Application Authorization Method, Device, Equipment, Storage Medium and Computer Program Product
By obtaining the authorization token of the second application and requesting the authorization result from the authorization server, the problem of inefficient application authorization in the prior art is solved, and efficient authorization is achieved with simplified operation and safe.
Patent Information
- Application Number
- CN202211040284.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-29
- Publication Date
- 2025-08-05
- Estimated Expiration
- 2042-08-29
AI Technical Summary
In the prior art, application authorization is inefficient, and users need to perform authorization operations multiple times to authorize the account information of the target application to different multiple applications.
By obtaining the authorization token obtained by the second application in advance, a second authorization request including the first application identification and the authorization token is generated, and the request is sent to the authorization server of the target application to identify the relationship between the first application and the second application and return the authorization result, avoiding the user's repeated authorization operations.
Simplifies application authorization operations, improves authorization efficiency, and ensures authorization security, avoiding the spread of authorization tokens between applications.
Smart Images

Figure CN115396217B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular to an application authorization method, device, electronic device, storage medium, and computer program product. Background Art
[0002] With the development of internet technology, users often have accounts on multiple online platforms, such as accounts for audio and video applications, social applications, and payment applications. To meet users' specific needs, an online platform can provide relevant account information to other platforms after obtaining user authorization.
[0003] In related technologies, if the account information of a target application is to be authorized to multiple different applications separately, the user needs to authorize them separately after triggering the corresponding applications. For example, if the account information of target application A is to be authorized to application B and application C, the user often needs to execute the corresponding trigger operation in application B, then authorize the account information of target application A to application B, and then execute the corresponding trigger operation in application C before the account information of target application A can be authorized to application B.
[0004] However, when there are multiple applications to be authorized, the above method requires the user to perform multiple authorization operations, which leads to low efficiency of application authorization. Summary of the Invention
[0005] The present disclosure provides an application authorization method, apparatus, electronic device, storage medium, and computer program product to at least address the problem of low application authorization efficiency in related technologies. The technical solutions of the present disclosure are as follows:
[0006] According to a first aspect of an embodiment of the present disclosure, there is provided an application authorization method, including:
[0007] In response to a first authorization request from the first application for account information of a target account in a target application, obtaining an authorization token previously obtained by the second application; the authorization token is obtained by the second application after obtaining authorization from the target application for account information of the target account;
[0008] Generate a second authorization request including the first application identifier of the first application and the authorization token, and send the second authorization request to the authorization server of the target application;
[0009] Among them, the second authorization request is used to trigger the authorization server to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier of the second application in the authorization token, and the pre-acquired application relationship information, and return the authorization result to the first application according to the relationship identification result.
[0010] In one embodiment, the step of obtaining the authorization token pre-acquired by the second application in response to the first authorization request by the first application for the account information of the target account in the target application includes:
[0011] In response to a first authorization request by a first application for account information of a target account in a target application, determining a second application that is associated with the first application and runs independently;
[0012] If the second application has obtained authorization from the target account, obtain the authorization token of the second application.
[0013] In one embodiment, in response to a first authorization request by a first application for account information of a target account in a target application, determining a second application that is associated with the first application and runs independently includes:
[0014] Displaying an application entry for the first application through an application page of the second application; the first application and the second application are independently running applications;
[0015] When a trigger operation for the application entry is detected and a first login request is obtained, a first authorization request is obtained by the first application for the account information of the target account in the target application, and it is determined that the second application displaying the application entry is associated with the first application; wherein, the first login request indicates logging into the first application based on the target account.
[0016] In one embodiment, the step of obtaining the authorization token pre-acquired by the second application in response to the first authorization request by the first application for the account information of the target account in the target application includes:
[0017] In response to a first authorization request by the first application for account information of a target account in a target application, determining a second application that provides an operating environment for the first application; the second application provides an operating environment for a plurality of sub-applications including the first application;
[0018] If the second application has obtained authorization from the target account, obtain the authorization token of the second application.
[0019] In one embodiment, before obtaining the authorization token pre-acquired by the second application in response to the first authorization request of the first application for the account information of the target account in the target application, the method further includes:
[0020] Associating the first application identifier of the first application with the second application identifier of the second application to generate application relationship information, and sending the application relationship information to the authorization server of the target application;
[0021] The application relationship information is used to instruct the authorization server to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier in the application relationship information, the first application identifier carried in the first authorization request, and the second application identifier in the authorization token when the authorization server receives the second authorization request.
[0022] In one embodiment, before obtaining the authorization token pre-acquired by the second application in response to the first authorization request of the first application for the account information of the target account in the target application, the method further includes:
[0023] Obtaining a second application, and displaying an authorization prompt for account information of a target account of the target application in response to a second login request from the second application to the target application, wherein the second login request indicates logging into the second application based on the target account;
[0024] If confirmation information of the target account for the authorization prompt is received, an authorization token is obtained from the authorization server of the target application.
[0025] According to a second aspect of an embodiment of the present disclosure, there is provided an application authorization method, including:
[0026] Receiving an authorization request from a first application for account information of a target account in a target application, and obtaining a first application identifier of the first application and an authorization token of a second application carried in the authorization request; the authorization token is obtained by the second application after obtaining authorization from the target application for the account information of the target account;
[0027] Obtain the second application identifier of the second application in the authorization token, identify the relationship between the first application and the second application based on the first application identifier, the second application identifier and the pre-acquired application relationship information, and return the authorization result to the first application according to the relationship identification result.
[0028] In one embodiment, returning the authorization result to the first application according to the relationship identification result includes:
[0029] If it is determined that the first application is associated with the second application, allocating association authorization for the second application to the first application;
[0030] Upon receiving the request from the first application for obtaining the account information of the target account, an authorization result is returned to the first application according to the authorization attribute information of the associated authorization.
[0031] In one embodiment, the authorization attribute information includes a validity period of an authorization token of the second application, and upon receiving a request from the first application to obtain account information of the target account, returning an authorization result to the first application according to the authorization attribute information of the associated authorization, includes:
[0032] Upon receiving a request from the first application for obtaining the account information of the target account, obtaining the validity period of the authorization token of the second application from the authorization attribute information;
[0033] If the request time of the acquisition request does not exceed the validity period, the account information of the target account is returned to the first application as an authorization result.
[0034] In one embodiment, the application relationship information stores associated application identifiers, and identifying the relationship between the first application and the second application based on the first application identifier, the second application identifier, and the pre-acquired application relationship information includes:
[0035] If it is determined based on the pre-acquired application relationship information that the first application identifier is associated with the second application identifier, then it is determined that the first application is associated with the second application.
[0036] According to a third aspect of an embodiment of the present disclosure, there is provided an application authorization device, including:
[0037] an authorization token acquisition unit configured to execute, in response to a first authorization request from a first application for account information of a target account in a target application, an authorization token pre-acquired by a second application; the authorization token being acquired by the second application after obtaining authorization from the target application for the account information of the target account;
[0038] an authorization request sending unit, configured to generate a second authorization request including the first application identifier of the first application and the authorization token, and send the second authorization request to the authorization server of the target application;
[0039] Among them, the second authorization request is used to trigger the authorization server to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier of the second application in the authorization token, and the pre-acquired application relationship information, and return the authorization result to the first application according to the relationship identification result.
