Method and system for providing single sign-on
Patent Information
- Application Number
- KR1020250038989
- Authority / Receiving Office
- KR · KR
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2025-02-28
- Filing Date
- 2025-03-26
- Publication Date
- 2026-09-04
Smart Images

Figure PAT00001_ABST
Abstract
Description
Technology Field
[0001] The present disclosure relates to a method and system for providing a single sign-on. Background Technology
[0003] In the modern digital environment, the need for users to access various websites, applications, and services is increasing. These services require user authentication procedures to enhance security, and most require the setting of individual accounts and passwords. However, users face the inconvenience of having to manage multiple accounts and remember authentication information for each one individually.
[0004] Single Sign-On (SSO) technology emerged to address these issues. SSO is a technology that allows users to access multiple services through a single authentication, offering the advantages of improved user experience and enhanced security. By utilizing SSO, users can log in to various systems using only a single piece of authentication information, without the need to remember multiple passwords.
[0005] Current single sign-on systems are unable to provide selective sign-on based on user information such as age and country. This leads to problems where inappropriate user access cannot be blocked when age or regional restrictions are applied to specific services. Furthermore, while appropriate authentication and access restrictions for user information are required due to differing data protection regulations and legal requirements across countries, existing SSO systems have limitations in adequately reflecting these needs. These issues can compromise security and cause difficulties for service providers in complying with legal regulations.
[0006] Therefore, there is a need to provide a selective single sign-on.
[0007] The information described above may be provided as related art for the purpose of aiding understanding of the present disclosure. No claim or determination is made as to whether any of the foregoing may be applied as prior art related to the present disclosure.
[0009] The present invention relates to a method and system for providing a single sign-on within the same service group according to one embodiment.
[0010] A method for providing a single sign-on within the same service group according to one embodiment may include: an operation of generating a random key when an authentication server receives login information including a user's account and password from a first service server; an operation of verifying group information including the first service server at the authentication server; an operation of generating a token for the user at the authentication server; an operation of storing user information, which is information about the user including the key, the token, and the group information including the first service server at the authentication server; and an operation of responding a cookie including the key to the first service server at the authentication server.
[0011] According to one embodiment, an authentication server providing a single sign-on within the same service group comprises one or more processors and a memory for storing instructions. When the instructions are executed by the one or more processors, the authentication server may perform the following operations: generating a random key when the authentication server receives login information including a user's account and password from a first service server; verifying group information including the first service server in the authentication server; generating a token for the user in the authentication server; storing user information, which is information about the user including the key, the token, and the group information including the first service server in the authentication server; and responding a cookie including the key to the first service server in the authentication server.
[0012] According to one embodiment, a computer-readable recording medium stores instructions, and when the instructions are executed by one or more processors, when an authentication server receives login information including a user's account and password from a first service server, the authentication server may perform the operation of generating a random key; the authentication server may perform the operation of verifying group information including the first service server; the authentication server may perform the operation of generating a token for the user; the authentication server may perform the operation of storing user information, which is information about the user including the key, the token, and the group information including the first service server; and the authentication server may perform the operation of responding to the first service server with a cookie including the key. Brief explanation of the drawing
[0014] In relation to the description of the drawings, the same or similar reference numerals may be used for identical or similar components. FIG. 1 is a diagram illustrating a message flow in a system that provides single sign-on according to one embodiment, in which a cookie is created for single sign-on and provided to a service server. FIG. 2 is a diagram illustrating a message flow that provides a single sign-on using a cookie in a system that provides a single sign-on according to one embodiment. FIG. 3 is a flowchart illustrating the flow of generating a cookie for single sign-on at an authentication server according to one embodiment and providing it to a service server. FIG. 4 is a flowchart illustrating the flow of providing single sign-on using cookies in an authentication server according to one embodiment. FIG. 5 is a flowchart illustrating the flow of checking the conditions for providing a single sign-on in an authentication server according to one embodiment. FIG. 6 is a flowchart illustrating the flow of providing user information of the group to which the service server belongs from an authentication server according to one embodiment. FIG. 7 is a diagram illustrating an example of a group management menu provided to an administrator by an authentication server according to one embodiment. FIG. 8 is a diagram illustrating an example of a user's login history provided to a user by an authentication server according to one embodiment. FIG. 9 is a diagram illustrating the schematic configuration of an authentication server according to one embodiment. Specific details for implementing the invention
[0015] Hereinafter, embodiments are described in detail with reference to the attached drawings. However, various modifications may be made to the embodiments, and thus the scope of the patent application is not limited or restricted by these embodiments. It should be understood that all modifications, equivalents, and substitutions to the embodiments are included within the scope of the rights.
