A third-party authorized login method and system
By identifying and transmitting the Quick App's identity information to the manufacturer's server for security testing through the engine app, the problem of the manufacturer's app being unable to verify the Quick App's identity is solved, ensuring the security and legitimacy of Quick App authorized login.
Patent Information
- Application Number
- CN202311557348.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-21
- Publication Date
- 2025-11-25
- Estimated Expiration
- 2043-11-21
Smart Images

Figure CN117499137B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of computer, in particular to a third-party authorization login method and system. BACKGROUND
[0002] Fast application is a kind of small program application based on underlying mobile phone system, which is used by terminal user immediately and runs in the engine App controlled by mobile phone manufacturer. At present, a large number of fast applications need to access the third-party authorization service of large mobile application (hereinafter referred to as manufacturer App), and authenticate the identity of the user through the returned authorization information without additional input of account and password by the user. However, the authorization service provided by the current manufacturer App is only suitable for general Android applications, not fast applications. More specifically, in the current authorization service, the engine App of the mobile phone manufacturer interacts with the manufacturer App, not the fast application running in it. Therefore, the manufacturer App cannot directly verify the identity of the fast application, which may introduce security risks. SUMMARY
[0003] One or more embodiments of the present specification provide a third-party authorization login method and system, which can provide a reliable third-party authorization login scheme for fast applications and guarantee the security of the authorization process.
[0004] According to a first aspect, a third-party authorization login method is provided, which is suitable for an authorization end including a mobile application APP and an application server; the method comprises:
[0005] In response to an authorization request of the engine APP, the mobile application APP acquires the identity information of the target fast application uploaded by the engine APP after authentication, and collects the identity information of the engine APP;
[0006] The mobile application APP initiates an authorization request to the application server and synchronously sends the identity information of the engine APP and the identity information of the target fast application;
[0007] In response to the authorization request of the mobile application APP, the application server authenticates the identity information of the engine APP and the identity information of the target fast application, and after the authentication is passed, the authorization credential is issued to the target fast application through the engine APP, so that the target fast application can acquire user information by means of the authorization credential and complete the login of the target fast application based on the user information.
[0008] As an optional implementation of the method of the first aspect, the engine APP authenticates the identity information of the target fast application, specifically comprising:
[0009] In response to the authorization request of the target fast application, the engine APP collects the identity information of the target fast application;
[0010] The engine APP performs consistency comparison on the identity information of the target fast application and the locally pre-stored fast application identity information. If there is pre-stored fast application identity information consistent with the identity information of the target fast application, the identity information of the target fast application is authenticated.
[0011] As an optional implementation of the method of the first aspect, after the mobile application APP collects the identity information of the engine APP, the identity information of the engine APP is further authenticated. After authentication, the application server is sent an authorization request, the identity information of the engine APP and the identity information of the target fast application.
[0012] Specifically, the mobile application APP authenticates the identity information of the engine APP, specifically including:
[0013] The identity information of the engine APP is compared with the authorization request of the engine APP. If the identity information of the engine APP is associated with the authorization request of the engine APP, the identity information of the engine APP is authenticated.
[0014] As an optional implementation of the method of the first aspect, the application server authenticates the identity information of the engine APP and the identity information of the target fast application, specifically including:
[0015] The application server performs consistency comparison on the identity information of the engine APP and the locally pre-stored engine identity information. If there is pre-stored engine identity information consistent with the identity information of the engine APP, the identity information of the engine APP is authenticated.
[0016] The application server performs consistency comparison on the identity information of the target fast application and the locally pre-stored fast application identity information. If there is pre-stored fast application identity information consistent with the identity information of the target fast application, the identity information of the target fast application is authenticated.
[0017] As an optional implementation of the method of the first aspect, before the application server issues the authorization credential to the target fast application through the engine APP, it further includes:
[0018] In response to the user's authorization confirmation information for the target fast application through the mobile application APP, the authorization credential is generated.
[0019] According to the second aspect, a third-party authorization login method is provided, which is suitable for a fast application end, the fast application end including a target fast application and a fast application server of the target fast application; the method includes:
[0020] In response to a user operation, the target fast application sends an authorization request to the engine APP to enable the engine APP to collect and authenticate identity information of the target fast application, and after authentication, apply for an authorization credential from an authorization end;
[0021] In response to the authorization credential returned by the engine APP, the target fast application sends the authorization credential to the fast application server;
[0022] In response to obtaining the authorization credential, the fast application server obtains user information from the authorization end based on the authorization credential, and completes the target fast application login based on the user information.
