Multi-party system mutual trust authentication method and device
By extracting and matching browser fingerprint information on the browser side and using authorization tokens to achieve mutual trust authentication between multiple systems, the user privacy leakage problem of the single sign-on model between loosely coupled systems is solved, and security and universality are improved.
Patent Information
- Application Number
- CN202111397556.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-23
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2041-11-23
AI Technical Summary
The existing single sign-on model has the risk of user privacy leakage and security is difficult to guarantee in the mutual trust scenario between multiple loosely coupled third-party application systems, and is not suitable for the mutual trust scenario between multiple loosely coupled third-party application systems.
By extracting and matching the user's browser fingerprint information on the browser side, mutual trust authentication between multiple systems is achieved using authorization tokens, user information sharing is avoided, and browser fingerprint information is used to verify whether the login operation is for the same user and the same browser.
It effectively protects user privacy and ensures information security. It is suitable for mutual trust scenarios of multiple loosely coupled third-party application systems, and improves the security and universality of mutual trust authentication between multiple systems.
Smart Images

Figure CN114090996B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing technology, and in particular to a multi-party system mutual trust authentication method and device. Background Art
[0002] This section is intended to provide a background or context to the embodiments of the invention that are recited in the claims. No statement herein is admitted to be prior art by virtue of its inclusion in this section.
[0003] Publicly available web services often rely on collaboration between systems from multiple vendors. Currently, a Single Sign-On (SSO) model is often used to achieve mutual trust and authentication between systems.
[0004] The widely used single sign-on model mentioned above solves the problem of users being able to access other authorized, mutually trusted application systems with a single login. However, this model uses centralized, unified authentication management and requires sharing user information across multiple systems. Due to the significant disparity in user systems between some third-party systems, it is not suitable for scenarios involving loosely coupled, mutually trusted third-party application systems and has limitations. Furthermore, the frequent sharing of user information across multiple systems is not conducive to protecting user privacy, and the security of this information sharing process is difficult to guarantee. Summary of the Invention
[0005] An embodiment of the present invention provides a multi-party system mutual trust authentication method, which is applied to a browser to improve the security and universality of mutual trust authentication between multi-party systems. The method includes:
[0006] Receiving: a user inputs an access request to the second system on a page of the first system;
[0007] Extracting first browser fingerprint information of the time period when the user logs into the first system; sending the first browser fingerprint information to the second system via the first system; the first system is used to send application information requesting an authorization token to the second system; the second system is used to send the authorization token to the first system after approving the application information; the first system is used to generate a directional link carrying the authorization token; the directional link is used to jump to a page of the second system;
[0008] Loading the directed link sent by the first system, and sending the access request to the second system via the directed link;
[0009] Extracting the second browser fingerprint information when sending the access request to the second system; sending the second browser fingerprint information to the second system; the second system is further configured to authorize the access request when determining that the first browser fingerprint information and the second browser fingerprint information match, thereby confirming that mutual trust authentication between the first system and the second system has been successful;
[0010] After the second system authorizes the access request, the page of the second system is displayed.
[0011] An embodiment of the present invention further provides a multi-party system mutual trust authentication device, which is applied to a browser side to improve the security and universality of mutual trust authentication between multi-party systems. The device includes:
[0012] An access request receiving module, configured to receive: an access request for a second system input by a user on a page of the first system;
[0013] The first browser fingerprint information extraction module is configured to extract the first browser fingerprint information of the time period during which the user logs into the first system; transmit the first browser fingerprint information to the second system via the first system; the first system is configured to transmit an application requesting an authorization token to the second system; the second system is configured to transmit the authorization token to the first system after approving the application; the first system is configured to generate a directional link carrying the authorization token; the directional link is configured to redirect to a page in the second system;
[0014] a directional link loading module, configured to load the directional link sent by the first system and send an access request to the second system via the directional link;
[0015] The second browser fingerprint information extraction module is configured to extract the second browser fingerprint information when sending the access request to the second system; and send the second browser fingerprint information to the second system; and the second system is further configured to authorize the access request and confirm that mutual trust authentication between the first system and the second system has been successful when determining that the first browser fingerprint information and the second browser fingerprint information match.
[0016] The second system page display module is used to display the page of the second system after the second system authorizes the access request.
[0017] An embodiment of the present invention further provides a multi-party system mutual trust authentication method, which is applied to a first system to improve the security and universality of mutual trust authentication between multi-party systems. The method includes:
[0018] When confirming that the user has the authority to log in to the first system, authorizing the user's login request to the first system;
[0019] Receive and issue an access request to the second system input by the user on the page of the first system;
[0020] Receiving the first browser fingerprint information of the time period when the user logs into the first system extracted by the browser, and forwarding it to the second system;
[0021] Sending an application requesting an authorization token to the second system; the second system is configured to send the authorization token to the first system after approving the application;
[0022] Based on the authorization token received from the second system, a directional link carrying the authorization token is generated and issued; the directional link is used for the browser to jump to the page of the second system; the browser is also used to: extract the second browser fingerprint information when sending the access request to the second system; send the second browser fingerprint information to the second system; the second system is also used to authorize the access request when it is determined that the first browser fingerprint information and the second browser fingerprint information match, confirming that the mutual trust authentication between the first system and the second system has passed; after the second system authorizes the access request, the page of the second system is displayed.
[0023] An embodiment of the present invention further provides a multi-party system mutual trust authentication device, which is applied to a first system to improve the security and universality of mutual trust authentication between multi-party systems. The device includes:
[0024] A login request authorization module, configured to authorize a user's login request to the first system when confirming that the user has the authority to log in to the first system;
[0025] An access request receiving module, configured to receive and issue an access request to the second system input by a user on a page of the first system;
[0026] A first browser fingerprint information forwarding module is used to receive the first browser fingerprint information of the time period when the user logs into the first system extracted by the browser, and forward it to the second system;
[0027] An application information sending module, configured to send application information requesting an authorization token to the second system; the second system is configured to send the authorization token to the first system after approving the application information;
[0028] The directional link generation module is configured to generate and issue a directional link carrying an authorization token based on an authorization token received from a second system; the directional link is used for a browser to jump to a page of the second system; the browser is further configured to: extract the second browser fingerprint information when sending an access request to the second system; send the second browser fingerprint information to the second system; the second system is further configured to authorize the access request when determining that the first browser fingerprint information and the second browser fingerprint information match, confirming that mutual trust authentication between the first system and the second system has been passed; and display the page of the second system after the second system authorizes the access request.
[0029] An embodiment of the present invention further provides a multi-party system mutual trust authentication method, which is applied to the second system to improve the security and universality of mutual trust authentication between the multi-party systems. The method includes:
[0030] Receiving first browser fingerprint information extracted by the browser and forwarded by the first system; the browser is used to receive: an access request for the second system input by a user on a page of the first system; extracting the first browser fingerprint information of the time period when the user logged into the first system; forwarding the first browser fingerprint information via the first system; the first system is used to send application information requesting an authorization token to the second system;
[0031] Verifying the application information received from the first system and, if the verification is successful, sending the authorization token to the first system; the first system is used to generate a directional link carrying the authorization token; the directional link is used to jump to a page of the second system; the browser is further used to: load the directional link sent by the first system and send an access request to the second system via the directional link; and extract the second browser fingerprint information when sending the access request to the second system;
[0032] Receiving second browser fingerprint information sent by the browser;
[0033] When it is determined that the first browser fingerprint information matches the second browser fingerprint information, the access request is authorized to confirm that the mutual trust authentication between the first system and the second system is passed; the browser end is also used to display the page of the second system after the second system authorizes the access request.
[0034] An embodiment of the present invention further provides a multi-party system mutual trust authentication device, which is applied to the second system to improve the security and universality of mutual trust authentication between the multi-party systems. The device includes:
[0035] The first system communication module is configured to receive first browser fingerprint information extracted by the browser and forwarded by the first system; the browser is configured to receive: an access request for the second system entered by a user on a page of the first system; extract the first browser fingerprint information of the time period during which the user logged into the first system; forward the first browser fingerprint information via the first system; and the first system is configured to send an application requesting an authorization token to the second system;
[0036] The application information verification module is used to verify the application information received from the first system and, if the verification is successful, send the authorization token to the first system; the first system is used to generate a directional link carrying the authorization token; the directional link is used to jump to a page of the second system; the browser is further used to: load the directional link sent by the first system and send an access request to the second system via the directional link; and extract the second browser fingerprint information when sending the access request to the second system;
[0037] The browser communication module is used to receive the second browser fingerprint information sent by the browser;
[0038] The fingerprint information matching module is used to authorize the access request and confirm that the mutual trust authentication between the first system and the second system has passed when it is determined that the fingerprint information of the first browser matches the fingerprint information of the second browser; the browser end is also used to display the page of the second system after the second system authorizes the access request.
