Single sign-on control method and device, electronic equipment and storage medium

Through the single sign-on control method, the authentication server is used to generate access tokens and verify their validity, which solves the problem of users frequently logging in between multiple systems, realizes cross-system password-free login and session synchronous logout, improves user experience and reduces system integration costs and security.

CN120658460APending Publication Date: 2025-09-16北京领雁科技股份有限公司

Patent Information

Application Number
CN202510809824.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-17
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

In the existing technology, users need to frequently enter their account passwords between multiple systems, and there is a lack of a unified identity management mechanism, which leads to inconsistent permissions, inconsistent security policies, and high development and maintenance costs.

Method used

It adopts a single sign-on control method, responds to user login requests through the authentication server, obtains user information, generates access tokens and verifies their validity, supports unified authentication and session control of multiple data sources and multiple clients, and realizes cross-system password-free login and synchronous session logout.

Benefits of technology

It improves user experience, reduces system integration costs, and enhances overall security, achieving unified authentication and session control for multiple data sources and multiple clients.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658460A_ABST
    Figure CN120658460A_ABST
Patent Text Reader

Abstract

The invention provides a single sign-on control method and device, electronic equipment and a storage medium, and is applied to an authentication server, and the method comprises the steps: obtaining and verifying user login information through responding to a login request of a user for a main client, generating an access token, and returning the access token to the main client; when the user uses the access token to access the service system, verifying the validity and granting authority; after the user successfully logs in, if a request for accessing the sub-client is detected, a temporary authorization code is generated, and the main client jumps to the sub-client; and after the authorization code is verified, the corresponding user identity information is analyzed and returned to the sub-client. According to the method, unified authentication and session control of multiple data sources and multiple clients can be supported, and cross-system password-free login and session synchronous logout can be realized on the premise of ensuring security, so that the user experience is improved, the system integration cost is reduced, and the overall security is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of computer network security, and in particular to a single sign-on control method, device, electronic device, and storage medium. Background Art

[0002] As enterprises continue to advance in information technology, the need for collaborative work across diverse business systems is growing. Traditional authentication models typically rely on each business system maintaining its own login logic and user information. This approach not only requires users to frequently enter their account passwords, impacting the user experience, but also, due to the lack of a unified identity management mechanism, can easily lead to inconsistent permissions and security policies.

[0003] To address the issue of users repeatedly logging in across multiple systems, existing technologies have proposed a single sign-on (SSO) mechanism based on the OAuth2 protocol, incorporating LDAP directory services as a user information source to achieve unified authentication. However, each business system must implement its own OAuth2 client logic, resulting in inconsistent authentication processes and high development and maintenance costs. Summary of the Invention

[0004] The embodiments of the present disclosure provide at least one single sign-on control method, device, electronic device, and storage medium, which can support unified authentication and session control of multiple data sources and multiple clients, and can achieve cross-system password-free login and synchronous session logout under the premise of ensuring security, thereby improving user experience, reducing system integration costs, and enhancing overall security.

[0005] The present disclosure provides a single sign-on control method, which is applied to an authentication server in a login authentication system. The method includes:

[0006] In response to a user login request to the primary client, obtain user login information, access a preset user information database with the user login information, and receive a verification result of identity verification performed by the preset user information database based on the user login information;

[0007] After the verification is passed, an access token containing user authority information is generated and returned to the master client. When the user uses the access token to access the business system, the validity of the access token is verified and the corresponding access rights are granted according to the user authority information.

[0008] Maintaining the user's login status, if monitoring the user's login request to the sub-client in the successful login state, generating a temporary authorization code and triggering the main client to jump to the sub-client with the temporary authorization code;

[0009] Receive and verify the temporary authorization code sent by the sub-client, and after verification, parse the user identity information corresponding to the temporary authorization code and return it to the sub-client.

[0010] In an optional implementation, the method further includes:

[0011] In response to a logout request triggered by the user through the main client or the sub-client, revoking the corresponding access token according to the user identity information and logging out of the main client;

[0012] Invalidate the login status corresponding to the sub-client, and synchronously log out of the sub-client that the user has logged in.

[0013] In an optional implementation, the authentication server includes an SDK module that generates the temporary authorization code based on the following steps:

[0014] In response to the main client's call operation on the authorization code generation interface in the SDK module, the temporary authorization code with a corresponding validity period is generated according to the pre-stored user identity information through the pre-packaged password-free login function method;

[0015] The temporary authorization code is returned to the primary client through the authorization code generation interface.

[0016] In an optional embodiment, receiving and verifying the temporary authorization code sent by the sub-client, and parsing the user identity information corresponding to the temporary authorization code and returning it to the sub-client after the verification is passed, specifically includes:

[0017] In response to the sub-client's calling operation on the authorization code verification interface in the SDK module, parsing the user identity information to which the temporary authorization code belongs through a pre-packaged authorization code verification function method;

[0018] The user identity information is returned to the sub-client through the authorization code verification interface.