[0023] As an optional implementation of the method of the second aspect, the authorization end includes a mobile application APP and an application server; the engine APP applies for the authorization credential from the authorization end, specifically including:
[0024] The engine APP initiates an authorization request to the mobile application APP and synchronizes the identity information of the target fast application;
[0025] In response to the authorization request of the engine APP, the mobile application APP collects the identity information of the engine APP, and sends an authorization request, the identity information of the target fast application and the identity information of the engine APP to the application server;
[0026] In response to the authorization request of the mobile application APP, the application server authenticates the identity information of the target fast application and the identity information of the engine APP, and after authentication, returns an authorization credential to the mobile application APP;
[0027] The mobile application APP sends the authorization credential to the target fast application through the engine APP.
[0028] According to a third aspect, a third-party authorization login system is provided, including an authorization end and a fast application end;
[0029] The authorization end is configured to execute the third-party authorization login method applicable to the authorization end, and the fast application end is configured to execute the third-party authorization login method applicable to the fast application end, to realize the authorization login of the target fast application.
[0030] According to a fourth aspect, a terminal device is provided, which is installed with an engine APP and a mobile application APP provided by an authorization end, and the engine APP is deployed with a target fast application; the target fast application performs third-party authorization login based on user information obtained by the mobile application APP, specifically including:
[0031] In response to a user operation, the target quick application sends an authorization request to the engine APP;
[0032] In response to the authorization request of the target quick application, the engine APP collects and authenticates the identity information of the target quick application, and after authentication, sends an authorization request and the identity information of the target quick application to the mobile application APP;
[0033] In response to the authorization request of the engine APP, the mobile application APP collects the identity information of the engine APP, and sends an authorization request, the identity information of the engine APP and the identity information of the target quick application to the application server;
[0034] In response to the authorization request of the mobile application APP, the application server authenticates the identity information of the engine APP and the identity information of the target quick application, and after authentication, issues an authorization credential to the target quick application through the engine APP;
[0035] In response to obtaining the authorization credential, the target quick application obtains user information from the application server based on the authorization credential, and completes login based on the user information.
[0036] As an optional implementation of the terminal device of the fourth aspect, the target quick application obtains user information from the application server based on the authorization credential, and completes login based on the user information, specifically including:
[0037] The target quick application sends the authorization credential to the quick application server;
[0038] In response to obtaining the authorization credential, the quick application service requests user information from the application server based on the authorization credential, and completes login of the target quick application based on the obtained user information.
[0039] The authorization login method of one or more embodiments of the present specification has the beneficial effect that in the process of third-party authorization login for a quick application, the engine App controlled by the mobile phone manufacturer is responsible for maintaining and identifying the subject identity information of the quick application, and the authorization request is transmitted to the mobile application App; the mobile application App also needs to collect the identity information of the engine App, and the two parts of information (quick application & engine App) are transmitted to the manufacturer server for security detection. Therefore, the mobile application App can ensure the legality of the quick application interacting with it, that is, to ensure that the user's authorization credential is transmitted to a legal third party.
[0040] The system and terminal device of the embodiments of the present specification also have the beneficial effects described above. BRIEF DESCRIPTION OF DRAWINGS
[0041] In order to make the technical solutions in the embodiments or the prior art of the specification clearer, the accompanying drawings needed in the embodiments or prior art description will be briefly introduced. Obviously, the accompanying drawings in the following description are some embodiments of the specification, and other drawings can be obtained by a person of ordinary skill in the art without creative effort.
[0042] Figure 1 A third-party authorization login process schematic diagram provided by a mobile application in the prior art is shown.
[0043] Figure 2 According to some embodiments of the present application, a structural schematic diagram of a third-party authorization login system is shown.
[0044] Figure 3 According to some embodiments of the present application, a third-party authorization login method implemented by a third-party authorization login system is shown.
[0045] Figure 4 According to some embodiments of the present application, a third-party authorization login method suitable for an authorization end is shown.
[0046] Figure 5 According to some embodiments of the present application, a third-party authorization login method suitable for a fast application end is shown.
[0047] Figure 6 According to some embodiments of the present application, a structural diagram of a terminal device is shown. DETAILED DESCRIPTION
[0048] A fast application is a kind of mini-program application based on an underlying mobile phone system, which is used by a terminal user as soon as it is clicked and runs in an engine App controlled by a mobile phone manufacturer. At present, a large number of fast applications (hereinafter referred to as merchant Apps) need to access the third-party authorization service of a large mobile application (hereinafter referred to as manufacturer App), and authenticate the identity of the user through the returned authorization information without the user entering additional account and password. However, the authorization service provided by the current manufacturer App is only suitable for general Android applications, not fast applications. More specifically, in the current authorization service, the engine App of the mobile phone manufacturer interacts with the manufacturer App, not the fast application running therein. Therefore, the manufacturer App cannot directly verify the identity of the fast application, and may introduce security risks.
