Implementation method and system of enterprise service platform capable of carrying multiple third-party applications

By implementing unified authentication and interface standardization for the enterprise service platform, the problem of incompatibility between the platform and various third-party applications has been solved, enabling collaborative operation and rich functionality between the platform and third-party applications, and reducing development and procurement costs.

CN114444057BActive Publication Date: 2026-03-03AISINO SOFTWARE TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111627998.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-28
Publication Date
2026-03-03
Estimated Expiration
2041-12-28

AI Technical Summary

Technical Problem

In existing technologies, the different account and authentication systems of applications designed by third-party application developers result in enterprise service platforms being unable to be compatible with various third-party applications.

Method used

The system performs a first authentication on enterprises intending to access the enterprise service platform to generate an enterprise ID, and a second authentication on platform users to confirm platform-authenticated users. This enables interaction between platform-authenticated users and platform-accessed applications. The system uses the SM2 national cryptographic algorithm to encrypt interface request and response messages and designs a unified interface specification and account management module.

Benefits of technology

It has achieved a unified authentication system for enterprise service platforms and third-party applications, reducing development complexity and redundant R&D costs, enriching platform functions, supporting customized application access, and reducing enterprise procurement costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114444057B_ABST
    Figure CN114444057B_ABST
Patent Text Reader

Abstract

The embodiment of the present application discloses an implementation method of an enterprise service platform capable of carrying multiple third-party applications, which comprises: performing first authentication on an enterprise intending to access a third-party application in the enterprise service platform, and managing the content of the service of the platform accessing the application, wherein the platform accessing application is a third-party application of the enterprise intending to access the enterprise service platform through the first authentication; performing second authentication on a platform user applying for the service of the platform accessing the application, confirming the platform user as a platform authentication user when the second authentication is passed; and realizing the interaction between the platform authentication user and the platform accessing application. The method and system design a unified interface specification of the platform, avoid the need of each enterprise to separately connect and promote, greatly reduce the development workload and development complexity; meanwhile, the access of the third-party application can effectively reduce the repeated research and development of the platform product, so as to realize the cooperation and win-win of the platform business and the third-party service developer.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of enterprise service platform construction, and in particular to a method and system for implementing an enterprise service platform that can carry multiple third-party applications. Background Technology

[0002] With the increasing demand for software development, software vendors have designed many different third-party applications. These numerous third-party applications have different account systems and authentication systems, making it an urgent technical problem for enterprise service platforms to be compatible with so many different third-party applications. Summary of the Invention

[0003] To address the technical problem in existing technologies where enterprise service platforms are incompatible with various heterogeneous third-party applications due to differences in account systems and authentication systems designed by third-party application developers, embodiments of the present invention provide a method and system for implementing an enterprise service platform capable of supporting multiple third-party applications.

[0004] According to one aspect of the present invention, a method for implementing an enterprise service platform capable of carrying multiple third-party applications is provided, the method comprising:

[0005] The platform performs initial authentication on enterprises that intend to access third-party applications on the enterprise service platform, and manages the content of services enabled for applications accessed on the platform. The applications accessed on the platform are third-party applications that are intended to access the enterprise service platform by enterprises that have passed the initial authentication.

[0006] A second authentication is performed on platform users who apply for platform access to application services. When the second authentication is successful, the platform user is confirmed as a platform-authenticated user.

[0007] Enables interaction between platform-authenticated users and platform-accessed applications.

[0008] Optionally, in the above-described method embodiments of the present invention, the first authentication of the enterprise intending to access the third-party application on the enterprise service platform, and the management of the platform access permissions for the application to enable services, include:

[0009] The platform conducts initial authentication for enterprises intending to integrate third-party applications, and manages the content of services enabled for applications integrated into the platform, including:

[0010] Receive the first authentication request sent by the enterprise that intends to access the third-party application on the enterprise service platform. The first authentication request includes the enterprise's identity information and relevant information about the third-party application service to be accessed.

[0011] The enterprise service platform parses the first authentication request;

[0012] If the enterprise's identity information in the first authentication request is valid, an enterprise ID is generated, and the service content of the third-party application service to be accessed is determined based on the relevant information of the third-party application service to be accessed. The service code of the third-party application to be accessed is generated, and the enterprise ID is associated with the service code of the third-party application to be accessed.

[0013] Optionally, in the above-described method embodiments of the present invention, performing a second authentication on platform users applying for platform access to the application service, and managing the platform-authenticated users' permissions to use the platform access application include:

[0014] A second authentication is performed on platform users applying for platform access services. When the second authentication is successful, the platform user is confirmed as a platform-authenticated user, including:

[0015] The platform user who intends to apply for a third-party application service sends a second authentication request through a security control device. The second authentication request includes the platform user's CA digital certificate, enterprise identification number, and the third-party application service to be applied for.

