Shared Login Method and Device

The shared login method using access tokens addresses the high integration costs of user account consolidation in group information systems by enabling seamless SSO across applications, reducing development and maintenance expenses.

CN115883156BActive Publication Date: 2025-07-15SUZHOU LANGDONG NET TEC CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211488187.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-25
Publication Date
2025-07-15
Estimated Expiration
2042-11-25

AI Technical Summary

Technical Problem

In the group's information management, using SOA technology to achieve shared login for the same user under different applications requires the integration of the account information of each application, resulting in an increase in development and maintenance costs.

Method used

By generating an access token, the terminal generates a login access request in response to user operations, and the interactive server obtains shared information and logs into the target application, avoiding the integration of the account information of each application.

Benefits of technology

It realizes shared login for the same user under different applications, reducing development and maintenance costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115883156B_ABST
    Figure CN115883156B_ABST
Patent Text Reader

Abstract

This application relates to a shared login method and device. The method includes: in response to an access operation of a target user to a second application in a first application, generating a login access request for the second application; wherein, the login access request includes an access token; sending the login access request to the server of the second application to request the server of the second application to obtain the shared information of the target user from the server of the first application based on the access token, and obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feedback the access interface of the second application to the terminal; displaying the access interface. By using this method, when the target user accesses the second application in the first application, it is possible to achieve shared login between different applications in the group for the target user without carrying all the account information of the target user in the first application, reducing the development and maintenance costs.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and particularly to a shared login method and device. Background Art

[0002] With the rapid development of informatization, system integration is to integrate scattered functions, information, etc. into an interconnected, unified, and coordinated system, enabling full sharing of resources and being a key measure to achieve centralization, high efficiency, and easy management. Especially in enterprise informatization, due to problems such as one system having one set of users, inconsistent users between systems, and the need to use multiple accounts to log in at different addresses for cross-system services. System integration has become an important part of enterprise informatization management.

[0003] Today, when SOA (Service-Oriented Architecture) has become the trend, the solution of packaging user authentication and permission verification into SOA services and using SOA services to authenticate user information and verify user permissions in a distributed system can well solve the problems of single sign-on authentication and permission verification.

[0004] However, using SOA technology, to achieve shared login of the same user under different applications within an enterprise, it is necessary to integrate all account information of the user in each application, which greatly increases the development and maintenance costs. Summary of the Invention

[0005] Based on this, in view of the above technical problems, it is necessary to provide a shared login method and device that can achieve shared login of the same user under different applications without integrating all account information of the user in each application, reducing the development and maintenance costs.

[0006] In a first aspect, this application provides a shared login method. The method includes:

[0007] In response to an access operation of a target user to a second application in a first application, generate a login access request for the second application; wherein, the login access request includes an access token;

[0008] Send the login access request to the server of the second application, so as to request the server of the second application to obtain the shared information of the target user from the server of the first application based on the access token, obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feedback the access interface of the second application to the terminal;

[0009] Display the access interface.

[0010] In one embodiment, generating the login access request for the second application includes:

[0011] Obtain the access timestamp of the access operation;

[0012] Generate an access token based on the access timestamp and the user identification information of the target user under the first application;

[0013] Generate a login access request based on the access token and the application identification information of the first application.

[0014] In one embodiment, generating an access token based on the access timestamp and the user identification information of the target user under the first application includes:

[0015] Encrypt the access timestamp and the user identification information of the target user under the first application to obtain encrypted data;

[0016] Use the encrypted data as the access token.

[0017] In a second aspect, the present application provides a shared login method. The method includes:

[0018] Receive a login access request sent by a terminal; wherein, the login access request is triggered and generated based on an access operation of the target user on a second application in the first application;

[0019] Extract the access token from the login access request;

[0020] Send a permission verification request including the access token to the server of the first application to request the server of the first application to perform permission verification on the access token, and in the case of successful permission verification, feedback the shared information of the target user;

[0021] Obtain the account information of the target user under the second application according to the shared information of the target user, and log in to the second application based on the account information;

[0022] Feedback the access interface of the second application to the terminal.

[0023] In one embodiment, obtaining the account information of the target user under the second application according to the shared information of the target user includes:

[0024] Determine whether the target user is a user under the second application according to the shared information of the target user;

[0025] If not, allocate account information for the target user under the second application.

[0026] In one embodiment, sending a permission verification request including the access token to the server of the first application includes:

[0027] Extract the application identification information of the first application from the login access request;

[0028] The control authority network sends a permission verification request including an access token to the server of the first application based on the application identification information.

[0029] Thirdly, the present application provides a shared login method. The method includes:

[0030] Receiving a permission verification request sent by the server of the second application; wherein, the permission verification request is sent by the server of the second application after receiving a login access request sent by the terminal, and the login access request is triggered and generated based on the access operation of the target user on the second application in the first application;

[0031] Performing permission verification on the access token in the permission verification request;

[0032] In the case where the permission verification is passed, feeding back the shared information of the target user to the server of the second application, so that the server of the second application obtains the account information of the target user under the second application based on the shared information, logs in to the second application based on the account information, and feeds back the access interface of the second application to the terminal.

