A method, device, equipment and storage medium for simulating account login
By using the target identity conversion information in the demo account login and adding it to the request, the problem of account security risks and low login efficiency in the prior art is solved, and a more secure and efficient demo account login is achieved.
Patent Information
- Application Number
- CN202011137356.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-10-22
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2040-10-22
AI Technical Summary
In the prior art, the login information of the simulated login account is directly obtained when logging in to the demo account, resulting in high account security risks and low login efficiency.
By receiving the target request sent by the terminal, if the target identity conversion information is included, the login status identification of the first account is obtained and added to the request, so that the terminal can log in to the first website through the identity information of the first account based on the login status identification, avoiding obtaining the login password.
It realizes that logging into the first website through the identity information of the first account without knowing the first account login password, which improves the security of the account and improves the efficiency of descriptive account login.
Smart Images

Figure CN112214743B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a method, device, equipment and storage medium for simulating account login. Background Art
[0002] In some scenarios, a user needs to simulate another user to log in to the corresponding website so that the above-mentioned user can complete some operations through the website as another user. However, in related technologies, one user often directly asks for the account login information such as the login account and login password of another user, and then one account uses the account login information of another account to log in to the above-mentioned website. However, in this process, the account login information of the above-mentioned other user is known by the above-mentioned user. There is a great security risk in the account of the above-mentioned other user. Therefore, how to reduce the account security risk caused by simulated account login is an issue that needs to be considered. Summary of the invention
[0003] The embodiments of the present application provide a method, apparatus, device and storage medium for simulating account login, which are used to improve the security of the account.
[0004] In a first aspect of the present application, a method for logging into a simulated account is provided, comprising:
[0005] receiving a target request for logging into a first website sent by a terminal;
[0006] If it is determined that the target request includes target identity conversion information, obtaining a login state identifier of the first account based on the target identity conversion information; wherein the target identity conversion information includes identity information of the first account and identity information of the second account, and the target identity conversion information is used to indicate that the second account requests to log in to the first website through the identity information of the first account, and the login state identifier is determined based on the identity information of the first account;
[0007] Adding the login status identifier to the target request;
[0008] A target request for adding the login status identifier is sent to the first website, so that the terminal logs in to the first website through the identity information of the first account based on the login status identifier.
[0009] In a possible implementation manner, after receiving the target request for logging into the first website sent by the terminal, the method further includes:
[0010] If it is determined that the target request does not include the target identity conversion information, and the target request does not include the login status identifier of the first account, sending second prompt information to the terminal, so that the terminal loads the login page of the first website based on the second prompt information;
[0011] If it is determined that the target request does not include target identity conversion information, and the target request includes the login status identifier of the first account, the target request is sent to the first website, so that the terminal logs in to the first website through the identity information of the first account based on the login status identifier of the first account.
[0012] In a second aspect of the present application, a method for logging into a simulated account is provided, comprising:
[0013] A login jump request sent by a receiving terminal is carried by the identity information of the first account, and the login jump request is triggered by a simulated login instruction of the second account;
[0014] Determine identity information of a second account that triggers the login jump request;
[0015] generating identity conversion information including the identity information of the first account and the identity information of the second account, wherein the identity conversion information is used to indicate that the second account requests to log in to the first website using the identity information of the first account;
[0016] Returning login instruction information including the identity conversion information to the terminal, so that the terminal sends a target request including the identity conversion information, wherein the target request is used to enable the terminal to log in to the first website through the identity information of the first account.
[0017] In a possible implementation, the method further includes: storing the identity conversion information in a preset identity conversion information library, so that after the service management device receives the target request, it determines whether to send a first prompt information to the terminal based on the identity conversion information, and the first prompt information is used to indicate that the target request is abnormal.
[0018] In a third aspect of the present application, a method for logging into a simulated account is provided, comprising:
[0019] In response to the simulated login instruction of the second account, a login jump request is sent to a target website, wherein the login jump request carries the identity information of the first account, and the target website is a first website registered by the first account or a second website other than the first website;
[0020] Receiving login indication information returned by the target website based on the login jump request;
[0021] Determine the identity conversion information included in the login instruction information as the target identity conversion information; the identity conversion information includes the identity information of the first account and the identity information of the second account, and the identity conversion information is used to indicate that the second account requests to log in to the first website with the identity information of the first account;
[0022] A target request including the target identity conversion information is sent to a service management device, so as to log in to the first website through the identity information of the first account based on the target identity conversion information.
[0023] In a possible implementation, the simulated login instruction is triggered by a target jump object corresponding to the first account, and the target jump object indicates a request to log in to the first website through identity information of the first account.
[0024] In a fourth aspect of the present application, a device for simulating account login is provided, comprising:
[0025] A request receiving unit, configured to receive a target request sent by a terminal for logging into a first website;
[0026] a first processing unit, configured to obtain a login state identifier of the first account based on the target identity conversion information if it is determined that the target request includes target identity conversion information; wherein the target identity conversion information includes the identity information of the first account and the identity information of the second account, and the target identity conversion information is used to indicate that the second account requests to log in to the first website through the identity information of the first account, and the login state identifier is determined based on the identity information of the first account;
[0027] A second processing unit, configured to add the login status identifier to the target request;
[0028] The request sending unit is used to send a target request for adding the login status identifier to the first website, so that the terminal logs in to the first website through the identity information of the first account based on the login status identifier.
[0029] In a possible implementation manner, the first processing unit is specifically configured to:
[0030] Obtain the mapping relationship between the preset identity conversion information and the login state identifier;
[0031] If the mapping relationship records a login state identifier corresponding to the target identity conversion information, obtaining the login state identifier;
[0032] If the login state identifier corresponding to the target identity conversion information is not recorded in the mapping relationship, a corresponding login state identifier is generated based on the identity information of the first account contained in the target identity conversion information, and a mapping relationship between the target identity conversion information and the generated login state identifier is created and saved.
[0033] In a possible implementation manner, the first processing unit is further configured to:
[0034] After determining that the target request includes target identity conversion information, and before obtaining the login status identifier of the first account based on the target identity conversion information, accessing a preset identity conversion information library through a target interface;
[0035] If the identity conversion information library does not store identity conversion information matching the target identity conversion information, a first prompt information is sent to the terminal, where the first prompt information is used to indicate that the target request is abnormal; the identity conversion information matching the target identity conversion information is used to indicate that the second account requests to log in to the first website with the identity information of the first account.
[0036] In a possible implementation manner, the request receiving unit is further configured to:
[0037] If it is determined that the target request does not include the target identity conversion information, and the target request does not include the login status identifier of the first account, sending second prompt information to the terminal, so that the terminal loads the login page of the first website based on the second prompt information;
[0038] If it is determined that the target request does not include target identity conversion information, and the target request includes the login status identifier of the first account, the target request is sent to the first website, so that the terminal logs in to the first website through the identity information of the first account based on the login status identifier of the first account.
[0039] In a fifth aspect of the present application, a device for simulating account login is provided, comprising:
[0040] A request receiving unit, configured to receive a login jump request sent by a terminal, wherein the login jump request carries identity information of a first account and is triggered by a simulated login instruction of a second account;
[0041] A first processing unit, configured to determine identity information of a second account that triggers the login redirect request;
[0042] a second processing unit, configured to generate identity conversion information including the identity information of the first account and the identity information of the second account, wherein the identity conversion information is used to indicate that the second account requests to log in to the first website using the identity information of the first account;
[0043] The information sending unit is used to return login instruction information containing the identity conversion information to the terminal, so that the terminal sends a target request containing the identity conversion information, and the target request is used to enable the terminal to log in to the first website through the identity information of the first account.
[0044] In a possible implementation manner, the second processing unit is further configured to:
[0045] The identity conversion information is stored in a preset identity conversion information library, so that after receiving the target request, the service management device determines whether to send first prompt information to the terminal according to the identity conversion information, wherein the first prompt information is used to indicate that the target request is abnormal.
[0046] In a possible implementation, the device is applied to an account registered on a second website other than the first website, the login jump request is sent after the terminal logs in to the second website through the second account, and the login indication information is used to enable the terminal to open the first website and send the target request after opening the first website.
[0047] In a sixth aspect of the present application, a device for simulating account login is provided, comprising:
[0048] a request sending unit, configured to respond to the simulated login instruction of the second account and send a login jump request to a target website, wherein the login jump request carries the identity information of the first account, and the target website is a first website registered by the first account or a second website other than the first website;
[0049] An information receiving unit, configured to receive login indication information returned by the target website based on the login jump request;
[0050] A first processing unit is configured to determine the identity conversion information included in the login instruction information as target identity conversion information; the identity conversion information includes the identity information of the first account and the identity information of the second account, and the identity conversion information is used to indicate that the second account requests to log in to the first website with the identity information of the first account;
[0051] The second processing unit is configured to send a target request including the target identity conversion information to a service management device, so as to log in to the first website through the identity information of the first account based on the target identity conversion information.
