Authentication method and apparatus, and readable storage medium and electronic device
By pre-injecting the sectional program on the server and client, decoupling and fine-grained access control of the authentication function is achieved, and the problem of coupling identity confirmation function with other functions in the prior art is solved, enhancing the security of private data.
Patent Information
- Application Number
- PCT/CN2024/128073
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-13
- Filing Date
- 2024-10-29
- Publication Date
- 2025-06-19
AI Technical Summary
In the prior art, the identity confirmation function is coupled with other functions of the client and server, which makes it easy to interfere with other functions when it is necessary to modify the identity confirmation function, and cannot achieve fine-grained authentication, increasing the risk of privacy leakage.
By pre-injecting the sectional program on the server and the client, decoupling of the authentication function is achieved, thereby avoiding interference with other functions, and determining the client's access rights through authentication, controlling the return of access data in a granular manner.
The authentication function is decoupled from other functions, avoiding interference with other functions, and through fine-grained access control, the security of private data is enhanced and the risk of privacy leakage is reduced.
Smart Images

Figure CN2024128073_19062025_PF_FP_ABST
Abstract
Description
Authentication method, device, readable storage medium and electronic device Technical Field
[0001] This specification relates to the field of privacy protection technology, and more specifically to an authentication method, device, readable storage medium, and electronic device. Background Art
[0002] With the development of Internet technology, users can achieve different functions through various application clients installed on terminal devices. When implementing their functions, application clients usually need to interact with the server, such as accessing server data and calling server interfaces.
[0003] Since the server stores a lot of private data (for example, in a trusted execution environment), when a client requests data from the server, the server will first confirm the identity of the client and then return the requested data to the client to prevent illegal clients from calling private data and causing privacy leaks.
[0004] However, the above functions are coupled with other functions of the client and the server. When the above functions need to be modified, the source code needs to be modified, which causes interference to other functions of the client and the server.
[0005] Summary of the Invention
[0006] One of the purposes of this specification is to provide an authentication method that is applied to a server. When a client accesses the server, the authentication function is implemented by pre-injecting a first-section program at a first preset section point on the server, so as to decouple the authentication function from other functions of the server and avoid interference with other functions.
[0007] Based on the above purpose, this specification provides an authentication method, which is applied to a server, and a first aspect program is pre-injected at a first preset cut-off point of the server. The authentication method includes: when a client accesses the server, receiving an access request sent by the client for accessing the server; wherein the access request carries the identity information of the client; the first aspect program determines the identity of the client based on the identity information of the client, and determines the access rights of the client based on the identity of the client, and then obtains access data based on the access rights of the client; and sends the access data to the client.
[0008] In some implementations, determining the identity of the client based on the identity information of the client includes: comparing the identity information of the client with pre-stored standard identity information to determine the identity of the client.
[0009] In some implementations, determining the access rights of the client according to the identity of the client includes searching for the access rights of the client in a preset access rights configuration table according to the identity of the client.
[0010] In some implementations, obtaining access data based on the access rights of the client includes: determining accessible fields of the client based on the access rights of the client; and obtaining all accessible fields of the client as access data.
[0011] Another purpose of this specification is to provide an authentication method, which is applied to the client and implements the authentication function by pre-injecting a second aspect program at a second preset tangent point of the client, so as to decouple the authentication function from other functions of the client and avoid interference with other functions.
[0012] Based on the above purpose, this specification provides an authentication method, which is applied to a client, and a second aspect program is pre-injected at the second preset aspect point of the client. The authentication method includes: when the client accesses the server, an access request for accessing the server is generated; the identity information of the client is collected through the second aspect program, and the identity information of the client is inserted into the access request; the access request carrying the identity information of the client is sent to the server, so that the server confirms the identity of the client based on the identity information of the client, and determines the access rights of the client based on the identity of the client, and then obtains access data based on the access rights of the client and sends the access data to the client; and receives the access data sent by the server.
[0013] Another purpose of this specification is to provide an authentication device, which is applied to a server, and implements an authentication function by pre-injecting a first section program at a first preset section point on the server, so as to decouple the authentication function from other functions of the server to avoid interference with other functions.
[0014] Based on the above purpose, this specification provides an authentication device, which is applied to a server, and a first aspect program is pre-injected at a first preset aspect point of the server. The authentication device includes: a first receiving module, which is used to receive an access request sent by the client for accessing the server when the client accesses the server; wherein the access request carries the identity information of the client; a determination module, which is used to determine the identity of the client according to the identity information of the client through the first aspect program, and determine the access rights of the client according to the identity of the client, and then obtain access data according to the access rights of the client; a first sending module, which is used to send the access data to the client.