[0016] The enterprise service platform parses the second authentication request;

[0017] When the enterprise identity information confirmed by the enterprise identification number matches the enterprise identity information in the CA digital certificate, the platform user applying for the third-party application service is confirmed as a platform-certified user, and a user ID is generated and associated with the third-party application service.

[0018] Optionally, in the above-described method embodiments of the present invention, before performing the first authentication on the third-party application intended to access the enterprise service platform, the method further includes setting up an interface for the third-party application to access the platform for the enterprise service platform, wherein:

[0019] The enterprise service platform can be configured with an authorization activation interface, an authorization login verification interface, and an authorization credit interface.

[0020] When setting up third-party application call authorization activation interface, authorization login verification interface, and authorization credit interface, the enterprise service platform uses the SM2 national cryptographic algorithm to generate separate key pairs to encrypt and decrypt interface request and response messages.

[0021] Optionally, in the above-described method embodiments of the present invention, the interaction between the platform-authenticated user and the platform access application includes:

[0022] Platform-authenticated users apply to activate the platform access application service on the enterprise service platform. The enterprise service platform calls the authorization activation interface of the platform access application, enabling the platform access application to complete the activation authorization for the platform-authenticated user.

[0023] After the platform access application completes the authorization for the platform-authenticated user, when the platform-authenticated user starts or is redirected to the platform access application through the enterprise service platform, the platform access application calls the authorization login verification interface pre-set in the enterprise service platform to verify the legitimacy of the platform-authenticated user. When the platform-authenticated user is verified to be legitimate, the login status is set. The platform access application then authorizes the platform-authenticated user to access the operation page of the platform-authenticated user in the platform access application through the enterprise service platform to perform operations.

[0024] When a platform-authenticated user applies to deactivate a platform access application on the enterprise service platform, the enterprise service platform calls the pre-configured authorization deactivation interface for the platform access application, and the platform access application completes the deactivation operation for the platform-authenticated user.

[0025] Optionally, in the above-described method embodiments of the present invention, the method further includes a service that enables platform-authenticated users to associate multiple third-party applications on an enterprise service platform based on a user ID.

[0026] Optionally, in the above-described method embodiments of the present invention, the method further includes configuring the number of platform access applications that can be displayed in the enterprise service platform and the services that the platform access applications can activate, according to the needs of the enterprise service platform customizer.

[0027] According to another aspect of the present invention, an implementation system for an enterprise service platform capable of carrying multiple third-party applications is provided, the implementation system comprising:

[0028] The first authentication module performs initial authentication on enterprises intending to access third-party applications on the enterprise service platform, and manages the content of services enabled for applications accessing the platform. The applications accessing the platform are third-party applications that are intended to access the enterprise service platform by enterprises that have passed the first authentication.

[0029] The second authentication module performs a second authentication on platform users who apply for platform access application services. When the second authentication is successful, the platform user is confirmed as a platform-authenticated user.

[0030] The data interaction module is used to enable interaction between platform-authenticated users and platform-accessed applications.

[0031] Optionally, in the above-described device embodiments of the present invention, the first authentication module performs a first authentication on the enterprise intending to access a third-party application on the enterprise service platform, and manages the content of the services enabled by the application accessed to the platform, including:

[0032] Receive the first authentication request sent by the enterprise that intends to access the third-party application on the enterprise service platform. The first authentication request includes the enterprise's identity information and relevant information about the third-party application service to be accessed.

[0033] The enterprise service platform parses the first authentication request;

[0034] If the enterprise's identity information in the first authentication request is valid, an enterprise ID is generated, and the service content of the third-party application service to be accessed is determined based on the relevant information of the third-party application service to be accessed. The service code of the third-party application to be accessed is generated, and the enterprise ID is associated with the service code of the third-party application to be accessed.

[0035] Optionally, in the above-described device embodiments of the present invention, the second authentication module performs a second authentication on the platform user applying for platform access to the application service. When the second authentication is successful, confirming that the platform user is a platform-authenticated user includes:

[0036] The platform user who intends to apply for a third-party application service sends a second authentication request through a security control device. The second authentication request includes the platform user's CA digital certificate, enterprise identification number, and the third-party application service to be applied for.

[0037] The enterprise service platform parses the second authentication request;

[0038] When the enterprise identity information confirmed by the enterprise identification number matches the enterprise identity information in the CA digital certificate, the platform user applying for the third-party application service is confirmed as a platform-certified user, and a user ID is generated and associated with the third-party application service.

[0039] Optionally, in the above-described device embodiments of the present invention, the system further includes an interaction interface module for setting up an interface for third-party applications to access the platform for the enterprise service platform, wherein:

[0040] The enterprise service platform can be configured with an authorization activation interface, an authorization login verification interface, and an authorization credit interface.

[0041] When setting up third-party application call authorization activation interface, authorization login verification interface, and authorization credit interface, the enterprise service platform uses the SM2 national cryptographic algorithm to generate separate key pairs to encrypt and decrypt interface request and response messages.