[0016] The terms used in this disclosure are described in their current, general form considering the functions mentioned herein; however, they may refer to various other terms depending on the intent of those skilled in the art, case law, or the emergence of new technologies. Accordingly, the terms used in this disclosure should not be interpreted solely by their names, but should be interpreted based on the meaning of the terms and the overall content of this disclosure.
[0017] Phrases such as "according to one embodiment" appearing in various places in this disclosure do not necessarily refer to the same embodiment.
[0018] One embodiment of the present disclosure may be represented by functional block configurations and various processing operations. Some or all of these functional blocks may be implemented by various numbers of hardware and / or software configurations that execute specific functions. For example, the functional blocks of the present disclosure may be implemented by one or more microprocessors or by circuit configurations for a specific function. Additionally, for example, the functional blocks of the present disclosure may be implemented in various programming or scripting languages. The functional blocks may be implemented as algorithms executed on one or more processors. Furthermore, the present disclosure may employ background technology for electronic configuration, signal processing, and / or data processing. Terms such as “element” and “configuration” may be used broadly and are not limited to mechanical and physical configurations.
[0019] The terms used in the embodiments are for illustrative purposes only and should not be interpreted as intended to be limiting. Singular expressions include plural expressions unless the context clearly indicates otherwise. In this specification, terms such as "comprising" or "having" are intended to indicate the existence of the features, numbers, steps, actions, components, parts, or combinations thereof described in the specification, and should be understood as not precluding the existence or addition of one or more other features, numbers, steps, actions, components, parts, or combinations thereof.
[0020] Unless otherwise defined, all terms used herein, including technical or scientific terms, have the same meaning as generally understood by those skilled in the art to which the embodiments pertain. Terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant technology, and should not be interpreted in an ideal or overly formal sense unless explicitly defined in this application.
[0021] In addition, when describing with reference to the attached drawings, identical components are assigned the same reference numeral regardless of drawing symbols, and redundant descriptions thereof are omitted. In describing the embodiments, if it is determined that a detailed description of related prior art could unnecessarily obscure the essence of the embodiments, such detailed description is omitted.
[0022] In addition, terms such as first, second, A, B, (a), (b), etc., may be used when describing the components of the embodiments. These terms are intended merely to distinguish the components from other components, and the nature, order, or sequence of the components is not limited by these terms. Where it is stated that a component is "connected," "combined," or "connected" to another component, it should be understood that while the component may be directly connected or connected to the other component, another component may also be "connected," "combined," or "connected" between each component.
[0023] Components included in any one embodiment and components having common functions shall be described using the same names in other embodiments. Unless otherwise stated, the description in any one embodiment may also apply to other embodiments, and specific descriptions shall be omitted to the extent of overlap.
[0024] FIG. 1 is a diagram illustrating a message flow in a system that provides single sign-on according to one embodiment, in which a cookie is created for single sign-on and provided to a service server.
[0025] Referring to FIG. 1, a system providing single sign-on within the same service group may be configured to include a plurality of service servers (110, 120), an authentication server (130), and a database (140).
[0026] When the first service server (110) receives a login request from a user, it can transmit the user's login information to the authentication server (130) (151).
[0027] When the authentication server (130) receives the user's login information, it can verify the user's login information to determine whether the user is a legitimate user (152). At this time, the login information may include the account and password of the user who requested the login. In addition, the login information
[0028] The authentication server (130) can generate a key (153) if the login information is verified as a result of the 152 operation and the user is a legitimate user. At this time, the authentication server (130) can generate a key with an arbitrary value.
[0029] The authentication server (130) requests group information of the first service server (110) from the database (140) (154), and can receive group information of the first service server (110) from the database (140) (155).
[0030] The authentication server (130) can generate a token for a user who has requested a login (156) and store user information for the user who has requested a login in a database (140), including a key, a token, and group information including the first service server (100) (157). At this time, the token is intended to prove the identity of the user and is an encrypted string containing the user's globally unique identifier (GUID). At this time, in addition to the user's globally unique identifier, the token may additionally include some or all of the user's profile information, the user's nationality, information on the authority held by the user, and the expiration date of the token. The token may be encrypted using the RSA algorithm, but is not limited thereto and may use various encryption methods.
