LDAP-based identity uniform authentication method and system
Patent Information
- Application Number
- CN202310554728.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-05-17
- Publication Date
- 2026-10-09
- Estimated Expiration
- 2043-05-17
AI Technical Summary
然而,这也带来了一个问题:用户需要在每个web应用对应的web系统中输入用户名和密码进行登录,这不仅给用户带来了麻烦,也增加了用户信息泄露的风险
[0039] The reverse proxy server intercepts and forwards authentication requests from web applications to the authentication server. The authentication server then forwards the authentication requests to the LDAP server. The LDAP server authenticates the authentication requests based on the created user data, generates a authentication result, and sends the result sequentially through the authentication server, reverse proxy server, and network firewall to the web application. The web application then performs a login operation based on the received authentication result. In short, the reverse proxy server forwards web application authentication requests to the LDAP server for verification, allowing users to seamlessly switch between multiple web applications without logging in to each application and without intruding on the web applications, thus greatly improving the convenience of unified identity verification. The network firewall protects the data transmitted between the web application and the reverse proxy server. Data transmission between the reverse proxy server, authentication server, and LDAP server uses secure protocols and is encrypted. Combined with logs recording the authentication process, the logs are monitored in real time based on preset regulatory rules. These five security measures significantly enhance the security of unified identity verification.
Smart Images

Figure CN116668096B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of identity verification technology, and in particular to a unified identity verification method and system based on LDAP. Background Technology
[0002] With the development of the internet, more and more web applications have emerged, providing users with a variety of services. However, this has also brought a problem: users need to enter their username and password to log in to each web application's corresponding web system. This not only causes inconvenience for users but also increases the risk of user information leakage. To solve this problem, the concept of unified authentication was proposed. Its goal is to allow users to log in to only one web system and automatically log in to other web systems without having to enter their username and password again.
[0003] Traditionally, there are several methods to implement unified authentication:
[0004] One approach is through session data sharing or session persistence. While these methods can achieve the goal of unified authentication, they require maintaining additional components or data storage layers, increasing the complexity of the web system. Furthermore, they are not well-suited for handling large-scale concurrent access.
[0005] Another approach is to integrate multiple web systems using Single Sign-On (SSO), which allows users to log in to one web system and automatically log in to other web systems. However, this method increases the complexity of the web system because it requires maintaining additional components and trust relationships, as well as some modifications to the web system. Different authentication clients need to be developed depending on the authentication server. Furthermore, it introduces security risks, because once the authentication server is compromised, attackers can gain access to all web systems.
[0006] Therefore, how to provide a unified identity verification method and system based on LDAP to improve the convenience and security of unified identity verification has become an urgent technical problem to be solved. Summary of the Invention
[0007] The technical problem to be solved by the present invention is to provide a unified identity verification method and system based on LDAP, so as to improve the convenience and security of unified identity verification.
[0008] In a first aspect, the present invention provides an LDAP-based unified identity verification method, comprising the following steps:
[0009] Step S10: Configure the reverse proxy for the web application on the reverse proxy server to forward the web application's verification requests to the authentication server.
[0010] Step S20: Create user data for authentication on the LDAP server;
[0011] Step S30: The reverse proxy server intercepts the verification request from the web application and forwards the intercepted verification request to the authentication server.
[0012] Step S40: The authentication server forwards the verification request to the LDAP server. The LDAP server verifies the verification request based on the user data and then generates a verification result.
[0013] Step S50: The LDAP server sends the verification result to the web application sequentially through the authentication server, the reverse proxy server, and the network firewall.
[0014] Step S60: The web application performs a login operation based on the received verification result.
[0015] Further, step S20 specifically includes:
[0016] Create user data for authentication on the LDAP server and store the user data in a pre-created LDAP directory.
[0017] Further, step S30 specifically includes:
[0018] The reverse proxy server intercepts the verification requests from web applications through a network firewall, encrypts the intercepted verification requests using a preset key, and forwards them to the authentication server based on a security protocol; the verification request carries at least the data to be verified and the request time.
[0019] Further, step S40 specifically includes:
[0020] The authentication server pre-stores the URL, DN, and password for connecting to the LDAP server. Based on the URL, DN, and password, the authentication server forwards the verification request to the LDAP server. The LDAP server decrypts the verification request using a preset key, authenticates the verification request based on the user data, and generates a verification result.