[0052] In a possible implementation, the target website is the second website, and the simulated login instruction is triggered after the terminal logs in to the second website through the second account; and the information receiving unit is further used to:
[0053] After receiving the login indication information returned by the target website based on the login jump request, and before sending the target request containing the target identity conversion information to the service management device, the first website is opened based on the login indication information.
[0054] In a possible implementation, the simulated login instruction is triggered by a target jump object corresponding to the first account, and the target jump object indicates a request to log in to the first website through identity information of the first account.
[0055] In a seventh aspect of the present application, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method described in the first aspect and any possible implementation manner is implemented.
[0056] In an eighth aspect of the present application, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method described in the second aspect and any possible implementation manner is implemented.
[0057] In a ninth aspect of the present application, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the program, the method described in the third aspect and any possible implementation manner is implemented.
[0058] In a tenth aspect of the present application, a computer program product is provided, the computer program product comprising computer instructions, the computer instructions being stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the method provided in various possible implementations of the first aspect, the second aspect, or the third aspect.
[0059] In an eleventh aspect of the present application, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions. When the computer instructions are executed on a computer, the computer executes the method described in any one of the first aspect, the second aspect, or the third aspect.
[0060] Since the embodiment of the present application adopts the above technical solution, it has at least the following technical effects:
[0061] In the embodiment of the present application, after the service management device determines, based on the target identity conversion information, that the target request is a request by the second account to log in to the first website using the identity information of the first account, it directly and automatically obtains the login status identifier of the first account, adds the obtained login status identifier to the target request, and then sends it to the first website, so that the terminal can log in to the first website using the identity information of the first account based on the login status identifier information without having to know the login password of the first account, thereby achieving a simulated login of the second account to the first website using the identity information of the first account without knowing the login account and login password of the first account, thereby improving the security of the account login information of the first account. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] Figure 1 A schematic diagram of an application scenario provided in an embodiment of the present application;
[0063] Figure 2 A schematic diagram of another application scenario provided by an embodiment of the present application;
[0064] Figure 3 A schematic diagram of a simulated account login process provided in an embodiment of the present application;
[0065] Figure 4 An example diagram of a first account query page of a target website provided in an embodiment of the present application;
[0066] Figure 5 An example diagram of a first account query page of a target website provided in an embodiment of the present application;
[0067] Figure 6 A schematic diagram of a simulated account login process provided in an embodiment of the present application;
[0068] Figure 7 A schematic diagram of a simulated account login process provided in an embodiment of the present application;
[0069] Figure 8 A schematic diagram of a simulated account login process of a service management device provided in an embodiment of the present application;
[0070] Fig. 9 A schematic diagram of the principle of a simulated account login provided in an embodiment of the present application;
[0071] Fig.10 An example diagram of an interaction process between terminals provided in an embodiment of the present application;
[0072] Fig.11 A schematic diagram of an interaction process between terminals provided in an embodiment of the present application;
[0073] Fig.12A schematic diagram of the principle of a simulated account login provided in an embodiment of the present application;
[0074] Fig.13 A schematic diagram of an interaction process between terminals provided in an embodiment of the present application;
[0075] Fig.14 A schematic diagram of an interaction process between terminals provided in an embodiment of the present application;
[0076] Fig.15 A structural example diagram of a device for simulating account login provided in an embodiment of the present application;
[0077] Fig.16 A structural example diagram of a device for simulating account login provided in an embodiment of the present application;
[0078] Fig.17 A structural example diagram of a device for simulating account login provided in an embodiment of the present application;
[0079] Fig.18 A diagram showing an example of a terminal structure provided in an embodiment of the present application;
[0080] Fig.19 This is a diagram showing an example of the structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0081] In order to better understand the technical solution provided by the embodiments of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.
[0082] In order to help those skilled in the art better understand the technical solution of the present application, the technical terms involved in the present application are explained below.
[0083] First account, second account: In the embodiment of the present application, the first account is the account that is simulated for login, and the first account is an account that has been registered on the first website; the second account is an account that requests to log in to the first website with the identity information of the first account; the second account can be an account that has been registered on the first website and is different from the first account, or the second account can be an account that has been registered on the second website.
[0084] The first website and the second website: In the embodiment of the present application, the first website is a website that provides services for the first account, and the service may include but is not limited to at least one of viewing news information, e-shopping, games, social networking, content sharing, live broadcasting, etc.; and the first website may use a service management device as a unified entrance for all dynamic requests; the second website is a website other than the first website, and the second website may be but is not limited to a website used to manage the first website, that is, the second website may be a backend management system for the first website; if the first website provides banking services, the second account may be an account of a bank staff member, and the bank staff member may query the bank flow information of the first account through the second website; when the first website provides communication services, the second account may be a communication customer service staff, and the communication customer service staff may query the mobile phone call records of the first account through the second website; when the first website provides transportation services (such as aviation, high-speed rail or car services, etc.), the second account may be a transportation customer service staff, and the transportation customer service staff may query the transportation ticketing information of the first account through the second website, and help the first account to order, change transportation tickets, or refund transportation tickets, etc.
[0085] Account (including first account and second account) identity information: information that can uniquely identify the identity of an account, which may include but is not limited to account identification number, account number, etc.
[0086] Identity conversion information: information used to indicate that the second account requests to log in to the first website through the identity information of the first account. The identity conversion information in the embodiment of the present application may include, but is not limited to, the identity information of the first account and the identity information of the second account.
[0087] Account login status identifier: identifier used to represent the login to the first website using the account's identity information. The first account login status identifier refers to identifier information used to represent the login to the first website using the first account's identity information. The login status identifier may be, but is not limited to, a string or a specific numerical value.
[0088] Simulated account login: The second account, on the second website, requests to log in to the first website using the identity information of the first account. Then, the second account views the page display content of the first website that the first account sees after logging in to the first website from the perspective of the first account.
[0089] Cookie information: In browser applications, cookie information is used to store text data recorded locally by websites. The size of cookie information generally does not exceed 4KB. The most common use of cookie information is to store the account's login status on the website through sessionId. Cookie information refers to data (usually encrypted) stored on the account's local terminal in order to identify the account's identity. Cookie information is a technology that allows the website's server to store a small amount of data on the hard disk or memory of the client on the terminal, or to read data from the client's hard disk. The cookie information can record the account ID, password, viewed web pages, length of stay, and other information of the account visiting the website. When the account visits the website again, the website can read the cookie information and obtain relevant information about the above account, and can take corresponding actions.
[0090] Cloud technology is a general term for network technology, information technology, integration technology, management platform technology, application technology, etc. based on the cloud computing business model. It can form a resource pool and be used on demand, which is flexible and convenient. Cloud service technology is an important support; the background service of the technical network system requires a large amount of computing and storage resources, such as video websites, picture websites and more portal websites.
[0091] The design concept of this application is described below.
[0092] In some scenarios, a user needs to simulate another user to log in to the corresponding website. For example, when another user logs in to the website through a registered account and obtains the services provided by the website, if there is a problem when operating through the above website or it is inconvenient for the other user to operate through the website, the above user needs to log in to the website through the account of the other user to solve the problem encountered during the operation or replace the other user to complete the target operation; and currently, the above user often logs in to the website through the login account and login password by directly asking for the login account and login password of the other user, but in the process, the above user learns the account login information of the other user, and the account login information has a great security risk; in the related technology, there is also an information query function of the background management system of the above website improved by the technicians, and the above user can query the problem when another user operates through the above website through the background management system of the above website through the background management system of the above website, but this method of improving the background management system requires a lot of time and workload, which leads to untimely information query and low query efficiency. Therefore, how to improve the security of the account in the process of simulated account login and improve the login efficiency of simulated account login has become a problem that needs to be considered.
[0093] In view of this, the inventor has designed a method, apparatus, device and storage medium for simulating account login; considering that directly obtaining the account login information of the account being simulated during the simulated account login will have a great impact on the security of the account login information of the account being simulated, the embodiment of the present application considers modifying the identity information of the account in the target request used to log in to the first website, so as to realize logging in to the first website with the identity information of the account being simulated without knowing the account login information of the account being simulated; specifically, after determining that the target request sent by the terminal is a simulated login request, based on the identity information of the first account and the identity information of the second account carried in the target request, the identity information of the account requesting to log in to the first website in the target request can be rewritten into the identity information of the first account, and then the target request can be sent to the first website, so that the terminal can log in to the first website through the identity information of the first account.
[0094] Further considering that in order to improve the login efficiency of the simulated account login, in the embodiment of the present application, the service management device can modify the identity information of the account used to log in to the first website in the above target request.
