Multi-identity switching method and device
By implementing a multi-identity switching method in the application system, users can quickly switch and access different system identities, solving the problems of cumbersome operations and poor user experience in the prior art, and improving user convenience.
Patent Information
- Application Number
- CN202111524253.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-14
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2041-12-14
AI Technical Summary
When existing application systems need to switch different system identities, the operation is complicated. Users need to remember multiple accounts and passwords, and need to log out and log in repeatedly, affecting the user experience.
A multi-identity switching method is provided, by receiving a user's identity switching request, it determines whether the target identity is associated with the current identity. If associated, update the session information and application access rights of the user's current session to realize identity switching.
It simplifies the operation process of user identity switching and improves user convenience. Users do not need to log out and log in repeatedly, and can quickly switch and access the required applications.
Smart Images

Figure CN114218539B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of identity security technology, and in particular to a multi-identity switching method and device. Background Art
[0002] With the development of Internet technology and the increasingly detailed division of labor in society, the same user in the application system often needs to use different system permissions to complete different tasks. For example, a user is seconded to work in other departments or regions during a certain period of time, and the work in different departments or regions has different application permissions. At this time, if the user needs to handle the work of two departments or regions in actual work, he needs to use different system identities to obtain the corresponding application permissions to complete the corresponding work.
[0003] For the above-mentioned problem of requiring users to switch corresponding system identities, existing application systems mostly create multiple different identity accounts for users. When users need to log in to access system resources with corresponding permissions, they can log in to the system through different identity accounts. However, although this method is simple for the application system, it is not user-friendly for the user's application experience. First, this method requires users to remember multiple sets of different accounts and passwords. Once they forget or lose their account information, they will not be able to log in and use the system normally; secondly, in actual operation, for the same user, when they need to switch user identities, they need to log out of the current logged-in identity first, jump to the login interface, and then log in with the new system account. The process is very cumbersome. Summary of the invention
[0004] In view of the above problems, the present invention proposes a multi-identity switching method and device, the main purpose of which is to simplify the operation process of user identity switching and improve the convenience of user use.
[0005] In order to achieve the above object, the present invention mainly provides the following technical solutions:
[0006] In a first aspect, the present invention provides a multi-identity switching method, comprising:
[0007] Receiving an identity switching request triggered by a user, wherein the identity switching request contains identification information of a target identity to be switched;
[0008] Determining whether the target identity has an association relationship with the current identity logged in by the user according to the identification information;
[0009] If so, the session information and application access rights of the user's current session are modified according to the target identity, so that the user can access applications with application access rights based on the modified current session.
[0010] Preferably, modifying the session information and application access rights of the user's current session according to the target identity includes:
[0011] Obtaining identity information of the target identity, wherein the identity information includes session identity information and permission identity information;
[0012] Using the session identity information to update the session information of the user's current session;
[0013] The user's current application access permissions are updated using the permission identity information.
[0014] Preferably, updating the user's current application access rights using the permission identity information includes:
[0015] The access token of the corresponding user in the authorization engine is updated according to the permission identity information, so that the authorization engine updates the application access rights corresponding to the access token to the application access rights corresponding to the target identity. The authorization engine is used to authenticate the user's access token when the user obtains application permissions.
[0016] Preferably, the permission identity information also includes the validity period of the access token, and the method further includes:
[0017] When the validity period is reached, the authorization engine is notified to change the application access rights corresponding to the access token.
[0018] Preferably, the method further comprises:
[0019] When the validity period is reached, an extension application prompt box is generated in the current interface so that the user can submit an extension request to extend the validity period of the access token according to usage requirements.
[0020] Preferably, the method further comprises:
[0021] Receive new identity information of the target user;
[0022] Determine whether the target user has existing identity information;
[0023] If so, the existing identity information of the target user is associated with the new identity information and stored.
[0024] Preferably, the method further comprises:
[0025] Receive an application access request from a user, wherein the access request contains an access token when the user logs in;
[0026] Acquire an authorization engine based on the access token to verify the application access rights that the user has;
[0027] Determining whether the application requested by the user to access complies with the application access rights;
[0028] If so, the user is allowed to access the application; otherwise, the application access permission is fed back to the user.