[0039] An embodiment of the present invention further provides a computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the multi-party system mutual trust authentication method when executing the computer program.
[0040] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the computer program implements the above-mentioned multi-party system mutual trust authentication method.
[0041] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the above-mentioned multi-party system mutual trust authentication method.
[0042] In an embodiment of the present invention, the following steps are performed: receiving an access request to a second system input by a user on a page of a first system; extracting first browser fingerprint information of the time period when the user logs into the first system; sending the first browser fingerprint information to the second system via the first system; the first system is used to send application information requesting an authorization token to the second system; the second system is used to send the authorization token to the first system after approving the application information; the first system is used to generate a directional link carrying the authorization token; the directional link is used to jump to a page of the second system; loading the directional link sent by the first system, and sending the access request to the second system via the directional link; extracting second browser fingerprint information when sending the access request to the second system; sending the second browser fingerprint information to the second system; the second system is also used to determine the first browser fingerprint information and the second browser fingerprint information. When the browser fingerprint information matches, the access request is authorized to confirm that the mutual trust authentication between the first system and the second system is passed; after the second system authorizes the access request, the page of the second system is displayed. Compared with the technical solution of realizing mutual trust authentication between systems based on the single sign-on model in the existing technology, the mutual trust authentication between multiple systems can be effectively realized through the interaction of authorization tokens between the first system and the second system, which solves the problem of user privacy leakage that is easily caused by the need to share identity information for mutual trust authentication between systems under the existing technology, which is conducive to protecting user privacy and ensuring user information security; at the same time, since centralized and unified authentication management is no longer required, it can be applied to the mutual trust scenarios of multiple loosely coupled third-party application systems, and has high universality; further, the extraction of browser fingerprint information can help verify whether the login operations of different systems are the same user and the same browser, effectively ensuring the security of mutual trust authentication between multiple systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0043] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative work. In the drawings:
[0044] Figure 1 Schematic diagram of a multi-party system mutual trust authentication method according to an embodiment of the present invention;
[0045] Figure 2 This is a schematic diagram of the structure of a multi-party system mutual trust authentication device according to an embodiment of the present invention;
[0046] Figure 3 Schematic diagram of a multi-party system mutual trust authentication method according to an embodiment of the present invention;
[0047] Figure 4This is a schematic diagram of the structure of a multi-party system mutual trust authentication device according to an embodiment of the present invention;
[0048] Figure 5 Schematic diagram of a multi-party system mutual trust authentication method according to an embodiment of the present invention;
[0049] Figure 6 This is a schematic diagram of the structure of a multi-party system mutual trust authentication device according to an embodiment of the present invention;
[0050] Figure 7 This is a specific example diagram of a multi-party system mutual trust authentication method according to an embodiment of the present invention;
[0051] Figure 8 This is a specific example diagram of a multi-party system mutual trust authentication method according to an embodiment of the present invention;
[0052] Figure 9 This is a specific example diagram of a multi-party system mutual trust authentication method according to an embodiment of the present invention;
[0053] Figure 10 Schematic diagram of a computer device used for multi-party system mutual trust authentication in an embodiment of the present invention. DETAILED DESCRIPTION
[0054] To make the purpose, technical solutions and advantages of the embodiments of the present invention more clear, the embodiments of the present invention are further described in detail below with reference to the accompanying drawings. Here, the exemplary embodiments of the present invention and their descriptions are used to explain the present invention, but are not intended to limit the present invention.
[0055] The embodiments of the present invention involve the following terms, which are explained as follows:
[0056] Mutual trust authentication: With the development of the Internet, public-facing Internet services provided by banks and other companies often require the collaboration of systems from multiple suppliers. Users often need to access services provided by other systems B (hereinafter referred to as target mutual trust systems) from the pages of the logged-in system A (hereinafter referred to as the original system A). In order to meet the needs of these system services to verify the identity and operation permissions of the current user, the original system A and the target mutual trust system need to interact and collaborate to confirm the user's identity and operation permissions, which is mutual trust authentication.
[0057] Browser fingerprinting: This technology uses multi-dimensional information to describe and locate browsers. This technology uses the browser's developer interface to directly or indirectly extract browser information, such as browser plug-ins, fonts, time zones, operating systems, and image rendering features. This information varies between different browsers used by different users, and the probability of two identical pieces of information is very low. When fingerprint information differs, it can be determined that they are not from the same browser.
[0058] Currently, an increasing number of public-facing web services rely on the collaborative work of multiple vendors' systems. Designing an identity authentication method suitable for mutually trusted systems in open platform environments is of vital practical significance. The widely used Single Sign-On (SSO) model solves the problem of users being able to access other authorized, mutually trusted application systems with a single login. However, the SSO model utilizes centralized, unified authentication management and requires user information to be shared across multiple systems. Due to the significant disparity in user systems between some third-party systems, it is not suitable for scenarios involving loosely coupled, mutually trusted third-party application systems.
[0059] The widely used single sign-on model mentioned above solves the problem of users being able to access other authorized, mutually trusted application systems with a single login. However, this model uses centralized, unified authentication management and requires sharing user information across multiple systems. Due to the significant disparity in user systems between some third-party systems, it is not suitable for scenarios involving loosely coupled, mutually trusted third-party application systems and has limitations. Furthermore, the frequent sharing of user information across multiple systems is not conducive to protecting user privacy, and the security of this information sharing process is difficult to guarantee.
[0060] In order to solve the above problems, the embodiment of the present invention provides a multi-party system mutual trust authentication method, which is applied to the browser side to improve the security and universality of the mutual trust authentication between multi-party systems. Figure 1 As shown, the method includes:
[0061] Step 101: receiving a request for accessing a second system input by a user on a page of a first system;
[0062] Step 102: Extracting first browser fingerprint information of the time period when the user logs into the first system; sending the first browser fingerprint information to the second system via the first system; the first system is used to send an application requesting an authorization token to the second system; the second system is used to send the authorization token to the first system after approving the application; the first system is used to generate a directional link carrying the authorization token; the directional link is used to jump to a page of the second system;
[0063] Step 103: Load the directional link sent by the first system, and send the access request to the second system via the directional link;
[0064] Step 104: Extracting the second browser fingerprint information when sending the access request to the second system; sending the second browser fingerprint information to the second system; the second system is further configured to authorize the access request upon determining that the first browser fingerprint information and the second browser fingerprint information match, thereby confirming that mutual trust authentication between the first system and the second system has been successful;
[0065] Step 105: After the second system authorizes the access request, a page of the second system is displayed.
[0066] During specific implementation, first receiving: an access request to the second system input by a user in a page of the first system.
[0067] In an embodiment, the first system may be the system that the user has currently logged into on the browser side, and the second system may be another system that the user clicks on the page of the current first system to log into, that is, the target mutual trust system.
[0068] In specific implementation, after receiving: a user inputs an access request to the second system on a page of the first system, extracting the first browser fingerprint information of the time period when the user logs into the first system; sending the first browser fingerprint information to the second system via the first system; the first system is used to send application information requesting an authorization token to the second system; the second system is used to send the authorization token to the first system after approving the application information; the first system is used to generate a directional link carrying the authorization token; the directional link is used to jump to the page of the second system.
[0069] In an embodiment, sending the first browser fingerprint information to the second system via the first system may include:
[0070] generating a binary sequence corresponding to the first browser fingerprint information;
[0071] The binary sequence corresponding to the first browser fingerprint information is sent to the second system via the first system.