[0021] Further, step S50 specifically includes:
[0022] The LDAP server encrypts the verification result using a preset key and sends it to the web application sequentially through the authentication server, reverse proxy server, and network firewall based on a security protocol. It also records logs during the verification process and monitors the logs in real time based on preset regulatory rules.
[0023] Secondly, this invention provides an LDAP-based unified identity verification system, comprising the following modules:
[0024] The reverse proxy server configuration module is used to configure the reverse proxy of web applications on the reverse proxy server, which forwards the verification requests of web applications to the authentication server.
[0025] The LDAP server configuration module is used to create user data for authentication on the LDAP server;
[0026] The verification request interception module is used by the reverse proxy server to intercept verification requests from web applications and forward the intercepted verification requests to the authentication server.
[0027] An authentication module is used by the authentication server to forward the authentication request to the LDAP server, and the LDAP server to authenticate the authentication request based on the user data and generate an authentication result.
[0028] The verification result sending module is used by the LDAP server to send the verification result to the web application sequentially through the authentication server, the reverse proxy server, and the network firewall.
[0029] The login module is used by the web application to perform a login operation based on the received verification result.
[0030] Furthermore, the LDAP server configuration module is specifically used for:
[0031] Create user data for authentication on the LDAP server and store the user data in a pre-created LDAP directory.
[0032] Furthermore, the verification request interception module is specifically used for:
[0033] The reverse proxy server intercepts the verification requests from web applications through a network firewall, encrypts the intercepted verification requests using a preset key, and forwards them to the authentication server based on a security protocol; the verification request carries at least the data to be verified and the request time.
[0034] Furthermore, the authentication module is specifically used for:
[0035] The authentication server pre-stores the URL, DN, and password for connecting to the LDAP server. Based on the URL, DN, and password, the authentication server forwards the verification request to the LDAP server. The LDAP server decrypts the verification request using a preset key, authenticates the verification request based on the user data, and generates a verification result.
[0036] Furthermore, the verification result sending module is specifically used for:
[0037] The LDAP server encrypts the verification result using a preset key and sends it to the web application sequentially through the authentication server, reverse proxy server, and network firewall based on a security protocol. It also records logs during the verification process and monitors the logs in real time based on preset regulatory rules.
[0038] The advantages of this invention are:
[0039] The reverse proxy server intercepts and forwards authentication requests from web applications to the authentication server. The authentication server then forwards the authentication requests to the LDAP server. The LDAP server authenticates the authentication requests based on the created user data, generates a authentication result, and sends the result sequentially through the authentication server, reverse proxy server, and network firewall to the web application. The web application then performs a login operation based on the received authentication result. In short, the reverse proxy server forwards web application authentication requests to the LDAP server for verification, allowing users to seamlessly switch between multiple web applications without logging in to each application and without intruding on the web applications, thus greatly improving the convenience of unified identity verification. The network firewall protects the data transmitted between the web application and the reverse proxy server. Data transmission between the reverse proxy server, authentication server, and LDAP server uses secure protocols and is encrypted. Combined with logs recording the authentication process, the logs are monitored in real time based on preset regulatory rules. These five security measures significantly enhance the security of unified identity verification. Attached Figure Description
[0040] The present invention will be further described below with reference to the accompanying drawings and embodiments.
[0041] Figure 1 This is a flowchart of an LDAP-based unified identity verification method according to the present invention.
[0042] Figure 2 This is a schematic diagram of the structure of an LDAP-based unified identity verification system according to the present invention. Detailed Implementation
[0043] The overall approach of the technical solution in this application is as follows: A reverse proxy server forwards the verification requests from web applications to an LDAP server for verification. The LDAP server allows users to seamlessly switch between multiple web applications without needing to log in to each application, and provides non-intrusive verification, thus improving the convenience of unified identity verification. A network firewall protects the transmitted data. Data transmission between the reverse proxy server, authentication server, and LDAP server is conducted using secure protocols and is encrypted. Logs recorded during the verification process are monitored in real-time based on preset regulatory rules to enhance the security of unified identity verification.
[0044] Please refer to Figures 1 to 2 As shown, a preferred embodiment of the LDAP-based unified identity verification method of the present invention includes the following steps:
[0045] Step S10: Configure a reverse proxy for the web application on a reverse proxy server (such as Nginx) to forward the web application's authentication requests to the authentication server.
