Authentication method, electronic device, server, server management platform and system
Patent Information
- Application Number
- CN202610969849.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2020-05-27
- Publication Date
- 2026-09-25
AI Technical Summary
[0006]由于在认证过程中,用户需要多次提交用户信息,所以不仅大大降低了认证效率,而且还用户造成了极大的不便
[0024]由于在本申请提供的访问网络资源的机制中,在接收到的来自于客户端的访问请求中添加标识信息,再将添加了标识信息的访问请求发送给服务端,在接收到服务端基于该标识信息返回的待验证标识时,通过验证待验证标识而非验证用户信息来实现对用户的合法性认证,使得服务端在对用户进行认证时不需要用户多次输入用户信息,所以大大提高了用户的认证效率,方便了用户操作。
Smart Images

Figure CN122824451A_ABST
Abstract
Description
[0001] This application is a divisional application of the invention application filed on May 27, 2020, with application number 2020104642239 and titled "An Authentication Method, Apparatus, Electronic Device and Server". Technical Field
[0002] This application relates to the field of computer communications, and in particular to authentication methods, electronic devices, servers, server management platforms, and systems. Background Technology
[0003] In a network architecture consisting of a client and at least one server, a server management platform is typically deployed to manage all servers in order to facilitate the management of the servers.
[0004] When a client needs to access network resources on a server, the client must first log in to the server management platform and then log in to the server before it can access the network resources on that server.
[0005] Specifically, the client needs to submit its user information to the server management platform for authentication. After the server management platform authenticates the client's user information, the client also needs to submit its user information to the server for authentication. Only after the server authenticates the client's user information will it return the network resources accessed by the client.
[0006] Because users need to submit their information multiple times during the authentication process, it not only greatly reduces authentication efficiency but also causes significant inconvenience to users. Summary of the Invention
[0007] In view of this, this application provides an authentication method, electronic device, server, server management platform, and system to improve user authentication efficiency.
[0008] Specifically, this application is implemented through the following technical solution: According to a first aspect of this application, an authentication method is provided, the method comprising: Upon receiving an access request from a client, generate identification information to be carried in the access request, and send the access request carrying the identification information to a first designated port on the server. Obtain the verification identifier returned by the first designated port; the verification identifier is returned by the server based on the identification information carried in the access request when the server detects that the access request has been received by the first designated port. The identifier to be verified is verified. If the identifier to be verified passes the verification, a first message indicating that the identifier has passed the verification is sent to a second designated port on the server, so that the server responds to the access request upon hearing that the second designated port has received the first message.
[0009] Optionally, the method is applied to an electronic device, which is a device located on the access path of the client accessing the server and connected to the server; the first designated port is a first port on the server connected to the electronic device; The second designated port is the second port on the server that connects to the electronic device; or, The method is applied to the server; the first designated port is the port on the server corresponding to the first designated protocol; the second designated port is the port on the server corresponding to the second designated protocol.
[0010] Optionally, after generating the identification information to be carried in the access request, the method further includes: Record the identification information; The verification of the identifier to be verified includes: Among all the recorded identification information, search for identification information that matches the identification to be verified; If it exists, then the identifier to be verified is determined to have passed verification; If it does not exist, then the identifier to be verified has failed verification.
[0011] Optionally, the method further includes: After confirming that the identifier to be verified has passed verification, delete the identifier information that matches the identifier to be verified; and / or, When the aging time of the identification information is detected to have expired, the identification information is deleted.
[0012] Optionally, the method further includes: If the identifier to be verified fails verification, a second message indicating that the identifier to be verified has failed verification is sent to the second designated port. This allows the server to instruct the client to provide verification information upon receiving the second message on the second designated port, and to verify the verification information provided by the client. Once the verification is successful, the server will respond to the access request.
[0013] According to a second aspect of this application, an authentication method is provided, the method being applied to a server, the method comprising: If an access request is received on the first designated port of the server, an identifier to be verified is returned to the peer that sent the access request based on the identification information carried in the access request. Upon receiving a first message indicating that the identifier to be verified has been successfully verified on the second designated port of the server, the access request is responded to.
[0014] Optionally, the first designated port is a first port on the server that connects to the peer; the second designated port is a second port on the server that connects to the peer. The peer is an electronic device that is on the access path of the client to the server and is connected to the server; or, The first designated port is the port on the server corresponding to the first designated protocol; the second designated port is the port on the server corresponding to the second designated protocol.
[0015] Optionally, the method further includes: If the system detects that the second message indicating that the identifier to be verified has failed verification is received on the second designated port, the system instructs the client to provide verification information, verifies the verification information provided by the client, and responds to the access request after the verification is successful.
[0016] According to a third aspect of this application, an authentication device is provided, the device comprising: The generation unit is used to generate identification information to be carried in the access request when receiving an access request from the client, and send the access request carrying the identification information to a first designated port on the server. The obtaining unit is used to obtain the verification identifier returned by the first designated port; the verification identifier is returned by the server based on the identifier information carried in the access request when the server listens to the first designated port receiving the access request; The verification unit is used to verify the identifier to be verified. If the identifier to be verified passes the verification, it sends a first message indicating that the identifier to be verified has passed the verification to a second designated port on the server, so that the server responds to the access request after listening to the second designated port receiving the first message.
