Authorized login method and device, computer equipment, readable storage medium and program product
By generating graphic codes on the management and control server and displaying by the zero-trust client, and obtaining authorization page information in combination with the mobile terminal identification graphic code, the problem that the zero-trust client cannot achieve authorization login under strict network control environment is solved, and authorization login and business function access is achieved in offline state.
Patent Information
- Application Number
- CN202411995688.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-31
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2044-12-31
AI Technical Summary
In some enterprise scenarios, due to strict network access control policies, the user's terminal equipment does not allow access to the Internet, resulting in zero-trust clients being unable to achieve authorized login, and thus unable to access business functions.
By generating a graphic code on the control server, including the access address and user ID of the authorization page, and the zero-trust client displays the graphic code. The mobile terminal recognizes the graphic code to obtain the access address and user ID of the authorization page, and then sends a login authorization request to the control server, obtain user identity information based on the authorization code of the third-party platform, and completes the authorization login.
It realizes the authorized login of zero-trust clients offline, ensuring that users can access business functions in strict network control environments.
Smart Images

Figure CN120128357A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of Internet technologies, and in particular, to an authorization login method, apparatus, computer device, computer-readable storage medium, and computer program product. Background Art
[0002] With the development of network security, the application of the zero-trust architecture is becoming more and more extensive. When a user accesses a service function under the zero-trust architecture, it is usually necessary to authorize and log in to the zero-trust client through a third-party application (such as DingTalk, Enterprise WeChat, etc.) and initiate an identity authentication. The control server in the zero-trust architecture will perform identity authentication based on the user's identity information, the device health status corresponding to the zero-trust client, and the access behavior, so as to determine whether to grant the user access permission.
[0003] In some enterprise scenarios, due to strict network access control policy restrictions, the user's terminal device is not allowed to access the Internet. Therefore, in this scenario, the zero-trust client cannot achieve authorization login, resulting in the inability to access the service function. Summary of the Invention
[0004] Based on this, it is necessary to provide an authorization login method, apparatus, computer device, computer-readable storage medium, and computer program product for the above technical problems.
[0005] In a first aspect, the present application provides an authorization login method, which is applied to a control server and includes:
[0006] In response to an access request for an authorization page sent by a mobile terminal, feedback the authorization page to the mobile terminal; the access request is sent by the mobile terminal in response to identifying a graphic code displayed by a zero-trust client, and the graphic code is generated based on parameter information in the control server; the parameter information at least includes the access address of the authorization page and a user identifier, and the authorization page is used to trigger a login authorization request;
[0007] Receive a login authorization request sent by the mobile terminal, where the login authorization request carries an authorization code provided by a third-party platform and the user identifier;
[0008] Based on the authorization code, obtain the identity information corresponding to the user identifier from the third-party platform, and complete the authorization login process.
[0009] In one of the embodiments, the method further includes:
[0010] In response to a parameter acquisition request sent by the zero-trust client, generate a user identifier and a device identifier corresponding to the zero-trust client;
[0011] Send parameter information to the zero-trust client, where the parameters include the user identifier, the device identifier, and the access address of the pre-stored authorization page.
[0012] In one embodiment, the method further includes:
[0013] Receive an authorization query request sent by the zero-trust client, where the authorization query request carries the device identifier;
[0014] Determine the user identifier corresponding to the device identifier, and query whether there is identity information corresponding to the user identifier;
[0015] When there is the identity information, feedback an authorization query result indicating successful authorization login to the zero-trust client;
[0016] When there is no such identity information, feedback an authorization query result indicating failed authorization login to the zero-trust client.
[0017] In a second aspect, the present application also provides an authorization login method, which is applied to a zero-trust client. The method includes:
[0018] In response to a login instruction, send a parameter acquisition request to the management and control server; the parameter acquisition request is used to instruct the management and control server to return parameter information corresponding to the zero-trust client; wherein, the parameter information at least includes the access address of the authorization page and the user identifier;
[0019] Receive the parameter information sent by the management and control server, generate and display a graphic code based on the parameter information; the graphic code is used to enable a mobile terminal to obtain the access address of the authorization page and the user identifier, and perform authorization login processing based on the access address of the authorization page and the user identifier.
[0020] In one embodiment, the step of, in response to a login instruction, sending a parameter acquisition request to the management and control server includes:
[0021] In response to a login instruction, detect the current network connectivity status;
[0022] When the network connectivity status is not connected, send a parameter acquisition request to the management and control server.