[0040] According to a fourth aspect of an embodiment of the present disclosure, there is provided an application authorization device, including:
[0041] an authorization request receiving unit configured to receive an authorization request from a first application for account information of a target account in a target application, and obtain a first application identifier of the first application and an authorization token of a second application carried in the authorization request; the authorization token is obtained by the second application after obtaining authorization from the target application for the account information of the target account;
[0042] The authorization result determination unit is configured to obtain the second application identifier of the second application in the authorization token, identify the relationship between the first application and the second application based on the first application identifier, the second application identifier and the pre-acquired application relationship information, and return the authorization result to the first application according to the relationship identification result.
[0043] According to a fifth aspect of the embodiments of the present disclosure, there is provided an electronic device, including:
[0044] processor;
[0045] a memory for storing instructions executable by the processor;
[0046] The processor is configured to execute the instructions to implement any of the above-mentioned application authorization methods.
[0047] According to a sixth aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided. When instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the application authorization method as described in any one of the above items.
[0048] According to a seventh aspect of an embodiment of the present disclosure, a computer program product is provided, wherein the computer program product includes instructions, and when the instructions are executed by a processor of an electronic device, the electronic device is able to execute the application authorization method as described in any one of the above items.
[0049] The technical solutions provided by the embodiments of the present disclosure bring at least the following beneficial effects:
[0050] In response to a first authorization request from a first application for account information of a target account in a target application, an authorization token pre-obtained by a second application is obtained; the authorization token is obtained by the second application after obtaining authorization from the target application for the account information of the target account; a second authorization request including a first application identifier of the first application and the authorization token is generated and sent to the authorization server of the target application; the second authorization request can trigger the authorization server to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier of the second application in the authorization token, and the pre-obtained application relationship information, and return an authorization result to the first application based on the relationship identification result. In the solution disclosed herein, the first application can request authorization for the target account information from the authorization server using the authorization token pre-obtained by the second application after authorization by the target account, and obtain an authorization result from the authorization server, without the user having to trigger the relevant operation of the authorization request for the first application again. The authorization server can also return the corresponding authorization result based on the relationship between the first application and the second application, avoiding the arbitrary propagation of the authorization token between applications, simplifying the application authorization operation while ensuring the security of the authorization, thereby effectively improving the authorization efficiency.
[0051] It is to be understood that the foregoing general description and the following detailed description are exemplary and explanatory only and are not restrictive of the disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] The accompanying drawings herein are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the present disclosure, and together with the description are used to explain the principles of the present disclosure, and do not constitute an improper limitation of the present disclosure.
[0053] Figure 1 The figure is an application environment diagram showing an application authorization method according to an exemplary embodiment.
[0054] Figure 2 The figure is a flowchart showing an application authorization method according to an exemplary embodiment.
[0055] Figure 3 The figure is a schematic diagram showing a step of obtaining an authorization token according to an exemplary embodiment.
[0056] Figure 4 The figure is a schematic diagram showing another step of obtaining an authorization token according to an exemplary embodiment.
[0057] Figure 5 The figure is a flowchart showing another application authorization method according to an exemplary embodiment.
[0058] Figure 6 The figure is a timing diagram showing an application authorization method according to an exemplary embodiment.
[0059] Figure 7 The figure is a block diagram showing an application authorization device according to an exemplary embodiment.
[0060] Figure 8 The figure is a block diagram showing another application authorization device according to an exemplary embodiment.
[0061] Figure 9 It is a block diagram of an electronic device according to an exemplary embodiment.
[0062] Figure 10 is a block diagram of another electronic device according to an exemplary embodiment. DETAILED DESCRIPTION
[0063] In order to enable ordinary persons in the art to better understand the technical solutions of the present disclosure, the technical solutions in the embodiments of the present disclosure will be clearly and completely described below with reference to the accompanying drawings.
[0064] It should be noted that the terms "first," "second," and the like in the specification and claims of the present disclosure and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. It should be understood that the numbers used in this manner are interchangeable where appropriate so that the embodiments of the present disclosure described herein can be implemented in an order other than those illustrated or described herein. The embodiments described in the following exemplary embodiments do not represent all embodiments consistent with the present disclosure. Instead, they are merely examples of apparatus and methods consistent with certain aspects of the present disclosure as detailed in the appended claims.
[0065] It should also be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data for analysis, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties.
[0066] The application authorization method provided by this disclosure can be applied to Figure 1 The illustrated application environment may include a terminal and an authorization server. The terminal may communicate with the authorization server via a network. The authorization server may provide data authorization services, such as data authorization for a specified target application. Upon obtaining authorization, other applications besides the target application may access data related to the target application. The authorization server may have a corresponding data storage system that can store data that the authorization server needs to process, such as data related to the target application. In practical applications, the data storage system may be integrated with the authorization server or placed in the cloud or on other network servers.
[0067] In an application authorization method disclosed herein, in response to a first authorization request from a first application for account information of a target account in a target application, a terminal can obtain an authorization token pre-obtained by a second application, and the authorization token can be obtained by the second application after obtaining authorization from the target application for the account information of the target account; then, the terminal can generate a second authorization request including a first application identifier and an authorization token of the first application, and send the second authorization request to the authorization server of the target application; after receiving the second authorization request, the authorization server can be triggered to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier of the second application in the authorization token, and the pre-obtained application relationship information, and then can return corresponding response data to the first application based on the relationship identification result.
[0068] Terminals include, but are not limited to, various personal computers, laptops, smartphones, tablets, IoT devices, and portable wearable devices. IoT devices include smart speakers, smart TVs, smart air conditioners, and smart car devices; portable wearable devices include smart watches, smart bracelets, and head-mounted devices. The authorization server can be implemented as a standalone server or a server cluster consisting of multiple servers.
[0069] Figure 2 FIG. 1 is a flow chart showing an application authorization method according to an exemplary embodiment. Figure 2 As shown, this method is used for Figure 1 Taking the terminal in as an example, the following steps may be included.
[0070] In step S210, in response to the first authorization request of the first application for the account information of the target account in the target application, the second application obtains the authorization token obtained in advance; the authorization token is obtained by the second application after obtaining the authorization of the target application for the account information of the target account.
[0071] As an example, the target application may be an application that is to provide account information related to a target account in the application to other applications. Exemplarily, the target account may be an account in a logged-in state in the target application.
[0072] The target account's account information may include information generated during the target account's use of the target application. For example, the account information may include information identifying the target account, such as the target account's account name or account ID. Alternatively, the account information may include the target account's usage history for the target application, such as multimedia content published by the target account.
[0073] In practice, a terminal may be deployed with multiple applications. When account authorization is obtained, the application may provide the relevant account information of the account in the application to other applications in the multiple applications. In this step, the terminal may be installed with the client of the first application, the second application, and the target application. Among them, the second application may pre-request the account information of the target account in the target application, requesting authorization to use the account information, and then after obtaining the authorization of the target application for the account information of the target account, the second application may obtain the authorization token (access_token) of the target application. Exemplarily, the authorization token may store one or more of the following information: target account identifier, second application identifier, token version number, device identifier, permission scope, and generation time.
[0074] After the first application detects an authorization trigger event for the target account's account information, the first application may generate a first authorization request for the target account's account information. In response to the first authorization request of the first application, the terminal may obtain the authorization token that the second application has previously obtained.
[0075] In step S220, a second authorization request including the first application identifier and the authorization token of the first application is generated, and the second authorization request is sent to the authorization server of the target application.
[0076] Among them, the second authorization request is used to trigger the authorization server to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier of the second application in the authorization token, and the pre-acquired application relationship information, and return the authorization result to the first application according to the relationship identification result.