[0042] Optionally, in the above-described device embodiments of the present invention, the data interaction module realizes the interaction between platform-authenticated users and platform-accessed applications, including:

[0043] Platform-authenticated users apply to activate the platform access application service on the enterprise service platform. The enterprise service platform calls the authorization activation interface of the platform access application, enabling the platform access application to complete the activation authorization for the platform-authenticated user.

[0044] After the platform access application completes the authorization for the platform-authenticated user, when the platform-authenticated user starts or is redirected to the platform access application through the enterprise service platform, the platform access application calls the authorization login verification interface pre-set in the enterprise service platform to verify the legitimacy of the platform-authenticated user. When the platform-authenticated user is verified to be legitimate, the login status is set. The platform access application then authorizes the platform-authenticated user to access the operation page of the platform-authenticated user in the platform access application through the enterprise service platform to perform operations.

[0045] When a platform-authenticated user applies to deactivate a platform access application on the enterprise service platform, the enterprise service platform calls the pre-configured authorization deactivation interface for the platform access application, and the platform access application completes the deactivation operation for the platform-authenticated user.

[0046] Optionally, in the above-described device embodiments of the present invention, the system further includes an account management module, which enables platform-authenticated users to associate multiple third-party application services on the enterprise service platform based on a user ID.

[0047] Optionally, in the above-described device embodiments of the present invention, the system further includes a customization module, used to configure the number of platform access applications that can be displayed in the enterprise service platform and the services that the platform access applications can activate, according to the needs of the enterprise service platform customizer.

[0048] The implementation method of an enterprise service platform capable of carrying multiple third-party applications, based on the above embodiments of the present invention, includes: performing a first authentication on an enterprise intending to access a third-party application on the enterprise service platform, and managing the content of the services enabled by the platform-accessed application, wherein the platform-accessed application is a third-party application of the enterprise intending to access the enterprise service platform through the first-authenticated enterprise; performing a second authentication on a platform user applying for the service of the platform-accessed application, and confirming the platform user as a platform-authenticated user when the second authentication is successful; and realizing the interaction between the platform-authenticated user and the platform-accessed application. The beneficial effects of the method and system include: 1) The enterprise service platform establishes an authentication system for platform users and enterprises accessing third-party applications, unifying users and third-party applications within the service platform framework; 2) A unified interface specification is designed for the platform, allowing enterprises to connect to third-party applications according to the specification, thus avoiding the need for each enterprise to connect and promote separately, greatly reducing development workload and complexity; simultaneously, the access of third-party applications enriches the service platform's functionality and effectively reduces redundant R&D of platform products, reducing costs and increasing efficiency, thereby achieving a win-win collaboration between platform providers and third-party service developers; 3) A customization function is designed, allowing the enterprise service platform to customize the number of third-party applications and the services that applications can provide according to the different needs of the customizer; 4) An account management module is designed, allowing users to be authenticated through the platform and use a single user ID to associate with and use the services of third-party applications on the platform, effectively reducing enterprise procurement costs, and enabling the use of membership packages for on-demand subscription services.

[0049] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description

[0050] The above and other objects, features, and advantages of the present invention will become more apparent from the more detailed description of the embodiments of the invention in conjunction with the accompanying drawings. The drawings are provided to further illustrate the embodiments of the invention and form part of the specification. They are used together with the embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings, the same reference numerals generally represent the same parts or steps.

[0051] Figure 1 This is a flowchart illustrating an exemplary embodiment of the present invention of a method for implementing an enterprise service platform capable of carrying multiple third-party applications;

[0052] Figure 2 This is a schematic diagram illustrating the interaction between a platform-authenticated user and a platform access application, provided in an exemplary embodiment of the present invention.

[0053] Figure 3This is a schematic diagram of the structure of an enterprise service platform implementation system capable of carrying multiple third-party applications, provided by an exemplary embodiment of the present invention. Detailed Implementation

[0054] Hereinafter, exemplary embodiments according to the present invention will be described in detail with reference to the accompanying drawings. Obviously, the described embodiments are merely some embodiments of the present invention, and not all embodiments of the present invention. It should be understood that the present invention is not limited to the exemplary embodiments described herein.

[0055] It should be noted that, unless otherwise specifically stated, the relative arrangement, numerical expressions, and values ​​of the components and steps described in these embodiments do not limit the scope of the invention.

[0056] Those skilled in the art will understand that the terms "first," "second," etc., in the embodiments of the present invention are only used to distinguish different steps, devices, or modules, and do not represent any specific technical meaning, nor do they indicate a necessary logical order between them.

[0057] It should also be understood that in the embodiments of the present invention, "multiple" can refer to two or more, and "at least one" can refer to one, two or more.

[0058] It should also be understood that any component, data or structure mentioned in the embodiments of the present invention can generally be understood as one or more unless explicitly defined or given contrary instructions in the context.

[0059] Furthermore, the term "and / or" in this invention is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this invention generally indicates that the preceding and following related objects have an "or" relationship.

