Single Sign-On Method, System, Electronic Device and Readable Medium
A dual verification process using digital signatures and asymmetric encryption strengthens SSO security by validating application identifiers and credentials, addressing vulnerabilities in existing SSO systems.
Patent Information
- Application Number
- CN202111583717.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-12-22
- Publication Date
- 2025-07-15
- Estimated Expiration
- 2041-12-22
AI Technical Summary
The existing single sign-on technology is not safe and reliable enough, and is easily counterfeited or tampered by malicious third parties, resulting in user data leakage and property damage.
By using digital signature technology during single sign-on, digital signature verification is used to use composite data, including verification of the application identification of mobile applications, and asymmetric encryption is used to generate digital signatures to ensure the legality and security of the data.
Strengthen the security of single sign-on, reduce the possibility of third parties tampering with digital signature content, and improve the reliability and security of the login process.
Smart Images

Figure CN114398620B_ABST
Abstract
Description
Technical Field
[0001] Embodiments of the present invention relate to the field of single sign-on technology, and in particular, to a single sign-on method, a single sign-on system, an electronic device, and a computer-readable medium. Background Art
[0002] With the rise of mobile applications (APP, Application), the scene of opening embedded H5 pages in mobile applications is becoming more and more common. In order to avoid the secondary login of the embedded H5 page, the single sign-on technology is usually used to achieve fast login of the embedded H5 page.
[0003] Specifically, single sign-on, also known as SSO (Single Sign On), means that for multiple mutually trusted business platform systems, users only need to log in once to access all business platform systems until the login expires. In a single sign-on environment, each mobile application will hand over the authentication function to the single sign-on system instead of using its own authentication system. Currently, single sign-on technology has been widely used in communication systems.
[0004] With the further improvement of information security requirements, how to ensure the security and reliability of single sign-on has become an important issue that needs to be solved urgently. Summary of the invention
[0005] The embodiment of the present invention provides a single sign-on method, system, electronic device and computer-readable storage medium to solve the problem that the current single sign-on is not secure and reliable enough.
[0006] The embodiment of the present invention discloses a single sign-on method, which is applied to a business platform system. The business platform system stores a digital signature and a single sign-on credential reported by a mobile application through an interface, wherein the digital signature is generated by the mobile application according to an application identifier and the single sign-on credential, and the single sign-on credential is a credential for authorized login issued by a single sign-on authentication center to the mobile application; the method comprises:
[0007] Receiving a login request for logging into an embedded page in the mobile application; the login request includes an application identifier to be verified and a single sign-on credential to be verified;
[0008] Generate data to be verified according to the application identifier to be verified and the single sign-on credential to be verified;
[0009] When the data to be verified matches the digital signature, verification is performed in the single sign-on authentication center based on the single sign-on credential, so as to log in the embedded page in the mobile application when the verification passes.
[0010] Optionally, the digital signature is generated by the application in the following manner: the application is used to obtain the application identifier of the application; obtain the single sign-on credential issued by the single sign-on authentication center for the mobile application; combine the application identifier and the single sign-on credential to obtain composite data and perform data hashing on the composite data to obtain a data hash value; use a private key to encrypt the data hash value to obtain a digital signature.
[0011] Optionally, generating the data to be verified according to the application identifier to be verified and the single sign-on credential to be verified includes:
[0012] Perform data hashing on the composite data to be verified obtained by combining the application identifier to be verified and the single sign-on credential to be verified to obtain the data to be verified;
[0013] After generating the data to be verified according to the application identifier to be verified and the single sign-on credential to be verified, the method further includes:
[0014] Use the public key corresponding to the private key to decrypt the digital signature to obtain a data hash value; wherein, if the data to be verified is consistent with the data hash value, it is determined that the data to be verified matches the digital signature; if the data to be verified is inconsistent with the data hash value, it is determined that the data to be verified does not match the digital signature.
[0015] Optionally, the method further includes:
[0016] When the data to be verified does not match the digital signature, or when the verification fails at the single sign-on authentication center based on the single sign-on credential, notify the application to log in to the embedded page in the mobile application in other ways.
[0017] An embodiment of the present invention also discloses a single sign-on method applied to a mobile application. In the business platform system corresponding to the mobile application, the digital signature and the single sign-on credential reported by the mobile application through an interface are stored. The digital signature is generated by the mobile application according to the application identifier and the single sign-on credential, and the single sign-on credential is a credential for authorized login issued by the single sign-on authentication center for the mobile application; the method includes:
[0018] Send a login request to log in to the embedded page in the mobile application to the business platform system; the login request includes the application identifier to be verified and the single sign-on credential to be verified; the business platform system is used to generate the data to be verified according to the application identifier to be verified and the single sign-on credential to be verified, and when the data to be verified matches the digital signature, perform verification at the single sign-on authentication center based on the single sign-on credential;
[0019] When the verification in the single sign-on authentication center is passed, log in to the embedded page in the mobile application.
