User management method, device, equipment and computer-readable storage medium
Identity authentication sharing between multiple business systems is achieved through the user management system (UM system), which solves the problem that users need to remember multiple accounts and passwords, improves user management efficiency and reduces management costs.
Patent Information
- Application Number
- CN201910461003.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2019-05-29
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2039-10-25
AI Technical Summary
In financial enterprises, employees need to remember the accounts and passwords of multiple business systems, resulting in inefficient user management, and system managers need to register and manage accounts of multiple business systems separately.
Identity authentication is performed through the user management system (UM system), and the user is bound to the token token. If not bound, the initial password verification is used. If bound, the secure password verification is used to realize identity authentication sharing between multiple business systems.
Users can use the same account and password to log in to various business systems, simplifying user account management, improving user management efficiency, and reducing management costs.
Smart Images

Figure CN110175439B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of financial technology (Fintech), and particularly to a user management method, device, equipment, and computer-readable storage medium. Background Art
[0002] With the development of computer technology, more and more technologies (big data, distributed, blockchain, artificial intelligence, etc.) are applied in the financial field. The traditional financial industry is gradually transforming into financial technology (Fintech). However, due to the security and real-time requirements of the financial industry, higher requirements are also imposed on technologies.
[0003] In many financial enterprises or institutions, there are often multiple business systems to provide corresponding business functions for each department respectively. However, the data of some business systems is related. Employees often need to use multiple business systems. Especially for managers, they usually need to view the data of multiple business systems. Correspondingly, they need to log in to multiple systems to view. At present, since identity authentication is carried out within each business system, different business systems need to use different accounts and passwords for logging in. In this way, users need to remember multiple accounts and passwords, which is rather inconvenient. At the same time, system managers also need to register accounts for employees in multiple business systems respectively and manage them, resulting in low user management efficiency. Summary of the Invention
[0004] The main purpose of the present invention is to provide a user management method, device, equipment, and computer-readable storage medium, aiming to avoid the inconvenience of users having to remember multiple accounts and passwords and improve user management efficiency at the same time.
[0005] To achieve the above object, the present invention provides a user management method, and the user management method includes:
[0006] When receiving an identity authentication request sent by a business system, obtaining the user account and input password of the user to be authenticated according to the identity authentication request;
[0007] Detecting whether the user to be authenticated has bound a token according to the user account;
[0008] If not, obtaining the initial password according to the user account, verifying whether the input password matches the initial password, and returning the first verification result to the business system, so that the business system determines whether to allow the user to be authenticated to log in according to the first verification result;
[0009] If so, obtain the security password according to the user account, verify whether the input password matches the security password, and return the second verification result to the service system, so that the service system determines whether to allow the user to be authenticated to log in according to the second verification result.
[0010] Optionally, after the step of returning the first verification result to the service system, the method further includes:
[0011] Generate a Token binding prompt message and send the Token binding prompt message to the service system;
[0012] When receiving a Token binding request returned by the service system based on the Token binding prompt message, obtain the Token serial number according to the Token binding request, and bind the Token serial number to the user account, so as to obtain the Token code sent by the corresponding Token, and the Token code is used as the security password for identity authentication.
[0013] Optionally, the security password further includes a PIN code, and the user management method further includes:
[0014] Generate a personal identification password PIN code setting prompt message and send the PIN code setting prompt message to the service system;
[0015] When receiving a PIN code setting request returned by the service system based on the PIN code setting prompt message, obtain the PIN code according to the PIN code setting request, and associate and store the PIN code with the user account.
[0016] Optionally, the user management method further includes:
[0017] When receiving an account allocation instruction, obtain the user information of the target allocated user according to the account allocation instruction;
[0018] Generate a corresponding user account and an initial password based on the user information of the target allocated user and a preset generation rule, and associate and store the user account, the initial password and the user information of the target allocated user.
[0019] Optionally, the user management method further includes:
[0020] When receiving a permission setting request, obtain permission setting information according to the permission setting request, where the permission setting information includes a target user account, target permission information and a target service system;
[0021] Update the user permission information of the target user account in the preset user permission list according to the target permission information, and synchronize the target user account and the updated user permission information to the target business system.
[0022] Optionally, the user management method further includes:
[0023] When receiving a list of departing users, obtain the corresponding departing user accounts according to the list of departing users;
[0024] Clear the user permission information corresponding to the departing user accounts in the preset user permission list, and synchronize the preset user permission list after the clearing process to each business system.