[0049] Please refer to Figure 1 , Figure 1 A third-party authorization login process schematic diagram provided by a manufacturer App in the prior art is shown, which includes the following steps:
[0050] (101) The merchant App initiates an authorization request to the vendor App.
[0051] (102) The vendor App collects the identity information of the merchant App and detects whether the identity information of the merchant App is associated with the authorization request in step (101); if yes, proceed to step (103), otherwise, terminate the authorization login process.
[0052] (103) The vendor App sends an authorization request to the vendor server and synchronously sends the identity information of the merchant App.
[0053] (104) The vendor server verifies the received identity information of the merchant App.
[0054] (105) After the vendor server verifies the received identity information of the merchant App, the vendor server returns a user authorization request to the vendor App, which is used to inquire whether the user agrees to authorize the user information in the vendor App to the merchant App.
[0055] (106) The user confirms to authorize the user information in the vendor App to the merchant App through the page of the vendor App; the vendor App sends the user confirmation authorization information to the vendor server.
[0056] (107) After the vendor server receives the user confirmation authorization information, the vendor server generates an authorization credential code, and then returns the authorization credential code to the vendor App.
[0057] (108) The vendor App returns the authorization credential code to the merchant App.
[0058] (109) The merchant App sends the authorization credential code to the merchant server and requests the merchant server to verify the authorization credential code.
[0059] (110) The merchant server verifies the authorization credential code to the vendor server and requests to obtain the user information.
[0060] (111) After the vendor server verifies the authorization credential code, the vendor server returns the user information to the merchant server.
[0061] (112) The merchant server authenticates the user identity according to the user information.
[0062] (113) The merchant server returns the user login state to the merchant App, and completes the login of the user on the merchant App.
[0063] From the above flow, in steps (102) to (104), the vendor App actively collects the identity information of the merchant App and detects whether it is associated with the authorization request in step 1. Otherwise, an attacker may control a malicious App and initiate subsequent attacks by tricking the victim's authorization credentials from the vendor App through a fake authorization request. However, in the fast application scenario, the interaction subject of the vendor App becomes the engine App of the mobile phone manufacturer, which cannot directly interact with the fast application and authenticate its identity, and therefore may introduce security risks, for example, a malicious fast application may pretend to be another legitimate fast application, initiate an authorization request to the vendor App, and steal the user's authorization information, and then log in to the user's account through the stolen authorization information, resulting in the user's personal information or funds being lost.
[0064] Therefore, one or more embodiments of the present specification propose a third-party authorization login method and system to prevent potential user information theft attacks in the third-party authorization login process for fast applications.
[0065] In order for those skilled in the art to better understand the technical solutions in the present specification, the technical solutions in the embodiments of the present specification will be described clearly and completely below in combination with the drawings in the embodiments of the present specification. Obviously, the described embodiments are only part of the embodiments of the present specification, not all. Based on the embodiments in the present specification, all other embodiments obtained by those skilled in the art without creative labor should be within the scope of protection of the present specification.
[0066] It should be noted that: in other embodiments, the steps of the corresponding method do not necessarily follow the order shown and described in the present specification. In some other embodiments, the steps included in the method can be more or less than described in the present specification. In addition, a single step described in the present specification may be divided into multiple steps for description in other embodiments; and multiple steps described in the present specification may also be combined into a single step for description in other embodiments.
[0067] Those skilled in the art can understand that the terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, and are not intended to limit the present application. The singular forms "a", "said" and "the" used in the embodiments of the present application and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise.
[0068] One or more embodiments of the present application provide a third-party authorization login method. Please refer to Figure 2 , Figure 2An exemplary third-party authorization login system is shown, which can be used to implement the third-party authorization login method. It should be noted that the third-party authorization login method described in one or more embodiments of the present application can be implemented by relying on Figure 2 the third-party authorization login system shown, but is not limited to the third-party authorization login system.
[0069] As shown in Figure 2 , the authorization login system includes a terminal device 20, a merchant server 21 and a vendor server 22. The terminal device 20 is connected to the merchant server 21 and the vendor server 22 through a communication link 23. The communication link 23 can be a wired network or a wireless network. For example, the terminal device 20 can use WIFI, Bluetooth, infrared and other communication methods to establish a communication connection with the merchant server 21 and the vendor server 22. Alternatively, the terminal device 20 can also establish a communication connection with the merchant server 21 and the vendor server 22 through a mobile network, wherein the network standard of the mobile network can be any one of 2G (GSM), 2.5G (GPRS), 3G (WCDMA, TD-SCDMA, CDMA2000, UTMS), 4G (LTE), 4G+(LTE+), WiMax, etc.
