An authentication method, a computing device and a readable storage medium
By introducing a proxy PAM module and an authentication module into the PAM module, and combining multiple user information authentication methods, the problem that the PAM module cannot support multiple authentication methods at the same time is solved. This achieves flexible support for multiple authentication methods and compatibility with traditional authentication, thus ensuring the security of user login.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-21
- Publication Date
- 2026-03-27
AI Technical Summary
The existing PAM module cannot perform joint verification of multiple authentication methods or perform authentication in a specified order, which makes it unable to meet the login requirements of different application scenarios.
By introducing a proxy PAM module into the PAM module, the authentication module performs user information authentication using multiple authentication methods, including password, gesture, facial information, fingerprint, iris, and voice. Combined with an image acquisition device, user information is acquired and displayed, and authentication is performed in a predetermined order.
It supports multiple authentication methods while ensuring compatibility with traditional login authentication and user login security, enhancing the flexibility and richness of authentication.
Smart Images

Figure CN115033851B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, and in particular, to an authentication method, a computing device and a readable storage medium. BACKGROUND
[0002] Pluggable Authentication Modules (PAM) is a user-level authentication method with high efficiency and flexibility. By providing some dynamic link libraries and a set of unified APIs, the services provided by the system and the authentication method of the services are separated, so that the system administrator can flexibly configure different authentication methods for different services without changing the service program.
[0003] For security considerations, the operating system presents a login interface before entering the desktop after booting, so as to perform user authentication. At present, for different login authentication methods required by different application scenarios, the existing implementation method is to complete login by authentication and authorization through the PAM module, which cannot realize common verification of login by multiple authentication methods, for example, simultaneously starting multiple authentication methods or performing authentication according to the order of specified authentication methods.
[0004] Therefore, an authentication method is needed to solve the problems in the above technical solutions. SUMMARY
[0005] Therefore, the present application provides an authentication method, a computing device and a readable storage medium to solve or at least alleviate the above problems.
[0006] According to one aspect of the present application, an authentication method is provided, which is executed in a computing device including a desktop display manager, a login interface module, an authentication module and a PAM module. The method comprises: after the PAM module receives a first authentication request from the desktop display manager, requesting authorization information from the desktop display manager, so that the desktop display manager requests authorization information from the login interface module for login authentication; the login interface module initiates a second authentication request to the authentication module, so that the authentication module obtains user information from the login interface module and performs authentication based on the obtained user information; if the authentication module succeeds in authentication, the authentication module sends authorization information to the login interface module, so that the login interface module sends the authorization information to the desktop display manager; and the desktop display manager sends the authorization information to the PAM module, so that the PAM module confirms whether the authorization information is valid and returns the confirmation result to the desktop display manager.
[0007] Optionally, in the authentication method according to the present application, the step that the PAM module confirms whether the authorization information is valid comprises: the PAM module confirms whether the authorization information is valid by calling an interface provided by the authentication module.
[0008] Optionally, in the authentication method according to the present application, the step that the authentication module obtains the user information from the login interface module comprises: the authentication module obtains one or more kinds of user information through an image acquisition device of the computing device; and the obtained user information is displayed on the login interface module through an interface provided by the authentication module.
[0009] Optionally, in the authentication method according to the present application, the step of authenticating based on the obtained user information comprises: authenticating the obtained user information in a synchronous or predetermined order.
[0010] Optionally, in the authentication method according to the present application, further comprising: if the authentication module fails to authenticate, the authentication module sends an authentication result indicating the authentication failure to the login interface module, so as to re-execute the step that the login interface module initiates a second authentication request to the authentication module.
[0011] Optionally, in the authentication method according to the present application, the user information comprises at least one of a password, a gesture, facial information, a fingerprint, an iris, and a voice.
[0012] Optionally, in the authentication method according to the present application, the desktop display manager is LightDM.
[0013] Optionally, in the authentication method according to the present application, the login interface module is Greeter.
[0014] Optionally, in the authentication method according to the present application, the step of returning the confirmation result to the desktop display manager comprises: if the confirmation result is that the authorization information is valid, notifying the desktop display manager of a successful confirmation; otherwise, notifying the desktop display manager of a failed confirmation.
[0015] According to an aspect of the present application, there is provided a computing device comprising: at least one processor; a memory storing program instructions configured to be executed by the at least one processor, wherein the program instructions comprise instructions for performing the authentication method as described above.
[0016] According to an aspect of the present application, there is provided a readable storage medium storing program instructions, which, when read and executed by a computing device, cause the computing device to perform the authentication method as described above.