[0025] Optionally, the user management method further includes:
[0026] When receiving permission reporting information, extract the user accounts in the permission reporting information, denoted as reported user accounts;
[0027] Detect whether there are any of the departing user accounts among the reported user accounts;
[0028] If any exist, generate corresponding prompt information and send the prompt information to a preset management terminal, so that the management personnel can delete the user permission information corresponding to the existing departing user accounts in the corresponding business system according to the prompt information.
[0029] In addition, to achieve the above object, the present invention further provides a user management device, and the user management device includes:
[0030] A first acquisition module, configured to, when receiving an identity authentication request sent by a business system, obtain the user account and the input password of a user to be authenticated according to the identity authentication request;
[0031] A first detection module, configured to detect whether the user to be authenticated has bound a token according to the user account;
[0032] A first verification module, configured to, if not, obtain an initial password according to the user account, verify whether the input password matches the initial password, and return a first verification result to the business system, so that the business system determines whether to allow the user to be authenticated to log in according to the first verification result;
[0033] A second verification module, configured to, if so, obtain a security password according to the user account, verify whether the input password matches the security password, and return a second verification result to the business system, so that the business system determines whether to allow the user to be authenticated to log in according to the second verification result.
[0034] In addition, to achieve the above object, the present invention further provides a user management device, which includes: a memory, a processor, and a user management program stored on the memory and executable on the processor. When the user management program is executed by the processor, the steps of the user management method described above are implemented.
[0035] In addition, to achieve the above object, the present invention further provides a computer-readable storage medium, on which a user management program is stored. When the user management program is executed by a processor, the steps of the user management method described above are implemented.
[0036] The present invention provides a user management method, device, equipment, and computer-readable storage medium. When an identity authentication request sent by a service system is received, the user account and input password of the user to be authenticated are obtained according to the identity authentication request; it is detected whether the user to be authenticated has bound a Token according to the user account; if it is detected that the user to be authenticated has not bound a Token yet, the initial password is obtained according to the user account, it is verified whether the input password matches the initial password, and the first verification result is returned to the service system so that the service system can judge whether to allow the user to be authenticated to log in according to the first verification result; if it is detected that the user to be authenticated has bound a Token, the security password is obtained according to the user account, it is verified whether the input password matches the security password, and the second verification result is returned to the service system so that the service system can judge whether to allow the user to be authenticated to log in according to the second verification result. By the above method, the present invention can realize the sharing of identity authentication among multiple service systems, and users can use the same account and password to log in to each service system. Furthermore, the identity authentication requests of each service system are authenticated through the same user management system. Therefore, the present invention can avoid users from memorizing the accounts and passwords of multiple service systems. At the same time, compared with the prior art in which system administrators need to register and manage the accounts of multiple service systems for users respectively, the present invention simplifies the management of user accounts and can improve the user management efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] Figure 1 It is a schematic diagram of the device structure of the hardware operating environment related to the solution of the embodiment of the present invention;
[0038] Figure 2 It is a schematic flowchart of the first embodiment of the user management method of the present invention;
[0039] Figure 3 It is a schematic flowchart of the second embodiment of the user management method of the present invention;
[0040] Figure 4Schematic diagram of the functional modules of the first embodiment of the user management device of the present invention.
[0041] The implementation, functional features and advantages of the present invention will be further described with reference to the embodiments and the accompanying drawings. Detailed implementation manners
[0042] It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0043] Refer to Figure 1 , Figure 1 Schematic diagram of the device structure of the hardware operating environment involved in the embodiment solution of the present invention.
[0044] The user management device in the embodiment of the present invention can be a smart phone, or a PC (Personal Computer), a tablet computer, a portable computer and other terminal devices.
[0045] As Figure 1 shown, the user management device may include: a processor 1001, such as a CPU, a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. Among them, the communication bus 1002 is used to realize the connection and communication between these components. The user interface 1003 may include a display screen (Display), an input unit such as a keyboard (Keyboard), and optionally the user interface 1003 may also include a standard wired interface and a wireless interface. The network interface 1004 may optionally include a standard wired interface and a wireless interface (such as a Wi-Fi interface). The memory 1005 may be a high-speed RAM memory, or a stable memory (non-volatile memory), such as a disk memory. The memory 1005 may optionally also be a storage device independent of the aforementioned processor 1001.
[0046] Those skilled in the art can understand that Figure 1 the user management device structure shown in
[0047] As Figure 1 shown, the memory 1005, as a computer storage medium, may include an operating system, a network communication module, a user interface module, and a user management program.