[0033] In one embodiment, the access token includes the user identification information of the target user under the first application;

[0034] Performing permission verification on the access token in the permission verification request includes:

[0035] Verifying whether the target user has the permission to access the second application according to the user identification information.

[0036] In one embodiment, verifying whether the target user has the permission to access the second application according to the user identification information includes:

[0037] If it is identified according to the user identification information that the target user is a user of the first application and the account of the target user under the first application is in the logged-in state, it is determined that the target user has the permission to access the second application.

[0038] In one embodiment, the access token further includes an access timestamp;

[0039] Verifying whether the target user has the permission to access the second application according to the user identification information includes:

[0040] Determining the validity of the access token according to the time interval between the current timestamp and the access timestamp;

[0041] In the case where it is determined that the access token is valid, verifying whether the target user has the permission to access the second application according to the user identification information.

[0042] In one embodiment, performing permission verification on the access token in the permission verification request includes:

[0043] Decrypting the access token in the permission verification request to obtain decrypted data;

[0044] Performing permission verification on the decrypted data.

[0045] Fourthly, the present application further provides a shared login device. The device includes:

[0046] An access generation module, configured to generate a login access request for the second application in response to an access operation of a target user on the second application in the first application; wherein, the login access request includes an access token;

[0047] An access sending module, configured to send the login access request to the server of the second application, so as to request the server of the second application to obtain the shared information of the target user from the server of the first application based on the access token, and obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feedback the access interface of the second application to the terminal;

[0048] An interface display module, configured to display the access interface.

[0049] Fifthly, the present application further provides a shared login device. The device includes:

[0050] An access receiving module, configured to receive the login access request sent by the terminal; wherein, the login access request is triggered and generated based on the access operation of the target user on the second application in the first application;

[0051] A token extraction module, configured to extract the access token from the login access request;

[0052] A verification sending module, configured to send a permission verification request including the access token to the server of the first application, so as to request the server of the first application to perform permission verification on the access token, and in the case that the permission verification passes, feedback the shared information of the target user;

[0053] An application login module, configured to obtain the account information of the target user under the second application according to the shared information of the target user, and log in to the second application based on the account information;

[0054] An interface feedback module, configured to feedback the access interface of the second application to the terminal.

[0055] Sixthly, the present application further provides a shared login device. The device includes:

[0056] A verification receiving module, configured to receive a permission verification request sent by the server of the second application; wherein, the permission verification request is sent by the server of the second application after receiving a login access request sent by the terminal, and the login access request is triggered and generated based on the access operation of the target user on the second application in the first application;

[0057] A permission verification module, configured to perform permission verification on the access token in the permission verification request;

[0058] An information feedback module, configured to, when the permission verification is passed, feedback the shared information of the target user to the server of the second application, so that the server of the second application obtains the account information of the target user under the second application based on the shared information, logs in to the second application based on the account information, and feedbacks the access interface of the second application to the terminal.

[0059] In a seventh aspect, the present application further provides a computer device. The computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0060] In response to the access operation of the target user on the second application in the first application, generate a login access request for the second application; wherein, the login access request includes an access token;

[0061] Send the login access request to the server of the second application, so as to request the server of the second application to obtain the shared information of the target user from the server of the first application based on the access token, obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feedback the access interface of the second application to the terminal;

[0062] Display the access interface.

[0063] In an eighth aspect, the present application further provides a computer device. The computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0064] Receive a login access request sent by the terminal; wherein, the login access request is triggered and generated based on the access operation of the target user on the second application in the first application;

[0065] Extract the access token from the login access request;

[0066] Send a permission verification request including the access token to the server of the first application, so as to request the server of the first application to perform permission verification on the access token, and feedback the shared information of the target user when the permission verification is passed;

[0067] Obtain the account information of the target user under the second application according to the shared information of the target user, and log in to the second application based on the account information;

[0068] Feedback the access interface of the second application to the terminal.

[0069] In a ninth aspect, the present application further provides a computer device. The computer device includes a memory and a processor. The memory stores a computer program. When the processor executes the computer program, the following steps are implemented:

[0070] Receive a permission verification request sent by the server of the second application; wherein, the permission verification request is sent by the server of the second application after receiving the login access request sent by the terminal, and the login access request is triggered and generated based on the access operation of the target user on the second application in the first application;

[0071] Verify the access token in the permission verification request;

[0072] In the case where the permission verification is passed, feedback the shared information of the target user to the server of the second application, so that the server of the second application can obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feedback the access interface of the second application to the terminal.

[0073] In a tenth aspect, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0074] Respond to the access operation of the target user on the second application in the first application, and generate a login access request for the second application; wherein, the login access request includes an access token;

[0075] Send the login access request to the server of the second application, so as to request the server of the second application to obtain the shared information of the target user from the server of the first application based on the access token, obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feedback the access interface of the second application to the terminal;

[0076] Display the access interface.

[0077] In an eleventh aspect, the present application further provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the following steps are implemented:

[0078] Receive the login access request sent by the terminal; wherein, the login access request is triggered and generated based on the access operation of the target user on the second application in the first application;

[0079] Extract an access token from the login access request;

[0080] Send a permission verification request including the access token to the server of the first application to request the server of the first application to verify the access token, and in the case of successful permission verification, feedback the shared information of the target user;

[0081] Obtain the account information of the target user under the second application according to the shared information of the target user, and log in to the second application based on the account information;

[0082] Feedback the access interface of the second application to the terminal.

