A system login method, device, and its medium

By storing the authentication information of the target subsystem in the backend server and using dual encryption for authentication, the problem that the existing system login method relies on a third-party authentication center and cannot be guaranteed for security is solved, and unsensed password-free login and high-security system login are achieved.

CN116055149BActive Publication Date: 2025-06-27NINGBO NINGSHU SAFETY TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211731475.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-12-30
Publication Date
2025-06-27
Estimated Expiration
2042-12-30

AI Technical Summary

Technical Problem

The existing system login method relies on third-party authentication centers, resulting in high operating costs and insecurity insecurity.

Method used

By storing the IP address, username, password and token information of the target subsystem in the back-end server, and using double encryption (preset key and token information) to authenticate, avoiding authentication through the login page.

Benefits of technology

It realizes unsensed password-free login, reduces system operation costs, improves the security of the login process, and avoids the security risks of single sign-in.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116055149B_ABST
    Figure CN116055149B_ABST
Patent Text Reader

Abstract

The present application discloses a system login method, device and medium, relating to the technical field of data visualization, and is used to achieve passwordless login of a data system. Aiming at the problem that in the current system login process, it depends on a third-party certification center and the security cannot be guaranteed, a system login method is provided. The server located at the backend in the data system stores the IP addresses, usernames, passwords and token information corresponding to other node subsystems in the data system, and there is no need to deploy an additional third-party certification center; during the process of accessing the target page, the information used for authentication such as the username and password is encrypted throughout the process and uses a double encryption method. Each subsystem corresponds to different usernames and passwords, and it is also necessary to re-authenticate each time the target page is accessed, which can effectively ensure the security of system login.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of data visualization, and in particular to a system login method, device and medium thereof. Background Art

[0002] With the booming development of the big data industry, more and more enterprises have begun to apply data visualization. The data visualization large screen is a data visualization application mainly carried by a large screen, which can clearly display some relatively complex and abstract data in a graphical way to help technicians explore the value behind the data. The data visualization large screen generally centrally displays the general situation of each index. When it is necessary to further pay attention to the specific data behind the index, the interface can be clicked to jump to the target system to view the corresponding page data. However, each target system has its own login verification, and it is necessary to jump to the login page and use the username and password of the system to log in. At this time, if it is possible to directly jump from the current large screen to the target page of the target system without opening the login page, the user experience will be greatly improved.

[0003] Currently, the single sign-on (SSO) method is generally adopted to achieve passwordless login, that is, through an independent third-party authentication center, all subsystems log in through the login entrance of this authentication center, and the address is carried when logging in. The authentication center verifies whether the account password of the username is correct. If the authentication is passed, a token will be returned to the user. After the user gets the token, it is equivalent to getting authorization and can log in to the target system. For multiple application systems under the same account, the user only needs to log in once to access all mutually trusted systems.

[0004] However, this single sign-on method also has limitations: First, this method depends on a trusted third-party authentication center, which requires integrating a central authentication service in the system, introducing more dependencies in the system, making the operation cost of the system higher and too cumbersome; because only logging in to the third-party authentication center once can achieve access between multiple systems, the security of single sign-on cannot be guaranteed.

[0005] Therefore, those skilled in the art now urgently need a system login method to solve the problems of relying on a third-party authentication center and lack of security guarantee in the current system login process. Summary of the Invention

[0006] The purpose of the present application is to provide a system login method, device and medium thereof to solve the problems of relying on a third-party authentication center and lack of security guarantee in the current system login process.

[0007] To solve the above technical problems, the present application provides a system login method, including:

[0008] Receiving an access request from a user; wherein, the access request includes: a target subsystem and a target page;

[0009] Forwarding the access request to a backend server to obtain the IP address, username, password, and token information corresponding to the target subsystem; wherein, the token information is an encrypted key transmitted in the form of a token, and the backend server stores the decryption key corresponding to the token information;

[0010] According to the IP address of the target subsystem, combining with the pre-configured routing information corresponding to the target subsystem to obtain an access path pointing to the target page in the target subsystem;

[0011] Encrypting the username and password corresponding to the target subsystem according to a preset key, and encrypting the preset key with the token information;

[0012] Accessing the target subsystem according to the access path and sending the encrypted username, password, and preset key to the target subsystem, so that the target subsystem requests the backend server to perform user login verification. If the user login verification is passed, the backend server notifies the target subsystem to jump to the target page.

