Single Sign-On Method, Device, Electronic Device and Storage Medium

By introducing a single sign-on method in the APP client and using tokens to achieve cross-domain single sign-on, the problems of poor user experience and low identity authentication security are solved, and efficient and secure cross-domain single sign-on is achieved.

CN114218550BActive Publication Date: 2025-06-27CHINA CONSTRUCTION BANK
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111320376.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-09
Publication Date
2025-06-27
Estimated Expiration
2041-11-09

AI Technical Summary

Technical Problem

In the APP clients of multiple application systems, users need to log in and log out one by one, resulting in poor user experience and independent user systems of different application systems lead to low identity authentication security.

Method used

Through the single sign-on method, cross-domain single sign-on is achieved using tokens (Tokens), to generate tokens and pass them between different application systems, realizing user identity authentication and jump.

Benefits of technology

Cross-domain single sign-in is realized, user experience is improved, users can avoid repeated login between different application systems, and cookies are solved through tokens.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114218550B_ABST
    Figure CN114218550B_ABST
Patent Text Reader

Abstract

The present disclosure provides a single sign-on method, apparatus, electronic device, and storage medium, belonging to the technical field of artificial intelligence identification and classification. Among them, the method includes: receiving a first user authentication request, where the first user authentication request includes user authentication information of a first application system; generating a first token according to the user authentication information of the first application system, where the first token includes a first user number of the first application system; sending the first token to the first application system; receiving a second user authentication request, where the second user authentication request includes the first token; obtaining a second user number of a first target jump system according to the first user number; sending the second user number to the first target jump system, where the first target jump system completes the login authentication according to the second user number. Thus, the function of cross-domain single sign-on can be realized, and all application systems do not need to use the same user system, and at the same time, the identity authentication can be effectively ensured to be safe and reliable.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of artificial intelligence recognition and classification, and particularly to a single sign-on method, device, electronic device, and storage medium. Background Art

[0002] In recent years, the mobile Internet has developed rapidly. With the continuous improvement of infrastructure and the popularization of intelligent terminals, the number of APP (Application) client applications has increased rapidly, and the range of functions provided by a single APP client has also been continuously expanded. For example, the mobile banking APP clients provided by major commercial banks have evolved from initially only providing basic financial services such as account query, loss reporting, and transfer to now covering almost all aspects of daily life, such as life payment, investment and financial management, online shopping, etc.

[0003] In the early days, most APP clients were served by a single application system. Gradually, as the functions became more and more abundant, the number of application systems providing services for them gradually increased. Several different application systems provide H5 pages, that is, HTML5 (HyperText Markup Language 5) pages. The APP client embeds these H5 pages to provide different services for customers. For example, for a certain mobile banking APP, its financial services such as loss reporting and transfer are provided by the bank's core system, while the function of buying movie tickets is provided by a third-party system. These application systems providing different services often have their own independent user systems and usually require registering different users and passwords. In the same APP client, when switching between different application scenarios, if one has to log in or log out one by one, the customer experience will be very poor. Summary of the Invention

[0004] Embodiments of the present disclosure provide a single sign-on method, device, electronic device, and storage medium, which can realize the function of cross-domain single sign-on, and all application systems do not need to use the same user system, and at the same time, can effectively ensure the security and credibility of identity authentication.

[0005] The first aspect embodiment of the present disclosure proposes a single sign-on method, including: receiving a first user authentication request, where the first user authentication request includes user authentication information of a first application system; generating a first token according to the user authentication information of the first application system, where the first token includes a first user number of the first application system; sending the first token to the first application system, where the first application system completes the login authentication according to the first token; receiving a second user authentication request, where the second user authentication request includes the first token; obtaining a second user number of a first target jump system according to the first user number; sending the second user number to the first target jump system, where the first target jump system completes the login authentication according to the second user number.

[0006] In an embodiment of the present disclosure, the above single sign-on method further includes: receiving a third user authentication request, where the third user authentication request includes user authentication information of the first target jump system; generating a second token according to the user authentication information of the first target jump system, where the second token includes the second user number; sending the second token to the first target jump system; receiving a fourth user authentication request, where the fourth user authentication request includes the second token; obtaining a third user number of a second target jump system according to the second user number; sending the third user number to the second target jump system, where the second target jump system completes the login authentication according to the third user number.

[0007] In an embodiment of the present disclosure, the user authentication information of the first application system includes the first user number, the number of the first target jump system, and user personal information. Generating the first token according to the user information of the first application system includes: obtaining user portrait information according to the user personal information; generating the first token according to the user portrait information, the first user number, and the number of the first target jump system.

[0008] In an embodiment of the present disclosure, obtaining the second user number of the first target jump system according to the first user number includes: verifying the first token; if the first token passes the verification, obtaining the second user number from the user portrait information according to the first user number.

[0009] In one embodiment of the present disclosure, the user authentication information of the first target jump system includes the second user code and the number of the second target jump system. Generating a second token according to the user authentication information of the first target jump system includes: generating the second token according to the user profile information, the second user number, and the number of the second target jump system.

[0010] In one embodiment of the present disclosure, obtaining the third user number of the second target jump system according to the second user number includes: verifying the second token; if the second token passes the verification, obtaining the third user number from the user profile information according to the second user number.