[0031] User information may include group information including a key, a token, and a first service server. Additionally, user information may further include some or all of the following: the user's globally unique identifier, the user's account, the user's name, information on when the user information is stored, and information on when the user information expires.
[0032] In operation 156, the authentication server (130) can generate a token by encrypting information including at least one of the user's global unique identifier, the user's account, the user's name and the user's age.
[0033] In operation 157, the authentication server (130) can classify and store user information by group when storing user information in the database (140).
[0034] The authentication server (130) can store key and group-specific user login information in the form of a data structure as shown in the example below.
[0035] {key} : {
[0036] {group1} : [ {User information(account, Last Name, First Name, Age, token)}, {User information(account, Last Name, First Name, Age, token)} ],
[0037] {group2} : [ {User information(account, last name, first name, age, token)} ]
[0038] }
[0039] The authentication server (130) may transmit a cookie containing a key to the first service server (110) (158). At this time, the cookie may store user recognition information to prevent the user from repeating the same authentication across multiple services. In addition to the key, the cookie may additionally include some or all of the user's token, global unique identifier (GUID), cookie expiration date, and optional information regarding security settings.
[0040] The first service server (110) can provide cookies to the user's browser so that cookies can be stored in the user's browser.
[0042] FIG. 2 is a diagram illustrating a message flow that provides a single sign-on using a cookie in a system that provides a single sign-on according to one embodiment.
[0043] Referring to FIG. 2, a system providing single sign-on within the same service group may be configured to include a plurality of service servers (110, 120), an authentication server (130), and a database (140).
[0044] When the second service server (120) receives a login request from a user whose browser has a cookie stored therein, it can send the cookie to the authentication server (130) to request a lookup on whether the user is capable of single sign-on (211).
[0045] When the authentication server (130) receives a cookie from the second service server (120), it requests user information corresponding to the key included in the cookie from the database (140) (212), and can receive the requested user information from the database (140) (213).
[0046] The authentication server (130) requests group information containing the second service server (120) that sent the cookie from the database (140) (214), and can receive the group information of the second service server (120) from the database (140) (215).
[0047] The authentication server (130) can check whether the group information included in the user information is the same as the group information included in the second service server (120) (216).
[0048] 216 If the group information included in the user information and the group information included in the second service server (120) are the same as the result of the operation, the authentication server (130) can transmit the user information to the second service server (120) (217). The fact that the group information included in the user information and the group information included in the second service server (120) are the same means that the group user of the second service server (120) is in the same group as the first service server (110) that performed the login.
[0049] 216 If, as a result of checking the operation, the group information included in the user information and the group information included in the second service server (120) are not the same, the authentication server (130) can send an empty list to the second service server (120) to indicate that the user is not included in the same service group as the second service server (120).
[0050] If a user logs into the same service group as the second service server (120) and single sign-on is possible, the second service server (120) can request single sign-on by sending a token included in the received user information to the authentication server (130) (219).
[0051] When the authentication server (130) receives a token included in user information from the second service server (120), it can authenticate the user with the token (220). In operation 220, the authentication server (130) can authenticate the user by decrypting the received token.
[0052] The authentication server (130) can check whether all conditions for providing a single sign-on are satisfied (221). In operation 221, the conditions for providing a single sign-on that the authentication server (130) checks may include at least one of whether the country required by the service provided by the second service server is the same as the user's country, whether the user is included in the age restriction required by the service provided by the second service server, and whether there are terms and conditions that must be agreed upon by the user.
[0053] When the authentication server (130) succeeds in user authentication and satisfies all conditions for providing a single sign-on, it can send a login completion to the second service server (120) to complete the login through a single sign-on (222).
[0054] Meanwhile, if the authentication server (130) does not satisfy the conditions for providing a single sign-on, it can send a notification message to the user regarding the conditions for providing a single sign-on that are not satisfied.
[0055] If there are terms and conditions that the authentication server (130) needs to obtain consent from the user through a notification message, the authentication server may obtain consent to the terms and conditions and provide a single sign-on.
[0056] Although the authentication server (130) and the database (140) are shown separately in FIGS. 1 and FIGS. 2, the authentication server (130) may be configured to include the database (140).
