A method and storage medium for unified identity authentication
Through symmetric encryption algorithms and timestamp verification, the problem of insufficient security of information transmission in the unified authentication system is solved, and a more secure unified identity authentication is achieved.
Patent Information
- Application Number
- CN202111545285.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-16
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2041-12-16
AI Technical Summary
In the existing unified authentication system, there is a security risk for usernames and passwords to be transmitted through plain text, and users are prone to forget passwords, resulting in unsafe identity authentication.
A symmetric encryption algorithm is used to transmit information using application passwords as keys, and a time stamp is introduced during the authentication process for aging verification to ensure information security.
Improve the security of unified identity authentication, reduce the risks of key leakage and tampering, and ensure the security of data transmission and the access security of the authentication platform.
Smart Images

Figure CN114186208B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of unified authentication, and in particular to a method and storage medium for unified identity authentication. Background Art
[0002] With the development of information technology, there are more and more application programs. Since application programs are independent of each other, users must log in according to the corresponding identities when using each application program. Therefore, users must remember the accounts and passwords of each application program, which brings a lot of trouble to users. Therefore, concepts such as unified authentication and single sign-on have emerged.
[0003] Unified authentication is an authentication method that unifies the management of user identity information under different application systems by establishing unified user management and permission management, so that the identity of the same user is consistent in all applications, and the application program does not need to care about the authentication process. The purpose of unified authentication is to achieve single sign-on of applications, realize dynamic synchronization of user identities and permissions, strengthen information security early warning and auditing, and improve the availability, security and convenience of user use of the system. For example, for two applications A and B, a unified authentication platform is established, and user information is named and stored in a standardized format on the unified authentication platform. The user ID is globally unique, and any changes to the user information of applications A and B are processed by the unified authentication platform. Applications A and B can select the user information attributes they need.
[0004] When a user logs in, the common identity authentication method is to check whether the user name and password (password) entered by the user are consistent with the user name and password stored for the user to determine whether the user identity is correct. More complex identity authentication methods use some more complex encryption algorithms and protocols, and require the user to present more information (such as a private key) to prove their identity, such as the Kerberos identity authentication system.
[0005] The user name and password authentication method is relatively simple to implement. The unified authentication server provides a unified Webservice authentication service to the application program. It receives the user name and password passed by the application program, compares them with the user information stored in the unified authentication server, and returns the authentication token to the application program after successful verification. The user completes the login in the application program. The disadvantage is that the user name and password are transmitted in plain text during the authentication process, there is a security risk of being intercepted and misused; and users are prone to forget the password.
[0006] In summary, in the unified authentication system, a more secure authentication method is needed. Summary of the Invention
[0007] The purpose of the present invention is to provide a method and storage medium for unified identity authentication to overcome the defects of the above-mentioned prior art.
[0008] The object of the present invention can be achieved by the following technical solutions:
[0009] A method for unified identity authentication, used for identity authentication between users, application programs and a unified authentication platform. A symmetric encryption algorithm is used between the application program and the unified authentication platform, including the following steps:
[0010] S1. The application program registers on the unified authentication platform. The unified authentication platform generates a token and a key key for the application program and issues them to the application program. Both the application program and the unified authentication platform store the token and the key key.
[0011] S2. The user logs in to the application program. The application program obtains the user information input by the user. The application program encrypts the token and the timestamp information with the key key to obtain an authentication ciphertext, and sends the authentication ciphertext, the token and the user information to the unified authentication platform.
[0012] S3. The unified authentication platform decrypts the authentication ciphertext to obtain the token and the timestamp, verifies the legitimacy of the token and the timeliness of the timestamp. If the legitimacy and timeliness pass, the user information is verified, and step S4 is executed. Otherwise, a prompt for failed verification of the authentication ciphertext is given.
[0013] S4. If the user information verification is correct, a session ID is generated. The unified authentication platform returns the session ID to the application program. Otherwise, a prompt for failed verification of the user information is given.