[0070] The communication link 23 can be implemented through a communication interface provided on the terminal device 20, the merchant server 21 and the vendor server 22. The communication interface can use a transceiver module such as but not limited to a network interface card and a transceiver to realize communication between the terminal device 20 and the merchant server 21 and the vendor server 22.
[0071] The terminal device 20 can be implemented by using a smart device such as but not limited to a smart phone, a notebook computer, an Ipad, etc. The terminal device 20 will be described below taking a smart phone as an example.
[0072] The smart phone is installed with an engine APP provided by a mobile phone vendor, and a plurality of quick applications are deployed in the engine APP. The engine APP provides an authorization jsapi interface to the quick applications, and the quick applications can initiate an authorization request to a vendor App through this channel, obtain user information of the vendor App, and log in a page of the quick application based on the user information.
[0073] The merchant server 21 is a server of the quick application, which can be any device, equipment, platform or device cluster with computing and processing capabilities. In this embodiment, the implementation form of the merchant server 21 is not limited, for example, the merchant server 21 can be a single server, or a server cluster composed of a plurality of servers, and the merchant server 21 can also be a cloud server, also known as a cloud computing server or a cloud host, which is a host product in a cloud computing service system.
[0074] The vendor server 22 is a server of the vendor App. Similarly, the vendor server 22 can be any device, apparatus, platform or cluster of devices with computing and processing capabilities. In the present embodiment, the implementation form of the vendor server 22 is not limited, for example, the vendor server 22 can be a single server, or a server cluster composed of multiple servers, or a cloud server, also known as a cloud computing server or a cloud host, which is a host product in a cloud computing service system.
[0075] Please refer to Figure 3 , Figure 3 The above-mentioned third-party authorization login system is shown in the flowchart when implementing the third-party authorization login method described in the present embodiment. In the third-party authorization login method, the vendor App and the vendor server 22 constitute the authorization end, and the target fast application and the merchant server 21 constitute the fast application end.
[0076] The terminal device 20, the merchant server 21 and the vendor server 22 perform the following processes:
[0077] (301) The fast application calls the authorization jsapi interface provided by the engine App, and initiates an authorization request to the engine App.
[0078] (302) The engine App collects the identity information of the fast application, and authenticates the identity information of the fast application.
[0079] (303) After the engine App authenticates the identity information of the fast application, the engine App initiates an authorization request to the vendor App, and synchronously sends the identity information of the fast application.
[0080] (304) The vendor App collects the identity information of the engine App, and authenticates the identity information of the engine App, specifically, judges whether the identity information of the engine App is associated with the authorization request in step (303); if yes, proceed to step (305), otherwise, terminate the third-party authorization login process.
[0081] (305) The vendor App initiates an authorization request to the vendor server, and synchronously sends the identity information of the engine App and the identity information of the fast application.
[0082] (306) The vendor server verifies the identity information of the engine App and the identity information of the fast application.
[0083] (307) After the vendor server verifies the identity information of the engine App and the identity information of the fast application, the vendor server returns a user authorization request for the fast application to the vendor App, which is used to ask the user whether to agree to authorize the user information in the vendor App to the fast application.
[0084] (308)The user confirms the authorization of the user information in the vendor App to the merchant App through the authorization page provided by the vendor App; and the vendor App sends the user confirmation authorization information to the vendor server.
[0085] (309)The vendor server generates an authorization credential code according to the user confirmation authorization information, and returns the authorization credential code to the vendor App.
[0086] (310)The vendor App returns the authorization credential code to the engine App.
[0087] (311)The engine App returns the authorization credential code to the fast application.
[0088] (312)The fast application returns the authorization credential code to the fast application server, and requests the fast application server to verify the authorization credential code.
[0089] (313)The fast application server verifies the authorization credential code to the vendor server, and requests to obtain the user information.
[0090] (314)The vendor server returns the user information to the fast application server after verifying the authorization credential code.
[0091] (315)The fast application server authenticates the user identity according to the user information.
[0092] (316)The fast application server returns the user login state to the fast application, and completes the login of the user on the fast application server.