[0017] According to a fourth aspect of this application, an authentication device is provided, the device comprising: The sending unit is configured to, upon detecting that an access request has been received on a first designated port of the server, return a verification identifier to the peer that sent the access request based on the identification information carried in the access request. The response unit is used to respond to the access request when the server receives a first message indicating that the identifier to be verified has been verified on a second designated port.
[0018] According to a fifth aspect of this application, an electronic device is provided, the device including a readable storage medium and a processor; The readable storage medium is used to store machine-executable instructions; The processor is configured to read the machine-executable instructions on the readable storage medium and execute the instructions to implement the authentication method steps in the first aspect described above.
[0019] According to a sixth aspect of this application, a server is provided, including a readable storage medium and a processor; The readable storage medium is used to store machine-executable instructions; The processor is configured to read the machine-executable instructions on the readable storage medium and execute the instructions to implement the authentication method steps in the second aspect described above.
[0020] According to a seventh aspect of this application, a computer program is provided, which is stored in a machine-readable storage medium, and when a processor executes the computer program, causes the processor to implement the authentication method in the first aspect described above.
[0021] According to an eighth aspect of this application, a computer program is provided, which is stored in a machine-readable storage medium, and when a processor executes the computer program, causes the processor to implement the authentication method in the second aspect described above.
[0022] According to a ninth aspect of this application, a machine-readable storage medium is provided, the machine-readable storage medium storing machine-executable instructions, which, when invoked and executed by a processor, cause the processor to perform the authentication method of the first aspect.
[0023] According to a tenth aspect of this application, a machine-readable storage medium is provided, the machine-readable storage medium storing machine-executable instructions, which, when invoked and executed by a processor, cause the processor to perform the authentication method of the second aspect.
[0024] Because the mechanism for accessing network resources provided in this application adds identification information to the access request received from the client, and then sends the access request with the added identification information to the server, when the server returns the identifier to be verified based on the identification information, the legitimacy of the user is verified by verifying the identifier to be verified rather than verifying the user information. This means that the user does not need to enter user information multiple times when the server authenticates the user, thus greatly improving the user authentication efficiency and making the user operation more convenient. Attached Figure Description
[0025] Figure 1 This is a schematic diagram illustrating an authentication network according to an exemplary embodiment of this application; Figure 2 This is a flowchart illustrating a conventional method for accessing network resources as shown in this application; Figure 3 This is a flowchart illustrating an authentication method in an exemplary embodiment of this application; Figure 4 This is a flowchart illustrating another authentication method in an exemplary embodiment of this application; Figure 5 This is an interactive diagram illustrating an authentication method according to an exemplary embodiment of this application; Figure 6 This is a hardware structure diagram of an electronic device illustrated in an exemplary embodiment of this application; Figure 7 This is a block diagram illustrating an authentication device according to an exemplary embodiment of this application; Figure 8 This is a hardware structure diagram of a server shown in an exemplary embodiment of this application; Figure 9 This is a block diagram illustrating another authentication device in an exemplary embodiment of this application. Detailed Implementation
[0026] Exemplary embodiments will now be described in detail, examples of which are illustrated in the accompanying drawings. When the following description relates to the drawings, unless otherwise indicated, the same numbers in different drawings denote the same or similar elements. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with this application. Rather, they are merely examples of apparatuses and methods consistent with some aspects of this application as detailed in the appended claims.
[0027] The terminology used in this application is for the purpose of describing particular embodiments only and is not intended to be limiting of the application. The singular forms “a,” “the,” and “the” used in this application and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used herein refers to and includes any or all possible combinations of one or more of the associated listed items.
[0028] It should be understood that although the terms first, second, third, etc., may be used in this application to describe various information, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, without departing from the scope of this application, first information may also be referred to as second information, and similarly, second information may also be referred to as first information. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to determination."
[0029] See Figure 1 , Figure 1 This is a schematic diagram illustrating an authentication network according to an exemplary embodiment of this application.
[0030] The authentication network consists of: a client, a server management platform, and at least one server.
[0031] The server has been certified by the server management platform in advance, and the server management platform can manage the server.
[0032] In this network architecture, the traditional way for a client to access the server's network resources is as follows: the client needs to log in to the server's management platform first, and then log in to the server itself before it can access the network resources on that server.
[0033] See Figure 2 , Figure 2 This is a flowchart illustrating a conventional method for accessing network resources as shown in this application.
[0034] Step 201: The client sends the first authentication request carrying user information to the server management platform.
[0035] In implementation, the client displays the server-side management platform login interface to the user, where the user can enter their information. After receiving the entered user information, the client can send a first authentication request carrying that user information to the server-side management platform.
[0036] Step 202: After receiving the first authentication request, the server-side management platform authenticates the user information carried in the first authentication request.
[0037] Step 203: The server-side management platform returns a message to the client indicating whether authentication was successful or failed.
[0038] The server-side management platform can also return authentication success or failure messages to the client.
[0039] Step 204: The client sends an access request to the server management platform.
[0040] Step 205: After confirming that the client has been successfully authenticated on the server management platform, the server management platform forwards the access request to the server.
[0041] Step 206: When the server determines that the client has not authenticated with the server, it sends an unauthenticated message to the server management platform.
[0042] Step 207: The server-side management platform forwards the unauthenticated message to the client.
[0043] Step 208: The client sends a second authentication request carrying user information to the server management platform.