[0013] Preferably, the preset key is the key of a symmetric encryption algorithm.

[0014] Preferably, the token information and its corresponding decryption key are a pair of keys of an asymmetric encryption algorithm; wherein, the token information is the public key, and the decryption key is the private key.

[0015] Preferably, the obtained IP address, username, and password corresponding to the target subsystem are pre-encrypted by the backend server;

[0016] Correspondingly, after obtaining the IP address, username, password, and token information corresponding to the target subsystem, it further includes:

[0017] Decrypting the IP address, username, password, and token information corresponding to the target subsystem to obtain the decrypted IP address, username, password, and token information.

[0018] Preferably, the preset key is the key of the AES encryption algorithm.

[0019] Preferably, the token information is the public key of the RSA encryption algorithm.

[0020] Preferably, it further includes:

[0021] Receiving and storing the configuration information sent by the user; wherein, the configuration information includes the routing information and preset key corresponding to each subsystem.

[0022] To solve the above technical problems, the present application also provides a system login device, including:

[0023] A request receiving module, configured to receive an access request from a user; wherein, the access request includes: a target subsystem and a target page;

[0024] An information obtaining module, configured to forward the access request to a backend server to obtain the IP address, username, password, and token information corresponding to the target subsystem; wherein, the token information is an encrypted key transmitted in the form of a token, and the backend server stores the decryption key corresponding to the token information;

[0025] A path determining module, configured to obtain an access path pointing to the target page in the target subsystem according to the IP address of the target subsystem and in combination with the pre-configured routing information corresponding to the target subsystem;

[0026] An information encryption module, configured to encrypt the username and password corresponding to the target subsystem according to a preset key, and encrypt the preset key by using the token information;

[0027] A page login module, configured to access the target subsystem according to the access path and send the encrypted username, password, and preset key to the target subsystem, so that the target subsystem requests the backend server to perform user login verification. If the user login verification is passed, the backend server notifies the target subsystem to jump to the target page.

[0028] Preferably, the above system login device further includes:

[0029] An information configuration module, configured to receive and store configuration information sent by a user; wherein, the configuration information includes the routing information and preset key corresponding to each subsystem.

[0030] To solve the above technical problems, the present application also provides a system login device, including:

[0031] A memory, configured to store a computer program;

[0032] A processor, configured to implement the steps of the system login method as described above when executing the computer program.

[0033] To solve the above technical problems, the present application also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps of the system login method as described above are implemented.

[0034] A system login method provided by this application uses a server located at the backend of a data system to store the IP addresses, usernames, passwords, and token information corresponding to other node subsystems in the data system. When the data dashboard located at the front end receives an access request from a user to a certain page of a certain subsystem, it can use the existing network communication architecture to access the backend server to obtain the corresponding information. After determining the access path, the username and password are encrypted, and the key for encrypting the username and password is double-encrypted using the token information. The encrypted username, password, and key are sent to the target subsystem. Since the target subsystem does not have the decryption key corresponding to the token information, the encrypted username and password are forwarded to the backend server for decryption and verification. The backend server decrypts the key using the decryption key corresponding to the token information, and then decrypts the username and password according to the decrypted key to achieve identity verification and determine whether the access request has the corresponding access permission. If the verification passes, the backend server notifies the target subsystem to jump to the target page, and the front-end dashboard can access and display the data of the target page. The system login method provided by this application does not require identity verification through the login page every time the target page is accessed, which is not perceptible to the user and will not affect the user experience. Moreover, compared with the single sign-on method, this application does not require an additional deployment of a trusted third-party authentication center. It only needs to use the servers in the existing system architecture to store the necessary information. During the process of accessing the target page, the information used for identity verification such as the username and password is encrypted throughout the process and uses the double-encryption method. Each subsystem corresponds to different usernames and passwords, and verification also needs to be performed again every time the target page is accessed, which can effectively ensure the security of system login.