[0093] From the above process, the engine App controlled by the mobile phone vendor is responsible for maintaining and identifying the identity information of the subject of the fast application, and the authorization request is transmitted to the vendor App. The vendor App also needs to collect the identity information of the engine App, and transmit the two parts of information (fast application & engine App) to the vendor server for security detection. Therefore, the vendor App can ensure the legality of the fast application interacting with it, that is, to ensure that the user's authorization credential code is transmitted to a legal third party, so as to ensure the security of the fast application authorization login process.
[0094] This method transfers the responsibility of identifying the identity of the fast application to the engine App of the mobile phone vendor, so the modification of the original protocol mainly occurs on the mobile phone vendor and the platform side, and the access mode of the fast application and the general Android application remains basically the same, reducing the modification cost. This third-party authorization login scheme has scalability and can be extended and applied to other Android fast application three-party services, such as face recognition and payment deduction.
[0095] Corresponding to the third-party authorized login system described above, in some embodiments, a third-party authorized login method is provided. Please refer to Figure 4 , Figure 4 A flowchart of the third-party authorized login method is shown, which is applicable to an authorized end including a mobile application APP (i.e., a vendor App) and an application server; the method includes steps S400 to S404:
[0096] S400: In response to an authorization request of an engine APP, the mobile application APP acquires the identity information of the target fast application uploaded by the engine APP after authentication, and collects the identity information of the engine APP.
[0097] Among them, the identity information can include but is not limited to the package name & signature of the target fast application and other information that can uniquely identify the target fast application.
[0098] Before uploading the identity information of the target fast application, the engine APP needs to authenticate the identity information of the target fast application. A plurality of fast applications are deployed in the engine APP, and when these fast applications are deployed into the engine APP, the identity information will be pre-synchronized to the engine APP for local storage, and the engine APP will synchronize the identity information of these fast applications to the application server for local storage. Therefore, the engine APP can authenticate the identity information of the target fast application in the following way:
[0099] In response to the authorization request of the target fast application, the engine APP collects the identity information of the target fast application;
[0100] The engine APP compares the identity information of the target fast application with the pre-stored fast application identity information locally, and if there is a pre-stored fast application identity information consistent with the identity information of the target fast application, the identity information of the target fast application is authenticated.
[0101] Through the above authentication method, the engine APP can confirm that the identity of the target fast application is trustworthy.
[0102] S402: The mobile application APP initiates an authorization request to the application server and synchronously sends the identity information of the engine APP and the identity information of the target fast application.
[0103] In some embodiments, before the mobile application APP initiates an authorization request to the application server, the collected identity information of the engine APP also needs to be authenticated to determine that the identity of the engine APP is trustworthy. Specifically, the mobile application APP can authenticate the identity information of the engine APP in the following way:
[0104] The identity information of the engine APP is compared with the authorization request of the engine APP, and if the identity information of the engine APP is associated with the authorization request of the engine APP, the identity information of the engine APP is authenticated.
[0105] In the authorization request of the engine APP, all or part of the identity information of the engine APP or other identifiers mapped from all or part of the identity information of the engine APP are carried, so that the mobile application APP can verify whether the engine APP can be trusted by judging whether the authorization request of the engine APP is associated with the identity information of the engine APP.
[0106] S404: In response to the authorization request of the mobile application APP, the application server authenticates the identity information of the engine APP and the identity information of the target fast application, and after authentication, the application server issues an authorization credential to the target fast application through the engine APP.
[0107] Among them, the application server locally pre-stores the identity information of the engine APP, and also stores the identity information of the fast application uploaded by the engine APP and deployed in the engine APP, so that the application server can authenticate the identity information of the engine APP and the identity information of the target fast application in the following way:
[0108] For the identity information of the engine APP, the application server compares the identity information of the engine APP with the pre-stored engine identity information locally, and if the pre-stored engine identity information is consistent with the identity information of the engine APP, the identity information of the engine APP is authenticated.
[0109] For the identity information of the target fast application, the application server compares the identity information of the target fast application with the pre-stored fast application identity information locally, and if the pre-stored fast application identity information is consistent with the identity information of the target fast application, the identity information of the target fast application is authenticated.
[0110] In the above way, the application server confirms that the engine APP and the target fast application are trusted. After authentication, the application server generates an authorization credential code to enable the target fast application to obtain user information based on the authorization code credential, and complete the target fast application login based on the user information.
[0111] Specifically, the authorization credential code is a temporary certificate for the user to confirm the operation of authorizing the fast application, which has a short valid time period. Within this valid time period, the fast application server of the target fast application can apply for user information from the application server by means of the temporary certificate. The application server will verify the validity of the authorization credential code, and after verification, the user information will be issued to the fast application server. After the fast application server authenticates the user identity according to the user information, the login state will be returned to the target fast application, that is, the login operation of the user on the target fast application page is completed.