[0095] In order to more clearly understand the design ideas of the present application, the following describes the contents of the embodiments of the present application in detail with reference to the accompanying drawings. In order to more clearly understand the design ideas of the present application, the following provides two application scenarios:
[0096] The first application scenario:
[0097] The first website and the second website are the same website; the first account and the second account are both accounts registered on the first website; the second account is an account other than the first account, and the first account and the second account may be, but are not limited to, different types of accounts; if the first account and the second account are accounts with different operating permissions, such as when the first website provides electronic shopping services, the first account may be an account with permissions to purchase goods, and the second account may be an account with permissions to provide consulting services to the first account (such as, but not limited to, the account of the customer service staff of the first website, etc.), and the second account may also be an account with permissions to manage goods or account information or order information, etc., and technicians in this field may set the specific types of the first account and the second account according to actual needs.
[0098] Please refer to Figure 1 , the first application scenario includes at least one terminal 100, a service management device 200 and a first server 300 of a first website; the terminal 100 and the service management device 200 can communicate with each other, the service management device 200 and the first server 300 can communicate with each other, and the terminal 100 and the first server 300 can communicate through the bridge of the service management device 200; wherein:
[0099] The terminal 100 (such as but not limited to including 100-1 or 100-2 in the figure) can send a login jump request to the first server 300 in response to a simulated login instruction of the second account; and receive login indication information returned by the first server 300; specifically, the terminal 100 can send a login jump request to the service management device 200, and receive a login jump request returned by the first server 300 forwarded by the service management device 200; then the terminal adds the target identity conversion information contained in the login indication information to the target request and sends it to the service management device 200, so as to log in to the first website through the identity information of the first account.
[0100] The service management device 200 forwards the login jump request sent by the terminal 100 to the first server 300, and forwards the login jump request returned by the first server 300 to the terminal 100; and receives the target request sent by the terminal 100. If it is determined that the target request contains target identity conversion information, the login state identifier of the first account is obtained based on the target identity conversion information, and the login state identifier is added to the target request and sent to the first server 300.
[0101] The first server 300 (such as but not limited to 300-1, 300-2, or 300-3 in the figure) receives the login jump request sent by the terminal 100, sends a login indication message to the terminal 100, and receives a target request containing a login status identifier sent by the service management device 200, allowing login to the first website through the identity information of the first account, and then the resources requested by the terminal 100 can be sent to the terminal 100.
[0102] The second application scenario:
[0103] The first website and the second website are different websites; the first account is an account registered on the first website, and the second account is an account registered on the second website; if the first website provides electronic shopping services, and the second account is the backend management system of the first website, then the first account can be an account with the authority to purchase goods, and the second account can be an account that provides consulting services to the first account (such as but not limited to the account of the customer service staff of the first website, etc.), and the second account can also be an account with the authority to manage the first website, etc.
[0104] Please refer to Figure 2 The second application scenario includes at least one terminal 100, a service management device 200, a first server 300 of a first website, and a second server 400 of a second website; wherein:
[0105] The terminal 100 (such as but not limited to including 100-1 or 100-2 in the figure) can send a login jump request to the second server 400 in response to the simulated login instruction of the second account; and receive the login indication information returned by the second server 400, and then add the identity conversion information contained in the login indication information to the target request to send to the service management device 200.
[0106] The second server 400 (such as but not limited to 400-1, 400-2, or 400-3 in the figure) receives the login jump request sent by the terminal 100, and sends a login indication message to the terminal 100, wherein the second server 400 and the terminal 100 can communicate directly, and the second server 400 and the terminal 100 can also be bridged through the above-mentioned service management device 200 to realize the communication between the second server 400 and the terminal 100. Technical personnel in this field can set it according to actual needs.
[0107] The service management device 200 receives the target request sent by the terminal 100. If it is determined that the target request contains target identity conversion information, it obtains the login state identifier of the first account based on the target identity conversion information, and adds the login state identifier to the target request and sends it to the first server 300.
[0108] The first server 300 (such as but not limited to 300-1, 300-2, or 300-3 in the figure) receives the target request containing the login status identifier sent by the service management device 200, allows logging into the first website through the identity information of the first account, and then can send the resources requested by the terminal 100 to the terminal 100.
[0109] The service management device 200 in the embodiment of the present application is a device for uniformly managing various websites used for services. The service management device 200 can be but is not limited to a server or an application programming interface (API) gateway. The above-mentioned API gateway is used to implement API-hosted services. In website applications, the API gateway generally serves as the entry point for all external requests; the API gateway encapsulates various back-end services and provides them to all parties in the form of APIs for calling; the API gateway serves as the entry point for all requests and can usually be used for functions such as current limiting, monitoring, and API management.
[0110] Any one of the first server 300 and the second server 400 in the embodiment of the present application may be an independent physical server, or a server cluster or distributed system composed of multiple physical servers, or may be multiple cloud servers that provide basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms through cloud service technology (for example, the first server 300 may include but is not limited to the server 300-1, server 300-2 or server 300-3 shown in the figure, and the second server 400 may include but is not limited to the server 400-1, server 400-2 or server 400-3 shown in the figure); the functions of the above-mentioned first server 300 may be implemented by one or more cloud servers, or by one or more cloud server clusters, etc.; the functions of the above-mentioned second server 400 may be implemented by one or more cloud servers, or by one or more cloud server clusters, etc.
[0111] The terminal 100 in the embodiment of the present application can be a mobile terminal, a fixed terminal or a portable terminal, such as a mobile phone, a station, a unit, a device, a multimedia computer, a multimedia tablet, an Internet node, a communicator, a desktop computer, a laptop computer, a notebook computer, a netbook computer, a tablet computer, a personal communication system (PCS) device, a personal navigation device, a personal digital assistant (PDA), an audio / video player, a digital camera / camcorder, a positioning device, a television receiver, a radio broadcast receiver, an e-book device, a gaming device or any combination thereof, including accessories and peripherals of these devices or any combination thereof.
[0112] based on Figure 1 and Figure 2 The following is an example of the application scenario of the simulated account login method involved in this application.
[0113] Please refer to Figure 3 , represents the method for simulating account login designed in the embodiment of the present application, for the above-mentioned terminal 100, specifically comprising the following steps:
[0114] Step S301, responding to the simulated login instruction of the second account, sending a login jump request to the target website, the login jump request carries the identity information of the first account, and the target website is the first website or the second website;
[0115] Specifically, when the embodiment of the present application is applied to the first application scenario mentioned above, the target website is the first website, and the second account can, but is not limited to, trigger a simulated login instruction after logging into the first website through the identity information of the second account; when the embodiment of the present application is applied to the second application scenario mentioned above, the target website is the second website, and the second account can, but is not limited to, trigger a simulated login instruction after logging into the second website through the identity information of the second account.
[0116] Step S302: receiving login instruction information returned by the target website based on the above login jump request.
[0117] The target website determines the content of the login indication information based on the login jump request, which will be explained below.
[0118] Step S303, determining the identity conversion information contained in the above-mentioned login indication information as the target identity conversion information; the identity conversion information is used to indicate that the above-mentioned second account requests to log in to the above-mentioned first website with the identity information of the above-mentioned first account, and the identity conversion information includes the identity information of the above-mentioned first account and the identity information of the above-mentioned second account.
[0119] Step S304: sending a target request including the target identity conversion information to the service management device 200, so as to log in to the first website through the identity information of the first account based on the target identity conversion information.
[0120] As an embodiment, after the terminal 100 determines the target identity conversion information, it can be saved in a local preset storage space. When the second account requests a simulated login to the first account, the terminal 100 automatically obtains the target identity conversion information from the preset storage space, and sends a target request carrying the above target identity conversion information to indicate a request to log in to the first website through the identity information of the first account; if the first account itself requests to log in to the first website, the above preset storage space will store the login status identifier of the first account, but will not store the target identity conversion information. Therefore, when the first account itself requests to log in to the first website, the target request sent by the terminal does not include the target identity conversion information.
[0121] For ease of understanding, a specific example is given here. If the terminal 100 accesses the first website through a browser, the above-mentioned preset storage space may include but is not limited to the cookie information corresponding to the first website in the browser. After obtaining the target identity conversion information, the terminal 100 may store the target identity conversion information in the cookie information corresponding to the first network in the browser; due to the characteristics of the browser, all target requests issued from the browser to log in to the first website will carry cookie information. In the embodiment of the present application, when the second account requests to simulate a login to the first account, the target request issued from the browser will carry the cookie information corresponding to the first website (the cookie information includes the above-mentioned target identity conversion information); and in the case where the first account requests to log in to the first website through the browser, the target website will not return the login indication information, and the terminal 100 cannot obtain the target identity conversion information. Therefore, the cookie information corresponding to the first website does not include the target identity conversion information. In this case, the cookie information carried in the target request triggered by the first account does not include the target identity conversion information.