[0035] The system login device and computer-readable storage medium provided by this application correspond to the above method and have the same effect. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] To more clearly illustrate the embodiments of this application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of this application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.

[0037] Figure 1 It is a flowchart of a system login method provided by the present invention;

[0038] Figure 2 It is a flowchart of another system login method provided by the present invention;

[0039] Figure 3 It is a structural diagram of a system login device provided by the present invention;

[0040] Figure 4 This is the structural diagram of another system login device provided by the present invention. Detailed implementation manners

[0041] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.

[0042] The core of the present application is to provide a system login method, device and its medium.

[0043] In order to enable those skilled in the art of the present technology to better understand the solution of the present application, the present application will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.

[0044] In today's environment, enterprises and institutions cannot complete their daily work through only one set of systems. Usually, there are multiple sets of systems. At this time, the data of different systems is relatively independent. If you want to understand the data between systems intuitively and clearly, you need a carrier to collect the data between systems, and the visual large screen is a common choice for the data carrier, which can display the data intuitively in the form of charts.

[0045] Therefore, in a complete set of data systems, which include multiple subsystems, the subsystems establish communication through network devices such as routers to ensure the relative independence of data while also enabling data interconnection. The visual large screen serves as the front-end device that directly interacts with users for them to view various data in the data system, and the server serves as the back-end device for storing a large amount of data and providing network services in the data system.

[0046] In the application scenario of the present application, the front-end refers to the application program of the system running on the browser, which is the main body that directly interacts with users and uses the visual large screen as the carrier. In the operations of users, they are usually the initiator or requester of actions; the back-end is the application program running on the server and is the receiver of actions. The data visual large screen integrates the index statistical data of multiple subsystems. If users need to understand the content of the subsystem data in more detail, they can click on the corresponding subsystem and other operations to make the visual large screen jump to the target page of the target subsystem, so as to display more detailed data of the target subsystem.

[0047] Since there are many deficiencies in the single sign-on method for solving the login problem when the data visual large screen jumps to each subsystem at present, the present application provides a system login method, as Figure 1 shown, including:

[0048] S11: Receive the access request from the user.

[0049] Among them, the access request includes but is not limited to: the target subsystem and the target page. The target subsystem and the target page can specifically be the unique information pointing to a certain subsystem and a certain page, and can be in the form of the name or code of the subsystem and the page, etc. This embodiment does not limit this.

[0050] The user's access request is also an instruction for the user to issue to the visual large screen to retrieve a certain index data. This index data is the data in the target subsystem, and the target page is also the detailed data page of this index data.

[0051] Therefore, in another possible implementation, the user's access request can specifically include the target index data, and the target page of the target subsystem to be jumped to is determined by the target index data.

[0052] S12: Forward the access request to the backend server to obtain the IP address, username, password, and token information corresponding to the target subsystem.

[0053] Among them, the token information is an encrypted key transmitted in the form of a token. The backend server stores the decryption key corresponding to the token information. It should be noted that what the specific token information and the corresponding decryption key are should be determined according to the encryption algorithm used. This embodiment does not limit this. Based on different encryption algorithms used, the token information and its corresponding decryption key can be the same or different.

[0054] For the username and password, when the data visual large screen needs to access the target subsystem, it is the information used to complete user authentication instead of the login page. For different groups of usernames and passwords, they can be respectively corresponding to different subsystems, that is, each subsystem corresponds to one or more groups of usernames and passwords, and one group of usernames and passwords only corresponds to one subsystem; or it can be a group of usernames and passwords randomly assigned by the server with access to the target subsystem, etc. This embodiment does not limit this.