[0072] In the above embodiment, the first browser fingerprint information includes user identity information;
[0073] The first system is further configured to: determine, based on the user information, whether the user has the authority to access the second system; request an authorization token from the second system if it is determined that the user has the authority to access the second system; and issue an alarm indicating that the user does not have the authority to access the second system if it is determined that the user does not have the authority to access the second system;
[0074] The above-mentioned multi-party system mutual trust authentication may also include:
[0075] Receive and display the alarm information sent by the first system.
[0076] In one embodiment, the above-mentioned step of extracting the first browser fingerprint information can be executed in the user's browser. The extracted browser fingerprint information may include the user's identity token information and browser fingerprint features. The browser fingerprint features may include browser version information, operating system information, network address, language, screen color depth, screen resolution, whether some features of HTML5 are supported, plug-ins, Canvas fingerprints, WebGL fingerprints, fonts, voiceprints, etc., a total of 43 fingerprint features that can identify the visitor's identity information.
[0077] Canvas fingerprint and WebGL fingerprint are fingerprint information extracted from the browser's drawing capabilities. Canvas is a drawing function based on the browser, and it can be used to create some simple drawing functions. The drawing results will vary from browser to browser, so Canvas fingerprint can be used as a fingerprint information to identify the browser.
[0078] WebGL fingerprint is a drawing operation based on Canvas, which can perform more complex image drawing functions. Since the WebGL engine version information and drawing results are different in different browsers, this information can also be used as one of the fingerprint information to identify the browser.
[0079] In the above embodiment, since the extracted browser fingerprint information is multi-dimensional, in order to facilitate the determination of whether two browser fingerprints belong to the same browser in subsequent steps, a binary conversion algorithm can be used to convert the multi-dimensional browser fingerprint information into a binary sequence, and the binary sequence should meet the condition of not being easy to forge.
[0080] There is also a method in the existing technology to achieve mutual trust authentication between systems, such as the authentication method based on the OAuth2.0 protocol, which aims to solve the authorization relationship between users, service providers and third-party applications. The authorization process is as follows:
[0081] 1. The user needs to access the third-party system from the current system page;
[0082] 2. The third-party system needs to request a temporary token from the service provider;
[0083] 3. After the third-party system obtains this temporary token, the user is directed to the service provider's authorization page;
[0084] 4. After successful authorization, the user is directed to the return address provided by the third-party application website;
[0085] 5. The third-party application uses the temporary token obtained from the service provider to exchange for an access token from the service provider;
[0086] 6. The service provider then grants the corresponding access token to the third-party application based on the temporary token submitted by the third-party application and the user's authorization.
[0087] 7. The third-party application returns operational user resources with the access token obtained from the service provider.
[0088] As can be seen, the OAuth 2.0 protocol addresses the problem of users allowing third-party systems to access resources stored by users with service providers. Multi-party mutual-trust authentication, on the other hand, addresses the problem of allowing users of a service provider to access the resources of a mutually trusted application. The two objectives differ. Furthermore, when relying on tokens for authentication, if a user redirects a new address returned by a third-party application, and if the new address is forwarded to others or intercepted by a malicious third party, there is no guarantee that the operator and the operation scenario are from the same user. This poses a high security risk for services with high security requirements (such as transfers and payments).
[0089] To solve the above problem, in a specific implementation of an embodiment of the present invention, first browser fingerprint information of the time period when a user logs into a first system is extracted; after the first browser fingerprint information is sent to a second system via the first system, a directional link sent by the first system is loaded, and an access request is sent to the second system via the directional link; second browser fingerprint information when the access request is sent to the second system is extracted; and the second browser fingerprint information is sent to the second system. The second system is further configured to authorize the access request upon determining that the first browser fingerprint information and the second browser fingerprint information match, thereby confirming that mutual trust authentication between the first and second systems has been successful.
[0090] In an embodiment, the second system is further configured to: receive an authorization token carried in an access request sent by a browser via a directed link; verify the validity of the authorization token carried in the access request, and, if the validity verification passes, issue a notification message for extracting the second browser fingerprint information;
[0091] Extracting the second browser fingerprint information may include:
[0092] When the notification information sent by the second system is received, the second browser fingerprint information is extracted.
[0093] In the above embodiment, the second system is further configured to: when the validity verification of the authorization token fails, issue an alarm indicating that the authorization token carried in the access request has expired, and terminate the mutual trust authentication between the first system and the second system;
[0094] The above-mentioned multi-party system mutual trust authentication may also include:
[0095] Receive and display the alarm information sent by the second system.
[0096] In the above embodiment, through the interaction of authorization tokens between the first system and the second system, mutual trust authentication between multiple systems can be effectively achieved, which solves the problem of user privacy leakage that is easily caused by the need to share identity information for mutual trust authentication between systems under the existing technology, is conducive to protecting user privacy and ensuring user information security.
[0097] Compared to existing solutions for achieving inter-system mutual trust authentication based on the OAuth 2.0 protocol, these solutions require a unified mutual trust authentication system, with which all systems must establish connections. This presents significant challenges and implementation risks for third-party systems. Token-based verification, with certain restrictions on token validity, can protect sensitive information such as usernames and passwords from being transmitted between systems. However, mutual trust jump links and tokens still pose the risk of being forwarded or intercepted. For high-security applications, it's impossible to ensure that mutual trust link jumps are performed by the same operator on the same operating device. The embodiments of the present invention, however, eliminate the need for centralized authentication management and are therefore applicable to inter-system mutual trust scenarios involving multiple loosely coupled third-party application systems. This approach offers high universal applicability. Because a unified authentication system is not required, secure channels are established between mutual trust systems to bind trusted domains. Inter-system mutual trust, in addition to token verification, incorporates browser fingerprint verification to ensure that mutual trust link jumps between systems are performed by the same operator on the same operating device, thus ensuring security.
[0098] In a specific implementation, the second browser fingerprint information is extracted when the access request is sent to the second system; after the second browser fingerprint information is sent to the second system, the page of the second system is displayed after the second system authorizes the access request.
[0099] In the above embodiment, the extraction of browser fingerprint information can help verify whether the login operations of different systems are performed by the same user and the same browser, effectively ensuring the security of mutual trust authentication between multiple systems.
[0100] In an embodiment of the present invention, the following steps are performed: receiving an access request to a second system input by a user on a page of a first system; extracting first browser fingerprint information of the time period when the user logs into the first system; sending the first browser fingerprint information to the second system via the first system; the first system is used to send application information requesting an authorization token to the second system; the second system is used to send the authorization token to the first system after approving the application information; the first system is used to generate a directional link carrying the authorization token; the directional link is used to jump to a page of the second system; loading the directional link sent by the first system, and sending the access request to the second system via the directional link; extracting second browser fingerprint information when sending the access request to the second system; sending the second browser fingerprint information to the second system; the second system is also used to determine the first browser fingerprint information and the second browser fingerprint information. When the browser fingerprint information matches, the access request is authorized to confirm that the mutual trust authentication between the first system and the second system is passed; after the second system authorizes the access request, the page of the second system is displayed. Compared with the technical solution of realizing mutual trust authentication between systems based on the single sign-on model in the existing technology, the mutual trust authentication between multiple systems can be effectively realized through the interaction of authorization tokens between the first system and the second system, which solves the problem of user privacy leakage that is easily caused by the need to share identity information for mutual trust authentication between systems under the existing technology, which is conducive to protecting user privacy and ensuring user information security; at the same time, since centralized and unified authentication management is no longer required, it can be applied to the mutual trust scenarios of multiple loosely coupled third-party application systems, and has high universality; further, the extraction of browser fingerprint information can help verify whether the login operations of different systems are the same user and the same browser, effectively ensuring the security of mutual trust authentication between multiple systems.
[0101] Compared with the prior art that relies on cookies for mutual trust authentication between systems, the prior art can return a cookie in the first system page under the same domain (the two pages have the same protocol, domain name, and port), and carry the cookie for verification in the second page to ensure that it is the same browser. However, cookies can be disabled on the browser side, and the cross-domain problem cannot be solved. The method provided in the embodiment of the present invention can be applied to mutual trust authentication between multiple systems with browser fingerprint verification. On the basis of using authorization token authentication, the purpose of auxiliary verification of operating users and scenarios (browsers) is achieved through the application of browser fingerprint recognition technology. Since there is no need for a unified authentication center, there is no need for multiple systems to be in the same domain, it does not rely on browser cookies and supports cross-domain, effectively realizing a mutual trust system for the same user in multiple information interaction systems.
