Single Sign-On Method, Device, Non-Volatile Storage Medium, and Processor
By querying the target key indicated by the key identification in the preset storage space in the single sign-on system and decrypting the single point of ticket, the stability problem caused by the existing single sign-on system relying on centralized authentication services is solved, and decentralization and stability improvement is achieved.
Patent Information
- Application Number
- CN202211183729.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-27
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-09-27
AI Technical Summary
The existing single sign-on system relies on centralized authentication services, resulting in stable and poor authentication. If the authentication service fails, the entire single point function will fail, and there is a lack of effective solutions.
By receiving a single sign-on request, query the target key indicated by the key identification in the preset storage space, decrypt the single point of ciphertext based on the target key, obtain a single point of ticket, and perform unique verification. If unique, login is allowed to be implemented to realize decentralized single sign-on.
The interface of the authentication system is not required to call, and the entire single-point cluster is decentralized, and the authentication service is no longer dependent on authentication services, which improves the stability of the single-point cluster and eliminates the risks of the system at the network level.
Smart Images

Figure CN115529178B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computers, and more particularly, to a single sign-on method, apparatus, non-volatile storage medium, and processor. Background Art
[0002] Single Sign-On (SSO) is one of the more popular solutions for enterprise business integration. The definition of SSO is that in multiple application systems, a user only needs to log in once to access all mutually trusted application systems.
[0003] When a user first accesses an application system, since they have not logged in yet, they will be redirected to the authentication system for logging in. Based on the login information provided by the user, the authentication system performs identity verification. If the verification passes, the user is set as logged in. When the user accesses other applications, the single sign-on ticket and user information will be passed to other applications. After receiving the request, other application systems will verify the single sign-on ticket. If the verification passes, the user can access all other applications without having to log in again.
[0004] Currently, the implementation of single sign-on is mainly a centralized single-point mode that provides authentication and single sign-on functions. When a user logs in to System A and then clicks to access System B, System A calls the authentication service to generate a token. The browser redirects to System B with the token. After System B obtains the token, it calls the authentication service again for authorization. If the authorization passes, the user is considered to have successfully logged in to System B.
[0005] Traditional single sign-on clusters are all centralized single points. The authentication service provides unified single sign-on and authentication services. The initiating end calls the authentication system to generate a single sign-on ticket → the single sign-on ticket is passed to the receiving end -> the receiving end calls the ticket authorization interface of the authentication system for verification.
[0006] This centralized single-point mode has high requirements for the authentication service, which will cause a large pressure on the authentication service. If the authentication service fails, the single sign-on function of all services will fail.
[0007] In view of the above problem of poor authentication stability due to the existing single sign-on relying on a centralized authentication service, no effective solution has been proposed yet.
[0008] Summary of the Application
[0009] Embodiments of this application provide a single sign-on method, apparatus, non-volatile storage medium, and processor to at least solve the technical problem of poor authentication stability due to the existing single sign-on relying on a centralized authentication service.
[0010] According to one aspect of the embodiments of the present application, a single sign-on method is provided, including: receiving a single sign-on request of a target object, where the single sign-on request carries a single sign-on ciphertext and a key identifier, and the single sign-on ciphertext at least includes an encrypted single sign-on ticket, and the single sign-on ticket is a login credential of the target object; querying a target key indicated by the key identifier in a first preset storage space, where the first preset storage space stores one or more preset keys updated according to a preset period and key identifiers of each of the preset keys; decrypting the single sign-on ciphertext based on the target key to obtain the single sign-on ticket; performing a uniqueness verification on the single sign-on ticket, where if the single sign-on ticket is unique, it is determined to allow the target object to log in to the system requested by the single sign-on request.
[0011] Optionally, the key identifier is a binary value. Querying the target key indicated by the key identifier in the first preset storage space includes: identifying the parity of the key identifier; according to the parity of the key identifier, querying the target key indicated by the key identifier in the first preset storage space, where the first preset storage space pre-stores a first preset key corresponding to an odd key identifier and a second preset key corresponding to an even key identifier, and the update periods of the first preset key and the second preset key are adjacent.
[0012] Optionally, before querying the target key indicated by the key identifier in the first preset storage space, the method further includes: obtaining a pre-configured key update period and a key update rule; determining a preset key corresponding to each key update period according to the key update period and the key update rule; determining a key identifier of each preset key according to the key update period.
[0013] Optionally, determining a preset key corresponding to each key update period according to the key update period and the key update rule includes: obtaining a first key of a first key period; using the first key as a seed key, calculating a second key of a second key period based on the key update rule, where the second key period is adjacent to the first key period and the second key period is later than the first key period.
[0014] Optionally, determining a key identifier of each preset key according to the key update period includes: determining the number of key updates of a target key period according to the key update period; determining the key identifier of the preset key corresponding to the target key period according to the number of key updates.
[0015] According to another aspect of the embodiments of the present application, a single sign-on method is further provided, including: obtaining an access request of a target object, where the access request carries login information, the initiation time of the access request, and a single-point link of the access object, the login information at least includes a single-point ticket, and the single-point ticket is a login credential of the target object; querying a target secret key corresponding to the initiation time and a secret key identifier of the target secret key in a second preset storage space, where the second preset storage space stores one or more preset secret keys updated according to a preset period and a secret key identifier of each preset secret key; encrypting the login credential according to the target secret key to generate a single-point ciphertext; splicing the single-point ciphertext and the secret key identifier into the single-point link to generate a single-point login request for the access object.
[0016] According to another aspect of the embodiments of the present application, a single sign-on device is further provided, including: a receiving module, configured to receive a single-point login request of a target object, where the single-point login request carries a single-point ciphertext and a secret key identifier, the single-point ciphertext at least includes an encrypted single-point ticket, and the single-point ticket is a login credential of the target object; a decryption query module, configured to query a target secret key indicated by the secret key identifier in a first preset storage space, where the first preset storage space stores one or more preset secret keys updated according to a preset period and a secret key identifier of each preset secret key; a decryption module, configured to decrypt the single-point ciphertext based on the target secret key to obtain the single-point ticket; a verification module, configured to perform uniqueness verification on the single-point ticket, where if the single-point ticket is unique, it is determined to allow the target object to log in to the system requested by the single-point login request.
[0017] According to another aspect of the embodiments of the present application, a single sign-on device is further provided, including: an obtaining module, configured to obtain an access request of a target object, where the access request carries login information, the initiation time of the access request, and a single-point link of the access object, the login information at least includes a single-point ticket, and the single-point ticket is a login credential of the target object; an encryption query module, configured to query a target secret key corresponding to the initiation time and a secret key identifier of the target secret key in a second preset storage space, where the second preset storage space stores one or more preset secret keys updated according to a preset period and a secret key identifier of each preset secret key; an encryption module, configured to encrypt the login credential according to the target secret key to generate a single-point ciphertext; a generating module, configured to splice the single-point ciphertext and the secret key identifier into the single-point link to generate a single-point login request for the access object.