[0044] In implementation, upon receiving an unauthenticated message, the client displays the server login interface to the user, where the user can enter their information. After obtaining the entered user information, the client can send a second authentication request containing that user information to the server management platform.
[0045] Step 209: The server management platform forwards a second authentication request carrying user information to the server.
[0046] Step 210: The server obtains the user information carried in the second authentication request and authenticates the client based on the user information.
[0047] Step 211: The server returns a message indicating successful or failed authentication to the server management platform.
[0048] Step 212: The server-side management platform returns a message to the client indicating whether authentication was successful or failed.
[0049] Step 213: The client sends an access request to the server management platform.
[0050] Step 214: The server management platform forwards the access request to the server.
[0051] Step 215: After confirming successful authentication of the client, the server returns the network resource requested by the access request to the server management platform.
[0052] Step 216: The server-side management platform forwards network resources to the client.
[0053] This shows that in traditional client-side network resource access technologies, users need to submit user information multiple times to log in to the server management platform and the server itself. This not only greatly reduces authentication efficiency but also causes significant inconvenience for users accessing network resources.
[0054] In view of this, this application provides an authentication method. Upon receiving an access request from a client, an identification information to be carried in the access request is generated, and an access request carrying the identification information is sent to a first designated port on the server. When the server detects that the access request has been received on the designated port, it returns a pending verification identifier based on the identification information carried in the access request. Upon receiving the pending verification identifier returned by the server, the pending verification identifier is verified. If the pending verification identifier passes verification, a first message indicating that the pending verification identifier has passed verification is sent to a second designated port on the server. This allows the server to respond to the access request upon detecting that the second designated port has received the first message.
[0055] Because the mechanism for accessing network resources provided in this application adds identification information to the access request received from the client, and then sends the access request with the added identification information to the server, when the server returns the identifier to be verified based on the identification information, the legitimacy of the user is verified by verifying the identifier to be verified rather than verifying the user information. This means that the user does not need to enter user information multiple times when the server authenticates the user, thus greatly improving the user authentication efficiency and making the user operation more convenient.
[0056] See Figure 3 , Figure 3 This is a flowchart illustrating an authentication method in an exemplary embodiment of this application, which may include the following steps.
[0057] Step 301: Upon receiving an access request from a client, generate identification information to be carried in the access request, and send the access request carrying the identification information to the first designated port on the server.
[0058] Step 302: Obtain the verification identifier returned by the first designated port; the verification identifier is returned by the server based on the identification information carried in the access request when it hears that the first designated port has received the access request.
[0059] Step 303: Verify the identifier to be verified. If the identifier to be verified passes the verification, send a first message indicating that the identifier to be verified has passed the verification to the second designated port on the server, so that the server responds to the access request when it hears that the second designated port has received the first message.
[0060] The identification information can correspond to the access request. The identification information can be generated randomly or based on the feature information of the access request. The specific method of generating the identification information is not limited here.
[0061] The identification information can be a token, or other information; no specific restrictions are placed on the identification information here.
[0062] In the embodiments of this application, Figure 3 The method shown can be applied to an electronic device, which can be a device on the access path of the client accessing the server and connected to the server. The first designated port is the first port on the server connecting to the electronic device. The second designated port is the first port on the server connecting to the electronic device. The first and second designated ports can be the same port on the server or different ports on the server; this is merely an illustrative example and not a specific limitation.
[0063] For example, the electronic device could be Figure 1 The server-side management platform shown. Of course, this electronic device could also be... Figure 1 The server management platform shown here is connected to the newly added device between the server and the server. Figure 1 (Not shown), this is merely an illustrative example of an electronic device and is not intended to specifically limit it.
[0064] Optionally, in the embodiments of this application, Figure 3 The method shown can be applied to the server side, where the first designated port is the first port on the server side corresponding to the designated protocol. The second designated port is the second port on the server side corresponding to the designated protocol. The first and second designated protocols can be the same protocol or different protocols; therefore, the first and second designated ports can be the same port or different ports. This is merely an illustrative example of the first and second designated ports and is not specifically limited thereto.
[0065] In implementation, the server-side may include a validity verification module and a business logic module. Of course, in practical applications, the server-side may also include modules related to the specific application; therefore, the specific modules included on the server-side are not limited here.
[0066] Figure 3 The method shown can be applied to the server-side validation module, where the first designated port can be the first port on the server corresponding to the specified protocol. The business module connects to the validation module through the first port.
[0067] The second designated port can be a second port on the server corresponding to the specified protocol. The business module connects to the validity verification module through the second port.
[0068] The following describes several ways to implement steps 301 to 303.
[0069] Method 1 for implementing steps 301 and 303: When this method is applied to a server-side management platform, the first designated port is the first port on the server used to connect to the server-side management platform. The second designated port is the second port on the server used to connect to the electronic device.
[0070] In steps 301 and 303, the client can send an access request to the server management platform. Upon receiving the access request from the client, the server management platform can generate identification information for the access request and add this identification information to the access request. Then, the server management platform can send the access request to the first designated port on the server.
[0071] After the server detects that the access request has been received on the first designated port, it can obtain the identification information carried in the access request and return the verification identifier to the server management platform based on the identification information.
[0072] The identifier to be verified can be identifier information or an identifier generated based on identifier information. This is just an example of the identifier to be verified and is not specifically limited to it.