[0015] In some implementations, determining the identity of the client based on the identity information of the client includes: comparing the identity information of the client with pre-stored standard identity information to determine the identity of the client.
[0016] In some implementations, determining the access rights of the client according to the identity of the client includes searching for the access rights of the client in a preset access rights configuration table according to the identity of the client.
[0017] In some implementations, obtaining access data based on the access rights of the client includes: determining accessible fields of the client based on the access rights of the client; and obtaining all accessible fields of the client as access data.
[0018] Another embodiment of the present specification provides an authentication device, which uses a client to implement an authentication function by pre-injecting a second aspect program at a second preset tangent point of the client, so as to decouple the authentication function from other functions of the client and avoid interference with other functions.
[0019] Based on the above-mentioned purpose, this specification provides an authentication device, which is applied to a client, and a second aspect program is pre-injected at the second preset aspect point of the client. The authentication device includes: a generation module, which is used to generate an access request for accessing the server when the client accesses the server; a collection module, which is used to collect the identity information of the client through the second aspect program and insert the identity information of the client into the access request; a second sending module, which is used to send the access request carrying the identity information of the client to the server, so that the server confirms the identity of the client based on the identity information of the client, and determines the access rights of the client based on the identity of the client, and then obtains access data based on the access rights of the client and sends the access data to the client; a second receiving module, which is used to receive the access data sent by the server.
[0020] Another object of this specification is to provide a readable storage medium having a computer program stored thereon, which, when executed in a computer, enables the computer to implement the authentication method described above.
[0021] Another object of this specification is to provide a computing device, which includes a memory and a processor, wherein the memory stores executable code, and when the processor executes the executable code, it implements the authentication method as described above. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] FIG1 is a flow chart of an authentication method applied to a server according to an embodiment of the present disclosure.
[0023] FIG2 is a flow chart of an authentication method applied to a client according to another embodiment of the present disclosure.
[0024] FIG3 is a structural block diagram of an authentication device applied to a server according to another embodiment of the present disclosure.
[0025] FIG4 is a structural block diagram of an authentication device applied to a client according to another embodiment of the present disclosure. DETAILED DESCRIPTION
[0026] Some embodiments of the present specification are given below in conjunction with the accompanying drawings and described in detail.
[0027] Security aspects use aspect-oriented programming (AOP) to dynamically add or modify security aspect implementations within an application's runtime logic without modifying the application. This allows the implementation of security aspects while decoupling the implementation from the application, thus avoiding development iteration issues caused by high coupling.
[0028] The aspect program mentioned here is an enhancement program that implements security aspect functionality based on functional operation logic. By using aspect-oriented programming, the aspect program can be injected into the corresponding cutpoints of the application. The aspect program is triggered during the execution of the application to implement the required security aspect functionality.
[0029] When an application executes its functions, it typically does so by calling methods. Therefore, any method in the application can be used as an entry point for an aspect program, known as a pointcut. The aspect program can then be injected into the corresponding pointcut. This allows the application to execute the injected aspect program when it reaches the pointcut, i.e., when it calls the corresponding application method.
[0030] Typically, the code responsible for injecting aspect programs into pointcuts is highly reusable. Therefore, the program implementing this process is often abstracted into a service module, the aspect base. The aspect base retrieves the aspect programs to be deployed and the pointcuts into which the aspect programs should be injected in the application from the server providing the security aspect functionality. After the application container is started, it is activated and injects the corresponding aspect programs into the application's pointcuts.
[0031] An application can be an application that provides functional services on a server of a functional platform. A functional service can be a functional service provided by a server of a functional platform to a user, such as a query function or a payment function. A functional service can also be a functional service provided by a server of a functional platform to other servers, such as a settlement function.
[0032] Of course, as can be seen from the above description, in order to decouple the program of the security aspect function from the application, this specification adopts an aspect-oriented programming method so that the program of the security aspect function and the application are intertwined during the execution of the function, but are parallel to each other and can be maintained independently. Therefore, unlike the function provider of the application, the third party that provides the security aspect function can manage the content involved in the security aspect function through the server, such as the configuration of the security aspect function management policy, the version iteration of the aspect program, the deployment rule configuration of the aspect program, etc. Of course, the security aspect function can be provided by a third party or a function provider.