[0017] According to the technical scheme of the present application, an authentication method is provided, and the extension of a PAM module is realized, and the password is authenticated without using the PAM module, and the PAM module is reserved and extended to a proxy PAM module. The authentication of user information is performed by an authentication module, and a more abundant authentication mode can be realized by the authentication module compared with the PAM module. In this way, various authentication modes can be supported, and the compatibility of the traditional login authentication is ensured.
[0018] Further, the authorization information provided by the authentication module after the authentication is completed ensures the security of the authentication, and only when the authorization information obtained by the proxy PAM module is valid, the result of the authentication is obtained from the authentication module, and when the authorization information obtained by the proxy PAM module is invalid, the authentication of the authentication module cannot be passed, and the security of the user login is ensured.
[0019] The above description is only a summary of the technical scheme of the present application, in order to more clearly understand the technical means of the present application, and the present application can be implemented according to the content of the specification, and in order to make the above and other purposes, characteristics and advantages of the present application more obvious, the following specific embodiments of the present application are described. BRIEF DESCRIPTION OF DRAWINGS
[0020] In order to achieve the above and related purposes, certain illustrative aspects will be described herein in connection with the following description and drawings, which indicate various ways in which the principles disclosed herein can be practiced, and all aspects and their equivalents are intended to fall within the scope of the claimed subject matter. The above and other objects, features and advantages of the present disclosure will become more apparent from the following detailed description taken in conjunction with the accompanying drawings. Throughout the disclosure, like reference numerals are generally intended to refer to like parts or elements.
[0021] Figure 1 A schematic diagram of a computing device 100 according to one embodiment of the present application is shown;
[0022] Figure 2 A flowchart of an authentication method 200 according to one embodiment of the present application is shown;
[0023] Figure 3 A schematic diagram of a computing device 300 that performs the authentication method 200 according to one embodiment of the present application is shown;
[0024] Figure 4 A flowchart of an authentication method 400 according to another embodiment of the present application is shown;
[0025] Figure 5 A schematic diagram of a computing device 500 that performs the authentication method 400 according to another embodiment of the present application is shown; and
[0026] Figure 6 A schematic diagram illustrating an authentication method 600 according to another embodiment of the present application is shown. DETAILED DESCRIPTION
[0027] Exemplary embodiments of the present disclosure will be described in detail with reference to the accompanying drawings. Although exemplary embodiments of the present disclosure are shown in the drawings, it is understood that the present disclosure can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided so that the present disclosure can be thoroughly and completely understood, and so that the scope of the present disclosure can be accurately conveyed to those skilled in the art.
[0028] The authentication method of the present application is executed in a computing device. The computing device can be any device with storage and computing capabilities, which can be implemented as a server, a workstation, etc., as a personal computer such as a desktop computer, a notebook computer, etc., or as a terminal device such as a mobile phone, a tablet computer, a smart wearable device, an Internet of Things device, etc., but is not limited thereto.
[0029] Figure 1 A schematic diagram illustrating a computing device 100 according to an embodiment of the present application is shown. It is to be noted that, Figure 1 The computing device 100 shown is only an example, and in practice, the computing device used to implement the authentication method of the present application can be any model, and its hardware configuration can be the same as that of the computing device 100 shown, or can be different from that of the computing device 100 shown. In practice, the computing device used to implement the authentication method of the present application can add or delete hardware components of the computing device 100 shown, and the present application does not limit the specific hardware configuration of the computing device. Figure 1 The computing device 100 shown is only an example, and in practice, the computing device used to implement the authentication method of the present application can be any model, and its hardware configuration can be the same as that of the computing device 100 shown, or can be different from that of the computing device 100 shown. In practice, the computing device used to implement the authentication method of the present application can add or delete hardware components of the computing device 100 shown, and the present application does not limit the specific hardware configuration of the computing device. Figure 1 The computing device 100 shown is only an example, and in practice, the computing device used to implement the authentication method of the present application can be any model, and its hardware configuration can be the same as that of the computing device 100 shown, or can be different from that of the computing device 100 shown. In practice, the computing device used to implement the authentication method of the present application can add or delete hardware components of the computing device 100 shown, and the present application does not limit the specific hardware configuration of the computing device. Figure 1 The computing device 100 shown is only an example, and in practice, the computing device used to implement the authentication method of the present application can be any model, and its hardware configuration can be the same as that of the computing device 100 shown, or can be different from that of the computing device 100 shown. In practice, the computing device used to implement the authentication method of the present application can add or delete hardware components of the computing device 100 shown, and the present application does not limit the specific hardware configuration of the computing device.
[0030] As Figure 1 shown, in the basic configuration 102, the computing device 100 typically includes system memory 106 and one or more processors 104. A memory bus 108 can be used for communicating between the processor 104 and the system memory 106.