[0023] In one embodiment, the parameter information further includes a device identifier, and the method further includes:
[0024] Send an authorization query request to the management and control server, where the query request carries the device identifier;
[0025] Receive the authorization query result sent by the control server, where the authorization query result is used to indicate whether the authorized login is successful.
[0026] Thirdly, the present application also provides an authorized login device, which is applied to the control server. The device includes:
[0027] A feedback module, configured to, in response to an access request for an authorization page sent by a mobile terminal, feedback the authorization page to the mobile terminal; the access request is sent by the mobile terminal in response to recognizing a graphic code displayed by a zero-trust client, and the graphic code is generated based on parameter information in the control server; the parameter information at least includes an access address of the authorization page and a user identifier, and the authorization page is used to trigger a login authorization request;
[0028] A first receiving module, configured to receive a login authorization request sent by the mobile terminal, where the login authorization request carries an authorization code provided by a third-party platform and the user identifier;
[0029] An authorized login module, configured to obtain identity information corresponding to the user identifier from the third-party platform based on the authorization code, and complete the authorized login process.
[0030] In one embodiment, the device further includes:
[0031] A generation module, configured to, in response to a parameter acquisition request sent by the zero-trust client, generate a user identifier and a device identifier corresponding to the zero-trust client;
[0032] A first sending module, configured to send parameter information to the zero-trust client, where the parameter includes the user identifier, the device identifier, and an access address of a pre-stored authorization page.
[0033] In one embodiment, the device further includes:
[0034] A second receiving module, configured to receive an authorization query request sent by the zero-trust client, where the authorization query request carries the device identifier;
[0035] A query module, configured to determine a user identifier corresponding to the device identifier, and query whether there is identity information corresponding to the user identifier;
[0036] A second sending module, configured to, when there is the identity information, feedback an authorization query result indicating successful authorized login to the zero-trust client;
[0037] The second sending module is further configured to, when there is no such identity information, feedback an authorization query result indicating failed authorized login to the zero-trust client.
[0038] In a fourth aspect, the present application further provides an authorization login device, which is applied to a zero-trust client. The device includes:
[0039] A first sending module, configured to send a parameter acquisition request to a management and control server in response to a login instruction; the parameter acquisition request is used to instruct the management and control server to return parameter information corresponding to the zero-trust client; wherein, the parameter information at least includes an access address of an authorization page and a user identifier;
[0040] A first receiving module, configured to receive the parameter information sent by the management and control server, generate and display a graphic code based on the parameter information; the graphic code is used to enable a mobile terminal to obtain the access address of the authorization page and the user identifier, and perform authorization login processing based on the access address of the authorization page and the user identifier.
[0041] In one embodiment, the first sending module is specifically configured to:
[0042] In response to a login instruction, detect the current network connectivity status;
[0043] In the case where the network connectivity status is not connected, send a parameter acquisition request to the management and control server.
[0044] In one embodiment, the parameter information further includes a device identifier, and the device further includes:
[0045] A second sending module, configured to send an authorization query request to the management and control server, and the query request carries the device identifier;
[0046] A second receiving module, configured to receive an authorization query result sent by the management and control server, and the authorization query result is used to indicate whether the authorization login is successful.
[0047] In a fifth aspect, the present application further provides an authorization login system, including a zero-trust client and a management and control server; wherein:
[0048] The zero-trust client is configured to send a parameter acquisition request to the management and control server in response to a login instruction; the parameter acquisition request is used to instruct the management and control server to return parameter information corresponding to the zero-trust client; wherein, the parameter information at least includes an access address of an authorization page and a user identifier; receive the parameter information sent by the management and control server, and generate and display a graphic code based on the parameter information;
[0049] The control server is configured to respond to an access request for an authorization page sent by a mobile terminal, and feedback the authorization page to the mobile terminal; the access request is sent by the mobile terminal in response to the recognition of a graphic code displayed by a zero-trust client, and the authorization page is used to trigger a login authorization request; receive a login authorization request sent by the mobile terminal, where the login authorization request carries an authorization code provided by a third-party platform and the user identifier; obtain the identity information corresponding to the user identifier from the third-party platform based on the authorization code, and complete the authorization login process.
[0050] In a sixth aspect, the present application further provides a computer device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the method steps of the first aspect or the second aspect are implemented.
[0051] In a seventh aspect, the present application further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the method steps of the first aspect or the second aspect are implemented.
[0052] In an eighth aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the method steps of the first aspect or the second aspect are implemented.