[0019] In an optional implementation, accessing a preset user information database with the user login information and receiving a verification result of identity verification performed by the preset user information database based on the user login information specifically includes:

[0020] Sending the user login information to the preset user information database via a pre-configured database connection;

[0021] The preset user information database matches the user account and login password included in the user login information with the pre-stored user identity information to verify the legitimacy of the login request;

[0022] If the preset user information database verifies that the user account, the login password and the user identity information match, receiving a verification success message returned by the preset user information database;

[0023] If the preset user information database verifies that the user account, the login password and the user identity information do not match, then a verification failure message returned by the preset user information database is received.

[0024] In an optional implementation, the method further includes:

[0025] In response to a user information synchronization request triggered by the master client, triggering a preset resource center to update the user identity information through the preset user information database according to a preset update frequency;

[0026] The preset resource center returns the updated user identity information to the master client.

[0027] The present disclosure also provides a single sign-on control device, which is applied to an authentication server in a login authentication system. The device includes:

[0028] A master client login verification module is configured to, in response to a user login request to the master client, obtain user login information, access a preset user information database with the user login information, and receive a verification result of identity verification performed by the preset user information database based on the user login information;

[0029] An access token issuing module is used to generate an access token containing user permission information after verification, return the access token to the master client, and verify the validity of the access token when the user uses the access token to access the business system, and grant corresponding access rights based on the user permission information;

[0030] A temporary authorization code issuing module is used to maintain the user's login status. If a user's login request to a sub-client is detected while the user is logged in successfully, a temporary authorization code is generated and the main client is triggered to jump to the sub-client with the temporary authorization code.

[0031] The sub-client login verification module is used to receive and verify the temporary authorization code sent by the sub-client, and after the verification is passed, parse the user identity information corresponding to the temporary authorization code and return it to the sub-client.

[0032] An embodiment of the present disclosure also provides an electronic device, comprising: a processor, a memory, and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate via the bus, and when the machine-readable instructions are executed by the processor, the above-mentioned single sign-on control method or steps in any possible implementation of the above-mentioned single sign-on control method are executed.

[0033] An embodiment of the present disclosure further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the computer program executes the above-mentioned single sign-on control method or the steps of any possible implementation of the above-mentioned single sign-on control method.

[0034] The embodiments of the present disclosure further provide a computer program product, including a computer program / instruction, which, when executed by a processor, implements the above-mentioned single sign-on control method, or the steps in any possible implementation of the above-mentioned single sign-on control method.

[0035] The present disclosure provides a single sign-on control method, device, electronic device, and storage medium. The method, device, and electronic device, as well as a storage medium, provide a method for controlling a single sign-on. The method, device, and electronic device, respond to a user's login request to a main client, obtain user login information, access a preset user information database with the user login information, and receive a verification result of the preset user information database performing identity verification based on the user login information. Upon successful verification, the method generates an access token containing user permission information and returns the access token to the main client. When the user uses the access token to access a business system, the method verifies the validity of the access token and grants access rights based on the user permission information. The method maintains the user's login status. If a user successfully logs in to a sub-client, the method generates a temporary authorization code and triggers the main client to redirect the sub-client with the temporary authorization code. The method receives and verifies the temporary authorization code sent by the sub-client, and, upon successful verification, parses the user identity information corresponding to the temporary authorization code and returns it to the sub-client. The method supports unified authentication and session control for multiple data sources and multiple clients, and enables cross-system password-free login and synchronous session logout while ensuring security, thereby improving user experience, reducing system integration costs, and enhancing overall security.

[0036] In order to make the above-mentioned objectives, features and advantages of the present disclosure more obvious and easy to understand, preferred embodiments are given below and described in detail with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the technical solutions of the embodiments of the present disclosure, the following briefly introduces the drawings required for use in the embodiments. The drawings herein are incorporated into and constitute a part of the specification. These drawings illustrate embodiments consistent with the present disclosure and, together with the specification, are used to illustrate the technical solutions of the present disclosure. It should be understood that the following drawings only illustrate certain embodiments of the present disclosure and should not be regarded as limiting the scope. For those of ordinary skill in the art, other relevant drawings can be obtained based on these drawings without inventive effort.

[0038] Figure 1 A call flow chart of a login authentication system provided by an embodiment of the present disclosure is shown;

[0039] Figure 2 A flow chart of a single sign-on control method provided by an embodiment of the present disclosure is shown;

[0040] Figure 3 A schematic diagram of a single sign-on control device provided by an embodiment of the present disclosure is shown;

[0041] Figure 4 A schematic diagram of an electronic device provided by an embodiment of the present disclosure is shown. DETAILED DESCRIPTION

[0042] In order to make the purpose, technical solutions and advantages of the embodiments of the present disclosure clearer, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below in conjunction with the drawings in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, not all of the embodiments. The components of the embodiments of the present disclosure generally described and shown in the drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present disclosure provided in the drawings is not intended to limit the scope of the disclosure for which protection is sought, but merely represents selected embodiments of the present disclosure. Based on the embodiments of the present disclosure, all other embodiments obtained by those skilled in the art without making creative work are within the scope of protection of the present disclosure.