[0031] Depending on the desired configuration, the processor 104 can be of any type, including but not limited to a microprocessor (μP), a microcontroller (μC), a digital signal processor (DSP), or any combination thereof. The processor 104 can include one more levels of caching, such as a level one cache 110 and a level two cache 112, a processor core 114, and registers 116. The example processor core 114 can include an arithmetic logic unit (ALU), a floating point unit (FPU), a digital signal processing core (DSP Core), or any combination thereof. The example memory controller 118 can also be used in conjunction with the processor 104, or in some implementations, the memory controller 118 can be an internal part of the processor 104.
[0032] Depending on the desired configuration, the system memory 106 can be of any type including but not limited to volatile memory (such as RAM), non-volatile memory (such as ROM, flash memory, etc.) or any combination thereof. Physical memory storage within a computing device is typically volatile memory (such as RAM), and the data is typically transferred between physical memory storage and non-physical memory storage (such as a disk) for persistence. The system memory 106 can include an operating system 120, one or more applications 122, and program data 124. In some implementations, the applications 122 are arranged to operate with the operating system 120 on the one or more processors 104 to provide program instructions for execution by the computing device. The operating system 120, for example, can be a Linux, Windows, etc., that includes procedures for handling various basic
[0033] When the computing device 100 is in operation, the processor 104 is configured to read instructions from the memory 106 and execute these instructions to perform the operations for the embodiments. The applications 122 are
[0034] The computing device 100 is further comprised of an storage device 132, which can include a removable storage 136 and a non-removable storage 138, both accessible via a storage interface bus 134.
[0035] The computing device 100 can also include an interface bus 140 for facilitating communication from various interface devices (e.g., output devices 142, peripheral interfaces 144, and communication devices 146) to the basic configuration 102 via the bus / interface controller 130. Example output devices 142 include a graphics processing unit 148 and an audio processing unit 150, which can be configured to facilitate communication to various external devices such as a display or speakers via one or more A / V ports 152. Example peripheral interfaces 144 include a serial interface controller 154 or a parallel interface controller 156, which can be configured to facilitate communication to various external devices such as input devices (e.g., keyboard, mouse, pen, voice input device, touch input device) or other peripheral devices (e.g., printer, scanner, etc.) via one or more I / O ports 158. An example
[0036] Network communication links can be one example of a communication media. Communication media can typically be embodied by computer readable instructions, data structures, program modules, etc., in a modulated data signal, such as a carrier wave or other transport mechanism, and can include any information delivery media. A "modulated data signal" can be a signal that has one or more of its characteristics set or changed in such a manner as to encode information in the signal. By way of example, and not limitation, communication media can include wired media such as a wired network or direct-wired connection, and wireless media such as acoustic, radio frequency (RF), microwave, infrared (IR) and other wireless media. The term computer readable media as used herein can include both storage media and communication media.
[0037] In the computing device 100 according to the present application, the operating system 120 includes instructions for performing the authentication method of the present application, which can instruct the processor 104 to perform the authentication method 200, 400 or 600 of the present application. It should be noted that the operating system to which the method of the present application is directed can be any operating system, for example: Linux, Windows, and the authentication method of the present application is not limited to the specific type of operating system.
[0038] Figure 2 A flowchart of the authentication method 200 according to one embodiment of the present application is shown. The method 200 is suitable for execution in a computing device (e.g., the aforementioned computing device 100), which includes a desktop display manager, a login interface module, and a PAM module.
[0039] The desktop display manager can be implemented as a Light Display Manager (LightDM for short), which is a lightweight desktop display manager supporting multiple desktops, multiple display technologies, low memory occupation and high performance, remote login and the like. The LightDM can be used to start a graphical user interface.
[0040] The login interface module can be implemented as a graphical user interface (GUI for short) for user login.
[0041] As shown in FIG. 2, the method 200 starts from step S210. Figure 2
[0042] In step S210, when a user needs to log in, a login authentication request is initiated by the desktop display manager.
[0043] Specifically, the desktop display manager invokes the PAM module and sends the login authentication request to the PAM module. Through the configuration file of the PAM module, a specified PAM module is determined to complete the authentication and authorization.
[0044] The PAM module has a modular feature, and a set of standard interfaces are defined to agree on a common interaction mode. The application executing the method 200 does not need to be updated, and only needs to replace the PAM module therein with other authentication modules, so that other authentication modes can be supported.
[0045] Subsequently, in step S220, the PAM module requests user permission data from the desktop display manager through a callback, wherein the user permission data may be, for example, a user password.
[0046] Subsequently, in step S230, the desktop display manager requests a user password from the login interface module through a callback after receiving the request. The login interface module prompts the user to input the user password.