[0083] In a twelfth aspect, the present application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0084] Receive a permission verification request sent by the server of the second application; wherein, the permission verification request is sent by the server of the second application after receiving the login access request sent by the terminal, and the login access request is triggered and generated based on the access operation of the target user on the second application in the first application;

[0085] Verify the access token in the permission verification request;

[0086] In the case of successful permission verification, feedback the shared information of the target user to the server of the second application, so that the server of the second application can obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feedback the access interface of the second application to the terminal.

[0087] In a thirteenth aspect, the present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the following steps are implemented:

[0088] In response to the access operation of the target user on the second application in the first application, generate a login access request for the second application; wherein, the login access request includes an access token;

[0089] Send the login access request to the server of the second application to request the server of the second application to obtain the shared information of the target user from the server of the first application based on the access token, obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feedback the access interface of the second application to the terminal;

[0090] Display the access interface.

[0091] In a fourteenth aspect, the present application also provides a computer program product. The computer program product includes a computer program which, when executed by a processor, implements the following steps:

[0092] Receive a login access request sent by a terminal; wherein, the login access request is triggered and generated based on an access operation of a target user on a second application in a first application;

[0093] Extract an access token from the login access request;

[0094] Send a permission verification request including the access token to the server of the first application to request the server of the first application to perform permission verification on the access token, and in the case where the permission verification passes, feedback the shared information of the target user;

[0095] Obtain the account information of the target user under the second application according to the shared information of the target user, and log in to the second application based on the account information;

[0096] Feedback the access interface of the second application to the terminal.

[0097] In a fifteenth aspect, the present application also provides a computer program product. The computer program product includes a computer program which, when executed by a processor, implements the following steps:

[0098] Receive a permission verification request sent by the server of the second application; wherein, the permission verification request is sent by the server of the second application after receiving the login access request sent by the terminal, and the login access request is triggered and generated based on an access operation of a target user on the second application in the first application;

[0099] Perform permission verification on the access token in the permission verification request;

[0100] In the case where the permission verification passes, feedback the shared information of the target user to the server of the second application, so that the server of the second application obtains the account information of the target user under the second application according to the shared information, logs in to the second application based on the account information, and feedbacks the access interface of the second application to the terminal.

[0101] The above-mentioned shared login method and device, the terminal responds to the access operation of the target user to the second application in the first application, generates a login access request, and interacts with the server of the second application based on the login access request; the server of the second application interacts with the server of the first application, obtains the shared information of the target user from the server of the first application, and obtains the account information of the target user under the second application based on the shared information, and then can log in to the second application based on the account information, and feedback the access interface of the second application to the terminal; finally, the terminal displays the access interface of the second application to the target user. In the above solution, when the target user accesses the second application in the first application, it is not necessary to carry all the account information of the target user in the first application, and the shared login between different applications in the group for the same target user can be realized, reducing the development and maintenance costs. Brief Description of the Drawings

[0102] Figure 1 It is an application environment diagram of the shared login method in an embodiment;

[0103] Figure 2 It is a schematic flowchart of the shared login method in an embodiment;

[0104] Figure 3 It is a schematic flowchart of the shared login method in another embodiment;

[0105] Figure 4 It is a schematic flowchart of the shared login method in yet another embodiment;

[0106] Figure 5 It is a signaling diagram of the shared login method in an embodiment;

[0107] Figure 6 It is a structural block diagram of the shared login device in an embodiment;

[0108] Figure 7 It is a structural block diagram of the shared login device in another embodiment;

[0109] Figure 8 It is a structural block diagram of the shared login device in yet another embodiment;

[0110] Figure 9 It is an internal structure diagram of a computer device in an embodiment;

[0111] Figure 10 It is an internal structure diagram of a computer device in another embodiment. Detailed Embodiments

[0112] In order to make the objectives, technical solutions and advantages of the present application more clear and understandable, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.

[0113] The shared login method provided by the embodiment of the present application is applicable to the scenario where users achieve shared login between different applications in the same group. Optionally, the entire set of shared login methods can be implemented in cooperation with a terminal, the server of the first application, and the server of the second application. Among them, the first application and the second application can be different applications in the same group; optionally, the server of the first application is the background server of the first application, and the server of the second application is the background server of the second application; the terminal can be a computer device held by the target user. Optionally, an application processing tool provided by the server of the first application can be integrated in the terminal; further, the application processing tool can be presented in the form of a small program, a web page, or an independent APP, etc.; furthermore, an interface for entering the second application can be embedded in the application processing tool, and the interface can be presented in the form of a link, etc.

[0114] Figure 1 This is an application environment applicable to the shared login method provided by the present application. Among them, the terminal 102 interacts with the server 104 of the second application through the network; further, the server 104 of the second application interacts with the server 106 of the first application through the network. Optionally, in this embodiment, the terminal 102 can initiate a login access request to the server 104 of the second application, and the server 104 of the second application responds to the login access request and initiates a permission verification request to the server 106 of the first application; the server 106 of the first user responds to the permission verification request and performs permission verification; after passing the permission verification, the shared information of the user is fed back to the server 104 of the second application; the server 104 of the second application obtains the account information of the user under the second application according to the shared information, logs in to the second application; further, the access interface of the second application is fed back to the terminal 102. The terminal 102 displays the access interface of the second application to the user, and thus realizes the user's login to the second application under the first application.