[0077] As an example, the application relationship of associated applications may be recorded in the application relationship information. For example, if application B is associated with application C, the association relationship may be recorded in the application relationship information.
[0078] After obtaining the authorization token of the second application, the terminal can obtain the identifier of the first application, that is, the first application identifier, and then generate a second authorization request containing the first application identifier and the authorization token of the second application, and send the second authorization request to the authorization server that provides authorization services for the target application.
[0079] In actual applications, after receiving a request from an application containing an application identifier and an authorization token, the authorization server can obtain the application identifier stored in the authorization token. The application identifier is the application identifier corresponding to the application that has obtained authorization from the target account and obtained the authorization token. Then, the authorization server can verify whether the application sending the request is authorized based on the application identifier in the authorization token and the application identifier in the request.
[0080] In this step, after receiving the second authorization request, the authorization server can obtain the authorization token in the second authorization request. Since the authorization token in the second authorization request is obtained by the second application, the authorization server can obtain the second application identifier of the second application from the authorization token.
[0081] It can be understood that when the first application identifier and the second application identifier are different, the authorization server can determine that the first application currently sending the second authorization request and the second application that obtains the authorization token are two different applications, and then obtain the pre-acquired application relationship information, identify the relationship between the first application and the second application based on the first application identifier, the second application identifier and the application relationship information, obtain the relationship identification result, and return the corresponding authorization result to the first application based on the relationship identification result.
[0082] Specifically, in the present disclosure, the authorization token obtained by an application can be used by other applications related to it. In other words, the authorization token can be propagated between related applications. Based on this, the authorization server in this embodiment can identify the relationship between the first application and the second application, determine whether there is a preset relationship between the first application and the second application, and obtain a relationship identification result. If the relationship identification result indicates that there is a preset relationship between the first application and the second application, the first application can obtain authorization for the account information of the target account through the authorization token of the second application, and the authorization server can return the authorization result to the first application, which may include information indicating that authorization is allowed; if the relationship identification result indicates that there is no preset relationship between the first application and the second application, the authorization server can refuse the first application to obtain the account information of the target account through the authorization token of the second application, and return an authorization result indicating that authorization is refused to the first application, so as to avoid providing the account information of the target account to the first application.
[0083] In the above-mentioned application authorization method, in response to a first authorization request from a first application for the account information of a target account in a target application, an authorization token pre-obtained by a second application is obtained; the authorization token is obtained by the second application after obtaining authorization from the target application for the account information of the target account; a second authorization request including the first application identifier and the authorization token of the first application is then generated and sent to the authorization server of the target application; the second authorization request can trigger the authorization server to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier of the second application in the authorization token, and the pre-obtained application relationship information, and return an authorization result to the first application based on the relationship identification result. In the solution disclosed herein, the first application can request authorization for the account information of the target account from the authorization server using the authorization token pre-obtained by the second application after authorization by the target account, and obtain an authorization result from the authorization server, without the user having to trigger the relevant operation of the authorization request for the first application again. The authorization server can also return the corresponding authorization result based on the relationship between the first application and the second application, avoiding the arbitrary propagation of the authorization token between applications, simplifying the application authorization operation while ensuring the security of the authorization, thereby effectively improving the authorization efficiency.
[0084] In an exemplary embodiment, Figure 3 As shown, in step S210, in response to the first authorization request of the first application for the account information of the target account in the target application, obtaining the authorization token pre-acquired by the second application may include the following steps:
[0085] In step S310 , in response to a first authorization request from a first application for account information of a target account in a target application, a second application associated with the first application and running independently is determined.
[0086] In actual applications, after a first application detects an authorization trigger event for the account information of a target account in a target application, such as detecting a user triggering a request to log in to the first application using the target account in the target application or displaying media resources published by the target account in the target application in the first application, the first application may generate a first authorization request for the account information of the target account. In response to the first authorization request, the terminal may identify a second application that is associated with the first application and runs independently from the multiple deployed applications.
[0087] Specifically, multiple applications can be deployed on the terminal, among which the first application and the second application can run independently, that is, the operation of the first application and the second application does not depend on each other, and the first application and the second application can be downloaded and installed separately; and, users using the applications or developers of the first application and the second application can associate the first application and the second application in advance through relevant configurations, wherein the associated multiple applications can constitute an application collection.
[0088] After detecting the first authorization request of the first application, a second application that is associated with the first application and runs independently can be determined according to the pre-generated configuration.
[0089] In step S320 , if the second application has obtained authorization from the target account, an authorization token of the second application is obtained.
[0090] After determining the second application associated with the first application, it can be determined whether the second application has obtained authorization from the target account in the target application. If the second application has obtained authorization from the target account, it can be determined that the second application has obtained the corresponding authorization token, and the terminal can obtain the authorization token of the second application.
[0091] In this embodiment, in response to the first authorization request of the first application, an authorization token can be obtained from a second application that is associated with the first application and runs independently. The authorization token authorized by the user can be reused between multiple applications that are associated and run independently, avoiding the user from repeatedly performing authorization operations when using multiple applications that are associated and run independently, thereby improving application authorization efficiency.
[0092] In an exemplary embodiment, in step S310, in response to a first authorization request from a first application for account information of a target account in a target application, determining a second application that is associated with the first application and runs independently includes:
[0093] The application entry of the first application is displayed through the application page of the second application; the first application and the second application are independently running applications; when a trigger operation for the application entry is detected and a first login request is obtained, a first authorization request for the account information of the target account in the target application is obtained by the first application, and it is determined that the second application displaying the application entry is associated with the first application.
[0094] The first login request indicates logging into the first application based on a target account in the target application.
[0095] In a specific implementation, to facilitate users' invocation of associated applications, an application page of one application may provide application portals for other applications. In this embodiment, the terminal may display the application page of the second application and display the application portal of the first application within the application page of the second application. Although the application portal of the first application is displayed within the second application, in this embodiment, the first and second applications are independently running applications.
[0096] After the application entrance of the first application is displayed on the application page of the second application, if a trigger operation (such as a click) for the application entrance is detected and a first login request is obtained, it can be determined that a first authorization request for the account information of the target account in the target application is obtained by the first application.
[0097] In this embodiment, when the second application provides an application entry for the first application, if the user has authorized the second application to use the account information of the target account, then when triggering the use of the target account to log in to the first application, the first application can directly use the authorization token of the second application to request the authorization server to allow the first application to log in using the target account, and the user does not need to authorize the first application again.
[0098] In an exemplary embodiment, Figure 4 As shown, in step S210, in response to the first authorization request of the first application for the account information of the target account in the target application, obtaining the authorization token pre-acquired by the second application may include the following steps:
[0099] In step S410, in response to the first authorization request of the first application for the account information of the target account in the target application, a second application is determined to provide an operating environment for the first application; the second application provides an operating environment for multiple sub-applications including the first application.
[0100] Specifically, the first application may be an application that depends on the second application to run, that is, the second application provides a running environment for multiple sub-applications including the first application. The first application does not need to be downloaded and installed when used, but can run in the running environment provided by the second application and respond to user-related requests. For example, the second application that provides a running environment for multiple sub-applications including the first application can be called an application package or an application collection, and the first application can be called a sub-application or a mini-program.
[0101] In this step, after the first application detects an authorization trigger event for the account information of the target account in the target application, if the first application is an application that relies on the operating environment provided by other applications to run, a second application that provides the operating environment for the first application can be determined.
