Unified identity authentication system for bid invitation agency

Through the unified identity authentication system, the security risks and management inconvenience caused by the dispersion of user information are solved, high security and efficient user experience are achieved, and development and maintenance costs are reduced.

CN120512263APending Publication Date: 2025-08-19SHANGHAI MECHANICAL & ELECTRICAL EQUIP TENDERING CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510311976.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2025-08-19

AI Technical Summary

Technical Problem

In the prior art, the dispersed management of user identity information leads to security risks, high development and maintenance costs, inconsistent data, and cumbersome cross-system login, which affects work efficiency and security.

Method used

Design a unified identity authentication system, including account management, application management, audit management, permission management and interface management modules, realize centralized management of user identity and permissions, adopt encrypted transmission and secure audit, and support single sign-on and role permission control.

Benefits of technology

It improves the security and user experience of enterprise information systems, simplifies the login process, reduces development and maintenance costs, ensures data consistency and security, and improves work efficiency.

✦ Generated by Eureka AI based on patent content.
Patent Text Reader

Abstract

The invention discloses a unified identity authentication system for a bid invitation agency, and the system is characterized in that the system comprises an account management module; an application management module; an audit management module; an authority management module; and an interface management module. According to the technical scheme disclosed by the invention, the problems of potential safety hazards and inconvenience in use in the existing identity authentication system are solved, the unified identity authentication system based on multiple systems is provided, high safety and good user experience are realized, and the identity authentication system is suitable for various application scenes. The safety of the enterprise information system can be improved, the user management efficiency is enhanced, and the user experience is optimized. Unified identity authentication realizes centralized management of user identities and permissions by integrating identity authentication processes of a plurality of systems, thereby solving security risks and inconvenient management caused by dispersed identity authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a unified identity authentication system, and involves multiple aspects such as computer science, network security and information technology. Background Art

[0002] Currently, users must log in separately across multiple application systems, entering their username and password each time. Each application system independently manages user identity information. Each system requires its own independent user authentication module to be developed and maintained. User information is scattered across these different systems, and each system has its own independent authentication mechanism.

[0003] The process for users to log into the system is usually as follows:

[0004] 1) Access the login address required to log in to the system;

[0005] 2) Enter the system account and password for logging into the system;

[0006] 3) Access the data and resources of the login system.

[0007] The process of user switching across systems is usually as follows:

[0008] 1) Click the address you want to jump to across systems in the currently logged-in system;

[0009] 2) Enter the login page of the jump system;

[0010] 3) Enter the system account and password of the jump system;

[0011] 4) Login successful, jump to the access link.

[0012] For the purpose of business management and administrative management, the company has gradually introduced multiple systems such as tender management system, tender purchase system, OA system and CRM system during its development. The purpose is to standardize the management and information management of business data through various management systems. However, after the company's development scale expanded, it was found that multiple systems could not be uniformly authenticated and logged in, resulting in users needing to record multiple accounts and passwords. During use, there are problems such as cross-system jumps and inability to directly access business data, which increases the time cost in the business processing process, affects the overall work efficiency and the smoothness of business data processing, and limits the optimal use of company resources. It is also contrary to the company's pursuit of efficiency and automation goals. Especially in the current highly competitive market environment, companies have increasingly stringent requirements for operational efficiency and cost control. The traditional manual operation of cross-system login to access business data has become one of the bottlenecks restricting the company's development. Summary of the Invention

[0013] The technical problems to be solved by the present invention are: independent management of user identity information can easily lead to security vulnerabilities; each system needs to develop and maintain a user authentication module separately, which increases the cost of development and maintenance; user data in different systems may be out of sync, resulting in data inconsistency and affecting business processing; user information is scattered in different systems, making privacy protection difficult; the authentication mechanism of each system is independent, making it difficult to achieve single sign-on and permission management across systems; the authentication module of each system needs to be maintained independently, which increases maintenance costs.