[0102] The present invention also provides a multi-party system mutual trust authentication device, as described in the following embodiments. Since the principle of the device is similar to that of the multi-party system mutual trust authentication method, the implementation of the device can refer to the implementation of the multi-party system mutual trust authentication method, and the repeated parts will not be repeated.
[0103] The embodiment of the present invention also provides a multi-party system mutual trust authentication device, which is applied to the browser side to improve the security and universality of the mutual trust authentication between multiple systems. Figure 2 As shown, the device includes:
[0104] The access request receiving module 201 is configured to receive: an access request for a second system input by a user on a page of the first system;
[0105] The first browser fingerprint information extraction module 202 is configured to extract the first browser fingerprint information of the time period during which the user logs into the first system; transmit the first browser fingerprint information to the second system via the first system; the first system transmits an application requesting an authorization token to the second system; the second system transmits the authorization token to the first system after approving the application; the first system generates a directional link carrying the authorization token; the directional link is used to redirect to a page in the second system;
[0106] A directional link loading module 203 is configured to load the directional link sent by the first system and send an access request to the second system via the directional link;
[0107] The second browser fingerprint information extraction module 204 is configured to extract the second browser fingerprint information when sending the access request to the second system; and to send the second browser fingerprint information to the second system. The second system is further configured to authorize the access request upon determining that the first browser fingerprint information and the second browser fingerprint information match, thereby confirming that mutual trust authentication between the first system and the second system has been successful.
[0108] The second system page display module 205 is configured to display the page of the second system after the second system authorizes the access request.
[0109] In one embodiment, the first browser fingerprint information extraction module is specifically configured to:
[0110] generating a binary sequence corresponding to the first browser fingerprint information;
[0111] The binary sequence corresponding to the first browser fingerprint information is sent to the second system via the first system.
[0112] In one embodiment, the first browser fingerprint information includes user identity information;
[0113] The first system is further configured to: determine, based on the user information, whether the user has the authority to access the second system; request an authorization token from the second system if it is determined that the user has the authority to access the second system; and issue an alarm indicating that the user does not have the authority to access the second system if it is determined that the user does not have the authority to access the second system;
[0114] The above device may further include a first system alarm information receiving and displaying module, configured to:
[0115] Receive and display the alarm information sent by the first system.
[0116] In one embodiment, the second system is further configured to: receive an authorization token carried in an access request sent by a browser via a directed link; verify the validity of the authorization token carried in the access request, and, if the validity verification passes, issue a notification message for extracting the second browser fingerprint information;
[0117] The second browser fingerprint information extraction module is used to:
[0118] When the notification information sent by the second system is received, the second browser fingerprint information is extracted.
[0119] In one embodiment, the second system is further configured to: when the validity verification of the authorization token fails, issue an alarm indicating that the authorization token carried in the access request has expired, and terminate the mutual trust authentication between the first system and the second system;
[0120] The above device may further include a second system alarm information receiving and displaying module, configured to:
[0121] Receive and display the alarm information sent by the second system.
[0122] The embodiment of the present invention also provides a multi-party system mutual trust authentication method, which is applied to the first system to improve the security and universality of the mutual trust authentication between the multi-party systems. Figure 3 As shown, the method includes:
[0123] Step 301: When confirming that the user has the authority to log in to the first system, authorize the user's login request to the first system;
[0124] Step 302: Receive and issue an access request to the second system input by the user in the first system's page;
[0125] Step 303: receiving the first browser fingerprint information of the time period when the user logs into the first system extracted by the browser, and forwarding it to the second system;
[0126] Step 304: Sending an application requesting an authorization token to the second system; the second system is configured to send the authorization token to the first system after approving the application;
[0127] Step 305: Based on the authorization token received from the second system, a directional link carrying the authorization token is generated and issued; the directional link is used for the browser to jump to the page of the second system; the browser is further used to: extract the second browser fingerprint information when sending the access request to the second system; send the second browser fingerprint information to the second system; the second system is further used to authorize the access request when it is determined that the first browser fingerprint information and the second browser fingerprint information match, confirming that the mutual trust authentication between the first system and the second system has passed; after the second system authorizes the access request, the page of the second system is displayed.
[0128] In an embodiment of the present invention, when it is confirmed that the user has the authority to log in to the first system, the user's login request to the first system is authorized; an access request to the second system input by the user on the page of the first system is received and issued; first browser fingerprint information of the time period when the user logs in to the first system is received and forwarded to the second system; application information requesting an authorization token is sent to the second system; the second system is used to send the authorization token to the first system after approving the application information; based on the authorization token received from the second system, a directional link carrying the authorization token is generated and issued; the directional link is used for the browser to jump to the page of the second system; the browser is also used to: extract the second browser fingerprint information when sending the access request to the second system; send the second browser fingerprint information to the second system; the second system is also used to determine the first browser fingerprint information and the second browser fingerprint information. When the fingerprint information of the two browsers matches, the access request is authorized to confirm that the mutual trust authentication between the first system and the second system is passed; after the second system authorizes the access request, the page of the second system is displayed. Compared with the technical solution of realizing mutual trust authentication between systems based on the single sign-on model in the existing technology, the mutual trust authentication between multiple systems can be effectively realized through the interaction of authorization tokens between the first system and the second system, which solves the problem of user privacy leakage that is easily caused by the need to share identity information for mutual trust authentication between systems under the existing technology, which is conducive to protecting user privacy and ensuring user information security; at the same time, since centralized and unified authentication management is no longer required, it can be applied to the mutual trust scenarios of multiple loosely coupled third-party application systems, and has high universality; further, the extraction of browser fingerprint information can help verify whether the login operations of different systems are the same user and the same browser, effectively ensuring the security of mutual trust authentication between multiple systems.
[0129] In a specific implementation, the above-mentioned browser is further used to: generate a binary sequence corresponding to the first browser fingerprint information;
[0130] Receiving first browser fingerprint information extracted by the browser and forwarding it to the second system may include:
[0131] A binary sequence corresponding to the first browser fingerprint information generated by the browser is received and forwarded to the second system.
[0132] In a specific implementation, the first browser fingerprint information includes user identity information;
[0133] The above-mentioned multi-party system mutual trust authentication may also include:
[0134] Determining, based on the user information, whether the user has the authority to access the second system; and requesting an authorization token from the second system when it is determined that the user has the authority to access the second system;
[0135] When it is determined that the user does not have the authority to access the second system, an alarm message is issued indicating that the user does not have the authority to access the second system;
[0136] The above browsers are also used for:
[0137] Receive and display notification information or alarm information sent by the first system.
[0138] The embodiment of the present invention also provides a multi-party system mutual trust authentication device, which is applied to the first system to improve the security and universality of the mutual trust authentication between the multi-party systems. Figure 4 As shown, the device includes:
[0139] The login request authorization module 401 is used to authorize the user's login request to the first system when confirming that the user has the authority to log in to the first system;
[0140] The access request receiving module 402 is configured to receive and issue an access request to the second system input by a user on a page of the first system;
[0141] The first browser fingerprint information forwarding module 403 is configured to receive the first browser fingerprint information of the time period when the user logs into the first system extracted by the browser, and forward it to the second system;
[0142] The application information sending module 404 is used to send application information requesting an authorization token to the second system; the second system is used to send the authorization token to the first system after approving the application information;
[0143] The directional link generation module 405 is configured to generate and issue a directional link carrying the authorization token based on the authorization token received from the second system. The directional link is used to allow the browser to jump to a page on the second system. The browser is further configured to: extract the second browser fingerprint information when sending an access request to the second system; send the second browser fingerprint information to the second system; the second system is further configured to authorize the access request upon determining that the first browser fingerprint information and the second browser fingerprint information match, thereby confirming that mutual trust authentication between the first and second systems has been successful; and after the second system authorizes the access request, display the page on the second system.
[0144] In one embodiment, the browser is further configured to: generate a binary sequence corresponding to the first browser fingerprint information;
[0145] The first browser fingerprint information forwarding module is specifically used to:
[0146] A binary sequence corresponding to the first browser fingerprint information generated by the browser is received and forwarded to the second system.