[0112] Corresponding to the third-party authorization login system described above, in some embodiments, a third-party authorization login method is also provided. Please refer to Figure 5 , Figure 5 The flowchart of the third-party authorization login method is shown, which is applicable to the fast application end, and the fast application end includes the target fast application and the fast application server; the method includes steps S500 to S504:
[0113] S500: In response to the user operation, the target fast application sends an authorization request to the engine APP to make the engine APP collect and authenticate the identity information of the target fast application, and after the authentication is passed, the authorization credential is applied to the authorization end.
[0114] Among them, the identity information of the target fast application can include but is not limited to the package name & signature of the target fast application and other information that can uniquely identify the target fast application.
[0115] The engine APP is deployed with several fast applications, and when these fast applications are deployed in the engine APP, the identity information will be synchronized to the engine APP and saved locally. The engine APP will synchronize the identity information of these fast applications and its own identity information to the application server and save it locally. Therefore, the engine APP can authenticate the identity information of the target fast application in the following way:
[0116] In response to the authorization request of the target fast application, the engine APP collects the identity information of the target fast application;
[0117] The engine APP compares the identity information of the target fast application with the pre-stored fast application identity information locally, and if there is a pre-stored fast application identity information consistent with the identity information of the target fast application, the identity information of the target fast application is authenticated.
[0118] Through the above authentication method, the engine APP can confirm that the identity of the target fast application is trustworthy.
[0119] The authorization end includes a mobile application APP and an application server. After confirming that the identity of the target fast application is trusted, the engine APP initiates an authorization request to the mobile application APP and synchronously sends the identity information of the target fast application to the mobile application APP. The mobile application APP collects the identity information of the engine APP in response to the authorization request of the engine APP and authenticates the identity information of the engine APP, so as to determine whether the identity of the engine APP is trusted. Specifically, the mobile application APP can authenticate the identity information of the engine APP in the following manner:
[0120] The identity information of the engine APP is compared with the authorization request of the engine APP. If the identity information of the engine APP is associated with the authorization request of the engine APP, the identity information of the engine APP is authenticated.
[0121] In the authorization request of the engine APP, all or part of the identity information of the engine APP or other identifiers mapped from all or part of the identity information of the engine APP are carried. Therefore, the mobile application APP can verify whether the engine APP is trusted by judging whether the authorization request of the engine APP is associated with the identity information of the engine APP.
[0122] After the mobile application APP confirms that the engine APP is trusted, the mobile application APP initiates an authorization request to the application server and synchronously sends the identity information of the engine APP and the identity information of the target fast application. The application server authenticates the identity information of the engine APP and the identity information of the target fast application in response to the authorization request of the mobile application APP. After the authentication, the application server returns an authorization credential to the mobile application APP.
[0123] In some embodiments, since the application server locally pre-stores the identity information of the engine APP and also stores the identity information of the fast application uploaded by the engine APP and deployed in the engine APP, the application server can authenticate the identity information of the engine APP and the identity information of the target fast application in the following manner:
[0124] For the identity information of the engine APP, the application server compares the identity information of the engine APP with the pre-stored engine identity information locally, and if the pre-stored engine identity information is consistent with the identity information of the engine APP, the identity information of the engine APP is authenticated.
[0125] For the identity information of the target fast application, the application server compares the identity information of the target fast application with the pre-stored fast application identity information locally, and if the pre-stored fast application identity information is consistent with the identity information of the target fast application, the identity information of the target fast application is authenticated.
[0126] By the above manner, the application server confirms that the engine APP and the target quick application are trustworthy. After the authentication passes, the application server generates an authorization credential code and sends the authorization credential code to the mobile application APP, the mobile application APP sends the authorization credential code to the engine App, and the engine APP sends the authorization credential code to the target quick application.
[0127] S502: In response to the authorization credential returned by the engine APP, the target quick application sends the authorization credential to the quick application server.
[0128] Specifically, the authorization credential code is a temporary certificate for confirming that the user authorizes the quick application, and has a short valid time period.
[0129] S504: In response to obtaining the authorization credential, the quick application server obtains user information from the authorization end based on the authorization credential, and completes target quick application login based on the user information.
[0130] Within the valid time period of the authorization credential code, the quick application server of the target quick application can apply to the application server to obtain user information by virtue of the temporary certificate. The application server verifies the validity of the authorization credential code, and after the verification passes, issues user information to the quick application server. After the quick application server authenticates the user identity based on the user information, it returns a login state to the target quick application, that is, completes the login operation of the user on the target quick application page.