[0047] Subsequently, in step S240, after the user inputs the user password in the login interface module, the login interface module returns the user password to the desktop display manager.
[0048] Subsequently, in step S250, the desktop display manager sends the user password to the PAM module, so that the PAM module authenticates the obtained password.
[0049] Subsequently, in step S260, the PAM module authenticates the received user password.
[0050] Subsequently, in step S270, the PAM module returns the authentication result to the desktop display manager, so as to notify the desktop display manager whether the login is successful.
[0051] Subsequently, in step S280, if the authentication result received by the desktop display manager is authentication success, the login is successful, and the subsequent login process is executed. If the authentication result is authentication failure, the login is failed.
[0052] Figure 3 A schematic diagram of a computing device 300 adapted to execute the authentication method 200 according to an embodiment of the present application is shown. As shown, the computing device 300 comprises a desktop display manager 310, a login interface module 320 and a PAM module 330. Figure 3
[0053] The desktop display manager 310 is adapted to initiate a login authentication request to the PAM module when a user login is required. It is also adapted to request a user password from the login interface module by callback after receiving the request. It is also adapted to send the user password to the PAM module. It is also adapted to execute the subsequent login process if the authentication result received is authentication success. If the authentication result is authentication failure, the login is failed.
[0054] The login interface module 320 is adapted to prompt a user to input a user password. It is also adapted to return the user password to the desktop display manager.
[0055] The PAM module 330 is adapted to request a user password from the desktop display manager by callback. It is also adapted to authenticate the user password sent from the desktop display manager. It is also adapted to return the authentication result to the desktop display manager so as to inform the desktop display manager whether the login is successful.
[0056] According to the aforementioned authentication method, the desktop display manager authenticates the user password through the PAM module to implement the login of the user. However, the modular design of the PAM limits its interface to be fixed. The fixed interface design of the PAM module makes it difficult for the PAM module to support authentication methods requiring complex interfaces.
[0057] In order to implement an authentication method supporting multiple authentication methods, the present application further proposes an authentication method without modifying the mechanism of the desktop display manager and the PAM module, ensuring the compatibility of the traditional login authentication, without relying on the authentication service of the PAM module, implementing the PAM module as a proxy PAM module for forwarding the authentication request received from the desktop display manager, receiving the authorization information from the desktop display manager, forwarding the authorization information to the authentication module, and forwarding the confirmation result received from the authentication module to the desktop display manager. The specific authentication method is implemented by the authentication module, which can not only meet the compatibility of the traditional login authentication, but also support a variety of authentication methods.
[0058] Figure 4 A flowchart of an authentication method 400 according to another embodiment of the present application is shown. The method 400 is suitable for execution in a computing device (e.g., the aforementioned computing device 100) that includes a desktop display manager, a login interface module, an authentication module, and a PAM module.
[0059] The desktop display manager can be implemented as Light Display Manager (LightDM), which is a lightweight desktop display manager with support for multiple desktops, support for multiple display technologies, low memory footprint and high performance, support for remote login, and the like. LightDM can be used to start a graphical user interface. Of course, the authentication method of the present application can also be implemented by other desktop display managers other than LightDM.
[0060] The login interface module can be implemented as a graphical user interface (GUI) for user login. For example, the login interface module can employ Greeter, which is a GUI that can prompt a user to enter credentials. For example, lightdm-gtk-greeter or lightdm-deepin-greeter can be employed, but the present application is not limited thereto. Of course, the authentication method of the present application can also be implemented by other GUIs other than Greeter.
[0061] As shown in FIG. 4, the method 400 begins at step S410. Figure 4
[0062] In step S410, after the PAM module receives the first authentication request from the desktop display manager, the desktop display manager requests authorization information from the PAM module so that the desktop display manager requests authorization information from the login interface module for login authentication.
[0063] Specifically, when a user needs to log in, for example, when starting an operating system login user account, the login interface module initiates authentication and notifies the desktop display manager to start authentication. Then, the desktop display manager sends a first authentication request to the PAM module to call the PAM module to start authentication.
[0064] According to an embodiment of the present application, the PAM module acts as a proxy in the authentication method 400 of the present application, and the authentication of the authorization information is not directly performed by the PAM module. Specifically, the PAM module can be specified as a proxy PAM module by a configuration file of the PAM module. The configuration file of the PAM module can be a plurality of files in the / etc / pam.d / folder, and by configuring in the / etc / pam.d / lightdm file, the PAM module that should originally complete the authentication authorization can be specified as a proxy PAM module. For example, the general PAM module configuration originally specified as:
[0065] auth required pam_unix.so,
[0066] The general PAM module is now changed to the proxy PAM module pam_proxy, and is configured as:
[0067] auth required pam_proxy.so
[0068] Subsequently, after the PAM module (proxy PAM module in the method 400) receives the first authentication request from the desktop display manager, the authorization information is required in the authentication process to complete the authentication, and the PAM module calls back the desktop display manager to request the authorization information. The authorization information is a credential used for identity authentication, for example, a password. Subsequently, the desktop display manager requests the authorization information from the login interface module.