[0020] Optionally, before sending the login request for logging in to the embedded page in the mobile application to the business platform system, the method further includes:
[0021] Obtain the application identifier of the application;
[0022] Obtain the single sign-on credential issued by the single sign-on authentication center for the mobile application;
[0023] Perform data hashing on the combined composite data of the application identifier and the single sign-on credential to obtain a data hash value;
[0024] Use the private key to encrypt the data hash value to obtain a digital signature.
[0025] Optionally, the single sign-on credential is obtained in the following manner:
[0026] Send a request for obtaining to the single sign-on authentication center; the request for obtaining includes a user identifier and a timestamp, and the single sign-on authentication center is used to generate the single sign-on credential according to the user identifier, the timestamp, and a random string;
[0027] Receive the single sign-on credential sent by the single sign-on authentication center.
[0028] An embodiment of the present invention also discloses a single sign-on system, which includes a mobile application, a business platform system, and a single sign-on authentication center. The business platform system stores the digital signature and the single sign-on credential reported by the mobile application through an interface. The digital signature is generated by the mobile application according to the application identifier and the single sign-on credential, and the single sign-on credential is a credential for authorizing login issued by the single sign-on authentication center for the mobile application; wherein:
[0029] The mobile application is used to send a login request for logging in to the embedded page in the mobile application to the business platform system; the login request includes a to-be-verified application identifier and a to-be-verified single sign-on credential;
[0030] The business platform system is used to generate to-be-verified data according to the to-be-verified application identifier and the to-be-verified single sign-on credential; when the to-be-verified data matches the digital signature, perform verification in the single sign-on authentication center based on the single sign-on credential, so as to log in to the embedded page in the mobile application when the verification is passed.
[0031] Optionally, the mobile application is configured to obtain the application identifier of the application; obtain the single sign-on credential issued by the single sign-on authentication center for the mobile application; perform data hashing on the combined composite data of the application identifier and the single sign-on credential to obtain a data hash value; and encrypt the data hash value using a private key to obtain a digital signature.
[0032] Optionally, the mobile application is configured to send a fetch request to the single sign-on authentication center; the fetch request includes a user identifier and a timestamp, and the single sign-on authentication center is configured to generate the single sign-on credential according to the user identifier, the timestamp, and a random string; and receive the single sign-on credential sent by the single sign-on authentication center.
[0033] Optionally, the service platform system is configured to perform data hashing on the combined verification composite data obtained by combining the to-be-verified application identifier and the to-be-verified single sign-on credential to obtain to-be-verified data; decrypt the digital signature using the public key corresponding to the private key to obtain a data hash value; wherein, if the to-be-verified data is consistent with the data hash value, it is determined that the to-be-verified data matches the digital signature; if the to-be-verified data is inconsistent with the data hash value, it is determined that the to-be-verified data does not match the digital signature.
[0034] Optionally, the service platform system is configured to notify the application to log in to the embedded page in the mobile application in another way when the to-be-verified data does not match the digital signature, or when the verification fails at the single sign-on authentication center based on the single sign-on credential.
[0035] An embodiment of the present invention further discloses an electronic device, including a processor, a communication interface, a memory, and a communication bus, wherein the processor, the communication interface, and the memory complete communication with each other through the communication bus;
[0036] The memory is used to store a computer program;
[0037] When the processor is configured to execute the program stored on the memory, the method described in the embodiment of the present invention is implemented.
[0038] An embodiment of the present invention further discloses one or more computer-readable media, on which instructions are stored, and when executed by one or more processors, cause the processors to execute the method described in the embodiment of the present invention.
[0039] An embodiment of the present invention further discloses a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the method described in the embodiment of the present invention.
