An identity authentication method and system based on session sharing
Through the identity authentication method based on session sharing, after the user logs in to the first application system, the identity authentication center generates a key and token, and the second application system obtains the token through key information verification, which solves the tedious problem of multi-system login and realizes one system login and multi-system mutual trust login authentication, improving efficiency and security.
Patent Information
- Application Number
- CN202311779340.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-22
- Publication Date
- 2025-09-30
- Estimated Expiration
- 2043-12-22
AI Technical Summary
Users frequently enter their usernames and passwords when logging into multiple systems, resulting in a poor user experience and easy forgetting of passwords. Existing technologies make it difficult to achieve one-time system login and mutual trust among multiple systems.
Through the identity authentication method based on session sharing, after the user logs in to the first application system, the identity authentication center generates a key and token and puts the session information into the cache. The second application system verifies the key information with the main service session and obtains the token to complete the login authentication.
It enables users to automatically log in to multiple application systems with just one login authentication, improving login authentication efficiency, optimizing user experience, and ensuring the security and effectiveness of login.
Smart Images

Figure CN117938444B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of login authentication, and more particularly to an identity authentication method and system based on session sharing. Background Art
[0002] System login is a crucial component of permissions management and the foundation for other permissions management and design. System login requires users to provide information that satisfies the login requirements before they can access the system. Typically, the information provided is a username and password. The first thing to do before using the system is to log in. Only after entering a valid username and password can the system be used. Any operation performed within the system will be signed by the operator. System login functionality involves querying the database based on the username and password entered by the user, determining whether the user exists, and performing appropriate processing.
[0003] When users log in to multiple systems, frequently entering usernames and passwords can lead to a poor user experience and passwords are easily forgotten. Therefore, how to achieve a single system login with mutual trust among multiple systems is a problem that needs to be addressed. Summary of the Invention
[0004] The present invention proposes an identity authentication method and system based on session sharing to solve the problem of how to implement identity authentication based on session sharing.
[0005] In order to solve the above problem, according to one aspect of the present invention, a session sharing-based identity authentication method is provided, the method comprising:
[0006] When a user accesses the first application system, the first application system performs login authentication with the identity authentication center, and when the authentication is successful, the identity authentication center returns the user session information;
[0007] The identity authentication center creates a primary service session, generates a key and a token, and stores the session information in a cache as shared session information;
[0008] When a user accesses a second application system, the second application system creates a sub-service session and requests key information from the main service, so that the main service verifies the request and returns the key information to the second application system when the verification is successful;
[0009] The second application system verifies the primary service session based on the key information, obtains the token when the verification passes, and obtains the shared session information from the cache based on the token;
[0010] Complete login authentication of the second application system based on the shared session information.
[0011] Preferably, the first application system performs login authentication with the identity authentication center, including:
[0012] Verify whether the username and corresponding password provided by the user match the username and password in the user record stored in the database by the identity authentication center. If they match, the login authentication is successful; if not, the login authentication fails and a failure message is returned.
[0013] Preferably, the user session information is used to identify and track data of user activities in an application or system, and the user session information includes: session identifier, user identity information, session timestamp, user device information, IP address and session state information.
[0014] Preferably, the identity authentication center creates a primary service session and generates a key and a token, including:
[0015] The identity authentication center creates a primary service session and randomly generates a long string as a symmetric key for encrypting and verifying session information. It generates an identity token based on the user's identity information and an access token for authenticating the user when communicating with other services. The key, identity token, and access token are then sent to the primary service in an encrypted manner.
[0016] Preferably, the method further comprises:
[0017] Configure the validity period of session information in the cache.
[0018] According to another aspect of the present invention, there is provided an identity authentication system based on session sharing, the system comprising:
[0019] The authentication unit is used for, when a user accesses the first application system, the first application system performs login authentication with the identity authentication center, and when the authentication is successful, the identity authentication center returns user session information;
[0020] A primary service session creation unit, configured to create a primary service session for the identity authentication center, generate a key and a token, and store the session information in a cache as shared session information;
[0021] a key request unit, configured to, when a user accesses a second application system, cause the second application system to create a sub-service session and request key information from the primary service, so that the primary service verifies the request and returns the key information to the second application system upon successful verification;
[0022] a session information acquiring unit, configured for the second application system to verify the second application system with the primary service session based on the key information, and to acquire the token when the verification passes, and to acquire the shared session information from the cache based on the token;
[0023] A login unit is used to complete the login authentication of the second application system based on the shared session information.
[0024] Preferably, the authentication unit, wherein the first application system performs login authentication with the identity authentication center, includes:
[0025] Verify whether the username and corresponding password provided by the user match the username and password in the user record stored in the database by the identity authentication center. If they match, the login authentication is successful; if not, the login authentication fails and a failure message is returned.