[0069] Subsequently, in step S420, the login interface module initiates a second authentication request to the authentication module, so that the authentication module obtains the user information from the login interface module and performs authentication based on the obtained user information.
[0070] Specifically, after the login interface module receives the request for the authorization information from the desktop display manager, unlike the aforementioned method 200, the login interface module does not directly return the password to the desktop display manager, but initiates another authentication request, i.e., a second authentication request, to the authentication module. The authentication module generates a unique AuthID, i.e., authentication ID, for each authentication request received, so that when the authentication is successful, the AuthID is sent to the login interface module by the authentication module as the authorization information.
[0071] Optionally, the authentication module provides a Dbus-based API, and the login interface module completes the authentication-related interaction by calling the API provided by the authentication module. Subsequently, the authentication module starts to perform the authentication process after receiving the second authentication request from the login interface module. Optionally, the authentication module acquires one or more kinds of user information through an image acquisition device of the computing device, such as a camera, a peripheral camera, or the like. The user information includes at least one of a password, a gesture, facial information, a fingerprint, an iris, and a voice. The acquired user information is synchronously displayed on the login interface module through an interface provided by the authentication module for video forwarding. The authentication module can achieve the authentication of the user information through video interaction, such as face recognition and gesture recognition. Taking face recognition as an example, the authentication module can extract facial features from a video including facial information acquired through a camera, and perform recognition through machine learning to confirm whether the user information in the video is valid. Optionally, the authentication module can also be implemented to acquire user information such as a password, a gesture, and a fingerprint by acquiring information of a keyboard, a mouse, and a touchpad of the computing device. Optionally, the authentication module can also be implemented to acquire user information such as a voice by acquiring microphone information of the computing device. Optionally, the authentication module can also be implemented to acquire user information by acquiring an external device of the computing device. The authentication module can be implemented as any one or more of existing authentication modes.
[0072] In addition, the acquired user information can also be authenticated in a synchronous manner or in a predetermined order. For example, the acquired facial information and iris information are synchronously authenticated. The predetermined order can also be set in the authentication module, for example, the facial information authentication is set as the first, the fingerprint information authentication is set as the second, and the password information authentication is set as the third, but is not limited thereto. Here, the authentication mode can be one or more, and the predetermined order can be set as any order. The predetermined order can be set by a person skilled in the art as needed, and the present application does not specifically limit the specific selection of the authentication mode and the predetermined order of the authentication.
[0073] Subsequently, in step S430, if the authentication module is authenticated successfully, the authentication module sends the authorization information to the login interface module, so that the login interface module sends the authorization information to the desktop display manager.
[0074] Optionally, if the authentication module is authenticated successfully, the authentication module only returns the authorization information to the login interface module, where the authorization information is AuthID. Then, the login interface module authorizes the desktop display manager for this authentication, and notifies the authentication module that the authentication corresponding to the AuthID can be used by the desktop display manager, so that the AuthID can be regarded as the authorization information of the authentication.
[0075] Optionally, if the authentication module is authenticated successfully, the authentication module returns the authentication result and the authorization information to the login interface module. The authentication result is information indicating that the authentication is successful, and the authorization information is an AuthID. Then, the login interface module authorizes the desktop display manager for this authentication, and notifies the authentication module that the AuthID corresponding to this authentication can be used by the desktop display manager. Therefore, the AuthID can be regarded as the authorization information of this authentication.
[0076] Subsequently, in step S440, the desktop display manager sends the authorization information to the PAM module, so that the PAM module confirms whether the authorization information is valid, and returns the confirmation result to the desktop display manager.
[0077] Specifically, after obtaining the authorization information sent by the login interface module, the desktop display manager sends the authorization information to the proxy PAM module according to the mechanism of the PAM module. After obtaining the authorization information, the proxy PAM module confirms whether the authorization information is valid by calling an interface of the authentication module for confirming the authorization information according to the authorization information, that is, confirms whether the desktop display manager has the authorization. If the confirmation result indicates that the authorization information is valid, the proxy PAM module notifies the desktop display manager that the confirmation is successful, and the login is successful. If the confirmation result indicates that the authorization information is invalid, the proxy PAM module notifies the desktop display manager that the confirmation fails, and the login fails.
