users, and achieving user-level access control. (2) Device identity binding, i.e., binding the second user equipment SN with the token, such as permanently binding the second user equipment SN field: "sub": "00741Y11A20018" with the token. This achieves device-level precise authorization. Even if a leak occurs, when an attacker initiates a request from his device, i.e., a device other than the first device and the second device, the server verifies that the device ID does not match, and the request is immediately rejected for authentication, improving the security of the generated dynamic signed token. Even if the same user logs in from different devices, different token permissions are obtained, enhancing security. Further definitions can be made: (3) Issuer identification, indicating that this token is issued by a specific backend server, so that in a multi-service architecture, the API gateway or other services can accurately know which authentication service to verify the token authenticity, preventing token forgery. To further improve security, the token's validity period can also be set, i.e., the validity period is defined, and the field can be set as: "exp": 1754863947. Even if the token is leaked, the attacker can only misuse it within a very short window period (such as 10 minutes), greatly reducing the security risk. A unique request identifier is also defined for the token, so that a globally unique identifier is assigned to this token. This prevents the same token from being reused, effectively blocking network eavesdropping and replay attacks. After defining the fields, the defined fields are assembled into a standard JSON object, and the token payload is obtained. Then, the recalculated token header and token payload are compared with the token's own signature, and the token header and token payload of the token are compared for cryptographic security. If the comparison result is consistent, the user authentication token verification is passed, and the recalculated token header and token payload can be encoded, specifically Base64Url encoding, to obtain the encoded token header and token payload. The encoded token header and token payload are connected, specifically connected with a dot (.), to form a string, i.e., the first connection information.

[0048] In step S22, a session key is generated based on the information of the server and the second device terminal SN, specifically based on the master key of the server and the second device terminal SN.

[0049] In some embodiments of the application, a scheme for generating a session key is provided, and in S22, a process for generating a session key based on the information of the server and the second user equipment SN, specifically comprising the following steps:

[0050] Obtaining the master key of the server, and obtaining a preset hash algorithm;

[0051] Based on the preset hash algorithm, the master key of the server and the second user equipment SN are hashed to generate a session key.

[0052] Specifically, the master key of the server is obtained from the storage, the DeviceSN, i.e. the second user equipment SN, is extracted from the JWT payload to be signed, and a preset hash algorithm is obtained. The preset hash algorithm can be an HMAC algorithm. The master key is used as the key of the HMAC algorithm, and the DeviceSN is used as the input message of the HMAC algorithm. HMAC_SHA256 calculation is performed to obtain the session key. Thus, the risk of exposure of the master key is greatly reduced, and the security is improved.

[0053] In step S23, after obtaining the first connection information and the session key, a dynamic signed token is generated based on the first connection information and the session key, so that the specific token data is signed using the session key specific to the second user equipment.

[0054] In some embodiments of the application, a scheme for generating a dynamic signed token is provided, and in S23, a process for generating a dynamic signed token based on the first connection information and the session key, specifically comprising the following steps:

[0055] Based on the session key, an inner padding key and an outer padding key are calculated;

[0056] Based on the inner padding key and the first connection information, the second connection information is calculated;

[0057] Based on the outer padding key and the second connection information, the third connection information is generated;

[0058] The first connection information and the encoded third connection information are connected to obtain a dynamic signed token.

[0059] Specifically, the length of the session key can be first unified, i.e. the length of the session key is adjusted. For example, if the length of the session key is less than 64 bytes, zero 0x00 is filled on the right side to expand the length to 64 bytes. If the length of the session key is greater than 64 bytes, the session key is first hashed once by SHA256, and then the obtained hash value is filled with zero to 64 bytes. If the length of the session key is equal to 64 bytes, it is directly used.

[0060] Further, based on the adjusted length of the session key, an inner padding key is generated. Specifically, a 64-byte constant ipad is defined, and each byte of the ipad has a value of 0x36. The inner padding key K ipad = K adj (session key) XOR ipad. K ipad is a 64-byte sequence. Based on the adjusted length of the session key, an outer padding key is generated. A 64-byte constant opad is defined, and each byte of the opad has a value of 0x5C. The outer padding key K opad = K adj (session key) XOR opad. K opad is also a 64-byte sequence.

[0061] Based on the inner padding key and the first connection information, an inner layer hash value, i.e., the second connection information, is calculated. That is, the inner padding key is concatenated with the first connection information string, and a SHA-256 hash value is calculated, thereby obtaining the second connection information. That is, inner_data = K ipad + SigningInput (first connection information string). The SHA-256 hash value of the inner_data byte sequence is calculated. Thus, the second connection information inner_hash is obtained, inner_hash = SHA256 (inner_data), wherein inner_hash is a 32-byte binary hash value. Then, the second connection information is concatenated with the outer padding key, and a SHA-256 hash value is calculated, thereby obtaining the third connection information. The binary third connection information is Base64Url encoded, thereby obtaining the encoded third connection information. The first connection information and the encoded third connection information are concatenated, thereby obtaining the dynamic signature token.