[0115] Among them, the terminal 102 can be, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, Internet of Things devices, and portable wearable devices. The Internet of Things devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, etc. The portable wearable devices can be smart watches, smart bracelets, head-mounted devices, etc. The server 104 of the second application and the server 106 of the first application can both be implemented by an independent server or a server cluster composed of multiple servers.

[0116] In one embodiment, as Figure 2As shown, a shared login method is provided. Taking the terminal 102 in Figure 1 as an example for illustration, the method includes the following steps:

[0117] S201, in response to the target user's access operation on the second application in the first application, generate a login access request for the second application.

[0118] Optionally, the target user's access operation on the second application in the first application can be achieved by triggering a button containing a jump link to the second application in the first application.

[0119] Specifically, during the process of the target user operating the first application, if it is detected that the target user triggers an access operation on the second application in the first application, then respond to the access operation, that is, obtain the relevant information required by the target user to access the second application, such as the access token required to access the second application, and based on the relevant information, generate a login access request for the second application. Among them, the login access request includes the access token; the so-called access token is the credential for the target user to access the second application.

[0120] S202, send the login access request to the server of the second application, so as to request the server of the second application to obtain the shared information of the target user from the server of the first application based on the access token, and obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feedback the access interface of the second application to the terminal.

[0121] In this embodiment, the shared information of the target user is the information that can identify the target user, such as the mobile phone number of the target user, the ID number of the target user, etc. The account information of the target user under the second application is the user name, password, etc. of the target user under the second application. The access interface is the default page after logging in to the second application, such as the home page of the second application, etc.

[0122] Specifically, after generating the login access request, send the login access request to the server of the second application; the server of the second application obtains the shared information of the target user from the server of the first application according to the access token included in the login access request, and then according to the shared information of the target user, searches for the account information of the target user under the second application, and logs in to the second application based on the account information; further, after the second application logs in successfully, the server of the second application feeds back the access interface of the second application to the terminal for the target user to access the second application.

[0123] S203, display the access interface.

[0124] Specifically, after the terminal receives the access interface of the second application fed back by the server of the second application, it can display the access interface for the target user to perform the next operation.

[0125] It should be noted that the account information of the target user under the second application may be the same as or different from the account information of the target user under the first application; further, when the account information of the target user under the second application is different from the account information under the first application, when logging in to the second application from the first application, the access interface displayed contains the account information of the second application.

[0126] In the above shared login method, the terminal responds to the access operation of the target user to the second application in the first application, generates a login access request, and interacts with the server of the second application based on the login access request; the server of the second application interacts with the server of the first application, obtains the shared information of the target user from the server of the first application, and obtains the account information of the target user under the second application based on the shared information, and then can log in to the second application based on the account information, and feeds back the access interface of the second application to the terminal; finally, the terminal displays the access interface of the second application to the target user. In the above solution, when the target user accesses the second application in the first application, it is not necessary to carry all the account information of the target user in the first application, and the shared login between different applications in the group for the same target user can be realized, reducing the development and maintenance costs.

[0127] Exemplarily, on the basis of the above embodiment, generating the login access request may also be to obtain the access timestamp of the access operation, generate an access token according to the access timestamp and the user identification information of the target user under the first application; generate a login access request according to the access token and the application identification information of the first application.

[0128] In this embodiment, the access timestamp is the time point when it is detected that the target user triggers the access operation to the second application in the first application. The user identification information of the target user under the first application is the identity information that can identify the target user. For example, the exclusive number of the target user under the first application, etc. The application identification information of the first application is the information that can identify the first application. For example, the website of the first application, the exclusive number of the first application in the group, etc.

[0129] Specifically, when it is detected that the target user has an access operation to the second application in the first application, obtain the access timestamp of the access operation and the user identification information of the target user under the first application, and encapsulate the access timestamp and the user identification information according to the set format to obtain an access token.

[0130] Further, to ensure the security of the access token, the access timestamp and the user identification information of the target user under the first application can be encrypted to obtain encrypted data; and the encrypted data is used as the access token. Specifically, for example, the MD5 (MD5 Message-Digest Algorithm) is used to encrypt the access timestamp and the user identification information to obtain encrypted data; the encrypted data is used as the access token.

[0131] After that, the access token and the application identification information of the first application can be encapsulated in a set format to obtain a login access request.

[0132] In one embodiment, as Figure 3 shown, a shared login method is provided. Taking the method applied to the server 104 of the second application in Figure 1 as an example, the method includes the following steps:

[0133] S301, Receive the login access request sent by the terminal.

[0134] Among them, the login access request is triggered and generated based on the access operation of the target user on the second application in the first application.

[0135] Specifically, the terminal detects that the target user triggers an access operation on the second application in the first application, generates a login access request for the second application, and sends it to the server of the second application; further, the server of the second application receives the login access request.

[0136] S302, Extract the access token from the login access request.