[0011] An embodiment of the second aspect of the present disclosure provides a single sign-on device, including: a first receiving module, configured to receive a first user authentication request, where the first user authentication request includes user authentication information of a first application system; a first generating module, configured to generate a first token according to the user authentication information of the first application system, where the first token includes a first user number of the first application system; a first sending module, configured to send the first token to the first application system, where the first application system completes login authentication according to the first token; a second receiving module, configured to receive a second user authentication request, where the second user authentication request includes the first token; a first obtaining module, configured to obtain a second user number of a first target jump system according to the first user number; a second sending module, configured to send the second user number to the first target jump system, where the first target jump system completes login authentication according to the second user number.

[0012] In one embodiment of the present disclosure, the above single sign-on device further includes: a third receiving module, configured to receive a third user authentication request, where the third user authentication request includes user authentication information of the first target jump system; a second generating module, configured to generate a second token according to the user authentication information of the first target jump system, where the second token includes the second user number; a third sending module, configured to send the second token to the first target jump system; a fourth receiving module, configured to receive a fourth user authentication request, where the fourth user authentication request includes the second token; a second obtaining module, configured to obtain a third user number of a second target jump system according to the second user number; a fourth sending module, configured to send the third user number to the second target jump system, where the second target jump system completes login authentication according to the third user number.

[0013] In an embodiment of the present disclosure, the user authentication information of the first application system includes the first user number, the number of the first target jump system, and user personal information. The first generation module is specifically configured to: obtain user portrait information according to the user personal information; generate the first token according to the user portrait information, the first user number, and the number of the first target jump system.

[0014] In an embodiment of the present disclosure, the first acquisition module is specifically configured to: verify the first token; if the first token passes the verification, obtain the second user number from the user portrait information according to the first user number.

[0015] In an embodiment of the present disclosure, the user authentication information of the first target jump system includes the second user code and the number of the second target jump system. The second generation module is specifically configured to: generate the second token according to the user portrait information, the second user number, and the number of the second target jump system.

[0016] In an embodiment of the present disclosure, the second acquisition module is specifically configured to: verify the second token; if the second token passes the verification, obtain the third user number from the user portrait information according to the second user number.

[0017] An embodiment of the third aspect of the present disclosure provides an electronic device, including: a processor; a memory for storing instructions executable by the processor; wherein, the processor is configured to execute the instructions to implement the single sign-on method proposed in the first aspect embodiment of the present disclosure.

[0018] An embodiment of the fourth aspect of the present disclosure provides a non-transitory computer-readable storage medium, when the instructions in the storage medium are executed by a processor of an electronic device, enabling the electronic device to execute the single sign-on method proposed in the first aspect embodiment of the present disclosure.

[0019] An embodiment of the fifth aspect of the present disclosure provides a computer program product, including a computer program, and the computer program implements the single sign-on method proposed in the first aspect embodiment of the present disclosure when executed by a processor in a communication device.

[0020] The single sign-on method, device, electronic device, and storage medium provided by the embodiments of the present disclosure have at least the following beneficial effects:

[0021] ①. It can build a user portrait system (i.e., user portrait information) through an independent single sign-on authentication system, and use Token tokens to solve the limitations of writing cookies (data stored on the user's local terminal) across first-level domain names and the requirement to share the same customer system.

[0022] ②. The user portrait system realizes the identity recognition of users in different systems by creating a portrait table for each user, achieving the purpose of being able to recognize the user's identity in other application systems when logging in to a certain application system, thereby improving the user experience.

[0023] ③. Through the Token token method, it well solves the problems of writing cookies across first-level domains, low cookie security, and being easily tampered with and attacked in related technologies.

[0024] ④. It can realize the function of cross-domain single sign-on, and all application systems do not need to use the same user system, and at the same time, it can effectively ensure the security and credibility of identity authentication.

[0025] The additional aspects and advantages of the present disclosure will be partially given in the following description, partially become obvious from the following description, or be understood through the practice of the present disclosure. Brief Description of the Drawings

[0026] The above-mentioned and / or additional aspects and advantages of the present disclosure will become obvious and easy to understand from the following description of the embodiments in conjunction with the drawings, where:

[0027] Figure 1 is a schematic flowchart of a single sign-on method provided by the first embodiment of the present disclosure;

[0028] Figure 2 is a timing diagram of a single sign-on method provided by the second embodiment of the present disclosure;

[0029] Figure 3 is a schematic flowchart of another single sign-on method provided by the third embodiment of the present disclosure;

[0030] Figure 4 is a schematic diagram of the user portrait system in the third embodiment of the present disclosure;

[0031] Figure 5 is a schematic flowchart of another single sign-on method provided by the fourth embodiment of the present disclosure;

[0032] Figure 6 is a schematic flowchart of another single sign-on method provided by the fifth embodiment of the present disclosure;

[0033] Figure 7 is a schematic flowchart of another single sign-on method provided by the sixth embodiment of the present disclosure;

[0034] Figure 8 is a system architecture diagram of a single sign-on provided by the seventh embodiment of the present disclosure;

[0035] Figure 9 A schematic structural diagram of a single sign-on device provided in the eighth embodiment of the present disclosure; and

[0036] Figure 10 A schematic structural diagram of an electronic device shown according to an exemplary embodiment of the present disclosure. Detailed implementation manners

[0037] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the embodiments of the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the embodiments of the present disclosure as detailed in the appended claims.

[0038] The terms used in the embodiments of the present disclosure are only for the purpose of describing specific embodiments, and are not intended to limit the embodiments of the present disclosure. The singular forms "a" and "the" used in the embodiments of the present disclosure and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more of the associated listed items.