[0060] It should also be understood that the description of the various embodiments in this invention emphasizes the differences between the various embodiments, and the similarities or similarities can be referred to each other. For the sake of brevity, they will not be described in detail.

[0061] At the same time, it should be understood that, for ease of description, the dimensions of the various parts shown in the accompanying drawings are not drawn according to actual scale.

[0062] The following description of at least one exemplary embodiment is merely illustrative and is in no way intended to limit the invention or its application or use.

[0063] Techniques, methods, and equipment known to those skilled in the art may not be discussed in detail, but where appropriate, they should be considered part of the specification.

[0064] It should be noted that similar labels and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be discussed further in subsequent figures.

[0065] The embodiments of this invention can be applied to electronic devices such as terminal devices, computer systems, and servers, and can operate together with a wide range of other general-purpose or special-purpose computing system environments or configurations. Well-known examples of terminal devices, computing systems, environments, and / or configurations suitable for use with electronic devices such as terminal devices, computer systems, and servers include, but are not limited to: personal computer systems, server computer systems, thin clients, thick clients, handheld or laptop devices, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputer systems, mainframe computer systems, and distributed cloud computing environments including any of the above systems, etc.

[0066] Electronic devices such as terminal devices, computer systems, and servers can be described in the general context of computer system executable instructions (such as program modules) executed by a computer system. Typically, program modules can include routines, programs, object programs, components, logic, data structures, etc., which perform specific tasks or implement specific abstract data types. Computer systems / servers can be implemented in distributed cloud computing environments, where tasks are executed by remote processing devices linked through communication networks. In distributed cloud computing environments, program modules can reside on local or remote computing system storage media, including storage devices.

[0067] Exemplary methods

[0068] Figure 1 This is a flowchart illustrating an exemplary embodiment of the present invention, showing a method for implementing an enterprise service platform capable of supporting various third-party applications. This embodiment can be applied to electronic devices, such as... Figure 1 As shown in the figure, the implementation method of the enterprise service platform that can carry multiple third-party applications described in this embodiment includes the following steps:

[0069] Step 101: Perform first authentication on the enterprise intending to access the third-party application on the enterprise service platform, and manage the permission for the platform access application to open services. The platform access application is a third-party application that is intended to access the enterprise service platform by the enterprise that has passed the first authentication.

[0070] Optionally, the platform may perform initial authentication on enterprises intending to integrate third-party applications, and manage the platform's permissions for enabling services for integrated applications, including:

[0071] The platform conducts initial authentication for enterprises intending to integrate third-party applications, and manages the content of services enabled for applications integrated into the platform, including:

[0072] Receive the first authentication request sent by the enterprise that intends to access the third-party application on the enterprise service platform. The first authentication request includes the enterprise's identity information and relevant information about the third-party application service to be accessed.

[0073] The enterprise service platform parses the first authentication request;

[0074] If the enterprise's identity information in the first authentication request is valid, an enterprise ID is generated, and the service content of the third-party application service to be accessed is determined based on the relevant information of the third-party application service to be accessed. The service code of the third-party application to be accessed is generated, and the enterprise ID is associated with the service code of the third-party application to be accessed.

[0075] In one embodiment, for an enterprise to access a third-party application on an enterprise service platform, the enterprise and the third-party application to be accessed must first be verified. The enterprise identity information includes information proving the enterprise's qualifications, such as its name, while the information related to the third-party application service includes the application's security assessment report, performance data, etc. An enterprise ID is generated by verifying the enterprise identity information, and service codes are generated for the services that the third-party application can provide, thereby establishing a connection between the enterprise service platform and the enterprise to be accessed by the third-party application.

[0076] In step 102, a second authentication is performed on the platform user who applied for platform access application services. When the second authentication is successful, the platform user is confirmed as a platform-authenticated user.

[0077] Optionally, a second authentication is performed on platform users applying for platform access to applications, and the permissions of platform-authenticated users to use platform access applications are managed, including:

[0078] A second authentication is performed on platform users applying for platform access services. When the second authentication is successful, the platform user is confirmed as a platform-authenticated user, including:

[0079] The platform user who intends to apply for a third-party application service sends a second authentication request through a security control device. The second authentication request includes the platform user's CA digital certificate, enterprise identification number, and the third-party application service to be applied for.

[0080] The enterprise service platform parses the second authentication request;

[0081] When the enterprise identity information confirmed by the enterprise identification number matches the enterprise identity information in the CA digital certificate, the platform user applying for the third-party application service is confirmed as a platform-certified user, and a user ID is generated and associated with the third-party application service.

[0082] Optionally, the method also includes a service that allows platform-authenticated users to associate multiple third-party applications on an enterprise service platform based on a user ID.