[0043] It should be noted that similar reference numerals and letters denote similar items in the following drawings, and therefore, once an item is defined in one drawing, it does not need to be further defined or explained in subsequent drawings.

[0044] The term "and / or" herein simply describes an association relationship, indicating that three relationships can exist. For example, A and / or B can represent the existence of A alone, the simultaneous existence of A and B, and the existence of B alone. In addition, the term "at least one" herein refers to any combination of at least two of any one or more of a plurality of items. For example, "at least one of A, B, and C" can represent any one or more elements selected from the set consisting of A, B, and C.

[0045] Research has shown that to address the issue of users repeatedly logging in across multiple systems, existing technologies have proposed a single sign-on (SSO) mechanism based on the OAuth2 protocol, incorporating LDAP directory services as a user information source to achieve unified authentication. However, each business system must implement its own OAuth2 client logic, resulting in inconsistent authentication processes and high development and maintenance costs.

[0046] Based on the above research, the present disclosure provides a single sign-on control method, device, electronic device and storage medium. The method obtains user login information in response to a user login request to a main client, accesses a preset user information database with the user login information, and receives the verification result of the preset user information database performing identity verification based on the user login information. After the verification is successful, an access token containing user permission information is generated and returned to the main client. When the user uses the access token to access a business system, the validity of the access token is verified and the corresponding access rights are granted according to the user permission information. The method maintains the user's login status. If a user login request to a sub-client is detected while the login is successful, a temporary authorization code is generated and triggered to jump from the main client to the sub-client with the temporary authorization code. The method receives and verifies the temporary authorization code sent by the sub-client, and after the verification is successful, parses the user identity information corresponding to the temporary authorization code and returns it to the sub-client. The method can support unified authentication and session control for multiple data sources and multiple clients, and can achieve cross-system password-free login and session synchronous logout under the premise of ensuring security, thereby improving user experience, reducing system integration costs, and enhancing overall security.

[0047] To facilitate understanding of this embodiment, a login authentication system disclosed in the embodiment of the present disclosure is first introduced in detail. The executor of the single sign-on control method provided in the embodiment of the present disclosure is the authentication server in the login authentication system. The login authentication system includes an authentication server, a main client, a sub-client, an SDK module, a user information library and a resource center.

[0048] In the specific implementation, the authentication server serves as the core executive body of the method of the present invention, and assumes the responsibilities of identity verification, token issuance and centralized session management. It can be built using the Spring Boot framework, introduce the Spring SecurityOAuth2 module, and provide a standardized HTTP login interface for each client or SDK to call, supporting username and password authentication, authorization code authentication and other methods. At the same time, it supports the configuration of LDAP server or MySQL database as the user source, has flexible data source switching capabilities, and adopts the OAuth2 protocol specification, combined with the JWT format to generate access tokens. The token embeds user identification, role and authority scope information, and ensures the legitimacy and security of the token through signatures and expiration times. The authentication server supports the issuance of short-term authorization codes (temporary authorization codes) for users of the main system to jump to subsystems for password-free login. When the user of the main system initiates a logout operation, the authentication server notifies all subsystems through a broadcast mechanism to invalidate their login status, thereby achieving unified logout.

[0049] The authentication server is designed with a user identity management model, which includes a user table, a role table, and a permission table. The user table stores basic user information (such as username, password, and email address), the role table defines user roles (such as administrator and ordinary user), and the permission table defines the permissions associated with each role (such as access to resources and operation permissions). A user-role-permission relationship is also established, and information such as IDs and passwords for different client terminals is defined.

[0050] Furthermore, the main client and sub-client belong to multiple business systems of the enterprise. As authentication users, they access the authentication server and call the authentication interface, obtain access tokens, and resolve permissions through the integrated unified SDK component. The client accesses the unified authentication process by calling the standard method provided by the SDK. When the main system logs in successfully, it jumps to access the sub-client with a temporary authorization code. The sub-client calls the SDK to verify the temporary authorization code to achieve password-free login. The client writes the obtained JWT token into the request header and uses it for local permission judgment and resource access control.

[0051] Furthermore, the SDK module acts as an adapter between the authentication process and the client, encapsulating all key call logic and reducing client development costs. It includes the following features: Login method encapsulation: encapsulates the username and password login and authorization code (Code) login interfaces, automatically completing token application and caching; Token management component: includes local token storage, refresh mechanism, expiration detection, and automatic replacement logic; Logout interface: After the main client calls the logout method provided by the SDK, the SDK will notify the authentication server to cancel the login status of all related sub-clients; Exception handling and callback mechanism: provides a general exception callback interface for handling exception scenarios such as login failure and token expiration.