[0039] It should be understood that although the terms first, second, third, etc. may be used in the embodiments of the present disclosure to describe various information, such information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the embodiments of the present disclosure, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the words "if" and "when" as used herein may be interpreted as "when" or "when" or "in response to determining".

[0040] The embodiments of the present disclosure will be described in detail below. The examples of the embodiments are shown in the drawings, where the same or similar reference numerals represent the same or similar elements throughout. The embodiments described below by referring to the drawings are exemplary and are intended to explain the present disclosure, and should not be construed as a limitation of the present disclosure.

[0041] The single sign-on method, device, electronic device, and storage medium according to the embodiments of the present disclosure will be described below with reference to the drawings.

[0042] The single sign-on method provided by the embodiments of the present disclosure can be executed by an electronic device, which can be a PC (Personal Computer), a tablet computer, a handheld computer, a server, etc., and no limitation is made here.

[0043] In an embodiment of the present disclosure, a processing component, a storage component, and a driving component may be provided in an electronic device. Optionally, the driving component and the processing component may be integrally provided. The storage component may store an operating system, an application program, or other program modules. The processing component implements the single sign-on method provided in the embodiment of the present disclosure by executing the application program stored in the storage component.

[0044] It should be noted that the single sign-on method provided in the embodiment of the present disclosure can be applied to various clients. The client can be an APP client installed in a mobile terminal or a PC client installed in a PC. Among them, the client can integrate multiple third-party application systems. It should be noted that the client itself can also be an application system that provides services.

[0045] In an embodiment of the present disclosure, all application systems (including clients) that need to implement single sign-on authentication using the single sign-on method provided in the embodiment of the present disclosure need to be registered in advance in the single sign-on authentication system, providing the application system abbreviation, the domain name for external services, the server IP (Internet Protocol), etc., and applying to access the single sign-on authentication system. After being authorized by the single sign-on authentication system, access policies are configured for the application system (including the client), and a code (i.e., the unique code of the application system, the unique identity identifier of the user in the application system, etc.), an encryption key (i.e., a private key), etc. are assigned to it.

[0046] It should be noted that the single sign-on authentication system described in this embodiment can be installed in a relevant server, and the server can be a cloud server. In addition, the server can also establish a communication link with the server corresponding to the above application system for relevant registration.

[0047] Among them, each application system can enter and register relevant information through a corresponding registration page. Among them, the registration page can be provided by the corresponding application system (i.e., the server corresponding to the application system), and after registration is completed, relevant registration information is provided to the single sign-on authentication system (i.e., the server corresponding to the single sign-on authentication system), or the registration page can be uniformly provided by the single sign-on authentication system, and after the registration is completed, the relevant registration is provided to the corresponding application system to facilitate the application system to complete the registration. No limitation is made here.

[0048] Figure 1 It is a schematic flow diagram of a single sign-on method provided in an embodiment of the present disclosure.

[0049] The single sign-on method according to the embodiments of the present disclosure can also be executed by the single sign-on device provided by the embodiments of the present disclosure. The device can be configured in an electronic device to receive a first user authentication request, where the first user authentication request includes user authentication information of a first application system, and generate a first token according to the user authentication information of the first application system, where the first token includes a first user number of the first application system, and send the first token to the first application system so that the first application system completes the login authentication according to the first token, and then receive a second user authentication request, where the second user authentication request includes the first token, and obtain a second user number of a first target jump system according to the first user number, and send the second user number to the first target jump system so that the first target jump system completes the login authentication according to the second user number, thereby enabling the function of cross-domain single sign-on, and all application systems do not need to use the same user system and can ensure the security and credibility of identity authentication.

[0050] As a possible situation, the single sign-on method according to the embodiments of the present disclosure can also be executed on the server side. The server can be a cloud server, and the single sign-on method can be executed in the cloud.

[0051] As Figure 1 shown, the single sign-on method may include:

[0052] Step 101, receive a first user authentication request, where the first user authentication request includes user authentication information of a first application system. Wherein, the first user authentication request may further include the number of the first application system.

[0053] In the embodiments of the present disclosure, the above-mentioned first user authentication request may be sent by the server corresponding to the client, or may be sent by the server corresponding to the third-party application system integrated in the client.

[0054] To make those skilled in the art understand the present disclosure more clearly, see Figure 2 , taking the above-mentioned first user authentication request being sent by the server corresponding to the third-party application system (for example, Figure 2 the application system 1 in) integrated in the client as an example. Wherein, the first application system in the single sign-on method provided by the embodiments of the present disclosure is the application system 1, the first target jump system is the client (the application system of the client itself), and the second target jump system is the application system 2.

[0055] Specifically, when a user opens a certain client for access (browsing, viewing), when the user accesses the protected resources of Application System 1, Application System 1 will determine whether the user has logged in and has the permission to view the protected resources. If Application System 1 finds that the client has not logged in, it can provide (pop up) the login interface of Application System 1, that is, enter the login page of Application System 1. After the user successfully logs in as a member of Application System 1, Application System 1 can obtain the user number (the unique identity identifier of the user in Application System 1), user personal information (for example, the three key elements of the user, (name, ID number, mobile phone number)), etc. from the corresponding server, and obtain the ID (Identity document, unique code) of the target jump system (the client, that is, the application system of the client itself) from the client (that is, the unique code of the client). It should be noted that the codes (IDs) of the client and the third-party application systems integrated in the client can be pre-stored in the local client for obtaining when in use.