[0033] When managing the content involved in the security aspect function, the server can record various configuration information through configuration files, such as the configuration of various policies and the configuration of deployment rules for aspect programs. This allows the aspect base to complete the deployment of aspect programs based on the configuration files, or the server can implement the security aspect function based on the configuration files.
[0034] In actual applications, the function provider usually has a computer room with several physical machines or physical servers, and uses physical machines to provide the physical resources required by the application. Of course, an application may not require all the physical resources of the entire physical machine, so generally multiple virtual hosts (virtual hosting) are run on a physical machine through virtualization technology. Each virtual host is independent of each other and each enjoys part of the physical resources of the physical machine. Then, the application container can be deployed in the virtual host and the application can be run through the application container. The application container usually contains the physical resources allocated to the application container, such as CPU, memory, etc., and the operating environment provided to the application container, such as the operating system (OS) or other operating environment data, such as the container's serial number (SN), the assigned IP (Influential Property), the application name, the tenant, the environment variables, etc.). The application can be deployed in the application container to perform the function.
[0035] In the scenario where functions are executed based on security aspects, the function provider or a third-party server that provides security aspect functions can provide a server to manage the content involved in the security aspect functions, deploy the aspect base in the application container, and inject the aspect program into the application in the application container through the aspect base to provide support for the security aspect functions of the function provider's application container.
[0036] Therefore, the aspect base can be pre-deployed in the function provider's application container. Generally, when the application container is started, the operating system provided to the application container is invoked and the pre-deployed aspect base is run. The aspect base then obtains the aspect program and the application's point of entry from the server and injects the aspect program into the application's point of entry in the application container. Alternatively, the aspect base can obtain the aspect program and the application's point of entry from the server during application execution and inject the aspect program into the application's point of entry in the application container.
[0037] Of course, how the aspect base obtains the information required to deploy the aspect program from the server can be configured as needed. For example, it can actively pull the required information from the server based on the configuration file, or the server can actively send the required information to the aspect base.
[0038] After the aspect program is injected into the application's point of entry, the application can trigger the aspect program during execution to implement the corresponding security aspect function.
[0039] When the client of the application installed on the terminal device implements its various functions, it needs to interact with the server, such as accessing the server's data, calling the server's interface, etc. Since the server stores a lot of sensitive privacy data, when the client requests data from the server, the server will first confirm the client's identity, and then return the requested data to the client to prevent illegal clients from calling private data and causing privacy leaks. The existing identity confirmation function is coupled with other functions of the client and server. When the identity confirmation function needs to be modified, the source code needs to be modified, resulting in interference with other functions of the client and server. In addition, after the server confirms that the client's identity is trustworthy, it will directly return the access data requested by the client without further confirming its access rights, that is, it cannot achieve fine-grained authentication, which may also lead to privacy leakage risks.
[0040] Based on this, an embodiment of this specification provides an authentication method. When a client accesses a server, the authentication function is implemented by pre-injecting a section program at a preset section point on the client and the server, so that the authentication function is decoupled from other functions of the client and the server to avoid interference with other functions; at the same time, the client's access rights are determined through authentication, and access data is returned based on the access rights to achieve fine-grained access control.
[0041] As shown in FIG1 , an embodiment of the present specification provides an authentication method applied to a server. A first aspect program is pre-injected into a first preset tangent point of the server. The authentication method includes steps S110 to S130 .
[0042] S110: When the client accesses the server, an access request sent by the client for accessing the server is received; wherein the access request carries the identity information of the client.
[0043] When a client accesses a server, the client first generates an access request, then inserts the client's identity information into the access request, and then sends the access request carrying the client's identity information to the server. The server then receives the access request carrying the client's identity information.
[0044] In some embodiments, the client's identity information may include any suitable information for proving the client's identity, such as the model of the terminal device on which the client is installed, the SN number (product serial number), the application version number, the terminal identity certificate, the user's mobile phone number, etc. After generating an access request, the client may collect the client's identity information and then insert the client's identity information into the access request.
[0045] S120: The first aspect program determines the identity of the client according to the identity information of the client, determines the access rights of the client according to the identity of the client, and then obtains access data according to the access rights of the client.