[0014] Further, step S1 includes the following steps:
[0015] S11. The application program sends the registration information and the registration request to the unified authentication platform. After receiving the registration request, the unified authentication platform generates an application ID and an application password apppwd based on the registration information, and issues the application ID and the application password apppwd to the application program.
[0016] S12. The application program uses the application password apppwd as the key to encrypt the application ID and the timestamp to obtain an authorization Auth. The application program sends the user ID and the authorization Auth to the unified authentication platform.
[0017] S13. The unified authentication platform verifies the validity of the authorization Auth. If it is invalid, a prompt for expired authorization Auth is given. Otherwise, the unified authentication platform decrypts the authorization Auth with the application password apppwd to obtain the application ID and the timestamp, verifies the legitimacy of the application ID and the timeliness of the timestamp. If the legitimacy and timeliness pass, the unified authentication platform generates a token and a key key for the application program, and executes step S14. Otherwise, a prompt for failed verification of the authorization Auth is given.
[0018] S14. The unified authentication platform uses the application password apppwd as the key to encrypt the key key to obtain the registration ciphertext, and issues the registration ciphertext and the token to the application program together. The application program receives the registration ciphertext and the token, and decrypts the registration ciphertext to obtain the key;
[0019] Among them, in the unified authentication platform, the application ID and the token correspond uniquely to the application program. During the application program registration process (step S1), the unified authentication platform identifies the application program through the application ID. During the user login process of the application program, the unified authentication platform identifies the application program through the token. The application ID corresponds to the application password apppwd. In the unified authentication platform, the corresponding relationship between the application ID and the application password apppwd is stored. In this way, the corresponding application password apppwd can be found according to the application ID. The token corresponds to the key key. Similarly, in the unified authentication platform, the corresponding relationship between the token and the key key is stored. In this way, the corresponding key key can be found according to the token.
[0020] Further, the registration information includes the program number information that uniquely identifies the application program.
[0021] Further, in step S13, verifying the validity of the authorization Auth specifically is: before the unified authentication platform decrypts the authorization Auth, first compare the received authorization Auth with the historical records in the cache. If they are not repeated, the authorization Auth is valid, decrypt the authorization Auth, and write the authorization Auth into the cache. Otherwise, the authorization Auth is invalid, and an authorization Auth expiration prompt is given.
[0022] Further, verifying the legality of the application ID and the timeliness of the timestamp in step S13 specifically is:
[0023] The unified authentication platform obtains the received application ID, and obtains the application ID obtained by decrypting the authorization Auth. If the two application IDs are the same, the legality of the application ID passes. Otherwise, the legality of the application ID does not pass;
[0024] The unified authentication platform obtains the current time, and obtains the timestamp obtained by decrypting the authorization Auth. If the difference between the current time and the timestamp is not greater than the preset delay threshold, the timeliness of the timestamp passes. Otherwise, the timeliness of the timestamp does not pass.
[0025] Further, verifying the legality of the token and the timeliness of the timestamp in step S3 specifically is:
[0026] The unified authentication platform obtains the received token, and obtains the token obtained by decrypting the authentication ciphertext. If the two tokens are the same, the legality of the token passes. Otherwise, the legality of the token does not pass;
[0027] The unified authentication platform obtains the current time and the timestamp obtained by decrypting the authentication ciphertext. If the difference between the current time and the timestamp is not greater than a preset delay threshold, the timeliness of the timestamp passes; otherwise, the timeliness of the timestamp fails.
[0028] Further, the symmetric encryption algorithm is the AES encryption algorithm.
[0029] Further, in step S2, the user information input by the user is the mobile phone number and the mobile phone SMS verification code. In step S3, the verification of the user information is specifically the verification of the mobile phone number and the verification code, which is the same as the verification method in the existing login verification.
[0030] Further, in step S2, the user information input by the user is the user account and the strong password. In step S3, the verification of the user information is specifically the verification of the user account and the strong password, which is the same as the verification method in the existing login verification.