[0056] Then, Application System 1 can generate user authentication information of Application System 1 based on the user number, user personal information, the ID of the target jump system, etc. Then, Application System 1 can obtain the number of Application System 1 from the corresponding server, and can generate a first user authentication request based on the number of Application System 1 and the user authentication information of Application System 1, and send the first user authentication request to the single sign-on authentication system (that is, the server corresponding to the single sign-on authentication system). After receiving the first user authentication request, the single sign-on authentication system can perform subsequent operations in response to the first user authentication request.

[0057] In the embodiment of the present disclosure, Application System 1 can also encrypt the generated user authentication information. For example, it can be encrypted using the exclusive private key of Application System 1.

[0058] Step 102, generate a first token according to the user authentication information of the first application system, where the first token includes the first user number of the first application system. The first token can be a Token token.

[0059] To clearly illustrate the previous embodiment, in an embodiment of the present disclosure, the user authentication information of the first application system may include the first user number, the number of the first target jump system, and user personal information, as Figure 3 described, generating a first token according to the user information of the first application system includes:

[0060] Step 301, obtain user portrait information according to user personal information.

[0061] It should be noted that the user portrait information described in this embodiment can be pre-generated and stored in the storage space corresponding to the single sign-on authentication system. Among them, the user portrait information can be generated in the following ways:

[0062] When all application systems (including the client) in the client (such as the APP client) are registered offline, the single sign-on authentication system will assign an identifier to each application system to record its unique user number. At the beginning, the user has no information in the user portrait system (that is, the user portrait information). After he logs in to the client, the single sign-on authentication system will create a new portrait information for the client, including the user number, name, document type, document number, mobile phone number, etc. in the client. Specifically, please refer to Figure 4 .

[0063] When the user is about to jump to Application System 1, the single sign-on authentication system will return information such as the name, ID number, and mobile phone number according to the user number of the user in the client. Application System 1 can reverse-lookup the user number of the user in Application System 1 based on these three-element information and feedback it to the single sign-on authentication system. In this way, the user portrait system can update the portrait information of the user and supplement the user number of the user in Application System 1. By analogy, after the user logs in to other application systems, the user portrait system can obtain the user number and update the portrait information until the user numbers of all application systems are registered in the user portrait system. After the user number is registered in the user portrait system, the user can then achieve single sign-on in different application systems in the future, that is, only need to log in once to access the protected resources of all application systems.

[0064] Alternatively, when all application systems (including the client) in the client (such as the APP client) are registered offline, the single sign-on authentication system will assign an identifier to each application system to record its unique user number, and directly construct a complete user portrait system (that is, the user portrait information) based on the registration information of the users provided by each application system in all application systems. It should be noted that the user portrait system (that is, the user portrait information), by establishing a portrait table for each user, can realize the identity recognition of the user in different systems, achieve the purpose of being able to recognize the user's identity in other application systems when logging in to a certain application system, thereby improving the user experience

[0065] Step 302, generate a first token according to the user portrait information, the first user number, and the number of the first target jump system.

[0066] To make those skilled in the art understand the present disclosure more clearly, please refer to Figure 2 , the above first user authentication request is from a third-party application system integrated in the client (such asFigure 2 Taking the server corresponding to the application system 1) in [[]] as an example. Specifically, after receiving the first user authentication request sent by the application system 1, the single sign-on authentication system can first parse the first user authentication request to obtain the user number (the first user number) of the application system 1, the ID of the target jump system (the number of the client), and the user personal information, and then obtain the user portrait information from the storage space corresponding to the single sign-on authentication system according to the user personal information, that is, retrieve the storage space based on the three elements of the user (name, ID number, mobile phone number) to obtain the corresponding user portrait information, and generate a first token according to the user portrait information, the user number (the first user number), and the ID of the target jump system (the number of the first target jump system).

[0067] It should be noted that the data structure of the first token described in this embodiment can be as shown in Table 1 below:

[0068] Field Name Data Type Required Description Remarks KHDIDFROM varchar2(32) Y ID of the target jump system CUSTIDTO varchar2(32) Y ID of Application System 1 CUSTIDFRO varchar2(64) Y User number of Application System 1 CUSTNAME varchar2(64) User name CERTTYPE varchar2(2) Certificate type CERTNO varchar2(32) Certificate number MOBILENO varchar2(16) Mobile phone number CREATETIME varchar2(64) Y Token generation time

[0069] Table 1

[0070] In the embodiments of the present disclosure, if the user authentication information of the application system is encrypted, the public key can be first obtained according to the ID of the application system 1 in the first user authentication request to decrypt the user authentication information.

[0071] Step 103, send the first token to the first application system, where the first application system completes the login authentication according to the first token.

[0072] To make those skilled in the art understand the present disclosure more clearly, refer to Figure 2 , taking the above-mentioned first user authentication request sent by the server corresponding to the third-party application system (for example, Figure 2 the application system 1) integrated in the client as an example. Specifically, after generating the first token, the single sign-on authentication system can send the first token to the application system 1. After receiving the first token, the application system 1 can complete the login authentication according to the first token.

[0073] In the embodiments of the present disclosure, the application system 1 can also encrypt the first token.

[0074] As a possible situation, after the user completes the relevant login operation through the login page provided by the application system 1, the protected resources of the application system 1 can be accessed, and completing the login authentication according to the first token is to verify whether the first token is valid.

[0075] As another possible scenario, after the user completes the relevant login operation through the login page provided by application system 1, the user still cannot access the protected resources of application system 1. Instead, after receiving the first token, the user completes the subsequent login authentication based on this first token before being able to access the protected resources of application system 1.