[0018] According to another aspect of the embodiments of the present application, a non-volatile storage medium is further provided, characterized in that a program is stored in the non-volatile storage medium, and when the program runs, it controls the device where the non-volatile storage medium is located to execute the single sign-on method described above.
[0019] According to another aspect of the embodiments of the present application, an electronic device is further provided, characterized in that it includes: a memory and a processor, and the processor is used to run a program stored in the memory, and when the program runs, it executes the single sign-on method described above.
[0020] In the embodiments of the present application, a single sign-on request of a target object is received. The single sign-on request carries a single-point ciphertext and a key identifier. The single-point ciphertext at least includes an encrypted single-point ticket, and the single-point ticket is a login credential of the target object. Query the target key indicated by the key identifier in the first preset storage space, where the first preset storage space stores one or more preset keys updated according to a preset period and the key identifiers of each preset key. Decrypt the single-point ciphertext based on the target key to obtain the single-point ticket. Perform uniqueness verification on the single-point ticket. If the single-point ticket is unique, it is determined to allow the target object to log in to the system requested by the single sign-on request, enabling the single sign-on process to not require calling the interface of the authentication system, achieving decentralization of the entire single-point cluster, no longer relying on the authentication service, and achieving the technical effect of improving the stability of the entire single-point cluster. Since there is no need for each party to debug the single-point interface, each system can have non-interconnected networks and directly transmit the ciphertext through the public network https, thus eliminating the risks at the network level of the system, and further solving the technical problem of poor authentication stability due to the existing single sign-on relying on a centralized authentication service. Description of the Drawings
[0021] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:
[0022] Figure 1 is a flowchart of a single sign-on method according to an embodiment of the present application Figure 1 ;
[0023] Figure 2 is a schematic diagram of generating a pseudo-random number by a mixed congruence algorithm according to an embodiment of the present application;
[0024] Figure 3 is a flowchart of a single sign-on method according to an embodiment of the present application Figure 2 ;
[0025] Figure 4It is a schematic diagram of a single-point process according to an embodiment of the present application;
[0026] Figure 5 It is a schematic Figure 1 ;
[0027] Figure 6 It is a schematic Figure 2 ;
[0028] Figure 7 It is a structural block diagram of a computer terminal according to an embodiment of the present application. Detailed implementation manners
[0029] In order to enable those skilled in the art to better understand the solution of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0030] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that such data can be interchanged under appropriate circumstances so that the embodiments of the present application described herein can be implemented in an order different from those illustrated or described herein. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units does not necessarily need to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0031] According to an embodiment of the present application, an embodiment of a single sign-on method is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that here.
[0032] Figure 1 It is a flow Figure 1 of a single sign-on method according to an embodiment of the present application, Figure 1 as shown, the method includes the following steps:
[0033] Step S102: Receive a single sign-on request from a target object. The single sign-on request carries a single-point ciphertext and a secret key identifier. The single-point ciphertext includes at least an encrypted single-point ticket, and the single-point ticket is the login credential of the target object.
[0034] Step S104: Query the target secret key indicated by the secret key identifier in the first preset storage space. The first preset storage space stores one or more preset secret keys updated according to a preset period and the secret key identifier of each preset secret key.
[0035] Step S106: Decrypt the single-point ciphertext based on the target secret key to obtain the single-point ticket.
[0036] Step S108: Perform a uniqueness verification on the single-point ticket. If the single-point ticket is unique, it is determined to allow the target object to log in to the system requested by the single sign-on request.
[0037] In the embodiment of the present application, a single sign-on request from a target object is received. The single sign-on request carries a single-point ciphertext and a secret key identifier. The single-point ciphertext includes at least an encrypted single-point ticket, and the single-point ticket is the login credential of the target object. The target secret key indicated by the secret key identifier is queried in the first preset storage space. The first preset storage space stores one or more preset secret keys updated according to a preset period and the secret key identifier of each preset secret key. The single-point ciphertext is decrypted based on the target secret key to obtain the single-point ticket. A uniqueness verification is performed on the single-point ticket. If the single-point ticket is unique, it is determined to allow the target object to log in to the system requested by the single sign-on request, enabling the single sign-on process to not require calling the interface of the authentication system, achieving the decentralization of the entire single-point cluster, no longer relying on the authentication service, and achieving the technical effect of improving the stability of the entire single-point cluster. Since there is no need for each party to debug the single-point interface, each system can have non-interconnected networks and directly transmit the ciphertext over the public network https, thus eliminating the risks at the network level of the system and further solving the technical problem of poor authentication stability due to the existing single sign-on relying on a centralized authentication service.
[0038] In the above step S102, the target object can be a terminal or a user account.
[0039] In the above step S102, the single sign-on request can be an access request for the target object to re-access the logged-in application system.
[0040] In the above step S102, the single-point ticket is the login credential obtained by the target object after logging in to the application system for the first time.
[0041] In the above step S102, the single-point ciphertext includes an encrypted single-point ticket and encrypted user information.
[0042] Optionally, the single-point plaintext can be obtained by splicing the single-point bill and user information of the target object, and the single-point ciphertext is the single-point ciphertext logged in using the target secret key.
[0043] In the above step S104, the first preset storage space can be the cache of the device for temporarily storing the preset secret key, where the preset secret key stored in the first preset storage space is updated according to a preset time period.
[0044] In the above step S108, the system requested to log in by the single-point login request is the application system that the target object has logged in.
[0045] Optionally, the above steps S102 to S108 are applied to the receiving end of the single-point login request.
[0046] As an optional embodiment, the secret key identifier is a binary value. Querying the target secret key indicated by the secret key identifier in the first preset storage space includes: identifying the parity of the secret key identifier; according to the parity of the secret key identifier, querying the target secret key indicated by the secret key identifier in the first preset storage space, where a first preset secret key corresponding to an odd secret key identifier and a second preset secret key corresponding to an even secret key identifier are pre-stored in the first preset storage space, and the update periods of the first preset secret key and the second preset secret key are adjacent.
[0047] In the above embodiments of the present invention, the first preset storage space can store the preset secret keys of the two most recent adjacent secret key update periods when the secret key identifier is a binary value, and thus the target secret key indicated by the secret key identifier can be quickly determined by identifying the parity of the secret key identifier.
[0048] Optionally, the odd secret key identifier is an odd secret key update period with an odd number of update times, and the even secret key identifier is an even secret key update period with an even number of update times.
[0049] It should be noted that when the secret key identifier is a binary value, the secret key identifier is a parity check bit. By adding a parity check bit (i.e., the secret key identifier) to the single-point ciphertext, the target secret key corresponding to the single-point ciphertext can be directly determined, eliminating the process of cyclic traversal and improving the decryption efficiency.
