Third-party application integration method and system suitable for single sign-on

By providing three single sign-on integration solutions, the challenges of integrating multiple third-party applications in existing technologies are solved, achieving unified management and simplifying user operations, reducing integration complexity, and supporting single sign-on for multiple applications.

CN114329423BActive Publication Date: 2025-10-28SHANDONG EVAYINFO TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111573272.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-21
Publication Date
2025-10-28
Estimated Expiration
2041-12-21

AI Technical Summary

Technical Problem

Existing single sign-on (SSO) solutions cannot uniformly support third-party applications with different architectures and programming languages. Users still need to remember the addresses of each system, making integration difficult and usage complex.

Method used

Three single sign-on integration solutions are provided: standard mode, active mode, and simple mode. Through the operation management platform and user single sign-on authentication center, the appropriate registration mode can be selected according to the third-party application, and then modified and integrated, including information uploading, review, key parameter generation, and application publishing.

Benefits of technology

It enables unified integration and management of various third-party applications, eliminating the need for users to remember addresses, thus reducing integration and usage difficulty. It also supports integration with legacy systems and improves user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114329423B_ABST
    Figure CN114329423B_ABST
Patent Text Reader

Abstract

This invention discloses a method and system for integrating third-party applications with single sign-on (SSO). Applied to the third-party application development module of an operations management platform, the method includes: selecting a corresponding registration mode based on the application status of the third-party application and uploading the registration information corresponding to the registration mode to the administrator module; receiving the review result of the third-party application registration information from the administrator module of the operations management platform and receiving key parameters; modifying the third-party application based on the key parameters; and publishing the modified third-party application to enable the administrator module to install and use the third-party application. Three SSO integration schemes are provided for different situations of third-party applications: standard mode access, active mode access, and simple mode access, ensuring that each third-party application has a suitable SSO modification and integration scheme.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of application integration technology, and in particular to a method and system for integrating third-party applications suitable for single sign-on. Background Technology

[0002] The statements in this section merely refer to the background art related to this invention and do not necessarily constitute prior art.

[0003] With the development of the internet and the deepening of digital office practices in government and enterprises, the number of information technology application systems is increasing. Maintaining too many systems places a heavy burden on users, such as having to remember the usernames, passwords, login addresses, and verification codes for each system. This has led to the development of Single Sign-On (SSO) solutions, where users can access other application systems from the same browser without having to log in again after successfully logging into the main system. However, SSO still does not solve all the problems:

[0004] (1) Users still need to remember the addresses of different systems;

[0005] (2) Most single sign-on solutions on the market support only one condition, while there are many application systems that need to be integrated and have different architectures. It is difficult for a single sign-on solution to support all applications. Summary of the Invention

[0006] To address the shortcomings of existing technologies, this invention provides a method and system for integrating third-party applications with single sign-on (SSO). It offers three SSO integration schemes for different third-party applications: standard mode access, proactive mode access, and simple mode access, ensuring that each third-party application has a suitable SSO transformation and integration scheme.

[0007] In a first aspect, the present invention provides a method for integrating third-party applications suitable for single sign-on;

[0008] A third-party application integration method suitable for single sign-on, applied to the third-party application development module of the operation and management platform, including:

[0009] Select the appropriate registration mode based on the application of the third-party application, and upload the registration information corresponding to the registration mode to the administrator module;

[0010] Receive the review results of the administrator module of the operation management platform on the registration information of third-party applications, and receive the key parameters;

[0011] Modify third-party applications based on the aforementioned key parameters;

[0012] The modified third-party application will be published to enable the administrator module to install and use the third-party application.

[0013] Secondly, the present invention provides a third-party application integration system suitable for single sign-on;

[0014] A third-party application integration system suitable for single sign-on includes: an operations management platform and a user single sign-on authentication center; the operations management platform includes: a third-party application development module and an administrator module; the third-party application development module of the operations management platform is connected to the user single sign-on authentication center;

[0015] The third-party application development module selects the corresponding registration mode based on its own application situation and uploads the registration information to the administrator module;

[0016] The third-party application development module receives the registration information review results from the administrator module and receives the key parameter;

[0017] The third-party application development module modifies the third-party application based on the key parameters;

[0018] The third-party application development module will release the modified third-party application to enable the administrator module to install and use the third-party application.

