An account authentication method and device

By generating the first authentication indicator in the authentication server and generating an associated authentication token, the problem of cumbersome account opening process in the existing technology is solved, and a safe and convenient account opening is achieved, which improves the user experience.

CN114186203BActive Publication Date: 2025-06-27BEIJING WATERDROP TECH GRP CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111235742.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-10-22
Publication Date
2025-06-27
Estimated Expiration
2041-10-22

AI Technical Summary

Technical Problem

In the prior art, the method and process of opening accounts of WeChat public accounts is cumbersome, requiring user authorization operations, which are inefficient and have poor experience, resulting in poor user experience and difficulty in business linkage.

Method used

By generating a first authentication indicator for identifying the electronic device terminal information of the first public account in the authentication server, and upon receiving the authentication request for the second public account, it is determined whether the authentication request contains a valid first authentication indicator. If it is included, an associated authentication token will be generated to realize account merger.

Benefits of technology

The process of opening an account does not require the user's WeChat authorization information, which is safe and convenient, and improves the user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114186203B_ABST
    Figure CN114186203B_ABST
Patent Text Reader

Abstract

An embodiment of the present application provides an account authentication method and device. In the account authentication method, a first authentication indicator is generated to identify the electronic device terminal information for logging in to the first official account, so as to identify the official accounts from the same electronic device terminal. When receiving an authentication request for the second official account, it is determined whether the second official account and the first official account come from the same user by judging whether the authentication request contains a valid first authentication indicator. If the authentication request contains a valid first authentication indicator, an associated authentication token is generated to correspond to the user identity information of the first official account and the second official account respectively, so as to achieve the effect of account merging. The entire account merging process does not require obtaining the WeChat authorization information of the user, and the account connection is realized safely and conveniently, improving the user experience.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the field of intelligent terminals, and in particular, to an account authentication method and device.

Background Art

[0002] With the wide use of WeChat official accounts and the booming development of Internet services, it is an inevitable result of business development that there are multiple official accounts and multiple domain names. Different business lines of the same organization will apply for multiple official accounts. As a result, a single user will have multiple accounts under the same organization, which leads to poor user experience and difficulties in business linkage within the organization. Against this background, the primary need to be addressed urgently for business development and user experience is to integrate multiple accounts of the same user on multiple official accounts. However, the account integration method provided by WeChat is cumbersome, requiring users to be guided through the authorization process, resulting in low efficiency and poor experience.

Summary of the Invention

[0003] The embodiments of the present application provide an account authentication method and device, so as to achieve the integration of multiple accounts of the same user on multiple official accounts without restricting the user authorization method, thereby improving the user experience.

[0004] In a first aspect, the embodiments of the present application provide an account authentication method, which is applied to an authentication server of an account authentication system. The account authentication system further includes an electronic device terminal. The method includes: receiving a first authentication request triggered by a first official account link; obtaining first user identity information for logging in to the first official account, generating a first authentication indicator, and returning the first authentication indicator to the electronic device terminal, where the first authentication indicator is used to identify the electronic device terminal information for logging in to the first official account; receiving a second authentication request triggered by a second official account link; obtaining second user identity information for logging in to the second official account. If the second authentication request includes the first authentication indicator, an associated authentication token is generated, and the associated authentication token corresponds to the first user identity information and the second user identity information respectively; returning the associated authentication token to the electronic device terminal.

[0005] In the above account authentication method, the first authentication indicator for identifying the electronic device terminal information for logging in to the first official account is generated to identify the official accounts from the same electronic device terminal. When receiving the authentication request for the second official account, it is determined whether the second official account and the first official account both come from the same electronic device terminal by determining whether the authentication request contains a valid first authentication indicator. If the authentication request contains a valid first authentication indicator, an associated authentication token is generated to correspond to the user identity information of the first official account and the second official account respectively, so as to achieve the effect of account merging. The entire account merging process does not require obtaining the WeChat authorization information of the user, and securely and conveniently realizes account integration, improving the user experience.

[0006] In one implementation, the generating of the associated authentication token includes: when the valid time of the first authentication indicator included in the second authentication request does not exceed a preset time limit, generating the associated authentication token.

[0007] In one implementation, when returning the first authentication indicator to the electronic device terminal, an authentication token for characterizing the first user identity information is also returned. After generating the associated authentication token, the method further includes: receiving a third authentication request triggered through the first official account link, where the third authentication request includes the authentication token for characterizing the first user identity information; if the first user identity information included in the authentication token for characterizing the first user identity information is consistent with the first user identity information corresponding to the associated authentication token, returning the associated authentication token to the electronic device terminal.

[0008] In one implementation, the first user identity information and the second user identity information respectively corresponding to the associated authentication token both correspond to a combined storage area, and the combined storage area is used to store user personal information. The method further includes: receiving an access request triggered through the first official account link or the second official account link; when the access request includes the associated authentication token, determining whether the associated authentication token is valid, and if so, obtaining the user personal information corresponding to the associated authentication token from the combined storage area.

[0009] In a second aspect, an embodiment of the present application provides an account authentication method, which is applied to an electronic device terminal of an account authentication system, and the account authentication system further includes an authentication server. The method includes: in response to an authentication instruction triggered by a user through a first official account link displayed by a service platform client, sending a first authentication request to the authentication server; receiving a first authentication indicator returned by the authentication server, and storing the first authentication indicator in a client storage area corresponding to the service platform client in the electronic device terminal, where the first authentication indicator is used to identify the electronic device terminal information for logging in to the first official account; in response to an authentication instruction triggered by a user through a second official account link displayed by the service platform client, sending a second authentication request to the authentication server, and adding the first authentication indicator to the second authentication request; receiving an associated authentication token returned by the authentication server, and storing the associated authentication token in a storage area corresponding to the second official account.