[0137] Specifically, after receiving the login access request sent by the terminal, the server of the second application extracts the access token included in the login access request.

[0138] S303, Send a permission verification request including the access token to the server of the first application to request the server of the first application to verify the access token, and feedback the shared information of the target user when the permission verification is passed.

[0139] In this embodiment, the permission verification request is a request for the server of the second application to verify whether the target user has the permission to access the second application; optionally, the permission verification request may include the access token. The shared information of the target user is information that can identify the target user, such as the mobile phone number of the target user, the ID number of the target user, etc.

[0140] Specifically, the server of the second application can directly or indirectly send an authentication request to the server of the first application. For example, an access token can be extracted from the login access request, and an authentication request can be generated based on the access token, and then the authentication request can be sent to the server of the first application.

[0141] Optionally, the login access request may further include the application identification information of the first application; further, the server of the second application can also extract the application identification information of the first application from the login access request; control the permission network, and based on the application identification information, send an authentication request including the access token to the server of the first application. Among them, the application identification information of the first application is the information that can identify the first application, such as the website of the first application, the exclusive number of the first application in the group, etc.

[0142] Specifically, the server of the second application can extract the application identification information of the first application from the login access request, and send an authentication request including the access token and the application identification information to the permission network; the permission network can find the address of the server of the first application through the application identification information of the first application, and send an authentication request including the access token to the server of the first application.

[0143] Further, the server of the first application verifies the access token based on the preset authentication logic. If the access token passes the permission verification of the first application, the user identification information of the target user under the first application included in the access token is extracted, and based on the user identification information, the shared information of the target user is searched in the first application, and the shared information is fed back to the server of the second application.

[0144] S304, obtain the account information of the target user under the second application according to the shared information of the target user, and log in to the second application based on the account information.

[0145] In this embodiment, the account information of the target user under the second application is the username, password, etc. of the target user under the second application.

[0146] Optionally, after receiving the shared information of the target user fed back by the server of the first application, the server of the second application determines whether the target user is a user under the second application according to the shared information of the target user; if not, account information for the target user under the second application is assigned.

[0147] Specifically, based on the shared information of the target user, search for the account information of the target user in the user library of the second application to determine whether the target user is a user under the second application. Optionally, if the account information of the target user is found in the user library of the second application, it is determined that the target user is a user under the second application. At this time, the target user can directly log in to the account in the second application based on the found account information.

[0148] If the account information of the target user is not found in the user library of the second application, it is determined that the target user is not a user under the second application. At this time, it means that the target user is a new user of the second application, and account information under the second application is assigned to the target user; further, based on the assigned account information, a login process is performed for the target user on the second application.

[0149] S305, feedback the access interface of the second application to the terminal.

[0150] Specifically, after the server of the second application logs in the target user on the second application, it feedbacks the access interface of the second application to the terminal.

[0151] Optionally, through the access interface, a service for modifying the account information of the target user under the second application can be provided to achieve the effect that the account information used by the user under different applications of the same group is different.

[0152] In the above shared login method, the server of the second application receives the login access request containing the access token sent by the terminal, generates a permission verification request containing the access token, and sends it to the server of the first application; when the server of the first application passes the permission verification of the access token, it queries the shared information of the user according to the user identification information and feedbacks the shared information to the server of the second application; the server of the second application obtains the account information of the user under the second application according to the feedback shared information of the user and performs a login; further, the access interface of the second application is feedback to the terminal. In the above solution, when the target user accesses the second application in the first application, it is possible to achieve shared login between different applications in the group for the same target user without carrying all the account information of the target user in the first application, reducing the development and maintenance costs.

[0153] In one embodiment, as Figure 4 shown, a shared login method is provided. Taking the first application 106 in Figure 1 as an example for illustration, the method includes the following steps:

[0154] S401, receive the permission verification request sent by the server of the second application.

[0155] Among them, the permission verification request is sent by the server of the second application after receiving the login access request sent by the terminal, and the login access request is triggered and generated based on the access operation of the target user on the second application in the first application.

[0156] Specifically, the terminal detects the access operation of the target user on the second application in the first application and generates a login access request; after receiving the login access request, the server of the second application generates a permission verification request and sends it to the server of the first application; further, the server of the first application receives the permission verification request.

[0157] S402, perform permission verification on the access token in the permission verification request.

[0158] Optionally, the access token may include an access timestamp and the user identification information of the target user in the first application.

[0159] Specifically, the server of the first application can perform permission verification on the information contained in the access token. For example, the user identification information can be verified.

[0160] Further, in the case where the access token is obtained by encrypting the access timestamp and the user identification information of the target user in the first application, the access token in the permission verification request can be decrypted to obtain decryption data; the decryption data is subjected to permission verification. Then, the information contained in the decryption data is verified.

[0161] S403, in the case where the permission verification is passed, feedback the shared information of the target user to the server of the second application, so that the server of the second application can obtain the account information of the target user in the second application based on the shared information, log in to the second application based on the account information, and feedback the access interface of the second application to the terminal.