[0078] After step S420, step S450 can also be included.
[0079] In step S450, if the authentication module fails to authenticate, the authentication module sends an authentication result indicating that the authentication fails to the login interface module, so that the login interface module reinitiates a second authentication request to the authentication module, that is, returns to the step of initiating the second authentication request to the authentication module by the login interface module described in the foregoing step S420, until the authentication module is authenticated successfully.
[0080] According to the authentication method 400 of the present application, the desktop display manager always maintains the process of using the PAM mechanism to authenticate to complete the login. The authentication method 400 is executed in the same way as the authentication method 200, and the steps required to be executed by the desktop display manager are not different. The authentication method 400 of the present application does not replace the original PAM module, but retains the PAM module and extends the function thereof. Instead of using the PAM module to authenticate the password, the PAM is extended to a proxy PAM module, and the authentication module is used to perform user information authentication, so as to support more rich authentication modes that cannot be supported by the PAM module. In this way, not only various authentication modes can be supported, but also the compatibility with the traditional login authentication is ensured.
[0081] Further, the authorization information provided by the authentication module after authentication ensures the security of the authentication, and only when the authorization information obtained by the proxy PAM module is valid, the result of passing the authentication can be obtained from the authentication module, and when the authorization information obtained by the proxy PAM module is invalid, the authentication of the authentication module cannot be passed, thereby ensuring the security of user login.
[0082] Figure 5 A schematic diagram of a computing device 500 adapted to perform the authentication method 400 of the present application according to another embodiment of the present application is shown. As shown, the system 500 comprises a desktop display manager 510, a login interface module 520, an authentication module 530, and a PAM module 540. Figure 5
[0083] According to an embodiment of the present application, the computing device 500 is adapted to perform the authentication method 400 of the present application, and the above description of the authentication method 400 can be referred to.
[0084] The desktop display manager 510 is adapted to request the authorization information from the login interface module for login authentication, and is also adapted to send the authorization information to the PAM module, so that the PAM module confirms whether the authorization information is valid, and returns the confirmation result to the desktop display manager.
[0085] The login interface module 520 is adapted to initiate a second authentication request to the authentication module, so that the authentication module obtains the user information from the login interface module, and performs authentication based on the obtained user information. It is also adapted to send the authorization information to the desktop display manager.
[0086] The authentication module 530 is adapted to obtain the user information from the login interface module, and perform authentication based on the obtained user information. It is also adapted to send the authorization information to the login interface module when the authentication is successful, so that the login interface module sends the authorization information to the desktop display manager.
[0087] The PAM module 540 is adapted to request the authorization information from the desktop display manager after receiving the first authentication request from the desktop display manager, so that the desktop display manager requests the authorization information from the login interface module for login authentication. It is also adapted to confirm whether the authorization information is valid, and returns the confirmation result to the desktop display manager.
[0088] In order to better illustrate the complete implementation process of the present application, the authentication method 400 of the present application is described in detail below. Figure 6 A schematic diagram of an authentication method 600 according to another embodiment of the present application is shown.
[0089] Method 600 is adapted to be executed in a computing device (such as the aforementioned computing device 100), the computing device including a desktop display manager, a login interface module, an authentication module, and a PAM module.
[0090] The desktop display manager can be implemented as Light Display Manager (LightDM). LightDM is a lightweight desktop display manager that supports multiple desktops, multiple display technologies, low memory usage, high performance, and remote login. LightDM can be used to launch graphical user interfaces.
[0091] The login interface module can be implemented as a graphical user interface (GUI) for user login. For example, the login interface module can use Greeter.
[0092] like Figure 6 As shown, method 600 begins with step S601.
[0093] In step S601, when a user needs to log in, the login interface module initiates an authentication and notifies the desktop display manager to start the authentication process.
[0094] Subsequently, in step S602, the desktop display manager initiates the first authentication request.
[0095] Specifically, the desktop display manager invokes the PAM module to send a login authentication request. The PAM module's configuration file is used to identify it as a proxy PAM module.
[0096] Subsequently, in step S603, the proxy PAM module is invoked to begin authentication. During the authentication process, authorization information is required to complete the authentication, and then the authorization information is requested through a callback to the desktop display manager. For details of steps S601-S603, please refer to the description in step S410 above.
[0097] Subsequently, in step S604, after receiving the request, the desktop display manager requests authorization information from the login interface module via a callback.
[0098] Subsequently, in step S605, the login interface module sends another second authentication request to the authentication module.
[0099] Subsequently, in step S606, after receiving the second authentication request from the login interface module, the authentication module begins the authentication process, which includes some interactions and authorization between the authentication module and the login interface module. The specific content of steps S604-S606 can be found in the description of step S420 above.