[0046] Step S20: Create user data for authentication on the LDAP server;
[0047] Deploying an LDAP server on a dedicated server and configuring all web applications to use that LDAP server for authentication enables unified management of user data. When a user logs in to a web application, their credentials are sent to the LDAP server for verification. If verification is successful, the user is granted access rights, and there's no need to log in again when switching to other web applications, greatly improving the user experience and reducing the hassle of switching between multiple systems. Compared to other authentication servers (such as OAuth2), LDAP servers offer advantages in terms of lightweightness and efficiency, and can quickly respond to user authentication requests.
[0048] Step S30: The reverse proxy server intercepts the verification request from the web application and forwards the intercepted verification request to the authentication server.
[0049] Step S40: The authentication server forwards the verification request to the LDAP server. The LDAP server verifies the verification request based on the user data and then generates a verification result.
[0050] Step S50: The LDAP server sends the verification result to the web application sequentially through the authentication server, the reverse proxy server, and the network firewall.
[0051] Step S60: The web application performs a login operation based on the received verification result, that is, single sign-on and unified user authentication are achieved without modifying the web application.
[0052] In terms of user authentication design, this invention, based on the design principles of LDAP, designs a more efficient authentication architecture, making user management across multiple web applications more efficient and achieving a better single sign-on experience. Regarding network security design, based on the design principles of a reverse proxy server, it designs a more efficient authentication architecture, making request interception and authentication in web applications more efficient, thus achieving the goal of single sign-on without modifying the web applications.
[0053] Step S20 specifically involves:
[0054] User data for authentication is created on the LDAP server and stored in a pre-created LDAP directory. Unifying user data from all web applications and systems into the LDAP directory simplifies user management and makes it easier for administrators to manage and maintain user data.
[0055] This means that LDAP (Lightweight Directory Access Protocol) is used to uniformly manage user data from multiple web applications. LDAP provides an information service known as a directory service, which can be viewed as a special database system. It can effectively solve the user account problem for many network services, define a unified identity information database, identity authentication mechanism and interface, realize unified management of resources and information, and ensure the consistency and integrity of user data.
[0056] Step S30 specifically involves:
[0057] The reverse proxy server intercepts the verification requests from web applications through a network firewall, encrypts the intercepted verification requests using a preset key, and forwards them to the authentication server based on a security protocol; the verification request carries at least the data to be verified and the request time.
[0058] A reverse proxy server intercepts authentication requests from a web application and performs authentication, then forwards the authenticated request to the web application. This allows for single sign-on without modifying the web application. Furthermore, by deploying the reverse proxy server behind a network firewall and acting as a "front end" to control and protect access to backend servers on a private network, it can effectively protect backend servers from attacks and improve system security.
[0059] Step S40 specifically involves:
[0060] The authentication server pre-stores the URL, DN, and password for connecting to the LDAP server. Based on the URL, DN, and password, the authentication server forwards the verification request to the LDAP server. The LDAP server decrypts the verification request using a preset key, authenticates the verification request based on the user data, and generates a verification result.
[0061] Step S50 specifically involves:
[0062] The LDAP server encrypts the verification result using a preset key and sends it to the web application sequentially through the authentication server, reverse proxy server, and network firewall based on a security protocol. It also records logs during the verification process and monitors the logs in real time based on preset regulatory rules.
[0063] A preferred embodiment of the LDAP-based unified identity verification system of the present invention includes the following modules:
[0064] The reverse proxy server configuration module is used to configure a reverse proxy for a web application on a reverse proxy server (such as Nginx), which forwards the web application's authentication requests to the authentication server.
[0065] The LDAP server configuration module is used to create user data for authentication on the LDAP server;
[0066] Deploying an LDAP server on a dedicated server and configuring all web applications to use that LDAP server for authentication enables unified management of user data. When a user logs in to a web application, their credentials are sent to the LDAP server for verification. If verification is successful, the user is granted access rights, and there's no need to log in again when switching to other web applications, greatly improving the user experience and reducing the hassle of switching between multiple systems. Compared to other authentication servers (such as OAuth2), LDAP servers offer advantages in terms of lightweightness and efficiency, and can quickly respond to user authentication requests.
[0067] The verification request interception module is used by the reverse proxy server to intercept verification requests from web applications and forward the intercepted verification requests to the authentication server.
[0068] An authentication module is used by the authentication server to forward the authentication request to the LDAP server, and the LDAP server to authenticate the authentication request based on the user data and generate an authentication result.
[0069] The verification result sending module is used by the LDAP server to send the verification result to the web application sequentially through the authentication server, the reverse proxy server, and the network firewall.