[0050] As an optional embodiment, before querying the target secret key indicated by the secret key identifier in the first preset storage space, the method further includes: obtaining the pre-configured secret key update period and secret key update rule; determining the preset secret key corresponding to each secret key update period according to the secret key update period and the secret key update rule; determining the secret key identifier of each preset secret key according to the secret key update period.
[0051] In the above embodiments of the present invention, the preset secret key stored in the first preset storage space can be updated according to the preconfigured secret key update period and secret key update rule, and the preset secret key corresponding to each secret key update period is determined, realizing the automatic update of the preset secret key.
[0052] As an optional embodiment, determining the preset secret key corresponding to each secret key update period according to the secret key update period and secret key update rule includes: obtaining the first secret key of the first secret key period; using the first secret key as the seed secret key, and calculating the second secret key of the second secret key period based on the secret key update rule, where the second secret key period is adjacent to the first secret key period and the second secret key period is later than the first secret key period.
[0053] In the above embodiments of the present invention, the first secret key period and the second secret key period are adjacent secret key update periods, and the second secret key period is later than the first secret key period. The second secret key corresponding to the second secret key period can be updated based on the first secret key corresponding to the first secret key period.
[0054] As an optional embodiment, when the first secret key period is the initial secret key period, the first secret key is the preconfigured initial secret key.
[0055] In the above embodiments of the present invention, when the first secret key period is the initial secret key period, the first secret key is the preconfigured initial secret key. Based on the secret key update rule, the preset secret key corresponding to each secret key update period can be calculated using the initial secret key.
[0056] As an optional embodiment, using the first secret key as the seed secret key and calculating the second secret key of the second secret key period based on the secret key update rule includes: obtaining the preset mixed congruence parameters in the secret key update rule, where the preset mixed congruence parameters include: the first preset parameter, the second preset parameter, and the third preset parameter; using the first secret key as the seed secret key and determining the product of the seed secret key and the first preset parameter; dividing the sum of the product and the second preset parameter by the third preset parameter to obtain the remainder of the division calculation; and using the remainder as the second secret key.
[0057] Optionally, the secret key update rule can update the secret key according to the mixed congruence algorithm.
[0058] Optionally, the mixed congruence algorithm is a pseudo-random number generator algorithm. Assume that the pseudo-random number sequence to be generated is R0, R1, R2...
[0059] Figure 2 is a schematic diagram of generating pseudo-random numbers according to a mixed congruence algorithm of an embodiment of the present application. As Figure 2 shown, according to the seed secret key of the pseudo-random number, the first pseudo-random number R0 is calculated using the following formula, that is, the second secret key is calculated according to the first secret key.
[0060] R0 = (A * Seed Key + C) mod M
[0061] Among them, the first preset parameter A, the second preset parameter C, and the third preset parameter M are all constants, and the first preset parameter A and the second preset parameter C need to be less than the third preset parameter M. Then, the next pseudo-random number R1 is calculated using the same formula based on R0.
[0062] R1 = (A * R0 + C) mod M
[0063] Next, in the same way, the next pseudo-random number R(n + 1) is calculated based on the current pseudo-random number Rn.
[0064] R(n + 1) = (A * Rn + C) mod M
[0065] In short, the mixed congruence method is to multiply the current pseudo-random number (i.e., the first key) by the first preset parameter A and then add the second preset parameter C, and then use the remainder obtained by dividing by the third preset parameter M as the next pseudo-random number (i.e., the second key). In the mixed congruence algorithm, the value of the most recently generated pseudo-random number is the internal state, and the seed of the pseudo-random number is used to initialize the internal state.
[0066] It should be noted that the characteristics of the mixed congruence algorithm are:
[0067] 1. The maximum capacity of the random number is M, and M generally takes the maximum value of the key binary length. For example, if the AES algorithm key is assumed to be 128 bits, the value range is 2 128 .
[0068] 2. The independence and uniformity both depend on the first preset parameter A and the second preset parameter C.
[0069] Optionally, the conditions for the pseudo-random number to have the maximum capacity of the third preset parameter M are:
[0070] 1. The parameter second preset parameter C and the third preset parameter M are relatively prime.
[0071] 2. Let P be the common divisor of A - 1 and M, and A - 1 mod P == 0.
[0072] 3. If M is a multiple of 4, A - 1 is also a multiple of 4.
[0073] Optionally, for the dynamic key generation method based on mixed congruence, the preset key will change irregularly within a certain range according to a period.
[0074] As an optional embodiment, determining the key identifier of each preset key according to the key update period includes: determining the number of key updates for the target key period according to the key update period; determining the key identifier of the preset key corresponding to the target key period according to the number of key updates.
[0075] In the above embodiments of the present invention, the preset secret key corresponding to each secret key update period can be determined according to the number of secret key updates in the secret key update period where the preset secret key is located.
[0076] Figure 3 is the process of a single sign-on method according to an embodiment of the present application Figure 2 , such as Figure 3 shown, the method includes the following steps:
[0077] Step S302, obtain an access request of a target object, where the access request carries login information, the initiation time of the access request, and a single-point link of the access object, and the login information includes at least a single-point ticket, and the single-point ticket is a login credential of the target object;
[0078] Step S304, query the target secret key corresponding to the initiation time and the secret key identifier of the target secret key in a second preset storage space, where the second preset storage space stores one or more preset secret keys updated according to a preset period and the secret key identifier of each preset secret key;
[0079] Step S306, encrypt the login credential according to the target secret key to generate a single-point ciphertext;
[0080] Step S308, splice the single-point ciphertext and the secret key identifier into the single-point link to generate a single-point login request for the access object.
[0081] In the embodiment of the present application, receive a single-point login request of a target object, where the single-point login request carries a single-point ciphertext and a secret key identifier, and the single-point ciphertext includes at least an encrypted single-point ticket, and the single-point ticket is a login credential of the target object; query the target secret key indicated by the secret key identifier in a first preset storage space, where the first preset storage space stores one or more preset secret keys updated according to a preset period and the secret key identifier of each preset secret key; decrypt the single-point ciphertext based on the target secret key to obtain a single-point ticket; perform uniqueness verification on the single-point ticket, where, if the single-point ticket is unique, it is determined to allow the target object to log in to the system requested by the single-point login request, so that the single sign-on process does not need to call the interface of the authentication system, realizing the decentralization of the entire single-point cluster, no longer relying on the authentication service, achieving the technical effect of improving the stability of the entire single-point cluster. Since there is no need for each party to debug the single-point interface, each system can have non-interconnected networks and directly transmit ciphertext over the public network https, thus eliminating the risk at the network level of the system, and further solving the technical problem of poor authentication stability due to the existing single sign-on relying on a centralized authentication service.
[0082] Optionally, the above steps S302 to S308 are applied to the sending end of the single-point login request.
[0083] Optionally, the sender and the receiver can update the preset secret key according to the same secret key update rule and secret key update period.
[0084] This application also provides a preferred embodiment, which provides a P2P dynamic single sign-on solution based on mixed congruence.