[0058] FIG. 3 is a flowchart illustrating the flow of generating a cookie for single sign-on at an authentication server according to one embodiment and providing it to a service server.
[0059] Referring to FIG. 3, when the authentication server (130) receives login information from the first service server (110) in operation 310, it can verify the login information in operation 312 to determine whether it is a legitimate user.
[0060] If the login information received as a result of the verification of operation 312 is the information of a legitimate user, the authentication server (130) can generate an arbitrary key in operation 314.
[0061] In operation 316, the authentication server (130) can check group information including the first service server (110) that transmitted the login information.
[0062] In operation 318, the authentication server (130) can generate a token. At this time, the authentication server (130) can generate a token by encrypting information including at least one of the user's global unique identifier, the user's account, the user's name, and the user's age.
[0063] In operation 320, the authentication server (130) may store user information in a database (140) that includes group information containing a key, a token, and a first service server (110). At this time, the user information includes group information containing a key, a token, and a first service server, and may additionally include some or all of the user's global unique identifier, the user's account, the user's name, information on when the user information is stored, and information on when the user information expires. Also, when the authentication server (130) stores user information in the database (140), it may classify and store user information by group.
[0064] In operation 322, the authentication server (130) may respond to the first service server (110) with a cookie containing a key.
[0066] FIG. 4 is a flowchart illustrating the flow of providing single sign-on using cookies in an authentication server according to one embodiment.
[0067] Referring to FIG. 4, when the authentication server (130) receives a cookie from the second service server (120) in operation 410, in operation 412, it can look up login information using the key included in the cookie and obtain user information corresponding to the key from the database (140).
[0068] In operation 414, the authentication server (130) can check group information including the second service server (120) through the database (140).
[0069] In operation 416, the authentication server (130) can check whether the group information included in the user information is the same as the group information included in the second service server.
[0070] If, as a result of checking operation 416, the group information included in the user information and the group information included in the second service server (120) are the same, then in operation 418, the authentication server (130) can transmit the user information to the second service server (120).
[0071] In operation 420, when the authentication server (130) receives a token included in user information from the second service server (120), it can authenticate the user with the token in operation 422 to check whether the authentication was successful.
[0072] If user authentication is successful as a result of the verification in operation 422, the authentication server (130) in operation 424 can verify whether all conditions for providing a single sign-on are satisfied. At this time, the conditions for providing a single sign-on may include at least one of whether the country required by the service provided by the second service server is the same as the user's country, whether the user is included in the age restriction required by the service provided by the second service server, and whether there are terms and conditions to which the user must consent. Operation 424 may then operate as shown in the example of FIG. 5.
[0073] If all conditions for providing a single sign-on are satisfied as a result of the verification of operation 424, the authentication server (130) can transmit login completion to the second service server (120) in operation 426.
[0074] If the result of the verification of operation 424 does not satisfy the conditions for providing a single sign-on, the authentication server (130) in operation 428 may send a notification message to the user regarding the conditions for providing a single sign-on that are not satisfied.
[0075] Meanwhile, if the group information included in the user information and the group information including the second service server are not the same as the result of checking operation 416, or if the authentication server (130) does not receive the token included in the user information from the second service server (120) in operation 420, or if user authentication fails as a result of checking operation 422, the authentication server (130) may terminate the algorithm.
[0077] FIG. 5 is a flowchart illustrating the flow of checking the conditions for providing a single sign-on in an authentication server according to one embodiment.
[0078] Referring to FIG. 5, in operation 510, the authentication server (130) can determine whether additional authentication of the second service server (120) is required.
[0079] If, as a result of checking operation 510, additional authentication of the second service server (120) is not required, in operation 512, the authentication server (130) can check the user's nationality through user information and check whether the user is of a nationality that can access the second service server (120).
[0080] If, as a result of the verification of operation 512, the user is of a nationality that can access the second service server (120), then in operation 514, the authentication server (130) can verify the user's age through user information and determine whether the user is of an age that can access the second service server (120).
[0081] If, as a result of the verification of operation 514, the user is of an age to access the second service server (120), then in operation 516, the authentication server (130) can verify whether the user has agreed to all the necessary terms and conditions.
[0082] If, as a result of the verification of the 516th operation, the user has agreed to all the necessary terms and conditions, the authentication server (130) in the 518th operation can determine that all conditions for providing a single sign-on are satisfied.