[0162] Specifically, after determining that the target user has the permission to access the second application, the server of the first application searches for the shared information of the target user according to the user identification information of the target user; further, feedbacks the shared information of the target user to the server of the second application for the server of the second application to search for the account information of the target user in the user library of the second application based on the shared information; logs in to the second application according to the found account information of the target user in the second application; further, feedbacks the access interface of the second application to the terminal for the terminal to display the access interface of the second application to the target user.

[0163] In the above shared login method, the server of the first application authenticates the access token in the permission verification request by receiving the permission verification request sent by the server of the second application. Further, in the case where the permission verification is passed, the shared information of the target user is fed back to the server of the second application. The server of the second application obtains the account information of the target user under the second application based on the shared information of the target user, and logs in the target user to the second application based on the obtained account information of the target user under the second application, and feeds back the access interface of the second application to the terminal for the terminal to display the access interface of the second application to the target user. In the above solution, when the target user accesses the second application in the first application, it is not necessary to carry all the account information of the target user in the first application, and the shared login between different applications in the group for the same target user can be realized, reducing the development and maintenance costs.

[0164] Exemplarily, the access token includes the user identification information of the target user under the first application. Authenticating the access token in the permission verification request may specifically be to verify whether the target user has the permission to access the second application according to the user identification information.

[0165] Specifically, if the account information of the target user is searched in the user database of the first application according to the user identification information; if the account information of the target user does not exist in the user database of the first application, it is determined that the target user is an illegal user, that is, the target user does not have the permission to access the second application; if the account information of the target user exists in the user database of the first application, it is determined that the target user is a legal user; further, if it is determined that the target user is a legal user, but the account of the target user under the first application is not in the logged-in state, it is determined that the target user does not have the permission to access the second application; if it is determined that the target user is a legal user and the account of the target user under the first application is in the logged-in state, it is determined that the target user has the permission to access the second application.

[0166] Further, in the case where the access token further includes an access timestamp, the validity of the access token can also be determined according to the time interval between the current timestamp and the access timestamp; in the case where the access token is determined to be valid, it is verified whether the target user has the permission to access the second application according to the user identification information.

[0167] Specifically, the current timestamp is obtained, and the time interval between the current timestamp and the access timestamp is calculated; further, the time interval is compared with a preset time threshold. Optionally, if the time interval is greater than the preset time threshold, it is determined that the access token is invalid, and it is not necessary to further verify whether the target user has the permission to access the second application; if the time interval is less than the preset time threshold, it is determined that the access token is valid, and it can be further verified whether the target user has the permission to access the second application.

[0168] In one embodiment, an optional example of a method for realizing shared login through interaction between a terminal, a server of a second application, and a server of a first application is given. Combining Figure 5 with the signaling interaction process schematic diagram of the shared login method shown, this method can be specifically implemented through the following steps:

[0169] S501, in response to an access operation of a target user on a second application in a first application, the terminal generates a login access request for the second application.

[0170] Specifically, obtain the access timestamp of the access operation; generate an access token according to the access timestamp and the user identification information of the target user under the first application; generate a login access request according to the access token and the application identification information of the first application.

[0171] Optionally, the terminal can encrypt the access timestamp and the user identification information of the target user under the first application to obtain encrypted data; use the encrypted data as the access token.

[0172] S502, the terminal sends the login access request to the server of the second application.

[0173] S503, the server of the second application receives the login access request sent by the terminal and extracts the access token from the login access request.

[0174] S504, the server of the second application sends a permission verification request including the access token to the server of the first application.

[0175] S505, the server of the first application receives the permission verification request sent by the server of the second application and verifies the access token in the permission verification request.

[0176] Specifically, extract the application identification information of the first application from the login access request; control the permission network, and based on the application identification information, send a permission verification request including the access token to the server of the first application.

[0177] S506, when the permission verification is passed, the server of the first application feeds back the shared information of the target user to the server of the second application.

[0178] S507, the server of the second application obtains the account information of the target user under the second application according to the shared information of the target user, and logs in to the second application based on the account information.

[0179] Specifically, determine whether the target user is a user under the second application according to the shared information of the target user; if not, allocate account information for the target user under the second application, and then log in to the second application based on the allocated account information.

[0180] S508, the server of the second application feeds back the access interface of the second application to the terminal.

[0181] S509, the terminal displays the access interface.

[0182] For the specific processes of the above S501 - S509, reference can be made to the descriptions in the foregoing method embodiments. Their implementation principles and technical effects are similar and will not be elaborated here.

[0183] It should be understood that although each step in the flowcharts involved in the foregoing embodiments is displayed in sequence according to the indication of the arrows, these steps do not necessarily need to be executed in the order indicated by the arrows. Unless otherwise clearly stated in this document, the execution of these steps has no strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the foregoing embodiments may include multiple steps or multiple stages. These steps or stages do not necessarily need to be executed at the same moment, but can be executed at different moments. The execution order of these steps or stages does not necessarily need to be sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.

[0184] Based on the same inventive concept, the embodiments of the present application also provide a shared login device for implementing the shared login method involved above. The solution for solving problems provided by this device is similar to the solution described in the above method. Therefore, the specific limitations in one or more of the following embodiments of the shared login device can refer to the limitations on the shared login method in the foregoing text and will not be elaborated here.