[0100] Subsequently, in step S607, if the authentication module authenticates successfully, the authentication result indicating the authentication success and the authorization information corresponding to this authentication are returned to the login interface module.
[0101] If the authentication module fails to authenticate, the authentication result indicating the authentication failure is sent to the login interface module so as to return to step S605 again to initiate a second authentication request to the authentication module.
[0102] Subsequently, in step S608, the login interface module sends the authorization information to the desktop display manager. The specific content of steps S607 and S608 can refer to the description in steps S430 and S450.
[0103] Subsequently, in step S609, the desktop display manager sends the obtained authorization information to the proxy PAM module according to the mechanism of the PAM.
[0104] Subsequently, in step S610, the proxy PAM module calls the interface of the authentication module according to the authorization information to confirm whether the authorization information is valid after receiving the authorization information.
[0105] Subsequently, in step S611, the authentication module returns the confirmation result to the proxy PAM module after confirming whether the authorization information is valid.
[0106] Subsequently, in step S612, the proxy PAM module returns the confirmation result to the desktop display manager. If the confirmation result is that the authorization information is valid, the desktop display manager is notified of the success of the confirmation. Otherwise, the desktop display manager is notified of the failure of the confirmation. The specific content of steps S609 and S612 can refer to the description in step S440.
[0107] According to the technical scheme of the present application, an authentication method is provided, which realizes the extension of a PAM module, does not use the PAM module to authenticate passwords, retains the PAM module and extends the PAM to a proxy PAM module. The authentication of user information is performed by the authentication module, and through the authentication module, more abundant authentication modes can be realized compared with the PAM module. In this way, not only various authentication modes can be supported, but also the compatibility with traditional login authentication is ensured.
[0108] Further, the authorization information provided by the authentication module after the authentication is completed ensures the security of this authentication. Only when the authorization information obtained by the proxy PAM module is valid, the result of the confirmation through the authentication module can be obtained from the authentication module. When the authorization information obtained by the proxy PAM module is invalid, the authentication through the authentication module cannot be passed, thereby ensuring the security of user login.
[0109] The various techniques described herein can be implemented in connection with hardware or software or, where appropriate, with a combination of both. Thus, the methods and apparatus of the present application, or certain aspects or portions thereof, can take the form of program code (i.e., instructions) embodied in tangible media, such as removable hard disks, USB flash drives, optical tapes, CD-ROMs, or any other machine-readable storage medium, wherein, when the program code is loaded into and executed by a machine, such as a computer, the machine becomes an apparatus for practicing the subject application.
[0110] Where a program code is executed on a programmable computer, the mobile terminal generally includes a processor, a processor-readable storage medium (including volatile and non-volatile memory and / or storage elements), at least one input device, and at least one output device. The memory is configured to store program code; the processor is configured to execute instructions in the program code stored in the memory to perform the authentication method of the present application.
[0111] In the description provided herein, numerous specific details are set forth. However, it is understood that embodiments of the application can be practiced without these specific details. In some instances, well-known methods, structures and techniques have not been described in detail in order not to obscure the understanding of this description.
[0112] In the description provided herein, numerous specific details are set forth. However, it is understood that embodiments of the application can be practiced without these specific details. In some instances, well-known methods, structures and techniques have not been described in detail in order not to obscure the understanding of this description.
[0113] In the description provided herein, numerous specific details are set forth. However, it is understood that embodiments of the application can be practiced without these specific details. In some instances, well-known methods, structures and techniques have not been described in detail in order not to obscure the understanding of this description.
[0114] Similarly, it is to be understood that the embodiments of the present application can be placed into practice notwithstanding modifications to form yet further embodiments of the present application. As such, the terms and expressions of the foregoing description are used as terms of description and not of limitation, and there is no intention, in the use of such terms and expressions, of excluding any equivalents of the features shown and described or portions thereof. It is recognized that various modifications are possible within the scope of the application, and the inventive scope is to be interpreted by the appended claims and their equivalents in which:
[0115] Those skilled in the art will understand that the modules, or units, or components of the devices in the examples disclosed herein can be arranged in a device as described in the examples, or alternatively can be located in one or more devices different from the devices in the examples. The modules in the foregoing examples can be combined into one module or further divided into multiple sub-modules.
[0116] Those skilled in the art will understand that the modules in the devices in the examples can be adaptively changed and disposed in one or more devices different from the examples. The modules or units or components in the examples can be combined into one module or unit or component, and further divided into multiple sub-modules or sub-units or sub-components. Except that at least some of such features and / or processes or units are mutually exclusive, any combination of all the features disclosed in the specification (including the accompanying claims, abstract and drawings), and all the processes or units of any method or device disclosed thus can be adopted. Unless explicitly stated otherwise, each feature disclosed in the specification (including the accompanying claims, abstract and drawings) can be replaced by an alternative feature providing the same, equivalent or similar purpose.