[0062] Through the HMAC calculation, the token is ensured to be non-forgery, thereby improving the security of the token.

[0063] S30: The dynamic signature token is sent to the first user equipment.

[0064] After the dynamic signature token is generated, the dynamic signature token can be sent to the first user equipment. After the first user equipment receives the dynamic signature token, the SSID, password, and the dynamic signature token of the home Wi-Fi can be sent to the second user equipment through near field communication such as Bluetooth. The second user equipment can perform network connection based on the received Wi-Fi information. After the second user equipment successfully connects to the network, an HTTPS POST request is initiated to the backend server, and the request body includes the dynamic signature token.

[0065] In some embodiments of the application, as shown in Figure 3 After S30, i.e. after the dynamic signed token is sent to the first user equipment, the method further comprises the following steps S40-S80:

[0066] S40, receiving a second request sent by a second user equipment, wherein the second request comprises the dynamic signed token;

[0067] S50, parsing the second request to obtain parsing information;

[0068] S60, generating verification information based on the second request;

[0069] S70, comparing and verifying the parsing information and the verification information;

[0070] S80, if the parsing information and the verification information are consistent, generating a permanent credential, and sending the permanent credential to the second user equipment.

[0071] Specifically, the second request sent by the second user equipment is received, the dynamic signed token in the second request is parsed to obtain parsing information, and the dynamic signed token string is divided into three parts, i.e. the parsing information: ReceivedHeader, ReceivedPayload, and ReceivedSignature, according to the point (.) to obtain the parsed header, payload, and signature. The verification information comprises signature verification information, payload verification information, and header verification information. Specifically, the third connection information is regenerated according to the process of step S23 to regenerate the signature verification information, i.e. the verification information. The generated signature verification connection information is compared with ReceivedSignature, and if they are completely consistent, it is indicated that the token is authentic and reliable. At this time, the payload verification information and the header verification information are further generated according to step S21, and are compared with ReceivedPayload and ReceivedHeader, respectively. In the case where the comparison results are consistent, it is determined that the verification is passed, i.e. it is determined that the first request is legal, the internal management API of the IoT platform can be called, the permanent credential is applied for the second user, and is sent to the second user equipment.

[0072] In some embodiments of the application, a scheme for verifying whether the second request is valid is provided, before S80, i.e. before the permanent credential is generated and sent to the second user equipment, the method further comprises the following steps:

[0073] extracting the timestamp in the second request;

[0074] comparing the timestamp with a current time;

[0075] In the case that the comparison result is that the current time is in the valid period, it is determined that the verification is passed.

[0076] Further, the second request is verified by the timestamp. Specifically, the timestamp in the second request is extracted, the timestamp is compared with a current time, and if the verification condition result is current_time>exp(timestamp), i.e., the current time has exceeded the "death time" specified on the dynamic signature token in the second request, it indicates that the dynamic signature token has expired, and the request is immediately rejected at this time. If the verification result is nbf<=current_time<=exp(timestamp), i.e., the current time is between the token effective time and the expiration time. At this time, it is determined that the verification result of the second request is that the verification is passed. A permanent credential can be generated.

[0077] The embodiment can achieve the binding of the dynamic signature token with two specific device IDs by receiving a first request sent by a first user equipment, wherein the first request includes a user authentication token, a first user equipment ID and a second user equipment SN, wherein the second user equipment is a device to be verified; generating a dynamic signature token based on the first request and information of the server, wherein the dynamic signature token is used to authenticate the second user equipment; and sending the dynamic signature token to the first user equipment. Even if a leak occurs, when an attacker initiates a request from his device, i.e., a device other than the first device and the second device, the server verifies that the device IDs do not match, the request is immediately rejected for authentication, the security of the generated dynamic signature token is improved, and thus the security of the authentication process is improved.

[0078] It should be understood that the size of the serial number of each step in the above embodiment does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiment of the present application.

[0079] In an embodiment, a data processing apparatus is provided, which corresponds to the data processing method in the above embodiment. As shown in the figure, the data processing apparatus includes a receiving module 101, a generating module 102 and a sending module 103. The functions of each functional module are described in detail as follows: Figure 4

[0080] The receiving module 101 is configured to receive a first request sent by a first user equipment, wherein the first request includes a user authentication token, a first user equipment ID and a second user equipment SN, wherein the second user equipment is a device to be verified;

[0081] ​The generating module 102 is configured to generate a dynamic signature token based on the first request and information of the server, wherein the dynamic signature token is used for authenticating the second user equipment;

[0082] The sending module 103 is configured to send the dynamic signature token to the first user equipment.