[0147] In one embodiment, the first browser fingerprint information includes user identity information;
[0148] The above device may further include a user authority determination module, configured to:
[0149] Determining, based on the user information, whether the user has the authority to access the second system; and requesting an authorization token from the second system when it is determined that the user has the authority to access the second system;
[0150] When it is determined that the user does not have the authority to access the second system, an alarm message is issued indicating that the user does not have the authority to access the second system;
[0151] The above browsers are also used for:
[0152] Receive and display notification information or alarm information sent by the first system.
[0153] The embodiment of the present invention also provides a multi-party system mutual trust authentication method, which is applied to the second system to improve the security and universality of the mutual trust authentication between the multi-party systems. Figure 5 As shown, the method includes:
[0154] Step 501: Receive first browser fingerprint information extracted by the browser and forwarded by the first system. The browser is configured to receive: a user's access request to a second system entered on a page of the first system; extract the first browser fingerprint information of the time period during which the user logged into the first system; forward the first browser fingerprint information via the first system; and the first system is configured to send an application requesting an authorization token to the second system.
[0155] Step 502: Verify the application information received from the first system. If the verification is successful, send the authorization token to the first system. The first system is configured to generate a directional link carrying the authorization token. The directional link is used to redirect to a page in the second system. The browser is further configured to load the directional link sent by the first system and send an access request to the second system via the directional link. Extract the second browser fingerprint information when sending the access request to the second system.
[0156] Step 503: Receive the second browser fingerprint information sent by the browser;
[0157] Step 504: When it is determined that the first browser fingerprint information matches the second browser fingerprint information, the access request is authorized to confirm that the mutual trust authentication between the first system and the second system is successful; the above-mentioned browser terminal is also used to display the page of the second system after the second system authorizes the access request.
[0158] In an embodiment of the present invention, first browser fingerprint information extracted by a browser and forwarded via a first system is received; the browser is configured to receive: an access request to a second system input by a user on a page of the first system; extract first browser fingerprint information of the time period in which the user logged into the first system; forward the first browser fingerprint information via the first system; the first system is configured to send application information requesting an authorization token to the second system; verify the application information received from the first system, and upon successful verification, send the authorization token to the first system; the first system is configured to generate a directional link carrying the authorization token; the directional link is configured to jump to a page of the second system; the browser is further configured to load the directional link sent by the first system and send an access request to the second system via the directional link; extract second browser fingerprint information when the access request is sent to the second system; and receive the second browser fingerprint information sent by the browser. When it is determined that the first browser fingerprint information and the second browser fingerprint information match, the access request is authorized, and the mutual trust authentication between the first system and the second system is confirmed to be successful. The browser end is also used to display the page of the second system after the second system authorizes the access request. Compared with the technical solution of realizing mutual trust authentication between systems based on the single sign-on model in the prior art, mutual trust authentication between multiple systems can be effectively realized through the interaction of authorization tokens between the first system and the second system, solving the problem of user privacy leakage that is easily caused by the need to share identity information in mutual trust authentication between systems under the prior art, which is conducive to protecting user privacy and ensuring user information security. At the same time, since centralized and unified authentication management is no longer required, it can be applied to the mutual trust scenarios of multiple loosely coupled third-party application systems, with high universality. Furthermore, the extraction of browser fingerprint information can help verify whether the login operations of different systems are the same user and the same browser, effectively ensuring the security of mutual trust authentication between multiple systems.
[0159] In the above embodiment, if Figure 9 As shown, the second system generates an authorization token, which can be issued and verified in a variety of ways, such as sending a unique random number as a token, or a key-encrypted string as a token, etc. In subsequent steps, the token stored on the authentication server or the token decrypted by the corresponding key can be used to verify whether the token submitted by the authentication object is valid.
[0160] In a specific implementation, the browser side is further used to generate a binary sequence corresponding to the first browser fingerprint information;
[0161] Receiving the first browser fingerprint information extracted by the browser and forwarded by the first system may include:
[0162] Receive a binary sequence corresponding to the first browser fingerprint information extracted by the browser and forwarded by the first system.
[0163] In the above embodiment, since the extracted browser fingerprint information is multi-dimensional, in order to facilitate the judgment of whether two browser fingerprints are from the same browser, the browser side can convert the multi-dimensional fingerprint information into a binary sequence through a binary information conversion algorithm, and the binary sequence should meet the condition of not being easy to forge.
[0164] After receiving the first browser fingerprint information and the second browser fingerprint information, the second system can determine whether the first browser fingerprint information and the second browser fingerprint information match in the following manner:
[0165] As shown in the figure, the timestamps of the two browser fingerprint information are XORed with the above two binary sequences to obtain a new binary sequence with timestamp information. The two binary sequences with timestamp information obtained before and after the mutual trust jump are XORed again. The number of 0 bits in the result can be used to determine whether it is the same browser.
[0166] Specific implementation may also include:
[0167] Receive the authorization token carried in the access request sent by the browser via the directed link; verify the validity of the authorization token, and when the validity verification passes, issue a notification message for extracting the second browser fingerprint information; the above-mentioned browser is also used to extract the second browser fingerprint information when receiving the above-mentioned notification message sent by the second system.
[0168] Specific implementation may also include:
[0169] When the validity verification of the authorization token fails, an alarm message indicating that the authorization token has expired is issued, and the mutual trust authentication between the first system and the second system is terminated; the above-mentioned browser end is also used to: receive and display the alarm message issued by the second system.
[0170] The embodiment of the present invention also provides a multi-party system mutual trust authentication device, which is applied to the second system to improve the security and universality of the mutual trust authentication between the multi-party systems. Figure 6 As shown, the device includes:
[0171] The first system communication module 601 is configured to receive first browser fingerprint information extracted by the browser and forwarded by the first system. The browser is configured to receive a user's access request to the second system entered on a page of the first system; extract the first browser fingerprint information of the time period during which the user logged into the first system; and forward the first browser fingerprint information via the first system. The first system is configured to send an application requesting an authorization token to the second system.
[0172] The application information verification module 602 is configured to verify the application information received from the first system and, upon successful verification, to send an authorization token to the first system. The first system is configured to generate a directional link carrying the authorization token; the directional link is configured to redirect to a page on the second system. The browser is further configured to: load the directional link sent by the first system and send an access request to the second system via the directional link; and extract the second browser fingerprint information when sending the access request to the second system.
[0173] The browser communication module 603 is used to receive the second browser fingerprint information sent by the browser;
[0174] The fingerprint information matching module 604 is used to authorize the access request and confirm that the mutual trust authentication between the first system and the second system has passed when it is determined that the fingerprint information of the first browser matches the fingerprint information of the second browser. The above-mentioned browser end is also used to display the page of the second system after the second system authorizes the access request.
[0175] In one embodiment, the browser is further configured to generate a binary sequence corresponding to the first browser fingerprint information;
[0176] The first system communication module is specifically used for:
[0177] Receive a binary sequence corresponding to the first browser fingerprint information extracted by the browser and forwarded by the first system.
[0178] In one embodiment, it may further include:
[0179] Validation module, used to:
[0180] Receive the authorization token carried in the access request sent by the browser via the directed link; verify the validity of the authorization token, and when the validity verification passes, issue a notification message for extracting the second browser fingerprint information; the above-mentioned browser is also used to extract the second browser fingerprint information when receiving the above-mentioned notification message sent by the second system.
[0181] In one embodiment, it may further include:
[0182] The alarm information sending module is used to:
[0183] When the validity verification of the authorization token fails, an alarm message indicating that the authorization token has expired is issued, and the mutual trust authentication between the first system and the second system is terminated; the above-mentioned browser end is also used to: receive and display the alarm message issued by the second system.
[0184] A specific example is given below to illustrate the specific application of the method of the present invention. In this example, the first system may be the original system A, and the second system may be the target mutual trust system.
[0185] See also Figure 7 and Figure 8 , this example may include the following steps:
[0186] 1. The user successfully logs in and accesses the original system A on the browser. After that, the user can click a button on the page of the original system A to access the target mutual trust system;
[0187] 2. Run the browser fingerprint extraction program on the browser to extract the browser fingerprint information. Then, the browser fingerprint and the parameter summary for accessing the target mutual trust system (i.e., the binary sequence described above, which is used to describe the browser fingerprint information) are used to apply for authorization from the original system A.