[0040] The embodiments of the present invention include the following advantages:
[0041] In the embodiments of the present invention, a digital signature of a mobile application is stored in a service platform system. When performing single sign-on in the mobile application, the service platform system will receive a login request for a login embedded page in the mobile application, generate data to be verified based on the application identifier to be verified and the single sign-on credential to be verified in the login request. When the data to be verified matches the digital signature, verification can be performed at a single sign-on authentication center based on the single sign-on credential, so as to log in to the embedded page in the mobile application when the verification is passed. When logging in to the embedded page in the mobile application in the embodiments of the present invention, single sign-on is performed. In addition to passing the verification of the single sign-on authentication center during single sign-on, the application identifier of the mobile application also needs to be verified, which enhances the security and reliability during single sign-on. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 is a flowchart of the steps of a single sign-on method provided in the embodiments of the present invention;
[0043] Figure 2 is a schematic diagram of the generation process of a digital signature provided in the embodiments of the present invention;
[0044] Figure 3 is a schematic diagram of the digital signature verification process provided in the embodiments of the present invention;
[0045] Figure 4 is a flowchart of the steps of another single sign-on method provided in the embodiments of the present invention;
[0046] Figure 5 is a system architecture diagram for implementing single sign-on provided in the embodiments of the present invention;
[0047] Figure 6 is a structural block diagram of a single sign-on system provided in the embodiments of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0048] To make the above objects, features, and advantages of the present invention more apparent and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0049] In existing single sign-on systems, verification is performed through tickets (single sign-on credentials), and the means are relatively single. If a malicious third party obtains a legitimate ticket, they can forge, tamper with it, and pass the verification of the single sign-on system, thereby obtaining user data in the service platform system, resulting in the leakage of user data and even property losses.
[0050] In view of the above problems, an embodiment of the present invention provides a secure single sign-on method. By using digital signature technology and performing digital signature on composite data, it is ensured that when digital signature verification is used in single sign-on, the application identifier of the mobile application is verified, reducing the possibility of a third party tampering with the content data in the digital signature, thereby enhancing the security and reliability during single sign-on.
[0051] Referring to Figure 1 , a flowchart of steps of a single sign-on method provided in an embodiment of the present invention is shown. It is applied to a business platform system, and the business platform system stores the digital signature and the single sign-on credential reported by the mobile application through an interface. The digital signature is generated by the mobile application according to the application identifier and the single sign-on credential, and the single sign-on credential is a credential for authorizing login issued by the single sign-on authentication center for the mobile application; the method may specifically include the following steps:
[0052] Step 101, receive a login request for logging in to an embedded page in the mobile application; the login request includes an application identifier to be verified and a single sign-on credential to be verified.
[0053] Among them, a mobile application refers to client software installed in mobile terminals such as mobile phones, tablet computers, and wearable devices. For example, a mobile application installed on a mobile phone that can provide services such as preferential promotions, self-service inquiries, recharge and payment, enjoying 3G, business handling, and help support for users.
[0054] Among them, an embedded page, also known as an inline page, is a technology for embedding a web page in a mobile application. Based on this technology, a mobile application can load a website page of a certain website and then embed it into the interface of the mobile application, so that users can browse the website page through the mobile application. Since the website page is stored in the background server, it can meet the requirements of rapid iteration.
[0055] In a specific implementation, in order to meet the requirement of browsing website pages in a mobile application, a native + h5 hybrid development mode is adopted. Here, native refers to the native system, such as local operating systems like iOS and Android, and h5 refers to HTML (Hyper Text Markup Language). It is used to implement the function of displaying website pages in a mobile application. By combining the native mode and the h5 mode, website pages can be displayed in a mobile application, or certain functions can be achieved by combining the client and the website page. It can be understood that if a mobile application adopts a hybrid development mode of native and h5, correspondingly, the mobile application is also divided into native login (mobile application login) and h5 login (website page login). These two logins are independent of each other. That is to say, even if the mobile application has been logged in, when the mobile application logs in to the website page, the user still needs to perform an h5 login to obtain the authorization to log in to the website page in the mobile application. If the user needs to open multiple website pages, the user needs to perform the login operation multiple times. Therefore, a single sign-on method can be used to avoid multiple logins when logging in to an embedded page in a mobile application.
[0056] In an embodiment of the present invention, the business platform system is a platform for implementing various services of a mobile application. Multiple mobile applications can be managed under one business platform system. The digital signature reported by the mobile application through the verification interface is saved in the business platform system. Specifically, the mobile application has a corresponding application identifier, that is, application ID (Identity document) information, which can be the code or name of the mobile application. The mobile application also includes a single sign-on ticket for authorized login issued by the single sign-on authentication center for the mobile application. The digital signature is generated by the mobile application based on the application identifier and the single sign-on ticket, and then the mobile application can report the digital signature to the business platform system through the verification interface for saving.
[0057] In an embodiment of the present invention, if a user wants to log in to an embedded page in a mobile application, that is, when logging in to the website page of the website in the mobile application, a single sign-on can be attempted. At this time, the business platform system will receive a login request for logging in to the embedded page in the mobile application sent by the mobile application. Among them, the login request may include a to-be-verified application identifier and a to-be-verified single sign-on ticket, and it is necessary to verify the to-be-verified application identifier and the to-be-verified single sign-on ticket to determine whether to allow logging in to the embedded page in the mobile application.