[0052] Furthermore, the resource center provides clients with synchronization support for user data, roles, and organizational information. It regularly pulls user basic information, role definitions, and permission mapping data from the authentication server to prevent clients from directly accessing the authentication database. It synchronizes user organizations, job information, etc. for subsequent permission control and business processing, and provides a RESTful interface for clients to query user information, role relationships, and other information in real time.

[0053] Combined with the above modules, the calling process of the unified authentication single sign-on control method of the entire system can be found in Figure 1 As shown in FIG, a call flow chart of a login authentication system provided by an embodiment of the present disclosure is provided. Figure 1 As shown in , the calling process of the login authentication system includes steps S1 to S17, wherein: S1. The user enters the account and password in the login interface of any client. S2. The main client calls the account and password login interface in the SDK. S3. The SDK calls the token generation interface of the authentication server. S4. The authentication server compares the account and password entered by the user with the user information database. S5. After successful comparison, the result is returned. S6. The authentication server generates a token and returns it to the SDK. S7. The client uses the token passed by the SDK to successfully log in. S8. The main client calls the code generation interface. S9. The SDK returns the generated code. S10. The main client jumps to the sub-client with the code. S11. The sub-client calls the SDK's coke code verification function. S12. The sub-client logs in based on the user information returned by the SDK. S13. The main client calls the SDK's exit function. S14. The SDK notifies the authentication server to invalidate the login status of the relevant sub-client. S15. The client calls the resource center's user synchronization function. S16: The resource center periodically updates the user information from the user information database. S17: The resource center returns the latest user information to the client.

[0054] Next, a single sign-on control method disclosed in the embodiment of the present disclosure is described in detail. Figure 2 FIG. 1 is a flow chart of a single sign-on control method provided by an embodiment of the present disclosure, which is applied to an authentication server in a login authentication system. The method includes steps S101 to S104, wherein:

[0055] S101. In response to a user's login request to a primary client, obtain user login information, access a preset user information database with the user login information, and receive a verification result of identity verification performed by the preset user information database based on the user login information.

[0056] In the specific implementation, the user initiates the login behavior through the main client (such as the main system web portal or App). The system needs to verify the legitimacy of its identity. The user enters the login credentials such as account number and password on the main client interface and clicks the login button. The main client packages this information into a login request and sends it to the authentication server.

[0057] Here, the login information may include user account, login password, and client identifier. After receiving the login request from the primary client, the authentication server extracts the user login information contained in the request body. According to the configuration, the authentication server verifies the user identity by connecting to the preset user information database.

[0058] Among them, user information base types can include LDAP servers: such as OpenLDAP and Active Directory, which are suitable for the organization's unified account system; and relational databases: such as MySQL and PostgreSQL, which are suitable for the business system's private account system.

[0059] It should be noted that during the authentication process, the authentication server can carry the user account and login password included in the login information, and use the LDAP protocol in the LDAP server to query the matching user information through DN and Base DN. The relational database is used to store user information, organizational structure, etc. read from the LDAP server to facilitate the subsystem to synchronize user information, and does not participate in the authentication process. In other words, during the verification query process through the user account and login password, the user information can be obtained by the relational database and then synchronized with the subsystem.

[0060] As a possible implementation method, the user login information is sent to a preset user information database through a pre-configured database connection; the preset user information database matches the user account and login password included in the user login information with the pre-stored user identity information to verify the legitimacy of the login request; if the preset user information database verifies that the user account and login password match the user identity information, the verification success information returned by the preset user information database is received; if the preset user information database verifies that the user account and login password do not match the user identity information, the verification failure information returned by the preset user information database is received.

[0061] In a specific implementation, the authentication server accesses a pre-set user information database with the user's login information to verify the user's identity. In database access scenarios, the authentication server can retrieve target records from the user data table and obtain the pre-stored encrypted password digest using a pre-set JDBC connection interface, using the user account as the query field. In directory service scenarios, the authentication server initiates an account verification request within the Base DN range to the directory system via the LDAP protocol.

[0062] Upon receiving the authentication server's query request, the user information database verifies the entered account and password. If the user information database confirms the account exists and the password matches successfully, it returns a verification result indicating identity verification passed. Upon receiving this verification result, the authentication server can proceed with subsequent operations such as token generation and permission loading. If the user information database returns a verification failure result indicating the account does not exist or the password is incorrect, the authentication server aborts the login process and returns a login failure notification to the primary client.