[0085] The purpose of this application is to construct a decentralized single-point cluster. After receiving the single-point ticket, the receiver does not need to call the interface of the authentication system, realizing the decentralization of the entire single-point cluster, no longer relying on the authentication service, improving the stability of the entire single-point cluster. Since there is no need for each party to debug the single-point interface, each system can have non-interconnected networks and directly transmit ciphertext through the public network https, thus eliminating the risks at the network level of the system.
[0086] This application provides a set of fast and secure single-point methods, decoupling from the existing single-point technologies, improving the stability of the single-point cluster, and enhancing the security of the single-point cluster by regularly updating the secret key. When a user single-points from the initiator to the receiver, after receiving the single-point request from the initiator, the receiver converts the ciphertext into a binary string, determines the secret key according to the parity check bit, then decrypts it using the secret key, and then obtains the user information and the single-point ticket. Then, it performs a uniqueness check on the single-point ticket. If the check passes, the single-point is successful. Each system only needs to follow the unified encryption specification during single-pointing, without the need to dock with the interface, reducing the development workload.
[0087] As an optional embodiment, the P2P dynamic single-point system based on mixed congruence includes: a sender and a receiver.
[0088] Optionally, the sender pre-sets information such as the initial secret key, the secret key update period, and the preset mixed congruence parameters, and agrees with the receiver on the same encryption algorithm.
[0089] Optionally, the sender determines the user and the receiver who need to perform single sign-on and executes the business logic.
[0090] Optionally, the sender can generate a single-point ticket, assemble the single-point ticket and the user information into plaintext, encrypt it using the encryption algorithm based on the target secret key to obtain a temporary ciphertext (i.e., the single-point ciphertext), add the parity check bit after temporarily converting it to binary, and then convert it to a byte stream as the final ciphertext, assemble it into the single-point link, generate a single sign-on request, and redirect it to the receiver.
[0091] Optionally, the receiver pre-sets the same initial secret key, secret key update period, preset mixed congruence parameters, etc. as the sender, and agrees with the sender on the same encryption algorithm.
[0092] Optionally, the receiving end receives the single sign-on request from the sending end, converts the byte stream in the single sign-on request into binary, obtains the single-point ciphertext and the key identifier (i.e., the value of the parity check bit), determines the target key based on the key identifier (i.e., the value of the parity check bit) to decrypt the single-point ciphertext, obtains the single-point ticket and the user information as plaintext, and then verifies the uniqueness of the single-point ticket.
[0093] Optionally, after the user's single sign-on is successful, the receiving end continues to execute relevant service functions according to the user information.
[0094] As an optional embodiment, based on the P2P dynamic single-point scheme of mixed congruence, the single-point specifications are as follows:
[0095] 1. The sending end and the receiving end agree on the same initial key, and the same symmetric encryption algorithm is used for encryption and decryption.
[0096] 2. The sending end and the receiving end set the same preset mixed congruence parameters for periodically updating the key.
[0097] 3. The sending end generates a random single-point ticket in the format of a 32-bit hexadecimal random number UUID.
[0098] 4. The sending end and the receiving end periodically update the key according to the key update period and the preset mixed congruence parameters, and record the key values of the current key update period and the previous key update period.
[0099] 5. The sending end calculates the parity check bits (i.e., the key identifiers) of the current key update period and the previous key update period according to the system time and the key update period. The iteration number (i.e., the update number) = the floor division of the time minute difference by the period minute number, and the parity check bit (i.e., the key identifier) = the iteration number (i.e., the update number) mod 2. The parity check bit (i.e., the key identifier) is default assembled at the last binary bit of the single-point ciphertext.
[0100] 6. The receiving end confirms the target key according to the parity check bit (i.e., the key identifier), and then decrypts and verifies the uniqueness of the single-point ticket.
[0101] 7. The same system can be used as both the sending end and the receiving end.
[0102] Figure 4 is a schematic diagram of a single-point process according to an embodiment of the present application. As Figure 4 shown, the single-point process includes:
[0103] 1. The user logs in to the sending end and clicks the single-point link to generate an access request.
[0104] 2. The sending end generates a 32-bit hexadecimal random number UUID as the single-point ticket, and then assembles the user information as the single-point plaintext.
[0105] 3. The sender obtains the target key for the current key update period, the cycle parity bit (i.e., the key identifier of the target key), encrypts the single-point plaintext using the target key for the current key update period to obtain a temporary ciphertext, then converts it into a binary number to obtain the single-point ciphertext, then assembles the parity bit (i.e., the key identifier), converts it into a byte stream, and then performs base64 encoding to obtain the final ciphertext.
[0106] 4. The sender assembles the final ciphertext into the single-point link and redirects it to the receiver.
[0107] 5. The receiving system receives the single-point login request, converts the final ciphertext into a binary number, obtains the value of the parity bit (i.e., the key identifier) and the single-point ciphertext, confirms the target key for decryption, and decrypts the single-point ciphertext based on the target key to obtain the single-point ticket and user information.
[0108] 6. The receiver verifies the uniqueness of the single-point ticket. If the ticket has been used, the single-point login fails.
[0109] 7. The receiver sets the user login to be successful, sets the single-point ticket to be deposited in the cache and marks it as used, and the cache time is the single-point timeliness time, and continues the subsequent business process.
[0110] As an optional embodiment, for the P2P dynamic single-point scheme based on mixed congruence, the key regular update logic is as follows:
[0111] 1. Each system agrees on the same initial key K0 and initial time T0, and uses a unified symmetric encryption algorithm for encryption and decryption.
[0112] 2. Each system agrees on the same preset mixed congruence parameters. Among them, the preset mixed congruence parameters include the first preset parameter A, the second preset parameter C, and the third preset parameter M, and uses the initial key K0 as the seed key.
[0113] 3. Each system agrees on the same key update period C (unit: minute), and 60 mod C == 0.
[0114] 4. When each system starts, set the current key update period time to T. Then the iteration number (i.e., the update number) N = (T - T0) / / C, and the parity bit (i.e., the key identifier) P = N mod 2. Substitute it into the mixed congruence algorithm (i.e., the key update rule) and execute it N times in a loop, then the key for the current key update period can be obtained. If P is odd, it is set as the odd-period key KP1, otherwise it is set as the even-period key KP0.
[0115] 5. Each system calculates the parity bit (i.e., the key identifier) of the current key update period every C minutes within one hour, and sets the current key update period time as T. Then, the parity bit (i.e., the key identifier) P = ((T - T0) / / C) mod 2.
[0116] 6. Each system executes a preset mixed congruential algorithm to update the preset key every C minutes within one hour, and obtains the preset key K1 of the current key update period. K = (A * K0 + C) mod M. Combining with the value of the parity bit (i.e., the key identifier) P obtained in the previous step, if the parity bit (i.e., the key identifier) P is odd, it is set as KP1, otherwise it is set as KP0.