[0031] Further, it further includes step S5: After the user completes the login, when the user uses the application program and requests to obtain service resources, the application program encrypts the session ID and the timestamp with the key key to obtain a request ciphertext, and sends the token, the service resource acquisition request, and the request ciphertext to the unified authentication platform;
[0032] The unified authentication platform finds the corresponding key key according to the token, decrypts the request ciphertext to obtain the session ID and the timestamp, verifies the timeliness of the timestamp, determines the user's permissions according to the session ID, and compares the user's permissions with the service resource acquisition request. If the permissions are satisfied, the corresponding service resources are returned; if the permissions are not satisfied, a permission deficiency is prompted.
[0033] Further, the verification of the timeliness of the timestamp is specifically: If the difference between the current time and the timestamp is not greater than a preset delay threshold, the timeliness of the timestamp passes; otherwise, the timeliness of the timestamp fails.
[0034] A computer storage medium, on which an executable computer program is stored, including an application-side program executed on the application program and a platform-side program executed on the unified authentication platform. When the computer program is executed, it implements a unified identity authentication method as described above.
[0035] Compared with the prior art, the present invention has the following beneficial effects:
[0036] (1) During the application registration process, the application password is used as the key to encrypt information transmission, thereby ensuring the security of the application's key "key", reducing the risk of the key "key" leakage and being tampered with. Moreover, the authorization "Auth" also includes timestamp information, and aging verification is performed through the timestamp, further ensuring the security of data transmission, and thus ensuring the security during the unified identity authentication process.
[0037] (2) When the user logs in to the application, the user information is transmitted normally, and the token and timestamp are encrypted into an authentication ciphertext, which can better ensure the security of access to the authentication platform while ensuring the unified identity authentication.
[0038] (3) The authorization "Auth" is put into the cache after use, and through the strategy of "once used, it becomes invalid", the security during the unified identity authentication process is further ensured. Brief Description of the Drawings
[0039] Figure 1 It is a schematic flow diagram of the present invention. Detailed Embodiments
[0040] The present invention will be described in detail below with reference to the drawings and specific embodiments. This embodiment is implemented on the premise of the technical solution of the present invention, and gives detailed implementation manners and specific operation processes, but the protection scope of the present invention is not limited to the following embodiments.
[0041] Embodiment 1:
[0042] A method for unified identity authentication, which is used for identity authentication between users, applications and a unified authentication platform. A symmetric encryption algorithm is used between the application and the unified authentication platform (in this embodiment, the symmetric encryption algorithm is the AES encryption algorithm, and in other embodiments, other symmetric encryption algorithms, such as DES, etc., can be used).
[0043] The backend server of the application interacts with the unified authentication platform, and the user interacts with the front end of the application. The unified authentication platform can obtain the user database of the application, so as to perform unified authentication. As Figure 1 shown, the method for unified identity authentication includes the following steps:
[0044] S1. The application registers in the unified authentication platform, and the unified authentication platform generates a token and a key "key" for the application and distributes them to the application. Both the application and the unified authentication platform store the token and the key "key".
[0045] Specifically, step S1 includes the following steps:
[0046] S11. The application sends the registration information and registration request to the unified authentication platform. After receiving the registration request, the unified authentication platform generates an application ID and an application password apppwd based on the registration information, and sends the application ID and the application password apppwd to the application;
[0047] S12. The application encrypts the application ID and the timestamp with the application password apppwd as the key to obtain an authorization Auth, and the application sends the user ID and the authorization Auth to the unified authentication platform;
[0048] S13. The unified authentication platform verifies the validity of the authorization Auth. If it is invalid, it gives a prompt that the authorization Auth has expired. Otherwise, it decrypts the authorization Auth with the application password apppwd to obtain the application ID and the timestamp, and verifies the legality of the application ID and the timeliness of the timestamp. If the legality and timeliness pass, the unified authentication platform generates a token and a key key for the application, and executes step S14. Otherwise, it gives a prompt that the authorization Auth verification fails;
[0049] Specifically, to verify the validity of the authorization Auth: before decrypting the authorization Auth, the unified authentication platform first compares the received authorization Auth with the historical records in the cache. If they are not repeated, the authorization Auth is valid, decrypt the authorization Auth, and write the authorization Auth into the cache. Otherwise, the authorization Auth is invalid, and a prompt that the authorization Auth has expired is given.