[0014] In order to solve the above technical problems, the technical solution of the present invention is to disclose a unified identity authentication system for bidding agencies, which is characterized by including:

[0015] Account management module: responsible for the authorization configuration of the relationship between the main account and the subsystem account, as well as controlling the user's access rights to each system;

[0016] Application management module: responsible for the addition and maintenance of subsystem applications, providing APPID and key information for each system access interface, and unified control of application usage status;

[0017] Audit Management Module: This module is responsible for recording and monitoring system access and operations, providing detailed log query capabilities to promptly identify and resolve system anomalies. The audit management module records every user operation in detail, allowing administrators to query and export logs through the management interface for security audits and compliance checks.

[0018] Permission management module: This module is responsible for controlling the functional and data permissions of system users. It adopts a role-based access control model and assigns corresponding permissions according to the user's role. Each time a user successfully logs in and passes authentication, the system dynamically assigns permissions based on the user's role and current context. The permission assignment results are cached to improve system response speed.

[0019] Interface management module: responsible for providing integration interfaces with third-party systems. Third-party systems can communicate with the unified identity authentication system through these interfaces to achieve unified identity authentication and authorization functions.

[0020] Preferably, in the account management module, a registered user can log in by entering a user name and password through a login interface, and the system will perform a preliminary verification of the input information and the associated account and authority verification of the login system.

[0021] Preferably, in the application management module, for an existing application system, its internal account is converted into an account identifiable by the unified identity authentication platform through account mapping capability, thereby realizing single sign-on.

[0022] Preferably, in the application management module, for a newly developed application system, the interface specification of the unified identity authentication platform should be followed at the beginning of the design to ensure that it can be seamlessly integrated into the unified identity authentication system.

[0023] Preferably, each record generated by the audit management module contains a timestamp, user ID, operation type and operation result, and these logs are stored in a secure storage medium for subsequent review and analysis.

[0024] Preferably, the audit management module supports real-time monitoring and alarm functions to detect abnormal behaviors in a timely manner and take corresponding measures.

[0025] Preferably, in the authority management module, roles can be predefined or customized according to actual needs.

[0026] Preferably, the interface management module provides a set of standard interface specifications.

[0027] Preferably, the interface of the interface management module adopts RESTful API design, supports common HTTP methods, and each interface has detailed documentation, including request parameters, response format and error codes.

[0028] Preferably, the interface management module also provides SDK and sample codes to help developers quickly integrate and use.

[0029] The technical solution disclosed in the present invention solves the security risks and inconveniences in existing identity authentication systems, and provides a unified identity authentication system based on multiple systems, which achieves high security and good user experience and is suitable for various application scenarios.

[0030] This invention can improve the security of enterprise information systems, enhance user management efficiency, and optimize user experience. Unified identity authentication integrates the authentication processes of multiple systems to achieve centralized management of user identities and permissions, thereby resolving the security risks and management inconveniences associated with decentralized authentication. Compared with existing technical solutions, this invention has the following specific benefits:

[0031] 1) Security improvement: The system security is ensured by adopting security measures such as encrypted transmission and cross-site request forgery; security audits are carried out through system logs to timely identify risk items.

[0032] 2) User experience optimization: A unified account login is implemented, and users only need to log in once in multiple application systems to switch seamlessly, greatly simplifying the login process.

[0033] 3) Strengthening management capabilities: Establish a unified user resource library to rationally categorize enterprise information system users and achieve unified management of user identities and permissions. Support a unified user management and authentication system, including user information management, role management, and organizational structure management, to achieve centralized control of various decentralized systems and improve bidding efficiency.

[0034] Through the comprehensive application of the above technical features, the present invention can significantly simplify the operation steps of business personnel, reduce the time cost of business processing, improve work efficiency and the smoothness of business data processing, and optimize the utilization of company resources, which is specifically reflected in the following aspects:

[0035] 1) Users only need to log in once to access all authorized application systems. This approach significantly improves work efficiency, simplifies user password management, and avoids the trouble of frequent system switching.