[0010] In one implementation, the method further includes: after sending a first authentication request to the authentication server, receiving an authentication token returned by the authentication server for characterizing the first user identity information, and storing the authentication token characterizing the first user identity information in the storage area corresponding to the first official account; in response to an authentication instruction triggered again by the user through the first official account link, sending a third authentication request to the authentication server, where the third authentication request includes the authentication token for characterizing the first user identity information; receiving an associated authentication token returned by the authentication server; and overwriting the authentication token for characterizing the first user identity information with the associated authentication token in the storage area corresponding to the first official account.

[0011] In one implementation, the terminal storage area includes a text file cookie.

[0012] In a third aspect, an embodiment of the present application provides an authentication server, which is applied to an account authentication system. The account authentication system further includes an electronic device terminal. The authentication server includes: a receiving module, configured to receive a first authentication request triggered through a first official account link; an indicator generation module, configured to obtain the first user identity information for logging in to the first official account, generate a first authentication indicator, and return the first authentication indicator to the electronic device terminal, where the first authentication indicator is used to identify the electronic device terminal information for logging in to the first official account; the receiving module is further configured to receive a second authentication request triggered through a second official account link; an associated token generation module, configured to obtain the second user identity information for logging in to the second official account, and if the second authentication request includes the first authentication indicator, generate an associated authentication token, where the associated authentication token corresponds to the first user identity information and the second user identity information respectively; and a return module, configured to return the associated authentication token to the electronic device terminal.

[0013] In one implementation, the associated token generation module is further configured to generate the associated authentication token when the valid time of the first authentication indicator included in the second authentication request does not exceed a preset time limit.

[0014] In one implementation, the receiving module is further configured to receive a third authentication request triggered through the first official account link, where the third authentication request includes the authentication token for characterizing the first user identity information; the return module is further configured to return the associated authentication token to the electronic device terminal if the first user identity information included in the authentication token for characterizing the first user identity information is consistent with the first user identity information corresponding to the associated authentication token.

[0015] In one embodiment, the device further includes: the receiving module, further configured to receive an access request triggered by the first official account link or the second official account link; a personal information acquisition module, configured to determine whether the associated authentication token is valid when the access request includes the associated authentication token, and if so, obtain the user personal information corresponding to the associated authentication token from the combined storage area.

[0016] In a fourth aspect, an embodiment of the present application provides an electronic device terminal applied to an account authentication system, and the account authentication system further includes an authentication server. The electronic device terminal includes: a sending module, configured to send a first authentication request to the authentication server in response to an authentication instruction triggered by a user through a first official account link displayed by a service platform client; a storage module, configured to receive a first authentication indicator returned by the authentication server and store the first authentication indicator in a client storage area corresponding to the service platform client in the electronic device terminal, where the first authentication indicator is used to identify the electronic device terminal information for logging in to the first official account; the sending module, further configured to send a second authentication request to the authentication server in response to an authentication instruction triggered by a user through a second official account link displayed by the service platform client, and add the first authentication indicator to the second authentication request; the storage module, further configured to receive an associated authentication token returned by the authentication server and store the associated authentication token in a storage area corresponding to the second official account.

[0017] In one embodiment, the device further includes: the storage module, further configured to, after sending the first authentication request to the authentication server, receive an authentication token for characterizing the first user identity information returned by the authentication server and store the authentication token for characterizing the first user identity information in a storage area corresponding to the first official account; the sending module, further configured to send a third authentication request to the authentication server in response to an authentication instruction triggered again by the user through the first official account link, where the third authentication request includes the authentication token for characterizing the first user identity information; an associated token receiving module, configured to receive the associated authentication token returned by the authentication server; the storage module, further configured to overwrite the authentication token for characterizing the first user identity information with the associated authentication token in the storage area corresponding to the first official account.

[0018] In a fifth aspect, an embodiment of the present application provides an authentication server, including: at least one processor; and at least one memory communicatively connected to the processor, where: the memory stores program instructions executable by the processor, and the processor can execute the above account authentication method by invoking the program instructions.

[0019] Sixth aspect, an embodiment of the present application provides an electronic device terminal, including: at least one processor; and at least one memory communicatively connected to the processor, wherein: the memory stores program instructions executable by the processor, and the processor can execute the above-mentioned account authentication method by invoking the program instructions.

[0020] It should be understood that the technical solutions of the second to sixth aspects of the embodiments of the present application are consistent with those of the first aspect of the embodiments of the present application, and the beneficial effects obtained by each aspect and the corresponding feasible implementation manners are similar, and will not be elaborated here.

BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required to be used in the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of this specification. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0022] Figure 1 It is a schematic flowchart of an account authentication method provided by an embodiment of the present application;

[0023] Figure 2 It is a schematic flowchart of storing an associated authentication token in the storage area corresponding to the first official account provided by an embodiment of the present application;

[0024] Figure 3 It is a schematic flowchart of an account authentication method for a multi-service platform client provided by an embodiment of the present application;

[0025] Figure 4 It is a schematic flowchart of an account authentication method provided by another embodiment of the present application;

[0026] Figure 5 It is a schematic structural diagram of an authentication server provided by an embodiment of the present application;

[0027] Figure 6 It is a schematic structural diagram of an authentication server provided by another embodiment of the present application;

[0028] Figure 7 It is a schematic structural diagram of an electronic device terminal provided by an embodiment of the present application;

[0029] Figure 8 It is a schematic structural diagram of an authentication server provided by still another embodiment of the present application;

[0030] Figure 9 It is a schematic structural diagram of an electronic device terminal provided by another embodiment of the present application;

[0031] Figure 10Schematic diagram of the structure of the electronic device terminal provided by another embodiment of the present application.

Specific Embodiments

[0032] In order to better understand the technical solutions of this specification, the embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0033] It should be clear that the described embodiments are only a part of the embodiments of this specification, rather than all the embodiments. Based on the embodiments in this specification, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope protected by this specification.

[0034] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit this specification. The singular forms "a", "the" and "said" used in the embodiments of the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.