[0073] Upon receiving the verification identifier returned by the server, the server-side management platform verifies the verification identifier.
[0074] If the identifier to be verified passes verification, the server management platform sends a first message indicating that the identifier has passed verification to a first designated port on the server, so that the server can respond to the access request (e.g., return the network resource accessed by the access request) when it hears that the first designated port has received the first message.
[0075] If the identifier to be verified fails verification, the server-side management platform sends a second message indicating that the identifier has failed verification to a first designated port on the server. This causes the server to instruct the client to provide verification information when it detects that the second message has been received on the first designated port. The server then verifies the verification information provided by the client and responds to the access request upon successful verification. This verification information can be user information (such as username, password, etc.), but it can also be other information. This is merely an illustrative example and is not specifically limited to any particular type of verification information.
[0076] The following describes the method for "verifying the identifier to be verified".
[0077] In this embodiment of the application, after generating the identification information to be carried in the access request, the identification information may also be recorded.
[0078] When verifying the identifier to be verified, you can search among all the recorded identifier information to see if there is any identifier information that matches the identifier to be verified. If there is an identifier that matches the identifier to be verified, then the identifier to be verified is determined to have passed the verification. If no matching identifier is found, the identifier to be verified is determined to have failed verification.
[0079] It should be noted that when the identifier to be verified is an identifier information, the identifier information that matches the identifier to be verified is the identifier to be verified.
[0080] When the identifier to be verified is generated by the identifier information based on the first rule, the identifier information that matches the identifier to be verified is the specified identifier information, and the identifier generated by the specified identifier information based on the first rule is the same as the identifier to be verified.
[0081] This is merely an illustrative description of "identification information", "identification to be verified", and "verification of identification to be verified", and is not specifically limited thereto.
[0082] Furthermore, in this embodiment of the application, in order to ensure the effectiveness of the verification of the identifier to be verified, after it is determined that the identifier to be verified has passed the verification, the identifier information matching the identifier to be verified can also be deleted.
[0083] Furthermore, in this embodiment of the application, in order to ensure the effectiveness of verifying the identifier to be verified, the identifier information is deleted when the aging time of the identifier information is detected to have arrived.
[0084] In one alternative implementation, after recording the identification information, an aging time is added to the identification information. Then, it can be periodically checked whether the aging time of the recorded identification information has expired, and the expired identification information can be deleted.
[0085] Method 2 for implementing steps 301 and 303: This method is applied to newly added electronic devices between the server-side management platform and the server. The first designated port is the first port on the server used to connect to the electronic device. The second designated port is the second port on the server used to connect to the electronic device.
[0086] In steps 301 and 303, the client can send an access request to the server management platform. Upon receiving the access request from the client, the server management platform can forward it to the newly added electronic device (referred to here as the target electronic device for convenience). The target electronic device can generate identification information for the access request and add this identification information to the access request. Then, the target electronic device can send the access request to the first port on the server.
[0087] After the server detects that the access request has been received on the first port, it can obtain the identification information carried in the access request and return a verification identifier to the target electronic device based on the identification information.
[0088] The target electronic device verifies the identifier to be verified upon receiving the identifier to be verified from the server.
[0089] If the identifier to be verified passes verification, the target electronic device sends a first message indicating that the identifier to be verified has passed verification to a first designated port on the server, so that the server responds to the access request when it detects that the first designated port has received the first message.
[0090] If the identifier to be verified fails the verification, the target electronic device sends a second message to the first designated port on the server, indicating that the identifier to be verified has failed the verification. This allows the server to instruct the client to provide verification information when it detects that the first designated port has received the second message. The server then verifies the verification information provided by the client and responds to the access request after the verification is successful.
[0091] It should be noted that the method for "verifying the identifier to be verified" is described above and will not be repeated here.
[0092] Method 3 for implementing steps 301 to 303: The server-side consists of a validity verification module and a business module. The server-side management platform establishes a connection with the validity verification module, and the validity verification module establishes a connection with the business module (such as a socket connection).
[0093] Figure 3 The method shown is applied to the server-side validity verification module. The first specified port is the port on the server corresponding to the first specified protocol. For example, the first specified port is the first port on the server corresponding to the HTTP protocol, such as port 80. The second specified port is the port on the server corresponding to the second specified protocol.
[0094] The business module establishes a first socket connection with the validity verification module through the first designated port. The business module can also establish a second socket connection with the validity verification module through the second designated port. In other words, the port on the business module for the first socket connection is the first designated port, and the business module can communicate with the validity verification module through the first designated port. The port on the business module for the second socket connection is the second designated port, and the business module can communicate with the validity verification module through the second designated port.
[0095] It should be noted that the second specified port can be the same as or different from the first specified port. Therefore, the first socket connection and the second socket connection can be the same or different.
[0096] In steps 301 and 303, the client can send an access request to the server management platform. Upon receiving the access request from the client, the server management platform can forward it to the server's authentication module. The authentication module can generate identification information for the access request and add this identification information to the access request. Then, the authentication module can send the access request to the first designated port on the server.
[0097] The business module can listen to the first designated port. After the business module hears that the access request has been received on the first designated port, it can obtain the identification information carried by the access request and return the identification to be verified to the legal verification module based on the identification information.
[0098] The validity verification module verifies the identifier to be verified upon receiving the identifier to be verified from the business module.