[0053] For the above authorization login method, device, computer device, computer-readable storage medium, and computer program product, the control server can feedback an authorization page to the mobile terminal in response to an access request for the authorization page sent by the mobile terminal. Among them, the access request is sent by the mobile terminal in response to the recognition of a graphic code displayed by a zero-trust client, and the graphic code is generated based on parameter information in the control server; the parameter information at least includes the access address of the authorization page and the user identifier, and the authorization page is used to trigger a login authorization request. Then, the control server can receive a login authorization request sent by the mobile terminal, where the login authorization request carries an authorization code provided by a third-party platform and the user identifier, and further obtain the identity information corresponding to the user identifier from the third-party platform based on the authorization code, and complete the authorization login process. Through this solution, the zero-trust client can display a graphic code based on the parameter information provided by the control server, without obtaining an image code from a third-party platform, realizing the offline display of the graphic code. Moreover, the control server can also provide an authorization page to the mobile terminal so that the user can perform a login operation on the authorization page, thereby obtaining an authorization code from the third-party platform through the interaction between the mobile terminal and the third platform, and then obtaining the user's identity information from the third-party platform based on the authorization code to complete the authorization login. In this way, even when the zero-trust client is in an offline state, login authorization can be performed, thereby realizing the access to business functions. Description of the Drawings
[0054] To more clearly illustrate the technical solutions in the embodiments of the present application or the related art, the following will briefly introduce the accompanying drawings required for the description of the embodiments of the present application or the related art. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0055] Figure 1 It is an application environment diagram of the authorization login method in an embodiment;
[0056] Figure 2 It is a schematic flowchart of the authorization login method in an embodiment;
[0057] Figure 3 It is a schematic flowchart of the authorization login method in another embodiment;
[0058] Figure 4 It is a schematic flowchart of the authorization login example in an embodiment;
[0059] Figure 5 It is a structural block diagram of the authorization login device in an embodiment;
[0060] Figure 6 It is a structural block diagram of the authorization login device in another embodiment;
[0061] Figure 7 It is an internal structure diagram of the terminal device in an embodiment;
[0062] Figure 8 It is an internal structure diagram of the server in an embodiment. Detailed implementation manners
[0063] In order to make the purpose, technical solutions and advantages of the present application clearer, the following further details the present application in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0064] The authorization login method provided by the embodiments of the present application can be applied to, for example Figure 1In the application environment shown. The application environment includes a zero-trust client 110, a management and control server 120, a mobile terminal 130, and a third-party platform 140. Among them, the zero-trust client can be installed on terminal devices such as personal computers and laptops. The mobile terminal can be a smart phone, a tablet computer, an Internet of Things device, a portable wearable device, etc. Third-party application programs such as Enterprise WeChat and DingTalk can be installed in the mobile terminal. The third-party platform is the service platform for the third-party application program. The zero-trust client can communicate with the management and control server; the mobile terminal can communicate with the management and control server and the third-party platform through the network. The management and control server and the third-party platform can be servers, which can be independent physical servers, or a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services. This embodiment does not make a limitation.
[0065] In an exemplary embodiment, as Figure 2 shown, a method for authorized login is provided. Taking the management and control server in Figure 1 as an example for illustration, the method includes the following steps:
[0066] Step 202, in response to an access request for an authorization page sent by the mobile terminal, feedback the authorization page to the mobile terminal.
[0067] Among them, the access request is sent by the mobile terminal in response to recognizing the graphic code displayed by the zero-trust client. The graphic code is generated based on the parameter information in the management and control server; the parameter information at least includes the access address of the authorization page and the user identifier, and the authorization page is used to trigger a login authorization request.
[0068] In the embodiment of the present application, when the zero-trust client is not connected to the network, it can request parameter information from the management and control server, and this parameter information is the parameter information for generating the graphic code. Among them, the image code can be a bar code, a two-dimensional code, etc. The parameter information at least includes the access address of the authorization page and the user identifier. The authorization page is the authorization page provided by the management and control server, and the access address of the authorization page can be the URL (Uniform Resource Locator) of the authorization page; the user identifier is a user code generated by the management and control server for uniquely identifying the user. The zero-trust client can generate a graphic code based on the obtained parameter information, and then display the graphic code. The user can scan the image code through the mobile terminal, and the mobile terminal can identify and parse the graphic code to obtain the access address of the authorization page and the user identifier. Then, the mobile terminal can send an access request for the authorization page to the management and control server based on the access address of the authorization page. After receiving the access request, the management and control server feeds back the page data of the authorization page to the mobile terminal. Among them, third-party application programs are installed in the mobile terminal.
[0069] Step 204: Receive the login authorization request sent by the mobile terminal. The login authorization request carries the authorization code and user identification provided by the third-party platform.