[0036] 2) Centralized management of user identity information reduces network attack surface and improves overall security.

[0037] 3) Authentication and authorization are performed through a unified authentication center, and multiple systems share a set of authentication mechanisms, saving development time and costs.

[0038] 4) All systems share data from the same identity authentication center to ensure the consistency and accuracy of user data.

[0039] 5) Maintenance is performed through a unified certification center, reducing overall maintenance costs.

[0040] To sum up, unified authentication login has obvious advantages in improving user experience, enhancing security and reducing development and maintenance costs. DETAILED DESCRIPTION

[0041] Below in conjunction with specific embodiment, further set forth the present invention.Should be understood that these embodiments are only used to illustrate the present invention and are not used in limiting the scope of the present invention.In addition, should be understood that after reading the content taught by the present invention, those skilled in the art can make various changes or modifications to the present invention, and these equivalent forms fall equally within the scope limited by the appended claims of the application.

[0042] The embodiment of the present invention discloses a unified identity authentication system for a bidding agency, comprising:

[0043] Account Management: This module is responsible for configuring the authorization relationship between the main account and subsystem accounts, as well as controlling the user's access rights to various systems. Registered users can log in by entering their username and password on the login screen. The system will perform a preliminary verification of the input information and verify the associated account and permissions of the login system.

[0044] Application Management Module: Responsible for the addition and maintenance of subsystem applications, providing APPID and key information for each system access interface, and unified control of the application usage status. For existing application systems, through account mapping capabilities, its internal accounts are converted into accounts that can be recognized by the unified identity authentication platform to achieve single sign-on. For newly developed application systems, the interface specifications of the unified identity authentication platform should be followed at the beginning of the design to ensure that it can be seamlessly integrated into the unified identity authentication system.

[0045] Audit management module: responsible for recording and monitoring system access and operation, providing detailed log query function, and timely discovering and resolving system anomalies. The system will record every step of the user's operation in detail, including login, authentication and other key operations. Each record contains information such as timestamp, user ID, operation type and operation result. These logs will be saved in a secure storage medium for subsequent review and analysis. Administrators can query and export logs through the management interface for security audits and compliance checks. The system also supports real-time monitoring and alarm functions to detect abnormal behavior in a timely manner and take corresponding measures.

[0046] Permission Management Module: Responsible for controlling the functional and data permissions of system users. The system utilizes a role-based access control (RBAC) model, assigning permissions based on user roles. Roles can be predefined or customized based on actual needs. Each time a user successfully logs in and passes authentication, the system dynamically assigns permissions based on the user's role and the current context. For example, administrators can access all functions, while standard users can only access specific resources. Permission assignments are cached to improve system responsiveness.

[0047] Interface management module: responsible for providing an integrated interface with a third-party system to achieve unified identity authentication. In order to achieve unified identity authentication with other systems, the present invention provides a set of standard interface specifications. Third-party systems can communicate with the unified identity authentication system through these interfaces to achieve identity authentication and authorization functions. The interface adopts RESTful API design and supports common HTTP methods (such as GET, POST, PUT, DELETE). Each interface has detailed documentation, including request parameters, response format, error codes, etc. In addition, the system also provides SDK and sample code to help developers quickly integrate and use.

[0048] The method for applying the above unified identity authentication system includes the following steps:

[0049] Application configuration: The system administrator logs in to the unified identity authentication platform, adds the unified authentication application system, and distributes the application ID and application key generated by the system.

[0050] User information import: Engineers of each system import user information through the interface.

[0051] User association: The system administrator logs in to the unified authentication platform and associates the user's information in each system with the main account information. The administrator also activates user account permissions and application permissions.

[0052] Login authentication: The user selects the application system to be logged in, enters the primary account and password information through the unified authentication login page, authenticates the account and password information through the unified identity authentication interface and matches the cross-system token to log in to the corresponding system.

[0053] Operation statistics: Record every step of management system operation and interface call, including login, authentication, interface request and other key operations for subsequent security review.