[0099] If the identifier to be verified passes verification, the validity verification module sends a first message indicating that the identifier to be verified has passed verification to a second designated port on the server, so that the business module responds to the access request when it hears that the second designated port has received the first message.
[0100] If the identifier to be verified fails the verification, the valid verification module sends a second message to the second designated port on the server indicating that the identifier to be verified has failed the verification. This allows the business module to instruct the client to provide verification information when it detects that the second designated port has received the second message. The module then verifies the verification information provided by the client and responds to the access request after the verification is successful.
[0101] It should be noted that by adopting this method, where "after receiving an access request from the server management platform, the server-side validity verification module can send the access request to a first designated port on the server, so that the business module on the server can listen to the first designated port and obtain the access request," the non-direct connection between the client and the server (i.e., the client is connected to the server management platform, and the server management platform is connected to the server) can be spoofed as a direct connection (i.e., the client is directly connected to the server). This makes the server-side business module think that the access request is a direct access request sent by the client, thereby allowing the server-side business module to ignore the handling of matters related to the server management platform protocol as much as possible, thus simplifying the server's processing flow for the access request.
[0102] It should also be noted that the method for "verifying the identifier to be verified" is described above and will not be repeated here.
[0103] As can be seen from the above description, on the one hand, identification information is added to the access request received from the client, and then the access request with the added identification information is sent to the server. When the server returns the identifier to be verified based on the identification information, the legitimacy of the user is verified by verifying the identifier to be verified instead of verifying the user information. This means that the server does not need the user to enter user information multiple times when authenticating the user, thus greatly improving the user authentication efficiency and making the user operation more convenient.
[0104] On the other hand, in the existing client-server management platform and server architecture, the server management platform is typically subject to secondary development to enable it to provide the network resources offered by the server. When a client accesses the server, it first logs into the server management platform. After successful login, the client sends an access request to the server management platform to access network resources on the server. The server management platform responds to the access request and returns the requested network resources to the client. It is clear that this approach requires secondary development of the server management platform, significantly increasing the workload for developers.
[0105] In this application, since the server-side management platform forwards the access request to the server, and the server responds to the client's access request, there is no need to perform secondary development on the server-side management platform, which greatly reduces the workload of developers.
[0106] See Figure 4 , Figure 4 This is a flowchart illustrating another authentication method in an exemplary embodiment of this application, which may include the steps shown below.
[0107] Step 401: If an access request is received on the first designated port of the server, based on the identification information carried in the access request, a verification identifier is returned to the peer that sent the access request. Step 402: If the server receives a first message indicating that the identifier to be verified has been verified on the second designated port, respond to the access request.
[0108] In the embodiments of this application, Figure 4 The method shown can be applied to the server-side or to the server-side validation module; however, it is not applicable here. Figure 4 The devices or modules used in the methods shown are specifically defined.
[0109] The following describes several ways to implement steps 401 and 402.
[0110] Method 1 for implementing steps 401 and 402: Figure 4 The method shown is applied on the server side, where the peer is a server management platform. The first designated port is the first port on the server side used to connect to the electronic device. The second designated port is the second port on the server side used to connect to the electronic device.
[0111] In steps 401 and 402, the client can send an access request to the server management platform. Upon receiving the access request from the client, the server management platform can generate identification information for the access request and add this identification information to the access request. Then, the server management platform can send the access request to the first designated port on the server.
[0112] After the server detects that the access request has been received on the first designated port, it can obtain the identification information carried in the access request and return the verification identifier to the server management platform based on the identification information.
[0113] Upon receiving the verification identifier returned by the server, the server-side management platform verifies the verification identifier.
[0114] If the identifier to be verified passes verification, the server management platform sends a first message indicating that the identifier has passed verification to a first designated port on the server, so that the server can respond to the access request (e.g., return the network resource accessed by the access request) when it hears that the first designated port has received the first message.
[0115] If the identifier to be verified fails the verification, the server management platform sends a second message to the first designated port on the server, indicating that the identifier to be verified has failed the verification. This allows the server to instruct the client to provide verification information when it detects that the first designated port has received the second message. The server then verifies the verification information provided by the client and responds to the access request after the verification is successful.
[0116] Method 2 for achieving steps 401 and 402: Figure 4 The method shown is applied on the server side, where the peer is the server management platform and a newly added electronic device between the server and the server. The first designated port is the first port on the server connected to the newly added electronic device. The second designated port is the second port on the server connected to the newly added electronic device.
[0117] In steps 401 and 402, the client can send an access request to the server management platform. Upon receiving the access request from the client, the server management platform can forward it to the newly added electronic device (referred to here as the target electronic device for convenience). The target electronic device can generate identification information for the access request and add this identification information to the access request. Then, the target electronic device can send the access request to the first port on the server.
[0118] After the server detects that the access request has been received on the first port, it can obtain the identification information carried in the access request and return a verification identifier to the target electronic device based on the identification information.
[0119] The target electronic device verifies the identifier to be verified upon receiving the identifier to be verified from the server.
[0120] If the identifier to be verified passes verification, the target electronic device sends a first message indicating that the identifier to be verified has passed verification to a first designated port on the server, so that the server responds to the access request when it detects that the first designated port has received the first message.
[0121] If the identifier to be verified fails the verification, the target electronic device sends a second message to the first designated port on the server, indicating that the identifier to be verified has failed the verification. This allows the server to instruct the client to provide verification information when it detects that the first designated port has received the second message. The server then verifies the verification information provided by the client and responds to the access request after the verification is successful.