[0063] As a possible implementation method, to further enhance the access security of the subsystem, a dual-factor authentication mechanism can be introduced during the authentication process, with the traditional user account and login password as the first authentication factor, and other verification methods such as mobile phone SMS verification code authentication, graphic verification code verification, dynamic password (such as TOTP) as the second authentication factor. In specific implementation, when the user jumps from the main client to the sub-client without a password and completes the identity verification through a temporary authorization code, the sub-client can further trigger the second factor verification based on the security policy. For example: a one-time verification code is sent to the user's bound mobile phone number, and the user must enter it correctly before completing the login; the user is required to complete the graphic verification code recognition operation to resist automated attacks; when accessing highly sensitive business systems, a one-time dynamic password generated by a hardware token or a two-factor app is combined for verification. This type of authentication mechanism serves as a supplement to the main authentication logic. Even if the user's main account password information is leaked, if the attacker cannot obtain the second factor through the bound mobile phone or dynamic authentication device, the final login cannot be completed, thereby significantly improving the system's overall anti-attack capability and account security, and effectively preventing unauthorized access.

[0064] S102. After the verification is passed, an access token containing user authority information is generated, and the access token is returned to the main client. When the user uses the access token to access the business system, the validity of the access token is verified, and corresponding access rights are granted according to the user authority information.

[0065] In practice, after the authentication server receives a user identity verification result from a preset user information repository, it further generates an access token. The access token is used to identify the user's login status and access rights, and is unique and time-sensitive. Specifically, the authentication server generates an access token based on the current user's identity (such as user ID, account name) and permission information (such as role information, functional permission list, organizational dimensions, etc.), using a preset encryption algorithm (such as HMAC-SHA256 or JWT standard).

[0066] The generated access token can encapsulate key information such as the user's unique identifier, login timestamp, permission scope, token validity period, and issuing authority identifier. If necessary, an encrypted signature and tamper-proof checksum fields can also be added to ensure the security of the token data during transmission and storage. After generating the access token, the authentication server returns it to the primary client via the HTTPS interface.

[0067] After receiving the access token, the primary client caches it locally or stores it in a secure container, which it then attaches to requests as authentication credentials when accessing the business system. During user operations, when the primary client initiates a request to the target business system (such as the management platform, functional module services, etc.), it includes the access token in the request header.

[0068] Furthermore, upon receiving a user request containing an access token, the business system will call the token validation API provided by the authentication server or use the built-in token parsing module to verify the validity of the access token. Verification includes, but is not limited to, whether the token signature is correct, whether it is within its validity period, whether it has been revoked, and whether the permission scope matches the currently requested resource. If verification passes, the business system will then apply fine-grained access control to the request based on the user permission information contained in the access token, such as determining whether functions are visible, data is readable, and whether operations are permitted.

[0069] As a possible implementation method, the authentication server is also responsible for unified management of the user login status and the life cycle of the access token. Specifically, when a user logs in through the main client and completes identity verification, the authentication server will generate an access token for the user that carries the user's identity information and permission information, and save the token information locally or in a cache system for subsequent verification and session management. To ensure system security and resource efficiency, the authentication server will set a validity period for each access token. For example, the default configuration is valid for 3 hours. Within this time range, the user can access multiple business systems without re-login. This validity period parameter can be flexibly configured by the system administrator according to business needs, and supports manual or strategic dynamic adjustment. When the token expires, the authentication server will automatically expire and clear the token information to prevent the expired token from being abused, thereby ensuring access security. At the same time, when the user actively logs out, the permissions change, or abnormal login behavior is detected, the authentication server will immediately revoke the user's token to avoid potential security risks.

[0070] S103: Maintain the user's login status. If a login request to the sub-client is detected while the user is successfully logged in, generate a temporary authorization code and trigger the main client to jump to the sub-client with the temporary authorization code.

[0071] In a specific implementation, the user's login status is maintained. If a user successfully logs in to a sub-client and then requests a login, a temporary authorization code is generated and the main client is triggered to jump to the sub-client with the temporary authorization code. The SDK module provides a mechanism for generating temporary authorization codes. Specifically, during user operation, if the main client triggers a jump to another service sub-client (such as a subsystem or third-party integration module), the SDK module will call the authorization code generation interface preset in the SDK module.

[0072] Specifically, in response to the main client's call operation on the authorization code generation interface in the SDK module, a temporary authorization code with a corresponding validity period is generated according to the pre-stored user identity information through the pre-packaged password-free login function method; the temporary authorization code is returned to the main client through the authorization code generation interface.

[0073] In response to this call from the main client, the SDK module executes a pre-packaged password-free login method. This method utilizes the user identity information (such as user ID and token) cached on the main client or authentication server after a successful login, eliminating the need to re-enter the username and password, thereby completing the temporary authentication credential generation process without the user's knowledge.

[0074] The password-free login method generates an authorization data structure based on the current user's identity information, including fields such as user ID, login time, target sub-client ID, and validity period settings. It then constructs a temporary authorization code with anti-counterfeiting capabilities using an encryption algorithm (such as AES, RSA, or JWT signature). This authorization code has a limited validity period to prevent malicious reuse or forgery.

[0075] The SDK module then returns the temporary authorization code to the master client through its authorization code generation interface. After receiving the temporary authorization code, the master client can carry it in the jump request and then jump to the target sub-client, thus completing the subsequent single sign-on process.