[0117] Further, those skilled in the art will understand that the combination of features of different embodiments means within the scope of the present application and forms different embodiments, although some of the examples described herein include certain features rather than others included in other examples. For example, in the following claims, any one of the claimed embodiments can be used in any combination.
[0118] Furthermore, some of the embodiments described herein are of a "method" or a "process" that can be embodied in software, firmware or hardware, and when embodied in software, can be implemented with computer- executable instructions. The rules of equivalence, as well as the "means-plus-function" or "step-plus-function" clauses below, are meant to cover both "articles of manufacture" and "combinations of articles of manufacture" that consist of one or more computers or one or more processors running software programs.
[0119] As used herein, unless otherwise indicated, the use of the ordinal adjectives "first", "second", "third", etc., are to add specificity and difference to a term, and are not intended to indicate a temporal or physical sequence or ordering. Nor, unless specifically stated, is the use of "about" to limit the value full or exact.
[0120] While the application has been described in terms of several embodiments, those skilled in the art will recognize that the application can be practiced with modifications and alterations limited only by the spirit and scope of the inventiveness. Furthermore, the purpose of the description is to enable any person skilled in the art to practice the application as described in the specification and claimed claims. The constructions and arrangements disclosed herein are all exemplary in nature, or are intended to provide specific examples of various embodiments of the application. It is therefore contemplated to be within the scope of the application to set forth and / or claim more general and / or modified structures. Other embodiments and modifications within the spirit and scope of the application will occur to those skilled in the art upon reading of the description of application. The descriptions and examples are intended to provide an overview and context for understanding the application. Accordingly, the application as set forth is not intended to be limited to the specific form set forth. Rather, it is intended to cover all modifications, equivalents and alternatives falling within the scope of the application. The scope of the application is limited only by the following claims.
Claims
1. An authentication method executed in a computing device, the computing device including a desktop display manager, a login interface module, an authentication module, and a PAM module, the method comprising: After the PAM module receives the first authentication request from the desktop display manager, it requests authorization information from the desktop display manager so that the desktop display manager can request authorization information from the login interface module for login authentication. The PAM module is then set to act as a proxy for the PAM module. The login interface module sends a second authentication request to the authentication module so that the authentication module can obtain various user information from the login interface module and perform various authentications based on the obtained user information. If the authentication module successfully completes multiple authentications, it sends the authorization information to the login interface module, which then sends the authorization information to the desktop display manager. The desktop display manager sends the authorization information to the PAM module so that the PAM module can confirm whether the authorization information is valid, and if the authorization information is valid, the confirmation result is returned to the desktop display manager.
2. The method according to claim 1, wherein, The step of the PAM module to confirm whether the authorization information is valid includes: The PAM module verifies the validity of the authorization information by calling the interface provided by the authentication module.
3. The method according to claim 1 or 2, wherein, The steps for the authentication module to obtain user information from the login interface module include: The authentication module obtains various user information through the image acquisition device of the computing device; The obtained user information is displayed in the login interface module through the interface provided by the authentication module.
4. The method according to claim 1 or 2, wherein, The authentication step based on the obtained user information includes: The acquired user information is authenticated synchronously or in a predetermined order.
5. The method according to claim 1 or 2, further comprising: If the authentication module fails to authenticate, it will send the authentication result indicating the failure to the login interface module so that the login interface module can re-execute the step of initiating a second authentication request to the authentication module.
6. The method according to claim 1 or 2, wherein, The user information includes at least one of the following: password, gesture, facial information, fingerprint, iris, and voice.
7. The method according to claim 1 or 2, wherein, The desktop display manager is LightDM.
8. The method according to claim 1 or 2, wherein, The login interface module is Greeter.
9. The method according to claim 1 or 2, wherein, The step of returning the confirmation result to the desktop display manager includes: If the confirmation result indicates that the authorization information is valid, then notify the desktop display manager to confirm success; Otherwise, notify the desktop display manager that confirmation failed.
10. A computing device, comprising: At least one processor; as well as A memory storing program instructions, wherein the program instructions are configured to be executed by the at least one processor, the program instructions including instructions for performing the method as described in any one of claims 1 to 9.
11. A readable storage medium storing program instructions that, when read and executed by a computing device, cause the computing device to perform the method as described in any one of claims 1 to 9.
Citation Information
Patent Citations
A system authentication method and device based on biological recognition under Linux
CN109784022A