[0046] The first-cut program is pre-injected at the first preset cut-off point on the server. It can be injected into the first preset cut-off point through the first-cut base pre-deployed on the server. The injection method can be static injection or dynamic injection. The first-cut program can execute the preset authentication function. When the server executes the first preset cut-off point, the first-cut program will be triggered, and the first-cut program will implement its authentication function. After the first-cut program completes the authentication function, it will return to the original execution logic of the server to implement the original function of the server. The location of the first preset cut-off point can be selected as needed, and the location of the first preset cut-off point may also be different for different clients. For example, the first preset cut-off point can be the function of receiving access requests on the server. In this way, after the server receives the access request through the function of receiving access requests, it will trigger the first-cut program to implement the authentication function.
[0047] The authentication function of the first-level program is to determine the identity of the client based on the client's identity information, determine the client's access rights based on the client's identity, and then obtain access data based on the client's access rights.
[0048] In some embodiments, determining the identity of the client may involve performing identity authentication on the client, i.e., determining whether the client is a legitimate client. If so, trusting the identity information of the client and determining that the client's identity is the identity provided in the access request. In other embodiments, determining the identity of the client may involve not performing identity authentication on the client, but directly trusting the identity information carried in the client's access request and determining that the client's identity is the identity provided in the access request.
[0049] In some embodiments, the server pre-stores standard identity information of the client, and determining the identity of the client based on the identity information of the client includes: comparing the identity information of the client with the standard identity information of the client in the server to determine the identity of the client.
[0050] The client's standard identity information can be the client's registration baseline data, that is, the device and environment information registered and reported to the server when the terminal device installs the client, including the terminal device model, SN number (product serial number), application version number, terminal identity certificate, user mobile phone number, etc. The client's identity information is compared with the client's standard identity information on the server to determine the client's identity, which specifically includes weak consistency authentication methods and strong consistency authentication methods.
[0051] The weak consistency authentication method includes comparing part of the client's identity information (i.e., core information, such as identity certificate, user mobile phone number, SN number, etc.) with the corresponding part of the client's standard identity information on the server (i.e., standard identity certificate, standard user mobile phone number, standard SN number). If they are completely consistent, the client's identity information is trusted and the client's identity is determined to be the identity provided in the access request; otherwise, the client's identity information is not trusted and the client's identity is determined to be illegal. The weak consistency method only requires comparing part of the core information in the client's identity information, which can reduce the computational complexity of the comparison process while also ensuring a certain degree of authentication accuracy.
[0052] Strong consistency authentication involves comparing all information in the client's identity information with the standard identity information on the server. If they are identical, the client's identity information is trusted and confirmed to be the identity provided in the access request. Otherwise, the client's identity information is distrusted and deemed invalid. Because strong consistency authentication compares all information in the identity information, it offers high accuracy, but also requires a high computational load.
[0053] After determining the identity of the client, the access rights of the client can be determined, and then the access data can be obtained based on the access rights. Specifically, an access rights configuration table is pre-set in the server, and the access rights configuration table includes the identity of each client and its corresponding access rights. The corresponding access rights can be viewed in the access rights configuration table through the identity of the client. For example, the identity of the determined client can be used to search in the access rights configuration table. If the identity of the corresponding client is found, the corresponding access rights are obtained, which is the access rights of the determined client. If the identity of the corresponding client is not found (that is, the identity of the client does not exist in the access rights configuration table), it is determined that the client has no access rights. For clients with access rights, the corresponding access data can be obtained based on their access rights. For clients without access rights, the access data obtained is empty (that is, no access data can be obtained) or is an access error prompt.
[0054] In some embodiments, if the identity of the client is illegal, it can be directly determined that the client has no access rights and the access data obtained is empty; for legal clients, their access rights are searched in the access rights configuration table.
[0055] In some embodiments, the access rights can be refined to fields, that is, the access rights include fields that the client can access. Obtaining access data based on the client's access rights includes: determining the accessible fields of the client based on the client's access rights; and obtaining all accessible fields of the client as access data.
[0056] In an exemplary embodiment, access rights include authorization interfaces and field information. For example, for client C1, its access rights include authorization interfaces S1 and S2. The field information of S1 includes field A and field B, and the field information of S2 includes all fields. Assuming that the data of S1 includes field A, field B and field C, and the data of S2 includes field D and field E, the above access rights indicate that client C1 can access fields A and field B of S1, as well as fields D and field E of S2, but cannot access field C of S1. When client C1 sends an access request to the server for data of S1 and / or S2, the server will obtain fields A and field B of S1, and / or fields D and field E of S2 as access data and return them to client C1. By refining access rights to field granularity, unauthorized access can be prevented and leakage of privacy data can be avoided, thereby achieving more secure and refined access control.