[0188] 3. Run the authorization application program on the backend server of the original system A. First, receive the user's authorization application and the above parameter summary, and then determine whether the current user has permission to access the services of the target mutual trust system:
[0189] If it is determined that there is no permission, the browser will be returned with an error message indicating that there is no permission.
[0190] If it is determined that there is permission, apply for an authorization token from the target mutual trust system;
[0191] 4. After verifying the validity of the authorization request, the target mutual trust system generates a random authorization token, uses the token as the key, and records the browser fingerprint and request parameter summary as the value. It then feeds the authorization token back to the original system A.
[0192] 5. The original system A generates a redirect link containing the authorization token and returns it to the browser;
[0193] 6. The browser opens the redirect link and sends a request to the target mutual trust system with the authorization token;
[0194] 7. The target mutual trust system authentication module verifies whether the token is valid,
[0195] If the token is invalid or expires, an unauthorized error message is returned;
[0196] If the token is valid, return to the browser fingerprint assisted verification page;
[0197] 8. The browser fingerprint extraction module re-collects the browser fingerprint and submits it to the target mutual trust system;
[0198] 9. The target mutual trust system authentication module verifies the browser fingerprint received this time and compares it with the browser fingerprint recorded in step 4.
[0199] If the fingerprint comparison is inconsistent, an unauthorized error message is returned;
[0200] If the fingerprint comparison is consistent, the verification is successful and the service page is returned.
[0201] The above example is applicable when the original system needs to access services from multiple mutually trusted systems (these systems may be from different vendors and may span domains). To ensure that the jump between the original system and the target mutually trusted system is performed by the same user, the above example can be combined with browser fingerprint verification on top of token authorization. Compared with existing technologies, the above example has the following advantages:
[0202] 1. Based on the fingerprint information of the browser, it can determine whether the mutual trust operation is the same operator and the operation scenario, which is highly secure;
[0203] Token-based authentication between multiple systems eliminates the need to transmit sensitive information such as usernames and passwords, protecting user privacy.
[0204] 2. There is no unified authentication center, and the authentication method is flexible and easy to expand;
[0205] 3. Does not rely on browser cookies and supports cross-domain.
[0206] In actual applications, the above examples can be used in combination with different systems, such as using the original system A to access the target mutual-trust system B, and using the original system B to access the target mutual-trust system C. In these scenarios, the mutual-trust authentication method can be used to jump from any original system to the target mutual-trust system. By superimposing the browser fingerprint on the authorization token, there is no need for a unified authentication center, no reliance on cookies, cross-domain support, and strong security.
[0207] A specific embodiment is given below to illustrate the specific application of the device of the present invention. In this embodiment, the following modules may be included:
[0208] Browser fingerprint extraction module: extracts browser fingerprint features and converts the extracted multi-dimensional information into a binary sequence through the above algorithm.
[0209] Authorization application module: After receiving the user's authorization application, the original system A first determines whether the current user has the authority to access the target mutual trust system. If so, it applies for authorization from the third-party system.
[0210] Token generation module: When the target mutual trust system receives an authorization application, it determines whether to issue a token based on relevant parameters.
[0211] Identity verification module: When the target mutual trust system wants to determine the identity of the visitor, it will first verify the identity token. If the verification is successful, it will then verify the browser fingerprints collected twice before and after. Only when the fingerprints are consistent can the visitor be successfully accessed.
[0212] Of course, it is understandable that the above detailed process may have other variations, and all relevant variations should fall within the scope of protection of the present invention.
[0213] An embodiment of the present invention provides an embodiment of a computer device for implementing all or part of the content of the above-mentioned multi-party system mutual trust authentication method. The computer device specifically includes the following content:
[0214] A processor, a memory, a communications interface, and a bus; wherein the processor, the memory, and the communications interface communicate with each other via the bus; the communications interface is used to implement information transmission between related devices; the computer device can be a desktop computer, a tablet computer, a mobile terminal, etc., but this embodiment is not limited thereto. In this embodiment, the computer device can be implemented with reference to the embodiment for implementing the multi-party system mutual trust authentication method and the embodiment for implementing the multi-party system mutual trust authentication device, the contents of which are incorporated herein and repeated parts are not repeated.
[0215] Figure 10 1 is a schematic block diagram of the system structure of the computer device 1000 according to an embodiment of the present application. Figure 10 As shown, the computer device 1000 may include a central processor 1001 and a memory 1002; the memory 1002 is coupled to the central processor 1001. Figure 10 is exemplary; other types of structures may also be used to supplement or replace this structure to implement telecommunication functions or other functions.
[0216] In one embodiment, the multi-party system mutual trust authentication function may be integrated into the central processing unit 1001. The central processing unit 1001 may be configured to perform the following control:
[0217] Receiving: a user inputs an access request to the second system on a page of the first system;
[0218] Extracting first browser fingerprint information of the time period when the user logs into the first system; sending the first browser fingerprint information to the second system via the first system; the first system is used to send application information requesting an authorization token to the second system; the second system is used to send the authorization token to the first system after approving the application information; the first system is used to generate a directional link carrying the authorization token; the directional link is used to jump to a page of the second system;
[0219] Loading the directed link sent by the first system and sending the access request to the second system via the directed link;
[0220] Extracting the second browser fingerprint information when sending the access request to the second system; sending the second browser fingerprint information to the second system; the second system is further configured to authorize the access request when determining that the first browser fingerprint information and the second browser fingerprint information match, thereby confirming that mutual trust authentication between the first system and the second system has been successful;
[0221] After the second system authorizes the access request, the page of the second system is displayed.
[0222] or, when confirming that the user has the authority to log in to the first system, authorizing the user's login request to the first system;
[0223] Receive and issue an access request to the second system input by the user on the page of the first system;
[0224] Receiving the first browser fingerprint information of the time period when the user logs into the first system extracted by the browser, and forwarding it to the second system;
[0225] Sending an application requesting an authorization token to the second system; the second system is configured to send the authorization token to the first system after approving the application;
[0226] Based on the authorization token received from the second system, a directional link carrying the authorization token is generated and issued; the directional link is used for the browser to jump to the page of the second system; the browser is also used to: extract the second browser fingerprint information when sending the access request to the second system; send the second browser fingerprint information to the second system; the second system is also used to authorize the access request when it is determined that the first browser fingerprint information and the second browser fingerprint information match, confirming that the mutual trust authentication between the first system and the second system has passed; after the second system authorizes the access request, the page of the second system is displayed.
[0227] or,
[0228] Receiving first browser fingerprint information extracted by the browser and forwarded by the first system; the browser is used to receive: an access request for the second system input by a user on a page of the first system; extracting the first browser fingerprint information of the time period when the user logged into the first system; forwarding the first browser fingerprint information via the first system; the first system is used to send application information requesting an authorization token to the second system;
[0229] Verifying the application information received from the first system and, if the verification is successful, sending the authorization token to the first system; the first system is used to generate a directional link carrying the authorization token; the directional link is used to jump to a page of the second system; the browser is further used to: load the directional link sent by the first system and send an access request to the second system via the directional link; and extract the second browser fingerprint information when sending the access request to the second system;
[0230] Receiving second browser fingerprint information sent by the browser;
[0231] When it is determined that the first browser fingerprint information matches the second browser fingerprint information, the access request is authorized to confirm that the mutual trust authentication between the first system and the second system is passed; the browser end is also used to display the page of the second system after the second system authorizes the access request.
[0232] In another embodiment, the multi-party system mutual trust authentication device can be configured separately from the central processor 1001. For example, the multi-party system mutual trust authentication device can be configured as a chip connected to the central processor 1001, and the multi-party system mutual trust authentication function can be realized through the control of the central processor.
[0233] like Figure 10 As shown, the computer device 1000 may further include: a communication module 1003, an input unit 1004, an audio processor 1005, a display 1006, and a power supply 1007. It is worth noting that the computer device 1000 does not necessarily have to include Figure 10In addition, the computer device 1000 may also include all components shown in Figure 10 For components not shown, reference may be made to the prior art.