[0070] The login module is used by the web application to perform a login operation based on the received verification result, that is, to achieve single sign-on and unified user authentication without modifying the web application.
[0071] In terms of user authentication design, this invention, based on the design principles of LDAP, designs a more efficient authentication architecture, making user management across multiple web applications more efficient and achieving a better single sign-on experience. Regarding network security design, based on the design principles of a reverse proxy server, it designs a more efficient authentication architecture, making request interception and authentication in web applications more efficient, thus achieving the goal of single sign-on without modifying the web applications.
[0072] The LDAP server configuration module is specifically used for:
[0073] User data for authentication is created on the LDAP server and stored in a pre-created LDAP directory. Unifying user data from all web applications and systems into the LDAP directory simplifies user management and makes it easier for administrators to manage and maintain user data.
[0074] This means that LDAP (Lightweight Directory Access Protocol) is used to uniformly manage user data from multiple web applications. LDAP provides an information service known as a directory service, which can be viewed as a special database system. It can effectively solve the user account problem for many network services, define a unified identity information database, identity authentication mechanism and interface, realize unified management of resources and information, and ensure the consistency and integrity of user data.
[0075] The verification request interception module is specifically used for:
[0076] The reverse proxy server intercepts the verification requests from web applications through a network firewall, encrypts the intercepted verification requests using a preset key, and forwards them to the authentication server based on a security protocol; the verification request carries at least the data to be verified and the request time.
[0077] A reverse proxy server intercepts authentication requests from a web application and performs authentication, then forwards the authenticated request to the web application. This allows for single sign-on without modifying the web application. Furthermore, by deploying the reverse proxy server behind a network firewall and acting as a "front end" to control and protect access to backend servers on a private network, it can effectively protect backend servers from attacks and improve system security.
[0078] The authentication module is specifically used for:
[0079] The authentication server pre-stores the URL, DN, and password for connecting to the LDAP server. Based on the URL, DN, and password, the authentication server forwards the verification request to the LDAP server. The LDAP server decrypts the verification request using a preset key, authenticates the verification request based on the user data, and generates a verification result.
[0080] The verification result sending module is specifically used for:
[0081] The LDAP server encrypts the verification result using a preset key and sends it to the web application sequentially through the authentication server, reverse proxy server, and network firewall based on a security protocol. It also records logs during the verification process and monitors the logs in real time based on preset regulatory rules.
[0082] To facilitate understanding of the present invention, the following examples are provided for further illustration:
[0083] 1. Set up Nginx and configure reverse proxy and authentication:
[0084] 1. Configure a reverse proxy on Nginx: In the Nginx configuration file, add a new `server` block to forward Kibana requests to the Kibana server. For example:
[0085]
[0086] 2. Configure authentication on Nginx: In the Nginx configuration file, use the ngx_http_auth_request_module module to implement LDAP authentication. For example:
[0087]
[0088]
[0089] Using Nginx's ngx_http_auth_request_module to implement LDAP authentication offers greater flexibility. This module allows sub-requests to be sent to an external authentication server before processing the main request. You can use this module to send authentication requests to an LDAP-enabled authentication server, such as auth-ldap. The authentication server is responsible for receiving authentication requests from Nginx and communicating with the LDAP server using the LDAP protocol to verify the user's identity. This allows for flexible configuration of the authentication process to meet the needs of different applications.
[0090] II. Setting up an LDAP server:
[0091] Create a new user on the LDAP server for Kibana authentication, for example:
[0092] dn:uid=kibanauser,ou=people,dc=yourdomain,dc=com
[0093] objectClass:top
[0094] objectClass:person
[0095] objectClass:organizationalPerson
[0096] objectClass:inetOrgPerson
[0097] uid:kibanauser
[0098] cn:Kibana User
[0099] sn:User
[0100] givenName:Kibana
[0101] mail:kibanauser@yourdomain.com
[0102] userPassword:{CLEARTEXT}password
[0103] III. Application Configuration:
[0104] In the Kibana configuration file, set `elasticsearch.username` and `elasticsearch.password` to empty so that Kibana can authenticate and authorize via Nginx. Specifically, add the following content to the `kibana.yml` file:
[0105] ```
[0106] elasticsearch.username:""
[0107] elasticsearch.password:""
[0108] ```
[0109] IV. Setting up and configuring an LDAP-enabled Authentication Server:
[0110] The authentication server is responsible for receiving authentication requests from Nginx and communicating with the LDAP server using the LDAP protocol to verify the user's identity. This can be implemented by writing your own Python code or by installing an OAuth2 authorization server.