[0026] Preferably, the user session information is used to identify and track data of user activities in an application or system, and the user session information includes: session identifier, user identity information, session timestamp, user device information, IP address and session state information.
[0027] Preferably, the primary service session creation unit, wherein the identity authentication center creates the primary service session and generates a key and a token, includes:
[0028] The identity authentication center creates a primary service session and randomly generates a long string as a symmetric key for encrypting and verifying session information. It generates an identity token based on the user's identity information and an access token for authenticating the user when communicating with other services. The key, identity token, and access token are then sent to the primary service in an encrypted manner.
[0029] Preferably, the primary service session creation unit further includes:
[0030] Configure the validity period of session information in the cache.
[0031] The present invention provides an identity authentication method and system based on session sharing, comprising: when a user accesses a first application system, the first application system performs login authentication with an identity authentication center, and when the authentication is successful, the identity authentication center returns user session information; the identity authentication center creates a main service session, generates a key and a token, and stores the session information in a cache as shared session information; when the user accesses a second application system, the second application system creates a sub-service session and requests key information from the main service, so that the main service verifies the request and returns the key information to the second application system when the verification is successful; the second application system verifies the main service session based on the key information, obtains the token when the verification is successful, and obtains the shared session information from the cache based on the token; and completes login authentication for the second application system based on the shared session information. When a user needs to log in to multiple application systems to conduct business, the present invention only requires completing login authentication once with the identity authentication center, without having to create a session for each application system. Other application systems automatically complete login with the identity authentication center through session sharing, which can improve login authentication efficiency, optimize user experience, and ensure the security and effectiveness of login authentication, thus achieving login authentication with one system and mutual trust among multiple systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] A more complete understanding of exemplary embodiments of the present invention may be obtained by referring to the following drawings:
[0033] Figure 1 This is a process of the session sharing-based identity authentication method 100 according to an embodiment of the present invention;
[0034] Figure 2 Schematic diagram of identity authentication interaction based on session sharing according to an embodiment of the present invention;
[0035] Figure 3 2 is a structural diagram of an identity authentication system 300 based on session sharing according to an embodiment of the present invention. DETAILED DESCRIPTION
[0036] Exemplary embodiments of the present invention will now be described with reference to the accompanying drawings. However, the present invention may be embodied in many different forms and is not limited to the embodiments described herein. These embodiments are provided to provide a thorough and complete disclosure of the present invention and to fully convey the scope of the present invention to those skilled in the art. The terminology used in the exemplary embodiments shown in the accompanying drawings is not intended to limit the present invention. In the accompanying drawings, identical elements are denoted by the same reference numerals.
[0037] Unless otherwise specified, the terms used herein (including technical terms) have the meanings commonly understood by those skilled in the art. In addition, it is understood that terms defined in commonly used dictionaries should be understood to have the same meanings as those in the context of the relevant fields, and should not be understood as idealized or overly formal meanings.
[0038] The present invention proposes a session sharing-based identity authentication method for multiple application systems used by users that need to complete identity authentication with an identity authentication center. The user performs identity authentication at the identity authentication center and generates a main service. After the main service obtains the session, it generates a key and a token and places the session in a public cache. When other application systems have authenticated with the identity authentication center, they obtain the key from the main service, verify it with the main service, obtain the token after successful verification, and use the token to obtain the session from the cache, thereby completing the identity authentication. The key can only be used once and becomes invalid after use, thereby ensuring the security and effectiveness of the system. The cache validity period is configurable and can be configured based on the security level requirements of the application system to meet diverse needs.
[0039] Figure 1 FIG. 1 is a flow chart of the session-sharing-based identity authentication method 100 according to an embodiment of the present invention. Figure 1 As shown, the identity authentication method based on session sharing provided by the embodiment of the present invention is that when a user needs to log in to multiple application systems to handle business, he only needs to complete login authentication with the identity authentication center once, without having to create a session for each application system. Other application systems automatically complete login with the identity authentication center through session sharing, which can improve login authentication efficiency and optimize user experience. At the same time, it ensures the security and effectiveness of login authentication, and realizes one system login and multi-system mutual trust login authentication. The identity authentication method 100 based on session sharing provided by the embodiment of the present invention starts from step 101. In step 101, after the user accesses the first application system, the first application system performs login authentication with the identity authentication center, and when the authentication is successful, the identity authentication center returns the user session information.
[0040] Preferably, the first application system performs login authentication with the identity authentication center, including:
[0041] Verify whether the username and corresponding password provided by the user match the username and password in the user record stored in the database by the identity authentication center. If they match, the login authentication is successful; if not, the login authentication fails and a failure message is returned.
[0042] Preferably, the user session information is used to identify and track data of user activities in an application or system, and the user session information includes: session identifier, user identity information, session timestamp, user device information, IP address and session state information.