[0185] In one embodiment, as Figure 6 shown, a shared login device 1 is provided, including: a request generation module 110, an interface feedback module 120, and an interface display module 130, where:

[0186] An access generation module 110, configured to generate a login access request for the second application in response to an access operation of a target user on the second application in the first application.

[0187] An access sending module 120, configured to send the login access request to the server of the second application, so as to request the server of the second application to obtain the shared information of the target user from the server of the first application based on the access token, obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feed back the access interface of the second application to the terminal.

[0188] An interface display module 130, configured to display the access interface.

[0189] Based on the above embodiments, in one embodiment, the above request generation module 110 further includes:

[0190] A time acquisition unit, configured to acquire the access timestamp of the access operation.

[0191] A token generation unit, configured to generate an access token according to the access timestamp and the user identification information of the target user under the first application.

[0192] A request generation unit, configured to generate a login access request according to the access token and the application identification information of the first application.

[0193] Based on the above embodiments, in one embodiment, the above token generation unit may specifically further be used for:

[0194] Encrypt the access timestamp and the user identification information of the target user under the first application to obtain encrypted data; use the encrypted data as the access token.

[0195] In one embodiment, as Figure 7 shown, a shared login device 2 is provided, including: a request receiving module 210, a token extraction module 220, an information feedback module 230, an application login module 240, and an interface feedback module 250, where:

[0196] An access receiving module 210, configured to receive the login access request sent by the terminal.

[0197] A token extraction module 220, configured to extract the access token from the login access request.

[0198] A verification sending module 230, configured to send a permission verification request including the access token to the server of the first application, so as to request the server of the first application to perform permission verification on the access token, and feedback the shared information of the target user when the permission verification is passed.

[0199] An application login module 240, configured to obtain the account information of the target user under the second application according to the shared information of the target user, and log in to the second application based on the account information.

[0200] An interface feedback module 250, configured to feedback the access interface of the second application to the terminal.

[0201] Based on the above embodiments, in one embodiment, the above application login module 240 may specifically further be used for:

[0202] Determine whether the target user is a user under the second application according to the shared information of the target user; if not, allocate the account information of the target user under the second application.

[0203] Based on the above embodiments, in one embodiment, the information feedback module 230 may specifically further be configured to:

[0204] Extract the application identification information of the first application from the login access request; control the permission network, and based on the application identification information, send a permission verification request including an access token to the server of the first application.

[0205] In one embodiment, as Figure 8 shown, a shared login device 3 is provided, including: a request receiving module 310, a permission verification module 320, and an interface feedback module 330, where:

[0206] The verification receiving module 310 is configured to receive a permission verification request sent by the server of the second application.

[0207] The permission verification module 320 is configured to perform permission verification on the access token in the permission verification request.

[0208] The information feedback module 330 is configured to, in the case where the permission verification is passed, feedback the shared information of the target user to the server of the second application, so that the server of the second application can obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feedback the access interface of the second application to the terminal.

[0209] Based on the above embodiments, in one embodiment, the access token includes the user identification information of the target user under the first application; the permission verification module 320 further includes:

[0210] A permission verification unit, configured to verify whether the target user has the permission to access the second application according to the user identification information. Optionally, if it is identified according to the user identification information that the target user is a user of the first application and the account of the target user under the first application is in a logged-in state, it is determined that the target user has the permission to access the second application.

[0211] Based on the above embodiments, in one embodiment, the access token further includes an access timestamp; the permission verification unit may specifically further be configured to:

[0212] Determine the validity of the access token according to the time interval between the current timestamp and the access timestamp; in the case where it is determined that the access token is valid, verify whether the target user has the permission to access the second application according to the user identification information.

[0213] Based on the above embodiments, in one embodiment, the permission verification module 320 may specifically further be configured to:

[0214] Decrypt the access token in the permission verification request to obtain decryption data; perform permission verification on the decryption data.

[0215] Each module in the above-mentioned shared login device can be implemented in whole or in part by software, hardware, or a combination thereof. Each of the above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0216] In one embodiment, a computer device is provided. The computer device can be a server of a second application or a server of a first application. Its internal structure diagram can be as shown in Figure 9 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store data such as shared information of target users. The network interface of the computer device is used to communicate with external terminals through a network connection. When the computer program is executed by the processor, it implements a shared login method.

[0217] In one embodiment, a computer device is provided. The computer device can be a terminal, and its internal structure diagram can be as shown in Figure 10 shown. The computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with external terminals in a wired or wireless manner. The wireless manner can be implemented through WIFI, a mobile cellular network, NFC (Near Field Communication), or other technologies. When the computer program is executed by the processor, it implements a shared login method. The display screen of the computer device can be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device can be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the housing of the computer device, or an external keyboard, touchpad, or mouse, etc.

[0218] Those skilled in the art can understand that Figure 9 、 Figure 10The structure shown is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0219] In one embodiment, a computer device is provided, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0220] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0221] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0222] It should be noted that the user information (including but not limited to the shared information of the target user, the account information of the target user under the first application, the account information of the target user under the second application, etc.) and data (including but not limited to the data for analysis, the stored data, the displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.

[0223] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetoresistive random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., and are not limited thereto. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logic devices, data processing logics based on quantum computing, etc., and are not limited thereto.

[0224] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0225] The above-described embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.