[0058] Step 102: Generate data to be verified according to the to-be-verified application identifier and the to-be-verified single sign-on ticket.
[0059] Step 103: When the data to be verified matches the digital signature, perform verification at the single sign-on authentication center based on the single sign-on credential, so as to log in to the embedded page in the mobile application when the verification is passed.
[0060] In an embodiment of the present invention, the application identifier to be verified and the single sign-on credential to be verified can be extracted from the login request, and then the data to be verified is generated according to the application identifier to be verified and the single sign-on credential to be verified. Then, when it is determined that the data to be verified matches the digital signature, if the data to be verified matches the digital signature, it indicates that the application identifier and the single sign-on credential in the mobile application have not been tampered with. Then, further verification can be performed at the single sign-on authentication center based on the single sign-on credential. If the verification is also passed at the single sign-on authentication center, the embedded page can be logged in to the mobile application.
[0061] In the above single sign-on method, the digital signature of the mobile application is stored in the business platform system. When performing single sign-on in the mobile application, the business platform system will receive a login request for logging in to the embedded page in the mobile application, generate the data to be verified according to the application identifier to be verified and the single sign-on credential to be verified in the login request. When the data to be verified matches the digital signature, verification can be performed at the single sign-on authentication center based on the single sign-on credential, so as to log in to the embedded page in the mobile application when the verification is passed. In the embodiment of the present invention, single sign-on is performed when logging in to the embedded page in the mobile application. When performing single sign-on, in addition to passing the verification of the single sign-on authentication center, the application identifier of the mobile application also needs to be verified, which strengthens the security and reliability during single sign-on.
[0062] In an exemplary embodiment, the digital signature can be generated by the application program in the following manner: The application program is used to obtain the application identifier of the application program; obtain the single sign-on credential issued by the single sign-on authentication center for the mobile application; combine the application identifier and the single sign-on credential to obtain composite data and perform data hashing to obtain a data hash value; encrypt the data hash value with a private key to obtain a digital signature.
[0063] Specifically, in order to ensure the validity of data when generating a digital signature, a composite type of composite data is used to generate the digital signature. Among them, the composite data can be obtained by combining the following data: single sign-on credential ticket and application ID information. Even if other third parties obtain the single sign-on credential ticket, they cannot use the single sign-on credential ticket for single sign-on if the application ID information obtained during the loading of the embedded H5 page does not match. At the same time, since asymmetric encryption can be used to perform data hashing on the composite data obtained by combining the single sign-on credential ticket and application ID information to obtain a data hash value, and finally the data hash value is encrypted using a private key to generate a digital signature, third parties cannot tamper with the content of the digital signature either. Therefore, based on the digital signature for verification, the legality and security of the verification are ensured.
[0064] As an optional example, referring to Figure 2 , when generating a digital signature, first combine the single sign-on credential ticket (single point ticket) and application ID information to obtain composite data, perform data hashing on the composite data to obtain a data hash value, and then encrypt the data hash value using the signature private key to generate a digital signature.
[0065] It should be noted that after the mobile application generates a digital signature, the verification field structure reported to the business platform system through the verification interface is: ticket + digital signature. Therefore, in the business platform system, verification can be first performed based on the digital signature, and then after the digital signature verification passes, verification can be performed on the single sign-on authentication platform based on the single sign-on credential ticket. Then, if the single sign-on credential ticket also passes the verification, the embedded page can be logged in on the mobile application. Through the dual verification of the digital signature and the single sign-on authentication platform, the security and reliability of single sign-on are enhanced.
[0066] In an exemplary embodiment, step 102, generating the data to be verified according to the application identifier to be verified and the single sign-on credential to be verified, includes:
[0067] Perform data hashing on the composite data to be verified obtained by combining the application identifier to be verified and the single sign-on credential to be verified to obtain the data to be verified;
[0068] After generating the data to be verified according to the application identifier to be verified and the single sign-on credential to be verified, the method further includes:
[0069] Decrypt the digital signature using the public key corresponding to the private key to obtain a data hash value. If the data to be verified is consistent with the data hash value, it is determined that the data to be verified matches the digital signature. If the data to be verified is inconsistent with the data hash value, it is determined that the data to be verified does not match the digital signature.