[0122] Method 3 for achieving steps 401 and 402: The server-side consists of a validation module and a business logic module. The server-side management platform establishes a connection with the server-side validation module. The validation module then establishes a connection with the business logic module (e.g., via a socket connection).
[0123] Figure 4 The method shown is applied to the business module on the server side, and the peer is the server-side validity verification module. The first specified port is the port on the server side corresponding to the first specified protocol. For example, the first specified port is the first port on the server side corresponding to the HTTP protocol, such as port 80. The second specified port is the port on the server side corresponding to the second specified protocol.
[0124] In implementation, the business module establishes a first socket connection with the validity verification module through the first designated port. The business module can also establish a second socket connection with the validity verification module through the second designated port. In other words, the port on the business module for the first socket connection is the first designated port, and the business module can communicate with the validity verification module through the first designated port. Similarly, the port on the business module for the second socket connection is the second designated port, and the business module can communicate with the validity verification module through the second designated port.
[0125] In steps 401 and 402, the client can send an access request to the server management platform. Upon receiving the access request from the client, the server management platform can forward it to the server's authentication module. The authentication module can generate identification information for the access request and add this identification information to the access request. Then, the authentication module can send the access request to the first designated port on the server.
[0126] The business module can listen to the first designated port. After the business module hears that the access request has been received on the first designated port, it can obtain the identification information carried by the access request and return the identification to be verified to the legal verification module based on the identification information.
[0127] The validity verification module verifies the identifier to be verified upon receiving the identifier to be verified from the business module.
[0128] If the identifier to be verified passes verification, the validity verification module sends a first message indicating that the identifier to be verified has passed verification to a second designated port on the server, so that the business module responds to the access request when it hears that the second designated port has received the first message.
[0129] If the identifier to be verified fails the verification, the valid verification module sends a second message to the second designated port on the server indicating that the identifier to be verified has failed the verification. This allows the business module to instruct the client to provide verification information when it detects that the second designated port has received the second message. The module then verifies the verification information provided by the client and responds to the access request after the verification is successful.
[0130] Completed above Figure 4 Introduction.
[0131] The following describes a preferred embodiment of this application, using the token as the identifier and the identifier to be verified as the identifier information.
[0132] See Figure 5 , Figure 5 This is an interactive diagram illustrating an authentication method according to an exemplary embodiment of this application.
[0133] Step 501: The client sends a first authentication request carrying user information to the server management platform.
[0134] In implementation, the client displays the server-side management platform login interface to the user, where the user can enter their information. After receiving the entered user information, the client can send a first authentication request carrying that user information to the server-side management platform.
[0135] Step 502: After receiving the first authentication request, the server-side management platform authenticates the user based on the user information.
[0136] Step 503: The server-side management platform returns a message to the client indicating whether authentication was successful or failed.
[0137] Step 504: The client sends an access request to the server management platform.
[0138] Step 505: After confirming that the user has successfully authenticated on the server management platform, the server management platform forwards the access request to the server's validity verification module.
[0139] Step 506: The validity verification module assigns a token to the access request, adds the assigned token to the access request, and records the token assigned to the access request locally.
[0140] Step 507: The validity verification module sends an access request carrying a token to the target port on the server corresponding to the HTTP protocol.
[0141] Step 508: When the business module detects that an access request has been received on the target port, it obtains the Token in the access request.
[0142] Step 509: The business module sends a token to the validity verification module.
[0143] Step 510: The validity verification module checks whether there is a token that matches the token returned by the business module among all the tokens recorded locally.
[0144] If there is a matching token among all the tokens recorded locally that matches the token returned by the business module, then proceed to steps 511 to 513.
[0145] If none of the locally recorded tokens match the token returned by the business module, proceed to steps 514 to 521.
[0146] Step 511: If it exists, the validity verification module sends the first message of token verification to the target port.
[0147] Step 512: When the business module detects that the target port has received the first message, it returns the network resources requested by the access request to the server management platform.
[0148] Step 513: The server-side management platform forwards network resources to the client.
[0149] Step 514: If it does not exist, the validity verification module sends a second message to the target port that the token failed verification.
[0150] Step 515: When the business module detects that the target port has received the second message, it returns an unauthenticated message to the server management platform.
[0151] Step 516: The server-side management platform returns an unauthenticated message to the client.
[0152] Step 517: The client sends a second authentication request carrying user information to the server management platform.
[0153] In implementation, upon receiving an unauthenticated message, the client displays the server login interface to the user, where the user can enter their information. After obtaining the entered user information, the client can send a second authentication request containing that user information to the server management platform.
[0154] Step 518: The server-side management platform forwards a second authentication request carrying user information to the legitimacy verification module.
[0155] Step 519: The legitimacy verification module verifies the legitimacy of the user based on the user information.
[0156] Step 520: After confirming the user's legitimacy, send a third message confirming the user's legitimacy to the target port.
[0157] Step 521: After the business module detects that the target port has received a third message, it returns the network resources requested by the access request to the server management platform.
[0158] Step 522: The server-side management platform forwards the network resource to the client.
[0159] As can be seen from the above description, on the one hand, a token is added to the access request received from the client, and then the access request with the token added is sent to the server. When the token returned by the server is received, the client's legitimacy is verified by verifying the token instead of verifying user information. This means that the server does not need the user to enter user information multiple times when authenticating the client, thus greatly improving the verification efficiency and making it more convenient for the user.