[0035] In the prior art, with the wide use of official accounts (such as WeChat official accounts) on service platforms and the booming development of Internet services, multiple official accounts and multiple domain names are an inevitable result of business development. Different business lines of the same organization will apply for multiple official accounts. As a result, a single user will have multiple accounts on the servers of the same organization, resulting in a poor user experience and difficulties in business linkage within the organization. Against this background, connecting multiple accounts of the same user across multiple official accounts is the primary need urgently to be solved for business development and user experience. However, the account connection method provided by the service platform has a cumbersome process. For a service platform such as WeChat, it is necessary to guide users to perform authorization operations, which is inefficient and provides a poor experience.

[0036] Figure 1 Flowchart of an account authentication method provided for an embodiment of the present application. As shown in the figure, the steps of the account authentication method at the authentication server include:

[0037] Step S101, receiving a first authentication request triggered by a first official account link.

[0038] Optionally, for a user account that logs in to an official account link for the first time, since the authentication request does not carry an authentication token Token that identifies the user identity information, the authentication server cannot identify the user identity information corresponding to the official account when receiving the official account link and cannot perform resource matching. It is necessary to first send the official account link to the service platform server for identity authentication to obtain the user identity information. The specific method and process of the service platform server for relevant identity authentication adopt the prior art and will not be elaborated here.

[0039] Step S102: Obtain the first user identity information for logging in to the first official account, generate a first authentication indicator, and return the first authentication indicator to the electronic device terminal, where the first authentication indicator is used to identify the information of the electronic device terminal logging in to the first official account.

[0040] Optionally, after the service platform server identifies the first user identity information corresponding to the official account link, it sends the first user identity information to the authentication server. The authentication server generates a corresponding first authentication token and a first authentication identifier, such as pToken, for identifying the information of the electronic device terminal logging in to the first official account, and stores the first user identity information, the first authentication token, such as TokenA, the first authentication identifier pToken, and the corresponding relationships among the three in the memory, and returns the first authentication token TokenA and the first authentication identifier pToken to the electronic device terminal. It should be noted that the electronic device terminal information includes one or a combination of the following: device hardware information, client information of the service platform client for displaying the content of the official account, such as WeChat client information.

[0041] Step S103: Receive a second authentication request triggered by the second official account link.

[0042] Optionally, when the authentication server receives a second authentication request triggered by the second official account link, it will also perform an identity information matching query on the second official account link. If no corresponding user identity information is found, it still needs to send the second official account link to the service platform server for identity authentication to obtain the corresponding second user identity information.

[0043] Step S104: Obtain the second user identity information for logging in to the second official account. If the second authentication request includes the first authentication indicator, generate an associated authentication token, where the associated authentication token corresponds to the first user identity information and the second user identity information respectively.

[0044] Optionally, after the authentication server obtains the second user identity information corresponding to the second official account, it needs to generate a corresponding second authentication token, such as TokenB.

[0045] Optionally, if the first authentication identifier pToken is not included in the second authentication request, the authentication server determines that the electronic device terminal information to which the electronic device terminal information for logging in to the first official account and the second official account belongs is different, generates a second authentication identifier for identifying the electronic device terminal information for logging in to the second official account, and stores the second authentication identifier, the second authentication token TokenB, the second user identity information, and the corresponding relationships among the three.

[0046] Optionally, if the first authentication identifier pToken is included in the second authentication request, the authentication server determines that the electronic device terminal information to which the electronic device terminal information for logging in to the first official account and the second official account belongs is the same, generates an associated authentication token, such as TokenC, associates the first user identity information and the second user identity information with the associated authentication token TokenC respectively, and stores the associated authentication token TokenC and the correspondence between the associated authentication token TokenC and the first user identity information and the second user identity information.

[0047] It should be noted that taking the service platform as the WeChat platform as an example, the above user identity information can be the WeChat user identity information UnionID obtained through authorized login, or the ordinary user identity information OpenID for non-authorized login. It depends on the actual needs. The specific way to obtain user identity information can be selected when the user logs in through the official account link. For example, in the case of authorized login, an authorization pop-up window will appear. After the user triggers the authorization, the UnionID is obtained through matching by the service platform server; in the case of non-authorized login, no authorization pop-up window will appear, and only the OpenID is generated.

[0048] In one implementation, when the validity period of the first authentication indicator included in the second authentication request does not exceed the preset time limit, an associated authentication token is generated.

[0049] Optionally, for security reasons, the first authentication indicator pToken needs to be set with a validity period. If the validity period of the first authentication indicator included in the second authentication request does not exceed the preset time limit, an associated authentication token can be generated; if the validity period of the first authentication indicator exceeds the preset time limit, the generation of the associated authentication token is stopped. At this time, only the association between the second user identity information and the second authentication token TokenB can be performed. After the first official account link sends an authentication request again and extends the validity period of the first authentication indicator, further matching, association, and merging are performed.

[0050] In one implementation, when the first user identity information and the second user identity information contain different user identity information, no matching, association, and merging of user identity information are performed. Different user identity information includes, for example, different UnionIDs, different mobile phone numbers, etc.

[0051] In one implementation, when the authentication server generates a Token, it uses the user agent (UA) of the service platform client as an interference code to encrypt the data, and returns the Token and UA to the electronic device terminal. When the electronic device terminal makes a request, it will pass in the Token and UA at the same time. The server decrypts the Token using the UA to verify the user's identity. Different UAs will cause the server to fail to parse the Token, thus achieving a certain degree of anti-impersonation. When the authentication server determines that the UA included in the second authentication request carrying the first authentication indicator is different from the corresponding UA in the authentication server, it will not perform the matching and merging of the user identity information, and only generate a corresponding authentication token for the user identity information.

[0052] In one implementation, both the first user identity information and the second user identity information corresponding to the associated authentication token correspond to the merged storage area. The merged storage area is used to store user personal information and receive access requests triggered by the first official account link or the second official account link; when the access request includes an associated authentication token, it is judged whether the associated authentication token is valid. If so, the user personal information corresponding to the associated authentication token is obtained from the merged storage area.