[0070] In the embodiment of the present application, after the mobile terminal receives the page data of the authorization page, it can display the authorization page based on the page data. The authorization page may include authorization options. After the user triggers the authorization option on the authorization page, the mobile device responds to the trigger operation and sends an authorization request to the third-party platform. The authorization request carries the user identification and verification information, and is used to access the non-login authorization URL. The non-login authorization URL is the URL of the non-authorization login function provided by the third-party platform. After the third-party IM platform verifies the IM application user according to the verification information, if the verification is successful, it sends a response message to the mobile terminal. The response message includes the authorization code and the redirect status code.
[0071] After the mobile terminal receives the response message, it parses the response message to obtain the authorization code and the redirect status code. The mobile terminal can send a login authorization request to the management server based on the redirect status code. The login authorization request carries the authorization code and the user identification. After the management server receives the login authorization request, it can parse the login authorization request to obtain the authorization code and the user identification.
[0072] Step 206: Obtain the identity information corresponding to the user identification from the third-party platform based on the authorization code, and complete the authorization login process.
[0073] In the embodiment of the present application, the management server can call the open interface of the third-party platform through the authorization code to obtain the user's identity information, and store the identity information corresponding to the user identification. The management server can complete the authorization login based on the identity information. For example, if the management server successfully obtains the identity information, it determines that the user's authorization is successful; otherwise, it determines that the user's authorization fails.
[0074] Through this solution, the zero-trust client can display the graphic code based on the parameters provided by the management server, without obtaining the image code from the third-party platform, realizing the offline display of the graphic code. Moreover, the management server can also provide an authorization page to the mobile terminal, so that the user can perform a login operation on the authorization page. Thus, through the interaction between the mobile terminal and the third platform, the authorization code of the third-party platform is obtained, and then the identity information of the user is obtained from the third-party platform through the authorization code to complete the authorization login. In this way, even when the zero-trust client is in an offline state, authorization login can be performed, thus realizing the access to the business function.
[0075] Optionally, the method further includes: generating a user identifier and a device identifier corresponding to the zero-trust client in response to a parameter acquisition request sent by the zero-trust client; sending parameter information to the zero-trust client, where the parameter includes the user identifier, the device identifier, and the access address of the pre-stored authorization page.
[0076] In the embodiments of the present application, when the network of the zero-trust client is not connected, the zero-trust client can send a parameter acquisition request to the management and control server. The parameter acquisition request can carry a client identifier, and the client identifier is a pre-configured identifier in the zero-trust client. After receiving the parameter acquisition request, the management and control server can generate a user identifier and a device identifier corresponding to the zero-trust client. Among them, the user identifier can be a user code, and the device identifier can be a device code; the user identifier and the device identifier are one-time temporary identifiers with a valid duration, and the valid duration is less than a preset duration threshold. For example, if the valid duration is 10 minutes, the user identifier and the device identifier are valid within 10 minutes. The user identifier and the device identifier are unique identifiers within the valid duration. The management and control server can also obtain the access address of the pre-configured authorization page, and use the user identifier, the device identifier, and the pre-stored access address of the authorization page as parameter information and send it to the zero-trust client. When the management and control server generates a user identifier and a device identifier corresponding to the zero-trust client, it can also store the corresponding relationship between the user identifier and the device identifier, and can delete the corresponding relationship when the valid duration is reached.
[0077] Based on the above solution, the management and control server can send parameter information to the zero-trust client, so that the zero-trust client can display an offline QR code based on the parameter information to achieve offline login to the zero-trust client; and, the user identifier and the device identifier in the parameter information are one-time temporary identifiers, which can improve the security of offline login.
[0078] Optionally, the method further includes: receiving an authorization query request sent by the zero-trust client, where the authorization query request carries a device identifier; determining the user identifier corresponding to the device identifier, and querying whether there is identity information corresponding to the user identifier; in the case where there is identity information, sending an authorization query result indicating successful authorization login to the zero-trust client; in the case where there is no identity information, sending an authorization query result indicating failed authorization login to the zero-trust client.
[0079] In the embodiments of the present application, after receiving the parameter information, the zero-trust client can poll the authorization result from the management server. Specifically, the zero-trust client can send an authorization query request to the management server according to a preset sending period, and the authorization query request carries a device identifier. This device identifier can uniquely identify the zero-trust client within the valid duration. The management server receives the authorization query request sent by the zero-trust client and parses the device identifier carried in the authorization query request. Then, the management server can query whether there is a user identifier corresponding to this device identifier in the correspondence between the user identifiers and device identifiers cached locally. In the case where there is such a user identifier, it further queries whether there is identity information corresponding to this user identifier stored. If it exists, it feeds back an authorization query result indicating successful authorized login and the access token of the user to the zero-trust client; if there is no identity information, or if the user identifier corresponding to this device identifier is not found, it feeds back an authorization query result indicating failed authorized login to the zero-trust client. After receiving the authorization query result indicating successful authorized login and the access token of the user, the zero-trust client can call the API (Application Programming Interface) of the relevant zero-trust system for the user to perform business access.