[0076] As another possible scenario, after the user completes the relevant login operation through the login page provided by application system 1, the user can access the protected resources of application system 1. After application system 1 receives the first token, it only forwards this first token to the client. Among them, application system 1 can also perform relevant authentication based on this first token, that is, login authentication, which is not limited here.

[0077] Step 104: Receive a second user authentication request, where the second user authentication request includes a first token.

[0078] To make those skilled in the art understand the present disclosure more clearly, refer to Figure 2 , taking the above first user authentication request as an example sent by the server corresponding to the third-party application system (for example, Figure 2 application system 1 in

[0079] Step 105: Obtain the second user number of the first target jump system according to the first user number.

[0080] To clearly illustrate the previous embodiment, in an embodiment of the present disclosure, as Figure 5 shown, obtaining the second user number of the first target jump system according to the first user number may include:

[0081] Step 501: Verify the first token.

[0082] In the embodiments of the present disclosure, it is possible to verify whether the first token has expired, whether it has been used, etc.

[0083] Step 502: If the first token passes the verification, obtain the second user number from the user portrait information according to the first user number.

[0084] To make those skilled in the art understand the present disclosure more clearly, refer to Figure 2, taking the first user authentication request as an example, which is sent by the server corresponding to the third-party application system integrated in the client (for example, Figure 2 Application System 1 in

[0085] Specifically, after receiving the second user authentication request sent by the client, the single sign-on authentication system may first parse the second user authentication request to obtain the first token and verify its legality, such as whether the first token has expired or has been used. After passing the verification, the single sign-on authentication system may obtain the user number (the first user number) of Application System 1 from the first token, and obtain the user number of the client (i.e., the second user number of the first target jump system) from the user portrait information according to the user number.

[0086] To make those skilled in the art understand the present disclosure more clearly, refer to Figure 2 , taking the first user authentication request as an example, which is sent by the server corresponding to the third-party application system integrated in the client (for example, Figure 2 Application System 1 in

[0087] In order to further clarify the present disclosure, in an embodiment of the present disclosure, as Figure 6 shown, the single sign-on method may further include:

[0088] Step 601: Receive a third user authentication request, where the third user authentication request includes user authentication information of the first target jump system. Additionally, the third user authentication request may also include the number of the first target jump system.

[0089] In an embodiment of the present disclosure, the above-mentioned third user authentication request may be sent by the above-mentioned first target jump system.

[0090] To enable those skilled in the art to understand the present disclosure more clearly, refer to Figure 2 , taking the above-mentioned first user authentication request as an example sent by the server corresponding to the third-party application system integrated in the client (for example, Figure 2 Application System 1 in ). Among them, in the single sign-on method provided by the embodiment of the present disclosure, the first application system is Application System 1, the first target jump system is the client (the application system of the client itself), and the second target jump system is Application System 2.

[0091] Specifically, after the client completes the login authentication, when the user is about to access the protected resources of Application System 2, the client can obtain the user number (the unique identity identifier of the user in the client), user personal information (such as the three elements of the user, (name, ID number, mobile phone number)), etc. from the corresponding server, and obtain the ID of the target jump system (Application System 2) from the client (i.e., the unique encoding of Application System 2).

[0092] Then the client can generate the user authentication information of the client based on the user number, user personal information, the ID of the target jump system, etc. Then the client can obtain the number of the client from the corresponding server, and can generate a third user authentication request based on the number of the client and the user authentication information of the client, and send the third user authentication request to the single sign-on authentication system. After receiving the third user authentication request, the single sign-on authentication system can perform subsequent operations in response to the third user authentication request.

[0093] In an embodiment of the present disclosure, the client can also encrypt the generated user authentication information. For example, encrypt it using the exclusive private key of the client.

[0094] Step 602: Generate a second token based on the user authentication information of the first target jump system, where the second token includes a second user number. Additionally, the second token can also be a Token token.

[0095] To clearly illustrate the previous embodiment, in an embodiment of the present disclosure, the user authentication information of the first target jump system may include a second user code and the number of the second target jump system. Generating a second token according to the user authentication information of the first target jump system may include generating a second token according to the user profile information, the second user number, and the number of the second target jump system.

[0096] To enable those skilled in the art to understand the present disclosure more clearly, refer to Figure 2 , taking the above first user authentication request sent by the server corresponding to the third-party application system (for example, Figure 2 Application System 1 in) integrated in the client as an example. Specifically, after receiving the third user authentication request sent by the client, the single sign-on authentication system may first parse the third user authentication request to obtain the user number (second user number) of the client and the ID of the target jump system (the number of Application System 2), and then generate a first token according to the obtained user profile information, the user number (second user number), and the ID of the target jump system (the number of the second target jump system).

[0097] In the embodiment of the present disclosure, if the user authentication information of the client is encrypted, the public key may first be obtained according to the ID of the client in the third user authentication request to decrypt the user authentication information.

[0098] Step 603, send the second token to the first target jump system.

[0099] Step 604, receive a fourth user authentication request, where the fourth user authentication request includes a second token.

[0100] To enable those skilled in the art to understand the present disclosure more clearly, refer to Figure 2 , taking the above first user authentication request sent by the server corresponding to the third-party application system (for example, Figure 2 Application System 1 in) integrated in the client as an example. Specifically, after generating the second token, the single sign-on authentication system may send the second token to the client, and then the client may forward the second token to Application System 2. After receiving the second token, Application System 2 may obtain the ID of Application System 2, and generate a fourth user authentication request according to the ID of Application System 2 and the second token, and send the fourth user authentication request to the single sign-on authentication system. After receiving the fourth user authentication request, the single sign-on authentication system may perform subsequent operations in response to the second user authentication request.