[0053] Optionally, after associating the first user identity information and the second user identity information, the storage area A corresponding to the first user identity information and the storage area B corresponding to the second user identity information are associated through the associated authentication token to form a merged storage area. The merged storage area stores user personal information, such as the user's order information, mall integral information, and browsing records, etc.

[0054] In one implementation, after associating the first user identity information and the second user identity information, when the authentication server receives an access request triggered by the first official account link or the second official account link, it first judges whether the access request includes a valid associated authentication token. If so, it obtains the user personal information corresponding to the associated authentication token from the merged storage area for display; when the first user identity information and the second user identity information are not merged, when the authentication server receives an access request triggered by the first official account link or the second official account link, it first judges whether the first authentication token or the second authentication token included in the access request is consistent with the first authentication token or the second authentication token stored in the memory and whether the first authentication token or the second authentication token is within the validity period. If it is consistent with the memory and within the validity period, the corresponding user personal information is obtained from the storage area A corresponding to the first user identity information or the storage area B corresponding to the second user identity information.

[0055] Step S105, return the associated authentication token to the electronic device terminal.

[0056] Optionally, at this time, the data content returned by the authentication server varies according to different data merging situations. For example, when the first authentication identifier is included in the second authentication request, the associated authentication token TokenC is returned; when the first authentication identifier is not included in the second authentication request, the second authentication token TokenB and the second authentication identifier are returned; when the valid time of the first authentication indicator included in the second authentication request exceeds the preset time limit, the second authentication token TokenB and the second authentication identifier are returned.

[0057] In one implementation, when receiving a third authentication request triggered through the first official account link, the first user identity information contained in the first authentication token included in the third authentication request is compared with the first user identity information corresponding to the associated authentication token. If they are the same, the associated authentication token is returned to the electronic device terminal.

[0058] Optionally, after receiving the first authentication request triggered through the first official account link, a first authentication token TokenA is generated correspondingly, and the first user identity information is associated with the first authentication token TokenA. However, after the authentication server associates the first user identity information and the second user identity information using the associated authentication token TokenC, the authentication token corresponding to the first user identity information in the memory of the authentication server changes from the first authentication token TokenA to the associated authentication token TokenC. However, since the data association action is in response to the second authentication request, the object of data return at this time is the second official account. That is, the authentication token of the first official account at the electronic device terminal has not changed from the first authentication token TokenA to the associated authentication token TokenC yet, and the authentication token needs to be refreshed when receiving the next authentication request triggered through the first official account link.

[0059] Optionally, when the authentication server receives the third authentication request triggered through the first official account link again, the third authentication request includes the first authentication token TokenA at this time, but the authentication token corresponding to the first user identity information in the memory of the authentication server is the associated authentication token TokenC. After determining that the user identity information contained in the first authentication token TokenA and the associated authentication token TokenC is the same, the authentication server returns the associated authentication token TokenC to the electronic device terminal to replace the authentication token at the electronic device terminal and make it consistent with the data at the authentication server.

[0060] In the above account authentication method, the authentication server identifies the official accounts from the same electronic device terminal by generating a first authentication indicator for identifying the electronic device terminal information of the first official account. When receiving an authentication request for a second official account, it determines whether the second official account and the first official account are from the same user by judging whether the authentication request contains a valid first authentication indicator. If the authentication request contains a valid first authentication indicator, it generates an associated authentication token corresponding to the user identity information of the first official account and the second official account respectively, so as to achieve the effect of account merging. The entire account merging process does not require obtaining the WeChat authorization information of the user, and securely and conveniently realizes account connection, improving the user experience.

[0061] As Figure 1 shown, the steps of the account authentication method at the electronic device terminal include:

[0062] Step S201, in response to an authentication instruction triggered by a user clicking on a link to the first official account displayed through the service platform client, send a first authentication request to the authentication server.

[0063] Optionally, the ways for the user to trigger the authentication instruction through the link to the first official account include directly clicking on the virtual button corresponding to the link, inputting the corresponding query text to trigger the link, etc.

[0064] Step S202, receive the first authentication indicator returned by the authentication server, and store the first authentication indicator in the client storage area corresponding to the service platform client in the electronic device terminal, where the first authentication indicator is used to identify the electronic device terminal information for logging in to the first official account.

[0065] In one implementation, the client storage area includes a text file cookie, and the electronic device terminal stores the first authentication indicator in the corresponding text file cookie.

[0066] Step S203, in response to an authentication instruction triggered by a user clicking on a link to the second official account displayed through the service platform client, send a second authentication request to the authentication server, and add the first authentication indicator to the second authentication request.

[0067] Optionally, when the authentication server returns the first authentication indicator, it uses the set - cookie command of the http protocol under the interface domain name to enable the electronic device terminal to automatically return the first authentication indicator in the cookie when sending subsequent authentication requests.

[0068] Optionally, when the electronic device terminal sends a second authentication request, if the first public account and the second public account belong to the same client, the electronic device terminal automatically carries the first authentication indicator by obtaining the corresponding command character in the Cookie in the http request header.

[0069] Step S204: Receive the associated authentication token returned by the authentication server and store the associated authentication token in the storage area corresponding to the second public account.

[0070] In one implementation, when receiving the first authentication indicator, the authentication token for characterizing the first user identity information returned by the authentication server is also received. The schematic flowchart of the method for storing the associated authentication token in the storage area corresponding to the first public account is as Figure 2 shown and includes:

[0071] Step S2041: In response to the authentication instruction triggered again by the user through the first public account link, send a third authentication request to the authentication server.

[0072] Optionally, after the electronic device terminal sends a first authentication request to the authentication server, in addition to receiving the first authentication indicator returned by the authentication server, the electronic device terminal also receives the first authentication token for characterizing the first user identity information returned by the authentication server. The electronic device terminal stores the first authentication token in the storage area corresponding to the first public account. However, when the electronic device terminal sends an authentication request through the second public account link and the authentication server completes the association of the first user identity information and the second user identity information, the authentication server generates an associated authentication token and associates the associated authentication token with the first user identity information and the second user identity information respectively. After the electronic device terminal receives the associated authentication token returned by the authentication server, it stores it in the storage area corresponding to the second public account. Therefore, in the memory of the authentication server, the authentication token corresponding to the first user identity information changes from the first authentication token to the associated authentication token. However, at this time, the authentication token corresponding to the first public account at the electronic device terminal has not changed from the first authentication token to the associated authentication token, that is, the authentication token carried in the third authentication request is still the first authentication token.