[0234] like Figure 10 As shown, the central processing unit 1001 is sometimes also referred to as a controller or an operation control unit, and may include a microprocessor or other processor device and / or logic device. The central processing unit 1001 receives inputs and controls the operations of various components of the computer device 1000 .
[0235] Memory 1002 can be, for example, one or more of a cache, flash memory, hard drive, removable media, volatile memory, non-volatile memory, or other suitable devices. It can store the aforementioned failure-related information and a program that executes the relevant information. The CPU 1001 can execute the program stored in memory 1002 to implement information storage or processing.
[0236] Input unit 1004 provides input to CPU 1001. Input unit 1004 may be, for example, a keypad or touch input device. Power supply 1007 is used to provide power to computer device 1000. Display 1006 is used to display objects such as images and text. This display may be, for example, an LCD display, but is not limited thereto.
[0237] The memory 1002 may be a solid-state memory, such as a read-only memory (ROM), random access memory (RAM), or SIM card. Alternatively, it may be a memory that retains information even when power is off, can be selectively erased, and is provided with more data. Examples of such memory are sometimes referred to as EPROMs. The memory 1002 may also be some other type of device. The memory 1002 includes a buffer memory 1021 (sometimes referred to as a buffer). The memory 1002 may include an application / function storage unit 1022 for storing application programs and function programs or processes used by the central processing unit 1001 to execute the operations of the computer device 1000.
[0238] The memory 1002 may also include a data storage unit 1023 for storing data, such as contacts, digital data, pictures, sounds, and / or any other data used by the computer device. The driver storage unit 1024 of the memory 1002 may include various driver programs for the computer device for communication functions and / or for executing other functions of the computer device (such as messaging applications, address book applications, etc.).
[0239] The communication module 1003 is a transmitter / receiver 1003 that sends and receives signals via the antenna 1008. The communication module (transmitter / receiver) 1003 is coupled to the central processor 1001 to provide input signals and receive output signals, which may be the same as the case of a conventional mobile communication terminal.
[0240] Based on different communication technologies, multiple communication modules 1003 can be provided in the same computer device, such as a cellular network module, a Bluetooth module, and / or a wireless local area network module. The communication module (transmitter / receiver) 1003 is also coupled to a speaker 1009 and a microphone 1010 via an audio processor 1005 to provide audio output via the speaker 1009 and receive audio input from the microphone 1010, thereby implementing common telecommunication functions. The audio processor 1005 may include any suitable buffer, decoder, amplifier, etc. Furthermore, the audio processor 1005 is coupled to the central processing unit 1001, enabling local recording via the microphone 1010 and playback of stored audio via the speaker 1009.
[0241] An embodiment of the present invention further provides a computer-readable storage medium storing a computer program. When the computer program is executed by a processor, the computer program implements the above-mentioned multi-party system mutual trust authentication method.
[0242] An embodiment of the present invention further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, it implements the above-mentioned multi-party system mutual trust authentication method.
[0243] In an embodiment of the present invention, first browser fingerprint information extracted by a browser and forwarded via a first system is received; the browser is configured to receive: an access request to a second system input by a user on a page of the first system; extract first browser fingerprint information of the time period in which the user logged into the first system; forward the first browser fingerprint information via the first system; the first system is configured to send application information requesting an authorization token to the second system; verify the application information received from the first system, and upon successful verification, send the authorization token to the first system; the first system is configured to generate a directional link carrying the authorization token; the directional link is configured to jump to a page of the second system; the browser is further configured to load the directional link sent by the first system and send an access request to the second system via the directional link; extract second browser fingerprint information when the access request is sent to the second system; and receive the second browser fingerprint information sent by the browser. When it is determined that the first browser fingerprint information and the second browser fingerprint information match, the access request is authorized, and the mutual trust authentication between the first system and the second system is confirmed to be successful. The browser end is also used to display the page of the second system after the second system authorizes the access request. Compared with the technical solution of realizing mutual trust authentication between systems based on the single sign-on model in the prior art, mutual trust authentication between multiple systems can be effectively realized through the interaction of authorization tokens between the first system and the second system, solving the problem of user privacy leakage that is easily caused by the need to share identity information in mutual trust authentication between systems under the prior art, which is conducive to protecting user privacy and ensuring user information security. At the same time, since centralized and unified authentication management is no longer required, it can be applied to the mutual trust scenarios of multiple loosely coupled third-party application systems, with high universality. Furthermore, the extraction of browser fingerprint information can help verify whether the login operations of different systems are the same user and the same browser, effectively ensuring the security of mutual trust authentication between multiple systems.
[0244] It will be understood by those skilled in the art that embodiments of the present invention may be provided as methods, systems, or computer program products. Thus, the present invention may take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0245] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0246] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0247] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0248] The specific embodiments described above further illustrate the objectives, technical solutions and beneficial effects of the present invention in detail. It should be understood that the above description is only a specific embodiment of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A multi-party system mutual trust authentication method, characterized in that: Applied to the browser side, including: Receiving: a user inputs an access request to the second system on a page of the first system; Extracting first browser fingerprint information of the time period when the user logs into the first system; sending the first browser fingerprint information to the second system via the first system; the first system is used to send application information requesting an authorization token to the second system; the second system is used to send the authorization token to the first system after approving the application information; the first system is used to generate a directional link carrying the authorization token; the directional link is used to jump to a page of the second system; Loading the directed link sent by the first system, and sending the access request to the second system via the directed link; Extracting the second browser fingerprint information when sending the access request to the second system; sending the second browser fingerprint information to the second system; the second system is further configured to authorize the access request when determining that the first browser fingerprint information and the second browser fingerprint information match, thereby confirming that mutual trust authentication between the first system and the second system has been successful; After the second system authorizes the access request, displaying a page of the second system; The method includes: generating a binary sequence corresponding to the first browser fingerprint information; and sending the binary sequence corresponding to the first browser fingerprint information to the second system via the first system. The second system is also used to: receive an authorization token carried in an access request sent by a browser via a directed link; verify the validity of the authorization token carried in the access request, and when the validity verification passes, issue a notification message for extracting the second browser fingerprint information; extracting the second browser fingerprint information includes: extracting the second browser fingerprint information when receiving the notification message sent by the second system.
2. The method according to claim 1, wherein The first browser fingerprint information includes user identity information; The first system is further configured to: determine, based on the user information, whether the user has the authority to access the second system; and request an authorization token from the second system when it is determined that the user has the authority to access the second system; When it is determined that the user does not have the authority to access the second system, an alarm message is issued indicating that the user does not have the authority to access the second system; The method further comprises: Receive and display the alarm information sent by the first system.
3. The method according to claim 1, wherein The second system is further configured to: when the validity verification of the authorization token fails, issue an alarm indicating that the authorization token carried in the access request has expired, and terminate the mutual trust authentication between the first system and the second system; The method further comprises: Receive and display the alarm information sent by the second system.
4. A multi-party system mutual trust authentication device, characterized in that: Applied to the browser side, including: An access request receiving module, configured to receive: an access request for a second system input by a user on a page of the first system; The first browser fingerprint information extraction module is configured to extract the first browser fingerprint information of the time period during which the user logs into the first system; transmit the first browser fingerprint information to the second system via the first system; the first system is configured to transmit an application requesting an authorization token to the second system; the second system is configured to transmit the authorization token to the first system after approving the application; the first system is configured to generate a directional link carrying the authorization token; the directional link is configured to redirect to a page in the second system; a directional link loading module, configured to load the directional link sent by the first system and send an access request to the second system via the directional link; The second browser fingerprint information extraction module is configured to extract the second browser fingerprint information when sending the access request to the second system; and send the second browser fingerprint information to the second system; and the second system is further configured to authorize the access request and confirm that mutual trust authentication between the first system and the second system has been successful when determining that the first browser fingerprint information and the second browser fingerprint information match. A second system page display module, configured to display a page of the second system after the second system authorizes the access request; The first browser fingerprint information extraction module is specifically configured to: generate a binary sequence corresponding to the first browser fingerprint information; and send the binary sequence corresponding to the first browser fingerprint information to the second system via the first system; The second system is also used to: receive the authorization token carried in the access request sent by the browser via the directed link; verify the validity of the authorization token carried in the access request, and when the validity verification passes, issue a notification message for extracting the second browser fingerprint information; the second browser fingerprint information extraction module is used to: extract the second browser fingerprint information when receiving the notification message sent by the second system.