[0048] In Figure 1In the terminal shown, the network interface 1004 is mainly used to connect to the background server and communicate with the background server for data; the user interface 1003 is mainly used to connect to the client and communicate with the client for data; and the processor 1001 can be used to call the user management program stored in the memory 1005 and execute each step of the following user management method.
[0049] Based on the above hardware structure, various embodiments of the user management method of the present invention are proposed.
[0050] The present invention provides a user management method.
[0051] Referring to Figure 2 , Figure 2 is a schematic flowchart of the first embodiment of the user management method of the present invention.
[0052] In this embodiment, the user management method includes:
[0053] Step S10, when receiving an identity authentication request sent by the service system, obtaining the user account and input password of the user to be authenticated according to the identity authentication request;
[0054] The user management method of this embodiment is implemented by a user management device. Among them, the user management device is equipped with a UM system (User Management), which is used for identity authentication and permission management. The UM system supports multiple login protocols to ensure that each service system can be accessed. Among them, by uniformly setting the interface of the UM system, multiple login protocols can be supported. The protocols supported by the UM system include HTTP (Hyper Text Transfer Protocol) authentication interface, LDAP (Lightweight Directory Access Protocol) login protocol, and SSO (Single Sign On) single sign-on. The HTTP authentication interface is suitable for direct docking with the background of JAVA application systems; the LDAP login protocol is suitable for externally purchased and open-source systems, and these systems usually can only use the LDAP login protocol; SSO single sign-on is suitable for application systems with a large number. Users only need to log in to one system on the browser and can use other systems on the browser without logging in. When each service system accesses, it can select the corresponding protocol for access according to the type of each service system.
[0055] In this embodiment, when each service system receives an identity authentication request triggered by a user during login, it forwards the identity authentication request to the UM system. At this time, when the UM system receives the identity authentication request sent by the service system, it obtains the user account and input password of the user to be authenticated according to the identity authentication request.
[0056] Step S20: Detect whether the user to be authenticated has bound a token according to the user account.
[0057] After obtaining the user account and the input password of the user to be authenticated, detect whether the user to be authenticated has bound a Token according to the user account. It should be noted that when the UM system creates a user account, it will generate a corresponding initial password (the specific process can refer to the following embodiments) and send it to each user. However, to ensure the security of the account, it will also require the user to receive a hard Token (a hardware device that can generate 6 - digit random numbers for identity verification) and bind the user account with the serial number of the hard Token (the specific binding process can refer to the following embodiments). The user can subsequently log in based on the dynamic Token code generated by the hard Token. In addition, it should be noted that the Token code can also be generated based on a soft Token. Among them, the soft Token is usually an algorithm integrated on the APP page to display 6 - digit random numbers for identity verification, bringing a better experience to users by utilizing the privacy and portability of mobile phones. Therefore, the token Token can be optionally the serial number displayed by the hard Token, or optionally the serial number generated by the UM system and sent to the APP page for display. This serial number can be optionally 6 - digit random numbers.
[0058] If not, execute step S31: Obtain the initial password according to the user account, verify whether the input password matches the initial password, and return the first verification result to the service system so that the service system can determine whether to allow the user to be authenticated to log in according to the first verification result.
[0059] If it is detected that the user to be authenticated has not bound a Token, it means that the user to be authenticated should currently log in using the initial password. At this time, obtain the initial password according to the user account, verify whether the input password matches the initial password, and return the first verification result to the service system so that the service system can determine whether to allow the user to be authenticated to log in according to the first verification result. Among them, if the input password matches the initial password, the verification is successful. When the service system receives the verification result of successful verification returned by the UM system, it can allow the user to be authenticated to log in; if the input password does not match the initial password, the verification fails. When the service system receives the verification result of failed verification returned by the UM system, it does not allow the user to be authenticated to log in and prompts the user that the account or password is incorrect.
[0060] If so, execute step S32: Obtain the security password according to the user account, verify whether the input password matches the security password, and return the second verification result to the service system, so that the service system determines whether to allow the user to be authenticated to log in according to the second verification result.
[0061] If it is detected that the user to be authenticated has bound a Token, it means that the user to be authenticated should currently log in using the security password. At this time, obtain the security password according to the user account, verify whether the input password matches the security password, and return the second verification result to the service system, so that the service system determines whether to allow the user to be authenticated to log in according to the second verification result. Among them, the security password can be a dynamically generated Token code, or a password composed of a dynamically generated Token code and a PIN (Personal Identification Number) code set by the user. If the input password matches the security password, the verification is successful. When the service system receives the verification result of successful verification returned by the UM system, it can allow the user to be authenticated to log in; if the input password does not match the security password, the verification fails. When the service system receives the verification result of failed verification returned by the UM system, it does not allow the user to be authenticated to log in and prompts that the user account or password is incorrect.