[0117] 7. When the system restarts, it only needs to iterate from KP1 or KP0. Assuming it iterates from KP0, the number of iterations N = (T - T kp0 ) / / C. If N is even, the parity bit (i.e., the key identifier) is the same as KP0. If N is odd, the parity bit (i.e., the key identifier) is opposite to KP0. Therefore, when the system restarts, it will iterate from the previous key update period without iterating from the initial key and initial time.
[0118] 8. Each system needs to save the key KP1 of the odd period and the key KP0 of the even period, and their generation times.
[0119] 9. The receiving end determines the target key according to the parity bit (i.e., the key identifier) of the ciphertext and then decrypts it. Therefore, the single-point validity period < 2 * C.
[0120] It should be noted that 60 mod C == 0. Since it is necessary to ensure the synchronous update of the keys of each system, and the startup times of each system are inconsistent, the strategy of updating the keys with an interval period C within one hour is used. Therefore, C should be able to divide 60 minutes.
[0121] Optionally, the number of iterations (i.e., the update times) N = (T - T0) / / C, where T - T0 is the minute difference between the current key update time and the initial time. Dividing the baseboard by the key update period C gives the number of iterations (i.e., the update times).
[0122] Optionally, the parity bit (i.e., the key identifier) P = N mod 2, where the number of iterations (i.e., the key identifier) N is taken modulo 2. 1 is odd and 0 is even.
[0123] Optionally, the single-point validity period < 2 * C. Each system only saves the latest KP0 and KP1. If the single-point validity period > 2C, the system cannot find the corresponding key for decryption.
[0124] It should be noted that traditional single-point dependent centralized authentication services provide authentication services and single-point functions. Each system needs to establish a network docking interface with the authentication service, resulting in a high degree of coupling among them. The load pressure on the authentication service is relatively large. Once it fails, the single-point functions of all systems in the cluster will fail.
[0125] For the technical solution claimed in this application, the single point of P2P does not depend on a certain centralized service. It directly goes from single point of system A to system B, and both parties only need to follow a common encryption algorithm.
[0126] The preset secret key is updated regularly, and the third preset parameter M can be set to 2 128 , combined with the preset mixed congruence parameter, can make the preset secret key randomly distributed within 2 128 . Even if the secret key of a certain period is cracked, due to the unknown preset mixed congruence parameter, it is still impossible to crack the ciphertext of the subsequent period, greatly improving the security of the system.
[0127] For the sake of easy understanding, the following is a complete description of the change process of the entire secret key update cycle.
[0128] Suppose the first preset parameter A = 3, the second preset parameter C = 0, and the third preset parameter M = 7. Taking 6 as the seed of the pseudo-random number (i.e., the seed secret key), the process of generating the pseudo-random number sequence is as follows:
[0129] R1 = (3 * 6 + 0) mod 7 = 4
[0130] R2 = (3 * 4 + 0) mod 7 = 5
[0131] R3 = (3 * 5 + 0) mod 7 = 1
[0132] R4 = (3 * 1 + 0) mod 7 = 3
[0133] R5 = (3 * 3 + 0) mod 7 = 2
[0134] R6 = (3 * 2 + 0) mod 7 = 6
[0135] R7 = (3 * 6 + 0) mod 7 = 4
[0136] And so on, a pseudo-random number sequence like 4, 5, 1, 3, 2, 6, 4, 5, 1, 3, 2, 6... can be obtained. Here, the sequence cycles continuously in the order of 4, 5, 1, 3, 2, 6, with a period of 6. In an actual production environment, M generally takes the maximum value of the binary length of the secret key. For example, a 16-bit hexadecimal secret key corresponds to 128-bit binary, and the maximum value is 2 128 , the second preset parameter C and the third preset parameter M are relatively prime, and A - 1 and M are relatively prime.
[0137] According to an embodiment of the present application, an embodiment of a single sign-on device is further provided. It should be noted that this single sign-on device can be used to execute the single sign-on method in the embodiment of the present application, and the single sign-on method in the embodiment of the present application can be executed in this single sign-on device.
[0138] Figure 5 is a schematic diagram of a single sign-on device according to an embodiment of the present application Figure 1 , such as Figure 5 shown, the device may include: a receiving module 52, configured to receive a single sign-on request of a target object, where the single sign-on request carries a single sign-on ciphertext and a secret key identifier, and the single sign-on ciphertext at least includes an encrypted single sign-on ticket, and the single sign-on ticket is a login credential of the target object; a decryption query module 54, configured to query a target secret key indicated by the secret key identifier in a first preset storage space, where the first preset storage space stores one or more preset secret keys updated according to a preset period and the secret key identifier of each preset secret key; a decryption module 56, configured to decrypt the single sign-on ciphertext based on the target secret key to obtain a single sign-on ticket; a verification module 58, configured to perform uniqueness verification on the single sign-on ticket, where if the single sign-on ticket is unique, it is determined to allow the target object to log in to the system requested by the single sign-on request.
[0139] It should be noted that the receiving module 52 in this embodiment can be used to execute step S102 in the embodiment of the present application, the decryption query module 54 in this embodiment can be used to execute step S104 in the embodiment of the present application, the decryption module 56 in this embodiment can be used to execute step S106 in the embodiment of the present application, and the verification module 58 in this embodiment can be used to execute step S108 in the embodiment of the present application. The examples and application scenarios implemented by the above modules and the corresponding steps are the same, but are not limited to the content disclosed in the above embodiments.
[0140] In the embodiment of the present application, a single sign-on request of a target object is received. The single sign-on request carries a single-point ciphertext and a key identifier. The single-point ciphertext at least includes an encrypted single-point ticket, and the single-point ticket is a login credential of the target object. Query the target key indicated by the key identifier in the first preset storage space, where the first preset storage space stores one or more preset keys updated according to a preset period and the key identifiers of each preset key. Decrypt the single-point ciphertext based on the target key to obtain the single-point ticket. Perform uniqueness verification on the single-point ticket. In the case where the single-point ticket is unique, it is determined to allow the target object to log in to the system requested by the single sign-on request, enabling the single sign-on process to not require calling the interface of the authentication system, achieving the decentralization of the entire single-point cluster, no longer relying on the authentication service, and achieving the technical effect of improving the stability of the entire single-point cluster. Since there is no need for each party to debug the single-point interface, each system can have non-interconnected networks and directly transmit the ciphertext through the public network https, thus eliminating the risks at the network level of the system, and further solving the technical problem of poor authentication stability due to the existing single sign-on relying on a centralized authentication service.
[0141] As an optional embodiment, the key identifier is a binary value. The query module includes: an identification unit for identifying the parity of the key identifier; a query unit for querying the target key indicated by the key identifier in the first preset storage space according to the parity of the key identifier. The first preset storage space pre-stores a first preset key corresponding to an odd key identifier and a second preset key corresponding to an even key identifier, and the update periods of the first preset key and the second preset key are adjacent.