[0073] Step S2042: Receive the associated authentication token returned by the authentication server.

[0074] Optionally, when the authentication server determines that the first authentication token included in the third authentication request sent by the electronic device terminal is inconsistent with the associated authentication token stored in its own memory, the authentication server determines whether the user identity information included in the first authentication token is consistent with the user identity information included in the associated authentication token. If they are consistent, the authentication server returns the associated authentication token to the electronic device terminal.

[0075] Step S2043, overwrite the authentication token in the storage area corresponding to the first official account with the associated authentication token.

[0076] Optionally, after receiving the authentication server, the electronic device terminal overwrites the first authentication token in the storage area corresponding to the first official account with the associated authentication token to achieve the replacement of the authentication token.

[0077] In one implementation, if there are multiple clients in the electronic device terminal to achieve simultaneous login of different service platform accounts, there will be multiple different authentication indicators stored in the electronic device terminal at this time. These authentication indicators are stored in the client storage area corresponding to the service platform client, but the authentication indicators will be eliminated due to the user clearing the client storage area of the electronic device terminal. The electronic device terminal needs to send an authentication request again to obtain the corresponding authentication indicators.

[0078] For example, in the same electronic device terminal, the authentication indicators for two service platform accounts logged in on different service platform clients also need to be stored separately. For example, for account A and account B, the first official account is displayed on account A, and account A is logged in on service platform client A. The second official account is displayed on account B, and account B is logged in on service platform client B. The corresponding account authentication method process is as Figure 3 shown, and the steps include:

[0079] Step S301, the electronic device terminal responds to the authentication instruction triggered by the user through the first official account link and sends a first authentication request to the authentication server.

[0080] Step S302, the authentication server receives the first authentication request and obtains the first user identity information of the first official account according to the first authentication request.

[0081] Step S303, generate a first authentication indicator for identifying the service platform client information of the first official account, generate a first authentication token according to the first user identity information, store the first authentication indicator, the first authentication token, the first user identity information and the corresponding relationship among the three, and return the first authentication indicator and the first authentication token to the electronic device terminal.

[0082] Step S304, the electronic device terminal receives the first authentication indicator and the first authentication token, stores the first authentication indicator in the client storage area corresponding to service platform client A, and stores the first authentication token in the storage area corresponding to the first official account.

[0083] Step S305, the electronic device terminal responds to the authentication instruction triggered by the user through the second official account link and sends a second authentication request to the authentication server.

[0084] Step S306: The authentication server receives the second authentication request and obtains the second user identity information of the second official account according to the second authentication request.

[0085] Step S307: The authentication server generates a second authentication indicator for identifying the service platform client information of the second official account, generates a second authentication token according to the second user identity information, stores the second authentication indicator, the second authentication token, the second user identity information, and the corresponding relationships among the three, and returns the second authentication indicator and the second authentication token to the electronic device terminal.

[0086] Step S308: The electronic device terminal receives the second authentication indicator and the second authentication token, stores the second authentication indicator in the client storage area corresponding to service platform client B, and stores the second authentication token in the storage area corresponding to the second official account.

[0087] In the above account authentication method, the electronic device terminal stores the authentication indicator in the client storage area corresponding to the service platform client. Thus, when sending an authentication request to the authentication server, the authentication indicator for identifying the electronic device terminal information including the client information can be automatically carried, facilitating the authentication server to obtain the corresponding client information of the official account link, identifying which official accounts come from the same service platform client, and thus achieving account connection and improving the user experience.

[0088] As Figure 4 shown, for ease of understanding, taking the above service platform as the WeChat service platform as an example, the embodiments of the present invention provide a method flow in a specific scenario. The method includes:

[0089] Step S401: Trigger an authentication request for the first official account link in the service platform client of the electronic device terminal and send a first authentication request.

[0090] Step S402, after the authentication server receives the first authentication request, it determines whether the first authentication request contains the authentication token Token generated by the authentication server. If the authentication token Token generated by the authentication server is not included, the first authentication request is sent to the WeChat server to obtain the first user identity information corresponding to the first public account, and the first authentication token Token is generated according to the first user identity information. For the sake of distinction, the first authentication token generated according to the first user identity information is called TokenA; it is determined whether the first authentication request contains the authentication indicator pToken. If it does not contain it, the corresponding first authentication indicator pToken is generated, and the first user identity information, the first authentication token TokenA, the first authentication identifier pToken, and the corresponding relationship among the three are stored in the memory of the authentication server, and the first authentication indicator pToken and the first authentication token TokenA are returned to the electronic device terminal.

[0091] Step S403, after the electronic device terminal receives the first authentication indicator pToken and the first authentication token TokenA, the first authentication indicator pToken is stored in the client storage area of the corresponding service platform client, such as a cookie, and the first authentication token TokenA is stored in the storage area corresponding to the first public account.

[0092] Step S404, the electronic device terminal sends an access request to the authentication server carrying the first authentication token TokenA.

[0093] Step S405, the authentication server determines whether the first authentication token TokenA is valid. If it is valid, the corresponding user personal information is obtained from the storage area corresponding to the first authentication token TokenA and returned to the electronic device terminal.

[0094] Step S406, trigger the authentication request of the second public account link in the same service platform client of the electronic device terminal and send the second authentication request. Since the first public account and the second public account are in the same service platform client, the first authentication indicator pToken will be automatically carried when sending the second authentication request.