[0057] When you need to change the access rights of each client, you only need to update the access rights configuration table in the server, which is very convenient.
[0058] Since the above-mentioned authentication function is implemented through the first aspect program, when changes are needed, it is only necessary to modify the first aspect program, and then send the modified first aspect program to the first aspect base of the server through the aspect server, and re-inject it into the first preset aspect point through the first aspect base. Then, the modified authentication function can be implemented. There is no need to modify the source code of the server, and it will not affect other functions of the server. It is very convenient.
[0059] S130: Send the access data to the client.
[0060] After the first-level program obtains the access data based on the client's access rights, it will return to the original execution logic of the server. Then the original execution logic of the server will send the access data to the client, so that the client can receive the data it can access.
[0061] The authentication method of the embodiment of this specification is applied to the server side, and the authentication function is realized by pre-injecting the first aspect program at the first preset tangent point of the server side, so as to decouple the authentication function from other functions of the server side to avoid interference with other functions; the access rights of the client are determined through authentication, and access data is returned according to the access rights to realize fine-grained access control.
[0062] As shown in FIG2 , another embodiment of the present specification provides an authentication method applied to a client, wherein a second aspect program is pre-injected into a second preset tangent point of the client, and the authentication method includes steps S210 to S240 .
[0063] S210: When the client accesses the server, an access request for accessing the server is generated.
[0064] In some embodiments, the access request may include the requested interface, data, etc., so that the server returns the data that the client can access according to the access request.
[0065] S220: Collect the client's identity information through the second aspect program, and insert the client's identity information into the access request.
[0066] The second aspect program is pre-injected at the second preset tangent point on the server side. It can be injected into the second preset tangent point through the second aspect base pre-deployed on the server side. The injection method can be static injection or dynamic injection. The second aspect program can execute the preset authentication function. When the client executes the second preset tangent point, the second aspect program will be triggered, and the second aspect program will implement its authentication function. After the second aspect program completes the authentication function, it will return to the original execution logic of the client to implement the original function of the client. The location of the second preset tangent point can be selected as needed, and the location of the second preset tangent point may also be different for different clients. For example, the second preset tangent point can be the client's function for generating an access request. In this way, after the client generates an access request through the function for generating an access request, the second aspect program will be triggered to implement the authentication function.
[0067] The authentication function of the second aspect program is to collect the client's identity information and insert the client's identity information into the access request.
[0068] In some embodiments, the client's identity information may include any suitable information for proving the client's identity, such as the model of the terminal device on which the client is installed, the SN number (product serial number), the application version number, the terminal identity certificate, the user's mobile phone number, etc.
[0069] In some embodiments, after the second aspect program collects the identity information of the client, it can first perform a legitimacy check on the identity information to determine whether it is legal. If so, it can be inserted into the access request; otherwise, it can be directly determined that the identity information of the client is illegal and no subsequent processes will be carried out.
[0070] In some embodiments, after the second aspect program collects the identity information of the client, it may also pre-process it (for example, perform a hash calculation) and then insert the pre-processed identity information into the access request.
[0071] Since the above-mentioned authentication function is implemented through the second aspect program, when changes are needed, it is only necessary to modify the second aspect program, and then send the modified second aspect program to the second aspect base of the client through the aspect server, and re-inject it into the second aspect point through the second aspect base. Then, the modified authentication function can be implemented. There is no need to modify the source code of the client, and it will not affect other functions of the client. It is very convenient.
[0072] S230: Send an access request carrying the client's identity information to the server, so that the server confirms the client's identity based on the client's identity information, determines the client's access rights based on the client's identity, and then obtains access data based on the client's access rights and sends the access data to the client.
[0073] After the second aspect program inserts the client's identity information into the access request, it returns to the client's original execution logic. The client's original execution logic then sends the access request carrying the client's identity information to the server. The server then determines the client's identity based on the client's identity information, determines access rights based on the client's identity, and then obtains access data based on the access rights and sends the access data to the client. The server's methods for determining the client's identity based on the client's identity information, determining access rights based on the client's identity, and then obtaining access data based on the access rights can be found in the previous embodiment and will not be repeated here.
[0074] S240: Receive access data sent by the server.
[0075] The access data sent by the server is the access data obtained after the server authenticates the client, which can avoid privacy leakage caused by unauthorized access by the client.
[0076] In some embodiments, the access data includes accessible fields. The server obtains the accessible fields of the client based on the field-based access rights, which can implement fine-grained authentication access control of the fields, thereby achieving more secure and refined access control.