[0102] In step S420 , if the second application has obtained authorization from the target account, an authorization token of the second application is obtained.
[0103] After determining the second application associated with the first application, it can be determined whether the second application has obtained authorization from the target account in the target application. If the second application has obtained authorization from the target account, it can be determined that the second application has obtained the corresponding authorization token, and the terminal can obtain the authorization token of the second application.
[0104] In this embodiment, in response to the first authorization request of the first application, an authorization token can be obtained from the second application that provides a running environment for multiple sub-applications and used by the sub-applications of the second application, thereby realizing the propagation of the authorization token between the main application (i.e., the second application) and the sub-application under the main application (i.e., the first application). When the second application has obtained authorization from the target account, it is avoided to perform authorization operations again when using each sub-application under the second application, thereby improving the efficiency of application authorization.
[0105] In an exemplary embodiment, before step S210, the method may further include the following steps:
[0106] The first application identifier of the first application and the second application identifier of the second application are associated to generate application relationship information, and the application relationship information is sent to the authorization server of the target application.
[0107] Among them, the application relationship information is used to instruct the authorization server to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier in the application relationship information, the first application identifier carried in the first authorization request, and the second application identifier in the authorization token when the authorization server receives the second authorization request.
[0108] Specifically, the application relationship information between different applications can be pre-configured to create an application group. Multiple applications in the same application group can be associated. In this embodiment, the first application identifier of the first application and the second application identifier of the second application can be obtained. The first application and the second application can be two independently running applications, or the second application can provide an operating environment for the first application, that is, the operation of the first application is dependent on the second application. Alternatively, the first application and the second application can be applications of the same type or applications from the same developer, such as both audio and video applications or both developed and released by Developer A. Of course, those skilled in the art can also select the first application and the second application to be associated in other ways.
[0109] After obtaining the first application identifier and the second application identifier, the first application identifier and the second application identifier can be associated, and application relationship information can be generated based on the associated first application identifier and the second application identifier. The terminal can then send the application relationship information to the authorization server. It should be noted that the application relationship information may include information about three or more associated applications in addition to information about two associated applications.
[0110] After obtaining the application relationship information, the authorization server can, upon receiving a second authorization request, query the obtained associated application information based on the first application identifier in the second authorization request and the second application identifier in the authorization token, identify the relationship between the first application and the second application, and obtain a relationship identification result.
[0111] In an optional embodiment, when creating an application group, application relationship information representing each application in the application group may be recorded and stored in a database table. The database table may be in the form shown in Table 1. The database table may include multiple fields that record different attributes of the application group. For example, if the application group includes an application that provides an operating environment for other applications, the application identifier of the application may be recorded in the field "app_id", such as the second application identifier in the above embodiment. Other sub-applications that rely on the application environment provided by the second application may be recorded in the field "related_app_group", such as the first application identifier. Of course, if the first and second applications are independently running applications, the application relationship information may also be stored in the database table. For example, for an application package 1 that includes applications 2, 3, and 4, the data stored in the table may be "app_id = 1" and "related_app_group = [2, 3, 4]".
[0112] Table 1
[0113] Field Field meaning type id Logo bigint app_id Application Identification bigint related_app_group Related application groups list <long> < / long> create_time Creation time bigint update_time Update Time bigint
[0114] In this embodiment, by associating the first application identifier of the first application and the second application identifier of the second application, application relationship information is generated, and the application relationship information is sent to the authorization server of the target application. When the authorization server receives an authorization request from the first application containing authorization tokens of other applications, it can correctly identify whether the first application is associated with the second application and return the corresponding authorization result, thereby realizing the propagation and sharing of authorization tokens within the application group and avoiding users from repeatedly performing authorization operations on associated applications.
[0115] In an exemplary embodiment, before step S210, the method may further include the following steps:
[0116] Obtain a second application, and in response to the second login request of the second application for the target application, display an authorization prompt for the account information of the target account of the target application; if confirmation information of the target account for the authorization prompt is received, obtain an authorization token from the authorization server of the target application.
[0117] The second login request may indicate logging into the second application based on the target account.
[0118] In actual application, the second application can be downloaded and deployed on the terminal. After detecting a trigger operation in which the user logs in to the second application using the target account in the target application, the second application can generate a second login request for the target application.
[0119] In response to the second login request, the terminal may display an authorization prompt for the target account's account information in the target application. This authorization prompt may inquire whether the user authorizes the second application to use the target account's account information. If the user confirms authorization for the second application to use the target account's account information, the user may perform a corresponding confirmation operation on the terminal. In response to this operation, the terminal may receive confirmation information from the target account regarding the authorization prompt and obtain a corresponding authorization token from the target application's authorization server.
[0120] For example, in response to a trigger operation in which a user uses a target account in a target application to log in to a second application, the client of the second application on the terminal can call an SDK (Software Development Kit) to generate a second login request, triggering authorization to obtain the account information of the target account in the target application. The second login request can be forwarded to the client of the target application in the terminal, and the client of the target application communicates with the authorization server of the target application. After the client of the target application obtains the relevant authorization information from the authorization server, the client of the target application can pull the authorization page, display the authorization prompt on the authorization page, and wait for the user to authorize. After detecting the user's confirmation operation in response to the authorization prompt, the client of the target application can determine that it has received the confirmation information of the target account in response to the authorization prompt. After generating an authorization code and sending it to the second application, the client of the second application can send the authorization code to the server of the second application, and the server of the second application can send the authorization code to the authorization server to obtain a replaced authorization token. The server of the second application can return the authorization token to the client of the second application on the terminal.
[0121] In this embodiment, when the target account in the target application is used to log in to the second application, the second application can be triggered to obtain an authorization token authorized by the target account, providing identity verification information for subsequent dissemination of trusted authorization tokens in related applications and reducing the number of user authorization times.
[0122] Figure 5 FIG. 1 is a flow chart showing another application authorization method according to an exemplary embodiment. Figure 5 As shown, this method is used for Figure 1 The following steps can be used to illustrate the authorization server in the example.
[0123] In step S510, an authorization request from the first application for the account information of the target account in the target application is received, and the first application identifier of the first application and the authorization token of the second application carried in the authorization request are obtained; the authorization token is obtained by the second application after obtaining authorization from the target application for the account information of the target account.
[0124] In actual applications, a terminal may be deployed with multiple applications. Upon obtaining account authorization, an application may provide the relevant account information of the account in the application to other applications in the multiple applications. In this embodiment, the terminal may be installed with a first application, a second application, and a client for a target application. The second application may pre-request the account information of the target account in the target application, requesting authorization to use that account information. After obtaining authorization from the target application for the target account's account information, the second application may then obtain an authorization token for the target application.
[0125] After the first application detects an authorization trigger event for the target account's account information, the terminal can obtain the first application identifier of the first application and the authorization token previously obtained by the second application, generate an authorization request containing the first application identifier and authorization token, and send the authorization request to the target application's authorization server. After receiving the authorization request, the authorization server can obtain the first application identifier and authorization token in the authorization request.
[0126] In step S520, the second application identifier of the second application in the authorization token is obtained, and the relationship between the first application and the second application is identified based on the first application identifier, the second application identifier and the pre-acquired application relationship information, and the authorization result is returned to the first application according to the relationship identification result.
[0127] As an example, the application relationship of associated applications may be recorded in the application relationship information. For example, if application B is associated with application C, the association relationship may be recorded in the application relationship information.