[0050] Specifically, to verify the legality of the application ID and the timeliness of the timestamp:
[0051] The unified authentication platform obtains the received application ID, and obtains the application ID obtained by decrypting the authorization Auth. If the two application IDs are the same, the legality of the application ID passes. Otherwise, the legality of the application ID does not pass;
[0052] The unified authentication platform obtains the current time, and obtains the timestamp obtained by decrypting the authorization Auth. If the difference between the current time and the timestamp is not greater than the preset delay threshold, the timeliness of the timestamp passes. Otherwise, the timeliness of the timestamp does not pass.
[0053] S14. The unified authentication platform encrypts the key key with the application password apppwd as the key to obtain a registration ciphertext, and sends the registration ciphertext and the token to the application together. The application receives the registration ciphertext and the token, and decrypts the registration ciphertext to obtain the key;
[0054] Among them, in the unified authentication platform, the application ID and the token correspond uniquely to the application. During the application registration process (step S1), the unified authentication platform identifies the application through the application ID. During the process of a user logging in to the application, the unified authentication platform identifies the application through the token. The application ID corresponds to the application password apppwd. The corresponding relationship between the application ID and the application password apppwd is stored in the unified authentication platform. In this way, the corresponding application password apppwd can be found according to the application ID. The token corresponds to the secret key key. Similarly, the corresponding relationship between the token and the secret key key is stored in the unified authentication platform. In this way, the corresponding secret key key can be found according to the token.
[0055] In this embodiment, the registration information includes the program number information that uniquely identifies the application. In other embodiments, the registration information may further include information such as the permissions and descriptions of the application.
[0056] S2. The user logs in to the application. The application obtains the user information input by the user. The application uses the secret key key to encrypt the token and the timestamp information to obtain the authentication ciphertext, and sends the authentication ciphertext, the token, and the user information to the unified authentication platform;
[0057] The user information input by the user in step S2 is the mobile phone number and the mobile phone SMS verification code. The verification of the user information in step S3 is specifically the verification of the mobile phone number and the verification code, which is the same as the verification method in the existing login verification.
[0058] The user information input by the user in step S2 is the user account and the strong password. The verification of the user information in step S3 is specifically the verification of the user account and the strong password, which is the same as the verification method in the existing login verification.
[0059] Generally, when a user uses the application for the first time, the user needs to register an account and set a password. Therefore, when logging in to the application for the first time, the information input by the user is the mobile phone number and the mobile phone SMS verification code. After the user logs in for the first time using the mobile phone number and the verification code, the user can set a strong password (i.e., the password of the account) in the application. When logging in to the application again later, the user can use the user account and the strong password to log in. Similarly, if the account is bound to a mobile phone number, the user can also continue to log in through the mobile phone number and the mobile phone SMS verification code.
[0060] The data transmission method of the user information uses the commonly used data transmission methods in the art, such as encryption using the MD5 method (MD5 encryption is irreversible), etc. The data transmission method and the verification method are both commonly used means in the art and will not be elaborated here. Relevant industry practitioners can understand.
[0061] S3. The unified authentication platform decrypts the authentication ciphertext to obtain a token and a timestamp, verifies the legitimacy of the token and the timeliness of the timestamp. If the legitimacy and timeliness pass, it verifies the user information and executes step S4; otherwise, it gives a prompt indicating that the verification of the authentication ciphertext fails.