[0019] Compared with the prior art, the beneficial effects of the present invention are:

[0020] After successful integration with a third-party application, this invention will display the corresponding system icon on the user's workbench page. Users do not need to remember and maintain the address of each third-party application; they can simply click the icon to enter the corresponding third-party application. For different situations of third-party applications, three single sign-on integration solutions are provided: standard mode access, active mode access, and simple mode access, ensuring that each third-party application can have a suitable single sign-on transformation and integration solution.

[0021] This invention reduces the difficulty of integrating single sign-on systems, supporting the integration and unification of multiple outdated systems with different architectures and development languages. After integration, third-party applications are displayed and managed uniformly, reducing the difficulty of use for users. Attached Figure Description

[0022] The accompanying drawings, which form part of this invention, are used to provide a further understanding of the invention. The illustrative embodiments of the invention and their descriptions are used to explain the invention and do not constitute an improper limitation of the invention.

[0023] Figure 1 This is a flowchart of the method in Example 1. Detailed Implementation

[0024] It should be noted that the following detailed descriptions are exemplary and intended to provide further illustration of the invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0025] It should be noted that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the exemplary embodiments of the present invention. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. Furthermore, it should be understood that the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion, for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0026] Where there is no conflict, the embodiments and features in the embodiments of the present invention can be combined with each other.

[0027] All data acquisition in this embodiment is carried out in accordance with laws and regulations and with user consent, and the data is used legally.

[0028] Terminology Explanation: Third-party applications refer to system applications that need to be integrated.

[0029] Third-party applications, including: connectivity applications, business applications, lifestyle applications, and entertainment applications;

[0030] This includes connecting applications such as email, instant messaging, GPS navigation, and remote access.

[0031] These include business applications such as mobile banking services, stock market tracking and trading, document processing, and scheduling.

[0032] Among these are lifestyle applications, such as e-commerce, bill payment, health monitoring, digital reading, and social networking.

[0033] Among these are entertainment applications, such as news, games, multimedia players, and photo and video editors.

[0034] Example 1

[0035] This embodiment provides a method for integrating third-party applications suitable for single sign-on;

[0036] like Figure 1As shown, the third-party application integration method for single sign-on, applied to the third-party application development module of the operation management platform, includes:

[0037] S101: Select the corresponding registration mode based on the application status of the third-party application, and upload the registration information corresponding to the registration mode to the administrator module;

[0038] S102: Receive the review results of the third-party application registration information from the administrator module of the operation management platform, and receive the key parameters;

[0039] S103: Modify the third-party application based on the key parameters;

[0040] S104: Publish the modified third-party application to enable the administrator module to install and use the third-party application.

[0041] The operation and management platform includes:

[0042] The third-party application development module is configured to: integrate third-party applications, obtain keys, and view how to use the OpenAPI.

[0043] The administrator module is configured to: review the application information of third-party application development modules and make the installation settings of applications released by third-party application development modules visible to ordinary users.

[0044] Further, step S101: Selecting the corresponding registration mode based on the application status of the third-party application, and uploading the registration information corresponding to the registration mode to the administrator module; specifically including:

[0045] When a third-party application needs modification, choose the standard mode as the registration mode; or...

[0046] When third-party applications cannot be modified, choose the proactive mode as the registration mode; or...

[0047] When third-party applications need to be quickly integrated, select the simple mode as the registration mode.

[0048] The registration modes include: standard mode, active mode, or simple mode.

[0049] The standard mode refers to authentication using the OAuth2 mode;

[0050] The active mode refers to the mode in which the authentication is performed by the authentication center of the third-party application to be integrated. During single sign-on, the third-party application first completes the authentication process of its own authentication center, and then the third-party application obtains authentication data from its own authentication center to complete the login authentication.

[0051] The simple mode refers to a third-party application providing a secret text receiving address. When a user logs into the third-party application through the open portal, they access the secret text receiving address. After receiving the secret text through the secret text receiving address, the third-party application decrypts the secret text and obtains the user information of the user accessing the third-party application to complete the login.

[0052] It should be understood that the standard mode is applicable to third-party applications that support OAuth2 authentication, and the application needs to be modified to a certain extent, but it has a high level of security.

[0053] It should be understood that the active mode is applicable to an access method for third-party applications that cannot be modified or are difficult to modify, in which the authentication authority acts as the active party.

[0054] It should be understood that the simplified mode described herein is suitable for those who wish to quickly integrate into this system. This method is convenient for integration and modification, and its logic is simple, but its security is relatively low.