[0160] On the other hand, since the server-side management platform forwards access requests to the server, and the server responds to the client's access requests, rather than the server-side management platform being responsible for responding to the access requests sent by the client, there is no need for secondary development of the server-side management platform in this application, which greatly reduces the workload of developers.
[0161] See Figure 6 , Figure 6 This is a hardware structure diagram of an electronic device illustrated in an exemplary embodiment of this application. The electronic device can be a server management platform, a newly added device between the server management platform and the server, or, of course, the electronic device itself can be the server. No specific limitation is made to this electronic device.
[0162] The electronic device may include: a readable storage medium and a processor; The readable storage medium is used to store machine-executable instructions; The processor is configured to read the machine-executable instructions on the readable storage medium and execute the instructions to implement the authentication method steps described above.
[0163] Optionally, in addition to the processor 602 and the machine-readable storage medium 603, the electronic device may also include a communication interface 601 and a bus 604; wherein the communication interface 601, the processor 602, and the machine-readable storage medium 603 communicate with each other through the bus 604. The processor 602 can execute the authentication method described above by reading and executing the machine-executable instructions corresponding to the authentication control logic in the machine-readable storage medium 603.
[0164] The machine-readable storage medium 603 mentioned herein can be any electronic, magnetic, optical, or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium can be volatile memory, non-volatile memory, or similar storage media. Specifically, the machine-readable storage medium 603 can be RAM (Random Access Memory), flash memory, storage drives (such as hard disk drives), solid-state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or combinations thereof.
[0165] See Figure 7 , Figure 7 This is a block diagram illustrating an authentication device according to an exemplary embodiment of this application. The device can be applied to... Figure 6 The electronic device, or the device that can be applied to the server-side legal verification module, may include the following units.
[0166] The generation unit 701 is used to generate identification information to be carried in the access request when receiving an access request from the client, and send the access request carrying the identification information to a first designated port on the server. The obtaining unit 702 is used to obtain the verification identifier returned by the first designated port; the verification identifier is returned by the server based on the identifier information carried in the access request when it hears that the first designated port has received the access request; The verification unit 703 is used to verify the identifier to be verified. If the identifier to be verified passes the verification, it sends a first message indicating that the identifier to be verified has passed the verification to a second designated port on the server, so that the server responds to the access request after listening to the second designated port receiving the first message.
[0167] Optionally, the method is applied to an electronic device, which is a device located on the access path of the client accessing the server and connected to the server; the first designated port is a first port on the server connected to the electronic device; The second designated port is the second port on the server that connects to the electronic device; or, The method is applied to the server; the first designated port is the port on the server corresponding to the first designated protocol; the second designated port is the port on the server corresponding to the second designated protocol.
[0168] Optionally, the electronic device is a server management platform for managing the server; or, The electronic device is a newly added device located between the server management platform and the server.
[0169] Optionally, the generation unit 701 is further configured to generate identification information to be carried after the access request and record the identification information; When verifying the identifier to be verified, the verification unit 702 searches among all recorded identifier information to see if there is any identifier information that matches the identifier to be verified; if there is, it is determined that the identifier to be verified has passed the verification; if there is no, it is determined that the identifier to be verified has failed the verification.
[0170] Optionally, the device further includes: Delete unit 704 ( Figure 7 (Not shown in the image), used to delete the identifier information matching the identifier to be verified after determining that the identifier to be verified has passed verification; and / or to delete the identifier information when the aging time of the identifier information is detected to have arrived.
[0171] Optionally, the verification unit 703 is further configured to send a second message indicating that the identifier to be verified has failed verification to the second designated port if the identifier to be verified fails verification, so that the server, upon hearing that the second designated port has received the second message, instructs the client to provide verification information, verifies the verification information provided by the client, and responds to the access request after the verification is successful.
[0172] In addition, an exemplary embodiment of this application also provides a server.
[0173] The server may include: a readable storage medium and a processor; The readable storage medium is used to store machine-executable instructions; The processor is configured to read the machine-executable instructions on the readable storage medium and execute the instructions to implement the authentication method steps described above.
[0174] Optional, such as Figure 8As shown, the server includes a processor 802, a machine-readable storage medium 803, a communication interface 801, and a bus 804. The communication interface 801, processor 802, and machine-readable storage medium 803 communicate with each other via the bus 804. The processor 802 can execute the authentication method described above by reading and executing the machine-executable instructions corresponding to the authentication control logic in the machine-readable storage medium 803.
[0175] The machine-readable storage medium 803 mentioned herein can be any electronic, magnetic, optical, or other physical storage device that can contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium can be volatile memory, non-volatile memory, or similar storage media. Specifically, the machine-readable storage medium 803 can be RAM (Random Access Memory), flash memory, storage drives (such as hard disk drives), solid-state drives, any type of storage disk (such as optical discs, DVDs, etc.), or similar storage media, or combinations thereof.
[0176] See Figure 9 , Figure 9 This is a block diagram illustrating another authentication device in an exemplary embodiment of this application. The device can be applied to... Figure 8 The device shown can also be applied to server-side business modules; no specific limitations are made here. The device may include the units shown below.