[0101] Step 605, obtain the third user number of the second target jump system according to the second user number.

[0102] To clearly illustrate the previous embodiment, in one embodiment of the present disclosure, as Figure 7 shown, obtaining the third user number of the second target jump system according to the second user number may include:

[0103] Step 701, verify the second token.

[0104] In an embodiment of the present disclosure, it is possible to verify whether the second token has expired, whether it has been used, etc.

[0105] Step 702, if the second token passes the verification, obtain the third user number from the user portrait information according to the second user number.

[0106] To enable those skilled in the art to understand the present disclosure more clearly, refer to Figure 2 , taking the above-mentioned first user authentication request sent by the server corresponding to the third-party application system integrated in the client (for example, Figure 2 the application system 1 in) as an example. Specifically, after receiving the fourth user authentication request sent by the application system 2, the single sign-on authentication system may first parse the fourth user authentication request to obtain the second token and verify its legality, such as whether the second token has expired, whether it has been used, etc. After passing the verification, the single sign-on authentication system may obtain the user number (second user number) of the client from the second token, and obtain the user number of the application system 2 (that is, the third user number of the second target jump system) from the user portrait information according to the user number.

[0107] Step 606, send the third user number to the second target jump system, where the second target jump system completes the login authentication according to the third user number.

[0108] To enable those skilled in the art to understand the present disclosure more clearly, refer to Figure 2 , taking the above-mentioned first user authentication request sent by the server corresponding to the third-party application system integrated in the client (for example, Figure 2Taking the example of sending to the corresponding server of the application system 1), specifically, after obtaining the user ID of the application system 2, the single sign-on authentication system can send the user ID of the application system 2 to the corresponding application system 2. After receiving the user ID of the application system 2, the application system 2 can complete the login authentication based on this user ID. For example, obtain the authorization information from the server of the application system 2 based on this user ID, so as to access the protected resources of the application system 2. Thus, single sign-on for the client, application system 1, and application system 2 can be completed. If multiple application systems are integrated in the client, the login authentication of multiple application systems can be completed by analogy according to the above login authentication method. Thus, the function of cross-domain single sign-on can be realized, and all application systems do not need to use the same user system, and at the same time, the identity authentication can be effectively ensured to be safe and reliable. In addition, through the Token token method, the problems of writing cookies across the first-level domain name, low cookie security, and being easily tampered with and attacked in the related art are well solved.

[0109] In the embodiment of the present disclosure, refer to Figure 8 , where the single sign-on authentication system is the core component of the entire single sign-on authentication mechanism, and it can be composed of a Token (token) service, an encryption service, an authentication service, an interface service, and a user portrait system, etc. Among them, the Token (token) service can be used to generate authorization tokens (for example, the first token, the second token), the encryption and decryption service can be used to encrypt and decrypt user information, the authentication service is used to verify the user identity, and the user portrait system can be used to generate, query, update, or delete the user portrait.

[0110] According to the single sign-on method of the embodiment of the present disclosure, receive a first user authentication request, where the first user authentication request includes the user authentication information of the first application system, and generate a first token according to the user authentication information of the first application system, where the first token includes the first user ID of the first application system, and send the first token to the first application system, so that the first application system completes the login authentication according to the first token. Then receive a second user authentication request, where the second user authentication request includes the first token, and obtain the second user ID of the first target jump system according to the first user ID, and send the second user ID to the first target jump system, so that the first target jump system completes the login authentication according to the second user ID. Thus, the function of cross-domain single sign-on can be realized, and all application systems do not need to use the same user system, and at the same time, the identity authentication can be effectively ensured to be safe and reliable.

[0111] Figure 9 It is a schematic structural diagram of a single sign-on device provided by an embodiment of the present disclosure.

[0112] The single sign-on device according to an embodiment of the present disclosure can be configured in an electronic device to receive a first user authentication request, where the first user authentication request includes user authentication information of a first application system, and generate a first token according to the user authentication information of the first application system, where the first token includes a first user number of the first application system, and send the first token to the first application system so that the first application system completes the login authentication according to the first token, and then receive a second user authentication request, where the second user authentication request includes the first token, and obtain a second user number of a first target jump system according to the first user number, and send the second user number to the first target jump system so that the first target jump system completes the login authentication according to the second user number, thereby being able to implement the function of cross-domain single sign-on, and all application systems do not need to use the same user system and can ensure the security and credibility of identity authentication.

[0113] As Figure 9 shown, the single sign-on device 900 may include: a first receiving module 901, a first generating module 902, a first sending module 903, a second receiving module 904, a first obtaining module 905, and a second sending module 906.

[0114] Among them, the first receiving module 901 is used to receive a first user authentication request, where the first user authentication request includes user authentication information of a first application system.

[0115] The first generating module 902 is used to generate a first token according to the user authentication information of the first application system, where the first token includes a first user number of the first application system.

[0116] The first sending module 903 is used to send the first token to the first application system, where the first application system completes the login authentication according to the first token.

[0117] The second receiving module 904 is used to receive a second user authentication request, where the second user authentication request includes the first token.

[0118] The first obtaining module 905 is used to obtain a second user number of a first target jump system according to the first user number.

[0119] The second sending module 906 is used to send the second user number to the first target jump system, where the first target jump system completes the login authentication according to the second user number.