[0080] Based on the above solution, the zero-trust client can query the authorization query result from the management server and feedback to the user whether the login is successful based on the authorization query result, thereby realizing the offline login of the zero-trust client.
[0081] In an exemplary embodiment, as Figure 3 shown, a method for authorized login is provided. Taking the zero-trust client in Figure 1 as an example, the method includes the following steps:
[0082] Step 302, in response to a login instruction, send a parameter acquisition request to the management server.
[0083] Among them, the parameter acquisition request is used to instruct the management server to return the parameter information corresponding to the zero-trust client; among them, the parameter information at least includes the access address of the authorization page and the user identifier.
[0084] In an embodiment of the present application, when the zero-trust client is not connected to the network, it can send a parameter acquisition request to the management and control server. The parameter acquisition request can carry a client identifier, which is a pre-configured identifier in the zero-trust client. After receiving the parameter acquisition request, the management and control server can generate a user identifier and a device identifier corresponding to the zero-trust client. Among them, the user identifier can be a user code, and the device identifier can be a device code; the user identifier and the device identifier are one-time temporary identifiers with a valid duration, and the valid duration is less than a preset duration threshold. For example, if the valid duration is 10 minutes, the user identifier and the device identifier are valid within 10 minutes. The user identifier and the device identifier are unique identifiers within the valid duration. The management and control server can also obtain the access address of the pre-configured authorization page, and send the user identifier, the device identifier, and the access address of the pre-stored authorization page as parameter information to the zero-trust client.
[0085] Step 304: Receive the parameter information sent by the management and control server, and generate and display a graphic code based on the parameter information.
[0086] Among them, the graphic code is used to enable the mobile terminal to obtain the access address of the authorization page and the user identifier, and perform authorization login processing based on the access address of the authorization page and the user identifier.
[0087] In an embodiment of the present application, the zero-trust client can generate a graphic code based on the obtained parameter information, and then display the graphic code. The user can scan the image code through the mobile terminal, and the mobile terminal can identify and parse the graphic code to obtain the access address of the authorization page and the user identifier. Then, the mobile terminal can send an access request for the authorization page to the management and control server based on the access address of the authorization page. After receiving the access request, the management and control server feeds back the page data of the authorization page to the mobile terminal. Among them, a third-party application is installed in the mobile terminal.
[0088] After receiving the page data of the authorization page, the mobile terminal can display the authorization page based on the page data. The authorization page can include authorization options. After the user triggers the authorization option on the authorization page, the mobile device responds to the trigger operation and sends an authorization request to the third-party platform. The authorization request carries the user identifier and verification information, and the authorization request is used to access the login-free authorization URL. The login-free authorization URL is the URL of the login-free authorization function provided by the third-party platform. After the third-party IM platform verifies the IM application user according to the verification information, if the verification is successful, it sends a response message to the mobile terminal, and the response message includes the authorization code and the redirect status code.
[0089] After the mobile terminal receives the response message, it parses the response message to obtain the authorization code redirection status code. The mobile terminal can send a login authorization request to the management server based on the redirection status code. The login authorization request carries the authorization code and the user identification. After receiving the login authorization request, the management server can parse the login authorization request to obtain the authorization code and the user identification. The management server can call the open interface of the third-party platform through the authorization code to obtain the user's identity information and store the identity information corresponding to the user identification. The management server can complete the authorized login based on the identity information. For example, if the management server successfully obtains the identity information, it determines that the user authorization is successful; otherwise, it determines that the user authorization fails.
[0090] Through this solution, the zero-trust client can display the graphic code based on the parameters provided by the management server without obtaining the image code from the third-party platform, realizing the offline display of the graphic code. Moreover, the management server can also provide an authorization page to the mobile terminal so that the user can perform a login operation on the authorization page. Thus, through the interaction between the mobile terminal and the third platform, the authorization code of the third-party platform can be obtained, and then the user's identity information can be obtained from the third-party platform through the authorization code to complete the authorized login. In this way, even when the zero-trust client is in an offline state, the authorized login can be performed, thereby realizing the access to the service function.