[0055] Furthermore, the process of uploading registration information to the administrator module includes:

[0056] The standard registration information includes: application avatar, application name, login address, and OAuth2 callback address;

[0057] The registration information for proactive mode includes: application avatar, application name, login address, authorization interface method, authorization result parameters, authorization parameter expression, login address, and login parameter expression;

[0058] The registration information for the simple mode includes: application avatar, application name, login address, and address for receiving secret messages.

[0059] It should be understood that the active mode registration information is intended to simulate a request from this system to an existing certification authority;

[0060] Further, step S102: receiving the registration information review result from the administrator module and receiving the key parameter; specifically including:

[0061] The administrator module reviews the registration information;

[0062] If the review is approved, the key parameters will be sent to the third-party application development module;

[0063] If the review fails, an access denial instruction will be sent to the third-party application development module.

[0064] It should be understood that because integrated third-party applications can obtain user information and access the system's internal interfaces, for security reasons, it is necessary for an administrator to control and review registration information.

[0065] It should be understood that the key parameter is a key-value pair, both of which are random strings and cannot be decrypted to reveal any useful information. The key-value pairs issued by the system of this invention will not be duplicated, and the system of this invention can determine the identity of the authentication system based on the key. The key parameter is generated using the UUID algorithm from java.util.

[0066] Further, S103: Modifying the third-party application based on the key parameters; specifically including: login modification; the login modification specifically includes:

[0067] Based on the selected registration mode, modify the code corresponding to the login of the third-party application.

[0068] Furthermore, the modification of the third-party application login code based on the selected registration mode includes:

[0069] (1) For the active mode, the login page of the third-party application is transformed to carry the callback address and key to jump to the single sign-on page. A new callback page is added. After the single sign-on is successful, the user returns to the third-party application. Based on the callback success mark, the login username, user ID and user contact information are obtained to identify and authenticate a unique user.

[0070] (2) For the standard mode, when accessing the application, the callback address is carried to redirect to the single sign-on page; the third-party application adds a callback page, obtains the authorization code at the time of the callback, and carries the authorization code and key parameters to request user information to complete the login.

[0071] (3) In the simple mode, when accessing a third-party application, the callback address is carried to redirect to the single sign-on page; after the single sign-on is successful, the specified address of the third-party application is accessed and the secret text is carried. The specified address is filled in during registration; the third-party application adds an interface to receive the secret text, decrypts the secret text according to the provided key parameters, obtains user information, and completes the login.

[0072] It should be understood that for active mode, the login page needs to be modified to carry a callback URL and a key. The callback URL is used to redirect to the third-party application after successful single sign-on, and the key is used to verify the identity of the third-party application.

[0073] Furthermore, S103: Modify the third-party application based on the key parameters; specifically including: simultaneous modification of users and departments;

[0074] The synchronized transformation of users and departments specifically includes:

[0075] The system uses the key to call open interfaces and obtain user and department information.

[0076] The system uses the user's account as the identifier when authenticating login, so it is necessary to ensure the consistency of user information between the system and third-party applications before implementing authorized authentication login.

[0077] Furthermore, the system includes: an operations management platform and a user single sign-on authentication center;

[0078] The operation and management platform includes: a third-party application development module and an administrator module;

[0079] The third-party application development module of the operation management platform is connected to the authentication center for single sign-on.

[0080] Furthermore, step S103: Modifying the third-party application based on the key parameters; specifically including:

[0081] Messages and to-do lists were updated simultaneously;

[0082] The specific improvements to synchronize messages and to-do lists include:

[0083] Third-party applications can use the key to call the system's open interfaces to send messages or tasks to the system for unified processing.

[0084] When the system receives messages from third-party applications, it uses a key parameter for authentication and identifies the data as originating from the third-party application. When the system sends callback messages containing pending data, it includes the key parameter. If a third-party application has been modified, the system checks whether it includes the key to ensure security.

[0085] There are two ways to synchronize messages and to-do lists:

[0086] Method 1: When the system processes messages or to-dos, the third-party application adds a callback address for the message or to-do. When the user processes the to-do or views the message, the changes made by the system are synchronized to the third-party application through the callback address.

[0087] Method 2: Process to-dos in a third-party application. When a user opens a message or to-do in the system, the system redirects the user to the corresponding link for the message or to-do stored in the third-party application. The system is notified of the data change only after the message or to-do data in the third-party application is updated by calling the open interface.