[0076] S104: Receive and verify the temporary authorization code sent by the sub-client, and after verification, parse the user identity information corresponding to the temporary authorization code and return it to the sub-client.

[0077] In practice, after receiving the temporary authorization code from the sub-client, the authentication server first verifies the validity of the authorization code. This process may include verifying the validity period of the authorization code to ensure that the authorization code has not expired; checking the signature and integrity of the authorization code to ensure that the authorization code has not been tampered with; and verifying the uniqueness of the authorization code to ensure that it has not been reused.

[0078] Once the temporary authorization code is verified, the authentication server parses it and extracts the user identity information contained within. This identity information typically includes the user's unique identifier, user role, and permissions. The authentication server returns the parsed user identity information to the sub-client. This identity information can be used by the sub-client to perform subsequent user operations, such as authorized resource access and personalized display.

[0079] As a possible implementation method, in response to a logout request triggered by a user through a main client or a sub-client, the corresponding access token is revoked according to the user's identity information, and the main client is logged out; the login status corresponding to the sub-client is invalidated, and the sub-client to which the user has logged in is logged out synchronously.

[0080] In practice, when a user triggers a logout request on the primary client or sub-client, the system first receives the logout request. This request may include the user's identity information, identifying the user to be logged out. Based on the received user identity information, the authentication server searches for and revokes the user's access token on the primary client. The access token identifies the user's login status in the system. Revoking the access token invalidates the user's authentication, terminating the user's current session.

[0081] Here, after revoking the access token, the authentication server notifies the primary client and asks it to log out the current user. The primary client then destroys the user's login session and clears related authentication information, ensuring that the user can no longer access system resources.

[0082] At the same time, the authentication server checks whether the user is logged in on the sub-client. If the user is logged in on the sub-client, the authentication server invalidates their login. This means that the sub-client can no longer authenticate using the expired or revoked access token, and the user's session is terminated.

[0083] It should be noted that to ensure consistency, the authentication server will simultaneously log out all users logged in on other sub-clients. This is done by notifying all sub-clients of the invalid user's login information, triggering the sub-client to clear the user's login status, thereby preventing the user from remaining logged in on some sub-clients.

[0084] In this way, after the user triggers the logout operation, the authentication server can completely revoke the user's login status on all clients, ensuring that all devices of the user are logged out of the current session, thereby enhancing the security and consistency of the system.

[0085] As another possible implementation, in response to a user information synchronization request triggered by the master client, the preset resource center is triggered to update the user identity information through the preset user information library according to the preset update frequency; the preset resource center returns the updated user identity information to the master client.

[0086] In practice, the authentication server supports dynamic synchronization and updating of user identity information, ensuring that the master client receives the latest user identity information, improving the consistency and timeliness of authentication data. When a user triggers a user information synchronization operation in the master client, the master client initiates a user information synchronization request to the authentication server. This request indicates that the system needs to refresh and obtain the user's latest identity information at the current point in time.

[0087] Upon receiving the synchronization request, the authentication server sends a command to the pre-set resource center, triggering it to execute the user identity information update process. The resource center then decides whether to immediately pull the latest data from the pre-set user information repository based on the system's pre-set update frequency policy.

[0088] If the resource center determines that the update conditions are met, it accesses and extracts the latest records related to the current user's identity information through a data connection established with the pre-set user information repository. After completing the user identity update, the resource center returns the updated user identity information to the authentication server, which then forwards it to the primary client. The primary client then refreshes its local cache based on the returned identity information, ensuring that subsequent permission control and user interface display are based on the latest data.

[0089] The present disclosure provides a single sign-on control method, which obtains user login information in response to a user login request to a main client, accesses a preset user information database with the user login information, and receives a verification result of the preset user information database performing identity verification based on the user login information; after the verification is successful, generates an access token containing user permission information, returns the access token to the main client, and verifies the validity of the access token when the user uses the access token to access a business system, and grants corresponding access rights based on the user permission information; maintains the user's login status, and if a user login request to a sub-client is detected while the login is successful, generates a temporary authorization code and triggers the main client to jump to the sub-client with the temporary authorization code; receives and verifies the temporary authorization code sent by the sub-client, and after the verification is successful, parses the user identity information corresponding to the temporary authorization code and returns it to the sub-client. The method can support unified authentication and session control for multiple data sources and multiple clients, and can achieve cross-system password-free login and session synchronous logout under the premise of ensuring security, thereby improving user experience, reducing system integration costs, and enhancing overall security.

[0090] Those skilled in the art will understand that in the above-mentioned method of the specific implementation method, the writing order of each step does not mean a strict execution order and does not constitute any limitation on the implementation process. The specific execution order of each step should be determined by its function and possible internal logic.