[0142] As an optional embodiment, the device further includes: an acquisition sub-module for acquiring the pre-configured key update period and key update rule before querying the target key indicated by the key identifier in the first preset storage space; a first determination sub-module for determining the preset key corresponding to each key update period according to the key update period and the key update rule; a second determination sub-module for determining the key identifier of each preset key according to the key update period.
[0143] As an optional embodiment, the first determination sub-module includes: an acquisition unit for acquiring the first key of the first key period; a calculation unit for using the first key as a seed key to calculate the second key of the second key period based on the key update rule, where the second key period is adjacent to the first key period and the second key period is later than the first key period.
[0144] As an alternative embodiment, the computing unit includes: an obtaining subunit configured to obtain preset mixed congruence parameters in a key update rule, where the preset mixed congruence parameters include: a first preset parameter, a second preset parameter, and a third preset parameter; a first calculation subunit configured to use a first key as a seed key and determine a product of the seed key and the first preset parameter; a second calculation subunit configured to divide a sum of the product and the second preset parameter by the third preset parameter to obtain a remainder of the division calculation; and a determination subunit configured to use the remainder as a second key.
[0145] As an alternative embodiment, when the first key period is an initial key period, the first key is a preconfigured initial key.
[0146] As an alternative embodiment, the second determination submodule includes: a first determination unit configured to determine a key update count for a target key period according to a key update period; and a second determination unit configured to determine a key identifier of a preset key corresponding to the target key period according to the key update count.
[0147] Figure 6 is a schematic diagram of a single sign-on device according to an embodiment of the present application Figure 2 , such as Figure 6 shown, the device may include: an obtaining module 62 configured to obtain an access request of a target object, where the access request carries login information, an initiation time of the access request, and a single-point link of the access object, and the login information includes at least a single-point ticket, and the single-point ticket is a login credential of the target object; an encryption query module 64 configured to query, in a second preset storage space, a target key corresponding to the initiation time and a key identifier of the target key, where the second preset storage space stores one or more preset keys updated according to a preset period and a key identifier of each preset key; an encryption module 66 configured to encrypt the login credential according to the target key to generate a single-point ciphertext; and a generation module 68 configured to splice the single-point ciphertext and the key identifier into the single-point link to generate a single sign-on request for the access object.
[0148] It should be noted that the obtaining module 62 in this embodiment may be configured to execute step S202 in the embodiment of the present application, the encryption query module 64 in this embodiment may be configured to execute step S204 in the embodiment of the present application, the encryption module 66 in this embodiment may be configured to execute step S206 in the embodiment of the present application, and the generation module 68 in this embodiment may be configured to execute step S208 in the embodiment of the present application. The examples and application scenarios implemented by the above modules and the corresponding steps are the same, but are not limited to the content disclosed in the above embodiments.
[0149] In an embodiment of the present application, a single sign-on request of a target object is received. The single sign-on request carries a single-point ciphertext and a key identifier. The single-point ciphertext at least includes an encrypted single-point ticket, and the single-point ticket is a login credential of the target object. Query the target key indicated by the key identifier in a first preset storage space, where the first preset storage space stores one or more preset keys updated according to a preset period and the key identifier of each preset key. Decrypt the single-point ciphertext based on the target key to obtain the single-point ticket. Perform a uniqueness check on the single-point ticket. If the single-point ticket is unique, it is determined to allow the target object to log in to the system requested by the single sign-on request. This enables the single sign-on process to avoid calling the interface of the authentication system, achieving decentralization of the entire single-point cluster and no longer relying on the authentication service, thus achieving the technical effect of improving the stability of the entire single-point cluster. Since there is no need for each party to debug the single-point interface, each system can communicate without a network connection and directly transmit the ciphertext via public network https, thereby eliminating the risk at the network level of the system and solving the technical problem of poor authentication stability due to the existing single sign-on relying on a centralized authentication service.
[0150] An embodiment of the present application can provide a computer terminal, which can be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the above computer terminal can also be replaced with a terminal device such as a mobile terminal.
[0151] Optionally, in this embodiment, the above computer terminal can be located in at least one of multiple network devices in a computer network.
[0152] In this embodiment, the above computer terminal can execute the program code of the following steps in the single sign-on method: receive a single sign-on request of a target object, where the single sign-on request carries a single-point ciphertext and a key identifier, the single-point ciphertext at least includes an encrypted single-point ticket, and the single-point ticket is a login credential of the target object; query the target key indicated by the key identifier in a first preset storage space, where the first preset storage space stores one or more preset keys updated according to a preset period and the key identifier of each preset key; decrypt the single-point ciphertext based on the target key to obtain the single-point ticket; perform a uniqueness check on the single-point ticket. If the single-point ticket is unique, it is determined to allow the target object to log in to the system requested by the single sign-on request.
[0153] In this embodiment, the above computer terminal may execute the program code of the following steps in the single sign-on method: obtain an access request of a target object, where the access request carries login information, the initiation time of the access request, and a single-point link of the access object, and the login information includes at least a single-point ticket, and the single-point ticket is a login credential of the target object; query, in a second preset storage space, a target secret key corresponding to the initiation time and a secret key identifier of the target secret key, where the second preset storage space stores one or more preset secret keys updated according to a preset period and the secret key identifier of each preset secret key; encrypt the login credential with the target secret key to generate a single-point ciphertext; splice the single-point ciphertext and the secret key identifier into the single-point link to generate a single sign-on request for the access object.
[0154] Optionally, Figure 7 is a structural block diagram of a computer terminal according to an embodiment of the present application. As Figure 7 shown, the computer terminal 70 may include: one or more (only one is shown in the figure) processors 72 and a memory 74.
[0155] Among them, the memory may be used to store software programs and modules, such as program instructions / modules corresponding to the single sign-on method and device in the embodiment of the present application. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the above single sign-on method. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely disposed relative to the processor, and these remote memories may be connected to the terminal 70 through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0156] The processor may call the information and application programs stored in the memory through a transmission device to execute the following steps: receive a single sign-on request of a target object, where the single sign-on request carries a single-point ciphertext and a secret key identifier, and the single-point ciphertext includes at least an encrypted single-point ticket, and the single-point ticket is a login credential of the target object; query, in a first preset storage space, a target secret key indicated by the secret key identifier, where the first preset storage space stores one or more preset secret keys updated according to a preset period and the secret key identifier of each preset secret key; decrypt the single-point ciphertext with the target secret key to obtain a single-point ticket; perform a uniqueness check on the single-point ticket, where if the single-point ticket is unique, it is determined to allow the target object to log in to the system requested by the single sign-on request.
[0157] Optionally, the key identifier is a binary value, and the above-mentioned processor can also execute the program code of the following steps: identify the parity of the key identifier; according to the parity of the key identifier, query the target key indicated by the key identifier in the first preset storage space, where a first preset key corresponding to an odd key identifier and a second preset key corresponding to an even key identifier are pre-stored in the first preset storage space, and the update periods of the first preset key and the second preset key are adjacent.