[0077] The authentication method provided in the embodiment of this specification is applied to the client, and implements the authentication function by pre-injecting a second aspect program at a second preset tangent point of the client, so as to decouple the authentication function from other functions of the client and avoid interference with other functions.
[0078] As shown in Figure 3, another embodiment of this specification provides an authentication device, which is applied to a server. A first aspect program is pre-injected at a first preset tangent point of the server. The authentication device includes a first receiving module 11, a determining module 12 and a first sending module 13.
[0079] The first receiving module 11 is used to receive an access request sent by a client for accessing the server when the client accesses the server; wherein the access request carries the identity information of the client.
[0080] When a client accesses a server, the client first generates an access request, then inserts the client's identity information into the access request, and then sends the access request carrying the client's identity information to the server. The server then receives the access request carrying the client's identity information.
[0081] In some embodiments, the client's identity information may include any suitable information for proving the client's identity, such as the model of the terminal device on which the client is installed, the SN number (product serial number), the application version number, the terminal identity certificate, the user's mobile phone number, etc. After generating an access request, the client may collect the client's identity information and then insert the client's identity information into the access request.
[0082] The determination module 12 is used to determine the identity of the client according to the identity information of the client through the first aspect program, determine the access rights of the client according to the identity of the client, and then obtain access data according to the access rights of the client.
[0083] The first-cut program is pre-injected into the server at the first preset cut point. It can be injected into the first preset cut point via the first-cut base pre-deployed on the server. The injection method can be static injection or dynamic injection.
[0084] In some embodiments, determining the identity of the client may involve performing identity authentication on the client, i.e., determining whether the client is a legitimate client. If so, trusting the identity information of the client and determining that the client's identity is the identity provided in the access request. In other embodiments, determining the identity of the client may involve not performing identity authentication on the client, but directly trusting the identity information carried in the client's access request and determining that the client's identity is the identity provided in the access request.
[0085] In some embodiments, the server pre-stores standard identity information of the client, and determining the identity of the client based on the identity information of the client includes: comparing the identity information of the client with the standard identity information of the client in the server to determine the identity of the client.
[0086] The standard identity information of the client can be the client's registration baseline data, that is, the device and environment information registered and reported to the server when the terminal device installs the client, including the model of the terminal device, SN number (product serial number), application version number, terminal identity certificate, user mobile phone number, etc. The client's identity information is compared with the client's standard identity information in the server to determine the client's identity. Specifically, there are weak consistency authentication methods and strong consistency authentication methods. The weak consistency authentication method is to compare part of the client's identity information with the corresponding part of the standard identity information. The calculation amount is small and can also guarantee a certain degree of accuracy. The strong consistency authentication is to compare all the information of the client's identity information with all the information of the standard identity information. The accuracy is high, but correspondingly, the calculation amount is also large.
[0087] The server is pre-configured with an access rights configuration table, which includes the identity of each client and its corresponding access rights. The client's corresponding access rights can be viewed in the access rights configuration table based on its identity.
[0088] In some embodiments, if the identity of the client is illegal, it can be directly determined that the client has no access rights and the access data obtained is empty; for legal clients, their access rights are searched in the access rights configuration table.
[0089] In some embodiments, the access rights can be refined to fields, that is, the access rights include fields that the client can access. Obtaining access data based on the client's access rights includes: determining the accessible fields of the client based on the client's access rights; and obtaining all accessible fields of the client as access data.
[0090] By refining access rights to the field granularity, unauthorized access can be prevented and the leakage of private data can be avoided, thereby achieving more secure and refined access control.
[0091] When you need to change the access rights of each client, you only need to update the access rights configuration table in the server, which is very convenient.
[0092] Since the above-mentioned authentication function is implemented through the first aspect program, when changes are needed, it is only necessary to modify the first aspect program, and then send the modified first aspect program to the first aspect base of the server through the aspect server, and re-inject it into the first preset aspect point through the first aspect base. Then, the modified authentication function can be implemented. There is no need to modify the source code of the server, and it will not affect other functions of the server. It is very convenient.
[0093] The first sending module 13 is used to send the access data to the client.
[0094] The authentication device of the embodiment of this specification is applied to the server side, and the determination module 12 implements the authentication function by pre-injecting the first aspect program at the first preset tangent point of the server side, so as to decouple the authentication function from other functions of the server side to avoid interference with other functions; the determination module 12 determines the access rights of the client through authentication, and returns access data based on the access rights to achieve fine-grained access control.