[0091] Based on the same inventive concept, a single sign-on control device corresponding to the single sign-on control method is also provided in the embodiment of the present disclosure. Since the principle of solving the problem by the device in the embodiment of the present disclosure is similar to the above-mentioned single sign-on control method in the embodiment of the present disclosure, the implementation of the device can refer to the implementation of the method, and the repeated parts will not be repeated.

[0092] See also Figure 3 , Figure 3 This is a schematic diagram of a single sign-on control device provided by an embodiment of the present disclosure. Figure 3 As shown in , the single sign-on control device 300 provided by the embodiment of the present disclosure includes:

[0093] The main client login verification module 310 is used to respond to the user's login request for the main client, obtain user login information, access the preset user information database with the user login information, and receive the verification result of the preset user information database performing identity verification based on the user login information.

[0094] The access token issuance module 320 is used to generate an access token containing user permission information after verification, return the access token to the main client, and verify the validity of the access token when the user uses the access token to access the business system, and grant corresponding access rights based on the user permission information.

[0095] The temporary authorization code issuing module 330 is used to maintain the user's login status. If a user's login request to the sub-client is detected in the successful login state, a temporary authorization code is generated and the main client is triggered to jump to the sub-client with the temporary authorization code.

[0096] The sub-client login verification module 340 is configured to receive and verify the temporary authorization code sent by the sub-client, and after verification, parse the user identity information corresponding to the temporary authorization code and return it to the sub-client.

[0097] For descriptions of the processing flow of each module in the device and the interaction flow between each module, reference can be made to the relevant descriptions in the above method embodiment, which will not be described in detail here.

[0098] The present disclosure provides a single sign-on control device that, in response to a user's login request to a main client, obtains user login information, accesses a preset user information database with the user login information, and receives a verification result of the preset user information database performing identity verification based on the user login information. After the verification is successful, an access token containing user permission information is generated and returned to the main client. When the user uses the access token to access a business system, the validity of the access token is verified and corresponding access rights are granted based on the user permission information. The device maintains the user's login status and, if a user logs in successfully to a sub-client, generates a temporary authorization code and triggers the main client to jump to the sub-client with the temporary authorization code. The device receives and verifies the temporary authorization code sent by the sub-client and, after verification is successful, parses the user identity information corresponding to the temporary authorization code and returns it to the sub-client. The device can support unified authentication and session control for multiple data sources and multiple clients, and can achieve cross-system password-free login and session synchronous logout while ensuring security, thereby improving user experience, reducing system integration costs, and enhancing overall security.

[0099] Corresponding to Figure 2 The present disclosure also provides an electronic device 400, such as Figure 4 FIG. 4 is a schematic diagram of the structure of an electronic device 400 provided in an embodiment of the present disclosure, including:

[0100] Processor 41, memory 42, and bus 43; memory 42 is used to store execution instructions, including memory 421 and external memory 422; the memory 421 here is also called internal memory, which is used to temporarily store the operation data in the processor 41 and the data exchanged with the external memory 422 such as the hard disk. The processor 41 exchanges data with the external memory 422 through the memory 421. When the electronic device 400 is running, the processor 41 and the memory 42 communicate through the bus 43, so that the processor 41 executes Figure 2 Steps for the single sign-on control method in .

[0101] The present disclosure also provides a computer-readable storage medium having a computer program stored thereon. When executed by a processor, the computer program executes the steps of the single sign-on control method described in the above method embodiment. The storage medium may be a volatile or non-volatile computer-readable storage medium.

[0102] The embodiments of the present disclosure also provide a computer program product, which includes computer instructions. When the computer instructions are executed by a processor, the steps of the single sign-on control method described in the above method embodiment can be executed. For details, please refer to the above method embodiment, which will not be repeated here.

[0103] The computer program product may be implemented in hardware, software, or a combination thereof. In one embodiment, the computer program product is implemented as a computer storage medium. In another embodiment, the computer program product is implemented as a software product, such as a software development kit (SDK).

[0104] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the device described above can refer to the corresponding process in the aforementioned method embodiment, and will not be repeated here. In the several embodiments provided in the present disclosure, it should be understood that the disclosed device and method can be implemented in other ways. The device embodiments described above are merely schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be through some communication interfaces, and the indirect coupling or communication connection of the device or unit can be electrical, mechanical or other forms.

[0105] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.

[0106] In addition, each functional unit in each embodiment of the present disclosure may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

[0107] If the functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a non-volatile computer-readable storage medium that is executable by a processor. Based on this understanding, the technical solution of the present disclosure, or the part that contributes to the prior art or the part of the technical solution, can be embodied in the form of a software product, which is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present disclosure. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.