[0055] S13: According to the IP address of the target subsystem, combined with the pre-configured routing information corresponding to the target subsystem, obtain the access path pointing to the target page in the target subsystem.

[0056] Among them, the above routing information, that is, the uniform resource locator (URL) address, parameter information, etc. required to access the corresponding page of a certain subsystem, can be combined with the Internet Protocol (IP) address to splice out a complete access path for accessing the corresponding page of the target subsystem, which is pre-configured by the user and stored in the front end.

[0057] S14: Encrypt the user name and password corresponding to the target subsystem according to a preset key, and encrypt the preset key through token information.

[0058] The preset key can be pre-configured or generated randomly in real time, and can be determined according to the different encryption algorithms used; when the preset key is pre-configured, it is the same as the routing information in step S13, and is pre-configured and stored in the front end for subsequent calls; if the preset key is generated randomly in real time, it is generated according to the corresponding random seed when or before using the preset key, and the preset key needs to be stored after generation for subsequent calls.

[0059] S15: Access the target subsystem according to the access path, and send the encrypted user name, password and preset key to the target subsystem, so that the target subsystem requests the back-end server to perform user login verification. If the user login verification is passed, the back-end server notifies the target subsystem to jump to the target page.

[0060] The above steps S11 to S15 are all processes applied to the front end, that is, the data visualization large screen is the main body of the operation. However, in fact, the entire system login method involves three main bodies, namely: the data visualization large screen at the front end, the server at the back end, and the target subsystem.

[0061] For step S12, it involves the interaction between the data visualization large screen and the server. The data visualization large screen forwards the user's access request to the server, and the server sends the corresponding IP address, user name, password, and token information to the data visualization large screen according to the access request. All this information is pre-configured and stored in the server.

[0062] For step S15, it involves a data visualization large screen, a server, and a target subsystem. When the visualization large screen accesses the target subsystem through the access path, it sends the encrypted username, password, and preset key to the target subsystem. Since the target subsystem does not have the corresponding decryption key, it cannot perform authentication. Therefore, the target subsystem forwards this part of the encrypted identity information to the server. The server stores the decryption key corresponding to the token information, so it can decrypt the preset key encrypted according to the token information. Furthermore, it decrypts the username and password according to the obtained preset key to obtain the complete plaintext data, and the server can thus implement the authentication of the access request. When the authentication is passed, the server notifies the target subsystem, and the target subsystem then jumps to the target page for the data visualization large screen to access, completing the password-free login process from the visualization large screen to the target page of the target subsystem.

[0063] It should also be noted that for the encryption process based on the preset key and token information, different encryption algorithms can be used to further improve the security of the data and avoid the problem that the data is no longer secure when a key or encryption algorithm is cracked.

[0064] In the above description, the preset key and routing information need to be configured in advance. Therefore, as Figure 1 shown, in a possible implementation, the method further includes:

[0065] S10: Receive and store the configuration information sent by the user.

[0066] Among them, the configuration information includes the routing information and preset key corresponding to each subsystem.

[0067] Specifically, a configuration page can be added to the system of the data visualization large screen to configure the username, password, and token information corresponding to each subsystem. Correspondingly, the configuration of the preset key can also be implemented through this configuration page.

[0068] A system login method provided in this embodiment utilizes the architecture of an existing data system, with the backend server serving as the authenticator and the storage for the target subsystem and authentication information. When the front-end data visualization dashboard receives an access request sent by a user, there is no need to authenticate the user through a login page. Instead, it obtains the corresponding authentication information from the backend server and encrypts the authentication information in a two-layer encryption manner. The first layer of encryption encrypts the username and password using a preset key, and the second layer of encryption encrypts the preset key using token information, ensuring the security of data and authentication to the greatest extent. Furthermore, when accessing the target page of the target subsystem, the backend server receives the encrypted authentication information, decrypts the preset key according to the decryption key corresponding to the token information, and then decrypts the username and password according to the decrypted preset key to obtain the complete plaintext authentication information for authentication. When the authentication is passed, it notifies the target subsystem to jump to the target page to complete the entire system login process. In this method, the authentication process of the entire login process does not require the assistance of a login page and is completely imperceptible to the user. The user also does not need to remember the corresponding username and password, achieving the effect of passwordless login, greatly optimizing the user experience. Moreover, this method does not require an additional deployment of a trusted third-party authentication center and can achieve passwordless login using the existing data system architecture, reducing the implementation complexity. This method requires a corresponding login process for each access to the target subsystem, and the authentication information required for each login process is different, preventing the situation where cracking one password can access the resources of multiple subsystems in a single sign-on method, ensuring data security more effectively. Additionally, the security is further enhanced through two-layer encryption. This method takes into account both the user experience and data security, better meeting the actual application needs of the data system.