[0128] In the specific implementation, after receiving the request sent by the application containing the application identifier and authorization token, the authorization server can obtain the application identifier stored in the authorization token. The application identifier is the application identifier corresponding to the application that obtains the authorization of the target account and obtains the authorization token. Then, the authorization server can verify whether the application sending the request is authorized based on the application identifier in the authorization token and the application identifier in the request.
[0129] In this step, after obtaining the authorization token from the second application in the authorization request, since the authorization token is obtained by the second application, the authorization server can obtain the second application identifier of the second application from the authorization token.
[0130] It can be understood that when the first application identifier and the second application identifier are different, the authorization server can determine that the first application sending the authorization request and the second application obtaining the authorization token are two different applications, and then obtain the pre-obtained application relationship information, identify the relationship between the first application and the second application based on the first application identifier, the second application identifier and the application relationship information, obtain the relationship identification result, and return the corresponding authorization result to the first application based on the relationship identification result.
[0131] Specifically, in the present disclosure, the authorization token obtained by an application can be used by other applications related to it. In other words, the authorization token can be propagated between related applications. Based on this, the authorization server in this embodiment can identify the relationship between the first application and the second application, determine whether there is a preset relationship between the first application and the second application, and obtain a relationship identification result. If the relationship identification result indicates that there is a preset relationship between the first application and the second application, the first application can obtain authorization for the account information of the target account through the authorization token of the second application, and the authorization server can return the authorization result to the first application, which may include information indicating that authorization is allowed; if the relationship identification result indicates that there is no preset relationship between the first application and the second application, the authorization server can refuse the first application to obtain the account information of the target account through the authorization token of the second application, and return an authorization result indicating that authorization is refused to the first application, so as to avoid providing the account information of the target account to the first application.
[0132] In the above-mentioned application authorization method, the authorization server can receive an authorization request from the first application for the account information of the target account in the target application, obtain the first application identifier of the first application and the authorization token of the second application carried in the authorization request, and the authorization token is obtained by the second application after obtaining the authorization of the target application for the account information of the target account; then the authorization server can obtain the second application identifier of the second application in the authorization token, identify the relationship between the first application and the second application based on the first application identifier, the second application identifier and the pre-acquired application relationship information, and return the authorization result to the first application according to the relationship identification result. In the scheme disclosed herein, the first application can request the authorization of the target account account information from the authorization server through the authorization token obtained by the second application after the authorization of the target account, and obtain the authorization result from the authorization server, without the user having to trigger the relevant operation on the authorization request of the first application again, and the authorization server can return the corresponding authorization result according to the relationship between the first application and the second application, avoiding the arbitrary propagation of the authorization token between applications, simplifying the application authorization operation while ensuring the security of the authorization, thereby effectively improving the authorization efficiency.
[0133] In an exemplary embodiment, in step S520, returning the authorization result to the first application according to the relationship identification result may include the following steps:
[0134] If it is determined that the first application is associated with the second application, the association authorization of the second application is allocated to the first application; when the first application receives a request to obtain account information of the target account, the authorization result is returned to the first application according to the authorization attribute information of the association authorization.
[0135] The authorization attribute information may be information representing the authorization content.
[0136] In actual applications, if it is determined that the first application is not related to the second application, the authorization server can refuse to authorize the first application; if it is determined that the first application is associated with the second application, the target account's previous authorization to the second application can be regarded as authorization to the first application, and it is determined that the first application can legally use the target account's account information. In order to facilitate the subsequent provision of corresponding data to the first application, the first application's associated authorization can be allocated to the second application as an identity credential that allows the first application to legally use the target account's account information. In other words, if the first application can rely on the second application's authorization token to legally use the target account's account information, it is not necessary to reallocate an authorization token to the first application. Instead, it can allocate an associated authorization indicating the source of the authorization. The associated authorization indicates that the authorization currently obtained by the first application comes from the second application.
[0137] Furthermore, when the first application receives a request to obtain the account information of the target account, that is, the first application requests to obtain the account information of the target account, the authorization attribute information of the associated authorization can be combined to determine the account information that the first application is allowed to obtain, and based on the account information that the first application is allowed to obtain, the authorization result is returned to the first application, and the authorization result may include the account information that the first application is allowed to obtain.
[0138] Among them, the terminal can send the acquisition request together with the second authorization request to the authorization server. After the authorization server assigns the associated authorization to the first application, it can process the acquisition request accordingly. Alternatively, the terminal can also send the second authorization request first, and after detecting the relevant trigger operation (such as the operation of logging into the first application using the target account) subsequently, send the corresponding acquisition request according to the content of the trigger operation, requesting to obtain the specified content in the account information of the target account from the authorization server.
[0139] In this embodiment, when the first application is associated with the second application, the association authorization of the second application can be allocated to the first application, and the corresponding authorization result can be returned to the first application based on the authorization attribute information of the association authorization. First, the authorization token is used between different applications to avoid users from repeatedly performing authorization operations.
[0140] In an exemplary embodiment, the authorization attribute information may include the validity period of the authorization token of the second application. Of course, the authorization attribute information may also include the account identifier of the target account, the first application identifier, the second application identifier, the authorization status, the creation time of the authorization attribute information, and the update time of the authorization attribute information. Exemplarily, the authorization attribute information may be stored in the form of a database table, which may be shown in Table 2 below:
[0141] Table 2
[0142]
[0143]
[0144] Upon receiving a request from the first application for obtaining the account information of the target account, returning the authorization result to the first application according to the authorization attribute information of the associated authorization may include the following steps:
[0145] Upon receiving a request from the first application to obtain the account information of the target account, the validity period of the authorization token of the second application is obtained from the authorization attribute information; if the request time of the acquisition request does not exceed the validity period, the account information of the target account is returned to the first application as an authorization result.
[0146] As an example, the request time may be the time when the terminal sends the acquisition request or the time when the authorization server receives the acquisition request.
[0147] Specifically, since the associated authorization of the first application depends on the authorization of the second application, when the first application receives a request to obtain the account information of the target account, the validity period of the authorization token of the second application can be obtained from the authorization attribute information of the associated authorization, and it can be determined whether the request time of the acquisition request exceeds the validity period of the authorization token.
[0148] If the request time of the acquisition request does not exceed the validity period, the authorization server can return the account information of the target account to the first application as the authorization result; if the request time of the authorization request has exceeded the validity period, it can be determined that the associated authorization has expired and refuse to provide the account information of the target account to the first application.
[0149] In this embodiment, if the request time of the acquisition request does not exceed the validity period of the second application authorization token, the account information of the target account can be returned to the first application as the authorization result, thereby avoiding the user from repeatedly performing authorization operations while ensuring the security of the account information.
[0150] In an exemplary embodiment, the application relationship information stores associated application identifiers, and identifying the relationship between the first application and the second application based on the first application identifier, the second application identifier, and the pre-acquired application relationship information includes:
[0151] If it is determined based on the pre-acquired application relationship information that the first application identifier is associated with the second application identifier, then it is determined that the first application is associated with the second application.
[0152] Specifically, the application relationship information between different applications can be pre-configured to create an application group. Multiple applications in the same application group can be associated. In this embodiment, the first application identifier of the first application and the second application identifier of the second application can be obtained. The first application and the second application can be two independently running applications, or the second application can provide an operating environment for the first application, that is, the operation of the first application is dependent on the second application. Alternatively, the first application and the second application can be applications of the same type or applications from the same developer, such as both audio and video applications or both developed and released by Developer A. Of course, those skilled in the art can also select the first application and the second application to be associated in other ways.