[0029] Preferably, when the target identity has no association with the current identity logged in by the user, the method further comprises:
[0030] Detecting whether the current identity of the user has the authority to establish an identity association relationship;
[0031] If yes, then generate identity association prompt information, so that the user can update the association relationship between the multiple identities of the user according to the identity association prompt information;
[0032] If not, a prompt message indicating that the identity switching failed is generated.
[0033] In a second aspect, the present invention provides a multi-identity switching device, the device comprising:
[0034] A receiving unit, configured to receive an identity switching request triggered by a user, wherein the identity switching request contains identification information of a target identity to be switched;
[0035] A judging unit, configured to judge whether the target identity has an association relationship with the current identity of the user logged in, according to the identification information obtained by the receiving unit;
[0036] The modification unit is used to modify the session information and application access rights of the user's current session according to the target identity when the judgment unit determines that the target identity has an association relationship with the current identity of the user logged in, so that the user can access the application with application access rights based on the modified current session.
[0037] Preferably, the modification unit comprises:
[0038] An acquisition module, used to acquire identity information of a target identity, wherein the identity information includes session identity information and authority identity information;
[0039] An updating module, used for updating the session information of the current session of the user using the session identity information;
[0040] The updating module is further configured to update the user's current application access rights using the permission identity information.
[0041] Preferably, the update module is also used to update the access token of the corresponding user in the authorization engine according to the permission identity information, so that the authorization engine updates the application access rights corresponding to the access token to the application access rights corresponding to the target identity, and the authorization engine is used to authenticate the user's access token when the user obtains application permissions.
[0042] Preferably, the permission identity information also includes the validity period of the access token, and the modification unit further includes:
[0043] The notification module is used to notify the authorization engine to change the application access rights corresponding to the access token when the validity period is reached.
[0044] Preferably, the modification unit further includes:
[0045] The prompt module is used to generate an extension application prompt box in the current interface when the validity period is reached, so that the user can submit an extension request to extend the validity period of the access token according to usage requirements.
[0046] Preferably, the device further comprises:
[0047] A collection unit, used for receiving new identity information of a target user;
[0048] A detection unit, used to determine whether the target user has existing identity information;
[0049] The association unit is used to associate and store the existing identity information of the target user with the new identity information obtained by the collection unit when the detection unit determines that there is existing identity information.
[0050] Preferably, the device includes: an access response unit, which is used to respond to the application access request of the user after switching identities, specifically including:
[0051] A receiving module, used to receive an application access request from a user based on the current session after the session information is modified, wherein the access request contains an access token when the user logs in;
[0052] An acquisition module, configured to acquire the application access rights that the authorization engine verifies the user has according to the access token obtained by the receiving module;
[0053] A determination module, used to determine whether the application requested by the user to access complies with the application access rights obtained by the acquisition module;
[0054] The processing module is used to allow the user to access the application when the judgment module determines that the conditions are met, otherwise, prevent the user from accessing the application, and / or provide feedback to the user on the application access rights.
[0055] Preferably, when the judgment unit determines that the target identity has no association with the current identity logged in by the user, the device further comprises:
[0056] An authority detection unit, used to detect whether the current identity of the user has the authority to establish an identity association relationship;
[0057] The information generating unit is used to generate identity association prompt information when the permission detecting unit determines that the user has the permission, so that the user can update the association relationship between the user's multiple identities according to the identity association prompt information; when the permission detecting unit determines that the user does not have the permission, generate prompt information of identity switching failure.
[0058] On the other hand, the present invention further provides a processor, which is used to run a program, wherein the program executes the multi-identity switching method of the first aspect when running.
[0059] On the other hand, the present invention further provides a storage medium, which is used to store a computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute the multi-identity switching method of the first aspect above.
[0060] By means of the above technical scheme, the present invention provides a method and device for switching multiple identities. When a user needs to switch the identity of the logged-in user, based on the identity switching request triggered by the user, it is determined whether the target identity requested to be switched has an association relationship with the current identity currently logged in. When it is determined that the two have an association relationship, the session information of the user's current session is modified. At the same time, the application access rights corresponding to the target identity are also modified, so that when the user uses the original session information to access the application, it can be authenticated based on the access rights corresponding to the target identity to ensure that the user can enjoy the application access rights of the target identity. The identity switching scheme provided by the present invention allows users to quickly switch identities. Users only need to trigger a switching request, and the system background can complete the synchronous update of the user's login identity and application access rights. Users can understand whether the identity switching operation is completed based on the displayed application access rights, so that they can continue to access the required applications based on the original login session, and no longer need to repeatedly log out and log in to the system, which greatly improves the convenience of user use.