[0069] As can be seen from the above embodiments, the system login method provided in this application ensures the security of the system login process through a two-layer encryption method. Regarding the encryption algorithm used for each encryption, no limitation is made in the above embodiments. Generally speaking, selecting two different encryption algorithms as the two-layer encryption algorithm can better ensure data security. Based on this, this embodiment provides a preferred implementation:

[0070] The above-mentioned preset key is the key of the symmetric encryption algorithm.

[0071] That is to say, the encryption process achieved through the preset key is based on the symmetric algorithm. The advantage of the symmetric encryption algorithm compared to the asymmetric encryption algorithm is that the encryption and decryption speed is faster. Using the symmetric algorithm to encrypt authentication information such as the username and password is beneficial to improving the efficiency of the system login process, enabling the user's access request to be responded to more quickly, and thus optimizing the user experience.

[0072] It should be noted that this embodiment does not limit the specific symmetric encryption algorithm to be used. Common symmetric encryption algorithms include Data Encryption Standard (DES), Triple Data Encryption Algorithm (TripleDES, also known as 3DES), and Advanced Encryption Standard (AES), etc. In this embodiment, the AES algorithm can be preferably used, that is, the preset key is an AES key.

[0073] Furthermore, for the encryption algorithm used for the token information, this embodiment also provides a preferred implementation:

[0074] The above token information and its corresponding decryption key are a pair of keys of an asymmetric encryption algorithm.

[0075] Among them, the token information is the public key, and the decryption key is the private key.

[0076] That is, the process of encrypting the preset key with the token information is implemented based on an asymmetric encryption algorithm. For the asymmetric encryption algorithm used, this embodiment also does not make any restrictions. It can be the RSA encryption algorithm (RSA algorithm), DSA algorithm (Digital Signature Algorithm), Elliptic Curve Cryptography (ECC), Key Exchange Protocol / Algorithm (Diffie-Hellman, DH), etc. In this embodiment, the RSA algorithm can be preferably used, that is, the token information is the public key transmitted in the form of a token and is used for data encryption. Correspondingly, the decryption key is also the private key corresponding to the public key and is used for data decryption.

[0077] When the server receives an access request, it generates a set of RSA keys, sends the public key in the form of a token to the front-end visualization dashboard for data encryption, and the private key is stored in the server. When the encrypted authentication information is received later, the private key is called for decryption.

[0078] In this embodiment, the purpose of selecting the preset key to use the AES symmetric encryption algorithm and the token information to use the RSA asymmetric encryption algorithm is as follows: The symmetric encryption algorithm has a fast encryption and decryption speed for data, so it is used to encrypt authentication information such as user names and passwords with a relatively large amount of data, improving the efficiency of the authentication process. This is also reflected in the front end as a faster response speed for system login, optimizing the user experience. Although the asymmetric encryption algorithm has a slower encryption and decryption speed compared to the symmetric encryption algorithm, it has higher security. Therefore, the asymmetric encryption algorithm is used to encrypt the preset key with a relatively small amount of data, further enhancing the security of double encryption without significantly affecting the efficiency of the entire login process.