Claims

1. A shared login method, characterized in that, The method includes: Generating a login access request for the second application in response to an access operation of a target user on the second application in the first application; wherein, an access token is included in the login access request; Sending the login access request to the server of the second application to request the server of the second application to obtain the shared information of the target user from the server of the first application based on the access token, obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feedback the access interface of the second application to the terminal; Displaying the access interface.

2. The method according to claim 1, wherein The generating the login access request for the second application includes: Obtaining the access timestamp of the access operation; Generating an access token according to the access timestamp and the user identification information of the target user under the first application; Generating a login access request according to the access token and the application identification information of the first application.

3. The method according to claim 2, wherein The generating the access token according to the access timestamp and the user identification information of the target user under the first application includes: Encrypting the access timestamp and the user identification information of the target user under the first application to obtain encrypted data; Using the encrypted data as the access token.

4. A shared login method, characterized in that, The method includes: Receiving a login access request sent by a terminal; wherein, the login access request is triggered and generated based on an access operation of a target user on the second application in the first application; Extracting an access token from the login access request; Sending a permission verification request including the access token to the server of the first application to request the server of the first application to perform permission verification on the access token, and feedbacking the shared information of the target user in the case of successful permission verification; Obtaining the account information of the target user under the second application according to the shared information of the target user, and logging in to the second application based on the account information; Feedbacking the access interface of the second application to the terminal.

5. The method according to claim 4, wherein The obtaining the account information of the target user under the second application according to the shared information of the target user includes: Determining whether the target user is a user under the second application according to the shared information of the target user; If not, allocating account information for the target user under the second application.

6. The method according to claim 4, wherein The sending the permission verification request including the access token to the server of the first application includes: Extracting the application identification information of the first application from the login access request; Controlling the permission network to send a permission verification request including the access token to the server of the first application based on the application identification information.

7. A shared login method, characterized in that The method includes: Receiving a permission verification request sent by the server of the second application; wherein, the permission verification request is sent by the server of the second application after receiving the login access request sent by the terminal, and the login access request is triggered and generated based on an access operation of a target user on the second application in the first application; Performing permission verification on the access token in the permission verification request; When the permission verification is passed, the shared information of the target user is fed back to the server of the second application, so that the server of the second application can obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feed back the access interface of the second application to the terminal.

8. The method according to claim 7, wherein The access token includes the user identification information of the target user under the first application; The permission verification of the access token in the permission verification request includes: According to the user identification information, verify whether the target user has the permission to access the second application.

9. The method according to claim 8, wherein The step of verifying whether the target user has the permission to access the second application according to the user identification information includes: If it is identified according to the user identification information that the target user is a user of the first application and the account of the target user under the first application is in the logged-in state, it is determined that the target user has the permission to access the second application.

10. The method according to claim 8, wherein The access token further includes an access timestamp; The step of verifying whether the target user has the permission to access the second application according to the user identification information includes: Determine the validity of the access token according to the time interval between the current timestamp and the access timestamp; When it is determined that the access token is valid, verify whether the target user has the permission to access the second application according to the user identification information.

11. The method according to claim 7, wherein The permission verification of the access token in the permission verification request includes: Decrypt the access token in the permission verification request to obtain decryption data; Perform permission verification on the decryption data.

12. A shared login device, characterized in that, The device includes: An access generation module, configured to generate a login access request for the second application in response to an access operation of a target user to the second application in the first application; wherein, the login access request includes an access token; An access sending module, configured to send the login access request to the server of the second application, so as to request the server of the second application to obtain the shared information of the target user from the server of the first application based on the access token, obtain the account information of the target user under the second application based on the shared information, log in to the second application based on the account information, and feed back the access interface of the second application to the terminal; An interface display module, configured to display the access interface.

13. A shared login device, characterized in that, The device includes: An access receiving module, configured to receive a login access request sent by a terminal; wherein, the login access request is triggered and generated based on an access operation of a target user to the second application in the first application; A token extraction module, configured to extract an access token from the login access request; A verification sending module, configured to send a permission verification request including the access token to the server of the first application, so as to request the server of the first application to perform permission verification on the access token, and feed back the shared information of the target user when the permission verification is passed; An application login module, configured to obtain the account information of the target user under a second application according to the shared information of the target user, and log in to the second application based on the account information; An interface feedback module, configured to feedback the access interface of the second application to the terminal.

14. A shared login device, characterized in that, The device includes: A verification receiving module, configured to receive a permission verification request sent by a server of a second application; wherein, the permission verification request is sent by the server of the second application after receiving a login access request sent by a terminal, and the login access request is triggered and generated based on an access operation of the target user on the second application in a first application; A permission verification module, configured to perform permission verification on the access token in the permission verification request; An information feedback module, configured to, when the permission verification is passed, feedback the shared information of the target user to the server of the second application, so that the server of the second application obtains the account information of the target user under the second application based on the shared information, logs in to the second application based on the account information, and feedbacks the access interface of the second application to the terminal.

15. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 11 are implemented.

16. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 11 are implemented.

17. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 11 are implemented.

Citation Information

Patent Citations

  • Login method and device of multiple applications

    CN105099985A

  • Login state sharing method and apparatus based on device ID

    CN109639740A