[0061] The above description is only an overview of the technical solution of the present invention. In order to more clearly understand the technical means of the present invention, it can be implemented according to the contents of the specification. In order to make the above and other purposes, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] Various other advantages and benefits will become apparent to those of ordinary skill in the art by reading the detailed description of the preferred embodiments below. The accompanying drawings are only for the purpose of illustrating the preferred embodiments and are not to be considered as limiting the present invention. Moreover, the same reference symbols are used throughout the accompanying drawings to represent the same components. In the accompanying drawings:
[0063] Figure 1 A flowchart of a multi-identity switching method proposed in an embodiment of the present invention is shown;
[0064] Figure 2 A flowchart of another multi-identity switching method proposed in an embodiment of the present invention is shown;
[0065] Figure 3 A schematic diagram of the structure of a multi-identity switching device proposed in an embodiment of the present invention is shown;
[0066] Figure 4 A schematic structural diagram of another multi-identity switching device proposed in an embodiment of the present invention is shown. DETAILED DESCRIPTION
[0067] The exemplary embodiments of the present invention will be described in more detail below with reference to the accompanying drawings. Although the exemplary embodiments of the present invention are shown in the accompanying drawings, it should be understood that the present invention can be implemented in various forms and should not be limited by the embodiments set forth herein. On the contrary, these embodiments are provided in order to enable a more thorough understanding of the present invention and to enable the scope of the present invention to be fully communicated to those skilled in the art.
[0068] In the process of using some application systems, users need to log in to the system to obtain corresponding access rights. In some scenarios, such as office systems, the same user needs to log in to the system with different identities. For example, when the user is seconded from one department to another, due to the different system access rights of different departments, the user needs to handle some work of the original department while completing the work of the new department. At this time, the user needs to switch his login identity on the system to obtain the access rights of the corresponding department and complete the relevant work. However, most existing application systems allocate multiple login accounts to the user. When using, the user needs to log out of the current account first, and then enter a new account to log in. The operation is complicated and the process is cumbersome. To this end, an embodiment of the present invention provides a multi-identity switching method, through which the user can achieve "one-click" switching of system identities, thereby improving the convenience of users switching system login identities. The specific execution steps are as follows: Figure 1 As shown, including:
[0069] 101. Receive an identity switching request triggered by a user.
[0070] The execution premise of this step is that the user has logged in to the system, and the account currently used to log in to the system is associated with at least one other account, that is, after the user logs in to the system, his corresponding identity has one or more other identities in addition to the currently logged in account, and each identity of the user corresponds to an account, and different identities (or accounts) correspond to different application access rights. On this basis, the user can trigger an identity switching request according to his own needs to obtain different application access rights. Specifically, the triggering method of the identity switching request includes but is not limited to: the user triggers the identity switching request by clicking the corresponding switching button in the current system interface, or by executing a preset operation in the interface (such as drawing a circle, multi-finger operation, etc.), or by voice command or gesture command, etc., and this embodiment does not make specific limitations.
[0071] The identity switching request triggered by the user contains at least the identification information of the target identity to be switched, and the identification information may be the identification of the account corresponding to the target identity of the user, or the unique identification information of the application access rights corresponding to the target identity. This embodiment does not limit this.
[0072] 102. Determine whether the target identity is associated with the current identity of the user logged in based on the identification information.
[0073] The association relationship in this step is pre-constructed before executing this embodiment, that is, the identification information corresponding to the multiple identities of the user needs to be associated and stored. When the user has multiple identities, the target identity that the user wants to switch to can be determined through the judgment of this step.
[0074] In addition, the identification information in the identity switching request may also be added by the user himself. At this time, it is necessary to determine whether the target identity corresponding to the identification information is associated with the user identity currently logged in to the system. If it is associated, continue to execute step 103; otherwise, the identity cannot be switched for the user, and the user can be informed through a prompt message that the target identity to be switched does not exist or is not associated with the current identity.