[0122] The terminal 100 may also store the target identity conversion information in a space other than the above-mentioned cookie information, and then when the terminal 100 sends a target request, the target identity conversion information may be added at the set string position of the target request; if the target request is a Hyper Text Transfer Protocol (HTTP) request, an HTTP header called Auth-Token may be added to the HTTP request, and the first server 300 will uniformly obtain the value of Auth-Token from the header to verify the login state, and the value of the above-mentioned Auth-Token is the above-mentioned target identity conversion information.
[0123] It should be noted that, when the target website is the first website, the second account has logged in to the first website before step 301, that is, the terminal 100 has opened the first website; but when the target website is the second website, the second account has logged in to the second website before step 301, and the terminal 100 has opened the second website. The above-mentioned simulated login instruction is triggered after the terminal 100 logs in to the second website through the identity information of the second account, and the terminal 100 opens the second website in steps S301 to S303. In the embodiment of the present application, the purpose of the terminal 100 is to log in to the first website through the identity information of the first account. Therefore, after the above-mentioned step S303 and before step S304, the terminal 100 needs to be redirected to the first website, and the terminal 100 can open the first website based on the received login instruction information.
[0124] As an embodiment, in order to improve the accuracy of the simulated login instruction, the simulated login instruction in step S301 can be triggered by the target jump object corresponding to the above-mentioned first account; the target jump object is used to indicate that the second account requests to log in to the first website through the identity information of the first account. Technical personnel in this field can set the specific form of the simulated login instruction according to actual needs, such as but not limited to setting the target jump object to a simulated login jump link or button.
[0125] It should be noted that the second account needs to obtain information about the first account being simulated before step S301, that is, before step S301, the user corresponding to the second account can obtain account query information of the first account in some way (such as talking on the phone or chatting online with the user corresponding to the first account), and then the second account can determine the target jump object corresponding to the first account through the account query information of the first account; the above account query information can be used to indicate the identity information of the first account, and the account query information can be but is not limited to the account name or account identity of the first account, and the account identity mark can be but is not limited to including the account identification number of the first account, or a unique character string assigned to the first account by the first website, etc. Technical personnel in this field can set the above account query information according to actual needs.
[0126] In order to improve the convenience of triggering the login jump instruction, in an embodiment of the present application, a target application for accessing the website can be installed on the terminal 100, and the terminal 100 can open the page of the target website (the first website or the second website mentioned above) through the target application; the above-mentioned target jump object can be displayed in the page of the target website, and the above-mentioned target application can be but is not limited to the above-mentioned browser; in order to facilitate understanding of the triggering mechanism of the login jump instruction, two process examples for triggering the login jump instruction are given below.
[0127] The first trigger method:
[0128] See also Figure 4, the embodiment of the present application provides a first account query page 4000 of a target website. After the terminal 100 logs in to the target website through the identity information of the second account, the account query information of the first account can be input in the account query box 401; then, after the terminal 100 detects that the second account clicks the query button 402, the target jump object of the first account matching the account query information input by the second account is queried, and the queried target object is displayed in the account information display area 403; the above-mentioned target jump object can be, but is not limited to, the simulated login button 404 in the figure, and then the second account can trigger the above-mentioned simulated login instruction by clicking or long pressing the simulated login button 404; then In the first step, when the terminal 100 queries the target jump object of the first account that matches the account query information input by the second account, it can also obtain the account information of the above-mentioned first account, and display the obtained account information in the account information display area 403; the above-mentioned account information may include but is not limited to the account name of the first account illustrated in the figure, the identity information of the first account, the creation time and operation information, etc., the operation information may include but is not limited to modifying the account button 405 and removing the button 406, the second account can trigger the modification of the information of the first account through the information modification button 405, and can also delete the account information of the first account through the remove button 406.
[0129] The second way to trigger the login jump instruction:
[0130] See also Figure 5 , the embodiment of the present application provides a first account query page 4000 of a target website, wherein the account query information may also include project information of a project to which the first account belongs; after the terminal 100 logs in to the first website through the identity information of the second account, the target jump objects of all first accounts under the corresponding project may be queried through the project information, and then the target jump object corresponding to the first account to be simulatedly logged in may be determined from the target jump objects of all first accounts. In the figure, the XX project is taken as an example of the project to which the first account to be simulatedly logged in belongs, and the terminal 100 may display the target jump objects of all first accounts queried under the XX project in the account information display area 501. The target jump object may be, but is not limited to, the simulated login button 502 in the figure, and then the second account may trigger the simulated login instruction by clicking or long pressing the simulated login button 502 corresponding to the first account to be simulatedly logged in; further, when the terminal 100 queries the target jump objects of all first accounts under the project XX, the account information of all first accounts under the XX project may be obtained, and the obtained account information may be displayed in the account information display area 501; the account information may refer to the above description, and will not be repeated here.
[0131] Please refer to Figure 6, which represents the method for simulating account login designed in the embodiment of the present application, for the server of the target website (the first server 300 or the second server 400 mentioned above), specifically includes the following steps:
[0132] Step S601: receiving a login jump request sent by the terminal 100, wherein the login jump request carries identity information of a first account.
[0133] For detailed instructions on login jump request, please refer to the above description, which will not be repeated here.
[0134] Step S602: determining the identity information of the second account that triggers the above login jump request.
[0135] Typically, a request sent by an account to a target website will carry the identity information of the account. Therefore, in this step, the server of the target website can directly determine the identity information of the second account that sends the login jump request based on the received login jump request.
[0136] Step S603: Generate identity conversion information including the identity information of the first account and the identity information of the second account.
[0137] Specifically, the server of the target website can use the identity information of the first account and the identity information of the second account as a parameter to obtain identity conversion information, such as storing the identity information of the first account and the identity information of the second account in a parameter of a specific data format to obtain the above-mentioned identity conversion information, and the above-mentioned specific parameter format can be but not limited to including key-value pairs, lists, arrays, etc.; such as generating a key-value pair K-V1 based on the identity information of the first account and the identity information of the second account, and determining the key-value pair K-V1 as the identity conversion information, wherein the key K in the key-value pair K-V1 can be but not limited to a random string k1, k1 is used to identify the identity conversion information, and the value V1 can be the identity information of the first account and the identity information of the second account.
[0138] As an embodiment, in order to improve the security level of simulated account login, the generated identity conversion information can also be saved in the embodiment of the present application, so as to judge whether the above-mentioned target request is legal based on the saved identity conversion information at a later time, such as the generated identity conversion information can be saved in a preset identity conversion information library; specifically, if the identity conversion information is the above-mentioned key-value pair K-V1, the identity information of the first account includes the name of the first account "Li" and the first account ID "2918374", and the identity information of the second account includes the name of the second account "Customer Service Zhang" and the second account ID "zhangmou", the server of the target website can store the key-value pair K-V1 in the preset identity conversion information library according to the storage fields shown in Table 1, so that after the service management device 200 receives the target request containing the identity conversion information, it determines whether the target request is legal according to the identity conversion information, so as to determine whether to send the first prompt information for indicating that the target request is abnormal to the terminal 100, wherein the specific process of the service management device 200 sending the first prompt information will be described in detail in the following content.
[0139] Table 1: Storage fields of key-value pair K-V1
[0140]
[0141] Step S604, returning login instruction information including the identity conversion information to the terminal 100, so that the terminal 100 sends a target request including the identity conversion information, wherein the target request is used to enable the terminal 100 to log in to the first website through the identity information of the first account.
[0142] As an embodiment, in the embodiment of the present application, when the target website is the first website, the login indication information may, but is not limited to, include identity conversion information; then the first server 300 of the first website may also include receiving the target request forwarded by the service management device 200 after step S604, and returning the resources and data corresponding to the target request to the terminal 100 based on the received target request.
[0143] In the embodiment of the present application, when the target website is the second website, the login instruction information may include, in addition to the identity conversion information, information instructing the terminal 100 to open the first website, thereby causing the terminal 100 to open the first website after receiving the login instruction information.
[0144] As an embodiment, when the target website is the second website, in order to improve the efficiency of the terminal opening the first website based on the login instruction information, the login instruction information may be, but not limited to, a redirection link url, and the redirection link may be, but not limited to, HTTP 302 redirection; if the URL of the first website is https: / / nei.com and the URL of the second website is https: / / wai.com, then the redirection link may be, but not limited to, https: / / wai.com? mockToken= <xxxx>, where mockToken is the above identity conversion information, <xxx>The value V1 of the key-value pair K-V1 of the above identity conversion information. Those skilled in the art can also set the specific form of the above login indication information or redirection link according to actual needs, which is not limited too much here.
[0145] By combining steps S301 to S303 on the above-mentioned terminal 100 with steps S601 to S602 on the server of the target website, it is possible to store the target identity conversion information on the terminal 100, and then the terminal 100 can send a target request containing the target identity conversion information to the service management device 200 through step S304, thereby logging in to the first website through the identity information of the first account.