[0131] To implement the above third-party authorization login method, in some embodiments, a terminal device is also provided. The terminal device is installed with an engine APP and a mobile application APP provided by an authorization end, and the engine APP is deployed with a target quick application; the target quick application performs third-party authorization login based on user information obtained by the mobile application APP, and specifically includes steps S600 to S608:
[0132] S600: In response to a user operation, the target quick application sends an authorization request to the engine APP;
[0133] S602: In response to the authorization request of the target quick application, the engine APP collects and authenticates identity information of the target quick application, and after the authentication passes, sends an authorization request and the identity information of the target quick application to the mobile application APP;
[0134] S604: In response to the authorization request of the engine APP, the mobile application APP collects identity information of the engine APP, and sends an authorization request, the identity information of the engine APP and the identity information of the target quick application to the application server;
[0135] S606: In response to the authorization request of the mobile application APP, the application server authenticates the identity information of the engine APP and the identity information of the target fast application. After the authentication is passed, the authorization credential is issued to the target fast application through the engine APP;
[0136] S608: In response to obtaining the authorization credential, the target fast application obtains the user information from the application server based on the authorization credential, and completes the login based on the user information.
[0137] Please refer to Figure 6 , Figure 6 A structure diagram of the terminal device is shown. The terminal device includes a bus 701, a processor 702, a memory 703, and a communication interface 704. The memory 703 stores a computer program, which, when running on the processor 702, causes the processor 702 to execute the specific steps of the terminal device in which the target fast application performs third-party authorization login based on the user information obtained by the mobile application APP. It should be understood that the number of processors and memories in the terminal device is not limited.
[0138] The bus 701 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus 701 can be divided into an address bus, a data bus, a control bus, etc. For the sake of representation, Figure 6 In the figure, only one line is used to represent, but it does not mean that there is only one bus or one type of bus. The bus 701 can include a channel for transmitting information between various components of the terminal device (for example, the processor 702, the memory 703 and the communication interface 704).
[0139] The processor 702 can include any one or more of a processor (central processing unit, CPU), a graphics processor (graphics processing unit, GPU), a microprocessor (MP), or a digital signal processor (digital signal processor, DSP).
[0140] The memory 703 can include volatile memory (volatile memory), such as random access memory (RAM). The memory 703 can also include non-volatile memory (non-volatile memory), such as read-only memory (ROM), flash memory, a mechanical hard disk drive (HDD) or a solid state drive (SSD).
[0141] The communication interface 704 uses a transceiver module such as, but not limited to, a network interface card, a transceiver, to enable communication between the terminal device and other devices or communication networks, such as between the application server and the fast application server.
[0142] Those skilled in the art should understand that the modules or steps of the present application described above can be realized by general computing devices, which can be concentrated on a single computing device or distributed on a network composed of multiple computing devices, and optionally, they can be realized by program codes executable by computing devices, so that they can be stored in storage devices and executed by computing devices, and in some cases, the steps shown or described can be executed in different order, or they can be made into individual integrated circuit modules, or multiple modules or steps can be made into a single integrated circuit module. Thus, the present application is not limited to any particular combination of hardware and software.
[0143] Each embodiment in the specification is described in a progressive manner, and the same or similar parts between each embodiment can be referred to each other, and each embodiment focuses on the difference from other embodiments. In particular, for system embodiments, since they are basically similar to method embodiments, the description is relatively simple, and the relevant parts can be referred to the part of the method embodiment.
[0144] The above describes specific embodiments of the present application. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in an order different than the order in which they are recited in the embodiments and still achieve the desired result. In addition, the processes depicted in the figures do not necessarily require the particular order shown, or sequential order, to achieve the desired results. In certain implementations, multitasking and parallel processing can be advantageous or necessary.
[0145] It should be noted that the above-mentioned are only specific embodiments of the present application, and obviously the present application is not limited to the above-mentioned embodiments, and there are many similar changes. All the changes directly derived or thought from the disclosure of the present application by those skilled in the art should belong to the protection scope of the present application.
Claims
1. A third-party authorization login method, applicable to the authorization end, wherein the authorization end includes a mobile application (APP) and an application server; the method includes: In response to the authorization request from the engine APP, the mobile application APP obtains the identity information of the target quick application uploaded by the engine APP after authentication, and collects the identity information of the engine APP. The target quick app is deployed in the engine APP; Before initiating an authorization request to the mobile application, the engine application authenticates the identity information of the target quick application based on the pre-stored quick application's identity information. After successful authentication, it initiates an authorization request to the mobile application. The mobile application (APP) authenticates the identity information of the engine APP. After successful authentication, the mobile application (APP) sends an authorization request, the identity information of the engine APP, and the identity information of the target quick application to the application server. In response to the authorization request of the mobile application APP, the application server authenticates the identity information of the engine APP and the identity information of the target quick application. After successful authentication, the engine APP issues authorization credentials to the target quick application so that the target quick application can obtain user information based on the authorization credentials and complete the login of the target quick application based on the user information.