[0158] Optionally, the above-mentioned processor can also execute the program code of the following steps: before querying the target key indicated by the key identifier in the first preset storage space, obtain the pre-configured key update period and key update rule; according to the key update period and the key update rule, determine the preset key corresponding to each key update period; determine the key identifier of each preset key according to the key update period.
[0159] Optionally, the above-mentioned processor can also execute the program code of the following steps: obtain the first key of the first key period; use the first key as the seed key and calculate the second key of the second key period based on the key update rule, where the second key period is adjacent to the first key period and the second key period is later than the first key period.
[0160] Optionally, the above-mentioned processor can also execute the program code of the following steps: obtain the preset mixed congruence parameters in the key update rule, where the preset mixed congruence parameters include: a first preset parameter, a second preset parameter, and a third preset parameter; use the first key as the seed key and determine the product of the seed key and the first preset parameter; divide the sum of the product and the second preset parameter by the third preset parameter to obtain the remainder of the division calculation; use the remainder as the second key.
[0161] Optionally, when the first key period is the initial key period, the first key is the pre-configured initial key.
[0162] Optionally, the above-mentioned processor can also execute the program code of the following steps: determine the number of key updates in the target key period according to the key update period; determine the key identifier of the preset key corresponding to the target key period according to the number of key updates.
[0163] The processor can call the information and application programs stored in the memory through a transmission device to execute the following steps: obtain an access request of a target object, where the access request carries login information, the initiation time of the access request, and a single-point link of the access object, and the login information includes at least a single-point ticket, and the single-point ticket is a login credential of the target object; query a target secret key corresponding to the initiation time and a secret key identifier of the target secret key in a second preset storage space, where the second preset storage space stores one or more preset secret keys updated according to a preset period and a secret key identifier of each preset secret key; encrypt the login credential according to the target secret key to generate a single-point ciphertext; splice the single-point ciphertext and the secret key identifier into the single-point link to generate a single-point login request for the access object.
[0164] By adopting the embodiment of the present application, a single-point login scheme is provided. Receive a single-point login request of a target object, where the single-point login request carries a single-point ciphertext and a secret key identifier, and the single-point ciphertext includes at least an encrypted single-point ticket, and the single-point ticket is a login credential of the target object; query a target secret key indicated by the secret key identifier in a first preset storage space, where the first preset storage space stores one or more preset secret keys updated according to a preset period and a secret key identifier of each preset secret key; decrypt the single-point ciphertext based on the target secret key to obtain a single-point ticket; perform uniqueness verification on the single-point ticket. Wherein, when the single-point ticket is unique, it is determined that the target object is allowed to log in to the system requested by the single-point login request, so that the single-point login process does not need to call the interface of the authentication system, realizing the decentralization of the entire single-point cluster, no longer relying on the authentication service, achieving the technical effect of improving the stability of the entire single-point cluster. Since there is no need for each party to debug the single-point interface, each system can have non-interconnected networks and directly transmit ciphertext through public network https, thus eliminating the risks at the network level of the system, and further solving the technical problem of poor authentication stability due to the existing single-point login relying on a centralized authentication service.
[0165] Those of ordinary skill in the art can understand that Figure 7 The structure shown is only for illustration, and the computer terminal can also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a palm computer, and terminal devices such as Mobile Internet Devices (MID), PAD, etc. Figure 7 It does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 7 may further include more or fewer components (such as a network interface, a display device, etc.) than those shown Figure 7 in, or have a different configuration from that shown Figure 7 in.
[0166] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by a program instructing the hardware related to the terminal device. The program can be stored in a computer-readable storage medium, and the storage medium can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, an optical disk, etc.
[0167] An embodiment of the present application further provides a storage medium. Optionally, in this embodiment, the above storage medium can be used to store the program code executed by the single sign-on method provided in the above embodiment.
[0168] Optionally, in this embodiment, the above storage medium can be located in any one of the computer terminals in the computer terminal group in the computer network, or in any one of the mobile terminals in the mobile terminal group.
[0169] Optionally, in this embodiment, the storage medium is set to store program code for performing the following steps: receiving a single sign-on request of a target object, where the single sign-on request carries a single sign-on ciphertext and a key identifier, the single sign-on ciphertext at least includes an encrypted single sign-on ticket, and the single sign-on ticket is the login credential of the target object; querying the target key indicated by the key identifier in a first preset storage space, where the first preset storage space stores one or more preset keys updated according to a preset period and the key identifier of each preset key; decrypting the single sign-on ciphertext based on the target key to obtain the single sign-on ticket; performing a uniqueness check on the single sign-on ticket, where if the single sign-on ticket is unique, it is determined to allow the target object to log in to the system requested by the single sign-on request.
[0170] Optionally, in this embodiment, the key identifier is a binary value, and the storage medium is set to store program code for performing the following steps: identifying the parity of the key identifier; according to the parity of the key identifier, querying the target key indicated by the key identifier in the first preset storage space, where the first preset storage space pre-stores a first preset key corresponding to an odd key identifier and a second preset key corresponding to an even key identifier, and the update periods of the first preset key and the second preset key are adjacent.
[0171] Optionally, in this embodiment, the storage medium is set to store program code for performing the following steps: before querying the target key indicated by the key identifier in the first preset storage space, obtaining a pre-configured key update period and a key update rule; determining the preset key corresponding to each key update period according to the key update period and the key update rule; determining the key identifier of each preset key according to the key update period.
[0172] Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps: obtaining a first secret key for a first secret key period; using the first secret key as a seed secret key, calculating a second secret key for a second secret key period based on a secret key update rule, where the second secret key period is adjacent to the first secret key period and the second secret key period is later than the first secret key period.
[0173] Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps: obtaining preset mixed congruence parameters in the secret key update rule, where the preset mixed congruence parameters include: a first preset parameter, a second preset parameter, and a third preset parameter; using the first secret key as a seed secret key, determining the product of the seed secret key and the first preset parameter; dividing the sum of the product and the second preset parameter by the third preset parameter to obtain the remainder of the division calculation; using the remainder as the second secret key.
[0174] Optionally, in this embodiment, when the first secret key period is the initial secret key period, the first secret key is a pre-configured initial secret key.
[0175] Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps: determining the number of secret key updates for a target secret key period according to the secret key update period; determining the secret key identifier of the preset secret key corresponding to the target secret key period according to the number of secret key updates.
[0176] Optionally, in this embodiment, the storage medium is configured to store program code for performing the following steps: obtaining an access request for a target object, where the access request carries login information, the initiation time of the access request, and a single-point link to the access object, and the login information includes at least a single-point ticket, and the single-point ticket is the login credential of the target object; querying the target secret key corresponding to the initiation time and the secret key identifier of the target secret key in a second preset storage space, where the second preset storage space stores one or more preset secret keys updated according to a preset period and the secret key identifier of each preset secret key; encrypting the login credential using the target secret key to generate a single-point ciphertext; splicing the single-point ciphertext and the secret key identifier into the single-point link to generate a single-point login request for the access object.