[0095] As shown in Figure 4, another embodiment of this specification provides an authentication device, which is applied to a client. A second section program is pre-injected at the second preset section point of the client. The authentication device includes a generation module 21, an acquisition module 22, a second sending module 23 and a second receiving module 24.
[0096] The generating module 21 is used to generate an access request for accessing the server when the client accesses the server.
[0097] The collection module 22 is used to collect the identity information of the client through the second aspect program and insert the identity information of the client into the access request.
[0098] The second aspect program is pre-injected into the server at the second preset cutoff point. It can be injected into the second preset cutoff point via the second aspect base pre-deployed on the server. This injection method can be static or dynamic.
[0099] In some embodiments, the client's identity information may include any suitable information for proving the client's identity, such as the model of the terminal device on which the client is installed, the SN number (product serial number), the application version number, the terminal identity certificate, the user's mobile phone number, etc.
[0100] In some embodiments, after the second aspect program collects the identity information of the client, it can first perform a legitimacy check on the identity information to determine whether it is legal. If so, it can be inserted into the access request; otherwise, it can be directly determined that the identity information of the client is illegal and no subsequent processes will be carried out.
[0101] In some embodiments, after the second aspect program collects the identity information of the client, it may also pre-process it (for example, perform a hash calculation) and then insert the pre-processed identity information into the access request.
[0102] Since the above-mentioned authentication function is implemented through the second aspect program, when changes are needed, it is only necessary to modify the second aspect program, and then send the modified second aspect program to the second aspect base of the client through the aspect server, and re-inject it into the second aspect point through the second aspect base. Then, the modified authentication function can be implemented. There is no need to modify the source code of the client, and it will not affect other functions of the client. It is very convenient.
[0103] The second sending module 23 is used to send an access request carrying the client's identity information to the server, so that the server confirms the client's identity based on the client's identity information, determines the client's access rights based on the client's identity, and then obtains access data based on the client's access rights and sends the access data to the client.
[0104] The second receiving module 24 is used to receive access data sent by the server.
[0105] The access data sent by the server is the access data obtained after the server authenticates the client, which can avoid privacy leakage caused by unauthorized access by the client.
[0106] In some embodiments, the access data includes accessible fields. The server obtains the accessible fields of the client based on the field-based access rights, which can implement fine-grained authentication access control of the fields, thereby achieving more secure and refined access control.
[0107] The authentication device of the embodiment of this specification is applied to the client, and the acquisition module 22 implements the authentication function by pre-injecting a second section program at a second preset section point of the client, so as to decouple the authentication function from other functions of the client and avoid interference with other functions.
[0108] Another embodiment of the present specification provides a readable storage medium having a computer program stored thereon. When the computer program is executed in a computer, the computer is caused to execute the steps of the authentication method in the above embodiment of the present specification.
[0109] Another embodiment of the present specification provides a computing device, which includes a memory and a processor. The memory stores executable code. When the processor executes the executable code, it performs the steps of the authentication method in the above embodiment of the present specification.
[0110] The systems, devices, modules, or units described in the above embodiments may be implemented by computer chips or entities, or by products having certain functions. A typical implementation device is a computer. Specifically, the computer may be, for example, a personal computer, a laptop computer, a cellular phone, a camera phone, a smartphone, a personal digital assistant, a media player, a navigation device, an email device, a game console, a tablet computer, a wearable device, or a combination of any of these devices.
[0111] For the convenience of description, the above devices are described as being divided into various units according to their functions. Of course, when implementing this specification, the functions of each unit can be implemented in the same or multiple software and / or hardware.
[0112] Those skilled in the art will appreciate that the embodiments of this specification may be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, this specification may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0113] This specification is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of this specification. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device produce a device for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0114] These computer program instructions may also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device that implements the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0115] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.
[0116] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0117] Memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. Memory is an example of a computer-readable medium.
[0118] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0119] It should also be noted that the terms "comprises," "includes," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, commodity, or apparatus that includes a series of elements includes not only those elements but also other elements not explicitly listed, or includes elements inherent to such process, method, commodity, or apparatus. In the absence of further limitations, an element defined by the phrase "comprises a ..." does not exclude the presence of other identical elements in the process, method, commodity, or apparatus that includes the element.
[0120] This specification may be described in the general context of computer-executable instructions, such as program modules, executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, and the like that perform specific tasks or implement specific abstract data types. This specification may also be practiced in distributed computing environments where tasks are performed by remote processing devices connected through a communications network. In a distributed computing environment, program modules may be located in both local and remote computer storage media, including storage devices.