[0070] In an embodiment of the present invention, with reference to Figure 3 , after combining the application identifier to be verified and the single sign-on credential to be verified submitted by the mobile application, the data to be verified composite data is obtained, and the data to be verified composite data is processed for data hashing to obtain the data to be verified, specifically, the data hash value to be verified. In addition, the business platform system decrypts the digital signature submitted by the mobile application using the public key corresponding to the private key to obtain the data hash value, and then matches the data hash value to be verified and the data hash value of the digital signature. If the two match, that is, they are consistent, it can be determined that the data to be verified matches the digital signature, which means that the application identifier to be verified and the single sign-on credential to be verified submitted by the mobile application have not been tampered with, and further verification can be performed based on the single sign-on credential ticket in the single sign-on system platform. On the contrary, if the two do not match, that is, they are consistent, it can be determined that the data to be verified does not match the digital signature, which means that the application identifier to be verified and the single sign-on credential to be verified submitted by the mobile application are likely to have been tampered with, and there is no need to perform verification based on the single sign-on credential ticket in the single sign-on system platform.
[0071] In an exemplary embodiment, the method may further include the following steps:
[0072] When the data to be verified does not match the digital signature, or when the verification fails at the single sign-on authentication center based on the single sign-on credential, notify the application program to log in to the embedded page in the mobile application in other ways.
[0073] In an embodiment of the present invention, if it is determined that the data to be verified does not match the digital signature, it can be explained that the application identifier to be verified and the single sign-on credential to be verified submitted by the mobile application are likely to have been tampered with, and there is no need to perform verification based on the single sign-on credential ticket in the single sign-on system platform. In addition, notify the application program to log in to the embedded page in the mobile application in other ways, for example, re-enter the login account and password in the mobile application.
[0074] With reference to Figure 4, showing the flowchart of another single sign-on method provided in the embodiment of the present invention, which is applied to a mobile application. In the business platform system corresponding to the mobile application, the digital signature and the single sign-on credential reported by the mobile application through the interface are saved. The digital signature is generated by the mobile application according to the application identifier and the single sign-on credential, and the single sign-on credential is the credential for authorized login issued by the single sign-on authentication center for the mobile application. The method may specifically include the following steps:
[0075] Step 401: Send a login request for logging in to the embedded page in the mobile application to the business platform system; the login request includes the application identifier to be verified and the single sign-on credential to be verified; the business platform system is used to generate the data to be verified according to the application identifier to be verified and the single sign-on credential to be verified, and when the data to be verified matches the digital signature, perform verification at the single sign-on authentication center based on the single sign-on credential.
[0076] Step 402: When the verification at the single sign-on authentication center is passed, log in to the embedded page in the mobile application.
[0077] In the embodiment of the present invention, if a user wants to log in to an embedded page in a mobile application, the mobile application can send a login request to its corresponding business platform system. Then, the business platform system generates the data to be verified according to the application identifier to be verified and the single sign-on credential to be verified in the login request, and matches it with the digital signature submitted by the previous mobile application. When the data to be verified matches the digital signature, it is regarded as passing the first verification. Then, the second verification can be performed at the single sign-on authentication center based on the single sign-on credential ticket. If the second verification at the single sign-on authentication center is successful, the embedded page can be logged in to the mobile application. When performing single sign-on when logging in to the embedded page in the mobile application in the embodiment of the present invention, in addition to passing the verification of the single sign-on authentication center, it is also necessary to verify the application identifier (digital signature) of the mobile application, which enhances the security and reliability during single sign-on.
[0078] In an exemplary embodiment, before the step 401: send a login request for logging in to the embedded page in the mobile application to the business platform system, the method may further include the following steps:
[0079] Obtain the application identifier of the application program;
[0080] Obtain the single sign-on credential issued by the single sign-on authentication center for the mobile application;
[0081] Perform data hashing on the combined composite data of the application identifier and the single sign-on credential to obtain a data hash value;
[0082] Use the private key to encrypt the data hash value to obtain a digital signature.
[0083] Specifically, when generating a digital signature, in order to ensure the validity of the data, composite data is used to generate the digital signature. The composite data can be obtained by combining the following data: single sign-on credential ticket and application ID information. Even if other third parties obtain the single sign-on credential ticket, they cannot use the single sign-on credential ticket for single sign-on when the application ID information obtained during the loading of the embedded H5 page does not match. At the same time, since asymmetric encryption can be used to perform data hashing on the composite data obtained by combining the single sign-on credential ticket and application ID information to obtain a data hash value, and finally the private key is used to encrypt the data hash value to generate a digital signature, third parties cannot tamper with the content of the digital signature. Therefore, verification based on the digital signature ensures the legality and security of the verification.
[0084] In an exemplary embodiment, the single sign-on credential can be obtained in the following manner:
[0085] Send a request for acquisition to the single sign-on authentication center; the acquisition request includes a user identifier and a timestamp, and the single sign-on authentication center is used to generate the single sign-on credential according to the user identifier, timestamp, and random string;
[0086] Receive the single sign-on credential sent by the single sign-on authentication center.