[0088] Furthermore, step S103: Modifying the third-party application based on the key parameters; specifically including:

[0089] System exit and renovation;

[0090] The system exit and transformation specifically includes:

[0091] The system should be notified when a third-party application logs out; otherwise, the issue of ineffective login for a different user may occur.

[0092] Further, step S104 involves: publishing the modified third-party application to enable the administrator module to install and use the third-party application; specifically including:

[0093] The third-party application development module publishes the application to the system's application marketplace;

[0094] After a third-party application is published in the app store, the administrator module installs the application.

[0095] The administrator module sets the visibility range of installed third-party applications. Users outside the visibility range cannot see or use third-party applications.

[0096] Example 2

[0097] This embodiment provides a third-party application integration system suitable for single sign-on;

[0098] Third-party application integration systems suitable for single sign-on include: operations management platforms and authentication centers for user single sign-on;

[0099] The operation and management platform includes: a third-party application development module and an administrator module;

[0100] The third-party application development module of the operation management platform is connected to the authentication center for single sign-on.

[0101] The third-party application development module selects the corresponding registration mode based on its own application situation and uploads the registration information to the administrator module;

[0102] The third-party application development module receives the registration information review results from the administrator module and receives the key parameter;

[0103] The third-party application development module modifies the third-party application based on the key parameters;

[0104] The third-party application development module will release the modified third-party application to enable the administrator module to install and use the third-party application.

[0105] The details of each step in Example 2 are consistent with the details of each step in Example 1, and will not be repeated here.

[0106] The foregoing description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Those skilled in the art will readily appreciate that various modifications and variations of the present invention are possible. Any modifications, equivalent substitutions, or improvements made within the spirit and principles of the present invention are intended to be within the scope of protection of the present invention.

Claims

1. A method for integrating third-party applications with single sign-on, characterized in that: Third-party application development modules used in operations management platforms include: Select the appropriate registration mode based on the application's usage, and upload the corresponding registration information to the administrator module; specifically including: When a third-party application needs modification, choose the standard mode as the registration mode; or... When third-party applications cannot be modified, choose the proactive mode as the registration mode; or... When third-party applications need to be quickly integrated, select the simple mode as the registration mode; The standard mode refers to authentication using the OAuth2 mode; The active mode refers to the mode in which the authentication is performed by the authentication center of the third-party application to be integrated. During single sign-on, the third-party application first completes the authentication process of its own authentication center, and then the third-party application obtains authentication data from its own authentication center to complete the login authentication. The simple mode refers to a third-party application providing a secret text receiving address. When a user logs into the third-party application through the open portal, they access the secret text receiving address. After receiving the secret text through the secret text receiving address, the third-party application decrypts the secret text and obtains the user information of the user accessing the third-party application to complete the login. Receive the review results of the administrator module of the operation management platform on the registration information of third-party applications, and receive the key parameters; Modify the third-party application based on the key parameters; specifically including: login modification, which involves modifying the login code of the third-party application according to the selected registration mode; specifically including: (1) For the active mode, the login page of the third-party application is transformed to carry the callback address and key to jump to the single sign-on page. A new callback page is added. After the single sign-on is successful, the user returns to the third-party application. Based on the callback success mark, the login username, user ID and user contact information are obtained to identify and authenticate a unique user. (2) For the standard mode, when accessing the application, the callback address is carried to redirect to the single sign-on page; the third-party application adds a callback page, obtains the authorization code at the time of the callback, and carries the authorization code and key parameters to request user information to complete the login; (3) For the simple mode, when accessing the third-party application, the callback address is carried to the single sign-on page; after the single sign-on is successful, the specified address of the third-party application is accessed and the secret text is carried. The specified address is filled in during registration; the third-party application adds an interface to receive the secret text, and decrypts the secret text according to the provided key parameters to obtain user information and complete the login. The modified third-party application will be published to enable the administrator module to install and use the third-party application.

2. The third-party application integration method for single sign-on as described in claim 1, characterized in that, The process of uploading registration information to the administrator module includes: The standard registration information includes: application avatar, application name, login address, and OAuth2 callback address; The registration information for proactive mode includes: application avatar, application name, login address, authorization interface method, authorization result parameters, authorization parameter expression, login address, and login parameter expression; The registration information for the simple mode includes: application avatar, application name, login address, and address for receiving secret messages.

3. The third-party application integration method for single sign-on as described in claim 1, characterized in that, It receives the review results of the administrator module of the operation management platform on the registration information of third-party applications, and receives the key parameters; specifically including: The administrator module reviews the registration information; If the review is approved, the key parameters will be sent to the third-party application development module; If the review fails, an access denial instruction will be sent to the third-party application development module.