[0146] It should be noted that in the embodiment of the present application, when the target website is the second website, the second website can manage one first website or multiple first websites, that is, in the embodiment of the present application, a simulated account login can be implemented for one first website or multiple first websites. For the above two situations, the triggering method of the login jump request and the content of the login indication information are slightly different, which is further explained below.
[0147] (I) Implementing a simulated account login for a first website
[0148] In this case, a corresponding target jump object can be set for a first account on the above-mentioned first account query page 4000 or the first account query page 5000, and the target jump object may not carry the website indication information of the first website. The second account can trigger a login jump indication by clicking or long pressing the target jump object, and the terminal 100 sends a login jump request to the second server 400 based on the login jump indication.
[0149] The second server 400 of the second website has already known in advance the first website for implementing simulated account login, and the website jump indication information of the first website can be configured in the second server 400; after the second server 400 receives the login jump request, in step S604, the website jump indication information of the first website can be carried in the login indication information and sent to the terminal 100, so that the terminal 100 opens the first website based on the above website jump indication information.
[0150] (II) Implementing simulated account login for multiple first websites
[0151] In this case, on the above-mentioned first account query page 4000 or the first account query page 5000, for a first account, a corresponding target jump object can be set for different first websites, and the target jump object can carry the website indication information of the corresponding first website; then the second account can trigger the login jump indication carrying the website indication information by clicking or long pressing a target jump object in the target jump object corresponding to the first account; then the terminal 100 sends a login jump request to the second server 400 based on the login jump indication, and the login jump request carries the website indication information.
[0152] The second server 400 of the second website does not have prior knowledge of the first website for implementing simulated account login; therefore, after the second server 400 receives the login jump request, in step S604, the website jump indication information of the first website corresponding to the website indication information in the login jump request can be carried in the login indication information and sent to the terminal 100, thereby enabling the terminal 100 to open the first website based on the above-mentioned website jump indication information.
[0153] Please refer to Figure 7 , which represents the method for simulating account login designed in the embodiment of the present application, and for the upper service management device 200, specifically includes the following steps:
[0154] Step S701: receiving a target request sent by the terminal 100 for logging into a first website.
[0155] For a detailed introduction to target requests, please refer to the above content and will not be repeated here.
[0156] Step S702: If it is determined that the target request contains target identity conversion information, the login state identifier of the first account is obtained based on the target identity conversion information; wherein the login state identifier is determined based on the identity information of the first account, and the target identity conversion information includes the identity information of the first account and the identity information of the second account.
[0157] For a detailed introduction to the target identity conversion information, please refer to the above content, which will not be repeated here; and there is no limitation on the form of the above login status identifier, such as but not limited to the sessionId of the account in the browser technology.
[0158] Referring to the relevant description in the above step S304, when the second account requests to simulate a login to the first account, the target request sent by the terminal 100 includes target identity conversion information, and when the first account itself requests to log in to the first website, the target request sent by the terminal 100 does not include target identity conversion information. In step S702, the service management device 200 determines that the target request includes target identity conversion information, and then it can be determined that the target request is triggered when the second account requests to simulate a login to the first account.
[0159] Step S703: Add the login status identifier to the target request.
[0160] Specifically, the login state identifier may be directly added to the target request, such as but not limited to being added to the header of the target request; if the login state identifier is sessionId, a sessionId= may be directly added to the header of the cookie information in the target request. <yyy>,in <yyy>is the value of sessionId; the target identity conversion information in the target request can also be directly replaced with the above-mentioned login state identifier to obtain a target request with an added login state identifier; technicians in this field can also add the above-mentioned login state identifier to the target request in other forms according to actual needs.
[0161] Step S704: sending a target request for adding the login status identifier to the first website, so that the terminal 100 logs in to the first website through the identity information of the first account based on the login status identifier.
[0162] As an embodiment, considering that the target request sent by the terminal 100 may also be a normal login request sent by the first account to log in to the first website when the first account has not logged in to the first website, and the normal login request does not contain the target identity conversion information and the login state identifier of the first account, therefore, after step S701 of the embodiment of the present application, if the service management device 200 determines that the above-mentioned target request does not contain the target identity conversion information, and the above-mentioned target request does not contain the login state identifier of the above-mentioned first account, it sends a second prompt message to the terminal 100, so that the terminal 100 loads the login page of the above-mentioned first website based on the second prompt information, and the login page is used for the terminal 100 to log in to the first website through the identity information of the first account.
[0163] As an embodiment, considering that the target request sent by the terminal 100 may also be a normal access request sent by the first account after logging into the first website, requesting access to the resources of the first website, and the normal access request includes the login state identifier of the first account but does not include the target identity conversion information, therefore, after step S701 of the embodiment of the present application, if the service management device 200 determines that the above-mentioned target request does not include the target identity conversion information, and the above-mentioned target request includes the login state identifier of the above-mentioned first account, then the above-mentioned first website is logged in through the identity information of the above-mentioned first account.
[0164] As an embodiment, in order to improve the efficiency of obtaining the login status identifier of the above-mentioned first account, in step S702 in the embodiment of the present application, a mapping relationship between the identity conversion information and the login status identifier can be set to quickly obtain the above-mentioned login status identifier based on the above-mentioned mapping relationship.
[0165] Specifically, a mapping relationship between preset identity conversion information and a login state identifier can be obtained; if the above mapping relationship records a login state identifier corresponding to the above target identity conversion information, the above login state identifier is obtained; if the above mapping relationship does not record a login state identifier corresponding to the above target identity conversion information, a corresponding login state identifier is generated based on the identity information of the above first account contained in the above target identity conversion information, and a mapping relationship between the above target identity conversion information and the generated login state identifier is created and saved; wherein the login state identifier can be generated by the first server 300, and when the service management device 200 obtains the login state identifier, it can call the login state planting interface between the service management device 200 and the first server 300, and the first server 300 generates the corresponding login state identifier based on the identity information of the first account.
[0166] As an embodiment, in order to reduce the security risk of the first website and the security risk of the first account, after determining in step S702 that the target request is a simulated login request (i.e., a request from the second account to simulate a login to the first account), it is possible to determine whether the simulated login request is legal, so as to prevent illegal simulated login requests from affecting the security of the first website or the first account. Therefore, after determining that the target request contains target identity conversion information, the service management device 200 can also access a preset identity conversion information library through a target interface before obtaining a login state identifier of the first account based on the target identity conversion information, and determine the identity conversion information based on the identity conversion information stored in the preset identity conversion information library. Determine whether the above-mentioned simulated login request is legal; specifically, if the above-mentioned identity conversion information library stores identity conversion information matching the above-mentioned target identity conversion information, then the above-mentioned target request is a legal simulated login request; if the above-mentioned identity conversion information library does not store identity conversion information matching the above-mentioned target identity conversion information, then the above-mentioned target request is an illegal simulated login request, and send a first prompt information to the above-mentioned terminal 100, and the above-mentioned first prompt information is used to indicate that the above-mentioned target request is abnormal; the identity conversion information matching the above-mentioned target identity conversion information and the target identity conversion information are both used to indicate that the same second account requests to log in to the above-mentioned first website with the identity information of the same first account.
[0167] The following is an example of a complete process of a service management device 200. Figure 8 , specifically including the following steps:
[0168] Step S801: receiving a target request sent by the terminal 100.
[0169] Step S802, determining whether the target request contains the login status identifier of the first account, if not, proceeding to step S803, if contained, proceeding to step S812.
[0170] Step S803, determining whether the target request contains target identity conversion information, if so, proceeding to step S804, otherwise proceeding to step S813.
[0171] Step S804, determining whether the preset identity conversion information database stores identity conversion information matching the target identity conversion information, if yes, proceeding to step S805, otherwise proceeding to step S814.
[0172] Step S805: obtaining a mapping relationship between preset identity conversion information and a login status identifier.
[0173] Step S806, determining whether the acquired mapping relationship records the login status identifier of the target identity conversion information, if so, proceeding to step S807, otherwise proceeding to step S808.
[0174] Step S807: acquiring the login status identifier of the target identity conversion information from the mapping relationship.
[0175] Step S808, based on the identity information of the first account included in the target identity conversion information, generate a corresponding login status identifier, and proceed to step S809 and step S810.
[0176] Step S809: Create and save a mapping relationship between the target identity conversion information and the generated login state identifier.
[0177] Step S810: Add the login status identifier to the target request.
[0178] It should be noted here that there is no fixed order between step S809 and step S810.
[0179] Step S811, sending a target request for adding the above-mentioned login status identifier to the first website.
[0180] Step S812: Send a target request including a login status identifier of the first account to the first website.
[0181] Step S813: Send a second prompt message to the terminal 100, where the second prompt message is used to instruct the terminal 100 to load the login page of the first website.
[0182] Step S814: Send a first prompt message to the terminal 100 to indicate that the target request is abnormal.