[0153] After obtaining the first application identifier and the second application identifier, the first application identifier and the second application identifier can be associated, and application relationship information can be generated based on the associated first application identifier and the second application identifier. Then, the terminal can send the application relationship information to the authorization server.
[0154] After obtaining the application relationship information, the authorization server can, after receiving the authorization request, query the obtained associated application information based on the first application identifier in the authorization request and the second application identifier in the authorization token to identify the relationship between the first application and the second application. If the associated first application identifier and second application identifier are found in the application relationship information, it can be determined that the first application is associated with the second application, and a relationship identification result can be obtained.
[0155] In this embodiment, by determining the association between the first application identifier and the second application identifier based on the pre-acquired application relationship information, the first application is associated with the second application. This enables the authorization server to correctly identify whether the first application is associated with the second application and return the corresponding authorization result when receiving the authorization request from the first application containing the authorization token of other applications, thereby realizing the propagation and sharing of the authorization token within the application group and avoiding the user from repeatedly performing authorization operations on the associated applications.
[0156] In order to enable those skilled in the art to better understand the above steps, the embodiment of the present disclosure is illustrated below by using an example, but it should be understood that the embodiment of the present disclosure is not limited thereto.
[0157] like Figure 6 As shown, the target application's authorization server can include the target application open service and the target application authorization service. The collection package app can be understood as a second application, which can be an application that provides an operating environment for other sub-applications or an application that displays application portals for other independently running applications. The collection package app can have a corresponding server, and the terminal can have the collection package app client and the target application client installed.
[0158] In this embodiment, after detecting a triggering action in which a user opens the collection package app and requests to log in to the collection package app client using the target account, the collection package app client can call the SDK to generate a second login request in response to this action, requesting authorization from the target application to obtain the collection package app's account information for the target account. The second login request can be forwarded to the target application's client, which then communicates with the target application's authorization server. After the target application's client obtains the relevant authorization information from the authorization server, it can pull up the authorization page, display an authorization prompt on the authorization page, and wait for the user to authorize.
[0159] After detecting the user's confirmation operation for the authorization prompt, the client of the target application can determine that it has received the confirmation information of the target account for the authorization prompt. After generating the authorization code and sending it to the client of the collection package app, the client of the collection package app can send the authorization code to the server of the collection package app, and the server of the collection package app can send the authorization code to the authorization service to obtain the authorization token replaced with the authorization code. The server of the collection package app can return the authorization token to the client of the collection package app, and the server of the collection package app can use the currently obtained authorization token to request the open service of the target application to obtain the account information of the target account. After receiving the request of the collection package app, the open service of the target application can use the authorization token in the request to trigger the authorization service to perform authentication to check whether the collection package app has obtained user authorization; after the authorization service returns the authentication result, if the authentication result indicates that the collection package app has obtained user authorization, the open service can again request to obtain the user authorization relationship of the collection package app and receive the user authorization relationship returned by the authorization service. After receiving the information, the open service can return the account information of the target account to the server of the collection package App, and then the target account can be used to log in to the client of the collection package App.
[0160] When the user continues to open application B in the collection package App, the collection package App can propagate the obtained authorization token to application B. Application B can generate an authorization request carrying the authorization token and the application identifier of application B, and send it to the authorization service through the collection package App's server. After determining that application B is an application within the collection package App, the authorization service can allocate the collection package App's associated authorization to application B and return the authorization information to the collection package App's server. The collection package App's server can then request the open service to obtain the target account's account information for application B, sending a request carrying the collection package App's authorization token and the application B identifier. After receiving the request, the target application's open service can use the authorization token in the request and the application identifier of application B to trigger the authorization service to perform authentication to check whether the collection package App has obtained user authorization. If the authorization service determines that application B has obtained the collection package App's associated authorization based on the authorization token, the application identifier of application B, and the pre-obtained application relationship information, it can further determine whether the associated authorization is valid and return the authentication result. If the authentication result indicates that the associated authorization for Application B is valid, the Open Service can request the user authorization relationship for the collection package app again and receive the user authorization relationship returned from the authorization service. After receiving this information, the Open Service can return the account information of the target account to the collection package app server, triggering the collection package app server to log in to the client of Application B using the target account.
[0161] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.
[0162] It can be understood that the same / similar parts between the various embodiments of the above method in this specification can be referred to each other, and each embodiment focuses on the differences from other embodiments. For related parts, please refer to the description of other method embodiments.
[0163] Based on the same inventive concept, an embodiment of the present disclosure further provides an application authorization device for implementing the above-mentioned application authorization method.
[0164] Figure 7FIG. 1 is a block diagram of an application authorization device according to an exemplary embodiment. Figure 7 The device includes an authorization token obtaining unit 701 and an authorization request sending unit 702.
[0165] The authorization token acquisition unit 701 is configured to execute, in response to a first authorization request from a first application for account information of a target account in a target application, an authorization token pre-acquired by a second application; the authorization token is acquired by the second application after obtaining authorization from the target application for the account information of the target account;
[0166] The authorization request sending unit 702 is configured to generate a second authorization request including the first application identifier of the first application and the authorization token, and send the second authorization request to the authorization server of the target application;
[0167] Among them, the second authorization request is used to trigger the authorization server to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier of the second application in the authorization token, and the pre-acquired application relationship information, and return the authorization result to the first application according to the relationship identification result.
[0168] In an exemplary embodiment, the authorization token acquisition unit 701 includes:
[0169] a first determining module configured to execute, in response to a first authorization request by a first application for account information of a target account in a target application, determining a second application that is associated with the first application and runs independently;
[0170] The first acquisition module is configured to acquire an authorization token of the second application if the second application has obtained authorization from the target account.
[0171] In an exemplary embodiment, the first determining module is specifically configured to execute:
[0172] Displaying an application entry for the first application through an application page of the second application; the first application and the second application are independently running applications;
[0173] When a trigger operation for the application entry is detected and a first login request is obtained, a first authorization request is obtained by the first application for the account information of the target account in the target application, and it is determined that the second application displaying the application entry is associated with the first application; wherein, the first login request indicates logging into the first application based on the target account.
[0174] In an exemplary embodiment, the authorization token acquisition unit 701 includes:
[0175] a second determining module configured to execute, in response to a first authorization request by the first application for account information of a target account in the target application, determining a second application that provides an operating environment for the first application; the second application provides an operating environment for a plurality of sub-applications including the first application;
[0176] The second acquisition module is configured to acquire an authorization token of the second application if the second application has obtained authorization from the target account.
[0177] In an exemplary embodiment, the apparatus further comprises:
[0178] an application relationship information sending unit, configured to associate a first application identifier of a first application with a second application identifier of a second application, generate application relationship information, and send the application relationship information to an authorization server of a target application;
[0179] The application relationship information is used to instruct the authorization server to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier in the application relationship information, the first application identifier carried in the first authorization request, and the second application identifier in the authorization token when the authorization server receives the second authorization request.
[0180] In an exemplary embodiment, the apparatus further comprises:
[0181] an authorization prompt unit configured to execute acquisition of a second application and, in response to a second login request from the second application for a target application, display an authorization prompt for account information of a target account of the target application; wherein the second login request indicates login to the second application based on the target account;
[0182] The authorization token obtaining unit is configured to obtain the authorization token from the authorization server of the target application if confirmation information of the target account for the authorization prompt is received.