[0079] A preferred solution provided in this embodiment encrypts authentication information such as user names and passwords with a relatively large amount of data through the symmetric encryption algorithm, reducing the impact on the efficiency of the login process while ensuring data security; then, the symmetric encryption key (i.e., the preset key) is encrypted through the asymmetric encryption algorithm, and the second layer of encryption is implemented using the asymmetric encryption algorithm with higher security, further improving data security. Since the amount of data of the preset key is relatively small, using the asymmetric encryption algorithm will not have a significant impact on the entire login process, and the user experience is not affected.

[0080] The system login method provided in the above embodiment uses double encryption to ensure the security of system login. However, the encryption occurs during the data transmission process of the front-end visualization large screen accessing the target subsystem. Before that, there is also a communication process between the front-end visualization large screen and the back-end server to obtain the IP address, user name, password, and token information of the target subsystem. This process also has the need to protect data security. Therefore, this embodiment also provides a preferred implementation:

[0081] The IP address, user name, and password corresponding to the target subsystem obtained in step S12 are pre-encrypted by the back-end server.

[0082] Correspondingly, after step S12, the following should also be included:

[0083] Decrypt the IP address, user name, password, and token information corresponding to the target subsystem to obtain the decrypted IP address, user name, password, and token information.

[0084] It should be noted that the encryption method used in this embodiment is not limited. However, considering reducing the impact on the efficiency of the login process, a symmetric encryption algorithm can be used. Based on this, an encryption algorithm that is the same as or different from the preset key can be used. If the encryption algorithm of the preset key is used, further, the preset key can also be used for the encryption of this process. However, in this application scenario, the server learns the preset key before formal authentication. Therefore, in the process of decrypting the preset key encrypted by the token information with the private key, the server has an additional verification process, that is, verifying whether the received preset key is consistent with the preset key stored in advance. While the security is more guaranteed, the use of excessive keys is also reduced, which is a relatively preferred implementation scheme.

[0085] For a preferred solution provided in this embodiment, starting from the problem that the communication process of the front-end visual large screen obtaining the IP address, username, password, and token information corresponding to the target subsystem from the back-end server also has security requirements, the back-end server encrypts these information in advance before returning them. Further, to simplify the process, the same encryption algorithm as the preset key can be used for this encryption process, or even directly use the preset key for encryption. On the one hand, the front-end does not need to pre-enter the key for this encryption process, and on the other hand, it also provides an additional verification process in the server authentication, better ensuring the security of the user accessing the target page.

[0086] In the above embodiment, the front-end data visualization large screen is mostly used as the execution subject to illustrate a system login method provided by the present application. However, considering that the entire system login process is jointly completed by three main bodies: the data visualization large screen, the server, and the target subsystem, this embodiment is further described in combination with Figure 2 as follows:

[0087] Based on the preferred solution provided in the above embodiment, a system login method provided in this embodiment is as Figure 2 shown, including:

[0088] S200: The user configures the routing information and preset key of each subsystem in the data visualization large screen.

[0089] Like step S20, step S200 is also a preparatory process before the formal system login process. Therefore, to distinguish it from the formal process, "0" is used as the serial number.

[0090] S201: The data visualization large screen receives the access request sent by the user.

[0091] Among them, the access request includes: the target subsystem and the target page; or, the access request includes specific index data that can point to a certain target page of a certain subsystem.

[0092] S202: The data visualization large screen forwards the access request to the server.

[0093] S203: The server returns to the data visualization large screen the IP address, username, password, and token information corresponding to the target subsystem, encrypted according to a preset key.

[0094] S204: The data visualization large screen decrypts the IP address, username, password, and token information according to the preset key to obtain the corresponding plaintext data.

[0095] S205: The data visualization large screen obtains the access path pointing to the target page in the target subsystem based on the IP address of the target subsystem and in combination with the pre-configured routing information corresponding to the target subsystem.

[0096] S206: The data visualization large screen re-encrypts the IP address, username, and password with the preset key, and encrypts the preset key with the token information.

[0097] S207: The data visualization large screen accesses the target subsystem according to the access path and sends the encrypted username, password, and preset key.