[0062] In the user management system of financial institutions such as banks, when receiving the identity authentication requests sent by each service system, the present invention first performs identity authentication according to the above operation process, realizes the sharing of identity authentication among multiple service systems, avoids users from memorizing the accounts and passwords of multiple service systems. At the same time, compared with the system administrator needing to register and manage the accounts of multiple service systems for users respectively, the present invention simplifies the management of user accounts, can improve the user management efficiency of financial institutions such as banks, and reduces the management costs of financial institutions such as banks.
[0063] An embodiment of the present invention provides a user management method. When receiving an identity authentication request sent by a service system, the user account and input password of the user to be authenticated are obtained according to the identity authentication request; it is detected whether the user to be authenticated has bound a Token according to the user account; if it is detected that the user to be authenticated has not bound a Token yet, the initial password is obtained according to the user account, it is verified whether the input password matches the initial password, and the first verification result is returned to the service system, so that the service system determines whether to allow the user to be authenticated to log in according to the first verification result; if it is detected that the user to be authenticated has bound a Token, the security password is obtained according to the user account, it is verified whether the input password matches the security password, and the second verification result is returned to the service system, so that the service system determines whether to allow the user to be authenticated to log in according to the second verification result. By the above method, the embodiment of the present invention can realize the sharing of identity authentication between multiple service systems, and users can use the same account and password to log in to each service system. Furthermore, the identity authentication requests of each service system are authenticated through the same user management system. Therefore, the embodiment of the present invention can avoid users from memorizing the accounts and passwords of multiple service systems. At the same time, compared with the prior art in which the system administrator needs to register and manage the accounts of multiple service systems for users respectively, the embodiment of the present invention simplifies the management of user accounts and can improve the user management efficiency.
[0064] Further, after the above step S31, the user management method further includes:
[0065] Step A, generating a Token binding prompt message and sending the Token binding prompt message to the service system;
[0066] In this embodiment, after detecting that the user to be authenticated has not bound a Token yet, to ensure the security of the user account, the user needs to be reminded to bind the Token in time. Specifically, the UM system can generate a Token binding prompt message and send the Token binding prompt message to the service system. At this time, the service system can display a corresponding prompt window on the user side to display the Token binding prompt message to remind the user to bind the Token. Correspondingly, the user can receive a hard Token and fill in the serial number of the received hard Token on the corresponding binding interface to trigger a Token binding request. When the service system receives the Token binding request, it forwards the Token binding request to the UM system.
[0067] Step B: When receiving a Token binding request returned by the business system based on the Token binding prompt information, obtain the Token serial number according to the Token binding request, and bind the Token serial number to the user account, so as to obtain the Token code sent by the corresponding Token. The Token code is used as a security password for identity authentication.
[0068] When the UM system receives a Token binding request returned by the business system based on the Token binding prompt information, obtain the Token serial number according to the Token binding request, and bind the Token serial number to the user account, so as to obtain the Token code sent by the corresponding Token. Herein, the Token code is used as a security password for identity authentication. According to the type of the security password, the user can directly use the Token code as the password for login, or use the Token code and the PIN code set by the user as the security password for login.
[0069] It should be noted that in a specific embodiment, the above Step A can be executed by the business system. When the business system receives a Token binding request, it forwards the Token binding request to the UM system. Then, the UM system executes the steps of obtaining the Token serial number according to the Token binding request and binding the Token serial number to the user account.
[0070] In this embodiment, to ensure the security of the user account, login can be performed through the Token code. Therefore, in this embodiment, after detecting that the user to be authenticated has not bound the Token, the user is reminded to bind the Token in time. Then, the Token serial number in the Token binding request is bound to the user account, so as to obtain the Token code sent by the corresponding Token, and then the Token code is used for subsequent identity authentication. Through the above method, the security of the user account can be ensured.
[0071] To further ensure the security of the user account, in addition to the Token code, the security password can also include the PIN code. After the above Step B, the user management method further includes:
[0072] Step C: Generate a personal identification password PIN code setting prompt information, and send the PIN code setting prompt information to the business system;
[0073] In this embodiment, to further ensure the security of the user account, a two-factor authentication method can be adopted. That is, the user pre-sets a PIN code in advance, and then uses the Token code and the PIN code set by the user as the confidential password for verification. Through this two-factor authentication method, it can be avoided that the account is logged in by others when the hard Token and the user account are stolen, thereby further ensuring the security of the user account.