[0183] Figure 8 FIG. 1 is a block diagram of another application authorization device according to an exemplary embodiment. Figure 8 The device includes an authorization request receiving unit 801 and an authorization result determining unit 802.
[0184] The authorization request receiving unit 801 is configured to receive an authorization request from a first application for account information of a target account in a target application, and obtain a first application identifier of the first application and an authorization token of a second application carried in the authorization request; the authorization token is obtained by the second application after obtaining authorization from the target application for the account information of the target account;
[0185] The authorization result determination unit 802 is configured to obtain the second application identifier of the second application in the authorization token, identify the relationship between the first application and the second application based on the first application identifier, the second application identifier and the pre-acquired application relationship information, and return the authorization result to the first application according to the relationship identification result.
[0186] In an exemplary embodiment, the authorization result determination unit 802 includes:
[0187] an association authorization allocation module, configured to allocate association authorization of the second application to the first application if it is determined that the first application is associated with the second application;
[0188] The authorization result returning module is configured to execute, upon receiving a request from the first application to obtain the account information of the target account, returning an authorization result to the first application according to the authorization attribute information of the associated authorization.
[0189] In an exemplary embodiment, the authorization attribute information includes a validity period of the authorization token of the second application, and the authorization result returning module is specifically configured to execute:
[0190] Upon receiving a request from the first application for obtaining the account information of the target account, obtaining the validity period of the authorization token of the second application from the authorization attribute information;
[0191] If the request time of the acquisition request does not exceed the validity period, the account information of the target account is returned to the first application as an authorization result.
[0192] In an exemplary embodiment, the application relationship information stores an associated application identifier, and the authorization result determination unit 802 is configured to execute:
[0193] If it is determined based on the pre-acquired application relationship information that the first application identifier is associated with the second application identifier, then it is determined that the first application is associated with the second application.
[0194] Regarding the apparatus in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.
[0195] Each module in the aforementioned application authorization device may be implemented in whole or in part through software, hardware, or a combination thereof. Each module may be embedded in or independent of a processor in a computer device in the form of hardware, or may be stored in a memory in the computer device in the form of software, so that the processor can call and execute the corresponding operations of each module.
[0196] Figure 9 1 is a block diagram illustrating an electronic device 900 for implementing an application authorization method according to an exemplary embodiment. For example, the electronic device 900 may be a mobile phone, a computer, a digital broadcast terminal, a messaging device, a game console, a tablet device, a medical device, a fitness device, a personal digital assistant, etc.
[0197] Reference Figure 9 , the electronic device 900 may include one or more of the following components: a processing component 902 , a memory 904 , a power supply component 906 , a multimedia component 908 , an audio component 910 , an input / output (I / O) interface 912 , a sensor component 914 , and a communication component 916 .
[0198] The processing component 902 generally controls the overall operation of the electronic device 900, such as operations associated with display, phone calls, data communications, camera operation, and recording operations. The processing component 902 may include one or more processors 920 to execute instructions to perform all or part of the steps of the above-described method. In addition, the processing component 902 may include one or more modules to facilitate interaction between the processing component 902 and other components. For example, the processing component 902 may include a multimedia module to facilitate interaction between the multimedia component 908 and the processing component 902.
[0199] The memory 904 is configured to store various types of data to support operations on the electronic device 900. Examples of such data include instructions for any application or method operating on the electronic device 900, contact data, phone book data, messages, pictures, videos, etc. The memory 904 can be implemented by any type of volatile or non-volatile storage device, or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, optical disk, or graphene memory.
[0200] The power supply component 906 provides power to the various components of the electronic device 900. The power supply component 906 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power to the electronic device 900.
[0201] The multimedia component 908 includes a screen that provides an output interface between the electronic device 900 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touch, slide, and gestures on the touch panel. The touch sensor can not only sense the boundaries of the touch or slide action, but also detect the duration and pressure associated with the touch or slide operation. In some embodiments, the multimedia component 908 includes a front camera and / or a rear camera. When the electronic device 900 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera can receive external multimedia data. Each front camera and rear camera can be a fixed optical lens system or have a focal length and optical zoom capability.
[0202] The audio component 910 is configured to output and / or input audio signals. For example, the audio component 910 includes a microphone (MIC), which is configured to receive external audio signals when the electronic device 900 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signal can be further stored in the memory 904 or transmitted via the communication component 916. In some embodiments, the audio component 910 also includes a speaker for outputting audio signals.
[0203] I / O interface 912 provides an interface between processing component 902 and peripheral interface modules, such as a keyboard, click wheel, buttons, etc. These buttons may include but are not limited to: a home button, volume buttons, a start button, and a lock button.
[0204] The sensor assembly 914 includes one or more sensors for providing various aspects of status assessment for the electronic device 900. For example, the sensor assembly 914 can detect the open / closed state of the electronic device 900, the relative positioning of components, such as the display and keypad of the electronic device 900. The sensor assembly 914 can also detect changes in the position of the electronic device 900 or components of the electronic device 900, the presence or absence of user contact with the electronic device 900, the orientation or acceleration / deceleration of the device 900, and temperature changes of the electronic device 900. The sensor assembly 914 may include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor assembly 914 may also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor assembly 914 may also include an accelerometer, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.
[0205] The communication component 916 is configured to facilitate wired or wireless communication between the electronic device 900 and other devices. The electronic device 900 can access a wireless network based on a communication standard, such as WiFi, an operator network (such as 2G, 3G, 4G or 5G), or a combination thereof. In an exemplary embodiment, the communication component 916 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 916 also includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology and other technologies.
[0206] In an exemplary embodiment, the electronic device 900 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to perform the above-described methods.
[0207] In an exemplary embodiment, a computer-readable storage medium including instructions is also provided, such as a memory 904 including instructions, and the instructions can be executed by the processor 920 of the electronic device 900 to perform the above method. For example, the computer-readable storage medium can be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0208] In an exemplary embodiment, a computer program product is further provided. The computer program product includes instructions, and the instructions can be executed by the processor 920 of the electronic device 900 to implement the above method.
[0209] Figure 10 1 is a block diagram of an electronic device 1000 for implementing an application authorization method according to an exemplary embodiment. For example, the electronic device 1000 may be a server. Figure 10 The electronic device 1000 includes a processing component 1020, which further includes one or more processors, and a memory resource represented by a memory 1022 for storing instructions executable by the processing component 1020, such as an application. The application stored in the memory 1022 may include one or more modules, each corresponding to a set of instructions. In addition, the processing component 1020 is configured to execute the instructions to perform the above method.
[0210] The electronic device 1000 may further include a power supply component 1024 configured to perform power management of the electronic device 1000, a wired or wireless network interface 1026 configured to connect the electronic device 1000 to a network, and an input / output (I / O) interface 1028. The electronic device 1000 may operate based on an operating system stored in the memory 1022, such as Windows Server, Mac OS X, Unix, Linux, FreeBSD, or the like.
[0211] In an exemplary embodiment, a computer-readable storage medium including instructions is also provided, such as a memory 1022 including instructions, and the instructions can be executed by a processor of the electronic device 1000 to perform the above method. The storage medium can be a computer-readable storage medium, for example, a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, an optical data storage device, etc.
[0212] In an exemplary embodiment, a computer program product is further provided. The computer program product includes instructions, and the instructions can be executed by a processor of the electronic device 1000 to implement the above method.