[0075] 103. Modify the session information and application access permissions of the user's current session according to the target identity.
[0076] The current session in this step refers to the session created when the user logs in to the system with the current identity. For the existing login method, when the user logs in with a new identity account, a new session will be rebuilt with the system. It can be seen that the difference between this embodiment and the existing method is that the session information of the current session is modified instead of creating a new session. In this way, the user can use the original session to perform continuous access operations with the target identity, which is imperceptible to the user. Among them, the modification of the session information at least includes information content related to the identity, such as identity identification information, etc.
[0077] In addition, in this embodiment, the purpose of switching the user identity is to allow the user to have different permissions, specifically, in this embodiment, the access permissions to different applications in the system. The management of existing system application access permissions is mostly implemented through an independent permission verification server. Therefore, in this step, while modifying the session information, it is also necessary to modify the application access permissions of the identity corresponding to the original session, so as to adjust the application access permissions of the target identity. In other words, the modification of the session information in this step is to allow the user to continue access operations with the target identity through the original session, and its purpose is to inform the user that the identity has been switched, while the modification of the application access permissions is to grant the corresponding access permissions to the user in the system corresponding to the modified target identity, and its purpose is to achieve the correspondence between identity and permissions in the system.
[0078] After completing the above modification operation, the user can be further informed of the application access rights of the target identity to be switched, in order to inform the user that the identity switch is complete and the application access operation can be performed in the current session. Specifically, the method of informing the user is not limited to a prompt box, an application permission list, etc.
[0079] Based on the above Figure 1It can be seen from the implementation method that the multi-identity switching method proposed in the embodiment of the present invention is that when the user needs to switch the logged-in user identity, based on the identity switching request triggered by the user, it is determined whether the target identity to be switched by the request has an association relationship with the current identity currently logged in. When it is determined that the two have an association relationship, the session information of the user's current session is modified. At the same time, the application access rights corresponding to the target identity are also modified, so that when the user can use the original session to access the application, it can access it based on the access rights corresponding to the new target identity. The identity switching scheme provided by the embodiment of the present invention allows users to quickly switch identities. Users only need to trigger a switching request, and the system background can complete the synchronous update of the user's login identity and application access rights. Users can understand whether the identity switching operation is completed based on the displayed application access rights, so that they can continue to access the required application based on the original login session, and no longer need to repeatedly perform system logout and login operations, which greatly improves the convenience of user use.
[0080] Further, the preferred embodiment of the present invention is in the above Figure 1 Based on this, a detailed description of the target identity switching process is given, and the specific steps are as follows Figure 2 As shown, including:
[0081] 201. Build association relationships between multiple identities of the same target user.
[0082] In this embodiment, the same user can register multiple different identities in the system, and each identity corresponds to different application access rights. In order to facilitate the use of the user, a fixed login account and password can be configured for the user, and the corresponding identity is set as the main identity, while other identities are slave identities. The association relationship between the main identity and the slave identity needs to be pre-established. After the user uses the login account and password to log in as the main identity, the slave identity (target identity) to be switched can be selected through the identity switching operation. To this end, this step is to realize the association mapping between the slave identity and the main identity when the user already has an identity. The specific steps are as follows:
[0083] First, the new identity information of the target user is received, wherein the target user should be a user with a primary identity, and the new identity information is identity information having different application access rights from the primary identity.
[0084] Secondly, determine whether the target user has existing identity information. That is, determine whether the target user has a primary identity. The specific determination process includes checking the identity identification information and the application access rights corresponding to the identity. Among them, the existing identity information is not limited to the primary identity or the secondary identity.
[0085] Finally, when it is determined that there is existing identity information, the existing identity information of the target user is associated with the new identity information and stored. For example, a user identity association table is maintained in the user management library of the system, where each user can have a primary identity and multiple secondary identities, and different identities correspond to different application access rights. The user identity association table is a prerequisite for this embodiment to perform the following steps.
[0086] 202. Receive an identity switching request triggered by a user.
[0087] Before executing this step, at least the step of the user logging in to the system and accessing the application as the primary identity is included. Among them, the process of the user logging in to the system through the account can be implemented using an existing identity authentication method, such as OIDC (OpenID Connect) authentication method. This embodiment does not make specific limitations on this.