[0074] In this embodiment, after the user binds the Token, the user can be further prompted to set the PIN code. Specifically, the UM generates a personal identification password PIN code setting prompt message and sends the PIN code setting prompt message to the service system. At this time, the service system can display a corresponding prompt window on the user side to display the PIN code setting prompt message to remind the user to set the PIN code. Correspondingly, the user can set the PIN code on the corresponding PIN code setting interface to trigger a PIN code setting request. When the service system receives the PIN code setting request, it forwards the PIN code setting request to the UM system.
[0075] Step D, when receiving the PIN code setting request returned by the service system based on the PIN code setting prompt message, obtain the PIN code according to the PIN code setting request, and associate and store the PIN code with the user account.
[0076] When the UM system receives the PIN code setting request returned by the service system based on the PIN code setting prompt message, it obtains the PIN code according to the PIN code setting request, and associates and stores the PIN code with the user account for use in forming a security password with the received Token code for subsequent identity authentication.
[0077] It should be noted that in a specific embodiment, the above step C can be executed by the service system. When the service system receives the PIN code setting request, it forwards the PIN code setting request to the UM system. Then, the UM system executes the steps: obtaining the PIN code according to the PIN code setting request, and associating and storing the PIN code with the user account.
[0078] In this embodiment, to further ensure the security of the user account, a password can be formed by the Token code and the PIN code set by the user for login. Therefore, in this embodiment, after detecting that the user to be authenticated binds the Token, the user can be reminded to set the PIN code in time. Then, the PIN code in the PIN code setting request is associated and stored with the user account for use in forming a security password with the received Token code for subsequent identity authentication. Through the above method, a two-factor authentication method is implemented, which can further ensure the security of the user account.
[0079] Further, in the above embodiment, before step S10, the user management method further includes:
[0080] Step E, when receiving an account allocation instruction, obtaining user information of a target allocated user according to the account allocation instruction;
[0081] In this embodiment, when new employees are hired, the UM system can automatically allocate user accounts and initial passwords for them. Specifically, the management staff can select the account allocation option in the UM system, and then trigger the account allocation instruction after entering the user information of the new employees in the corresponding configuration interface. At this time, when the UM system receives the account allocation instruction, it obtains the user information of the target allocated user according to the account allocation instruction. Among them, the user information may include but is not limited to user name, ID number, gender, age, user's affiliated department, etc.
[0082] Step F, generating a corresponding user account and initial password based on the user information of the target allocated user and a preset generation rule, and associatively storing the user account, the initial password, and the user information of the target allocated user.
[0083] Then, a corresponding user account and initial password are generated based on the user information of the target allocated user and a preset generation rule. The preset generation rule can be set according to the actual situation. For example, the user name can be the pinyin of the user's name and the current employee number, and the initial password can be the last 6 digits of the user's ID number; or the user name can be the user's name, and the initial password can be the current employee number. Here is only an example and is not a specific limitation of the present invention. The user account and initial password can be used in each business system.
[0084] After generating the user account and initial password, the user account, the initial password, and the user information of the target allocated user are associatively stored to facilitate subsequent identity authentication and user query, etc.
[0085] In this embodiment, the user account and initial password can be uniformly set through the UM system. The user account and initial password can be used in each business system, without each business system setting the user account and initial password for the user separately, which can improve the user management efficiency. At the same time, it can also prevent users from memorizing multiple sets of accounts and passwords.
[0086] Since the existing user permission management is also carried out within each business system and it is impossible to achieve unified setting and management of permissions, based on the above embodiments, a second embodiment of the user management method of the present invention is proposed. Specifically, referring to Figure 3 , in this embodiment, the user management method further includes:
[0087] Step S40, when receiving a permission setting request, obtain permission setting information according to the permission setting request, where the permission setting information includes a target user account, target permission information, and a target business system;
[0088] In this embodiment, an employee can apply for user permissions through the ITSM system (IT Service Management, IT service management system), that is, the event approval system. When the approval is passed, the ITSM system will generate a corresponding permission setting request; alternatively, a manager can set the user permissions of a user through the permission editing tool of the ITSM system, thereby triggering a permission setting request. After that, the ITSM system will send the permission setting request to the UM system. At this time, when the UM system receives the permission setting request, it can obtain the permission setting information according to the permission setting request. Among them, the permission setting information includes a target user account, target permission information, and a target business system. Permission setting can include operations such as changing, deleting, and adding permissions, and involves changes in user role relationships, role permission relationships, role maintenance, permission maintenance, etc.
[0089] Step S50, update the user permission information of the target user account in the preset user permission list according to the target permission information, and synchronize the target user account and the updated user permission information to the target business system.