4. The third-party application integration method for single sign-on as described in claim 1, characterized in that, Modify third-party applications based on the aforementioned key parameters; Specifically, this includes: simultaneous upgrades for both users and departments; The synchronized transformation of users and departments specifically includes: Use the key to call the open interface and obtain user and department information of the system; The system uses the user's account as the identifier when authenticating login, so it is necessary to ensure the consistency of user information between the system and third-party applications before implementing authorized authentication login; The system includes: an operation management platform and a user single sign-on authentication center; The operation and management platform includes: a third-party application development module and an administrator module; The third-party application development module of the operation management platform is connected to the authentication center for single sign-on.

5. The third-party application integration method for single sign-on as described in claim 1, characterized in that, Modify third-party applications based on the aforementioned key parameters; Specifically, it includes: Messages and to-do lists were updated simultaneously; The specific improvements to synchronize messages and to-do lists include: Third-party applications can call the system's open interfaces based on the key to send messages or tasks to the system for unified processing. There are two ways to synchronize messages and to-do lists: Method 1: When the system processes messages or to-dos, the third-party application adds a callback address for the message or to-do. When the user processes the to-do or views the message, the changes made by the system are synchronized to the third-party application through the callback address. Method 2: Process to-dos in a third-party application. When a user opens a message or to-do in the system, the system redirects the user to the corresponding link for the message or to-do stored in the third-party application. The system is notified of the data change only after the message or to-do data in the third-party application is updated by calling the open interface.

6. The third-party application integration method for single sign-on as described in claim 1, characterized in that, The modified third-party application will be released to enable the administrator module to install and use it; specifically including: The third-party application development module publishes the application to the system's application marketplace; After a third-party application is published in the app store, the administrator module installs the application. The administrator module sets the visibility range of installed third-party applications. Users outside the visibility range cannot see or use third-party applications.

7. A third-party application integration system suitable for single sign-on, characterized in that: include: An operation management platform and a single sign-on authentication center for users; The operations management platform includes: a third-party application development module and an administrator module; the third-party application development module of the operations management platform is connected to the authentication center for single sign-on. The third-party application development module selects the appropriate registration mode based on its own application requirements and uploads the registration information to the administrator module; specifically including: When a third-party application needs modification, choose the standard mode as the registration mode; or... When third-party applications cannot be modified, choose the proactive mode as the registration mode; or... When third-party applications need to be quickly integrated, select the simple mode as the registration mode; The standard mode refers to authentication using the OAuth2 mode; The active mode refers to the mode in which the authentication is performed by the authentication center of the third-party application to be integrated. During single sign-on, the third-party application first completes the authentication process of its own authentication center, and then the third-party application obtains authentication data from its own authentication center to complete the login authentication. The simple mode refers to a third-party application providing a secret text receiving address. When a user logs into the third-party application through the open portal, they access the secret text receiving address. After receiving the secret text through the secret text receiving address, the third-party application decrypts the secret text and obtains the user information of the user accessing the third-party application to complete the login. The third-party application development module receives the registration information review results from the administrator module and receives the key parameter; The third-party application development module modifies the third-party application based on the key parameters; specifically, this includes: login modification, which involves modifying the login code of the third-party application according to the selected registration mode; specifically, this includes: (1) For the active mode, the login page of the third-party application is transformed to carry the callback address and key to jump to the single sign-on page. A new callback page is added. After the single sign-on is successful, the user returns to the third-party application. Based on the callback success mark, the login username, user ID and user contact information are obtained to identify and authenticate a unique user. (2) For the standard mode, when accessing the application, the callback address is carried to redirect to the single sign-on page; the third-party application adds a callback page, obtains the authorization code at the time of the callback, and carries the authorization code and key parameters to request user information to complete the login; (3) For the simple mode, when accessing the third-party application, the callback address is carried to the single sign-on page; after the single sign-on is successful, the specified address of the third-party application is accessed and the secret text is carried. The specified address is filled in during registration; the third-party application adds an interface to receive the secret text, and decrypts the secret text according to the provided key parameters to obtain user information and complete the login. The third-party application development module will release the modified third-party application to enable the administrator module to install and use the third-party application.

Citation Information

Patent Citations

  • Cross-domain SSO (single sign on) integration method and system

    CN107707570A

  • Visual integrated single sign-on method and device, medium and electronic equipment

    CN110768998A