[0091] Optionally, in response to the login instruction, sending a parameter acquisition request to the management server includes: in response to the login instruction, detecting the current network connectivity status; and in the case that the network connectivity status is not connected, sending a parameter acquisition request to the management server.
[0092] In the embodiment of the present application, the user can start the zero-trust client on the terminal. After the zero-trust client is started, it can detect the network connectivity status in response to the login instruction to obtain the current network connectivity status. If the current network connectivity status is not connected, it sends a parameter acquisition request to the management server. If the current network connectivity status is connected, it obtains the graphic code from the third-party platform for display. Among them, the login instruction can be an instruction triggered by the user after the zero-trust client is started, or an instruction automatically triggered after the zero-trust client is started.
[0093] Through this solution, the zero-trust client can detect the network connectivity status and, in the case of network disconnection, implement offline login using this solution, and in the case of network connection, perform login using the traditional login process. In this way, it can not only be compatible with the traditional login process but also realize the offline login of the zero-trust client, ensuring the normal use of the service function.
[0094] Optionally, the parameter information further includes a device identifier, and the method further includes: sending an authorization query request to the management control server, where the query request carries the device identifier; receiving an authorization query result sent by the management control server, and the authorization query result is used to indicate whether the authorized login is successful.
[0095] In an embodiment of the present application, after receiving the parameter information, the zero-trust client can poll the authorization result from the management control server. Specifically, the zero-trust client can send an authorization query request to the management control server according to a preset sending period, and the authorization query request carries the device identifier. This device identifier can uniquely identify the zero-trust client within the valid duration. The management control server receives the authorization query request sent by the zero-trust client and parses the device identifier carried in the authorization query request. Then, the management control server can query whether there is a user identifier corresponding to this device identifier in the corresponding relationship between the user identifier and the device identifier cached locally. If there is such a user identifier, it further queries whether there is identity information corresponding to this user identifier stored. If there is, it feeds back an authorization query result indicating successful authorized login and the access token of the user to the zero-trust client; if there is no identity information, or if the user identifier corresponding to this device identifier is not queried, it feeds back an authorization query result indicating failed authorized login to the zero-trust client. Optionally, the identity information of the user can also be sent to the zero-trust client. In this way, after receiving the authorization query result indicating successful authorized login and the access token of the user, the zero-trust client can call the API of the zero-trust system related to the identity information of the user for the user to perform business access.
[0096] Based on the above solution, the zero-trust client can query the authorization query result from the management control server and feedback to the user whether the login is successful based on the authorization query result, thereby realizing the offline login of the zero-trust client.
[0097] As Figure 4 shown, an embodiment of the present application provides an example of an authorization login method, including the following steps:
[0098] Step 401, the zero-trust client detects the current network connectivity status in response to a startup instruction.
[0099] If the network connectivity status is unconnected, step 403 is executed; if the network connectivity status is connected, the traditional login process is executed.
[0100] Step 402, the zero-trust client sends a parameter acquisition request to the zero-trust management control service.
[0101] Among them, the parameter acquisition request includes the client identifier of the zero-trust client.
[0102] Step 403, the zero-trust control server sends parameter information to the zero-trust client.
[0103] Among them, the parameter information includes the URL of the authorization page, as well as the user code and device code corresponding to the zero-trust client.
[0104] Step 404, the zero-trust client generates and displays a QR code based on the URL of the authorization page and the user code.
[0105] Step 405, the IM application on the mobile device scans the QR code displayed by the zero-trust client to obtain the URL of the authorization page and the user code.
[0106] Step 406, the IM application sends an access request for the authorization page to the zero-trust control server based on the URL of the authorization page.
[0107] Step 407, the zero-trust control server sends the page data of the authorization page to the IM application.
[0108] Step 408, the IM application displays the authorization page.
[0109] Step 409, the IM application sends an authorization request to the third-party IM platform in response to the trigger operation of the authorization option.
[0110] Among them, the authorization request carries the user code and verification information.
[0111] Step 410, after verifying the IM application user according to the verification information, the third-party IM platform returns the user authorization code.
[0112] Step 411, the IM application sends a login authorization request to the zero-trust control server.
[0113] Among them, the login authorization request carries the authorization code and the user code.
[0114] Step 412, the zero-trust control server uses the user authorization code to call the interface of the third-party IM platform to obtain the user identity information and confirm that the user authorization is successful.
[0115] Step 413, the zero-trust client sends an authorization query request to the control server.
[0116] Among them, the query request carries the device code.
[0117] Step 414, the control server feeds back the authorization query result of successful authorization and the access token.
[0118] Step 415, the zero-trust client calls the API of the relevant zero-trust system for the user to conduct business access.