[0090] After obtaining the permission setting information, update the user permission information of the target user account in the preset user permission list according to the target permission information, and synchronize the target user account and the updated user permission information to the target business system, so that the target business system can synchronously update the corresponding user permission information.
[0091] In the above manner, this embodiment can realize the unified management of user permissions of each business system through the UM system. At the same time, by synchronizing the updated user permission information to the business system, it can also ensure that users can use the business system even when the UM system fails, thereby ensuring the high availability of the business system.
[0092] Furthermore, based on the above second embodiment, a third embodiment of the user management method of the present invention is proposed.
[0093] In this embodiment, after the above step S50, the user management method further includes:
[0094] Step G, when receiving a list of departing users, obtain the corresponding departing user accounts according to the list of departing users;
[0095] In this embodiment, when a user leaves the company, the relevant department can compile a list of departing users and upload it to the UM system so that the UM system can delete the permissions of the departing users. Specifically, when the UM system receives the list of departing users, it can obtain the corresponding departing user accounts according to the list of departing users. Among them, the list of departing users includes at least the name or account of the departing user. If the list of departing users only includes the name of the departing user, the corresponding departing user account can be found according to the name of the user; if the list of departing users only includes the account of the departing user, the account of the departing user in the list of departing users can be directly extracted.
[0096] Step H, clear the user permission information corresponding to the departing user account in the preset user permission list, and synchronize the preset user permission list after the clearing process to each business system.
[0097] Then, clear the user permission information corresponding to the departing user account in the preset user permission list, and synchronize the preset user permission list after the clearing process to each business system, so that each business system can synchronously update the corresponding user permission information. It should be noted that in this embodiment, it is for the business systems that can access the UM system for permission management.
[0098] In the above manner, in this embodiment, the user permissions of departing users can be intelligently and uniformly cleared automatically without the need for each business system to clear them separately, which can improve the user management efficiency. At the same time, it can avoid the situation of obtaining system data and causing internal data leakage after a user leaves the company, and can ensure the security of system data.
[0099] Further, based on the above embodiments, a fourth embodiment of the user management method of the present invention is proposed.
[0100] In this embodiment, the user management method further includes:
[0101] Step I, when receiving the permission reporting information, extract the user account in the permission reporting information and record it as the reported user account;
[0102] In this embodiment, since some financial enterprises or institutions often outsource some systems, such as open-source systems, and cannot transform these outsourced and open-source systems, these business systems cannot be connected to the UM system for permission management. Therefore, it cannot be guaranteed that there are no illegal permissions in these business systems. For example, the permissions still exist even after a user leaves the company or changes positions. To address this, in this embodiment, by having these systems report permissions, the user permission information in these business systems can be obtained, and then illegal permissions can be detected through detection, such as the permissions of a departed user still existing. Specifically, when receiving a list of departed users, the business systems that cannot be connected to the UM system for permission management can also be notified to report the user permission information within their systems. When the UM system receives the permission report information, it extracts the user accounts in the permission report information and records them as the reported user accounts.
[0103] Step J, detect whether the departed user account exists in the reported user accounts;
[0104] If it exists, execute Step K: generate a corresponding prompt message and send the prompt message to a preset management terminal so that the management personnel can delete the user permission information corresponding to the existing departed user account in the corresponding business system according to the prompt message.
[0105] Then, detect whether the departed user account exists in the reported user accounts. If the departed user account exists in the reported user accounts, it indicates that there are illegal permissions. At this time, a corresponding prompt message is generated and sent to the preset management terminal so that the management personnel can delete the user permission information corresponding to the existing departed user account in the corresponding business system according to the prompt message, so as to avoid the situation where a user still has permissions after leaving the company and can obtain system data, resulting in internal data leakage, and the security of the system data can be guaranteed.
[0106] The present invention also provides a user management device.
[0107] Referring to Figure 4 , Figure 4 which is a schematic diagram of the functional modules of the first embodiment of the user management device of the present invention.
[0108] As Figure 4 shown, the user management device includes:
[0109] A first acquisition module 10, configured to obtain the user account and input password of the user to be authenticated according to the identity authentication request when receiving the identity authentication request sent by the business system;
[0110] A first detection module 20, configured to detect whether the user to be authenticated has been bound with a token Token according to the user account;
[0111] The first verification module 30, if the answer is no, is configured to obtain an initial password according to the user account, verify whether the input password matches the initial password, and return a first verification result to the service system, so that the service system determines whether to allow the user to be authenticated to log in according to the first verification result;
[0112] The second verification module 40, if the answer is yes, is configured to obtain a security password according to the user account, verify whether the input password matches the security password, and return a second verification result to the service system, so that the service system determines whether to allow the user to be authenticated to log in according to the second verification result.