[0183] The following content of the embodiments of the present application gives an example of a complete interaction process between the terminal 100, the service management device 200, the first server 300 and the second server 400 when applied in the above-mentioned first application scenario and the second scenario; for ease of understanding, in the following example, the browser in the terminal 100 (i.e., the above-mentioned target application) executes the method of the terminal 100, and the terminal 100 stores the target identity conversion information in the cookie information of the first website in the browser, and takes the API gateway as the above-mentioned service management device 200, and takes the simulated login jump link as the above-mentioned target jump object as an example for explanation.
[0184] Example 1: Applied to the first application scenario above
[0185] See also Fig. 9 In this example, user B of the second account and user A of the first account can chat by phone or online, and user B can obtain the account query information of the first account. Then, after user B logs in to the first website through the identity information of the second account, he queries the target jump object of the first account based on the account query information of the first account, and triggers the login jump instruction by clicking the target jump object of the first account.
[0186] The process of obtaining the target identity conversion information includes: after the browser on the terminal 100 detects the login jump indication, it sends a login jump request to the API gateway; the API gateway forwards the login jump request sent by the browser to the first server 300; the first server 300 determines the login indication information containing the identity conversion information based on the login jump request, and forwards it to the browser through the API gateway; and then the browser determines the identity conversion information in the login indication information as the target identity conversion information.
[0187] The process of simulating account login includes: the browser sends a target request containing target identity conversion information to the API gateway; the API gateway adds the login state identifier of the target identity conversion information to the target request and sends it to the first server 300; the first server 300 receives the target request with the login state identifier sent by the API gateway, allows the browser to log in using the identity information of the first account, and sends the information corresponding to the target request to the browser through the API gateway.
[0188] The interaction process between the browser, the API gateway and the first server 300 in the above process may specifically include but is not limited to the following steps:
[0189] The first step: The browser obtains the target identity conversion information
[0190] See also Fig.10 , the process specifically includes:
[0191] After user B of the second account communicates with user A of the first account to obtain account query information of the first account, user B enters the URL of the first website into the browser and requests to open the first website.
[0192] Step S1001: The browser opens the first website based on the URL of the first website, and logs in to the first website through the identity information of the second account based on the instruction.
[0193] After user B logs in to the first website with the identity information of the second account, he will enter the account query information of the first account in the first website to obtain the simulated login jump link corresponding to the first account, and then user B clicks the simulated login jump link.
[0194] Step S1002: When the browser detects that the simulated login jump link of the first account is clicked, it sends a login jump request to the API gateway, where the login jump request carries the identity information of the first account.
[0195] Step S1003 , the API gateway forwards the login jump request to the first server 300 .
[0196] Step S1004: The first server 300 obtains the identity information of the first account from the login jump request, and determines the identity information of the second account that triggers the login jump request.
[0197] Step S1005: The first server 300 generates identity conversion information including the identity information of the first account and the identity information of the second account.
[0198] Step S1006: The first server 300 stores the identity conversion information in a preset identity conversion information database.
[0199] Step S1007: The first server 300 creates login instruction information including identity conversion information, and sends the login instruction information to the API gateway.
[0200] Step S1008: The API gateway sends login instruction information including identity conversion information to the browser.
[0201] Step S1009: The browser determines the identity conversion information in the login instruction information as the target identity conversion information, and stores the target identity conversion information in the cookie information corresponding to the first website.
[0202] Second process: Demo account login process
[0203] See also Fig.11 , specifically including the following steps:
[0204] Step S1101: The browser creates a target request including cookie information, wherein the cookie information includes target identity conversion information.
[0205] The target request may be, but is not limited to, an http request.
[0206] Step S1102: The browser sends a target request containing cookie information to the API gateway.
[0207] Step S1103, the API gateway determines that the target request contains target identity conversion information.
[0208] It should be noted that this example only describes the situation of simulated account login, so the target request contains target identity conversion information. For the situation of the first account itself logging into the first website, please refer to the above content and will not be repeated here.
[0209] Step S1104 : The API gateway accesses the identity conversion information library stored on the first server 300 through the target interface between the API gateway and the first server 300 .
[0210] Step S1105: If the API gateway determines that the preset identity conversion information library stores identity conversion information matching the target identity conversion information, it obtains a mapping relationship between the preset identity conversion information and the login state identifier.
[0211] Step S11051: If the API gateway determines that the acquired mapping relationship records the login state identifier of the target identity conversion information, the API gateway acquires the login state identifier of the target identity conversion information from the mapping relationship.
[0212] Step S11052: If the API gateway determines that the acquired mapping relationship does not record the login state identifier of the target identity conversion information, it generates a corresponding login state identifier based on the identity information of the first account included in the target identity conversion information.
[0213] Step S11053, the API gateway creates and saves the mapping relationship between the above target identity conversion information and the generated login state identifier.
[0214] Step S1106: The API gateway adds the login status identifier to the cookie information in the target request.
[0215] Step S1107 , the API gateway sends the target request with the login status identifier added to the cookie information to the first server 300 .
[0216] Step S1108: If the API gateway determines that the preset identity conversion information library does not store identity conversion information matching the target identity conversion information, it sends a first prompt message to the browser.
[0217] Example 2: Applied to the second application scenario above
[0218] See also Fig.12 In this example, user B of the second account and user A of the first account can chat by phone or online, and user B can obtain the account query information of the first account. Then, after user B logs in to the second website through the identity information of the second account, he queries the target jump object of the first account based on the account query information of the first account, and triggers the login jump instruction by clicking the target jump object of the first account.
[0219] The process of obtaining the target identity conversion information includes: after the browser on the terminal 100 detects the login jump indication, it sends a login jump request to the second server 400; the second server 400 determines the login indication information containing the identity conversion information based on the login jump request, and sends the login indication information containing the identity conversion information to the browser; and then the browser determines the identity conversion information in the login indication information as the target identity conversion information.
[0220] The process of simulating account login includes: the browser sends a target request containing target identity conversion information to the API gateway; the API gateway adds the login state identifier of the target identity conversion information to the target request and sends it to the first server 300; the first server 300 receives the target request with the login state identifier sent by the API gateway, allows the browser to log in using the identity information of the first account, and sends the information corresponding to the target request to the browser through the API gateway.
[0221] The interaction process among the browser, the API gateway, the first server 300 and the second server 400 in the above process may specifically include but is not limited to the following steps:
[0222] The first step: The browser obtains the target identity conversion information
[0223] See also Fig.13 , the process specifically includes:
[0224] After user B of the second account communicates with user A of the first account to obtain account query information of the first account, user B enters the URL of the second website into the browser and requests to open the second website.
[0225] Step S1301: The browser opens the second website based on the URL of the second website, and logs in to the second website using the identity information of the second account based on the instruction.
[0226] After user B logs in to the second website with the identity information of the second account, he will enter the account query information of the first account in the second website to obtain the simulated login jump link corresponding to the first account, and then user B clicks the simulated login jump link.
[0227] Step S1302: When the browser detects that the simulated login jump link of the first account is clicked, it sends a login jump request to the second server 400, where the login jump request carries the identity information of the first account.
[0228] Step S1303: The second server 400 obtains the identity information of the first account from the login jump request, and determines the identity information of the second account that triggers the login jump request.
[0229] Step S1304: The second server 400 generates identity conversion information including the identity information of the first account and the identity information of the second account.
[0230] Step S1305: the second server 400 stores the identity conversion information in a preset identity conversion information database.
[0231] Step S1306: the second server 400 creates login instruction information including identity conversion information, and sends the login instruction information to the browser.
[0232] Step S1307: The browser opens the second website based on the login instruction information.
[0233] Step S1308: The browser determines the identity conversion information in the login instruction information as the target identity conversion information, and stores the target identity conversion information in the cookie information corresponding to the first website.
[0234] Specifically, the front-end code of the first website running in the browser can obtain the identity conversion information from the login indication information, and store the obtained identity conversion information as the target identity conversion information in the cookie information corresponding to the first website.
[0235] Second process: Demo account login process
[0236] See also Fig.14 , specifically including the following steps:
[0237] Steps S1401 to S1403 are the same as the above-mentioned steps S1101 to S1103 and will not be repeated here.
[0238] Step S1404 : the API gateway accesses the identity conversion information library stored on the second server 400 through the target interface between the API gateway and the second server 400 .
[0239] Steps S1405 to S1408 are consistent with the above-mentioned steps S1105 to S1108. The specific contents can be found in the above description and will not be repeated here.
[0240] In the embodiment of the present application, the second account does not need to ask the first account for the login account and login password for logging into the first website, and can log in to the first website through the identity information of the first account, thereby improving the account security of the first account; and in the embodiment of the present application, there is no need to spend a lot of time to develop and improve the information query function of the target website (first website or second website), which reduces the development of additional functions of the target website, thereby improving the efficiency of simulated account login; on the other hand, in the embodiment of the present application, there is no perception of the business code of the first website, which reduces the degree of intrusion into the business code of the first website, thereby reducing the possibility of other unpredictable problems in the simulated account login, thereby reducing the security risks caused by the simulated account login to the first website.