5. The device according to claim 4, characterized in that The first browser fingerprint information includes user identity information; The first system is further configured to: determine, based on the user information, whether the user has the authority to access the second system; request an authorization token from the second system when it is determined that the user has the authority to access the second system; and issue an alarm indicating that the user has no authority to access the second system when it is determined that the user does not have the authority to access the second system; The device further includes a first system alarm information receiving and displaying module, which is configured to: Receive and display the alarm information sent by the first system.
6. The device according to claim 4, characterized in that The second system is further configured to: when the validity verification of the authorization token fails, issue an alarm indicating that the authorization token carried in the access request has expired, and terminate the mutual trust authentication between the first system and the second system; The device further includes a second system alarm information receiving and displaying module, which is configured to: Receive and display the alarm information sent by the second system.
7. A multi-party system mutual trust authentication method, characterized in that: Applied to the first system, including: When confirming that the user has the authority to log in to the first system, authorizing the user's login request to the first system; Receive and issue an access request to the second system input by the user on the page of the first system; Receiving the first browser fingerprint information of the time period when the user logs into the first system extracted by the browser, and forwarding it to the second system; Sending an application requesting an authorization token to the second system; the second system is configured to send the authorization token to the first system after approving the application; Based on the authorization token received from the second system, a directional link carrying the authorization token is generated and issued; the directional link is used for the browser to jump to the page of the second system; the browser is further configured to: extract the second browser fingerprint information when sending the access request to the second system; send the second browser fingerprint information to the second system; the second system is further configured to authorize the access request when it is determined that the first browser fingerprint information and the second browser fingerprint information match, confirming that the mutual trust authentication between the first system and the second system has passed; after the second system authorizes the access request, display the page of the second system; The browser is further configured to: generate a binary sequence corresponding to the first browser fingerprint information; Receiving first browser fingerprint information extracted by the browser and forwarding it to the second system includes: receiving a binary sequence corresponding to the first browser fingerprint information generated by the browser and forwarding it to the second system; The first browser fingerprint information includes user identity information; The method further comprises: Determining, based on the user information, whether the user has the authority to access the second system; and requesting an authorization token from the second system when it is determined that the user has the authority to access the second system; When it is determined that the user does not have the authority to access the second system, an alarm message is issued indicating that the user does not have the authority to access the second system; The browser is also used to: Receive and display notification information or alarm information sent by the first system.
8. A multi-party system mutual trust authentication device, characterized in that: Applied to the first system, including: A login request authorization module, configured to authorize a user's login request to the first system when confirming that the user has the authority to log in to the first system; An access request receiving module, configured to receive and issue an access request to the second system input by a user on a page of the first system; A first browser fingerprint information forwarding module is used to receive the first browser fingerprint information of the time period when the user logs into the first system extracted by the browser, and forward it to the second system; An application information sending module, configured to send application information requesting an authorization token to the second system; the second system is configured to send the authorization token to the first system after approving the application information; A directed link generation module is configured to generate and issue a directed link carrying an authorization token based on an authorization token received from a second system; the directed link is used to allow a browser to jump to a page of the second system; the browser is further configured to: extract fingerprint information of the second browser when sending an access request to the second system; and send the second browser fingerprint information to the second system; the second system is further configured to authorize the access request upon determining that the first browser fingerprint information and the second browser fingerprint information match, thereby confirming that mutual trust authentication between the first system and the second system has been successful; and after the second system authorizes the access request, display the page of the second system. The browser is further configured to: generate a binary sequence corresponding to the first browser fingerprint information; The first browser fingerprint information forwarding module is specifically used to: receiving a binary sequence corresponding to the first browser fingerprint information generated by the browser and forwarding it to the second system; The first browser fingerprint information includes user identity information; The device further includes a user authority determination module, which is configured to: Determining, based on the user information, whether the user has the authority to access the second system; and requesting an authorization token from the second system when it is determined that the user has the authority to access the second system; When it is determined that the user does not have the authority to access the second system, an alarm message is issued indicating that the user does not have the authority to access the second system; The browser is also used to: Receive and display notification information or alarm information sent by the first system.
9. A multi-party system mutual trust authentication method, characterized in that: Applicable to the second system, including: Receiving first browser fingerprint information extracted by the browser and forwarded by the first system; the browser is used to receive: an access request for the second system input by a user on a page of the first system; extracting the first browser fingerprint information of the time period when the user logged into the first system; forwarding the first browser fingerprint information via the first system; the first system is used to send application information requesting an authorization token to the second system; Verifying the application information received from the first system and, if the verification is successful, sending the authorization token to the first system; the first system is used to generate a directional link carrying the authorization token; the directional link is used to jump to a page of the second system; the browser is further used to: load the directional link sent by the first system and send an access request to the second system via the directional link; and extract the second browser fingerprint information when sending the access request to the second system; Receiving second browser fingerprint information sent by the browser; When it is determined that the fingerprint information of the first browser matches the fingerprint information of the second browser, the access request is authorized, and the mutual trust authentication between the first system and the second system is confirmed to be successful; the browser terminal is further configured to display a page of the second system after the second system authorizes the access request; The browser side is further used to generate a binary sequence corresponding to the first browser fingerprint information; Receiving first browser fingerprint information extracted by the browser and forwarded by the first system includes: receiving a binary sequence corresponding to the first browser fingerprint information extracted by the browser and forwarded by the first system; It also includes: receiving an authorization token carried in an access request sent by a browser via a directed link; verifying the validity of the authorization token, and when the validity verification passes, issuing a notification message for extracting second browser fingerprint information; the browser is also used to extract the second browser fingerprint information when receiving the notification message sent by the second system.
10. The method according to claim 9, wherein Also includes: When the validity verification of the authorization token fails, an alarm message indicating that the authorization token has expired is issued, and the mutual trust authentication between the first system and the second system is terminated; the browser end is further used to: receive and display the alarm message issued by the second system.
11. A multi-party system mutual trust authentication device, characterized in that: Applicable to the second system, including: The first system communication module is configured to receive first browser fingerprint information extracted by the browser and forwarded by the first system; the browser is configured to receive: an access request for the second system entered by a user on a page of the first system; extract the first browser fingerprint information of the time period during which the user logged into the first system; forward the first browser fingerprint information via the first system; and the first system is configured to send an application requesting an authorization token to the second system; The application information verification module is used to verify the application information received from the first system and, if the verification is successful, send the authorization token to the first system; the first system is used to generate a directional link carrying the authorization token; the directional link is used to jump to a page of the second system; the browser is further used to: load the directional link sent by the first system and send an access request to the second system via the directional link; and extract the second browser fingerprint information when sending the access request to the second system; The browser communication module is used to receive the second browser fingerprint information sent by the browser; The fingerprint information matching module is used to authorize the access request and confirm that the mutual trust authentication between the first system and the second system has passed when it is determined that the fingerprint information of the first browser matches the fingerprint information of the second browser; the browser terminal is also used to display the page of the second system after the second system authorizes the access request; The browser side is further used to generate a binary sequence corresponding to the first browser fingerprint information; The first system communication module is specifically used to: receiving a binary sequence corresponding to the first browser fingerprint information extracted by the browser and forwarded by the first system; Also includes: a validity verification module for: Receive the authorization token carried in the access request sent by the browser via the directed link; verify the validity of the authorization token, and when the validity verification passes, issue a notification message for extracting the second browser fingerprint information; the browser is also used to extract the second browser fingerprint information when receiving the notification message sent by the second system.
12. The device according to claim 11, wherein Also includes: The alarm information sending module is used to: When the validity verification of the authorization token fails, an alarm message indicating that the authorization token has expired is issued, and the mutual trust authentication between the first system and the second system is terminated; the browser end is further used to: receive and display the alarm message issued by the second system.
13. A computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein: When the processor executes the computer program, the method according to any one of claims 1 to 3, 7, 9 to 10 is implemented.
14. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 3, 7, 9 to 10 is implemented.
15. A computer program product, characterized in that The computer program product comprises a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 3, 7, 9 to 10 is implemented.
Citation Information
Patent Citations
Website login method and website login device
CN107196892A
Sharing logging method and device
CN107948214A