[0043] In the present invention, a user logs in to a first application system using a username and password. The first application system then performs login authentication with an identity authentication center, verifying whether the username and corresponding password provided by the user match the username and password stored in the user record in the identity authentication center's database. If they match, the login authentication succeeds; if not, the login authentication fails, and a failure message is returned. If authentication succeeds, the identity authentication center returns user session information. This user session information is used to identify and track data related to user activity within an application or system. This user session information includes: a session identifier, user identity information, a session timestamp, user device information, an IP address, and session state information.
[0044] In step 102, the identity authentication center creates a primary service session, generates a key and a token, and puts the session information into a cache as shared session information.
[0045] Preferably, the identity authentication center creates a primary service session and generates a key and a token, including:
[0046] The identity authentication center creates a primary service session and randomly generates a long string as a symmetric key for encrypting and verifying session information. It generates an identity token based on the user's identity information and an access token for authenticating the user when communicating with other services. The key, identity token, and access token are then sent to the primary service in an encrypted manner.
[0047] Preferably, the method further comprises:
[0048] Configure the validity period of session information in the cache.
[0049] In this invention, the identity authentication center creates a primary service session, generates a key and token, and stores the session information in a cache as shared session information. A long, randomly generated string of characters is used as the key. An identity token is generated based on the user's identity information. An access token is also generated for user authentication when communicating with other services. The key, identity token, and access token are then encrypted and sent to the primary service.
[0050] In step 103, when the user accesses the second application system, the second application system creates a sub-service session and requests key information from the main service, so that the main service verifies the request and returns the key information to the second application system when the verification is successful.
[0051] In step 104, the second application system verifies the primary service session based on the key information, obtains the token when the verification passes, and obtains the shared session information from the cache based on the token.
[0052] In step 105, the login authentication of the second application system is completed based on the shared session information.
[0053] Combine Figure 2 As shown, in the present invention, the process of implementing identity authentication based on session sharing includes:
[0054] Step 1. The user accesses application system A and logs in and authenticates with the identity authentication center.
[0055] Step 2. After the identity authentication center passes the authentication, the user session information is returned;
[0056] Step 3. Create a main service session, generate a key and token, and put the session information into the cache as a shared session;
[0057] Step 4. The user accesses application system B, creates a sub-service session, obtains the key from the main service, and verifies it with the main service.
[0058] Step 5. After the main service passes the verification, application system B obtains the token for the sub-service session;
[0059] Step 6. Application system B obtains session information from the cache using the token for the service session.
[0060] Step 7. Complete the login authentication of application system B;
[0061] Step 8. The user performs business operations in application system B.
[0062] The key technical points of the present invention are:
[0063] 1. Through the session of the shared identity authentication center, users do not need to log in multiple times, and can log in to one system and log in to multiple systems with mutual trust, thus completing the authentication of trusted identities.
[0064] 2. The session duration is configurable to meet the security requirements of different application systems.
[0065] 3. The session of the main service can only be obtained through encryption keys and tokens. The session information is not directly exposed or shared externally, which ensures data security and user data privacy to a certain extent.
[0066] Figure 3 FIG is a structural diagram of an identity authentication system 300 based on session sharing according to an embodiment of the present invention. Figure 3As shown, the identity authentication system 300 based on session sharing provided by the embodiment of the present invention includes: an authentication unit 301, a main service session creation unit 302, a key request unit 303, a session information acquisition unit 304 and a login unit 305.
[0067] Preferably, the authentication unit 301 is used for, when a user accesses the first application system, the first application system to perform login authentication with the identity authentication center, and when the authentication is successful, the identity authentication center returns user session information.
[0068] Preferably, the authentication unit 301, wherein the first application system performs login authentication with the identity authentication center, includes:
[0069] Verify whether the username and corresponding password provided by the user match the username and password in the user record stored in the database by the identity authentication center. If they match, the login authentication is successful; if not, the login authentication fails and a failure message is returned.
[0070] Preferably, the user session information is used to identify and track data of user activities in an application or system, and the user session information includes: session identifier, user identity information, session timestamp, user device information, IP address and session state information.
[0071] Preferably, the primary service session creating unit 302 is configured for the identity authentication center to create a primary service session, generate a key and a token, and put the session information into a cache as shared session information.
[0072] Preferably, the primary service session creation unit 302, wherein the identity authentication center creates a primary service session and generates a key and a token, includes:
[0073] The identity authentication center creates a primary service session and randomly generates a long string as a symmetric key for encrypting and verifying session information. It generates an identity token based on the user's identity information and an access token for authenticating the user when communicating with other services. The key, identity token, and access token are then sent to the primary service in an encrypted manner.
[0074] Preferably, the primary service session creation unit further includes:
[0075] Configure the validity period of session information in the cache.