[0083] In one embodiment, taking a taxpayer applying for tax services on an enterprise service platform as an example, the enterprise's identity authentication consists of hardware devices (Golden Tax Disk + Certificate), enterprise identification number, and mobile phone number. The Golden Tax Disk is a security device that enables control over invoice sources, limits, and tax sources according to the business needs of the State Taxation Administration during the invoice issuance process. When issuing an invoice, important data on the invoice is encrypted to generate ciphertext for anti-counterfeiting purposes. The invoice data is uploaded for signing, and the invoice information is encrypted and stored in the device's internal memory to prevent tampering. The Golden Tax Disk contains a tax CA digital certificate and supports certificate applications, storing information such as the enterprise's tax number, enterprise name, competent tax authority code, and competent tax authority name. When a taxpayer sends an authentication request, the enterprise service platform authenticates the taxpayer's identity. When authentication is successful, a user ID is generated, which establishes the association between the taxpayer and the enterprise service platform. When a taxpayer needs to use one or more third-party applications on the service platform, it only needs to associate the user ID with the service of the third-party application it intends to apply for.

[0084] In step 103, the interaction between the platform-authenticated user and the platform access application is realized.

[0085] Optionally, before performing the first authentication on the third-party application to be connected to the enterprise service platform, the process also includes setting up an interface for the third-party application to access the platform, wherein:

[0086] The enterprise service platform can be configured with an authorization activation interface, an authorization login verification interface, and an authorization credit interface.

[0087] When setting up third-party application call authorization activation interface, authorization login verification interface, and authorization credit interface, the enterprise service platform uses the SM2 national cryptographic algorithm to generate separate key pairs to encrypt and decrypt interface request and response messages.

[0088] Optionally, the interaction between platform-authenticated users and platform-accessed applications includes:

[0089] Platform-authenticated users apply to activate the platform access application service on the enterprise service platform. The enterprise service platform calls the authorization activation interface of the platform access application, enabling the platform access application to complete the activation authorization for the platform-authenticated user.

[0090] After the platform access application completes the authorization for the platform-authenticated user, when the platform-authenticated user starts or is redirected to the platform access application through the enterprise service platform, the platform access application calls the authorization login verification interface pre-set in the enterprise service platform to verify the legitimacy of the platform-authenticated user. When the platform-authenticated user is verified to be legitimate, the login status is set. The platform access application then authorizes the platform-authenticated user to access the operation page of the platform-authenticated user in the platform access application through the enterprise service platform to perform operations.

[0091] When a platform-authenticated user applies to deactivate a platform access application on the enterprise service platform, the enterprise service platform calls the pre-configured authorization deactivation interface for the platform access application, and the platform access application completes the deactivation operation for the platform-authenticated user.

[0092] Figure 2 This is a schematic diagram illustrating the interaction between a platform-authenticated user and a platform access application, provided by an exemplary embodiment of the present invention. For example... Figure 2 As shown, when a platform-certified user purchases services from the enterprise service platform and uses the platform access application, the interaction between the platform-certified user and the platform access application includes: authorizing the platform access application to grant authorization to the platform-certified user through the authorization activation interface; launching the redirected application; the authorized platform-certified user completing login status settings and performing operations through the authorization login verification interface; and completing deregistration through the authorization credit interface.

[0093] In one embodiment, when a platform-authenticated user interacts with a platform-accessible application, packet processing is performed in terms of the communication protocol, and the main structure is as follows:

[0094] Full request message:

[0095]

[0096] The data items in the request include:

[0097]

[0098] The data items are described as follows:

[0099]

[0100]

[0101] In the above-mentioned example of a user requesting the cancellation of a third-party application on the platform, the message includes the user ID requesting authorization, the unique number of this authorization, the authorization number to be terminated, the authorization code to be terminated, and the encryption method, thus forming a secure and complete request message.

[0102] Information needs to be collected for applications to be listed, in order to enable account interoperability and application calls.

[0103] Example of a request message:

[0104] Full request message:

[0105]

[0106] Plaintext data in the request:

[0107]

[0108]

[0109] Description of data items in the request message:

[0110]

[0111] The request message for collecting information on third-party applications listed above includes the user name, company name, and activation project code (service code). This is equivalent to collecting information on the qualifications of the third-party application provider and the services provided by the third-party application. The collection and authentication of this information ensures the security of users using third-party applications.

[0112] Optionally, the method further includes configuring the number of platform access applications that can be displayed in the enterprise service platform and the services that the platform access applications can activate, according to the needs of the enterprise service platform customizer.

[0113] In one embodiment, for service platform customizers with different needs, such as national, provincial, and municipal service platform customizers, third-party applications of customized enterprise service platforms can be configured as needed according to their application requirements, thereby achieving greater customized promotion and application.

[0114] Exemplary System

[0115] Figure 3 This is a schematic diagram of the structure of an enterprise service platform implementation system capable of supporting various third-party applications, provided by an exemplary embodiment of the present invention. For example... Figure 3 As shown in this embodiment, the enterprise service platform implementation system capable of supporting multiple third-party applications includes:

[0116] The first authentication module 301 performs first authentication on enterprises that intend to access third-party applications on the enterprise service platform, and manages the content of services enabled by the platform access applications. The platform access applications are third-party applications that are intended to access the enterprise service platform by enterprises that have passed the first authentication.