[0087] In the embodiment of the present invention, a mobile application can send a request for obtaining a single sign-on credential to the single sign-on authentication center. The acquisition request may include a user identifier (User ID) and a timestamp. The single sign-on authentication center uses the user's User ID + timestamp + random string, and then performs encryption using AES (Advanced Encryption Standard) to obtain an encrypted string, and generates the encrypted string as the single sign-on credential ticket for this time and returns it to the mobile application.
[0088] To enable those skilled in the art to better understand, the following uses a specific example to illustrate the process of implementing single sign-on in the embodiment of the present invention.
[0089] Refer to Figure 5 , which shows a system architecture diagram for implementing single sign-on provided in the embodiment of the present invention, including an application app (mobile application), an embedded H5 system (business platform system), and a single sign-on platform (single sign-on authentication center). Specifically:
[0090] M1. Single sign-on authentication center
[0091] The single sign-on authentication center is independent of the business platform system and is mainly used for the verification functions of user registration, login, and single sign-on.
[0092] The modules involved in the single sign-on authentication center include:
[0093] M1.1 User First Registration and Login Module:
[0094] When users first use the mobile application, they need to register and log in. After user registration, user data is generated in the background.
[0095] M1.2 Login Verification Module: Generate a single sign-on credential ticket (hereinafter referred to as the single sign-on ticket)
[0096] When the mobile application requests a single sign-on ticket, the single sign-on authentication center uses the user's User ID + timestamp + random string, and then performs AES encryption to generate an encrypted string as the current single sign-on ticket and returns it to the mobile application.
[0097] M1.3 Single Sign-on Ticket Verification Module: The business platform system verifies the obtained single sign-on ticket with the single sign-on authentication center, and the single sign-on authentication center returns the verification result.
[0098] M2. Business Platform System
[0099] M2.1 Composite Signature Generation Module (Mobile Application Side):
[0100] When the mobile application invokes the embedded H5 page, a digital signature needs to be generated based on the composite data. Specifically, in order to ensure the validity of the data when generating the digital signature, the composite data is used to generate the digital signature, where the composite data can include: the single sign-on ticket and the application ID information. Even if other third parties obtain the single sign-on ticket, but the application ID information obtained when the H5 page is loaded does not match, they cannot use the single sign-on ticket for single sign-on. At the same time, through asymmetric encryption, third parties cannot tamper with the content of the verification data, ensuring the legality and security of the verification. Refer to Figure 2 When generating the digital signature, first splice the ticket and application ID information data, perform hash hashing to generate a data hash value, and then encrypt the data hash value with the private key to generate the digital signature. It should be noted here that the digital signature is the verification field structure reported by the mobile application to the background through the verification interface: ticket + digital signature.
[0101] M2.2 Module for Verifying the Digital Signature Generated from Composite Data (Embedded H5 System Side):
[0102] The embedded H5 page serves as the callee. When it is invoked, the single sign-on information of the user (i.e., the application ID information to be verified and the single sign-on ticket to be verified) is first verified for validity. Refer to Figure 3 , splice the single sign-on ticket and the current application ID information (obtained through the application interface), perform a hash on this composite data to obtain the hash value of the data to be verified; decrypt the digital signature with the public key to obtain the hash value of the decrypted data. Finally, compare the hash value of the data to be verified with the hash value of the data after signature processing to verify whether it is legal.
[0103] In summary, compared with the prior art, the main advantages of the embodiments of the present invention include: 1. By verifying the application ID information of the application that loads the embedded H5 page, the reliability of single sign-on security verification is increased. 2. Using the composite data for digital signature for secondary encryption to increase security.
[0104] It should be noted that for the method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the embodiments of the present invention are not limited by the described action sequences, because according to the embodiments of the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily essential for the embodiments of the present invention.
[0105] Refer to Figure 6 , which shows a structural block diagram of a single sign-on system provided in an embodiment of the present invention. The single sign-on system includes a mobile application 601, a service platform system 602, and a single sign-on authentication center 603. The service platform system stores the digital signature and the single sign-on credential reported by the mobile application through the interface. The digital signature is generated by the mobile application according to the application identifier and the single sign-on credential. The single sign-on credential is a credential for authorized login issued by the single sign-on authentication center for the mobile application; where:
[0106] The mobile application 601 is used to send a login request for logging in to the embedded page in the mobile application to the service platform system; the login request includes the application identifier to be verified and the single sign-on credential to be verified;
[0107] The service platform system 602 is used to generate data to be verified according to the application identifier to be verified and the single sign-on credential to be verified; when the data to be verified matches the digital signature, it is verified at the single sign-on authentication center based on the single sign-on credential to log in to the embedded page in the mobile application when the verification passes.