[0076] Preferably, the key request unit 303 is used for, when a user accesses a second application system, the second application system to create a sub-service session and request key information from the main service, so that the main service verifies the request and returns the key information to the second application system when the verification is successful.
[0077] Preferably, the session information acquisition unit 304 is configured for the second application system to verify the primary service session based on the key information, and when the verification passes, to obtain the token, and to obtain the shared session information from the cache based on the token.
[0078] Preferably, the login unit 305 is configured to complete login authentication of the second application system based on the shared session information.
[0079] The identity authentication system 300 based on session sharing according to the embodiment of the present invention corresponds to the identity authentication method 100 based on session sharing according to another embodiment of the present invention, and will not be described in detail here.
[0080] The present invention has been described with reference to a few embodiments. However, it is apparent to those skilled in the art that other embodiments than the ones disclosed above are equally within the scope of the present invention.
[0081] Generally, all terms used in this disclosure are to be interpreted according to their ordinary meaning in the art, unless explicitly defined otherwise herein. All references to "a / the / the [device, component, etc.]" are to be interpreted openly as referring to at least one instance of the device, component, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not necessarily need to be performed in the exact order disclosed, unless explicitly stated otherwise.
[0082] Those skilled in the art will appreciate that the embodiments of the present application can be provided as methods, systems, or computer program products. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.
[0083] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0084] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.
[0085] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.
[0086] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered by the scope of protection of the present invention.
Claims
1. An identity authentication method based on session sharing, characterized in that: The method comprises: When a user accesses the first application system, the first application system performs login authentication with the identity authentication center, and when the authentication is successful, the identity authentication center returns the user session information; The identity authentication center creates a primary service session, generates a key and a token, and stores the session information in a cache as shared session information; When a user accesses a second application system, the second application system creates a sub-service session and requests key information from the main service, so that the main service verifies the request and returns the key information to the second application system when the verification is successful; The second application system verifies the primary service session based on the key information, obtains the token when the verification passes, and obtains the shared session information from the cache based on the token; Complete login authentication of the second application system based on the shared session information.
2. The method according to claim 1, characterized in that The first application system performs login authentication with the identity authentication center, including: Verify whether the username and corresponding password provided by the user match the username and password in the user record stored in the database by the identity authentication center. If they match, the login authentication is successful; if not, the login authentication fails and a failure message is returned.
3. The method according to claim 1, characterized in that The user session information is used to identify and track data of user activities in an application or system. The user session information includes: a session identifier, user identity information, a session timestamp, user device information, an IP address, and session state information.
4. The method according to claim 1, wherein The identity authentication center creates a primary service session and generates keys and tokens, including: The identity authentication center creates a primary service session and randomly generates a long string as a symmetric key for encrypting and verifying session information. It generates an identity token based on the user's identity information and an access token for authenticating the user when communicating with other services. The key, identity token, and access token are then sent to the primary service in an encrypted manner.
5. The method according to claim 1, wherein The method further comprises: Configure the validity period of session information in the cache.
6. An identity authentication system based on session sharing, characterized in that: The system comprises: The authentication unit is used for, when a user accesses the first application system, the first application system performs login authentication with the identity authentication center, and when the authentication is successful, the identity authentication center returns user session information; A primary service session creation unit, configured to create a primary service session for the identity authentication center, generate a key and a token, and store the session information in a cache as shared session information; a key request unit, configured to, when a user accesses a second application system, cause the second application system to create a sub-service session and request key information from the primary service, so that the primary service verifies the request and returns the key information to the second application system upon successful verification; a session information acquiring unit, configured for the second application system to verify the second application system with the primary service session based on the key information, and to acquire the token when the verification passes, and to acquire the shared session information from the cache based on the token; A login unit is used to complete the login authentication of the second application system based on the shared session information.
7. The system according to claim 6, characterized in that The authentication unit, the first application system and the identity authentication center perform login authentication, including: Verify whether the username and corresponding password provided by the user match the username and password in the user record stored in the database by the identity authentication center. If they match, the login authentication is successful; if not, the login authentication fails and a failure message is returned.
8. The system according to claim 6, wherein: The user session information is used to identify and track data of user activities in an application or system. The user session information includes: a session identifier, user identity information, a session timestamp, user device information, an IP address, and session state information.
9. The system according to claim 6, wherein: The primary service session creation unit and the identity authentication center create a primary service session and generate a key and a token, including: The identity authentication center creates a primary service session and randomly generates a long string as a symmetric key for encrypting and verifying session information. It generates an identity token based on the user's identity information and an access token for authenticating the user when communicating with other services. The key, identity token, and access token are then sent to the primary service in an encrypted manner.
10. The system according to claim 6, wherein: The primary service session creation unit further includes: Configure the validity period of session information in the cache.
Citation Information
Patent Citations
Session data sharing system and method
CN104580226A
Session control sharing method and system in distributed cluster system
CN114979234A