[0117] The second authentication module 302 performs a second authentication on the platform user who applies for access to the application service. When the second authentication is successful, the platform user is confirmed as a platform-authenticated user.

[0118] The data interaction module 303 is used to enable interaction between platform-authenticated users and platform-accessed applications.

[0119] Optionally, the first authentication module 301 performs initial authentication on enterprises intending to access third-party applications on the enterprise service platform, and manages the content of services enabled for applications accessing the platform, including:

[0120] Receive the first authentication request sent by the enterprise that intends to access the third-party application on the enterprise service platform. The first authentication request includes the enterprise's identity information and relevant information about the third-party application service to be accessed.

[0121] The enterprise service platform parses the first authentication request;

[0122] If the enterprise's identity information in the first authentication request is valid, an enterprise ID is generated, and the service content of the third-party application service to be accessed is determined based on the relevant information of the third-party application service to be accessed. The service code of the third-party application to be accessed is generated, and the enterprise ID is associated with the service code of the third-party application to be accessed.

[0123] Optionally, the second authentication module 302 performs a second authentication on the platform user applying for platform access application services. When the second authentication is successful, confirming the platform user as a platform-authenticated user includes:

[0124] The platform user who intends to apply for a third-party application service sends a second authentication request through a security control device. The second authentication request includes the platform user's CA digital certificate, enterprise identification number, and the third-party application service to be applied for.

[0125] The enterprise service platform parses the second authentication request;

[0126] When the enterprise identity information confirmed by the enterprise identification number matches the enterprise identity information in the CA digital certificate, the platform user applying for the third-party application service is confirmed as a platform-certified user, and a user ID is generated and associated with the third-party application service.

[0127] Optionally, the system further includes an interaction interface module 304, used to set up an interface for third-party applications to access the platform for the enterprise service platform, wherein:

[0128] The enterprise service platform can be configured with an authorization activation interface, an authorization login verification interface, and an authorization credit interface.

[0129] When setting up third-party application call authorization activation interface, authorization login verification interface, and authorization credit interface, the enterprise service platform uses the SM2 national cryptographic algorithm to generate separate key pairs to encrypt and decrypt interface request and response messages.

[0130] Optionally, the data interaction module 303 enables the interaction between platform-authenticated users and platform-accessed applications, including:

[0131] Platform-authenticated users apply to activate the platform access application service on the enterprise service platform. The enterprise service platform calls the authorization activation interface of the platform access application, enabling the platform access application to complete the activation authorization for the platform-authenticated user.

[0132] After the platform access application completes the authorization for the platform-authenticated user, when the platform-authenticated user starts or is redirected to the platform access application through the enterprise service platform, the platform access application calls the authorization login verification interface pre-set in the enterprise service platform to verify the legitimacy of the platform-authenticated user. When the platform-authenticated user is verified to be legitimate, the login status is set. The platform access application then authorizes the platform-authenticated user to access the operation page of the platform-authenticated user in the platform access application through the enterprise service platform to perform operations.

[0133] When a platform-authenticated user applies to deactivate a platform access application on the enterprise service platform, the enterprise service platform calls the pre-configured authorization deactivation interface for the platform access application, and the platform access application completes the deactivation operation for the platform-authenticated user.

[0134] Optionally, the system also includes an account management module 305, which enables platform-authenticated users to associate multiple third-party application services on the enterprise service platform based on a user ID.

[0135] Optionally, the system further includes a customization module 306, which is used to configure the number of platform access applications that can be displayed in the enterprise service platform and the services that the platform access applications can activate, according to the needs of the enterprise service platform customizer.

[0136] Exemplary computer program products and computer-readable storage media

[0137] In addition to the methods and apparatus described above, embodiments of this disclosure may also be computer program products, including computer program instructions that, when executed by a processor, cause the processor to perform the steps in the implementation methods of an enterprise service platform capable of carrying various third-party applications according to various embodiments of this disclosure as described in the "Exemplary Methods" section of this specification.

[0138] The computer program product can be written in any combination of one or more programming languages ​​to perform the operations of the embodiments of this disclosure. The programming languages ​​include object-oriented programming languages ​​such as Java and C++, as well as conventional procedural programming languages ​​such as C or similar languages. The program code can be executed entirely on a user's computing device, partially on a user's computing device, as a standalone software package, partially on a user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.

[0139] Furthermore, embodiments of this disclosure may also be computer-readable storage media storing computer program instructions that, when executed by a processor, cause the processor to perform the steps in the implementation method of an enterprise service platform capable of carrying various third-party applications according to various embodiments of this disclosure as described in the "Exemplary Methods" section of this specification.