[0120] In an embodiment of the present disclosure, as Figure 9 shown, the single sign-on device 900 may further include: a third receiving module 907, a second generating module 908, a third sending module 909, a fourth receiving module 910, a second obtaining module 911, and a fourth sending module 912.

[0121] Among them, the third receiving module 907 is used to receive a third user authentication request, where the third user authentication request includes user authentication information of the first target jump system.

[0122] The second generating module 908 is used to generate a second token according to the user authentication information of the first target jump system, where the second token includes a second user number.

[0123] The third sending module 909 is used to send the second token to the first target jump system.

[0124] The fourth receiving module 910 receives a fourth user authentication request, where the fourth user authentication request includes the second token.

[0125] The second obtaining module 911 is used to obtain a third user number of the second target jump system according to the second user number.

[0126] The fourth sending module 912 is used to send the third user number to the second target jump system, where the second target jump system completes the login authentication according to the third user number.

[0127] In an embodiment of the present disclosure, the user authentication information of the first application system includes a first user number, a number of the first target jump system, and user personal information. The first generating module 902 is specifically configured to: obtain user portrait information according to the user personal information; generate a first token according to the user portrait information, the first user number, and the number of the first target jump system.

[0128] In an embodiment of the present disclosure, the first obtaining module 905 is specifically configured to: verify the first token; if the first token passes the verification, obtain a second user number from the user portrait information according to the first user number.

[0129] In an embodiment of the present disclosure, the user authentication information of the first target jump system includes a second user code and a number of the second target jump system. The second generating module 908 is specifically configured to: generate a second token according to the user portrait information, the second user number, and the number of the second target jump system.

[0130] In an embodiment of the present disclosure, the second obtaining module 911 is specifically configured to: verify the second token; if the second token passes the verification, obtain a third user number from the user portrait information according to the second user number.

[0131] It should be noted that for details not disclosed in the single sign-on device of the embodiments of the present disclosure, please refer to the details disclosed in the single sign-on device of the embodiments of the present disclosure, which will not be elaborated here.

[0132] In summary, the single sign-on device according to the embodiments of the present disclosure receives a first user authentication request through a first receiving module, where the first user authentication request includes user authentication information of a first application system, and generates a first token according to the user authentication information of the first application system through a first generating module, where the first token includes a first user number of the first application system, and sends the first token to the first application system through a first sending module, so that the first application system completes login authentication according to the first token, and then receives a second user authentication request through a second receiving module, where the second user authentication request includes the first token, and obtains a second user number of a first target jump system according to the first user number through a first obtaining module, and sends the second user number to the first target jump system through a second sending module, so that the first target jump system completes login authentication according to the second user number. Thus, the function of cross-domain single sign-on can be realized, and all application systems do not need to use the same user system, and at the same time, the identity authentication can be effectively ensured to be safe and reliable.

[0133] According to a third aspect of the embodiments of the present disclosure, an electronic device is further provided, including: a processor; a memory for storing executable instructions of the processor, where the processor is configured to execute the instructions to implement the single sign-on method as above.

[0134] To implement the above embodiments, the present disclosure also proposes a storage medium.

[0135] Wherein, when the instructions in the storage medium are executed by the processor of the electronic device, the electronic device can execute the single sign-on method as above.

[0136] To implement the above embodiments, the present disclosure also provides a computer program product.

[0137] Wherein, when the computer program product is executed by the processor of the electronic device, the electronic device can execute the single sign-on method as above.

[0138] Figure 10 is a block diagram of an electronic device shown according to an exemplary embodiment. Figure 10 The electronic device shown is only an example and should not bring any limitation to the functions and usage scope of the embodiments of the present disclosure.

[0139] As Figure 10As shown, the electronic device 1000 includes a processor 111, which can perform various appropriate actions and processes according to programs stored in a read-only memory (ROM) 112 or programs loaded from a memory 116 into a random access memory (RAM) 113. In the RAM 113, various programs and data required for the operation of the electronic device 1000 are also stored. The processor 111, the ROM 112, and the RAM 113 are connected to each other via a bus 114. An input / output (I / O) interface 115 is also connected to the bus 114.

[0140] The following components are connected to the I / O interface 115: a memory 116 including a hard disk, etc.; and a communication part 117 including a network interface card such as a LAN (local area network) card, a modem, etc., and the communication part 117 performs communication processing via a network such as the Internet; a drive 118 is also connected to the I / O interface 115 as needed.

[0141] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program carried on a computer-readable medium, and the computer program includes program codes for performing the methods shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication part 117. When the computer program is executed by the processor 111, the above functions defined in the method of the present disclosure are executed.

[0142] In an exemplary embodiment, a storage medium including instructions is also provided, such as a memory including instructions, and the above instructions can be executed by the processor 111 of the electronic device 1000 to complete the above method. Optionally, the storage medium can be a non-transitory computer-readable storage medium. For example, the non-transitory computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.

[0143] In the present disclosure, a computer-readable storage medium may be any tangible medium that contains or stores a program, which can be used by or in conjunction with an instruction execution system, apparatus, or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the foregoing. A computer-readable signal medium may also be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in conjunction with an instruction execution system, apparatus, or device. The program code contained on a computer-readable medium may be transmitted using any appropriate medium, including but not limited to: wireless, wire, optical fiber cable, RF, etc., or any suitable combination of the foregoing.