[0083] In an embodiment, the generating module 102 is specifically configured to:

[0084] obtain first connection information based on the user authentication token, the first user equipment ID, the second user equipment SN and the information of the server;

[0085] generate a session key based on the information of the server and the second user equipment SN;

[0086] generate the dynamic signature token based on the first connection information and the session key.

[0087] In an embodiment, the generating module 102 is further specifically configured to:

[0088] construct a token header based on a preset algorithm;

[0089] construct a token payload based on the first user equipment ID, the second user equipment SN and the information of the server;

[0090] verify the user authentication token based on the token header and the token payload;

[0091] if the verification is passed, encode the token header and the token payload to obtain an encoded token header and an encoded token payload;

[0092] connect the encoded token header and the encoded token payload to obtain the first connection information.

[0093] In an embodiment, the generating module 102 is further specifically configured to:

[0094] obtain a master key of the server and obtain a preset hash algorithm;

[0095] perform hash operation on the master key of the server and the second user equipment SN based on the preset hash algorithm to generate a session key.

[0096] In an embodiment, the generating module 102 is further specifically configured to:

[0097] calculate an inner padding key and an outer padding key based on the session key;

[0098] calculate second connection information based on the inner padding key and the first connection information;

[0099] generate third connection information based on the outer padding key and the second connection information;

[0100] connect the first connection information and the encoded third connection information to obtain a dynamic signature token.

[0101] In an embodiment, the data processing apparatus is further specific for:

[0102] receiving a second request sent by a second user equipment, wherein the second request comprises the dynamic signature token;

[0103] parsing the second request to obtain parsing information;

[0104] generating verification information based on the second request;

[0105] comparing and verifying the parsing information and the verification information;

[0106] if the verification is passed, generating a permanent credential and sending the permanent credential to the second user equipment.

[0107] In an embodiment, the data processing apparatus is further specific for:

[0108] extracting a timestamp in the second request;

[0109] comparing the timestamp with a current time;

[0110] if the comparison result is that the current time is within a valid period, determining that the verification is passed.

[0111] The application provides a data processing apparatus, which first receives a first request sent by a first user equipment, wherein the first request comprises a user authentication token, a first user equipment ID and a second user equipment SN, wherein the second user equipment is a device to be verified; generates a dynamic signature token based on the first request and information of the server, wherein the dynamic signature token is used for authenticating the second user equipment; and sends the dynamic signature token to the first user equipment, so as to bind the dynamic signature token with two specific equipment IDs, that is, even if a leak occurs, when an attacker initiates a request from his equipment, that is, other equipment except the first equipment and the second equipment, the server verifies that the equipment IDs do not match, the request is immediately rejected for authentication, the security of the generated dynamic signature token is improved, and thus the security of the authentication process is improved.

[0112] The specific limitation of the data processing apparatus can refer to the limitation of the data processing method in the above, which will not be repeated here. Each module in the above data processing apparatus can be realized by software, hardware and their combination in whole or in part. The above modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory in the computer device in software form, so that the processor calls and executes the operation corresponding to each module.

[0113] In one embodiment, a computer device is provided, which can be a server, and its internal structure diagram can be as shown in Figure 5 The computer device includes a processor, a memory, a network interface and a database connected by a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile and / or volatile storage medium, an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with the external client through the network connection. The computer program is executed by the processor to realize the function or step of the server side of the data processing method.

[0114] In one embodiment, a computer device is provided, which can be a client, and its internal structure diagram can be as shown in Figure 6 The computer device includes a processor, a memory, a network interface, a display screen and an input device connected by a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with the external server through the network connection. The computer program is executed by the processor to realize the function or step of the client side of the data processing method.

[0115] In one embodiment, a computer device is provided, which includes a memory, a processor and a computer program stored in the memory and executable on the processor, and the processor executes the computer program to realize the following steps:

[0116] receiving a first request sent by a first user device, wherein the first request includes a user authentication token, a first user device ID and a second user device SN, wherein the second user device is a device to be verified;

[0117] generate a dynamic signature token based on the first request and information of the server, wherein the dynamic signature token is used to authenticate the second user equipment;

[0118] send the dynamic signature token to the first user equipment.

[0119] In one embodiment, a computer readable storage medium is provided, having stored thereon a computer program, the computer program is executed by a processor to implement the following steps:

[0120] receive a first request sent by a first user equipment, wherein the first request comprises a user authentication token, a first user equipment ID and a second user equipment SN, wherein the second user equipment is a device to be verified;

[0121] generate a dynamic signature token based on the first request and information of the server, wherein the dynamic signature token is used to authenticate the second user equipment;

[0122] send the dynamic signature token to the first user equipment.