[0108] In an exemplary embodiment, the mobile application 601 is configured to obtain the application identifier of the application; obtain the single sign-on credential issued by the single sign-on authentication center for the mobile application; perform data hashing on the combined composite data of the application identifier and the single sign-on credential to obtain a data hash value; and encrypt the data hash value using a private key to obtain a digital signature.
[0109] In an exemplary embodiment, the mobile application 601 is configured to send a fetch request to the single sign-on authentication center; the fetch request includes a user identifier and a timestamp, and the single sign-on authentication center is configured to generate the single sign-on credential according to the user identifier, the timestamp, and a random string; and receive the single sign-on credential sent by the single sign-on authentication center.
[0110] In an exemplary embodiment, the service platform system 602 is configured to perform data hashing on the combined verification composite data obtained by combining the to-be-verified application identifier and the to-be-verified single sign-on credential to obtain to-be-verified data; decrypt the digital signature using the public key corresponding to the private key to obtain a data hash value; wherein, if the to-be-verified data is consistent with the data hash value, it is determined that the to-be-verified data matches the digital signature; if the to-be-verified data is inconsistent with the data hash value, it is determined that the to-be-verified data does not match the digital signature.
[0111] In an exemplary embodiment, the service platform system 602 is configured to, when the to-be-verified data does not match the digital signature, or when the verification fails at the single sign-on authentication center based on the single sign-on credential, notify the application to log in to the embedded page in the mobile application in another way.
[0112] For the system embodiment, since it is basically similar to the method embodiment, the description is relatively simple. For related parts, refer to the partial description of the method embodiment.
[0113] Preferably, an embodiment of the present invention further provides an electronic device, including: a processor, a memory, and a computer program stored on the memory and executable on the processor. When the computer program is executed by the processor, it implements each process of the above single sign-on method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0114] An embodiment of the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements each process of the above-mentioned single sign-on method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here. Among them, the computer-readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc, etc.
[0115] An embodiment of the present invention provides a computer program product. The program product is stored in a storage medium and is executed by at least one processor to implement each process of the above-mentioned method embodiment and can achieve the same technical effect. To avoid repetition, it will not be elaborated here.
[0116] It should be noted that in this article, the term "comprise", "include" or any other variant thereof is intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising a..." does not exclude the existence of additional identical elements in the process, method, article or device including the element.
[0117] Through the description of the above embodiments, those skilled in the art can clearly understand that the above embodiment method can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disc) and includes several instructions for causing a terminal (which may be a mobile phone, a computer, a server, an air conditioner, or a network device, etc.) to execute the methods described in the various embodiments of the present invention.
[0118] The embodiments of the present invention have been described above in conjunction with the accompanying drawings. However, the present invention is not limited to the above specific embodiments. The above specific embodiments are merely illustrative and not restrictive. Under the inspiration of the present invention, those of ordinary skill in the art can also make many forms without departing from the purpose of the present invention and the scope protected by the claims, and all of them belong to the protection scope of the present invention.
[0119] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed in the embodiments of the present invention can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present invention.
[0120] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be elaborated herein.
[0121] In the embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the devices or units can be in an electrical, mechanical, or other form.
[0122] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0123] In addition, the functional units in the various embodiments of the present invention can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit.
[0124] When the above-mentioned functions are implemented in the form of software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, ROM, RAM, magnetic disks, or optical discs.
[0125] As described above, the above are only specific embodiments of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention can easily think of changes or substitutions, which should all be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention shall be subject to the protection scope of the claims.
Claims
1. A single sign-on method, characterized in that, Applied to a business platform system, in which digital signatures and single sign-on credentials reported by a mobile application through an interface are saved. The digital signature is generated by the mobile application according to an application identifier and a single sign-on credential, and the single sign-on credential is a credential for authorized login issued by a single sign-on authentication center to the mobile application; The method includes: Receiving a login request for logging in to an embedded page in the mobile application; The login request includes a to-be-verified application identifier and a to-be-verified single sign-on credential; Generating to-be-verified data according to the to-be-verified application identifier and the to-be-verified single sign-on credential; When the to-be-verified data matches the digital signature, performing verification at the single sign-on authentication center based on the single sign-on credential, so as to log in to the embedded page in the mobile application when the verification passes; The digital signature is generated by the mobile application in the following manner: The mobile application is used to obtain the application identifier of the mobile application; Obtain the single sign-on credential issued by the single sign-on authentication center to the mobile application; Combine the application identifier and the single sign-on credential to obtain composite data and perform data hashing on the composite data to obtain a data hash value; Use a private key to encrypt the data hash value to obtain a digital signature; The generating to-be-verified data according to the to-be-verified application identifier and the to-be-verified single sign-on credential includes: Performing data hashing on the to-be-verified composite data obtained by combining the to-be-verified application identifier and the to-be-verified single sign-on credential to obtain to-be-verified data.