[0144] The technical solutions provided by the embodiments of the present disclosure at least bring the following beneficial effects:

[0145] In an embodiment of the present disclosure, the server receives a first user authentication request, where the first user authentication request includes user authentication information of a first application system, and generates a first token according to the user authentication information of the first application system. The first token includes a first user number of the first application system, and sends the first token to the first application system so that the first application system completes the login authentication according to the first token. Then, it receives a second user authentication request, where the second user authentication request includes the first token, obtains a second user number of a first target jump system according to the first user number, and sends the second user number to the first target jump system so that the first target jump system completes the login authentication according to the second user number. Thus, the function of cross-domain single sign-on can be realized, and all application systems do not need to use the same user system, and at the same time, the identity authentication can be effectively ensured to be secure and reliable.

[0146] Those skilled in the art will readily conceive of other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. The present disclosure is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include common general knowledge or conventional technical means in the technical field not disclosed herein. The specification and embodiments are only to be regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the following claims.

[0147] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.

Claims

1. A single sign-on method, characterized in that, It includes: Receiving a first user authentication request, where the first user authentication request includes user authentication information of a first application system, and the user authentication information of the first application system includes a first user number, a number of a first target jump system, and user personal information; Obtaining user portrait information according to the user personal information, where the user portrait information is pre-generated and stored in a storage space corresponding to the single sign-on authentication system, and the user portrait information includes user numbers of all application systems in the client, and the user number of each application system is assigned by the single sign-on authentication system for each application system when the user registers in the application system; Generating a first token according to the user portrait information, the first user number, and the number of the first target jump system, where the first token includes the first user number of the first application system; Sending the first token to the first application system, where the first application system completes the login authentication according to the first token; Receiving a second user authentication request, where the second user authentication request includes the first token; the second user authentication request is generated by the client according to the ID of the client and the first token, and after the first application system completes the login authentication according to the first token, it sends the first token to the client; Verifying the first token; If the first token passes the verification, obtaining a second user number from the user portrait information according to the first user number; Sending the second user number to the first target jump system, where the first target jump system completes the login authentication according to the second user number.

2. The single sign-on method according to claim 1, wherein It also includes: Receiving a third user authentication request, where the third user authentication request includes user authentication information of the first target jump system; Generating a second token according to the user authentication information of the first target jump system, where the second token includes the second user number; Sending the second token to the first target jump system; Receiving a fourth user authentication request, where the fourth user authentication request includes the second token; Obtaining a third user number of a second target jump system according to the second user number; Sending the third user number to the second target jump system, where the second target jump system completes the login authentication according to the third user number.

3. The single sign-on method according to claim 2, characterized in that The user authentication information of the first target jump system includes the second user number and the number of the second target jump system, and generating the second token according to the user authentication information of the first target jump system includes: Generating the second token according to the user portrait information, the second user number, and the number of the second target jump system.

4. The single sign-on method according to claim 3, wherein The obtaining the third user number of the second target jump system according to the second user number includes: Verifying the second token; If the second token passes the verification, obtaining the third user number from the user portrait information according to the second user number.

5. A single sign-on device, characterized in that, It includes: The first receiving module is used to receive a first user authentication request, where the first user authentication request includes user authentication information of a first application system, and the user authentication information of the first application system includes a first user number, a number of a first target jump system, and user personal information; The first generating module is used to obtain user portrait information according to the user personal information. The user portrait information is pre-generated and stored in a storage space corresponding to the single sign-on authentication system. The user portrait information includes user numbers of all application systems in the client, and the user number of each application system is assigned by the single sign-on authentication system for each application system when the user registers in the application system; generate a first token according to the user portrait information, the first user number, and the number of the first target jump system, where the first token includes the first user number of the first application system; The first sending module is used to send the first token to the first application system, where the first application system completes the login authentication according to the first token; The second receiving module is used to receive a second user authentication request, where the second user authentication request includes the first token; the second user authentication request is generated by the client according to the ID of the client and the first token, where after the first application system completes the login authentication according to the first token, it sends the first token to the client; The first obtaining module is used to verify the first token; if the first token passes the verification, obtain a second user number from the user portrait information according to the first user number; The second sending module is used to send the second user number to the first target jump system, where the first target jump system completes the login authentication according to the second user number.

6. The single sign-on device according to claim 5, wherein It further includes: The third receiving module is used to receive a third user authentication request, where the third user authentication request includes user authentication information of the first target jump system; The second generating module is used to generate a second token according to the user authentication information of the first target jump system, where the second token includes the second user number; The third sending module is used to send the second token to the first target jump system; The fourth receiving module receives a fourth user authentication request, where the fourth user authentication request includes the second token; The second obtaining module is used to obtain a third user number of a second target jump system according to the second user number; The fourth sending module is used to send the third user number to the second target jump system, where the second target jump system completes the login authentication according to the third user number.

7. The single sign-on device according to claim 6, wherein The user authentication information of the first target jump system includes the second user number and the number of the second target jump system. The second generating module is specifically used for: Generating the second token according to the user portrait information, the second user number, and the number of the second target jump system.

8. The single sign-on device according to claim 7, wherein The second obtaining module is specifically used for: Verifying the second token; If the second token passes the verification, the third user number is obtained from the user portrait information according to the second user number.

9. An electronic device, characterized in that, Comprising: A processor; A memory for storing executable instructions of the processor; Wherein, the processor is configured to execute the instructions to implement the single sign-on method according to any one of claims 1 to 4.

10. A non-transitory computer-readable storage medium, characterized in that, When the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the single sign-on method according to any one of claims 1 to 4.

Citation Information

Patent Citations

  • SOA-based single-point login method, authentication server and browser

    CN104378376A