[0177] The serial numbers of the embodiments of the present application above are only for description and do not represent the advantages or disadvantages of the embodiments.
[0178] In the above embodiments of the present application, the descriptions of the various embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.
[0179] In several embodiments provided by the present application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are merely illustrative. For example, the division of the units can be a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the couplings or direct couplings or communication connections shown or discussed with each other can be through some interfaces. The indirect couplings or communication connections of units or modules can be in electrical or other forms.
[0180] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place or distributed to multiple units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0181] In addition, in each embodiment of the present application, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0182] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the related technology, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of the present application. The foregoing storage medium includes: various media such as USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs that can store program codes.
[0183] The above are only the preferred embodiments of the present application. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present application.
Claims
1. A single sign-on method, characterized in that, Including: Receiving a single sign-on request of a target object, where the single sign-on request carries a single-point ciphertext and a key identifier, and the single-point ciphertext at least includes an encrypted single-point ticket, and the single-point ticket is a login credential of the target object; Querying a target key indicated by the key identifier in a first preset storage space, where the first preset storage space stores one or more preset keys updated according to a preset period and the key identifier of each preset key; Decrypting the single-point ciphertext based on the target key to obtain the single-point ticket; Performing uniqueness verification on the single-point ticket, where if the single-point ticket is unique, it is determined to allow the target object to log in to the system requested by the single sign-on request; Wherein, before querying the target key indicated by the key identifier in the first preset storage space, the method further includes: Obtaining a pre-configured key update period and a key update rule; Determining a preset key corresponding to each key update period according to the key update period and the key update rule; Determining the key identifier of each preset key according to the key update period; Wherein, determining a preset key corresponding to each key update period according to the key update period and the key update rule includes: Obtaining a first key of a first key period; Using the first key as a seed key, and calculating a second key of a second key period based on the key update rule, where the second key period is adjacent to the first key period and the second key period is later than the first key period.
2. The method according to claim 1, characterized in that, The key identifier is a binary value, and querying the target key indicated by the key identifier in the first preset storage space includes: Identifying the parity of the key identifier; Querying the target key indicated by the key identifier in the first preset storage space according to the parity of the key identifier, where the first preset storage space pre-stores a first preset key corresponding to an odd key identifier and a second preset key corresponding to an even key identifier, and the update periods of the first preset key and the second preset key are adjacent.
3. The method according to claim 1, wherein Determining the key identifier of each preset key according to the key update period includes: Determining the number of key updates of a target key period according to the key update period; Determining the key identifier of the preset key corresponding to the target key period according to the number of key updates.
4. A single sign-on method, characterized in that, Including: Obtaining an access request of a target object, where the access request carries login information, the initiation time of the access request, and a single-point link of the access object, and the login information at least includes a single-point ticket, and the single-point ticket is a login credential of the target object; Querying the target key corresponding to the initiation time and the key identifier of the target key in a second preset storage space, where the second preset storage space stores one or more preset keys updated according to a preset period and the key identifier of each preset key; Encrypting the login credential based on the target key to generate a single-point ciphertext; Splice the single-point ciphertext and the key identifier into the single-point link to generate a single-sign-on request for the access object; Wherein, the method further includes: Obtain a pre-configured key update period and a key update rule; Determine a preset key corresponding to each key update period according to the key update period and the key update rule; Determine the key identifier of each preset key according to the key update period; Wherein, determining a preset key corresponding to each key update period according to the key update period and the key update rule includes: Obtain the first key of the first key period; Use the first key as a seed key, and calculate the second key of the second key period based on the key update rule, wherein the second key period is adjacent to the first key period, and the second key period is later than the first key period.
5. A single sign-on device, characterized in that, Includes: A receiving module, configured to receive a single-sign-on request of a target object, wherein the single-sign-on request carries a single-point ciphertext and a key identifier, and the single-point ciphertext at least includes an encrypted single-point ticket, and the single-point ticket is a login credential of the target object; A decryption query module, configured to query a target key indicated by the key identifier in a first preset storage space, wherein the first preset storage space stores one or more preset keys updated according to a preset period and the key identifier of each preset key; A decryption module, configured to decrypt the single-point ciphertext based on the target key to obtain the single-point ticket; A verification module, configured to perform uniqueness verification on the single-point ticket, wherein if the single-point ticket is unique, it is determined to allow the target object to log in to the system requested by the single-sign-on request; Wherein, the device further includes: An obtaining sub-module, configured to obtain a pre-configured key update period and a key update rule before querying the target key indicated by the key identifier in the first preset storage space; A first determination sub-module, configured to determine a preset key corresponding to each key update period according to the key update period and the key update rule; A second determination sub-module, configured to determine the key identifier of each preset key according to the key update period; Wherein, the first determination sub-module includes: An obtaining unit, configured to obtain the first key of the first key period; A calculation unit, configured to use the first key as a seed key, and calculate the second key of the second key period based on the key update rule, wherein the second key period is adjacent to the first key period, and the second key period is later than the first key period.
6. A single sign-on device, characterized in that, Includes: An obtaining module, configured to obtain an access request of a target object, wherein the access request carries login information, the initiation time of the access request, and a single-point link of the access object, and the login information at least includes a single-point ticket, and the single-point ticket is a login credential of the target object; An encryption query module, configured to query, in a second preset storage space, a target secret key corresponding to the initiation time and a secret key identifier of the target secret key, where the second preset storage space stores one or more preset secret keys updated according to a preset period and a secret key identifier of each of the preset secret keys; An encryption module, configured to encrypt the login credential according to the target secret key to generate a single-point ciphertext; A generation module, configured to splice the single-point ciphertext and the secret key identifier into the single-point link to generate a single-point login request for the access object; Wherein, the apparatus is further configured to: Obtain a preset secret key update period and a secret key update rule configured in advance; Determine a preset secret key corresponding to each secret key update period according to the secret key update period and the secret key update rule; Determine a secret key identifier of each preset secret key according to the secret key update period; Wherein, determining a preset secret key corresponding to each secret key update period according to the secret key update period and the secret key update rule includes: Obtain a first secret key of a first secret key period; Use the first secret key as a seed secret key, and calculate a second secret key of a second secret key period based on the secret key update rule, where the second secret key period is adjacent to the first secret key period and the second secret key period is later than the first secret key period.
7. A non-volatile storage medium, characterized in that, The non-volatile storage medium stores a program, wherein when the program runs, it controls the device where the non-volatile storage medium is located to execute the single-point login method according to any one of claims 1 to 4.
8. An electronic device, characterized in that, Including: A memory and a processor, the processor is configured to run the program stored in the memory, wherein when the program runs, it executes the single-point login method according to any one of claims 1 to 4.
Citation Information
Patent Citations
Remote resources single-point sign on
CN102404314A
Securely processing client credentials used for Web-based access to resources
US20040098609A1