2. The method as described in claim 1, wherein the engine APP authenticates the identity information of the target quick app, specifically including: In response to the authorization request of the target quick app, the engine app collects the identity information of the target quick app; The engine app compares the identity information of the target quick app with the identity information of quick apps pre-stored locally. If there is a pre-stored quick app identity information that matches the identity information of the target quick app, then the identity information of the target quick app is authenticated.
3. The method as described in claim 1, wherein the mobile application (APP) authenticates the identity information of the engine APP, specifically including: The identity information of the engine app is compared with the authorization request of the engine app. If the identity information of the engine app is associated with the authorization request of the engine app, then the identity information of the engine app is authenticated.
4. The method as described in claim 1, wherein the application server authenticates the identity information of the engine APP and the identity information of the target quick app, specifically including: The application server compares the identity information of the engine APP with the engine identity information pre-stored locally. If there is pre-stored engine identity information that matches the identity information of the engine APP, then the identity information of the engine APP is authenticated. The application server performs a consistency comparison between the identity information of the target quick app and the identity information of quick apps pre-stored locally. If there is pre-stored quick app identity information that matches the identity information of the target quick app, then the identity information of the target quick app is authenticated.
5. The method of claim 1, further comprising, before the application server sends the authorization credential to the target quick app through the engine APP: The authorization credentials are generated in response to the user's authorization confirmation information for the target quick app through the mobile application APP.
6. A third-party authorization login method, applicable to a quick app client, wherein the quick app client includes a target quick app and a quick app server of the target quick app, the target quick app being deployed in an engine app; the method includes: In response to a user action, the target quick app sends an authorization request to the engine app, so that the engine app collects the identity information of the target quick app, authenticates the identity information of the target quick app based on the pre-stored identity information of the quick app, and after successful authentication, initiates an authorization request to the mobile app, so that the mobile app authenticates the identity information of the engine app. After successful authentication, the mobile application (APP) sends an authorization request, the identity information of the engine APP, and the identity information of the target quick application to the application server for authentication, and obtains the authorization credentials issued by the application server after successful authentication. In response to the authorization credentials returned by the engine APP, the target quick app sends the authorization credentials to the quick app server; In response to obtaining the authorization credentials, the Quick App server retrieves user information from the authorization end based on the authorization credentials, and completes the login for the target Quick App based on the user information.
7. A third-party authorization login system, comprising an authorization client and a quick app client; The authorization terminal is used to execute the method as described in any one of claims 1 to 5, and the quick app terminal is used to execute the method as described in claim 6, so as to achieve authorized login of the target quick app.
8. A terminal device, wherein the device is equipped with an engine APP and a mobile application APP provided by an authorized terminal, and a target quick application is deployed in the engine APP; The target quick app performs third-party authorization login based on the user information obtained by the mobile application (APP), specifically including: In response to a user action, the target quick app sends an authorization request to the engine app; In response to the authorization request of the target quick app, the engine APP collects the identity information of the target quick app and authenticates the identity information of the target quick app based on the pre-stored identity information of the quick app. After successful authentication, the engine APP sends the authorization request and the identity information of the target quick app to the mobile application APP. In response to the authorization request from the engine APP, the mobile application APP collects and authenticates the identity information of the engine APP. After successful authentication, the mobile application APP sends an authorization request, the identity information of the engine APP, and the identity information of the target quick application to the application server. In response to the authorization request of the mobile application APP, the application server authenticates the identity information of the engine APP and the identity information of the target quick application. After successful authentication, the engine APP issues authorization credentials to the target quick application. In response to obtaining the authorization credentials, the target app retrieves user information from the application server based on the authorization credentials and completes login based on the user information.
9. The device as described in claim 8, wherein the target quick app obtains user information from the application server based on the authorization credentials, and completes login based on the user information, specifically including: The target quick app sends the authorization credentials to the quick app server; In response to obtaining the authorization credentials, the Quick App service requests user information from the application server based on the authorization credentials, and completes the login of the target Quick App based on the obtained user information.
Citation Information
Patent Citations
Data processing method and device and storage medium
CN110008668A
Account association method, device, system, server, and storage medium
WO2020228013A1