[0113] Further, the user management device further includes:
[0114] The first sending module is configured to generate Token binding prompt information and send the Token binding prompt information to the service system;
[0115] The serial number binding module is configured to, when receiving a Token binding request returned by the service system based on the Token binding prompt information, obtain a Token serial number according to the Token binding request, and bind the Token serial number to the user account, so as to obtain a Token code sent by the corresponding Token, and the Token code is used as a security password for identity authentication.
[0116] Further, the security password further includes a PIN code, and the user management device further includes:
[0117] The second sending module is configured to generate personal identification password PIN code setting prompt information and send the PIN code setting prompt information to the service system;
[0118] The first associated storage module is configured to, when receiving a PIN code setting request returned by the service system based on the PIN code setting prompt information, obtain a PIN code according to the PIN code setting request, and associate and store the PIN code with the user account.
[0119] Further, the user management device further includes:
[0120] The second obtaining module is configured to obtain user information of a target assigned user according to the account assignment instruction when receiving the account assignment instruction;
[0121] The second associated storage module is configured to generate a corresponding user account and an initial password based on the user information of the target assigned user and a preset generation rule, and associate and store the user account, the initial password and the user information of the target assigned user.
[0122] Further, the user management device further includes:
[0123] A third acquisition module, configured to, when receiving a permission setting request, acquire permission setting information according to the permission setting request, where the permission setting information includes a target user account, target permission information, and a target business system;
[0124] A permission update module, configured to update the user permission information of the target user account in a preset user permission list according to the target permission information, and synchronize the target user account and the updated user permission information to the target business system.
[0125] Further, the user management device further includes:
[0126] A fourth acquisition module, configured to, when receiving a list of departing users, acquire corresponding departing user accounts according to the list of departing users;
[0127] A permission clearing module, configured to perform a clearing process on the user permission information corresponding to the departing user accounts in the preset user permission list, and synchronize the preset user permission list after the clearing process to each business system.
[0128] Further, the user management device further includes:
[0129] An account extraction module, configured to, when receiving permission reporting information, extract the user account in the permission reporting information, denoted as the reported user account;
[0130] A second detection module, configured to detect whether the departing user accounts exist in the reported user account;
[0131] A third sending module, configured to, if so, generate corresponding prompt information, and send the prompt information to a preset management terminal, so that the management personnel can delete the user permission information corresponding to the existing departing user accounts in the corresponding business system according to the prompt information.
[0132] Wherein, the function implementation of each module in the above user management device corresponds to each step in the above embodiments of the user management method, and its function and implementation process will not be elaborated herein one by one.
[0133] The present invention further provides a computer-readable storage medium, on which a user management program is stored. When the user management program is executed by a processor, the steps of the user management method described in any one of the above embodiments are implemented.
[0134] The specific embodiments of the computer-readable storage medium of the present invention are basically the same as those of the above embodiments of the user management method, and will not be elaborated herein.
[0135] It should be noted that, in this document, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, such that a process, method, article or system comprising a series of elements includes not only those elements but also other elements not expressly listed, or further includes elements inherent to such process, method, article or system. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the process, method, article or system comprising such element.
[0136] The serial numbers of the above-described embodiments of the present invention are for description only and do not represent the superiority or inferiority of the embodiments.
[0137] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described embodiment methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such understanding, the technical solution of the present invention, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. The computer software product is stored in a storage medium as described above (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in various embodiments of the present invention.
[0138] The above are only the preferred embodiments of the present invention and do not limit the patent scope of the present invention. Any equivalent structure or equivalent process transformation made by using the content of the specification and drawings of the present invention, or directly or indirectly applied in other related technical fields, is equally included in the patent protection scope of the present invention.