[0241] Please refer to Fig.15 Based on the same inventive concept, the embodiment of the present application provides a device 1500 for simulating account login, including:
[0242] The request receiving unit 1501 is used to receive a target request sent by a terminal for logging into a first website;
[0243] The first processing unit 1502 is configured to obtain a login state identifier of the first account based on the target identity conversion information if it is determined that the target request includes target identity conversion information; wherein the target identity conversion information includes the identity information of the first account and the identity information of the second account, and the target identity conversion information is used to indicate that the second account requests to log in to the first website through the identity information of the first account, and the login state identifier is determined based on the identity information of the first account;
[0244] The second processing unit 1503 is used to add the login status identifier to the target request;
[0245] The request sending unit 1504 is used to send a target request for adding the login status identifier to the first website, so that the terminal logs in to the first website through the identity information of the first account based on the login status identifier.
[0246] As an embodiment, the first processing unit 1502 is specifically used to: obtain a mapping relationship between preset identity conversion information and a login state identifier; if the above mapping relationship records a login state identifier corresponding to the above target identity conversion information, then obtain the above login state identifier; if the above mapping relationship does not record a login state identifier corresponding to the above target identity conversion information, then based on the identity information of the above first account contained in the above target identity conversion information, generate a corresponding login state identifier, and create and save the mapping relationship between the above target identity conversion information and the generated login state identifier.
[0247] As an embodiment, the first processing unit 1502 is also used to: after determining that the target request contains target identity conversion information, before obtaining the login status identifier of the first account based on the target identity conversion information, access a preset identity conversion information library through the target interface; if the identity conversion information library stores identity conversion information matching the target identity conversion information, send a first prompt message to the terminal, and the first prompt message is used to indicate that the target request is abnormal; the identity conversion information matching the target identity conversion information is used to indicate that the second account requests to log in to the first website with the identity information of the first account.
[0248] As an embodiment, the request receiving unit 1501 is further configured to:
[0249] If it is determined that the target request does not include the target identity conversion information, and the target request does not include the login status identifier of the first account, sending second prompt information to the terminal, so that the terminal loads the login page of the first website based on the second prompt information;
[0250] If it is determined that the target request does not contain target identity conversion information, and the target request contains the login status identifier of the first account, the target request is sent to the first website, so that the terminal logs in to the first website based on the login status identifier of the first account and through the identity information of the first account.
[0251] As an example, Fig.15 The device in can be used to implement any of the simulated account login methods of the service management device 200 discussed above.
[0252] Please refer to Fig.16 Based on the same inventive concept, the embodiment of the present application provides a device 1600 for simulating account login, including:
[0253] The request receiving unit 1601 is used to receive a login jump request sent by a terminal, where the login jump request carries the identity information of the first account and is triggered by a simulated login instruction of the second account;
[0254] The first processing unit 1602 is used to determine the identity information of the second account that triggers the login jump request;
[0255] The second processing unit 1603 is used to generate identity conversion information including the identity information of the first account and the identity information of the second account, wherein the identity conversion information is used to indicate that the second account requests to log in to the first website with the identity information of the first account;
[0256] The information sending unit 1604 is used to return the login instruction information including the identity conversion information to the terminal, so that the terminal sends a target request including the identity conversion information, and the target request is used to enable the terminal to log in to the first website through the identity information of the first account.
[0257] As an embodiment, the second processing unit 1603 is also used to: store the above-mentioned identity conversion information in a preset identity conversion information library, so that after the service management device receives the above-mentioned target request, it determines whether to send a first prompt information to the above-mentioned terminal according to the above-mentioned identity conversion information, and the above-mentioned first prompt information is used to indicate that the above-mentioned target request is abnormal.
[0258] As an embodiment, the above-mentioned device is applied to an account registered on a second website other than the above-mentioned first website. The above-mentioned login jump request is sent after the above-mentioned terminal logs in to the above-mentioned second website through the above-mentioned second account. The above-mentioned login indication information is used to enable the above-mentioned terminal to open the above-mentioned first website and send the above-mentioned target request after opening the above-mentioned first website.
[0259] As an example, Fig.16 The device in can be used to implement any of the simulated account login methods discussed above for the first server 300 or the second server 400.
[0260] Please refer to Fig.17 Based on the same inventive concept, the embodiment of the present application provides a device 1700 for simulating account login, including:
[0261] The request sending unit 1701 is used to respond to the simulated login instruction of the second account and send a login jump request to the target website, wherein the login jump request carries the identity information of the first account, and the target website is the first website registered by the first account or a second website other than the first website;
[0262] An information receiving unit 1702 is used to receive the login indication information returned by the target website based on the login jump request;
[0263] The first processing unit 1703 is used to determine the identity conversion information included in the login instruction information as the target identity conversion information; the identity conversion information includes the identity information of the first account and the identity information of the second account, and the identity conversion information is used to indicate that the second account requests to log in to the first website with the identity information of the first account;
[0264] The second processing unit 1704 is configured to send a target request including the target identity conversion information to the service management device, so as to log in to the first website through the identity information of the first account based on the target identity conversion information.
[0265] As an embodiment, the target website is the second website, and the simulated login instruction is triggered after the terminal logs in to the second website through the second account; the information receiving unit 1702 is further used to:
[0266] After receiving the login indication information returned by the target website based on the login jump request, before sending the target request including the target identity conversion information to the service management device, the first website is opened based on the login indication information.
[0267] As an embodiment, the simulated login instruction is triggered by a target jump object corresponding to the first account, and the target jump object indicates a request to log in to the first website through the identity information of the first account.
[0268] As an example, Fig.17 The device in can be used to implement any of the simulated account login methods of the terminal 100 discussed above.
[0269] Based on the same inventive concept, an embodiment of the present application provides a terminal 100, which is introduced below.
[0270] Please refer to Fig.18 The above-mentioned target application, browser, etc. can be installed on the terminal 100, which includes a display unit 1840, a processor 1880 and a memory 1820, wherein the display unit 1840 includes a display panel 1841, which is used to display information input by the user or information provided to the user and various operation interfaces of the target application and the browser, etc. In the embodiment of the present application, it is mainly used to display the interface, shortcut window, etc. of the client installed in the terminal 100.
[0271] Optionally, the display panel 1841 may be configured in the form of a liquid crystal display (LCD) or an organic light-emitting diode (OLED).
[0272] The processor 1880 is used to read the computer program and then execute the method defined by the computer program. For example, the processor 1880 reads the application corresponding to the client, so as to run the application on the terminal 100 and display the interface of the application on the display unit 1840. The processor 1880 may include one or more general-purpose processors and may also include one or more DSPs (Digital Signal Processors) to perform related operations to implement the technical solutions provided in the embodiments of the present application.
[0273] The memory 1820 generally includes internal memory and external memory, and the internal memory may be a random access memory (RAM), a read-only memory (ROM), and a cache (CACHE), etc. The external memory may be a hard disk, an optical disk, a USB disk, a floppy disk, or a tape drive, etc. The memory 1820 is used to store computer programs and other data, and the computer program includes an application corresponding to the client, etc. Other data may include data generated after the operating system or the application is run, and the data includes system data (such as configuration parameters of the operating system) and user data. In the embodiment of the present application, program instructions are stored in the memory 1820, and the processor 1880 executes the program instructions in the memory 1820 to implement any method of simulating account login discussed in the previous figure.
[0274] The display unit 1840 is used to receive input digital information, character information or contact touch operation / contactless gesture, and generate signal input related to user settings and function control of the terminal 100. Specifically, in the embodiment of the present application, the display unit 1840 may include a display panel 1841. The display panel 1841 is, for example, a touch screen, which can collect the user's touch operation on or near it (such as the user's operation on the display panel 1841 or on the display panel 1841 using any suitable object or accessory such as a finger, stylus, etc.), and drive the corresponding connection device according to a pre-set program. Optionally, the display panel 1841 may include two parts: a touch detection device and a touch controller. Among them, the touch detection device detects the player's touch orientation, detects the signal brought by the touch operation, and transmits the signal to the touch controller; the touch controller receives the touch information from the touch detection device, converts it into contact point coordinates, and then sends it to the processor 1880, and can receive and execute commands sent by the processor 1880. In an embodiment of the present application, if the user clicks on the client, the touch detection device in the display panel 1841 detects a touch operation, and sends a signal corresponding to the detected touch operation to the touch controller. The touch controller converts the signal into touch point coordinates and sends them to the processor 1880. The processor 1880 determines the operation that the user needs to perform based on the received touch point coordinates.
[0275] The display panel 1841 may be implemented in various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the display unit 1840, the terminal 100 may further include an input unit 1830, which may include a graphic input device 1831 and other input devices 1832, wherein the other input devices may include, but are not limited to, one or more of a physical keyboard, a function key (such as a volume control key, a switch key, etc.), a trackball, a mouse, and a joystick.