[0088] After the user completes the login as the primary identity, if the user needs to change the application access rights by switching identities, the user can quickly switch by triggering an identity switching request. The specific triggering method is described above. Figure 1 For the application system, this step will be executed to obtain the corresponding identity switching request, wherein the identity switching request contains the identification information of the target identity to be switched. The specific content of the step can be referred to Figure 1 Step 101 in the embodiment.
[0089] 203. Determine whether the target identity is associated with the current identity of the user logged in according to the identification information.
[0090] This step requires obtaining all identities of the user from the association relationship constructed in step 201 according to the identification information, so as to determine whether the target identity has an association relationship with the current identity of the user logging in, that is, to determine whether the target identity is a subordinate identity of the user.
[0091] When it is determined that there is an association relationship, step 204 is executed to switch the user's login identity and application access rights. On the contrary, if it is determined that there is no association relationship, it means that the target identity to be switched is a new identity for the user. At this time, a prompt message can be given to the user that the target identity cannot be switched, and the process can be further jumped to step 201 to allow the user to associate the target identity with the primary identity, that is, to update the association relationship of the user identity. Before jumping to step 201, the preferred execution method of this embodiment also includes:
[0092] Check whether the current identity of the user has the authority to build an identity association relationship; if it does, generate identity association prompt information, which can be a prompt information of a jump step, and the specific display form of the prompt information is not specifically limited here. The user can update the association relationship between the user's multiple identities according to the identity association prompt information; if it does not have, generate a prompt information of identity switching failure. It can be seen that after the user triggers the identity switching request, if the target identity to be switched does not have a pre-built association relationship, the authorized user can update the association relationship of his identity by himself, while the unauthorized user needs to inform the system administrator of the target identity to associate and update the identity.
[0093] 204. Obtain identity information of the target identity.
[0094] This step is the starting step for switching the user identity. The identity information obtained comes from the pre-set association relationship of the user identity, wherein the identity information at least includes session identity information and permission identity information. The session identity information user updates the information related to the user identity in the user's current session, and the permission identity information is used to modify the application access rights of the user.
[0095] 205. Use the session identity information to update the session information of the user's current session.
[0096] This step is to modify the session information of the session created when the user logs in, that is, to modify the session content, such as modifying the session identity information in MySQL and Redis, so that the user can access the application in the system with the target identity without creating a new session.
[0097] 206. Use the permission identity information to update the user's current application access permissions.
[0098] This step is executed synchronously with step 205, and there is no logical order relationship between the two.
[0099] Taking OIDC identity authentication as an example, after the user logs in to the system as the primary identity, the system will assign an access token to the user. The user uses the access token to verify the permission to access the application with the system's authorization engine. When the user switches identities, since the session used by the user is not newly created, the access token used by the user is also the original access token of the application. In order for the user to obtain new application access rights, it is necessary to update the access token of the corresponding user in the authorization engine according to the permission identity information, that is, to notify the authorization engine to modify the application access rights corresponding to the access token. In this way, when the user uses the original access token to access the application in the system, when the system authenticates the access token, the authorization engine can verify it based on the updated application access rights.
[0100] The above method is a specific method for updating the application access rights for the original access token used by the user, so that the user can use the original access token to verify the application access rights under the new user identity. In addition, another update method of the embodiment of the present invention can also be to update the access token, that is, when the user switches the identity, the system will notify the authorization engine to generate a new access token according to the new user identity, that is, the authorization engine authenticates the new user identity, queries the latest application access rights it has, and generates a new access token based on the latest application access rights, and at the same time informs the authentication module of the application access rights of the new access token. The authorization engine feeds the new access token back to the system, and the system informs the user, so that the user can use the new access token to perform access operations when accessing the application, and the corresponding authorization engine will also verify whether the user has access rights to the accessed application based on the new access token.
[0101] In another preferred embodiment of the present invention, when updating application access rights, the permission identity information may also contain the validity period of the access token, which can be customized according to needs. By setting the validity period, the time for users to access using the target identity can be more effectively controlled. When the validity period is reached, the authorization engine is notified to change the application access rights corresponding to the access token. For example, when a user needs to temporarily use a certain permission to access, in order to prevent the user from leaving in the middle of the use process and prevent others from using it, the validity period can be set shorter, such as 5-10 minutes. In this way, even if the user leaves, after the validity period, others will not be able to use the target identity to access the system application.