Claims
1. A user management method, characterized in that, Applied to a user management system, the user management method includes: When receiving an identity authentication request sent by a business system, obtaining the user account and input password of the user to be authenticated according to the identity authentication request; Detecting whether the user to be authenticated has bound a Token according to the user account; whether the user to be authenticated has bound a Token indicates the login password type adopted by the user to be authenticated, and the login password type includes an initial password and a security password; If not, obtaining the initial password according to the user account, verifying whether the input password matches the initial password, and returning the first verification result to the business system, so that the business system determines whether to allow the user to be authenticated to log in according to the first verification result; Generating a Token binding prompt message and sending the Token binding prompt message to the business system; When receiving a Token binding request returned by the business system based on the Token binding prompt message, obtaining the hard Token serial number according to the Token binding request and binding the hard Token serial number with the user account; obtaining the PIN code set by the user according to the PIN code setting prompt message of the personal identification password, and associatively storing the PIN code with the user account; wherein, the hard Token corresponding to the hard Token serial number is used to generate a dynamic Token code, and the dynamic Token code and the PIN code are used as security passwords for identity authentication; If so, obtaining the corresponding PIN code according to the user account, using the hard Token corresponding to the hard Token serial number to generate a random number with a set number of digits as the dynamic Token code, and generating a security password according to the PIN code and the dynamic Token code; verifying whether the input password matches the security password, and returning the second verification result to the business system, so that the business system determines whether to allow the user to be authenticated to log in according to the second verification result.
2. The user management method according to claim 1, characterized in that The obtaining the PIN code set by the user according to the PIN code setting prompt message of the personal identification password includes: Generating a PIN code setting prompt message of the personal identification password and sending the PIN code setting prompt message to the business system; When receiving a PIN code setting request returned by the business system based on the PIN code setting prompt message, obtaining the PIN code according to the PIN code setting request.
3. The user management method according to claim 1, characterized in that The user management method further includes: When receiving an account allocation instruction, obtaining the user information of the target allocated user according to the account allocation instruction; Generating a corresponding user account and initial password based on the user information of the target allocated user and a preset generation rule, and associatively storing the user account, the initial password and the user information of the target allocated user.
4. The user management method according to any one of claims 1-3, characterized in that, The user management method further includes: When receiving a permission setting request, obtaining permission setting information according to the permission setting request, and the permission setting information includes a target user account, target permission information and a target business system; Update the user permission information of the target user account in the preset user permission list according to the target permission information, and synchronize the target user account and the updated user permission information to the target business system.
5. The user management method according to claim 4, characterized in that The user management method further includes: When receiving the list of departing users, obtain the corresponding departing user accounts according to the list of departing users; Clear the user permission information corresponding to the departing user accounts in the preset user permission list, and synchronize the preset user permission list after the clearing process to each business system.
6. The user management method according to claim 5, wherein The user management method further includes: When receiving the permission reporting information, extract the user accounts in the permission reporting information, denoted as the reported user accounts; Detect whether the departing user accounts exist in the reported user accounts; If so, generate a corresponding prompt message and send the prompt message to the preset management terminal, so that the management personnel can delete the user permission information corresponding to the existing departing user accounts in the corresponding business system according to the prompt message.
7. A user management device, characterized in that, For a user management system, the user management device includes: A first acquisition module, configured to obtain the user account and the input password of the user to be authenticated according to the identity authentication request when receiving the identity authentication request sent by the business system; A first detection module, configured to detect whether the user to be authenticated has bound a token Token according to the user account; whether the user to be authenticated has bound a token Token indicates the login password type adopted by the user to be authenticated, and the login password type includes an initial password and a security password; A first verification module, configured to, if not, obtain the initial password according to the user account, verify whether the input password matches the initial password, and return the first verification result to the business system, so that the business system can determine whether to allow the user to be authenticated to log in according to the first verification result; A first sending module, configured to generate a Token binding prompt message and send the Token binding prompt message to the business system; A serial number binding module, configured to, when receiving the Token binding request returned by the business system based on the Token binding prompt message, obtain the hard Token serial number according to the Token binding request, and bind the hard Token serial number to the user account; obtain the PIN code set by the user according to the prompt message set by the personal identification password PIN code, and store the PIN code in association with the user account; wherein, the hard Token corresponding to the hard Token serial number is used to generate a dynamic Token code, and the dynamic Token code and the PIN code are used as security passwords for identity authentication; The second verification module is used to, if so, obtain the corresponding PIN code according to the user account, generate a random number with a set number of digits as the dynamic Token code using the hard Token corresponding to the hard Token serial number, and generate a security password according to the PIN code and the dynamic Token code; verify whether the input password matches the security password, and return the second verification result to the service system, so that the service system determines whether to allow the user to be authenticated to log in according to the second verification result.
8. A user management device, characterized in that, The user management device includes: a memory, a processor, and a user management program stored on the memory and executable on the processor. When the user management program is executed by the processor, it implements the steps of the user management method according to any one of claims 1 to 7.
9. A computer-readable storage medium, characterized in that, A user management program is stored on the computer-readable storage medium. When the user management program is executed by the processor, it implements the steps of the user management method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Single sign-on server, single sign-on method and computer readable storage medium
CN108200050A