[0095] Step S407, after the authentication server receives the second authentication request, it determines whether the second authentication request contains the authentication token generated by the authentication server. If the authentication token Token generated by the authentication server is not included, the second authentication request is sent to the WeChat server to obtain the second user identity information corresponding to the second official account, and the second authentication token Token is generated according to the second user identity information. For distinction, the second authentication token generated according to the second user identity information is TokenB. It is determined whether the second authentication request contains the authentication indicator pToken; if it contains, the user identity information corresponding to the same authentication indicator in the memory is queried, and the associated authentication token Token is generated. For distinction, the generated associated authentication token is called TokenC. The associated authentication token TokenC corresponds to the first user identity information and the second user identity information, and the associated authentication token TokenC and the corresponding relationship between the associated authentication token TokenC and the first user identity information and the second user identity information are stored, and the associated authentication token TokenC is returned to the electronic device terminal.

[0096] Step S408, after the electronic device terminal receives the associated authentication token TokenC, it stores the associated authentication token TokenC in the storage area corresponding to the second official account.

[0097] Step S409, trigger an authentication request for the first official account link in the service platform client of the electronic device terminal, and send a third authentication request, where the third authentication request includes the first authentication token TokenA.

[0098] Step S410, after the authentication server receives the third authentication request, it determines whether the first authentication token TokenA carried in the third authentication request for identifying the first user identity information is consistent with the corresponding authentication token in its own memory. However, at this time, the authentication token corresponding to the first user identity information in its own memory is the associated authentication token, so it is determined that the authentication token carried in the third authentication request is incorrect, and the associated authentication token TokenC is returned.

[0099] Step S411, after the electronic device terminal receives the associated authentication token TokenC, it stores it in the storage area corresponding to the first official account, and sends an access request through the first official account carrying the associated authentication token TokenC.

[0100] Step S412, the authentication server receives the access request, determines whether the authentication token TokenC included in the access request is consistent and valid with the authentication token in its own memory. If it is consistent and valid, it obtains the user personal information corresponding to the storage area corresponding to the associated authentication token TokenC, and returns it to the electronic device terminal.

[0101] In the above account authentication method, a first authentication indicator is generated in the authentication server to identify the electronic device terminal information for logging in to the first public account, and the public account is determined based on this. The public account is stored in the client storage area of the service platform of the electronic device terminal. When the electronic device terminal sends an authentication request, the first authentication indicator can be automatically carried through the http request header. The authentication server determines whether the second public account and the first public account both come from the same service platform client by judging whether the authentication request contains a valid first authentication indicator. If the authentication request contains a valid first authentication indicator, an associated authentication token is generated to correspond to the user identity information of the first public account and the second public account respectively, thereby achieving the effect of account merging.

[0102] An embodiment of the present application further provides an authentication server, which is applied to an account authentication system. The account authentication system further includes an electronic device terminal, as Figure 5 shown, the authentication server 50 includes:

[0103] A receiving module 501, configured to receive a first authentication request triggered by a first public account link;

[0104] An indicator generation module 502, configured to obtain the first user identity information for logging in to the first public account, generate a first authentication indicator, and return the first authentication indicator to the electronic device terminal, where the first authentication indicator is used to identify the electronic device terminal information of the first public account;

[0105] The receiving module 501 is further configured to receive a second authentication request triggered by a second public account link;

[0106] An associated token generation module 503, configured to obtain the second user identity information for logging in to the second public account. If the second authentication request includes the first authentication indicator, an associated authentication token is generated, and the associated authentication token corresponds to the first user identity information and the second user identity information respectively;

[0107] A return module 504, configured to return the associated authentication token to the electronic device terminal.

[0108] In one implementation, the associated token generation module 503 is further configured to generate the associated authentication token when the valid time of the first authentication indicator included in the second authentication request does not exceed a preset time limit.

[0109] In one implementation, as Figure 6As shown, the return module 504 is further configured to, when receiving a third authentication request triggered by the first official account link, if the associated authentication token is not included in the third authentication request, return the associated authentication token to the electronic device terminal.

[0110] In one implementation, the authentication server further includes: the receiving module 501 is further configured to receive an access request triggered by the first official account link or the second official account link; the data acquisition module 505 is configured to, when the associated authentication token is included in the access request, determine whether the associated authentication token is valid, and if so, obtain the user personal information corresponding to the associated authentication token from the combined storage area.

[0111] An embodiment of the present application further provides an electronic device terminal, which is applied to an account authentication system. The account authentication system further includes an authentication server, as Figure 7 shown, the electronic device terminal 60 includes:

[0112] A sending module 601, configured to, in response to an authentication instruction triggered by a user through the first official account link, send a first authentication request to the authentication server;

[0113] A storage module 602, configured to receive the first authentication indicator returned by the authentication server and store the first authentication indicator in the client storage area of the corresponding service platform client in the electronic device terminal, where the first authentication indicator is used to identify the electronic device terminal information of the first official account, and the service platform client is used to display the first official account and the second official account;

[0114] The sending module 601 is further configured to, in response to an authentication instruction triggered by a user through the second official account link, send a second authentication request to the authentication server and add the first authentication indicator to the second authentication request;

[0115] The storage module 602 is further configured to receive the associated authentication token returned by the authentication server and store the associated authentication token in the storage area corresponding to the second official account.

[0116] In one implementation, the sending module 601 is further configured to, in response to an authentication instruction triggered by the user through the first official account link again, send a third authentication request to the authentication server, where the third authentication request includes the authentication token; the storage module 602 is further configured to overwrite the authentication token with the associated authentication token in the storage area corresponding to the first official account.

[0117] As Figure 8As shown in the figure, an embodiment of the present application further provides a schematic structural diagram of an authentication server. The authentication server may include at least one processor; and at least one memory communicatively connected to the above-mentioned processor, where: the memory stores program instructions executable by the processor, and the above-mentioned processor can execute the procedures described in this specification Figures 1 to 4 The account authentication method provided by the embodiment shown.