[0062] The specific verification of the legitimacy of the token and the timeliness of the timestamp in step S3 is as follows:
[0063] The unified authentication platform obtains the received token and the token obtained by decrypting the authentication ciphertext. If the two tokens are the same, the legitimacy of the token passes; otherwise, the legitimacy of the token fails.
[0064] The unified authentication platform obtains the current time and the timestamp obtained by decrypting the authentication ciphertext. If the difference between the current time and the timestamp is not greater than the preset delay threshold, the timeliness of the timestamp passes; otherwise, the timeliness of the timestamp fails.
[0065] S4. If the user information verification is correct, a session ID is generated, and the unified authentication platform returns the session ID to the application; otherwise, it gives a prompt indicating that the user information verification fails.
[0066] S5: After the user completes the login, when the user uses the application and requests to obtain service resources, the application encrypts the session ID and the timestamp using the key key to obtain a request ciphertext, and sends the token, the service resource acquisition request, and the request ciphertext to the unified authentication platform.
[0067] The unified authentication platform finds the corresponding key key according to the token, decrypts the request ciphertext to obtain the session ID and the timestamp, verifies the timeliness of the timestamp, determines the user's permissions according to the session ID, and compares the user's permissions with the service resource acquisition request. If the permissions are satisfied, the corresponding service resources are returned; if the permissions are not satisfied, a prompt indicating insufficient permissions is given.
[0068] The specific verification of the timeliness of the timestamp is as follows: If the difference between the current time and the timestamp is not greater than the preset delay threshold, the timeliness of the timestamp passes; otherwise, the timeliness of the timestamp fails.
[0069] This application encrypts the information transmission between the application and the unified authentication platform through a symmetric encryption algorithm, thus avoiding risks such as data leakage and tampering, and improving the security of unified authentication.
[0070] A computer storage medium, on which an executable computer program is stored, including an application-side program executed on the application and a platform-side program executed on the unified authentication platform. When the computer program is executed, it implements a unified identity authentication method:
[0071] S1. The application registers on the unified authentication platform. The unified authentication platform generates a token and a key for the application and distributes them to the application. Both the application and the unified authentication platform store the token and the key.
[0072] S2. The user logs in to the application. The application obtains the user information entered by the user. The application uses the key to encrypt the token and the timestamp information to obtain an authentication ciphertext, and sends the authentication ciphertext, the token, and the user information to the unified authentication platform.
[0073] S3. The unified authentication platform decrypts the authentication ciphertext to obtain the token and the timestamp, verifies the legitimacy of the token and the timeliness of the timestamp. If the legitimacy and timeliness pass, it verifies the user information and executes step S4. Otherwise, it gives a prompt that the authentication ciphertext verification fails.
[0074] S4. If the user information verification is correct, it generates a session ID. The unified authentication platform returns the session ID to the application. Otherwise, it gives a prompt that the user information verification fails.
[0075] In this embodiment, when the application registers in step S1, the authorization Auth verification of the unified authentication platform is implemented as follows. Here, token is the token and key is the key. After the unified authentication platform receives the authorization Auth sent by the application, it compares it with the historical records in the cache. If it is not repeated, it decrypts it, verifies the legitimacy of the application ID and the timeliness of the timestamp, and writes it into the cache (the strategy that the authorization Auth becomes invalid after use). The following is an example implementation in C++ language:
[0076] / / Obtain Auth from the http request parameters
[0077] string auth = getHttpParam(http, http_auths, false);
[0078] if (auth == "") { / / If auth is empty, return 401 unauthorized
[0079] / / 401 Not Unauthorized
[0080] CHttpResponse::response_401_error(strrep, "auth not found");
[0081] return strrep;
[0082] }
[0083] / / Check the cache to see if Auth has expired
[0084] string kv = redis.execxCmd("ttl %s", auth);
[0085] if (atol(kv.c_str()) > 0 && atol(kv.c_str()) < option_ttltime) {
[0086] / / If Auth exists, it means it has been used, return 401
[0087] / / 401 Not Unauthorized
[0088] CHttpResponse::response_401_error(strrep, "auth invaild");
[0089] return strrep;
[0090] }
[0091] / / Get the timestamp
[0092] string stime = AES_decode(auth, key, true);
[0093] string ntime = GetSysTime("yyyy-MM-dd hh:mm:ss");
[0094] / / Compare the timestamp with the current time
[0095] long dt = GetDiffTime(ntime, stime);
[0096] long expireTime = option_timeout;
[0097] if (dt > expireTime || dt < 0) {
[0098] / / If it times out or is ahead of time, return 401 Unauthorized
[0099] CHttpResponse::response_401_error(strrep, "timeout");