[0140] The computer-readable storage medium may be any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may, for example, include, but is not limited to, electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatuses, or devices, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0141] The basic principles of this disclosure have been described above with reference to specific embodiments. However, it should be noted that the advantages, benefits, and effects mentioned in this disclosure are merely examples and not limitations, and should not be considered as essential features of each embodiment of this disclosure. Furthermore, the specific details disclosed above are for illustrative and facilitative purposes only, and are not limitations. These details do not limit the scope of this disclosure to the necessity of employing the aforementioned specific details for implementation.

[0142] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For system embodiments, since they largely correspond to method embodiments, the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.

[0143] The block diagrams of devices, apparatuses, devices, and systems disclosed herein are merely illustrative examples and are not intended to require or imply that they must be connected, arranged, or configured in the manner shown in the block diagrams. As those skilled in the art will recognize, these devices, apparatuses, devices, and systems can be connected, arranged, and configured in any manner. Words such as “comprising,” “including,” “having,” etc., are open-ended terms meaning “including but not limited to,” and are used interchangeably with them. The terms “or” and “and” as used herein refer to the terms “and / or,” and are used interchangeably with them unless the context clearly indicates otherwise. The term “such as” as used herein refers to the phrase “such as but not limited to,” and is used interchangeably with it.

[0144] The methods and apparatus of this disclosure may be implemented in many ways. For example, they may be implemented by software, hardware, firmware, or any combination of software, hardware, and firmware. The above-described order of steps for the methods is for illustrative purposes only, and the steps of the methods of this disclosure are not limited to the order specifically described above unless otherwise specifically stated. Furthermore, in some embodiments, this disclosure may also be implemented as a program recorded on a recording medium, the program including machine-readable instructions for implementing the methods according to this disclosure. Thus, this disclosure also covers recording media storing programs for performing the methods according to this disclosure.

[0145] It should also be noted that in the apparatus, devices, and methods of this disclosure, the components or steps are decomposable and / or recombinable. Such decomposition and / or recombination should be considered equivalent to the present disclosure. The above description of the disclosed aspects is provided to enable any person skilled in the art to make or use this disclosure. Various modifications to these aspects will be readily apparent to those skilled in the art, and the general principles defined herein can be applied to other aspects without departing from the scope of this disclosure. Therefore, this disclosure is not intended to be limited to the aspects shown herein, but rather to be carried out within the widest scope consistent with the principles and novel features disclosed herein.

[0146] The above description has been given for purposes of illustration and description. Furthermore, this description is not intended to limit the embodiments of this disclosure to the forms disclosed herein. Although numerous exemplary aspects and embodiments have been discussed above, those skilled in the art will recognize certain variations, modifications, alterations, additions, and sub-combinations therein.

Claims

1. An implementation method of an enterprise service platform capable of hosting multiple third-party applications, characterized in that, The implementation method comprises: Firstly, authenticating the enterprise which intends to access the third-party application on the enterprise service platform, and managing the content of the service of the platform accessing the application, comprising: Receiving the first authentication request sent by the enterprise which intends to access the third-party application on the enterprise service platform, wherein the first authentication request comprises the enterprise identity information and the related information of the third-party application service intended to be accessed; The enterprise service platform analyzes the first authentication request; When the enterprise identity information in the first authentication request is legal, generating the enterprise ID, determining the service content of the third-party application service intended to be accessed according to the related information of the third-party application service intended to be accessed, generating the service code of the third-party application intended to be accessed, and associating the enterprise ID with the service code of the third-party application intended to be accessed, wherein the platform accessing application is the third-party application of the enterprise intended to be accessed on the enterprise service platform through the first authentication; Secondly, authenticating the platform user applying for the service of the platform accessing the application, and confirming the platform user as a platform authentication user when the second authentication is passed, comprising: Receiving the second authentication request sent by the platform user applying for the service of the third-party application through the security control device, wherein the second authentication request comprises the CA digital certificate of the platform user, the enterprise identification number and the service of the third-party application intended to be applied for; The enterprise service platform analyzes the second authentication request; When the enterprise identity information confirmed according to the enterprise identification number is consistent with the enterprise identity information in the CA digital certificate, confirming the platform user applying for the service of the third-party application as a platform authentication user, generating the user ID, and associating the user ID with the service of the third-party application intended to be applied for; Realizing the interaction between the platform authentication user and the platform accessing application.

2. The implementation method of claim 1, wherein, Before the first authentication of the third-party application intended to be accessed on the enterprise service platform, further comprising setting the interface of the third-party application accessing the platform for the enterprise service platform, wherein: The enterprise service platform sets the authorized opening interface, the authorized login verification interface and the authorized credit interface; When the enterprise service platform sets the third-party application to call the authorized opening interface, the authorized login verification interface and the authorized credit interface, the SM2 national secret algorithm is used to generate a separate key pair to complete the encryption and decryption of the interface request and response message.