[0083] If, as a result of checking operation 510, additional authentication of the second service server (120) is required, or as a result of checking operation 512, the user is not of a nationality that can access the second service server (120), or as a result of checking operation 514, the user is not of an age that can access the second service server (120), or as a result of checking operation 516, the user has not agreed to all the necessary terms and conditions, then in operation 520, the authentication server (130) may determine that the single sign-on provision condition is not satisfied.
[0085] FIG. 6 is a flowchart illustrating the flow of providing user information of the group to which the service server belongs from an authentication server according to one embodiment.
[0086] Referring to FIG. 6, when the authentication server (130) receives a request to look up an account capable of single sign-on in operation 610, in operation 612 the authentication server (130) can check the list of users capable of single sign-on through the database (140).
[0087] In operation 614, the authentication server (130) can check the group to which the service server that requested the account lookup belongs.
[0088] In operation 616, the authentication server (130) can check the user information of the group to which the service server that requested account lookup belongs through the database (140).
[0089] In operation 618, the authentication server (130) can check whether user information exists in the group to which the service server requesting account lookup belongs.
[0090] If, as a result of the verification of operation 618, user information exists in the group to which the service server requesting account lookup belongs, the authentication server (130) can provide user information to the service server requesting account lookup in operation 620.
[0091] If, as a result of the verification of operation 618, there is no user information in the group to which the service server requesting account lookup belongs, the authentication server (130) in operation 622 may not provide user information to the service server requesting account lookup and may notify that there is no user information.
[0093] Meanwhile, in the embodiments of FIGS. 1 to 6, each operation may be performed sequentially, but is not necessarily performed sequentially. For example, the order of each operation may be changed, and at least two operations may be performed in parallel.
[0095] FIG. 7 is a diagram illustrating an example of a group management menu provided to an administrator by an authentication server according to one embodiment.
[0096] Referring to FIG. 7, the authentication server (130) may provide a group management menu (700) to the administrator. At this time, the group management menu (700) may include a group area (710) that outputs information about the groups being managed and a service area (720) that outputs information related to the service server included in the group.
[0098] FIG. 8 is a diagram illustrating an example of a user's login history provided to a user by an authentication server according to one embodiment.
[0099] Referring to FIG. 8, the authentication server (130) may provide a user management menu (800) to the user. At this time, the user management menu (800) may include a menu area (810) and a related information area (820) that outputs selected information.
[0100] In FIG. 8, the authentication server (130) can check the information that the user has logged in to by group through the related information area (820) as the linked login history is selected in the menu area (810).
[0102] FIG. 9 is a diagram illustrating the schematic configuration of an authentication server according to one embodiment.
[0103] Referring to FIG. 9, the authentication server (130) may include a processor (910) and memory (920).
[0104] Memory (920) can store various data used by at least one component of the authentication server (130) (e.g., processor (910)). The data may include, for example, input data or output data for software and related commands. Memory (920) may include volatile memory or non-volatile memory. Programs may be stored in memory (910) as software and may include, for example, an operating system, middleware, or applications.
[0105] The processor (910) can control the operations of the authentication server (130) of FIGS. 1 to 6 by executing instructions stored in memory (920). For example, the processor (910) may correspond to a plurality of processors that divide and collectively perform a plurality of operations among the processors. Accordingly, the processor (910) can perform the operations of FIGS. 3 to 6.
[0106] The present disclosure can enhance security and eliminate unnecessary redirects by grouping service servers into groups that share a single sign-on and providing selective single sign-on.
[0108] According to one embodiment, a method for providing a single sign-on within the same service group may include: an operation of generating a random key when an authentication server receives login information including a user's account and password from a first service server; an operation of verifying group information including the first service server at the authentication server; an operation of generating a token for the user at the authentication server; an operation of storing user information, which is information about the user including the key, the token, and the group information including the first service server at the authentication server; and an operation of responding a cookie including the key to the first service server at the authentication server.
[0109] At this time, the operation of storing the user information, which is information about the user including the key, the token, and group information including the first service server, in the authentication server may classify and store the user information by group in the authentication server.
[0110] At this time, the operation of generating the token for the user in the authentication server may include an operation of generating information including at least one of the user's global unique identifier, the user's account, the user's name, and the user's age by encrypting it.