[0121] The various embodiments in this specification are described in a progressive manner. Similar parts between the various embodiments can be referred to in conjunction with each other. Each embodiment focuses on the differences between the other embodiments. In particular, the system embodiments are generally similar to the method embodiments, so the description is relatively simple. For relevant parts, refer to the description of the method embodiments.
[0122] The above descriptions are merely examples of embodiments of this specification and are not intended to limit the scope of this specification. Various modifications are possible. In other words, any simple, equivalent changes and modifications made in accordance with the claims and the description of this application fall within the scope of protection of the claims of this application. Anything not fully described in this specification represents conventional technology.
Claims
1. An authentication method, applied to a server, wherein a first section program is pre-injected into a first preset section point of the server, and the authentication method comprises: When a client accesses a server, receiving an access request sent by the client for accessing the server; wherein the access request carries the identity information of the client; The first aspect program determines the identity of the client according to the identity information of the client, determines the access rights of the client according to the identity of the client, and then obtains access data according to the access rights of the client; The access data is sent to the client.
2. The authentication method according to claim 1, wherein: Determining the identity of the client according to the identity information of the client specifically includes: The identity information of the client is compared with pre-stored standard identity information to determine the identity of the client.
3. The authentication method according to claim 1, wherein: Determining the access rights of the client according to the identity of the client includes: The access rights of the client are searched in a preset access rights configuration table according to the identity of the client.
4. The authentication method according to claim 1, wherein: Access data is obtained according to the access rights of the client, including: Determining the accessible fields of the client according to the access rights of the client; Get all accessible fields of the client as access data.
5. An authentication method, applied to a client, wherein a second section program is pre-injected into a second preset section point of the client, and the authentication method comprises: When the client accesses the server, generating an access request for accessing the server; Collecting the identity information of the client through the second aspect program, and inserting the identity information of the client into the access request; Sending an access request carrying the identity information of the client to the server, so that the server confirms the identity of the client according to the identity information of the client, determines the access rights of the client according to the identity of the client, and then obtains access data according to the access rights of the client and sends the access data to the client; Receive access data sent by the server.
6. An authentication device, applied to a server, wherein a first section program is pre-injected into a first preset section point of the server, and the authentication device comprises: A first receiving module, used for receiving an access request sent by a client for accessing the server when the client accesses the server; wherein the access request carries the identity information of the client; a determination module, configured to determine the identity of the client according to the identity information of the client through the first aspect program, determine the access rights of the client according to the identity of the client, and then obtain access data according to the access rights of the client; The first sending module is used to send the access data to the client.
7. The authentication device according to claim 6, wherein: Determining the identity of the client according to the identity information of the client includes: The identity information of the client is compared with pre-stored standard identity information to determine the identity of the client.
8. The authentication device according to claim 6, wherein: Determining the access rights of the client according to the identity of the client includes: The access rights of the client are searched in a preset access rights configuration table according to the identity of the client.
9. The authentication device according to claim 6, wherein: Access data is obtained according to the access rights of the client, including: Determining the accessible fields of the client according to the access rights of the client; Get all accessible fields of the client as access data.
10. An authentication device, applied to a client, wherein a second section program is pre-injected into a second preset section point of the client, and the authentication device comprises: A generating module, used for generating an access request for accessing the server when the client accesses the server; A collection module, configured to collect the identity information of the client through the second aspect program, and insert the identity information of the client into the access request; A second sending module is used to send an access request carrying the identity information of the client to the server, so that the server confirms the identity of the client according to the identity information of the client, determines the access rights of the client according to the identity of the client, and then obtains access data according to the access rights of the client and sends the access data to the client; The second receiving module is used to receive the access data sent by the server.
11. A readable storage medium having a computer program stored thereon, which, when executed in a computer, enables the computer to implement the authentication method according to any one of claims 1 to 5.
12. A computing device comprising a memory and a processor, wherein an executable code is stored in the memory, and when the processor executes the executable code, it implements the authentication method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Data access method and equipment based on open API (Application Program Interface) and medium
CN114826661A
Service execution method and device, storage medium and electronic equipment
CN115185605A
Service calling method and device, storage medium and electronic equipment
CN115617471A
Service request processing method, device and equipment
CN115935427A
Key distribution method, key distribution device, communication method and communication device
CN117081736A
Cited By
Method for realizing interface authentication based on Springboot aspect
CN121644136A