[0118] As Figure 9 shown in the figure, an embodiment of the present application further provides a schematic structural diagram of an electronic device terminal. The electronic device terminal may include at least one processor; and at least one memory communicatively connected to the above-mentioned processor, where: the memory stores program instructions executable by the processor, and the above-mentioned processor can execute the procedures described in this specification Figures 1 to 4 The account authentication method provided by the embodiment shown.

[0119] As Figure 10 shown in the figure, an embodiment of the present application further provides a schematic structural diagram of an electronic device terminal. The above-mentioned electronic device terminal 100 may include at least one processor 110; and at least one memory communicatively connected to the above-mentioned processor, where: the memory stores program instructions executable by the processor, and the above-mentioned processor can execute the procedures described in this specification Figures 1 to 4 The account authentication method provided by the embodiment shown.

[0120] Among them, the above-mentioned electronic device terminal may be a smart electronic device such as a smart phone, a tablet computer or a notebook computer, and the form of the above-mentioned electronic device terminal is not limited in this embodiment.

[0121] It can be understood that the structure schematically shown in the embodiments of the present invention does not constitute a specific limitation on the electronic device terminal. In other embodiments of the present invention, the electronic device terminal may include more or fewer components than shown in the figure, or combine certain components, or split certain components, or have different component arrangements. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.

[0122] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors.

[0123] The controller can generate operation control signals according to the instruction operation code and timing signals to complete the control of fetching and executing instructions.

[0124] A memory may also be provided in the processor 110 for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can save the instructions or data that the processor 110 has just used or recycled. If the processor 110 needs to use the instruction or data again, it can be directly called from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.

[0125] The processor 110 executes various functional applications and data processing by running the programs stored in the internal memory 121, such as implementing the Figures 1 to 4 account authentication method provided by the embodiments shown in the present invention.

[0126] The wireless communication function of the electronic device terminal 100 can be implemented by the antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor, and baseband processor, etc.

[0127] The antenna 1 and antenna 2 are used for transmitting and receiving electromagnetic wave signals. Each antenna in the electronic device terminal 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example: the antenna 1 can be multiplexed as the diversity antenna of the wireless local area network. In some other embodiments, the antenna can be used in combination with a tuning switch.

[0128] The electronic device terminal 100 implements the display function through the GPU, the display screen 194, the application processor, etc. The GPU is a microprocessor for image processing, connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 may include one or more GPUs, which execute program instructions to generate or change the display information.

[0129] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. The display panel can adopt a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active matrix organic light-emitting diode or an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the electronic device terminal 100 may include 1 or N display screens 194, where N is a positive integer greater than 1.

[0130] The electronic device terminal 100 can implement the shooting function through the ISP, the camera 193, the video codec, the GPU, the display screen 194, the application processor, etc.

[0131] The ISP is used to process the data fed back by the camera 193. For example, when taking a photo, the shutter is opened, and the light passes through the lens and is transmitted to the camera photosensitive element. The optical signal is converted into an electrical signal, and the camera photosensitive element transmits the electrical signal to the ISP for processing and converts it into an image visible to the naked eye. The ISP can also optimize the noise, brightness, and skin color of the image through algorithms. The ISP can also optimize parameters such as the exposure and color temperature of the shooting scene. In some embodiments, the ISP can be set in the camera 193.

[0132] The camera 193 is used to capture static images or videos. An object generates an optical image through a lens and projects it onto a photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the optical signal into an electrical signal, and then transfers the electrical signal to the ISP to be converted into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard format such as RGB or YUV. In some embodiments, the electronic device terminal 100 may include one or N cameras 193, where N is a positive integer greater than 1.

[0133] The digital signal processor is used to process digital signals. In addition to processing digital image signals, it can also process other digital signals. For example, when the electronic device terminal 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy, etc.

[0134] The video codec is used to compress or decompress digital videos. The electronic device terminal 100 can support one or more video codecs. In this way, the electronic device terminal 100 can play or record videos in multiple coding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, MPEG4, etc.

[0135] The internal memory 121 can be used to store computer-executable program code, and the executable program code includes instructions. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area can store the operating system, application programs required for at least one function (such as the sound playback function, the image playback function, etc.). The data storage area can store the data created during the use of the electronic device terminal 100 (such as audio data, phone book, etc.). In addition, the internal memory 121 may include high-speed random access memory and may also include non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc. The processor 110 executes various functional applications and data processing of the electronic device terminal 100 by running the instructions stored in the internal memory 121 and / or the instructions stored in the memory provided in the processor.

[0136] The embodiments of the present application also provide a computer-readable storage medium, on which computer instructions are stored, and when the instructions are executed by a processor, the steps of the above account authentication method are implemented. The readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.

[0137] The specific embodiments of this specification have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be executed in a different order than in the embodiments and still achieve the desired result. Additionally, the processes depicted in the figures do not necessarily require the particular order or sequential order shown to achieve the desired result. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0138] In the description of the embodiments of the present invention, the descriptions referring to the terms "one embodiment", "some embodiments", "example", "specific example", or "some examples", etc. mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of this specification. In this specification, the schematic representations of the above terms do not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described may be combined in any one or more embodiments or examples in a suitable manner. In addition, without contradiction, those skilled in the art may combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0139] Any process or method description in the flowchart or described in other ways herein may be understood to represent a module, segment, or portion of code including one or more executable instructions for implementing a customized logical function or process, and the scope of the preferred embodiments of this specification includes additional implementations, where the functions may be executed in a manner not shown or discussed, including in a substantially simultaneous manner or in a reverse order according to the involved functions, which should be understood by those skilled in the art to which the embodiments of this specification pertain.

[0140] Depending on the context, the word "if" as used herein may be interpreted as "when" or "while" or "in response to determining" or "in response to detecting". Similarly, depending on the context, the phrase "if determined" or "if detecting (stated condition or event)" may be interpreted as "when determined" or "in response to determining" or "when detecting (stated condition or event)" or "in response to detecting (stated condition or event)".

[0141] In several embodiments provided in this specification, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces. The indirect coupling or communication connection of the devices or units can be in electrical, mechanical, or other forms.