[0108] Finally, it should be noted that the above-described embodiments are only specific implementation methods of the present disclosure, which are used to illustrate the technical solutions of the present disclosure, rather than to limit them. The scope of protection of the present disclosure is not limited thereto. Although the present disclosure has been described in detail with reference to the above-described embodiments, those skilled in the art should understand that any person skilled in the art can modify or easily conceive of changes to the technical solutions described in the above-described embodiments within the technical scope disclosed in the present disclosure, or replace some of the technical features therein with equivalents. Such modifications, changes, or replacements do not deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure, and should be included in the scope of protection of the present disclosure. Therefore, the scope of protection of the present disclosure shall be subject to the scope of protection of the claims.

Claims

1. A single sign-on control method, characterized in that: Applied to an authentication server in a login authentication system, the method comprises: In response to a user login request to the primary client, obtain user login information, access a preset user information database with the user login information, and receive a verification result of identity verification performed by the preset user information database based on the user login information; After the verification is passed, an access token containing user authority information is generated and returned to the master client. When the user uses the access token to access the business system, the validity of the access token is verified and the corresponding access rights are granted according to the user authority information. Maintaining the user's login status, if monitoring the user's login request to the sub-client in the successful login state, generating a temporary authorization code and triggering the main client to jump to the sub-client with the temporary authorization code; Receive and verify the temporary authorization code sent by the sub-client, and after verification, parse the user identity information corresponding to the temporary authorization code and return it to the sub-client.

2. The method according to claim 1, characterized in that The method further comprises: In response to a logout request triggered by the user through the main client or the sub-client, revoking the corresponding access token according to the user identity information and logging out of the main client; Invalidate the login status corresponding to the sub-client, and synchronously log out of the sub-client that the user has logged in.

3. The method according to claim 1, characterized in that The authentication server includes an SDK module, which generates the temporary authorization code based on the following steps: In response to the main client's call operation on the authorization code generation interface in the SDK module, the temporary authorization code with a corresponding validity period is generated according to the pre-stored user identity information through the pre-packaged password-free login function method; The temporary authorization code is returned to the primary client through the authorization code generation interface.

4. The method according to claim 3, characterized in that Receiving and verifying the temporary authorization code sent by the sub-client, and parsing the user identity information corresponding to the temporary authorization code after verification, and returning it to the sub-client, specifically including: In response to the sub-client's calling operation on the authorization code verification interface in the SDK module, parsing the user identity information to which the temporary authorization code belongs through a pre-packaged authorization code verification function method; The user identity information is returned to the sub-client through the authorization code verification interface.

5. The method according to claim 1, characterized in that Accessing a preset user information database with the user login information and receiving a verification result of identity verification performed by the preset user information database based on the user login information specifically includes: Sending the user login information to the preset user information database via a pre-configured database connection; The preset user information database matches the user account and login password included in the user login information with the pre-stored user identity information to verify the legitimacy of the login request; If the preset user information database verifies that the user account, the login password and the user identity information match, receiving a verification success message returned by the preset user information database; If the preset user information database verifies that the user account, the login password and the user identity information do not match, then a verification failure message returned by the preset user information database is received.

6. The method according to claim 1, wherein The method further comprises: In response to a user information synchronization request triggered by the master client, triggering a preset resource center to update the user identity information through the preset user information database according to a preset update frequency; The preset resource center returns the updated user identity information to the master client.

7. A single sign-on control device, characterized in that: Applicable to an authentication server in a login authentication system, the device comprises: A master client login verification module is configured to, in response to a user login request to the master client, obtain user login information, access a preset user information database with the user login information, and receive a verification result of identity verification performed by the preset user information database based on the user login information; An access token issuing module is used to generate an access token containing user permission information after verification, return the access token to the master client, and verify the validity of the access token when the user uses the access token to access the business system, and grant corresponding access rights based on the user permission information; A temporary authorization code issuing module is used to maintain the user's login status. If a user's login request to a sub-client is detected while the user is logged in successfully, a temporary authorization code is generated and the main client is triggered to jump to the sub-client with the temporary authorization code. The sub-client login verification module is used to receive and verify the temporary authorization code sent by the sub-client, and after the verification is passed, parse the user identity information corresponding to the temporary authorization code and return it to the sub-client.

8. An electronic device, characterized in that: include: A processor, a memory and a bus, wherein the memory stores machine-readable instructions executable by the processor, and when the electronic device is running, the processor and the memory communicate via the bus, and when the machine-readable instructions are executed by the processor, the steps of the single sign-on control method according to any one of claims 1 to 6 are performed.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, executes the steps of the single sign-on control method according to any one of claims 1 to 6.

10. A computer program product comprising computer instructions, characterized in that When the computer instructions are executed by a processor, the steps of the single sign-on control method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Single log-in method, mobile terminal, and computer readable storage medium

    CN109165499A

  • Single sign-on method and device and computer readable storage medium

    CN110177120A

  • Unified identity authentication method and device

    CN118118227A

  • Inter-application authentication method and device and readable storage medium

    CN118381626A

  • Single sign-on and single logout functionality for a multi-tenant identity and data security management cloud service

    IN201847041866A

Cited By

  • Login management method and device

    CN121309238A