[0100] return strrep;
[0101] }
[0102] / / Write to the cache and set the expiration time
[0103] redis.execxCmd("set %s %s", auth, ntime);
[0104] redis.execxCmd("expire %s %ld", auth, expireTime);
[0105] After the application registration is completed, the identity authentication process when the user logs in to the application is as follows. Here, appid is the application ID and apppwd is the application password. The following is an example in C# code:
[0106] (1) Obtain Auth through the sdk
[0107] [DllImport("auth.dll", CharSet = CharSet.Auto, SetLastError = true)]
[0108] public static extern string getAuth(string str, string key);
[0109] string auth = getAuth(appid, apppwd);
[0110] (2) Obtain the token through the API
[0111] post http: / / *.*.*.* / token
[0112] Request type: application / json
[0113] {
[0114] …
[0115] “appid”: “**********************”,
[0116] “auth”: “*******************************”
[0117] }
[0118] (3) Log in and authenticate through the API
[0119] Where phone is the mobile phone number, code is the SMS verification code encrypted with MD5, and token is the token
[0120] post http: / / *.*.*.* / login
[0121] Request type: application / json
[0122] {
[0123] …
[0124] "phone": "13*********",
[0125] "code": "********",
[0126] "token": "**********************",
[0127] "auth": "*******************************"
[0128] }
[0129] (4) Invoke the service through the API
[0130] post http: / / *.*.*.* / service / Service ID
[0131] Request type: application / json
[0132] {
[0133] …
[0134] "sessionID": "**********************",
[0135] "auth": "*******************************"
[0136] }
[0137] The preferred specific embodiments of the present invention are described in detail above. It should be understood that those of ordinary skill in the art can make many modifications and variations based on the concept of the present invention without creative efforts. Therefore, all technical solutions that can be obtained by those skilled in the art in the technical field based on the concept of the present invention through logical analysis, reasoning or limited experiments on the basis of the prior art should fall within the protection scope determined by the claims.
Claims
1. A method for unified identity authentication, which is used to perform identity authentication among users, application programs and a unified authentication platform, and is characterized in that, A symmetric encryption algorithm is used between the application and the unified authentication platform, including the following steps: S1. The application registers with the unified authentication platform. The unified authentication platform generates a token and a key "key" for the application and distributes them to the application. Both the application and the unified authentication platform store the token and the key "key". S2. The user logs in to the application. The application obtains the user information input by the user. The application uses the key "key" to encrypt the token and the timestamp information to obtain an authentication ciphertext, and sends the authentication ciphertext, the token, and the user information to the unified authentication platform. S3. The unified authentication platform decrypts the authentication ciphertext to obtain the token and the timestamp, verifies the legitimacy of the token and the timeliness of the timestamp. If the legitimacy and timeliness pass, it verifies the user information and executes step S4. Otherwise, it gives a prompt that the authentication ciphertext verification fails. S4. If the user information verification is correct, a session ID is generated. The unified authentication platform returns the session ID to the application. Otherwise, it gives a prompt that the user information verification fails. Step S1 includes the following steps: S11. The application sends the registration information and the registration request to the unified authentication platform. After receiving the registration request, the unified authentication platform generates an application ID and an application password "apppwd" based on the registration information, and distributes the application ID and the application password "apppwd" to the application. S12. The application uses the application password "apppwd" as the key to encrypt the application ID and the timestamp to obtain an authorization "Auth". The application sends the user ID and the authorization "Auth" to the unified authentication platform. S13. The unified authentication platform verifies the validity of the authorization "Auth". If it is invalid, it gives a prompt that the authorization "Auth" has expired. Otherwise, it decrypts the authorization "Auth" using the application password "apppwd" to obtain the application ID and the timestamp, and writes the authorization "Auth" into the cache. It verifies the legitimacy of the application ID and the timeliness of the timestamp. If the legitimacy and timeliness pass, the unified authentication platform generates a token and a key "key" for the application and executes step S14. Otherwise, it gives a prompt that the authorization "Auth" verification fails. S14. The unified authentication platform uses the application password "apppwd" as the key to encrypt the key "key" to obtain a registration ciphertext, and distributes the registration ciphertext and the token to the application. The application receives the registration ciphertext and the token, and decrypts the registration ciphertext to obtain the key. Among them, in the unified authentication platform, the application ID and the token correspond uniquely to the application. The application ID corresponds to the application password "apppwd", and the token corresponds to the key "key".