[0123] It should be noted that the functions or steps described above in relation to the computer readable storage medium or the computer device can correspond to the relevant description of the server side and the client side in the foregoing method embodiments. To avoid repetition, they will not be described one by one here.

[0124] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiments can be completed by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer readable storage medium. When the computer program is executed, it can include the processes of the above-mentioned embodiments. Any reference to memory, storage, database or other medium used in the embodiments provided by the present application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration but not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM) and memory bus dynamic RAM (RDRAM) and the like.

[0125] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above-mentioned division of each functional unit and module is taken as an example, and in actual application, the above-mentioned functions can be completed by different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above.

[0126] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than limit them; although the foregoing embodiments of the present application have been described in detail, those skilled in the art should understand that the technical solutions recorded in the foregoing embodiments can be modified, or some technical features can be replaced by equivalents; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be included in the protection scope of the present application.

Claims

1. A data processing method, performed by a server, characterized by, The method comprises: receiving a first request sent by a first user equipment, wherein the first request comprises a user authentication token, a first user equipment ID and a second user equipment SN, and the second user equipment is a device to be verified; generating a dynamic signature token based on the first request and information of the server, wherein the dynamic signature token is used for authenticating the second user equipment; sending the dynamic signature token to the first user equipment; the generating of the dynamic signature token based on the first request and information of the server comprises: obtaining first connection information based on the user authentication token, the first user equipment ID and the second user equipment SN and the information of the server; generating a session key based on the information of the server and the second user equipment SN; generating the dynamic signature token based on the first connection information and the session key.

2. The data processing method of claim 1, wherein, the obtaining of the first connection information based on the user authentication token, the first user equipment ID and the second user equipment SN and the information of the server comprises: constructing a token header based on a preset algorithm; constructing a token payload based on the first user equipment ID, the second user equipment SN and the information of the server; verifying the user authentication token based on the token header and the token payload; if the verification is passed, encoding the token header and the token payload to obtain an encoded token header and an encoded token payload; connecting the encoded token header and the encoded token payload to obtain the first connection information.

3. The data processing method of claim 1, wherein, the generating of the session key based on the information of the server and the second user equipment SN comprises: obtaining a master key of the server and obtaining a preset hash algorithm; performing hash operation on the master key of the server and the second user equipment SN based on the preset hash algorithm to generate the session key.

4. The data processing method of claim 1, wherein, the generating of the dynamic signature token based on the first connection information and the session key comprises: calculating an inner padding key and an outer padding key based on the session key; calculating second connection information based on the inner padding key and the first connection information; generating third connection information based on the outer padding key and the second connection information; connecting the first connection information and the encoded third connection information to obtain the dynamic signature token.

5. The data processing method of claim 1, wherein, after the sending of the dynamic signature token to the first user equipment, the method further comprises: receiving a second request sent by the second user equipment, wherein the second request comprises the dynamic signature token; parsing the second request to obtain parsing information; generating verification information based on the second request; comparing and verifying the parsing information and the verification information; if the parsing information and the verification information are consistent, generating a permanent credential and sending the permanent credential to the second user equipment.

6. The data processing method of claim 5, wherein, before the generating of the permanent credential and the sending of the permanent credential to the second user equipment if the parsing information and the verification information are consistent, the method comprises: extracting a timestamp in the second request; comparing the timestamp with a current time; if the current time is in a valid period according to the comparison result, determining that the verification is passed.

7. A data processing apparatus, characterized by, The method comprises: receive a first request sent by a first user equipment, wherein the first request comprises a user authentication token, a first user equipment ID and a second user equipment SN, wherein the second user equipment is a to-be-verified device; generate a dynamic signature token based on the first request and information of a server, wherein the dynamic signature token is used for authenticating the second user equipment; send the dynamic signature token to the first user equipment; the generation module is further configured to obtain first connection information based on the user authentication token, the first user equipment ID and the second user equipment SN and the information of the server; generate a session key based on the information of the server and the second user equipment SN; generate the dynamic signature token based on the first connection information and the session key.

8. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, The processor implements the steps of the data processing method according to any one of claims 1 to 6 when executing the computer program.

9. A computer-readable storage medium storing a computer program, the computer program comprising instructions that, when executed by a computer, cause the computer to perform the method of any one of claims 1 to 8. The computer program is executed by the processor to implement the steps of the data processing method according to any one of claims 1 to 6.

Citation Information

Patent Citations

  • Equipment authentication method, device and system, terminal equipment and storage medium

    CN112417425A

  • Mutual authentication method between mutual authentication devices based on session key and token, mutual authentication devices

    KR1020170017455A