[0102] Furthermore, after the access token expires, the user will no longer be able to obtain new application access rights by triggering an identity switching request. Therefore, for an access token with an expiration date, when it expires, this embodiment can also generate an extension application prompt box in the current interface so that the user can submit an extension request to extend the access token validity period according to usage requirements. It should be noted that when extending the validity period, the user's identity and permissions also need to be verified twice. For example, the user's identity can be verified by SMS verification or setting questions.
[0103] 207. Respond to the application access operation performed by the user as the target identity based on the current session.
[0104] In actual application, after requesting identity switching, the user can confirm whether the current login identity has been switched through its operation interface. The content displayed on the operation interface is the information fed back by the system after completing the above steps. The information can be reflected as a list of specific applications that the user has permission to access under the target identity; it can also be the feedback result provided when accessing a certain application. This step specifically includes:
[0105] First, based on the current session after the modified session information, the user's application access request is received. The access request contains the access token when the user logs in, that is, the original access token. The application access request is an access request for a certain application in the system.
[0106] Afterwards, the authorization engine is verified by the access token to obtain the application access rights that the user has. Since the authorization engine has been notified to update the rights corresponding to the access token during the above-mentioned identity switching process, when the user accesses with the target identity, the authorization engine will authenticate it according to the application access rights corresponding to the target identity and feedback the verification result; the system determines whether the application requested by the user to access complies with the application access rights based on the verification result. If so, the user is allowed to access the application, that is, the user can jump to the application interface; otherwise, if the user does not have the access right, the user is prevented from accessing the application, or a prompt message is fed back to the user while preventing the user from continuing to access, informing him that he does not have the application access right, or a list of applications that he currently has the right to access is displayed to the user.
[0107] Through the above Figure 2 From the description of the illustrated embodiment, it can be seen that a multi-identity switching method proposed in the embodiment of the present invention only requires the user to trigger an identity switching request to complete the conversion of the user identity. For the user, the session constructed during the initial login of the application and the obtained access token are used to access the system application. The system updates the session content and the application access rights corresponding to the access token, thereby reducing the operations on the user side and allowing the user to more conveniently switch identities with different permissions.
[0108] Furthermore, as a response to the above Figure 1-2 The implementation of the method embodiment shown in the figure, the embodiment of the present invention provides a multi-identity switching device, which is used to simplify the operation process of user identity switching and improve the convenience of user use. The embodiment of the device corresponds to the aforementioned method embodiment. For the sake of ease of reading, this embodiment will no longer repeat the details of the aforementioned method embodiment one by one, but it should be clear that the device in this embodiment can correspond to all the contents of the aforementioned method embodiment. Specifically, Figure 3 As shown, the device comprises:
[0109] A receiving unit 31 is used to receive an identity switching request triggered by a user, wherein the identity switching request contains identification information of a target identity to be switched;
[0110] A judging unit 32, configured to judge whether the target identity has an association relationship with the current identity of the user logging in, according to the identification information obtained by the receiving unit 31;
[0111] The modification unit 33 is used to modify the session information and application access rights of the user's current session according to the target identity when the judgment unit 32 determines that the target identity has an association with the current identity of the user logged in, so that the user can access the application with application access rights based on the modified current session.
[0112] Further, such as Figure 4 As shown, the modification unit 33 includes:
[0113] An acquisition module 331 is used to acquire identity information of a target identity, wherein the identity information includes session identity information and authority identity information;
[0114] An updating module 332, configured to update the session information of the current session of the user using the session identity information obtained by the obtaining module 331;
[0115] The updating module 332 is further configured to update the user's current application access rights using the permission identity information obtained by the acquiring module 331 .
[0116] Furthermore, the update module 332 is also used to update the access token of the corresponding user in the authorization engine according to the permission identity information, so that the authorization engine updates the application access rights corresponding to the access token to the application access rights corresponding to the target identity. The authorization engine is used to authenticate the user's access token when the user obtains application permissions.