[0111] At this time, the user information includes group information including the key, the token, and the first service server, and may include at least one of the user's global unique identifier, the user's account, the user's name, information on the time when the user information is stored, and information on the time when the user information expires.
[0112] At this time, the method of providing a single sign-on further comprises: when the authentication server receives the cookie from the second service server, querying the login information using the key included in the cookie to verify the user information corresponding to the key; verifying the group information including the second service server at the authentication server; if the group information including the user information at the authentication server is identical to the group information including the second service server, transmitting the user information to the second service server; and when the authentication server receives the token included in the user information from the second service server, authenticating the user with the token.
[0113] At this time, the method of providing a single sign-on may further include the operation of transmitting a login completion to the second service server when the authentication server succeeds in authenticating the user with the token received from the second service server.
[0114] At this time, the operation of transmitting the login completion to the second service server may include: an operation of checking whether all conditions for providing the single sign-on are satisfied; and an operation of transmitting the login completion to the second service server if the authentication of the user is successful and all conditions for providing the single sign-on are satisfied.
[0115] At this time, the conditions for providing the single sign-on may include at least one of the following: whether the country required by the service provided by the second service server is the same as the country of the user; whether the user is included in the age restriction required by the service provided by the second service server; and whether there are terms and conditions to which consent must be obtained from the user.
[0116] At this time, the method of providing a single sign-on may further include, if the condition for providing the single sign-on is not satisfied, the operation of sending to the user through a guidance message the condition among the conditions for providing the single sign-on that is not satisfied.
[0117] At this time, the method of providing a single sign-on may further include the operation of providing the administrator of the authentication server with the function to add, modify, and remove service servers from a group on the authentication server.
[0118] At this time, the method of providing a single sign-on may further include an operation of providing, in accordance with the user's request, the group in which the single sign-on was performed, service information corresponding to the service server to which the user connected, and a login history from the authentication server.
[0119] According to one embodiment, an authentication server providing a single sign-on within the same service group includes one or more processors and a memory for storing instructions. When the instructions are executed by the one or more processors, the authentication server may perform the following operations: generating a random key when the authentication server receives login information including a user's account and password from a first service server; verifying group information including the first service server in the authentication server; generating a token for the user in the authentication server; storing user information, which is information about the user including the key, the token, and the group information including the first service server in the authentication server; and responding a cookie including the key to the first service server in the authentication server.
[0120] At this time, when the above commands are executed by the one or more processors, the authentication server may classify and store the user information by group when storing the user information including the key, the token, and the first service server.
[0121] At this time, when the above commands are executed by the one or more processors, the authentication server may generate information including at least one of the user's global unique identifier, the user's account, the user's name, and the user's age by encrypting it when generating a token at the authentication server.
[0122] At this time, the user information includes group information including the key, the token, and the first service server, and may include at least one of the user's global unique identifier, the user's account, the user's name, information on the time when the user information is stored, and information on the time when the user information expires.
[0123] At this time, when the above commands are executed by the one or more processors, the authentication server may further perform the following operations: when the authentication server receives the cookie from the second service server, query the login information using the key included in the cookie to verify the user information corresponding to the key; when the authentication server verifies the group information including the second service server; when the group information including the user information including the authentication server is identical to the group information including the second service server, transmit the user information to the second service server; and when the authentication server receives the token included in the user information from the second service server, authenticate the user using the token.
[0124] At this time, when the above commands are executed by the one or more processors, the authentication server may further perform the operation of transmitting a login completion to the second service server if the authentication server succeeds in authenticating the user with the token received from the second service server.
[0125] At this time, when the above commands are executed by the one or more processors, the authentication server may further perform the operation of checking whether all conditions for providing the single sign-on are satisfied; and, if the authentication of the user is successful and all conditions for providing the single sign-on are satisfied, the operation of transmitting the login completion to the second service server.
[0126] At this time, the conditions for providing the single sign-on may include at least one of the following: whether the country required by the service provided by the second service server is the same as the country of the user; whether the user is included in the age restriction required by the service provided by the second service server; and whether there are terms and conditions to which consent must be obtained from the user.
[0127] According to one embodiment, a computer-readable recording medium stores instructions, and when the instructions are executed by one or more processors, when an authentication server receives login information including a user's account and password from a first service server, the authentication server may perform the operation of generating a random key; the authentication server may perform the operation of verifying group information including the first service server; the authentication server may perform the operation of generating a token for the user; the authentication server may perform the operation of storing user information, which is information about the user including the key, the token, and the group information including the first service server; and the authentication server may perform the operation of responding to the first service server with a cookie including the key.