2. The method for unified identity authentication according to claim 1, wherein, The registration information includes program number information that uniquely identifies the application.
3. A method for unified identity authentication according to claim 1, characterized in that, In step S13, verifying the validity of the authorization "Auth" specifically means: before the unified authentication platform decrypts the authorization "Auth", it first compares the received authorization "Auth" with the historical records in the cache. If they are not repeated, the authorization "Auth" is valid, decrypt the authorization "Auth" and write the authorization "Auth" into the cache. Otherwise, the authorization "Auth" is invalid and a prompt that the authorization "Auth" has expired is given.
4. A method for unified identity authentication according to claim 1, characterized in that, In step S13, the specific verification of the legality of the application ID and the timeliness of the timestamp is as follows: The unified authentication platform obtains the received application ID and the application ID obtained by decrypting the authorization Auth. If the two application IDs are the same, the legality of the application ID passes; otherwise, the legality of the application ID fails. The unified authentication platform obtains the current time and the timestamp obtained by decrypting the authorization Auth. If the difference between the current time and the timestamp is not greater than the preset delay threshold, the timeliness of the timestamp passes; otherwise, the timeliness of the timestamp fails.
5. A method for unified identity authentication according to claim 1, characterized in that, In step S3, the specific verification of the legality of the token and the timeliness of the timestamp is as follows: The unified authentication platform obtains the received token and the token obtained by decrypting the authentication ciphertext. If the two tokens are the same, the legality of the token passes; otherwise, the legality of the token fails. The unified authentication platform obtains the current time and the timestamp obtained by decrypting the authentication ciphertext. If the difference between the current time and the timestamp is not greater than the preset delay threshold, the timeliness of the timestamp passes; otherwise, the timeliness of the timestamp fails.
6. The method for unified identity authentication according to claim 1, wherein In step S2, the user information input by the user is the mobile phone number and the mobile phone SMS verification code. In step S3, the verification of the user information is specifically the verification of the mobile phone number and the verification code.
7. A method for unified identity authentication according to claim 1, characterized in that, In step S2, the user information input by the user is the user account and the strong password. In step S3, the verification of the user information is specifically the verification of the user account and the strong password.
8. A method for unified identity authentication according to claim 1, characterized in that, It further includes step S5: After the user completes the login, when the user uses the application program and requests to obtain service resources, the application program encrypts the session ID and the timestamp with the key key to obtain a request ciphertext, and sends the token, the service resource acquisition request, and the request ciphertext to the unified authentication platform.
9. A computer storage medium, characterized in that, Stored thereon is an executable computer program, including an application-side program executed on the application program and a platform-side program executed on the unified authentication platform. When the computer program is executed, it implements a unified identity authentication method as described in any one of claims 1-8.
Citation Information
Patent Citations
Application login method and system, terminal and electronic equipment
CN110324276A