[0117] Further, such as Figure 4 As shown, the permission identity information also includes the validity period of the access token, and the modification unit 33 also includes:
[0118] The notification module 333 is used to notify the authorization engine to change the application access rights corresponding to the access token when the validity period is reached.
[0119] Further, such as Figure 4 As shown, the modification unit 33 also includes:
[0120] The prompt module 334 is used to generate an extension application prompt box in the current interface when the validity period is reached, so that the user can submit an extension request for extending the validity period of the access token according to usage requirements.
[0121] Further, as Figure 4 shown, the device further includes:
[0122] A collection unit 34, configured to receive new identity information of a target user;
[0123] A detection unit 35, configured to determine whether the target user has existing identity information;
[0124] An association unit 36, configured to, when the detection unit 35 determines that there is existing identity information, associate and store the existing identity information of the target user with the new identity information obtained by the collection unit 34.
[0125] Further, as Figure 4 shown, the device further includes: An access response unit 37, configured to, after the modification unit 33 modifies the session information of the user's current session and the application access permission, respond to the user's application access request. The access response unit 37 specifically includes:
[0126] A receiving module 371, configured to receive the user's application access request based on the current session after modifying the session information. The access request contains an access token when the user logs in;
[0127] An obtaining module 372, configured to obtain, according to the access token obtained by the receiving module 371, an authorization engine to verify the application access permission that the user has;
[0128] A judgment module 373, configured to judge whether the application that the user requests to access conforms to the application access permission obtained by the obtaining module 372;
[0129] A processing module 374, configured to, when the judgment module 373 determines that it conforms, allow the user to access the application; otherwise, feedback the application access permission to the user.
[0130] Further, as Figure 4 shown, the device further includes:
[0131] A permission detection unit 38, configured to, when the judgment unit 32 determines that the target identity has no association relationship with the current identity of the logged-in user, detect whether the current identity of the user has the permission to construct an identity association relationship;
[0132] An information generation unit 39, configured to, when the permission detection unit 38 determines that there is permission, generate an identity association prompt information so that the user can update the association relationship between the multiple identities of the user according to the identity association prompt information; when the permission detection unit 38 determines that there is no permission, generate a prompt information indicating that the identity switch fails.
[0133] Furthermore, an embodiment of the present invention further provides a processor, the processor is used to run a program, wherein the program executes the above Figure 1-2 The multi-identity switching method described in .
[0134] Furthermore, an embodiment of the present invention further provides a storage medium, wherein the storage medium is used to store a computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute the above Figure 1-2 The multi-identity switching method described in .
[0135] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0136] It is understandable that the related features in the above methods and devices can be referenced to each other. In addition, the "first", "second" and the like in the above embodiments are used to distinguish the embodiments, but do not represent the advantages and disadvantages of the embodiments.
[0137] Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0138] The algorithm and display provided herein are not inherently related to any particular computer, virtual system or other device. Various general purpose systems can also be used together with the teachings based on this. According to the above description, it is obvious that the structure required for constructing such systems. In addition, the present invention is not directed to any specific programming language either. It should be understood that various programming languages can be utilized to realize the content of the present invention described herein, and the description of the above specific languages is for disclosing the best mode of the present invention.
[0139] In addition, the memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0140] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.
[0141] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0142] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0143] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0144] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0145] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0146] Computer readable media include permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. Information can be computer readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disk read-only memory (CD-ROM), digital versatile disk (DVD) or other optical storage, magnetic cassettes, magnetic tape magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer readable media does not include temporary computer readable media (transitory media), such as modulated data signals and carrier waves.
[0147] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0148] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0149] The above are only embodiments of the present application and are not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included within the scope of the claims of the present application.