[0213] It should be noted that the above-mentioned devices, electronic devices, computer-readable storage media, computer program products, etc. can also include other implementation methods according to the description of the method embodiments. The specific implementation methods can refer to the description of the relevant method embodiments and will not be described one by one here.
[0214] Other embodiments of the present disclosure will readily occur to those skilled in the art after considering the specification and practicing the invention disclosed herein. This disclosure is intended to cover any variations, uses, or adaptations of the present disclosure that follow the general principles of the present disclosure and include common knowledge or customary techniques in the art not disclosed herein. The description and examples are to be considered as exemplary only, with the true scope and spirit of the present disclosure being indicated by the claims.
[0215] It should be understood that the present disclosure is not limited to the exact structures that have been described above and shown in the drawings, and that various modifications and changes can be made without departing from the scope thereof. The scope of the present disclosure is limited only by the appended claims.
Claims
1. An application authorization method, characterized in that: include: Responding to a first authorization request by the first application for account information of a target account in the target application, obtaining an authorization token pre-acquired by the second application; The target application is an application that is to provide the account information of the target account in the application to other applications, and the authorization token is obtained by the second application after obtaining authorization from the target application for the account information of the target account; Generate a second authorization request including the first application identifier of the first application and the authorization token, and send the second authorization request to the authorization server of the target application; Among them, the second authorization request is used to trigger the authorization server to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier of the second application in the authorization token, and the pre-acquired application relationship information, and return the authorization result to the first application according to the relationship identification result.
2. The method according to claim 1, characterized in that The step of obtaining, in response to a first authorization request by the first application for account information of a target account in the target application, an authorization token pre-acquired by the second application includes: In response to a first authorization request by a first application for account information of a target account in a target application, determining a second application that is associated with the first application and runs independently; If the second application has obtained authorization from the target account, obtain the authorization token of the second application.
3. The method according to claim 2, characterized in that The determining, in response to a first authorization request by the first application for account information of a target account in the target application, a second application that is associated with the first application and runs independently includes: Displaying an application entry for the first application through an application page of the second application; the first application and the second application are independently running applications; When a trigger operation for the application entry is detected and a first login request is obtained, a first authorization request is obtained by the first application for the account information of the target account in the target application, and it is determined that the second application displaying the application entry is associated with the first application; wherein, the first login request indicates logging into the first application based on the target account.
4. The method according to claim 1, wherein The step of obtaining, in response to a first authorization request by the first application for account information of a target account in the target application, an authorization token pre-acquired by the second application includes: In response to a first authorization request by the first application for account information of a target account in a target application, determining a second application that provides an operating environment for the first application; the second application provides an operating environment for a plurality of sub-applications including the first application; If the second application has obtained authorization from the target account, obtain the authorization token of the second application.
5. The method according to claim 1, wherein Before obtaining the authorization token pre-acquired by the second application in response to the first authorization request of the first application for the account information of the target account in the target application, the method further includes: Associating the first application identifier of the first application with the second application identifier of the second application to generate application relationship information, and sending the application relationship information to the authorization server of the target application; The application relationship information is used to instruct the authorization server to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier in the application relationship information, the first application identifier carried in the first authorization request, and the second application identifier in the authorization token when the authorization server receives the second authorization request.
6. The method according to claim 1, characterized in that Before obtaining the authorization token pre-acquired by the second application in response to the first authorization request of the first application for the account information of the target account in the target application, the method further includes: Obtaining a second application, and displaying an authorization prompt for account information of a target account of the target application in response to a second login request from the second application to the target application, wherein the second login request indicates logging into the second application based on the target account; If confirmation information of the target account for the authorization prompt is received, an authorization token is obtained from the authorization server of the target application.
7. An application authorization method, characterized in that: include: Receiving an authorization request from a first application for account information of a target account in a target application, and obtaining a first application identifier of the first application and an authorization token of a second application carried in the authorization request; The target application is an application that is to provide the account information of the target account in the application to other applications, and the authorization token is obtained by the second application after obtaining authorization from the target application for the account information of the target account; Obtain the second application identifier of the second application in the authorization token, identify the relationship between the first application and the second application based on the first application identifier, the second application identifier and the pre-acquired application relationship information, and return the authorization result to the first application according to the relationship identification result.
8. The method according to claim 7, characterized in that The returning the authorization result to the first application according to the relationship identification result includes: If it is determined that the first application is associated with the second application, allocating association authorization for the second application to the first application; Upon receiving the request from the first application for obtaining the account information of the target account, an authorization result is returned to the first application according to the authorization attribute information of the associated authorization.
9. The method according to claim 8, characterized in that The authorization attribute information includes a validity period of the authorization token of the second application, and upon receiving the request from the first application to obtain the account information of the target account, returning the authorization result to the first application according to the authorization attribute information of the associated authorization, including: Upon receiving a request from the first application for obtaining the account information of the target account, obtaining the validity period of the authorization token of the second application from the authorization attribute information; If the request time of the acquisition request does not exceed the validity period, the account information of the target account is returned to the first application as an authorization result.
10. The method according to claim 7, characterized in that The application relationship information stores associated application identifiers, and identifying the relationship between the first application and the second application based on the first application identifier, the second application identifier, and the pre-acquired application relationship information includes: If it is determined based on the pre-acquired application relationship information that the first application identifier is associated with the second application identifier, then it is determined that the first application is associated with the second application.
11. An application authorization device, characterized in that: include: an authorization token acquisition unit configured to execute, in response to a first authorization request from a first application for account information of a target account in a target application, an acquisition of an authorization token pre-acquired by a second application; the target application is an application that will provide the account information of the target account in the application to other applications, and the authorization token is acquired by the second application after obtaining authorization from the target application for the account information of the target account; an authorization request sending unit, configured to generate a second authorization request including the first application identifier of the first application and the authorization token, and send the second authorization request to the authorization server of the target application; Among them, the second authorization request is used to trigger the authorization server to identify the relationship between the first application and the second application based on the first application identifier, the second application identifier of the second application in the authorization token, and the pre-acquired application relationship information, and return the authorization result to the first application according to the relationship identification result.
12. An application authorization device, characterized in that: include: an authorization request receiving unit configured to receive an authorization request from a first application for account information of a target account in a target application, and obtain a first application identifier of the first application and an authorization token of the second application carried in the authorization request; The target application is an application that is to provide the account information of the target account in the application to other applications, and the authorization token is obtained by the second application after obtaining authorization from the target application for the account information of the target account; The authorization result determination unit is configured to obtain the second application identifier of the second application in the authorization token, identify the relationship between the first application and the second application based on the first application identifier, the second application identifier and the pre-acquired application relationship information, and return the authorization result to the first application according to the relationship identification result.
13. An electronic device, characterized in that: include: processor; a memory for storing instructions executable by the processor; The processor is configured to execute the instructions to implement the method according to any one of claims 1 to 6 or the method according to any one of claims 7 to 10.
14. A computer-readable storage medium, characterized in that When the instructions in the computer-readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to perform the method according to any one of claims 1 to 6 or implement the method according to any one of claims 7 to 10.
15. A computer program product comprising instructions, characterized in that: When the instructions are executed by a processor of an electronic device, the electronic device is enabled to perform the method according to any one of claims 1 to 6 or implement the method according to any one of claims 7 to 10.
Citation Information
Patent Citations
Login authentication method and device, electronic equipment and computer readable storage medium
CN113010874A