[0129] The various embodiments of this document and the terms used therein are not intended to limit the technical features described in this document to specific embodiments, and should be understood to include various modifications, equivalents, or substitutions of said embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of said items unless the relevant context clearly indicates otherwise. In this document, phrases such as "A or B," "at least one of A and B," "at least one of A or B," "A, B or C," "at least one of A, B and C," and "at least one of A, B, or C" may each include any one of the items listed together in the corresponding phrase, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used simply to distinguish said components from other said components and do not limit said components in any other aspect (e.g., importance or order). Where any (e.g., 1st) component is referred to as “coupled” or “connected” to another (e.g., 2nd) component, with or without the terms “functionally” or “communicationly,” it means that said any component may be connected to said other component directly (e.g., via a wire), wirelessly, or through a third component.
[0130] The term “module” as used in the various embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit, for example. A module may be a component formed integrally, or a minimum unit of said component or a part thereof that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).
[0131] Various embodiments of the present document may be implemented as software (e.g., program (140)) comprising one or more instructions stored in a storage medium (e.g., internal memory (136) or external memory (138)) readable by a machine (e.g., electronic device (101)). For example, a processor (e.g., processor (120)) of the machine (e.g., electronic device (101)) may call at least one of the one or more instructions stored in the storage medium and execute it. This enables the machine to be operated to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code that can be executed by an interpreter. The storage medium readable by the machine may be provided in the form of a non-transitory storage medium. Here, 'non-temporary' simply means that the storage medium is a tangible device and does not contain a signal (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently and cases where it is stored temporarily.
[0132] According to one embodiment, the method according to the various embodiments disclosed herein may be provided by being included in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or an application store (e.g., Play Store). TM It can be distributed online (e.g., downloaded or uploaded) through ) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily created on a device-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.
[0133] According to various embodiments, each component (e.g., module or program) of the components described above may include a singular or multiple entities, and some of the multiple entities may be separated and placed in other components. According to various embodiments, one or more of the components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Generally or additionally, multiple components (e.g., module or program) may be integrated into a single component. In this case, the integrated component may perform one or more functions of each of the multiple components in the same or similar manner as those performed by the corresponding component among the multiple components prior to integration. According to various embodiments, operations performed by the module, program, or other components may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.
[0134] Furthermore, the embodiments of the present invention disclosed in this specification and drawings are merely specific examples provided to facilitate the explanation of the technical content according to the embodiments of the present invention and to aid in understanding the embodiments of the present invention, and are not intended to limit the scope of the embodiments of the present invention. Accordingly, the scope of the various embodiments of the present invention should be interpreted to include all modifications or variations derived based on the technical concept of the various embodiments of the present invention, in addition to the embodiments disclosed herein.
Claims
Claim 1 A method for providing a single sign-on within the same service group, comprising: an operation to generate a random key when an authentication server receives login information including a user's account and password from a first service server; an operation to verify group information including the first service server at the authentication server; an operation to generate a token for the user at the authentication server; an operation to store user information, which is information about the user including the key, the token, and the group information including the first service server at the authentication server; and an operation to respond to the first service server with a cookie including the key at the authentication server. Claim 2 In claim 1, the operation of storing the user information, which is information about the user including the key, the token, and group information including the first service server, in the authentication server is a method of classifying and storing the user information by group in the authentication server. Claim 3 A method according to any one of claims 1 to 2, wherein the operation of generating the token for the user in the authentication server comprises the operation of generating information including at least one of the user's global unique identifier, the user's account, the user's name, and the user's age by encrypting it. Claim 4 A method according to any one of claims 1 to 3, wherein the user information comprises group information including the key, the token and the first service server, and at least one of the user's global unique identifier, the user's account, the user's name, information on the time when the user information is stored, and information on the time when the user information expires. Claim 5 A method according to any one of claims 1 to 4, further comprising: when the authentication server receives the cookie from the second service server, the operation of querying the login information using the key included in the cookie to verify the user information corresponding to the key; the operation of verifying the group information including the second service server at the authentication server; if the group information including the user information at the authentication server is identical to the group information including the second service server, the operation of transmitting the user information to the second service server; and when the authentication server receives the token included in the user information from the second service server, the operation of