[0276] In addition to the above, the terminal 100 may also include a power supply 1890 for supplying power to other modules, an audio circuit 1860, a near field communication module 1870, and an RF circuit 1810. The terminal 100 may also include one or more sensors 1850, such as an acceleration sensor, a light sensor, a pressure sensor, etc. The audio circuit 1860 specifically includes a speaker 1861 and a microphone 1862, etc. For example, the terminal 100 can collect the user's voice through the microphone 1862 and perform corresponding operations.
[0277] As an embodiment, the number of processors 1880 may be one or more, and the processor 1880 and the memory 1820 may be coupled or relatively independently configured.
[0278] As an example, Fig.18 The processor 1880 in can be used to implement the following Fig.17 The functions of the request sending unit 1701, the information receiving unit 1702, the first processing unit 1703 and the second processing unit 1704 are shown.
[0279] As an example, Fig.18 The processor 1880 in the embodiment can be used to implement the functions of the aforementioned terminal 100 or browser.
[0280] The above device 1500 is an example of a hardware entity. Fig.19 The computer device shown includes a processor 1901 , a storage medium 1902 , and at least one external communication interface 1903 ; the processor 1901 , the storage medium 1902 , and the external communication interface 1903 are all connected via a bus 1904 .
[0281] The storage medium 1902 stores a computer program;
[0282] When the processor 1901 executes the computer program, the simulated account login method of the service management device 200 discussed above is implemented.
[0283] Fig.19 In the figure, one processor 1901 is taken as an example, but the number of processors 1901 is not actually limited.
[0284] The storage medium 1902 may be a volatile memory, such as a random-access memory (RAM); the storage medium 1902 may also be a non-volatile memory, such as a read-only storage medium, a flash memory, a hard disk drive (HDD) or a solid-state drive (SSD), or the storage medium 1902 is any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The storage medium 1902 may be a combination of the above storage media.
[0285] The above device 1600 is an example of a hardware entity. Fig.19 The computer device shown, wherein Fig.19 When the computer device shown is used as the hardware entity of the apparatus 1600, the storage medium 1902 stores a computer program; when the processor 1901 executes the computer program, the method of simulating account login of the first server 300 or the second server 400 discussed above is implemented.
[0286] According to one aspect of the present application, a computer program product or a computer program is provided, the computer program product or the computer program including computer instructions, the computer instructions being stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes a live broadcast control method provided in an embodiment of the present application.
[0287] A person skilled in the art can understand that: all or part of the steps of implementing the above method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above method embodiment; and the aforementioned storage medium includes: mobile storage devices, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), disks or optical disks, etc. Various media that can store program codes.
[0288] Alternatively, if the above-mentioned integrated unit of the invention is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the embodiment of the present invention can be essentially or partly reflected in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium and includes several instructions for a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the above-mentioned methods of each embodiment of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROM, RAM, magnetic disks or optical disks.
[0289] Based on the same technical concept, the embodiment of the present application also provides a computer-readable storage medium, which stores computer instructions. When the above-mentioned computer instructions are executed on a computer, the computer executes the simulated account login method discussed above.
[0290] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0291] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.< / yyy> < / yyy> < / xxx> < / xxxx>
Claims
1. A method for logging into a simulated account, characterized in that: include: receiving a target request for logging into a first website sent by a terminal; If it is determined that the target request includes target identity conversion information, obtaining a login state identifier of the first account based on the target identity conversion information; wherein the target identity conversion information includes identity information of the first account and identity information of the second account, and the target identity conversion information is used to indicate that the second account requests to log in to the first website through the identity information of the first account, and the login state identifier is determined based on the identity information of the first account; Adding the login status identifier to the target request; A target request for adding the login status identifier is sent to the first website, so that the terminal logs in to the first website through the identity information of the first account based on the login status identifier.
2. The method according to claim 1, characterized in that The obtaining the login status identifier of the first account based on the target identity conversion information includes: Obtain the mapping relationship between the preset identity conversion information and the login state identifier; If the mapping relationship records a login state identifier corresponding to the target identity conversion information, obtaining the login state identifier; If the login state identifier corresponding to the target identity conversion information is not recorded in the mapping relationship, a corresponding login state identifier is generated based on the identity information of the first account contained in the target identity conversion information, and a mapping relationship between the target identity conversion information and the generated login state identifier is created and saved.
3. The method according to claim 1, characterized in that After determining that the target request includes the target identity conversion information and before obtaining the login state identifier of the first account based on the target identity conversion information, the method further includes: Access the preset identity conversion information library through the target interface; If the identity conversion information library does not store identity conversion information matching the target identity conversion information, a first prompt information is sent to the terminal, where the first prompt information is used to indicate that the target request is abnormal; the identity conversion information matching the target identity conversion information is used to indicate that the second account requests to log in to the first website with the identity information of the first account.
4. A method for logging into a simulated account, characterized in that: include: A login jump request sent by a receiving terminal is carried by the identity information of the first account, and the login jump request is triggered by a simulated login instruction of the second account; Determine identity information of a second account that triggers the login jump request; Generate identity conversion information including the identity information of the first account and the identity information of the second account, wherein the identity conversion information is used to indicate that the second account requests to log in to the first website using the identity information of the first account; Returning login instruction information including the identity conversion information to the terminal, so that the terminal sends a target request including the identity conversion information, wherein the target request is used to enable the terminal to log in to the first website through the identity information of the first account.
5. The method according to claim 4, characterized in that The method is applied to an account registered on a second website other than the first website. The login jump request is sent after the terminal logs in to the second website through the second account. The login indication information is used to enable the terminal to open the first website and send the target request after opening the first website.
6. A method for logging into a simulated account, characterized in that: include: In response to the simulated login instruction of the second account, a login jump request is sent to a target website, wherein the login jump request carries the identity information of the first account, and the target website is a first website registered by the first account or a second website other than the first website; Receiving login indication information returned by the target website based on the login jump request; Determine the identity conversion information included in the login instruction information as the target identity conversion information; the identity conversion information includes the identity information of the first account and the identity information of the second account, and the identity conversion information is used to indicate that the second account requests to log in to the first website with the identity information of the first account; A target request including the target identity conversion information is sent to a service management device, so as to log in to the first website through the identity information of the first account based on the target identity conversion information.
7. The method according to claim 6, characterized in that The target website is the second website, the simulated login instruction is triggered after the terminal logs in to the second website through the second account; after receiving the login instruction information returned by the target website based on the login jump request, before sending the target request containing the target identity conversion information to the service management device, it also includes: Based on the login instruction information, the first website is opened.
8. A device for simulating account login, characterized in that: include: A request receiving unit, configured to receive a target request sent by a terminal for logging into a first website; a first processing unit, configured to obtain a login state identifier of the first account based on the target identity conversion information if it is determined that the target request includes target identity conversion information; wherein the target identity conversion information includes the identity information of the first account and the identity information of the second account, and the target identity conversion information is used to indicate that the second account requests to log in to the first website through the identity information of the first account, and the login state identifier is determined based on the identity information of the first account; A second processing unit, configured to add the login status identifier to the target request; The request sending unit is used to send a target request for adding the login status identifier to the first website, so that the terminal logs in to the first website through the identity information of the first account based on the login status identifier.
9. A device for simulating account login, characterized in that: include: A request receiving unit, configured to receive a login jump request sent by a terminal, wherein the login jump request carries identity information of a first account and is triggered by a simulated login instruction of a second account; A first processing unit, configured to determine identity information of a second account that triggers the login redirect request; a second processing unit, configured to generate identity conversion information including the identity information of the first account and the identity information of the second account, wherein the identity conversion information is used to indicate that the second account requests to log in to the first website using the identity information of the first account; The information sending unit is used to return login instruction information containing the identity conversion information to the terminal, so that the terminal sends a target request containing the identity conversion information, and the target request is used to enable the terminal to log in to the first website through the identity information of the first account.
10. A device for simulating account login, characterized in that: include: a request sending unit, configured to respond to the simulated login instruction of the second account and send a login jump request to a target website, wherein the login jump request carries the identity information of the first account, and the target website is a first website registered by the first account or a second website other than the first website; An information receiving unit, configured to receive login indication information returned by the target website based on the login jump request; A first processing unit is configured to determine the identity conversion information included in the login instruction information as target identity conversion information; the identity conversion information includes the identity information of the first account and the identity information of the second account, and the identity conversion information is used to indicate that the second account requests to log in to the first website with the identity information of the first account; The second processing unit is configured to send a target request including the target identity conversion information to a service management device, so as to log in to the first website through the identity information of the first account based on the target identity conversion information.
Citation Information
Patent Citations
Account login method, device and system
CN104735021A
Method and device for automatic registration between multiple websites
CN107359996A