2. The method according to claim 1, characterized in that After the generating to-be-verified data according to the to-be-verified application identifier and the to-be-verified single sign-on credential, the method further includes: Performing decryption processing on the digital signature using the public key corresponding to the private key to obtain a data hash value; Wherein, if the to-be-verified data is consistent with the data hash value, it is determined that the to-be-verified data matches the digital signature; If the to-be-verified data is inconsistent with the data hash value, it is determined that the to-be-verified data does not match the digital signature.
3. The method according to claim 1, wherein The method further includes: When the to-be-verified data does not match the digital signature, or when the verification at the single sign-on authentication center based on the single sign-on credential fails, notifying the mobile application to log in to the embedded page in the mobile application in other ways.
4. A single sign-on method, characterized in that, Applied to a mobile application, in the business platform system corresponding to the mobile application, digital signatures and single sign-on credentials reported by the mobile application through an interface are saved. The digital signature is generated by the mobile application according to an application identifier and a single sign-on credential, and the single sign-on credential is a credential for authorized login issued by a single sign-on authentication center to the mobile application; The method includes: Send a login request for logging in to the embedded page in the mobile application to the business platform system; the login request includes a to-be-verified application identifier and a to-be-verified single sign-on credential; the business platform system is used to generate to-be-verified data according to the to-be-verified application identifier and the to-be-verified single sign-on credential, and when the to-be-verified data matches the digital signature, perform verification at the single sign-on authentication center based on the single sign-on credential; When the verification at the single sign-on authentication center is passed, log in to the embedded page in the mobile application; Before sending the login request for logging in to the embedded page in the mobile application to the business platform system, the method further includes: Obtain the application identifier of the mobile application; Obtain the single sign-on credential issued by the single sign-on authentication center for the mobile application; Perform data hashing on the combined composite data of the application identifier and the single sign-on credential to obtain a data hash value; Use the private key to encrypt the data hash value to obtain a digital signature.
5. The method according to claim 4, characterized in that, The single sign-on credential is obtained through the following method: Send a obtain request to the single sign-on authentication center; the obtain request includes a user identifier and a timestamp, and the single sign-on authentication center is used to generate the single sign-on credential according to the user identifier, the timestamp and a random string; Receive the single sign-on credential sent by the single sign-on authentication center.
6. A single sign-on system, characterized in that, The single sign-on system includes a mobile application, a business platform system and a single sign-on authentication center. The business platform system stores the digital signature and the single sign-on credential reported by the mobile application through an interface. The digital signature is generated by the mobile application according to the application identifier and the single sign-on credential, and the single sign-on credential is a credential for authorizing login issued by the single sign-on authentication center for the mobile application; wherein: The mobile application is used to send a login request for logging in to the embedded page in the mobile application to the business platform system; the login request includes a to-be-verified application identifier and a to-be-verified single sign-on credential; The business platform system is used to generate to-be-verified data according to the to-be-verified application identifier and the to-be-verified single sign-on credential; when the to-be-verified data matches the digital signature, perform verification at the single sign-on authentication center based on the single sign-on credential to log in to the embedded page in the mobile application when the verification is passed; The digital signature is generated by the mobile application through the following method: the mobile application is used to obtain the application identifier of the mobile application; obtain the single sign-on credential issued by the single sign-on authentication center for the mobile application; combine the application identifier and the single sign-on credential and then perform data hashing on the combined composite data to obtain a data hash value; use the private key to encrypt the data hash value to obtain a digital signature; The generation of the to-be-verified data according to the to-be-verified application identifier and the to-be-verified single sign-on credential includes: Perform data hashing on the combined to-be-verified composite data of the to-be-verified application identifier and the to-be-verified single sign-on credential to obtain to-be-verified data.
7. An electronic device, characterized in that, It includes a processor, a communication interface, a memory, and a communication bus. Among them, the processor, the communication interface, and the memory complete mutual communication through the communication bus; The memory is used to store computer programs; When the processor is used to execute the program stored on the memory, it implements the method according to any one of claims 1-5.
8. One or more computer-readable media, on which instructions are stored, and when executed by one or more processors, cause the processors to execute the method according to any one of claims 1-5.
Citation Information
Patent Citations
Integration type registering method for web application or website
CN102404392A
Multi-page-based single sign-on method, device, electronic equipment and storage medium
CN112487400A