Claims
1. A multi-identity switching method, characterized in that, the method includes: Receiving an identity switching request triggered by a user, the identity switching request including identification information of the target identity to be switched; the identity switching request is triggered by the user by performing a preset operation in the system interface or by a gesture instruction, and the identification information is the identification of the account corresponding to the user's target identity, or, the identification information is the unique identification information of the application access permission corresponding to the target identity; Judging whether there is an association relationship between the target identity and the current identity logged in by the user according to the identification information; the association relationship is the association relationship between multiple different identities of the same user, and each identity corresponds to different application access permissions; If associated, modify the session information and application access permissions of the user's current session according to the target identity, so that the user can access the application with application access permissions based on the modified current session; The modifying the session information and application access permissions of the user's current session according to the target identity includes: obtaining the identity information of the target identity, the identity information including session identity information and permission identity information; updating the session information of the user's current session by using the session identity information; updating the user's current application access permissions by using the permission identity information; Updating the user's current application access permissions by using the permission identity information includes: determining the original access token of the application with the user's current application access permissions; notifying the authorization engine to modify the application access permissions corresponding to the original access token to the application access permissions corresponding to the target identity according to the permission identity information, so that the user can use the original access token to access the application with application access permissions; the authorization engine is used to authenticate the user's access token when the user obtains application permissions; the permission identity information also contains the validity period of the access token, and the validity period is used to limit that after the validity period of the access token arrives, the user can no longer obtain new application access permissions by triggering an identity switching request.
2. The method according to claim 1, characterized in that, the method further includes: When the validity period arrives, notifying the authorization engine to change the application access permissions corresponding to the access token.
3. The method according to claim 2, characterized in that, the method further includes: When the validity period arrives, generating a renewal application prompt box on the current interface, so that the user can submit a renewal request to extend the validity period of the access token according to the usage requirements.
4. The method according to claim 1, characterized in that, the method further includes: Receiving new identity information of the target user; Judging whether the target user has existing identity information; If it exists, associate and store the existing identity information of the target user with the new identity information.
5. The method according to any one of claims 1-4, characterized in that, the method further includes: Receiving the user's application access request based on the current session after modifying the session information, and the access request contains the access token when the user logs in; Acquire an authorization engine based on the access token to verify the application access rights that the user has; Determining whether the application requested by the user to access complies with the application access rights; If the conditions are met, the user is allowed to access the application; otherwise, the user is prevented from accessing the application, and / or the application access permission is fed back to the user.
6. The method according to claim 1, It is characterized in that When the target identity has no association relationship with the current identity logged in by the user, the method further includes: Detecting whether the current identity of the user has the authority to establish an identity association relationship; If yes, then generate identity association prompt information, so that the user can update the association relationship between the multiple identities of the user according to the identity association prompt information; If not, a prompt message indicating that the identity switching failed is generated.
7. A multi-identity switching device, It is characterized in that The device comprises: A receiving unit, configured to receive an identity switching request triggered by a user, wherein the identity switching request contains identification information of a target identity to be switched; the identity switching request is triggered by the user performing a preset operation in a system interface or by a gesture command, and the identification information is an identification of an account corresponding to the user's target identity, or the identification information is unique identification information of application access rights corresponding to the target identity; a judging unit, configured to judge whether the target identity has an association relationship with the current identity logged in by the user according to the identification information obtained by the receiving unit; the association relationship is an association relationship between multiple different identities of the same user, and each identity corresponds to a different application access right; A modification unit, configured to modify the session information and application access rights of the user's current session according to the target identity when the judgment unit determines that the target identity has an association with the current identity of the user logged in, so that the user can access the application with application access rights based on the modified current session; wherein, modifying the session information and application access rights of the user's current session according to the target identity comprises: obtaining identity information of the target identity, the identity information comprising session identity information and permission identity information; updating the session information of the user's current session using the session identity information; and updating the user's current application access rights using the permission identity information; Utilizing the permission identity information to update the user's current application access rights includes: determining the original access token of the user's current application access rights application; notifying an authorization engine according to the permission identity information to modify the application access rights corresponding to the original access token to the application access rights corresponding to the target identity, so that the user can use the original access token to access the application with application access rights; the authorization engine is used to authenticate the user's access token when the user obtains application rights; the permission identity information also contains the validity period of the access token, and the validity period is used to limit that after the validity period of the access token is reached, the user will no longer be able to obtain new application access rights by triggering an identity switching request.
8. A processor, It is characterized in that The processor is used to run a program, wherein the program executes the multi-identity switching method according to any one of claims 1 to 6 when running.
9. A storage medium, It is characterized in that The storage medium is used to store a computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute the multi-identity switching method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Cross-tenant authorization method and device, computer equipment and storage medium
CN110826086A
Cross-account login method and device based on cloud platform and server
CN111953708A