[0119] It should be understood that although the steps in the flowcharts involved in the above embodiments are sequentially shown according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0120] Based on the same inventive concept, an embodiment of the present application further provides an authorization login device for implementing the above-mentioned authorization login method. The solution provided by this device to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more embodiments of the authorization login device provided below can refer to the limitations on the authorization login method in the above text, and will not be repeated here.
[0121] In an exemplary embodiment, as Figure 5 shown, an authorization login device is provided, which is applied to a management and control server and includes:
[0122] A feedback module 510, configured to, in response to an access request for an authorization page sent by a mobile terminal, feedback the authorization page to the mobile terminal; the access request is sent by the mobile terminal in response to a graphic code displayed by an identified zero-trust client, and the graphic code is generated based on parameter information in the management and control server; the parameter information at least includes the access address of the authorization page and a user identifier, and the authorization page is used to trigger a login authorization request;
[0123] A first receiving module 520, configured to receive a login authorization request sent by a mobile terminal, where the login authorization request carries an authorization code provided by a third-party platform and the user identifier;
[0124] An authorization login module 530, configured to obtain identity information corresponding to the user identifier from the third-party platform based on the authorization code, and complete the authorization login process.
[0125] In one of the embodiments, the device further includes:
[0126] A generation module, configured to, in response to a parameter acquisition request sent by the zero-trust client, generate a user identifier and a device identifier corresponding to the zero-trust client;
[0127] A first sending module, configured to send parameter information to the zero-trust client, where the parameters include the user identifier, the device identifier, and the access address of the pre-stored authorization page.
[0128] In one embodiment, the device further includes:
[0129] A second receiving module, configured to receive an authorization query request sent by the zero-trust client, where the authorization query request carries the device identifier;
[0130] A query module, configured to determine the user identifier corresponding to the device identifier, and query whether there is identity information corresponding to the user identifier;
[0131] A second sending module, configured to, when there is the identity information, feedback an authorization query result indicating successful authorization login to the zero-trust client;
[0132] The second sending module is further configured to, when there is no such identity information, feedback an authorization query result indicating failed authorization login to the zero-trust client.
[0133] In an exemplary embodiment, as Figure 6 shown, there is provided an authorization login device applied to a zero-trust client, including:
[0134] A first sending module 610, configured to, in response to a login instruction, send a parameter acquisition request to a management and control server; the parameter acquisition request is used to instruct the management and control server to return parameter information corresponding to the zero-trust client; wherein, the parameter information at least includes the access address of the authorization page and the user identifier;
[0135] A first receiving module 620, configured to receive the parameter information sent by the management and control server, generate and display a graphic code based on the parameter information; the graphic code is used to enable a mobile terminal to obtain the access address of the authorization page and the user identifier, and perform authorization login processing based on the access address of the authorization page and the user identifier.
[0136] In one embodiment, the first sending module is specifically configured to:
[0137] In response to a login instruction, detect the current network connection status;
[0138] When the network connection status is not connected, send a parameter acquisition request to the management and control server.
[0139] In one embodiment, the parameter information further includes a device identifier, and the device further includes:
[0140] A second sending module, configured to send an authorization query request to the management and control server, where the query request carries the device identifier.
[0141] A second receiving module, configured to receive the authorization query result sent by the management and control server, where the authorization query result is used to indicate whether the authorized login is successful.
[0142] Each module in the above-mentioned authorized login device can be implemented in whole or in part by software, hardware, and their combination. Each of the above modules can be embedded in the processor in the computer device in hardware form or be independent of it, or can be stored in the memory in the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.
[0143] In an exemplary embodiment, a computer device is provided. The computer device can be a terminal, and its internal structure diagram can be as Figure 7 shown. The computer device includes a processor, a memory, an input / output interface, a communication interface, a display unit, and an input device. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface, the display unit, and the input device are connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The input / output interface of the computer device is used for the processor to exchange information with external devices. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner, and the wireless manner can be implemented through WIFI, a mobile cellular network, near field communication (NFC), or other technologies. When the computer program is executed by the processor, it implements an authorized login method. The display unit of the computer device is used to form a visually visible picture, which can be a display screen, a projection device, or a virtual reality imaging device. The display screen can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the computer device, or an external keyboard, touchpad, or mouse, etc.
[0144] In an exemplary embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 8As shown in the figure. The computer device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O), and a communication interface. Among them, the processor, the memory, and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data. The input / output interface of the computer device is used to exchange information between the processor and external devices. The communication interface of the computer device is used to communicate with external terminals through a network connection. The computer program, when executed by the processor, implements an authorized login method.