[0111] If system security requirements are not high, you can also configure ldap_server directly in Nginx to bypass the authentication server and directly authenticate with the LDAP server. The configuration of ldap_server in Nginx is as follows:
[0112] Configure the auth-ldap module. You need to add an `ldap_server` block to your Nginx configuration file to configure the LDAP server information. For example:
[0113]
[0114] In summary, the advantages of this invention are:
[0115] The reverse proxy server intercepts and forwards authentication requests from web applications to the authentication server. The authentication server then forwards the authentication requests to the LDAP server. The LDAP server authenticates the authentication requests based on the created user data, generates a authentication result, and sends the result sequentially through the authentication server, reverse proxy server, and network firewall to the web application. The web application then performs a login operation based on the received authentication result. In short, the reverse proxy server forwards web application authentication requests to the LDAP server for verification, allowing users to seamlessly switch between multiple web applications without logging in to each application and without intruding on the web applications, thus greatly improving the convenience of unified identity verification. The network firewall protects the data transmitted between the web application and the reverse proxy server. Data transmission between the reverse proxy server, authentication server, and LDAP server uses secure protocols and is encrypted. Combined with logs recording the authentication process, the logs are monitored in real time based on preset regulatory rules. These five security measures significantly enhance the security of unified identity verification.
[0116] While specific embodiments of the present invention have been described above, those skilled in the art should understand that the specific embodiments described are merely illustrative and not intended to limit the scope of the present invention. Equivalent modifications and variations made by those skilled in the art in accordance with the spirit of the present invention should be covered within the scope of protection of the claims of the present invention.
Claims
1. A unified identity verification method based on LDAP, characterized in that: Includes the following steps: Step S10: Configure the reverse proxy for the web application on the reverse proxy server to forward the web application's verification requests to the authentication server. Step S20: Create user data for authentication on the LDAP server and store the user data in a pre-created LDAP directory; Step S30: The reverse proxy server intercepts the verification requests of the web application through the network firewall, encrypts the intercepted verification requests using a preset key, and forwards them to the authentication server based on a security protocol. The verification request must carry at least the data to be verified and the request time; Step S40: The authentication server pre-stores the URL, DN, and password for connecting to the LDAP server; the authentication server forwards the verification request to the LDAP server based on the URL, DN, and password; the LDAP server decrypts the verification request using a preset key, authenticates the verification request based on the user data, and generates a verification result. Step S50: The LDAP server encrypts the verification result using a preset key and sends it to the web application sequentially through the authentication server, reverse proxy server, and network firewall based on the security protocol. It also records the logs during the verification process and monitors the logs in real time based on preset supervision rules. Step S60: The web application performs a login operation based on the received verification result.
2. An LDAP-based unified identity verification system, characterized in that: It includes a reverse proxy server configuration module, an LDAP server configuration module, a verification request interception module, an authentication module, a verification result sending module, and a login module; The reverse proxy server configuration module is set on the reverse proxy server and is used to configure the reverse proxy of the web application on the reverse proxy server so as to forward the verification request of the web application to the authentication server. The LDAP server configuration module is set on the LDAP server and is used to create user data for authentication on the LDAP server and store the user data in a pre-created LDAP directory. The verification request interception module is set on the reverse proxy server and is used by the reverse proxy server to intercept the verification requests of the web application through the network firewall, encrypt the intercepted verification requests using a preset key, and forward them to the authentication server based on a security protocol. The verification request must carry at least the data to be verified and the request time; The authentication module is set on the authentication server and the LDAP server. It is used by the authentication server to forward the authentication request to the LDAP server based on the pre-stored URL, DN and password. The LDAP server decrypts the authentication request using a preset key, authenticates the authentication request based on the user data and generates an authentication result. The verification result sending module is set on the LDAP server. It is used by the LDAP server to encrypt the verification result using a preset key and send it to the web application sequentially through the authentication server, reverse proxy server and network firewall based on the security protocol. It also records the logs during the verification process and monitors the logs in real time based on preset supervision rules. The login module is set on the web application and is used by the web application to perform a login operation based on the received verification result.
Citation Information
Patent Citations
Method and system for authentication and connection
CN101707522A
Proxy authentication system, proxy authentication method, and program
JP2019040319A