[0098] S208: The target subsystem forwards the encrypted username, password, and preset key to the server.

[0099] S209: The server decrypts the preset key according to the decryption key, determines whether it is consistent with the preset key stored in advance, and if so, decrypts the username and password according to the preset key for identity verification.

[0100] S210: If the identity verification is passed, the server notifies the target subsystem of the successful verification result.

[0101] S211: The target subsystem jumps to the target page for the data visualization large screen to access.

[0102] In the above embodiments, a system login method is described in detail. The present application also provides corresponding embodiments of a system login device. It should be noted that the present application describes the embodiments of the device part from two perspectives, one is from the perspective of functional modules, and the other is from the perspective of hardware.

[0103] From the perspective of functional modules, as Figure 3 shown, the present embodiment provides a system login device, including:

[0104] A request receiving module 31, configured to receive a user's access request; wherein, the access request includes: a target subsystem and a target page;

[0105] An information acquisition module 32, configured to forward an access request to a backend server to obtain the IP address, username, password, and token information corresponding to the target subsystem; wherein, the token information is an encrypted key transmitted in the form of a token, and the backend server stores the decryption key corresponding to the token information;

[0106] A path determination module 33, configured to obtain an access path pointing to a target page in the target subsystem according to the IP address of the target subsystem and in combination with pre-configured routing information corresponding to the target subsystem;

[0107] An information encryption module 34, configured to encrypt the username and password corresponding to the target subsystem according to a preset key, and encrypt the preset key through the token information;

[0108] A page login module 35, configured to access the target subsystem according to the access path and send the encrypted username, password, and preset key to the target subsystem, so that the target subsystem requests the backend server to perform user login verification. If the user login verification is passed, the backend server notifies the target subsystem to jump to the target page.

[0109] Preferably, the above system login device further includes:

[0110] An information configuration module, configured to receive and store configuration information sent by a user; wherein, the configuration information includes routing information and preset keys corresponding to each subsystem.

[0111] Since the embodiments of the device part correspond to the embodiments of the method part, for the embodiments of the device part, please refer to the description of the embodiments of the method part, and will not be elaborated here.

[0112] Figure 4 The structural diagram of a system login device provided by another embodiment of the present application is as follows Figure 4 As shown, a system login device includes: a memory 40, configured to store a computer program;

[0113] A processor 41, configured to implement the steps of a system login method as described in the above embodiment when executing the computer program.

[0114] The system login device provided in this embodiment may include but is not limited to a data system, a server, a visualization large screen, etc.

[0115] Among them, the processor 41 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 41 may be implemented in at least one hardware form of a digital signal processor (DSP), a field-programmable gate array (FPGA), or a programmable logic array (PLA). The processor 41 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the wake state, also known as the central processing unit (CPU); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 41 may be integrated with a graphics processing unit (GPU), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 41 may further include an artificial intelligence (AI) processor, and the AI processor is used to process computational operations related to machine learning.

[0116] The memory 40 may include one or more computer-readable storage media, and the computer-readable storage media may be non-transitory. The memory 40 may further include high-speed random access memory and non-volatile memory, such as one or more disk storage devices and flash storage devices. In this embodiment, the memory 40 is at least used to store the following computer program 401. After the computer program is loaded and executed by the processor 41, it can implement the relevant steps of a system login method disclosed in any of the foregoing embodiments. In addition, the resources stored in the memory 40 may further include an operating system 402 and data 403, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 402 may include Windows, Unix, Linux, etc. The data 403 may include, but is not limited to, a system login method, etc.

[0117] In some embodiments, a system login device may further include a display screen 42, an input / output interface 43, a communication interface 44, a power supply 45, and a communication bus 46.

[0118] Those skilled in the art can understand that Figure 4 the structure shown in

[0119] An example of a system login device provided by an embodiment of the present application includes a memory and a processor. When the processor executes the program stored in the memory, the following method can be implemented: A system login method.