[0145] Those skilled in the art can understand that Figure 7 and Figure 8 the structure shown in the figure is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0146] In an exemplary embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the above method steps are implemented.
[0147] In an embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the above method steps are implemented.
[0148] In an embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the above method steps are implemented.
[0149] It should be noted that the user information (including but not limited to user device identifiers, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use, and processing of relevant data need to comply with relevant regulations.
[0150] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, data processing logics based on quantum computing, artificial intelligence (AI) processors, etc., without limitation.
[0151] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered to be within the scope recorded in the present application.
[0152] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all fall within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the appended claims.
Claims
1. An authorized login method, characterized in that: The method is applied to a management and control server, and the method includes: In response to an access request for an authorization page sent by a mobile terminal, feeding back the authorization page to the mobile terminal; the access request is sent by the mobile terminal in response to identifying a graphic code displayed by a zero-trust client, the graphic code is generated based on parameter information in the management and control server; the parameter information at least includes an access address and a user identifier of the authorization page, and the authorization page is used to trigger a login authorization request; Receiving a login authorization request sent by a mobile terminal, wherein the login authorization request carries an authorization code provided by a third-party platform and the user identifier; Based on the authorization code, identity information corresponding to the user identifier is obtained from the third-party platform to complete the authorized login process.
2. The method according to claim 1, characterized in that The method further comprises: In response to the parameter acquisition request sent by the zero-trust client, generate a user identifier and a device identifier corresponding to the zero-trust client; Parameter information is sent to the zero-trust client, where the parameters include the user identifier, the device identifier, and an access address of a pre-stored authorization page.
3. The method according to claim 2, characterized in that The method further comprises: Receive an authorization query request sent by the zero-trust client, where the authorization query request carries the device identifier; Determine the user identifier corresponding to the device identifier, and query whether there is identity information corresponding to the user identifier; In the case where the identity information exists, feeding back to the zero-trust client an authorization query result indicating successful authorized login; In the absence of the identity information, an authorization query result indicating a failed authorized login is fed back to the zero trust client.
4. An authorized login method, characterized in that: The method is applied to a zero-trust client, and the method includes: In response to the login instruction, a parameter acquisition request is sent to the management and control server; the parameter acquisition request is used to instruct the management and control server to return parameter information corresponding to the zero-trust client; wherein the parameter information at least includes an access address of the authorization page and a user identifier; Receive parameter information sent by the management and control server, and generate and display a graphic code based on the parameter information; the graphic code is used to enable the mobile terminal to obtain the access address and user identification of the authorization page, and perform authorized login processing based on the access address of the authorization page and the user identification.
5. The method according to claim 4, characterized in that The step of sending a parameter acquisition request to the management and control server in response to the login instruction includes: In response to the login instruction, detecting the current network connectivity status; When the network connectivity status is disconnected, a parameter acquisition request is sent to the management and control server.
6. The method according to claim 4, characterized in that The parameter information further includes a device identifier, and the method further includes: Sending an authorization query request to the management and control server, wherein the query request carries the device identifier; Receive the authorization query result sent by the management and control server, and the authorization query result is used to indicate whether the authorized login is successful.
7. An authorized login device, characterized in that: The device is applied to a management and control server, and the device includes: A feedback module, configured to respond to an access request for an authorization page sent by a mobile terminal and to feed back the authorization page to the mobile terminal; the access request is sent by the mobile terminal in response to identifying a graphic code displayed by a zero-trust client, the graphic code being generated based on parameter information in the management and control server; the parameter information at least includes an access address and a user identifier of the authorization page, and the authorization page is used to trigger a login authorization request; A first receiving module, configured to receive a login authorization request sent by a mobile terminal, wherein the login authorization request carries an authorization code provided by a third-party platform and the user identifier; The authorization login module is used to obtain the identity information corresponding to the user identifier from the third-party platform based on the authorization code to complete the authorization login process.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 3 or claims 4 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method of any one of claims 1 to 3 or claims 4 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method of any one of claims 1 to 3 or claims 4 to 6 are implemented.
Citation Information
Patent Citations
Third party authorized login method and system
CN108632291A
Login request processing method and device, electronic equipment and storage medium
CN115695012A
Scanning login method, device and equipment based on two-dimensional code and readable storage medium
CN117520012A
Access processing method and device based on zero-trust network, electronic equipment and medium
CN118802149A
Techniques for onboarding web applications in a zero trust environment
US20230388271A1
Cited By
Application offline access method and device of zero-trust server
CN121441580A