[0177] The sending unit 901 is configured to, upon detecting that an access request has been received on the first designated port of the server, return a verification identifier to the peer that sent the access request based on the identification information carried in the access request. The response unit 902 is configured to respond to the access request when the server receives a first message indicating that the identifier to be verified has been verified on the second designated port of the server.
[0178] Optionally, the first designated port is a first port on the server that connects to the peer; the second designated port is a second port on the server that connects to the peer. The peer is an electronic device that is on the access path of the client to the server and is connected to the server; or, The first designated port is the port on the server corresponding to the first designated protocol; the second designated port is the port on the server corresponding to the second designated protocol.
[0179] Optionally, the response unit 902 is further configured to, upon receiving a second message on the second designated port indicating that the identifier to be verified has failed verification, instruct the client to provide verification information, verify the verification information provided by the client, and respond to the access request after the verification is successful.
[0180] Furthermore, this application also provides a computer program stored in a machine-readable storage medium, which, when executed by a processor, causes the processor to perform the above-described functions. Figure 3 The authentication method shown.
[0181] Furthermore, this application also provides a computer program stored in a machine-readable storage medium, which, when executed by a processor, causes the processor to perform the above-described functions. Figure 4 The authentication method shown.
[0182] Furthermore, this application also provides a machine-readable storage medium storing machine-executable instructions that, when invoked and executed by a processor, cause the implementation of the above-mentioned... Figure 3 The authentication method shown.
[0183] Furthermore, this application also provides a machine-readable storage medium storing machine-executable instructions that, when invoked and executed by a processor, cause the implementation of the above-mentioned... Figure 4 The authentication method shown.
[0184] The specific implementation process of the functions and roles of each unit in the above device can be found in the implementation process of the corresponding steps in the above method, and will not be repeated here.
[0185] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this application according to actual needs. Those skilled in the art can understand and implement this without creative effort.
[0186] The above description is merely a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application.
Claims
1. An authentication method, characterized in that, The method includes: Upon receiving an access request from a client, an identification information to be carried in the access request is generated, and an access request carrying the identification information is sent to a first designated port on the server; the access request is sent by the client via the server management platform. Obtain the verification identifier returned by the first designated port; the verification identifier is returned by the server based on the identifier information carried in the access request when the server detects that the access request has been received by the first designated port. The identifier to be verified is verified. If the identifier to be verified passes the verification, a first message indicating that the identifier to be verified has passed the verification is sent to the first designated port on the server, so that the server responds to the access request after listening to the first designated port receiving the first message.
2. The method according to claim 1, characterized in that, After generating the identification information to be carried in the access request, the method further includes: Record the identification information; The verification of the identifier to be verified includes: Among all the recorded identification information, search for identification information that matches the identification to be verified; If it exists, then the identifier to be verified is determined to have passed verification; If it does not exist, then the identifier to be verified has failed verification.
3. The method according to claim 2, characterized in that, The method further includes: After confirming that the identifier to be verified has passed verification, delete the identifier information that matches the identifier to be verified; and / or, When the aging time of the identification information is detected to have expired, the identification information is deleted.
4. The method according to claim 1, characterized in that, The method further includes: If the identifier to be verified fails verification, a second message indicating that the identifier to be verified has failed verification is sent to the first designated port. This allows the server to instruct the client to provide verification information via the server management platform when it detects that the second message has been received on the first designated port. The server then verifies the verification information provided by the client via the server management platform and responds to the access request after the verification is successful.
5. An authentication method, characterized in that, The method includes: Upon detecting an access request received on the first designated port, a verification identifier is returned to the peer that sent the access request based on the identification information carried in the access request; wherein, the access request is sent by the client via the server management platform; Upon receiving a first message indicating that the identifier to be verified has been successfully verified on the first designated port, the access request is responded to.
6. The method according to claim 5, characterized in that, The method further includes: If the system detects that the first designated port has received a second message indicating that the identifier to be verified has failed verification, the system instructs the client to provide verification information via the server management platform, verifies the verification information provided by the client via the server management platform, and responds to the access request after the verification is successful.
7. An electronic device, characterized in that, The device includes a readable storage medium and a processor; The readable storage medium is used to store machine-executable instructions; The processor is configured to read the machine-executable instructions on the readable storage medium and execute the instructions to implement the steps of the method according to any one of claims 1-4.
8. A server-side management platform, characterized in that, The server-side management platform includes a readable storage medium and a processor; The readable storage medium is used to store machine-executable instructions; The processor is configured to read the machine-executable instructions on the readable storage medium and execute the instructions to implement the steps of the method according to any one of claims 1-4.
9. A server-side component, characterized in that, Includes readable storage media and processor; The readable storage medium is used to store machine-executable instructions; The processor is configured to read the machine-executable instructions on the readable storage medium and execute the instructions to implement the steps of the method of any one of claims 5-6.
10. A server-side component, characterized in that: Includes readable storage media and processor; The readable storage medium is used to store machine-executable instructions; The processor is configured to read the machine-executable instructions on the readable storage medium and execute the instructions to implement the steps of the method according to any one of claims 1-6.
11. A system, characterized in that, include: Client, server management platform, electronic device as described in claim 7, and server as described in claim 9; or, The client, the server management platform as described in claim 8, and the server as described in claim 9; or, The client, the server management platform, and the server as described in claim 10; or, The client, the server management platform as described in claim 8, and the server as described in claim 10.