3. The implementation method of claim 2, wherein, The interaction between the platform authentication user and the platform accessing application comprises: The platform authentication user applies for opening the service of the platform accessing the application on the enterprise service platform, the enterprise service platform calls the authorized opening interface of the platform accessing the application, and the platform accessing the application completes the opening authorization of the platform authentication user; After the platform accessing the application completes the opening authorization of the platform authentication user, when the platform authentication user starts or jumps to the platform accessing the application through the enterprise service platform, the platform accessing the application calls the pre-set authorized login verification interface in the enterprise service platform to verify the legality of the platform authentication user, and when the platform authentication user is verified to be legal, completes the login state setting, and the platform accessing the application authorizes the platform authentication user to enter the operation page of the platform authentication user in the platform accessing the application through the enterprise service platform for operation. The platform authentication user applies to disable the platform access application in the enterprise service platform, the enterprise service platform calls the pre-set authorization disabling interface of the platform access application, and the platform access application completes the logout operation of the platform authentication user.

4. The method of claim 1, wherein, The method further comprises enabling the platform authentication user to associate multiple third-party application services in the enterprise service platform based on a user ID.

5. The implementation method of claim 1, wherein, The method further comprises configuring the number of platform access applications that can be displayed in the enterprise service platform and the services that can be opened by the platform access applications according to the needs of the enterprise service platform customizer.

6. An implementation system of an enterprise service platform on which a plurality of third-party applications can be mounted, characterized by, The implementation system comprises: A first authentication module performs first authentication on an enterprise that intends to access a third-party application in an enterprise service platform, and manages the content of services opened by the platform access application, including: receiving a first authentication request sent by an enterprise that intends to access a third-party application in an enterprise service platform, wherein the first authentication request comprises enterprise identity information and related information of the third-party application service intended to be accessed; the enterprise service platform analyzes the first authentication request; when the enterprise identity information in the first authentication request is legal, generating an enterprise ID and determining the service content of the third-party application service intended to be accessed according to the related information of the third-party application service intended to be accessed, generating a service code of the third-party application intended to be accessed, and associating the enterprise ID with the service code of the third-party application intended to be accessed, wherein the platform access application is the third-party application of the enterprise intended to be accessed in the enterprise service platform of the enterprise that passes the first authentication; A second authentication module performs second authentication on a platform user who applies for services of a platform access application, and confirms that the platform user is a platform authentication user when the second authentication is passed, including: receiving a second authentication request sent by a platform user who intends to apply for services of a third-party application through a secure control device, wherein the second authentication request comprises a CA digital certificate of the platform user, an enterprise identification number, and a third-party application service intended to be applied for; the enterprise service platform analyzes the second authentication request; when the enterprise identity information confirmed according to the enterprise identification number is consistent with the enterprise identity information in the CA digital certificate, confirming that the platform user who intends to apply for services of a third-party application is a platform authentication user, generating a user ID, and associating the user ID with the third-party application service intended to be applied for; A data interaction module is configured to realize the interaction between the platform authentication user and the platform access application.

7. The system of claim 6, wherein, The system further comprises an interaction interface module configured to set an interface for a third-party application to access the platform for the enterprise service platform, wherein: the enterprise service platform sets an authorization opening interface, an authorization login verification interface, and an authorization credit interface; when the enterprise service platform sets the third-party application to call the authorization opening interface, the authorization login verification interface, and the authorization credit interface, an SM2 national secret algorithm is used to generate a separate key pair to complete the encryption and decryption of the interface request and response message.

8. The implementation system of claim 7, wherein, The data interaction module realizes the interaction between the platform authentication user and the platform access application, including: the platform authentication user applies to open services of the platform access application in the enterprise service platform, the enterprise service platform calls the authorization opening interface of the platform access application, and the platform access application completes the opening authorization of the platform authentication user. After the platform access application completes the opening authorization of the platform authentication user, when the platform authentication user starts or jumps to the platform access application through the enterprise service platform, the platform access application calls the pre-set authorized login verification interface in the enterprise service platform, verifies the legality of the platform authentication user, and when the platform authentication user is verified to be legal, completes the login state setting, and the platform access application authorizes the platform authentication user to enter the operation page of the platform authentication user in the platform access application through the enterprise service platform to operate; When the platform authentication user applies to disable the platform access application in the enterprise service platform, the enterprise service platform calls the pre-set authorized disabling interface of the platform access application, and the platform access application completes the logout operation of the platform authentication user.

9. The system of claim 6, wherein, The system further comprises an account management module for enabling the platform authentication user to associate multiple third-party application services in the enterprise service platform based on a user ID.

10. The implementation system of claim 6, wherein, The system further comprises a customization module for configuring the number of platform access applications that can be displayed in the enterprise service platform and the services that can be opened by the platform access application according to the needs of the customization party of the enterprise service platform.

Citation Information

Patent Citations

  • Management method for unifying users by open platform and management system thereof

    CN105554025A