[0054] System integration: Integrate the unified identity authentication system into third-party applications through standard interfaces to ensure consistency of identity authentication across systems.

[0055] The above technical solution adopts the following technologies:

[0056] Vue.js front-end framework: Developed using the front-end framework commonly used in government and state-owned enterprise management systems to implement application management, user management and other functions.

[0057] Spring Boot application framework: The Spring Boot framework has many advantages, such as independent operation, embedded Servlet container, automatic configuration, startup dependencies, no code generation and XML configuration.

[0058] Strengthen authentication mechanism: Use high-strength passwords to increase cracking difficulty, prevent data leakage, and mitigate database collision attacks.

[0059] Sound system auditing and monitoring mechanism: facilitates timely detection and response to system security incidents and threats.

[0060] Data encryption transmission mechanism: Integrates the national commercial SM4 encryption algorithm to perform high-intensity data encryption and signature verification.

[0061] Identity token calling interface mechanism: authorizes users to access the interface and improves interface security.

Claims

1. A unified identity authentication system for a bidding agency, characterized in that: include: Account management module: responsible for the authorization configuration of the relationship between the main account and the subsystem account, as well as controlling the user's access rights to each system; Application management module: responsible for the addition and maintenance of subsystem applications, providing APPID and key information for each system access interface, and unified control of application usage status; Audit Management Module: This module is responsible for recording and monitoring system access and operations, providing detailed log query capabilities to promptly identify and resolve system anomalies. The audit management module records every user operation in detail, allowing administrators to query and export logs through the management interface for security audits and compliance checks. Permission management module: This module is responsible for controlling the functional and data permissions of system users. It adopts a role-based access control model and assigns corresponding permissions according to the user's role. Each time a user successfully logs in and passes authentication, the system dynamically assigns permissions based on the user's role and current context. The permission assignment results are cached to improve system response speed. Interface management module: responsible for providing integration interfaces with third-party systems. Third-party systems can communicate with the unified identity authentication system through these interfaces to achieve unified identity authentication and authorization functions.

2. A unified identity authentication system for a bidding agency according to claim 1, characterized in that: In the account management module, registered users can log in by entering their username and password through the login interface. The system will perform a preliminary verification of the input information and the associated account and permissions of the login system.

3. A unified identity authentication system for a bidding agency according to claim 1, characterized in that: In the application management module, for existing application systems, the internal accounts are converted into accounts that can be identified by the unified identity authentication platform through account mapping capabilities, thereby achieving single sign-on.

4. A unified identity authentication system for a bidding agency according to claim 1, characterized in that: In the application management module, for newly developed application systems, the interface specifications of the unified identity authentication platform should be followed at the beginning of the design to ensure that they can be seamlessly integrated into the unified identity authentication system.

5. A unified identity authentication system for a bidding agency according to claim 1, characterized in that: Each record generated by the audit management module contains a timestamp, user ID, operation type, and operation result. These logs are stored in a secure storage medium for subsequent review and analysis.

6. A unified identity authentication system for a bidding agency according to claim 1, characterized in that: The audit management module supports real-time monitoring and alarm functions, timely detecting abnormal behaviors and taking corresponding measures.

7. A unified identity authentication system for a bidding agency according to claim 1, characterized in that: In the rights management module, roles can be predefined or customized according to actual needs.

8. A unified identity authentication system for a bidding agency as claimed in claim 1, characterized in that: The interface management module provides a set of standard interface specifications.

9. A unified identity authentication system for a bidding agency according to claim 1, characterized in that: The interface of the interface management module adopts RESTful API design and supports common HTTP methods. Each interface has detailed documentation, including request parameters, response format and error codes.

10. A unified identity authentication system for a bidding agency according to claim 1, characterized in that: The interface management module also provides SDK and sample codes to help developers quickly integrate and use.

Citation Information

Patent Citations

  • Unified identity authentication system and method

    CN110334489A

  • Unified identity authentication system and method, electronic equipment and storage medium

    CN113360862A