authenticating the user with the token. Claim 6 A method according to claim 5, further comprising the operation of transmitting a login completion to the second service server when the authentication server succeeds in authenticating the user with the token received from the second service server. Claim 7 A method according to any one of claims 5 to 6, wherein the operation of transmitting the login completion to the second service server comprises: an operation of checking whether all conditions for providing the single sign-on are satisfied; and, if the authentication of the user is successful and all conditions for providing the single sign-on are satisfied, an operation of transmitting the login completion to the second service server. Claim 8 A method in which, in any one of paragraphs 5 to 7, the condition for providing the single sign-on includes at least one of whether the country required by the service provided by the second service server is the same as the country of the user, whether the user is included in the age restriction required by the service provided by the second service server, and whether there are terms and conditions to which consent must be obtained from the user. Claim 9 A method further comprising, in any one of claims 1 to 8, an operation of transmitting to the user, through a guidance message, the condition not satisfied among the conditions for providing the single sign-on, if the condition for providing the single sign-on is not satisfied. Claim 10 A method according to any one of claims 1 to 9, further comprising the operation of providing the administrator of the authentication server with the function to add, modify, and remove service servers from a group on the authentication server. Claim 11 A method according to any one of claims 1 to 10, further comprising the operation of providing, at the authentication server, a group in which the single sign-on was performed according to the user's request, service information corresponding to the service server accessed by the user, and a login history. Claim 12 An authentication server providing a single sign-on within the same service group comprises one or more processors and a memory for storing instructions, wherein the instructions, when executed by the one or more processors, cause the authentication server to perform the following operations: generating a random key when the authentication server receives login information including a user account and password from a first service server; verifying group information including the first service server in the authentication server; generating a token for the user in the authentication server; storing user information, which is information about the user including the key, the token, and the group information including the first service server in the authentication server; and responding a cookie including the key in the authentication server to the first service server. Claim 13 In paragraph 12, the above commands, when executed by the one or more processors, cause the authentication server to classify and store the user information by group when storing the user information including the key, the token, and the first service server. Claim 14 An authentication server that, in any one of claims 12 to 13, wherein the commands, when executed by the one or more processors, cause the authentication server to generate information including at least one of a user's global unique identifier, the user's account, the user's name, and the user's age when generating a token at the authentication server. Claim 15 In any one of paragraphs 12 to 14, the user information comprises group information including the key, the token and the first service server, and an authentication server comprising at least one of the user's global unique identifier, the user's account, the user's name, information on the time when the user information is stored, and information on the time when the user information expires. Claim 16 An authentication server that, in any one of claims 12 to 15, wherein the commands, when executed by the one or more processors, cause the authentication server to perform the operation of: querying the login information with the key included in the cookie and verifying the user information corresponding to the key when the authentication server receives the cookie from the second service server; verifying the group information including the second service server in the authentication server; transmitting the user information to the second service server when the group information including the user information in the authentication server is identical to the group information including the second service server; and further performing the operation of authenticating the user with the token when the authentication server receives the token included in the user information from the second service server. Claim 17 In paragraph 16, the above commands, when executed by the one or more processors, cause the authentication server to further perform the operation of transmitting a login completion to the second service server when the authentication server succeeds in authenticating the user with the token received from the second service server. Claim 18 An authentication server that, in any one of claims 16 to 17, wherein the commands, when executed by the one or more processors, further perform the operation of verifying whether all conditions for providing the single sign-on are satisfied; and, if the authentication of the user is successful and all conditions for providing the single sign-on are satisfied, transmit the login completion to the second service server. Claim 19 An authentication server that, in any one of paragraphs 16 to 18, the condition for providing the single sign-on includes at least one of whether the country required by the service provided by the second service server is the same as the country of the user, whether the user is included in the age restriction required by the service provided by the second service server, and whether there are terms and conditions to which consent must be obtained from the user. Claim 20 A computer-readable recording medium, wherein the computer-readable recording medium stores instructions, and wherein the instructions, when executed by one or more processors, perform the following operations: generating a random key when an authentication server receives login information including a user account and password from a first service server; verifying group information including the first service server at the authentication server; generating a token for the user at the authentication server; storing user information, which is information about the user including the key, the token, and the group information including the first service server at the authentication server; and responding a cookie including the key at the authentication server to the first service server.