[0142] In addition, in each embodiment of this specification, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of a combination of hardware and software functional units.

[0143] The above-mentioned integrated units implemented in the form of software functional units can be stored in a computer-readable storage medium. The above-mentioned software functional units stored in a storage medium include several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute some steps of the methods described in each embodiment of this specification. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROMs), random access memories (RAMs), magnetic disks, or optical discs that can store program codes.

[0144] The above is only a preferred embodiment of this specification and is not intended to limit this specification. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of this specification shall be included within the scope of protection of this specification.

Claims

1. An account authentication method, which is applied to an authentication server of an account authentication system, and the account authentication system further includes an electronic device terminal, characterized in that, The method includes: Receiving a first authentication request triggered by a first official account link; Obtaining first user identity information for logging in to the first official account, generating a first authentication indicator, and returning the first authentication indicator to the electronic device terminal, where the first authentication indicator is used to identify the electronic device terminal information for logging in to the first official account; Receiving a second authentication request triggered by a second official account link; Obtaining second user identity information for logging in to the second official account, and if the second authentication request includes the first authentication indicator, generating an associated authentication token, where the associated authentication token corresponds to the first user identity information and the second user identity information respectively; Returning the associated authentication token to the electronic device terminal.

2. The method according to claim 1, wherein The generating of the associated authentication token includes: When the valid time of the first authentication indicator included in the second authentication request does not exceed a preset time limit, generating the associated authentication token.

3. The method according to claim 1 or 2, characterized in that, When returning the first authentication indicator to the electronic device terminal, also returning an authentication token for characterizing the first user identity information; After generating the associated authentication token, the method further includes: Receiving a third authentication request triggered by the first official account link, where the third authentication request includes the authentication token for characterizing the first user identity information; If the first user identity information included in the authentication token for characterizing the first user identity information is consistent with the first user identity information corresponding to the associated authentication token, returning the associated authentication token to the electronic device terminal.

4. The method according to claim 3, wherein The first user identity information and the second user identity information respectively corresponding to the associated authentication token both correspond to a combined storage area, and the combined storage area is used to store user personal information. The method further includes: Receiving an access request triggered by the first official account link or the second official account link; When the access request includes the associated authentication token, determining whether the associated authentication token is valid. If so, obtaining the user personal information corresponding to the associated authentication token from the combined storage area.

5. An account authentication method, applied to an electronic device terminal of an account authentication system, the account authentication system further comprising an authentication server, characterized in that, The method includes: In response to an authentication instruction triggered by a first official account link displayed by a user through a service platform client, sending a first authentication request to the authentication server; Receiving the first authentication indicator returned by the authentication server, and storing the first authentication indicator in a client storage area corresponding to the service platform client in the electronic device terminal, where the first authentication indicator is used to identify the electronic device terminal information for logging in to the first official account; In response to an authentication instruction triggered by a second official account link displayed by the user through the service platform client, sending a second authentication request to the authentication server, and adding the first authentication indicator to the second authentication request; Receiving the associated authentication token returned by the authentication server, and storing the associated authentication token in a storage area corresponding to the second official account.

6. The method according to claim 5, characterized in that, The method further includes: After sending a first authentication request to the authentication server, receive an authentication token returned by the authentication server for characterizing the first user identity information, and store the authentication token characterizing the first user identity information in the storage area corresponding to the first official account; In response to an authentication instruction triggered again by the user through the link of the first official account, send a third authentication request to the authentication server, where the third authentication request includes the authentication token for characterizing the first user identity information; Receive the associated authentication token returned by the authentication server; In the storage area corresponding to the first official account, overwrite the authentication token for characterizing the first user identity information with the associated authentication token.

7. The method according to claim 5 or 6, characterized in that, The client storage area includes a text file cookie.

8. An authentication server is applied to an account authentication system, and the account authentication system further includes an electronic device terminal, characterized in that, The authentication server includes: A receiving module, configured to receive a first authentication request triggered through a link of the first official account; An indicator generation module, configured to obtain the first user identity information for logging in to the first official account, generate a first authentication indicator, and return the first authentication indicator to the electronic device terminal, where the first authentication indicator is used to identify the electronic device terminal information for logging in to the first official account; The receiving module is further configured to receive a second authentication request triggered through a link of the second official account; An associated token generation module, configured to obtain the second user identity information for logging in to the second official account, and if the second authentication request includes the first authentication indicator, generate an associated authentication token, where the associated authentication token corresponds to the first user identity information and the second user identity information respectively; A return module, configured to return the associated authentication token to the electronic device terminal.

9. An electronic device terminal is applied to an account authentication system, and the account authentication system further includes an authentication server, characterized in that, The electronic device terminal includes: A sending module, configured to, in response to an authentication instruction triggered by the user through a link of the first official account displayed by the service platform client, send a first authentication request to the authentication server; A storage module, configured to receive the first authentication indicator returned by the authentication server, and store the first authentication indicator in the client storage area corresponding to the service platform client in the electronic device terminal, where the first authentication indicator is used to identify the electronic device terminal information for logging in to the first official account; The sending module is further configured to, in response to an authentication instruction triggered by the user through a link of the second official account displayed by the service platform client, send a second authentication request to the authentication server, and add the first authentication indicator to the second authentication request; The storage module is further configured to receive the associated authentication token returned by the authentication server, and store the associated authentication token in the storage area corresponding to the second official account.

10. An authentication server, characterized in that, Includes: At least one processor; And At least one memory communicatively connected to the processor, where: the memory stores program instructions executable by the processor, and the processor can execute the method according to any one of claims 1 to 4 by invoking the program instructions.

11. An electronic device terminal, characterized in that, Includes: At least one processor; And At least one memory communicatively connected to the processor, where: The memory stores program instructions executable by the processor, and the processor can execute the method according to any one of claims 5 to 7 by invoking the program instructions.

Citation Information

Patent Citations

  • Authentication interaction method and system of business system and storage medium

    CN112417416A