[0120] Finally, the present application also provides an example corresponding to a computer-readable storage medium. A computer program is stored on the computer-readable storage medium, and when the computer program is executed by the processor, the steps recorded in the above method example are implemented.

[0121] It can be understood that if the method in the above embodiments is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and executes all or part of the steps of the methods described in various embodiments of the present application. And the foregoing storage media include: USB flash drives, mobile hard disks, read-only memories (ROM), random access memories (RAM), magnetic disks, or optical discs and other various media that can store program codes.

[0122] The above provides a detailed introduction to a system login method, device, and its medium provided by the present application. Each embodiment in the specification is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple. For the relevant parts, refer to the description of the method part. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.

[0123] It should also be noted that in this specification, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements not only includes those elements, but also includes other elements not expressly listed, or also includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the said element.

Claims

1. A system login method, characterized in that, including: Receiving an access request from a user; wherein, the access request includes: a target subsystem and a target page; Forwarding the access request to a backend server to obtain the IP address, username, password, and token information corresponding to the target subsystem; wherein, the token information is an encrypted key transmitted in the form of a token, and the backend server stores the decryption key corresponding to the token information; Obtaining an access path pointing to the target page in the target subsystem according to the IP address of the target subsystem and in combination with the pre-configured routing information corresponding to the target subsystem; Encrypting the username and password corresponding to the target subsystem according to a preset key, and encrypting the preset key with the token information; Accessing the target subsystem according to the access path and sending the encrypted username, password, and the preset key to the target subsystem, so that the target subsystem requests the backend server to perform user login verification. If the user login verification passes, the backend server notifies the target subsystem to jump to the target page.

2. The system login method according to claim 1, wherein, The preset key is the key of a symmetric encryption algorithm.

3. The system login method according to claim 2, wherein The token information and its corresponding decryption key are a pair of keys of an asymmetric encryption algorithm; wherein, the token information is the public key, and the decryption key is the private key.

4. The system login method according to claim 3, wherein The obtained IP address, username, password, and token information corresponding to the target subsystem are pre-encrypted by the backend server; Correspondingly, after obtaining the IP address, username, password, and token information corresponding to the target subsystem, it further includes: Decrypting the IP address, username, password, and token information corresponding to the target subsystem to obtain the decrypted IP address, username, password, and token information.

5. The system login method according to claim 4, wherein The preset key is the key of the AES encryption algorithm.

6. The system login method according to claim 5, characterized in that, The token information is the public key of the RSA encryption algorithm.

7. The system login method according to any one of claims 1 to 6, characterized in that, Before receiving the access request from the user, it further includes: Receiving and storing the configuration information sent by the user; wherein, the configuration information includes the routing information corresponding to each subsystem and the preset key.

8. A system login device, characterized in that, including: A request receiving module, configured to receive an access request from a user; wherein, the access request includes: a target subsystem and a target page; An information obtaining module, configured to forward the access request to a backend server to obtain the IP address, username, password, and token information corresponding to the target subsystem; wherein, the token information is an encrypted key transmitted in the form of a token, and the backend server stores the decryption key corresponding to the token information; A path determining module, configured to obtain an access path pointing to the target page in the target subsystem according to the IP address of the target subsystem and in combination with the pre-configured routing information corresponding to the target subsystem; An information encrypting module, configured to encrypt the username and password corresponding to the target subsystem according to a preset key, and encrypt the preset key with the token information; The page login module is used to access the target subsystem according to the access path, and send the encrypted username, password, and the preset key to the target subsystem, so that the target subsystem requests the backend server to perform user login verification. If the user login verification is passed, the backend server notifies the target subsystem to jump to the target page.

9. A system login device, characterized in that, It includes: A memory for storing computer programs; A processor for implementing the steps of the system login method according to any one of claims 1 to 7 when executing the computer program.

10. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by the processor, the steps of the system login method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Same-account incredible terminal login method and system based on credible terminal

    CN104135494A

  • Reverse proxy method and device, electronic equipment and storage medium

    CN107613005A